Skip to content
Legiscope
Menu
Data Privacy

GDPR Compliance Software Switzerland (+ revFADP)

Assess GDPR and Swiss FADP software requirements: applicability, register exemptions, breach thresholds, transfer safeguards and a practical procurement trial.

Key Takeaways

  • Determine FADP and GDPR applicability for each activity before requiring a dual-framework workflow.
  • Under the FADP, sanctions are criminal fines of up to CHF 250,000 against the responsible individual (Art. 60-63 FADP), not corporate administrative fines like the GDPR.
  • The FDPIC (Federal Data Protection and Information Commissioner) supervises but cannot itself levy fines — it investigates, orders, and refers.
  • The FADP has a processing-register obligation with exemptions, DPIAs for likely high-risk processing and notification of qualifying high-risk data breaches as soon as possible.

Why Switzerland Is a Dual-Framework Problem

Establish the scope before buying dual-framework coverage. GDPR Article 3 concerns processing in the context of an EU establishment and, in the specified circumstances, offering goods or services to people in the Union or monitoring their behaviour there. Merely holding data about an EU citizen or employing a cross-border worker does not by itself establish Article 3(2). Record the actual activity and the basis for each conclusion. Use the FADP/GDPR breach comparison after the scope is clear.

The sanction model is fundamentally different, and harsher for individuals. The GDPR fines the company — up to EUR 20 million or 4% of global turnover. The revFADP instead imposes criminal fines of up to CHF 250,000 on the natural person responsible for intentional breaches such as failing to inform data subjects, breaching duties of care, or ignoring FDPIC orders (Art. 60-63 FADP). The FADP also contains provisions concerning offences committed in business operations; avoid treating the headline personal maximum as automatic liability for every employee. Individual liability depends on the offence and the person’s conduct; a role title does not automatically establish it.

The FDPIC does not fine — it investigates and refers. The Federal Data Protection and Information Commissioner opens investigations, issues binding orders, and refers criminal matters to cantonal prosecutors. Its enforcement posture since the revFADP came into force has focused on transparency failures and the new register and breach-notification duties. Software that produces audit-ready records is your first line of defence when the FDPIC asks.

Criteria That Matter for a Swiss SME

Criterion Why it matters in Switzerland Minimum bar
Dual GDPR + revFADP mapping Two frameworks apply at once Both frameworks in one register
Register of processing Required under Art. 12 revFADP Structured, exportable record
DPIA module Required for high-risk processing Guided DPIA workflow
Breach notification FDPIC “as soon as possible” + GDPR 72h Deadline tracking for both regimes
Cross-border transfers Switzerland runs its own adequacy list Transfer mapping + SCC support
Multilingual output DE / FR / IT + English At least DE/FR documentation
EU/CH hosting Data-residency sensitivity EU or Swiss data centres

The transfer row is a genuine Swiss delta: Switzerland maintains its own adequacy decisions and recognition of contractual clauses with relevant Swiss adaptations, and the Swiss-US Data Privacy Framework operates separately from the EU-US one. If you already manage EU transfers, you cannot simply copy the analysis — see our guide to cross-border data transfers.

Run a dual-regime incident demonstration

Use a hypothetical supplier incident involving a Swiss service and an EU-facing activity. Begin with one factual timeline: discovery, affected systems, data categories, people concerned, containment and unanswered questions. Then ask the platform to record two legal assessments without duplicating or contradicting those facts.

The FDPIC guidance explains the likely-high-risk threshold under FADP Article 24. GDPR Article 33 uses a different risk threshold and its own timing rule. The platform should allow a reasoned non-notification decision under one regime while preserving a notification obligation under the other, where the facts justify that result. A single checkbox labelled “reportable breach” can conceal the distinction.

Introduce a change: the supplier later confirms that an encryption key was also exposed. Check who reviews the changed risk assessment, whether the initial submission remains preserved and how supplementary information is prepared. The process should show the decision owner, the version sent and evidence of submission; an automatically generated draft is not a filing receipt.

For a multi-entity group, identify which entity is the controller for each affected processing operation. Do not assume that the headquarters address determines every notification responsibility. The trial should identify the people who can obtain supplier facts and the person authorised to submit a report.

Use the general software comparison for the shortlist and the German procurement guide for shared DACH procurement questions. Keep Swiss legal conclusions separately traceable.

Obtain a quote with explicit Swiss scope

Specify whether the offer includes Swiss legal templates, language variants, transfer mapping, incident workflows and local assistance. Require the supplier to distinguish existing functions from planned work. Record which parts need your own adviser to configure and review.

Compare subscription, setup, data migration, support and termination assistance separately. Agree the quote currency and renewal basis. A Swiss hosting location may be a contractual requirement for a particular customer, but does not by itself establish that every support access and onward transfer is covered.

