The new Federal Act on Data Protection (FADP) went into effect on 1 September 2023 and the biggest difference between FADP and GDPR is that private data controllers can be fined up to 250,000 CHF – while in the EU, only companies are held liable.
But first, let’s get some basics straight.
Yes, Swiss companies need to comply with the GDPR if they:
In this case, they should take the necessary measures to ensure compliance with the EU regulation.
In Switzerland, the privacy and the fundamental rights of persons with regards to data processing are governed by the Federal Act on Data Protection (FADP) – which as of 1 September 2023 got its first revision since being enacted in 1992.
With the revision of the FADP, the Swiss government responds to the fundamental changes the technological and social landscape has undergone since 1992. The aim is to grant data subjects stronger self-determination in relation to their data.
Plus, by aligning the new FADP to the EU’s GDPR, Switzerland can be recognized as a third country with an adequate level of data protection. The benefit: Free data transfer between Switzerland and the EU is possible also in the future, helping Swiss companies to remain competitive.
«Organizations doing business in both Switzerland and the EU should be aware of this: Despite the alignment of the new FADP with the GDPR, certain differences remain. Most notably the provisions on sanctions.» Yasin Kücükkaya |
|
The GDPR and the FADP have many similarities, such as strict sanctions for violations, breach notification requirements, and a focus on data privacy and protection. However, the provisions may differ in detail. Here come the 7 key differences:
Topic |
New FADP |
GDPR |
Sanctions |
Up to CHF 250,000 against responsible private persons |
Up to EUR 20 million or 4% of the company’s worldwide annual revenue |
Designation of a Data Protection Officer |
Not mandatory but recommended |
Mandatory according to art. 37 GDPR. |
Data breach notifications |
Mandatory reporting as soon as possible |
Mandatory reporting within 72 hours |
Data exports |
Adequacy is determined by the Swiss Federal Council. |
Adequacy is determined by the European Commission. |
Data Protection Impact Assessment |
Consultation of a Data Protection Officer instead of the FDPIC is possible in case of high risk despite measures taken. |
Duty to consult the supervisory authority in case of high risk despite measures taken. |
Profiling |
General obligation to obtain consent is only imposed for high-risk profiling. |
General obligation to obtain consent |
Sensitive data |
Includes the two additional categories «data on administrative or criminal proceedings and sanctions» and «data on social security measures». |
According to art. 9 GDPR. |
|
|
|
Sanctions
Designation of a Data Protection Officer (DPO)
Data breach notifications
Data exports
New FADP: Adequacy of data exports is determined by the Swiss Federal Council. EU standard contractual clauses and binding corporate rules can be applied.
GDPR: Adequacy of data exports is determined by the European Commission. Standard contractual clauses and binding corporate rules apply.
Data Protection Impact Assessment
New FADP: If there is a high risk to the privacy of fundamental rights of data subjects, a Data Protection Impact Assessment (DPIA) must be performed. If the risk continues to exist despite the measures taken, a DPA instead of the FDPIC can be consulted.
GDPR: If the risk continues to exist despite the measures, the supervisory authority must be consulted.
Profiling
Sensitive data
To summarize: The new FADP is aligned to the GDPR as much as possible, making sure Swiss companies keep their competitive edge.
Yet, certain differences remain. The good news is: you are now aware of them.