Switzerland’s revised Federal Act on Data Protection (FADP) comes into force today, modernising the Swiss regime and bringing it closer to the GDPR.
Key points
- Breaches likely to create a high risk must be reported to the FDPIC as soon as possible.
- Criminal fines of up to CHF 250,000 fall on responsible individuals, not the company.
- Privacy by design and default, DPIAs and records of processing are required.
- The law applies extraterritorially where effects are felt in Switzerland.
UK organisations with Swiss customers or employees should check that their GDPR programmes cover the FADP’s differences, particularly the personal liability of individuals.
Source: Federal Act on Data Protection, SR 235.1 (Fedlex)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.