Two major data privacy laws now govern how organizations handle personal data across Europe; the EU’s General Data Protection Regulation (GDPR) and Switzerland’s revised Federal Act on Data Protection (FADP). With AI systems processing personal data at scale, understanding where these laws agree, where they diverge, and how each handles artificial intelligence is now a practical requirement for every security and compliance professional.
What Is the Swiss FADP?
The Swiss Federal Act on Data Protection, known as the nFADP or revFADP came into force on September 1, 2023. It replaced Switzerland’s original 1992 data protection law, which had become outdated as digital technologies evolved far beyond what the original drafters anticipated.
The revised FADP was designed to modernize Swiss privacy law and align it more closely with GDPR principles, partly to preserve Switzerland’s EU adequacy status, the formal recognition that Swiss data protection is equivalent to EU standards, allowing personal data to flow freely between the EU and Switzerland without additional transfer mechanisms.
The law is enforced by the Federal Data Protection and Information Commissioner (FDPIC), Switzerland’s national supervisory authority.
What Is the EU GDPR?
The General Data Protection Regulation has applied across all EU member states since May 25, 2018. It is the most widely adopted data privacy framework in the world, directly influencing legislation in over 100 countries including Switzerland’s revised FADP.
GDPR applies to any organization that processes the personal data of EU residents, regardless of where the organization itself is based. It is enforced by national Data Protection Authorities (DPAs) in each EU member state, with cross-border cases coordinated through the European Data Protection Board (EDPB).
Swiss FADP vs EU GDPR: Side-by-Side Comparison
| Area | Swiss FADP | EU GDPR |
|---|---|---|
| In force | September 1, 2023 | May 25, 2018 |
| Territorial scope | Applies to organizations processing data of persons in Switzerland | Applies to any org processing data of EU residents, worldwide |
| Personal data definition | Any information relating to an identified or identifiable natural person | Same broad definition, plus includes online identifiers and location data explicitly |
| Sensitive data categories | Health, biometric, genetic, political opinions, religious beliefs, criminal records, social welfare data | Same categories, also includes trade union membership and sexual orientation explicitly |
| Legal bases for processing | Consent, contract performance, legitimate interests, legal obligation, vital interests | Six legal bases under Article 6 same types but more formally structured |
| Data Protection Officer | No mandatory DPO voluntary “Data Protection Advisor” encouraged | Mandatory DPO for public authorities, large-scale processing, and sensitive data processing |
| Breach notification | “As soon as possible” to FDPIC if high risk to individuals | 72-hour deadline to notify the national DPA; individuals notified without undue delay |
| Data Protection Impact Assessment | Required for high-risk processing called DPIA in practice | Mandatory DPIA under Article 35 for high-risk processing |
| Privacy by design | Required data minimization and default privacy built in | Required under Article 25 |
| Data portability | Right to receive data in a machine-readable format applies to automated processing | Full right to portability under Article 20, broader in scope |
| Penalties | Up to CHF 250,000 imposed on individuals (not companies) | Up to €20M or 4% of global annual turnover imposed on organizations |
| Enforcer | Federal Data Protection and Information Commissioner (FDPIC) | National DPAs in each member state; EDPB for cross-border cases |
The Biggest Gotcha: Who Gets Fined
The most important practical difference between the two laws is who bears the financial penalty. Under GDPR, fines are levied against the organization, which is why headlines regularly report companies paying tens of millions in penalties. Under the Swiss FADP, fines of up to CHF 250,000 are imposed on individuals the specific employees or executives who made the decisions that violated the law.
This creates very different organizational risk dynamics. Under FADP, a data protection failure can result in personal criminal liability for a compliance officer, IT manager, or board member. Under GDPR, the corporate entity absorbs the financial hit. Security professionals working in Swiss organizations need to understand this distinction clearly it changes the internal incentive structure for data protection compliance.
How Each Law Handles AI and Automated Decision-Making
This is where the two frameworks diverge most visibly, and where both are still catching up to the speed of AI development.
