Key Takeaways
- Determine FADP and GDPR applicability for each activity before requiring a dual-framework workflow.
- Under the FADP, sanctions are criminal fines of up to CHF 250,000 against the responsible individual (Art. 60-63 FADP), not corporate administrative fines like the GDPR.
- The FDPIC (Federal Data Protection and Information Commissioner) supervises but cannot itself levy fines — it investigates, orders, and refers.
- The FADP has a processing-register obligation with exemptions, DPIAs for likely high-risk processing and notification of qualifying high-risk data breaches as soon as possible.
Why Switzerland Is a Dual-Framework Problem
Establish the scope before buying dual-framework coverage. GDPR Article 3 concerns processing in the context of an EU establishment and, in the specified circumstances, offering goods or services to people in the Union or monitoring their behaviour there. Merely holding data about an EU citizen or employing a cross-border worker does not by itself establish Article 3(2). Record the actual activity and the basis for each conclusion. Use the FADP/GDPR breach comparison after the scope is clear.
The sanction model is fundamentally different, and harsher for individuals. The GDPR fines the company — up to EUR 20 million or 4% of global turnover. The revFADP instead imposes criminal fines of up to CHF 250,000 on the natural person responsible for intentional breaches such as failing to inform data subjects, breaching duties of care, or ignoring FDPIC orders (Art. 60-63 FADP). The FADP also contains provisions concerning offences committed in business operations; avoid treating the headline personal maximum as automatic liability for every employee. Individual liability depends on the offence and the person’s conduct; a role title does not automatically establish it.
The FDPIC does not fine — it investigates and refers. The Federal Data Protection and Information Commissioner opens investigations, issues binding orders, and refers criminal matters to cantonal prosecutors. Its enforcement posture since the revFADP came into force has focused on transparency failures and the new register and breach-notification duties. Software that produces audit-ready records is your first line of defence when the FDPIC asks.
Criteria That Matter for a Swiss SME
| Criterion | Why it matters in Switzerland | Minimum bar |
|---|---|---|
| Dual GDPR + revFADP mapping | Two frameworks apply at once | Both frameworks in one register |
| Register of processing | Required under Art. 12 revFADP | Structured, exportable record |
| DPIA module | Required for high-risk processing | Guided DPIA workflow |
| Breach notification | FDPIC “as soon as possible” + GDPR 72h | Deadline tracking for both regimes |
| Cross-border transfers | Switzerland runs its own adequacy list | Transfer mapping + SCC support |
| Multilingual output | DE / FR / IT + English | At least DE/FR documentation |
| EU/CH hosting | Data-residency sensitivity | EU or Swiss data centres |
The transfer row is a genuine Swiss delta: Switzerland maintains its own adequacy decisions and recognition of contractual clauses with relevant Swiss adaptations, and the Swiss-US Data Privacy Framework operates separately from the EU-US one. If you already manage EU transfers, you cannot simply copy the analysis — see our guide to cross-border data transfers.
Run a dual-regime incident demonstration
Use a hypothetical supplier incident involving a Swiss service and an EU-facing activity. Begin with one factual timeline: discovery, affected systems, data categories, people concerned, containment and unanswered questions. Then ask the platform to record two legal assessments without duplicating or contradicting those facts.
The FDPIC guidance explains the likely-high-risk threshold under FADP Article 24. GDPR Article 33 uses a different risk threshold and its own timing rule. The platform should allow a reasoned non-notification decision under one regime while preserving a notification obligation under the other, where the facts justify that result. A single checkbox labelled “reportable breach” can conceal the distinction.
Introduce a change: the supplier later confirms that an encryption key was also exposed. Check who reviews the changed risk assessment, whether the initial submission remains preserved and how supplementary information is prepared. The process should show the decision owner, the version sent and evidence of submission; an automatically generated draft is not a filing receipt.
For a multi-entity group, identify which entity is the controller for each affected processing operation. Do not assume that the headquarters address determines every notification responsibility. The trial should identify the people who can obtain supplier facts and the person authorised to submit a report.
Use the general software comparison for the shortlist and the German procurement guide for shared DACH procurement questions. Keep Swiss legal conclusions separately traceable.
Obtain a quote with explicit Swiss scope
Specify whether the offer includes Swiss legal templates, language variants, transfer mapping, incident workflows and local assistance. Require the supplier to distinguish existing functions from planned work. Record which parts need your own adviser to configure and review.
