Swiss FADP vs EU GDPR: Key Differences for AI and Data Privacy

Two major data privacy laws now govern how organizations handle personal data across Europe; the EU’s General Data Protection Regulation (GDPR) and Switzerland’s revised Federal Act on Data Protection (FADP). With AI systems processing personal data at scale, understanding where these laws agree, where they diverge, and how each handles artificial intelligence is now a practical requirement for every security and compliance professional.

What Is the Swiss FADP?

The Swiss Federal Act on Data Protection, known as the nFADP or revFADP came into force on September 1, 2023. It replaced Switzerland’s original 1992 data protection law, which had become outdated as digital technologies evolved far beyond what the original drafters anticipated.

The revised FADP was designed to modernize Swiss privacy law and align it more closely with GDPR principles, partly to preserve Switzerland’s EU adequacy status, the formal recognition that Swiss data protection is equivalent to EU standards, allowing personal data to flow freely between the EU and Switzerland without additional transfer mechanisms.

The law is enforced by the Federal Data Protection and Information Commissioner (FDPIC), Switzerland’s national supervisory authority.

What Is the EU GDPR?

The General Data Protection Regulation has applied across all EU member states since May 25, 2018. It is the most widely adopted data privacy framework in the world, directly influencing legislation in over 100 countries including Switzerland’s revised FADP.

GDPR applies to any organization that processes the personal data of EU residents, regardless of where the organization itself is based. It is enforced by national Data Protection Authorities (DPAs) in each EU member state, with cross-border cases coordinated through the European Data Protection Board (EDPB).

Swiss FADP vs EU GDPR: Side-by-Side Comparison

AreaSwiss FADPEU GDPR
In forceSeptember 1, 2023May 25, 2018
Territorial scopeApplies to organizations processing data of persons in SwitzerlandApplies to any org processing data of EU residents, worldwide
Personal data definitionAny information relating to an identified or identifiable natural personSame broad definition, plus includes online identifiers and location data explicitly
Sensitive data categoriesHealth, biometric, genetic, political opinions, religious beliefs, criminal records, social welfare dataSame categories, also includes trade union membership and sexual orientation explicitly
Legal bases for processingConsent, contract performance, legitimate interests, legal obligation, vital interestsSix legal bases under Article 6 same types but more formally structured
Data Protection OfficerNo mandatory DPO voluntary “Data Protection Advisor” encouragedMandatory DPO for public authorities, large-scale processing, and sensitive data processing
Breach notification“As soon as possible” to FDPIC if high risk to individuals72-hour deadline to notify the national DPA; individuals notified without undue delay
Data Protection Impact AssessmentRequired for high-risk processing called DPIA in practiceMandatory DPIA under Article 35 for high-risk processing
Privacy by designRequired data minimization and default privacy built inRequired under Article 25
Data portabilityRight to receive data in a machine-readable format applies to automated processingFull right to portability under Article 20, broader in scope
PenaltiesUp to CHF 250,000 imposed on individuals (not companies)Up to €20M or 4% of global annual turnover imposed on organizations
EnforcerFederal Data Protection and Information Commissioner (FDPIC)National DPAs in each member state; EDPB for cross-border cases

The Biggest Gotcha: Who Gets Fined

The most important practical difference between the two laws is who bears the financial penalty. Under GDPR, fines are levied against the organization, which is why headlines regularly report companies paying tens of millions in penalties. Under the Swiss FADP, fines of up to CHF 250,000 are imposed on individuals the specific employees or executives who made the decisions that violated the law.

This creates very different organizational risk dynamics. Under FADP, a data protection failure can result in personal criminal liability for a compliance officer, IT manager, or board member. Under GDPR, the corporate entity absorbs the financial hit. Security professionals working in Swiss organizations need to understand this distinction clearly it changes the internal incentive structure for data protection compliance.

How Each Law Handles AI and Automated Decision-Making

This is where the two frameworks diverge most visibly, and where both are still catching up to the speed of AI development.