GDPR Article 22 gives individuals the explicit right not to be subject to decisions based solely on automated processing including profiling that produce legal or similarly significant effects. Organizations using AI for credit scoring, hiring, insurance pricing, or loan approvals must offer a human review mechanism and clearly inform individuals that automated decision-making is taking place.
The Swiss FADP addresses this through its high-risk profiling provisions. Profiling that carries a high risk to the data subject requires explicit consent or another strong legal basis. The law distinguishes between ordinary profiling (combining data to evaluate personal aspects) and high-risk profiling (profiling that allows conclusions about core attributes of personality). High-risk profiling is treated as sensitive data processing under the FADP.
| AI / Profiling Area | Swiss FADP | EU GDPR |
|---|---|---|
| Automated decision-making rights | High-risk profiling requires strong legal basis or consent | Article 22 explicit right to opt out of solely automated decisions with significant effects |
| Profiling definition | Two tiers: profiling and high-risk profiling | Single definition in Article 4(4) applies across all profiling |
| Transparency for AI systems | Right to be informed when high-risk profiling occurs | Right to meaningful information about the logic of automated systems |
| AI Act interaction | Switzerland is not an EU member, EU AI Act does not directly apply | EU AI Act applies alongside GDPR dual compliance required |
| Biometric data | Explicitly listed as sensitive special legal basis required | Explicitly listed under Article 9 requires explicit consent or specific exemption |
| Training AI on personal data | Requires lawful basis; purpose limitation and data minimization apply | Same requirements ICO and EDPB have issued specific guidance on this |
One critical point that often gets missed: organizations in the EU must now navigate both GDPR and the EU AI Act simultaneously when deploying AI systems. Switzerland, not being an EU member state, is not directly subject to the EU AI Act, but Swiss organizations that deploy AI systems to EU users may still fall under its scope based on the AI Act’s own territorial provisions.
Data Subject Rights Compared
| Right | Swiss FADP | EU GDPR |
|---|---|---|
| Right of access | Yes, request information on what data is held | Yes, Article 15, broader response requirements |
| Right to rectification | Yes | Yes, Article 16 |
| Right to erasure | Yes. right to have inaccurate or unlawfully processed data deleted | Yes, Article 17, “right to be forgotten,” broader scope |
| Right to data portability | Yes, machine-readable format for automated processing | Yes, Article 20, applies to consent and contract bases |
| Right to object | Yes, can object to processing | Yes, Article 21, includes objection to profiling |
| Right to restrict processing | Limited equivalent | Yes, Article 18, explicit right |
| Right not to be profiled | Yes, for high-risk profiling | Yes, Article 22, for automated decisions with significant effects |
Cross-Border Data Transfers
Switzerland holds an EU adequacy decision, meaning personal data can flow freely from EU member states to Switzerland without additional transfer mechanisms like Standard Contractual Clauses (SCCs). This is a significant operational advantage for Swiss organizations handling EU resident data.
For data leaving Switzerland to third countries, the FADP requires organizations to use approved transfer mechanisms similar to GDPR’s approach. The FDPIC maintains a list of countries recognized as offering adequate protection.
For organizations operating on both sides of the Swiss-EU border, this means one set of data flows (EU to Switzerland) is largely frictionless, while transfers onward from Switzerland to countries like the US or India still require proper mechanisms under both frameworks.
Which Law Applies to Your Organization?
The answer is often both. Any organization that:
- Is based in Switzerland and processes personal data of Swiss residents, FADP applies
- Processes personal data of EU residents, regardless of where it’s based, GDPR applies
- Is based in Switzerland and has EU customers or employees, both FADP and GDPR apply
For security professionals conducting penetration tests, vulnerability assessments, or incident response work in regulated environments, knowing which law governs the data you’re handling and whether that data crosses borders is not optional. Mishandling personal data during a security engagement can create liability under both frameworks simultaneously.
The Swiss FADP and EU GDPR share the same foundations but differ on enforcement mechanics, AI-specific rights, and the key question of who gets penalized. Know the differences, document your data flows, and build privacy into your processes from the start not as an afterthought. Questions about how either law applies to your situation? Drop them in the comments.

