Ottobre 30, 2024

Overview of the Swiss Federal Data Protection Act (nFADP)

The newly updated Swiss Federal Data Protection Act (nFADP), effective as of September 1, 2023, marks a major shift in data protection for Switzerland, aligning it more closely with the European Union’s General Data Protection Regulation (GDPR). The revised nFADP focuses on bolstering individual privacy rights, ensuring transparency in data processing, and clarifying the responsibilities of businesses operating within and outside Switzerland that handle Swiss citizens’ data

 

.

Key Features of the nFADP

  1. Risk-Based Regulation and Profiling Restrictions: The nFADP introduces stricter measures for high-risk data processing activities, especially those involving profiling or sensitive personal data, such as genetic and biometric information. Explicit consent is now mandatory for handling such data types

     

     

  2. Privacy by Design and by Default: This principle requires businesses to integrate privacy protections directly into their data processing systems, ensuring that products and services prioritize user privacy from the onset. This standard applies to both the software architecture and operational processes of organizations

     

  3. Appointment of a Swiss Representative: Foreign companies targeting Swiss residents or monitoring their behavior must appoint a Swiss-based representative. This representative serves as a liaison between the company, data subjects, and the Swiss Federal Data Protection and Information Commissioner (FDPIC)

     

  4. Obligation to Report Data Breaches: In cases of significant data breaches, businesses must notify both the FDPIC and affected individuals promptly. Although no exact timeframe is specified, this aligns with GDPR’s 72-hour breach notification rule

    Privacy Desk

     

  5. Fines and Sanctions for Non-Compliance: While the nFADP focuses on penalizing individuals directly responsible for data violations, businesses can still face penalties of up to CHF 250,000 for failing to adhere to key data protection regulations, especially if negligent in protecting personal information

     

Differences Between nFADP and GDPR

The nFADP mirrors much of GDPR’s framework but has unique aspects. For example, Switzerland’s law applies based on the “effects doctrine,” meaning it covers activities with an impact in Switzerland regardless of where the business operates. Additionally, while the GDPR imposes administrative fines on companies, the nFADP’s sanctions are more focused on individuals responsible for compliance lapses within a company

PwC

Implications for Businesses

The nFADP brings Switzerland’s data protection laws up to par with international standards, promoting consumer trust and allowing smoother data exchanges with the EU. Businesses operating in Switzerland, or those that target Swiss customers, need to review their data practices to ensure compliance with the updated legal requirements. Implementing privacy by design, assessing data risks, and maintaining clear communication with Swiss authorities will be crucial for navigating this regulatory landscape.

For further information on data compliance under the new nFADP and to explore how these changes could impact your organization, visit this official resource.