GDPR Article 22 gives individuals the explicit right not to be subject to decisions based solely on automated processing including profiling that produce legal or similarly significant effects. Organizations using AI for credit scoring, hiring, insurance pricing, or loan approvals must offer a human review mechanism and clearly inform individuals that automated decision-making is taking place.

The Swiss FADP addresses this through its high-risk profiling provisions. Profiling that carries a high risk to the data subject requires explicit consent or another strong legal basis. The law distinguishes between ordinary profiling (combining data to evaluate personal aspects) and high-risk profiling (profiling that allows conclusions about core attributes of personality). High-risk profiling is treated as sensitive data processing under the FADP.

AI / Profiling AreaSwiss FADPEU GDPR
Automated decision-making rightsHigh-risk profiling requires strong legal basis or consentArticle 22 explicit right to opt out of solely automated decisions with significant effects
Profiling definitionTwo tiers: profiling and high-risk profilingSingle definition in Article 4(4) applies across all profiling
Transparency for AI systemsRight to be informed when high-risk profiling occursRight to meaningful information about the logic of automated systems
AI Act interactionSwitzerland is not an EU member, EU AI Act does not directly applyEU AI Act applies alongside GDPR dual compliance required
Biometric dataExplicitly listed as sensitive special legal basis requiredExplicitly listed under Article 9 requires explicit consent or specific exemption
Training AI on personal dataRequires lawful basis; purpose limitation and data minimization applySame requirements ICO and EDPB have issued specific guidance on this

One critical point that often gets missed: organizations in the EU must now navigate both GDPR and the EU AI Act simultaneously when deploying AI systems. Switzerland, not being an EU member state, is not directly subject to the EU AI Act, but Swiss organizations that deploy AI systems to EU users may still fall under its scope based on the AI Act’s own territorial provisions.

Data Subject Rights Compared

RightSwiss FADPEU GDPR
Right of accessYes, request information on what data is heldYes, Article 15, broader response requirements
Right to rectificationYesYes, Article 16
Right to erasureYes. right to have inaccurate or unlawfully processed data deletedYes, Article 17, “right to be forgotten,” broader scope
Right to data portabilityYes, machine-readable format for automated processingYes, Article 20, applies to consent and contract bases
Right to objectYes, can object to processingYes, Article 21, includes objection to profiling
Right to restrict processingLimited equivalentYes, Article 18, explicit right
Right not to be profiledYes, for high-risk profilingYes, Article 22, for automated decisions with significant effects

Cross-Border Data Transfers

Switzerland holds an EU adequacy decision, meaning personal data can flow freely from EU member states to Switzerland without additional transfer mechanisms like Standard Contractual Clauses (SCCs). This is a significant operational advantage for Swiss organizations handling EU resident data.

For data leaving Switzerland to third countries, the FADP requires organizations to use approved transfer mechanisms similar to GDPR’s approach. The FDPIC maintains a list of countries recognized as offering adequate protection.

For organizations operating on both sides of the Swiss-EU border, this means one set of data flows (EU to Switzerland) is largely frictionless, while transfers onward from Switzerland to countries like the US or India still require proper mechanisms under both frameworks.

Which Law Applies to Your Organization?

The answer is often both. Any organization that:

  • Is based in Switzerland and processes personal data of Swiss residents, FADP applies
  • Processes personal data of EU residents, regardless of where it’s based, GDPR applies
  • Is based in Switzerland and has EU customers or employees, both FADP and GDPR apply

For security professionals conducting penetration tests, vulnerability assessments, or incident response work in regulated environments, knowing which law governs the data you’re handling and whether that data crosses borders is not optional. Mishandling personal data during a security engagement can create liability under both frameworks simultaneously.

The Swiss FADP and EU GDPR share the same foundations but differ on enforcement mechanics, AI-specific rights, and the key question of who gets penalized. Know the differences, document your data flows, and build privacy into your processes from the start not as an afterthought. Questions about how either law applies to your situation? Drop them in the comments.