The revised Federal Act on Data Protection has been in force since September 2023, and most Swiss companies we assess are still partially compliant in the same three places. Not because the law is unclear, but because compliance was treated as a document exercise rather than an inventory exercise.
This is the checklist we work from. It is not legal advice — for that you need Swiss counsel — but it is an accurate picture of what an assessment actually looks for.
What actually changed
Four changes carry practical weight for a mid-market Swiss company.
| Change | What it means in practice |
|---|---|
| Scope narrowed to natural persons | Legal-entity data is out of scope. Many companies over-scoped their inventory and drowned in it. |
| Privacy by design and by default | A design obligation, not a documentation one. Auditors ask to see it in architecture decisions. |
| Register of processing activities | Mandatory above 250 employees, and in practice expected below that where sensitive data is processed. |
| Criminal liability on individuals | Penalties up to CHF 250,000 attach to responsible individuals, not only the company. |
That last row changes behaviour more than any other. It is the reason data protection moved from a legal topic to a board topic in Switzerland.
Does the revised FADP require data to stay in Switzerland?
No. There is no data-residency requirement in the revised FADP. Cross-border transfers are permitted where the destination country provides adequate protection — the Federal Council maintains the list — or where appropriate safeguards such as standard contractual clauses are in place.
Residency is frequently adopted anyway, as internal policy or in response to supervisory expectations. That is a legitimate business decision. It is not a legal obligation, and it should be argued on its merits rather than asserted as law. We covered the practical version of this argument in cloud migration in Swiss banking after the revised FADP.
What does a data protection impact assessment require?
A DPIA is required where processing carries a high risk to personality or fundamental rights — typically large-scale processing of sensitive data, systematic monitoring, or automated decisions with legal effect.
A sufficient DPIA describes the processing, the necessity and proportionality of it, the risks to the individuals concerned, and the measures that reduce those risks. If the residual risk remains high after mitigation, the Federal Data Protection and Information Commissioner must be consulted.
The common failure is not an absent DPIA. It is a DPIA written after the system was built, which by definition cannot have influenced the design it is supposed to assess.
The three findings that come up every time
1. The inventory does not match reality. The register lists the systems someone remembered. The actual estate includes a marketing tool bought on a credit card, a shared drive with fifteen years of files, and an analytics pipeline nobody mapped. Start from network and expense data, not from interviews.
2. Access is granted and never revoked. Support vendors with standing production access, leavers whose accounts persist, and service accounts nobody owns. This is the finding most likely to stop a cloud programme, and it is an operations problem rather than a legal one.
3. Retention is theoretical. A policy says 90 days. The database has records from
- A retention policy that is not enforced by a job is a statement of intent, and
an assessor will read it as one.
A sequence that works
- Inventory before policy. Two to six weeks depending on estate size. Almost every downstream decision changes once you can see what you actually hold.
- Fix the access model. Least privilege, reviewed quarterly, revocation tied to the leaver process. This has security value far beyond compliance.
- Make retention executable. A scheduled deletion job beats a policy document. Ours runs on a 90-day window and is called by a cron trigger, not by a person.
- Write the register from the inventory, not from memory.
- Then write the policies, which are now descriptions of what happens rather than aspirations.
Companies that do this in the reverse order — policies first — produce a compliant binder and a non-compliant estate.
How long does it take and what does it cost?
For a Swiss company of 200 to 1,000 employees with a typical SaaS-heavy estate, expect two to four months of elapsed time with a part-time internal owner, and expect the inventory phase to surface at least one access finding that must be remediated before anything else proceeds.
The cost is dominated by the remediation, not by the assessment. Any firm quoting a fixed all-in price before seeing the inventory is pricing a document.
What this has to do with AI
Automated individual decisions with legal or significant effect trigger an information obligation and a right to human review. If you are deploying models that score people — credit, hiring, fraud, churn interventions with material consequence — that is in scope, and "the model decided" is not a defence.
This is worth designing for now rather than retrofitting. Our AI and machine learning practice treats the human-review path as part of the architecture, and our cybersecurity practice treats the access model as the first deliverable rather than the last.
Related reading
- Cloud migration in Swiss banking after the revised FADP
- How to choose a management consulting firm in Zurich
- Cybersecurity consulting
Working on this right now?
Tell us where you are in two questions. A consulting partner reviews every enquiry within 2 business days.