Use the cost worksheet to compare the same scope across bids. This guide supplies no verified universal Swiss price range; the demonstration and written proposal should determine the comparison.

Implementation Priorities for a Swiss SME

Sequence the work around the two frameworks rather than treating one as an afterthought. First, build a single register whose entries carry both revFADP and GDPR flags, so you never maintain two lists that drift apart. Second, map transfers explicitly against the Swiss adequacy list and the EU SCCs with the Swiss adaptations required for the case; verify the adaptations and the regime applicable to the transfer. This is the delta most generic configurations miss, and it is where a Swiss subsidiary of an EU group most often carries a hidden gap. Third, define breach handling for both clocks at once: the FADP and GDPR have different notification thresholds as well as timing rules; assess each separately and record both conclusions. Fourth, brief the named individuals — DPO, IT lead, managing director — on the duties relevant to their actual functions and on the escalation process for unresolved issues. Set the rollout schedule from the actual records, transfer assessments and reviews needed.

Recommendations by Situation

  • Swiss SaaS or fintech selling into the EU: a dual-framework EU platform, register first, transfer mapping second — you carry both regimes.
  • Domestic Swiss SME, no EU exposure: check the FADP register exemptions, likely-high-risk DPIA criteria and breach process; a lighter tool suffices, but do not skip documentation.
  • Swiss subsidiary of an EU group on OneTrust: keep the group instance but add the revFADP layer — generic GDPR configs miss the Swiss transfer list and the criminal-liability framing your management needs to understand.

FAQ

Does a Swiss company need GDPR software or FADP software?

Assess both legal frameworks and document which apply. The revFADP governs processing in Switzerland; GDPR applicability depends on the actual Article 3 criteria. The efficient answer is a single platform whose register and workflows satisfy both frameworks, so you maintain one set of records rather than two.

What are the penalties under the Swiss revFADP?

Criminal fines of up to CHF 250,000 against the responsible individual for intentional breaches (Art. 60-63 FADP) — for example failing to provide required information, breaching duties of care, or ignoring an FDPIC order. Unlike the GDPR, there is no corporate administrative fine, so the exposure falls on named people. The sanction is criminal and personal, pursued by cantonal authorities on referral, and it attaches to the individual who committed the breach rather than to the company — which is precisely why Swiss management treats defensible compliance documentation as personal risk mitigation, not corporate overhead.

Can the FDPIC issue fines like EU authorities?

No. The FDPIC investigates, issues binding orders and refers criminal cases to cantonal prosecutors, who pursue the fine against the individual. This is a structural difference from the GDPR’s administrative-fine model and it changes how Swiss management treats compliance evidence.

Is the Swiss revFADP the same as the GDPR?

No, though they are aligned. Both require a processing register, DPIAs and breach notification, but the FADP has its own transfer-adequacy list, recognised contractual clauses and Swiss adaptations, a different breach-notification standard, and criminal rather than administrative sanctions. Text of both: the revFADP on Fedlex and the GDPR on EUR-Lex.

Keep the transfer and exemption assessments usable

The FDPIC explains its processing-register exemptions, including the relevant circumstances for smaller private organisations. Evaluate the actual processing, including large-scale sensitive data and high-risk profiling, rather than treating an employee-count field as a complete decision. Any exemption from the register does not remove the other applicable duties.

For transfers, record the source regime, receiving entity, destination and mechanism relied on. The FDPIC recognises standard clauses, including EU clauses with the relevant adaptations; there is not a wholly separate universal Swiss contract to substitute automatically. Keep the executed version and the assessment connected to the actual transfer.

In an invented trial, change the provider’s support location while leaving the main hosting region unchanged. Ask the owner to find the affected transfer records and review the basis for continued access. This checks a practical dependency that a simple “Swiss hosting” filter misses.

At handover, export a complete activity with its scope decision, transfer assessment, incident contacts and pending actions. Have someone outside the implementation team explain it from the export alone. Record any missing context before approving the configuration. The FADP and GDPR remain the legal sources; the accepted software is a means of documenting and executing the agreed process.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

FADP vs GDPR: Breach Notification, Sanctions, Authorities

In one sentence. The revised Swiss FADP (nFADP) in force since 1 September 2023 and the GDPR in force since 25 May 2018 share most concepts but diverge on three operational points: (1) breach…

June 3, 2026
02Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
03Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

International transfers require the appropriate Chapter V route. Adequacy decisions, including the EU–US Data Privacy Framework for covered recipients, fall under Article 45. Standard Contractual…

April 30, 2026
04Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — a useful reminder to examine whether the organisation supports the DPO’s actual tasks and…

July 7, 2026
05Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
06Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
07Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

For a regulated-industry DPO, that distinction is the whole decision. Consent is one lawful basis under Art. 6(1)(a) GDPR; a compliance program is everything around it.

July 9, 2026
08Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026