The revFADP explained: Switzerland's revised data protection act
The revised Federal Act on Data Protection (revFADP) has been in force since 1 September 2023 and governs how companies in Switzerland may process personal data. It brings Swiss data protection law to a level comparable with the European GDPR – but it came into force without a transition period: the duties have applied from day one.
For companies that want to deploy AI tools, the revFADP is the central legal framework. Anyone also serving customers in the EU meets the GDPR in parallel – both frameworks can be covered by a single data protection concept rather than built twice.
The key duties at a glance
The revFADP builds on principles such as transparency, purpose limitation and proportionality. In practical terms, companies have to meet the following duties in particular:
- Duty to inform: data subjects must be informed when personal data is collected, usually through a privacy policy
- Record of processing activities: documentation of which data is processed for which purpose (with relief for SMEs with fewer than 250 employees)
- Duty to report: breaches of data security that pose a high risk must be reported to the FDPIC as quickly as possible
- Data protection impact assessment: mandatory for processing that is likely to entail a high risk
- Privacy by design and by default: data protection must be built in technically and organisationally
- Right of access: data subjects can request information about the processing of their data
Fines: who is liable and how much?
Unlike the GDPR, the revFADP primarily fines not the company but the responsible individual – for example a managing director or the person responsible for data protection. Intentional breaches of certain duties can lead to fines of up to CHF 250,000.
For comparison: the GDPR provides for fines of up to 20 million euros or 4 per cent of global annual turnover – directed at the company. Anyone with customers in the EU has to keep both regimes in view.
Sensitive personal data
Higher requirements apply to certain categories of data: health data, biometric data, information on religious or political views, genetic data and data on criminal proceedings. Anyone processing such data – medical practices, recruitment consultancies or social services, for instance – needs explicit consent in many cases, along with particularly careful technical safeguards.
What does the revFADP mean for using AI?
Every input into an AI tool is an act of data processing – so the revFADP applies to AI without restriction. The critical points are transfers to third countries, the use of inputs for model training and the lack of control over employees' private AI accounts.
Companies are on the safest footing with a centrally managed AI platform: hosting in Switzerland or the EU, a contractual commitment not to train on customer data, a data processing agreement and traceable access.
Frequently asked questions
Does the revFADP apply to small companies too?
Yes. The revFADP applies to everyone who processes personal data – regardless of size. SMEs with fewer than 250 employees merely benefit from relief in relation to the record of processing activities, provided there is no high risk.
What is the difference between the revFADP and the GDPR?
Both pursue similar principles. The main differences: the revFADP fines individuals (up to CHF 250,000), the GDPR fines companies (up to 4 per cent of global turnover). The GDPR also demands more formal documentation, such as a legal basis for every processing activity.
What should you do in the event of a data breach?
Breaches of data security that are likely to result in a high risk to data subjects must be reported to the Federal Data Protection and Information Commissioner (FDPIC) as quickly as possible. Internally, the process and responsibilities for this belong in an incident response plan.
Related reading
Bring AI into your company securely.
Try Vidimas with your team – and see how quickly secure AI becomes productive.
- Try it with the whole team
- Set up in minutes
- Productive from day one