Compare subscription, setup, data migration, support and termination assistance separately. Agree the quote currency and renewal basis. A Swiss hosting location may be a contractual requirement for a particular customer, but does not by itself establish that every support access and onward transfer is covered.
Use the cost worksheet to compare the same scope across bids. This guide supplies no verified universal Swiss price range; the demonstration and written proposal should determine the comparison.
Implementation Priorities for a Swiss SME
Sequence the work around the two frameworks rather than treating one as an afterthought. First, build a single register whose entries carry both revFADP and GDPR flags, so you never maintain two lists that drift apart. Second, map transfers explicitly against the Swiss adequacy list and the EU SCCs with the Swiss adaptations required for the case; verify the adaptations and the regime applicable to the transfer. This is the delta most generic configurations miss, and it is where a Swiss subsidiary of an EU group most often carries a hidden gap. Third, define breach handling for both clocks at once: the FADP and GDPR have different notification thresholds as well as timing rules; assess each separately and record both conclusions. Fourth, brief the named individuals — DPO, IT lead, managing director — on the duties relevant to their actual functions and on the escalation process for unresolved issues. Set the rollout schedule from the actual records, transfer assessments and reviews needed.
Recommendations by Situation
- Swiss SaaS or fintech selling into the EU: a dual-framework EU platform, register first, transfer mapping second — you carry both regimes.
- Domestic Swiss SME, no EU exposure: check the FADP register exemptions, likely-high-risk DPIA criteria and breach process; a lighter tool suffices, but do not skip documentation.
- Swiss subsidiary of an EU group on OneTrust: keep the group instance but add the revFADP layer — generic GDPR configs miss the Swiss transfer list and the criminal-liability framing your management needs to understand.
FAQ
Does a Swiss company need GDPR software or FADP software?
Assess both legal frameworks and document which apply. The revFADP governs processing in Switzerland; GDPR applicability depends on the actual Article 3 criteria. The efficient answer is a single platform whose register and workflows satisfy both frameworks, so you maintain one set of records rather than two.
What are the penalties under the Swiss revFADP?
Criminal fines of up to CHF 250,000 against the responsible individual for intentional breaches (Art. 60-63 FADP) — for example failing to provide required information, breaching duties of care, or ignoring an FDPIC order. Unlike the GDPR, there is no corporate administrative fine, so the exposure falls on named people. The sanction is criminal and personal, pursued by cantonal authorities on referral, and it attaches to the individual who committed the breach rather than to the company — which is precisely why Swiss management treats defensible compliance documentation as personal risk mitigation, not corporate overhead.
Can the FDPIC issue fines like EU authorities?
No. The FDPIC investigates, issues binding orders and refers criminal cases to cantonal prosecutors, who pursue the fine against the individual. This is a structural difference from the GDPR’s administrative-fine model and it changes how Swiss management treats compliance evidence.
Is the Swiss revFADP the same as the GDPR?
No, though they are aligned. Both require a processing register, DPIAs and breach notification, but the FADP has its own transfer-adequacy list, recognised contractual clauses and Swiss adaptations, a different breach-notification standard, and criminal rather than administrative sanctions. Text of both: the revFADP on Fedlex and the GDPR on EUR-Lex.
Keep the transfer and exemption assessments usable
The FDPIC explains its processing-register exemptions, including the relevant circumstances for smaller private organisations. Evaluate the actual processing, including large-scale sensitive data and high-risk profiling, rather than treating an employee-count field as a complete decision. Any exemption from the register does not remove the other applicable duties.
For transfers, record the source regime, receiving entity, destination and mechanism relied on. The FDPIC recognises standard clauses, including EU clauses with the relevant adaptations; there is not a wholly separate universal Swiss contract to substitute automatically. Keep the executed version and the assessment connected to the actual transfer.
In an invented trial, change the provider’s support location while leaving the main hosting region unchanged. Ask the owner to find the affected transfer records and review the basis for continued access. This checks a practical dependency that a simple “Swiss hosting” filter misses.
At handover, export a complete activity with its scope decision, transfer assessment, incident contacts and pending actions. Have someone outside the implementation team explain it from the export alone. Record any missing context before approving the configuration. The FADP and GDPR remain the legal sources; the accepted software is a means of documenting and executing the agreed process.