Skip to content
TB
TeamBenchResources

Swiss Data Protection (nDSG): Documentation Review Under the New Federal Act

Switzerland's nDSG closely aligns with GDPR while maintaining Swiss-specific requirements. Here's what documentation you need, key differences from GDPR, and how to review for compliance.

TeamBench· Content Quality PlatformFebruary 9, 202610 min read

Switzerland's new Federal Act on Data Protection (nDSG/nFADP) took effect on 1 September 2023, replacing the 1992 data protection law. The revision was driven by two objectives: aligning Swiss data protection with GDPR to maintain the EU's adequacy decision (critical for cross-border data flows) and modernising protections for Swiss residents in the digital age.

The nDSG shares significant common ground with GDPR but differs in key areas — most notably, criminal sanctions target individuals (not just organisations), there are no administrative fines comparable to GDPR's percentage-of-turnover penalties, and the Federal Data Protection and Information Commissioner (FDPIC) has enhanced investigative but limited sanctioning powers. These differences create a distinct documentation landscape that organisations operating in Switzerland must navigate.

nDSG Core Principles

PrincipleRequirementDocumentation Implication
LawfulnessProcessing must be lawful and in good faithLegal basis documented for each processing activity
Purpose limitationData collected for specific, recognisable purposesPurpose statements in privacy notices and processing records
ProportionalityProcessing limited to what is necessaryJustification for data elements collected
AccuracyData must be accurateData quality procedures
Storage limitationData deleted when no longer necessaryRetention policy with defined periods
SecurityAppropriate technical and organisational measuresSecurity documentation
TransparencyData subjects informed about processingPrivacy notices and disclosures

Required nDSG Documentation

1. Privacy Notice (Informationspflicht)

Required under Articles 19-21 nDSG. Must be provided at the time of collection.

ElementRequirement
Identity of controllerName and contact details
Purpose of processingSpecific purposes for each type of data
RecipientsCategories of recipients, including processors
Cross-border transfersCountries and safeguards (if data is transferred abroad)
Data subject rightsRight to information, correction, deletion, data portability, objection
Automated individual decisionsIf applicable — the logic involved and potential consequences
Source of dataIf not collected from the data subject directly

Key nDSG difference from GDPR: The nDSG does not require disclosure of the legal basis for processing (GDPR Article 13(1)(c)). However, best practice — and alignment with GDPR for organisations operating across both jurisdictions — suggests including it.

2. Records of Processing Activities (Article 12)

Mandatory for controllers and processors. Exemption for enterprises with fewer than 250 employees whose processing does not pose a high risk.

FieldDetail
Controller/processor identityName, contact details, DPO contact (if appointed)
Processing purposesPer processing activity
Data subject categoriesEmployees, customers, suppliers, etc.
Personal data categoriesTypes of data processed
RecipientsCategories of recipients
Retention periodsPer processing activity
Security measuresGeneral description of technical and organisational measures
Cross-border transfersCountries, safeguards, and legal mechanism

3. Data Protection Impact Assessment (DPIA — Article 22)

Required when processing is likely to result in a high risk to the personality or fundamental rights of data subjects.

ElementRequirement
Processing descriptionDetailed description of planned processing
Risk assessmentAssessment of risks to data subjects' rights
MeasuresPlanned measures to address identified risks
FDPIC consultationRequired if risks cannot be sufficiently mitigated (Article 23)

4. Cross-Border Transfer Documentation

The nDSG restricts transfers to countries without adequate data protection:

DocumentPurpose
Adequacy assessmentVerification that the receiving country is on the Federal Council's adequacy list
Appropriate safeguardsWhere no adequacy: standard contractual clauses, binding corporate rules, or other approved mechanisms
Transfer impact assessmentAssessment of the legal framework in the receiving country
Transfer registerRecord of all cross-border transfers with legal basis
Data subject notificationInformation about transfers in the privacy notice

Swiss-specific: The Federal Council maintains its own adequacy list, separate from the EU's. The lists largely overlap but are not identical.

5. Data Breach Notification Documentation

Article 24 nDSG requires notification to the FDPIC for breaches likely to result in a high risk to data subjects:

DocumentPurpose
Breach response planDetection, assessment, containment, notification, review procedures
FDPIC notificationNotification "as soon as possible" (no specific hour deadline like GDPR's 72 hours)
Data subject notificationWhen necessary for their protection, or when the FDPIC requires it
Breach registerRecord of all breaches, including those not notified

6. Data Processing Agreement (Article 9)

Required when engaging processors:

ElementRequirement
Processing scopeWhat processing the processor performs
Security requirementsTechnical and organisational measures
Sub-processor managementPrior approval requirements for sub-processors
Breach notificationProcessor must notify controller of breaches
Data return/deletionRequirements upon termination
Audit rightsController's right to verify compliance

7. DPO Documentation (Optional Under nDSG)

Unlike GDPR, the nDSG does not mandate DPO appointment. However, appointing a data protection adviser under Article 10 provides benefits:

DocumentPurpose
Adviser appointmentFormal appointment with defined responsibilities
Independence documentationAdviser must operate independently and without instructions
Notification to FDPICPublication of adviser's contact details
Exemption from FDPIC consultationOrganisations with an adviser may be exempt from mandatory FDPIC consultation for DPIAs

Key Differences: nDSG vs GDPR

AspectnDSGGDPR
SanctionsCriminal sanctions on individuals (fines up to CHF 250,000)Administrative fines on organisations (up to €20M or 4% turnover)
DPOOptional (data protection adviser)Mandatory in specified circumstances
Breach notification"As soon as possible" to FDPICWithin 72 hours to DPA
Legal basis disclosureNot required in privacy noticeRequired in privacy notice
SME exemptionEnterprises <250 employees exempt from processing records (if low risk)Enterprises <250 employees exempt from processing records (if low risk)
Adequacy listFederal Council list (separate from EU)European Commission list
EnforcementFDPIC investigative powers; criminal prosecution by cantonal authoritiesDPA enforcement with administrative fines
Profiling"High-risk profiling" concept with stricter requirements"Profiling" and "automated decision-making"

Common nDSG Compliance Gaps

Gap 1: Privacy Notices Not Updated for nDSG

Privacy notices drafted under the old FADP that don't include nDSG-required elements: cross-border transfer information, automated decision-making disclosure, and data subject rights under the new law.

Gap 2: No Data Processing Agreements

Engaging processors (cloud providers, SaaS platforms, payroll providers) without written agreements meeting Article 9 requirements. This is particularly common for services contracted before the nDSG took effect.

Gap 3: Cross-Border Transfers Without Assessment

Data transferred to non-adequate countries without implementing appropriate safeguards. Common with US-based cloud services — the Swiss-US Data Privacy Framework must be specifically relied upon and documented.

Gap 4: No Breach Response Plan

Despite Article 24's notification requirements, many organisations have no documented breach response plan. When a breach occurs, the lack of a plan leads to delayed and inadequate response.

Gap 5: Criminal Liability Not Addressed

The nDSG imposes criminal sanctions on individuals — typically the person responsible for the violation within the organisation. Many organisations have not documented responsibilities clearly enough to identify who bears this liability.

Reviewing nDSG Documentation

Privacy Notice Review Criteria

CriterionWeightWhat to Check
Completeness3All Article 19 elements present
Transparency3Written clearly for the intended audience
Cross-border transfers2All transfers disclosed with countries and safeguards
Currency2Reflects current processing activities
Multilingual1Available in relevant languages (German, French, Italian, English)

Cross-Border Transfer Review Criteria

CriterionWeightWhat to Check
Adequacy verification3Receiving country checked against Federal Council list
Safeguards documented3Where no adequacy, appropriate safeguards implemented
Transfer register complete2All transfers documented with legal mechanism
Privacy notice updated1Transfers disclosed in privacy notice

Frequently Asked Questions

Does the nDSG apply to companies outside Switzerland?

Yes — the nDSG applies to processing that has effects in Switzerland, regardless of where the controller or processor is located. Foreign companies processing data of Swiss residents must comply and may need to appoint a Swiss representative.

Who faces criminal liability under the nDSG?

Criminal sanctions apply to the natural person responsible for the violation — typically a manager, DPO, or the person who made the decision leading to the violation. Organisations can be fined up to CHF 50,000 if identifying the responsible individual would require disproportionate effort. This is fundamentally different from GDPR, where fines target the organisation.

Do we need a DPO under the nDSG?

No — the nDSG does not mandate DPO appointment. However, appointing a data protection adviser under Article 10 provides a benefit: exemption from mandatory FDPIC consultation for DPIAs. For organisations that also process EU personal data, a DPO may still be required under GDPR.

How does the Swiss-US Data Privacy Framework work?

The Swiss-US DPF provides an adequacy mechanism for transfers to US organisations that have self-certified under the framework. Organisations relying on the Swiss-US DPF should document: verification that the US recipient is certified, the scope of certification, and ongoing monitoring of certification status.

Can AI review help with nDSG documentation?

AI review can check privacy notices for Article 19 completeness, verify processing records contain all required fields, assess data processing agreements for Article 9 compliance, and check cross-border transfer documentation. Legal adequacy under Swiss law requires qualified Swiss data protection professionals.

Key Takeaways

  • The nDSG took effect 1 September 2023 — all documentation should be updated from the old FADP.
  • Criminal sanctions target individuals, not just organisations — clear documentation of responsibilities is essential.
  • Privacy notices must include cross-border transfer information and automated decision-making disclosure.
  • The Federal Council maintains its own adequacy list — verify against this list, not the EU list.
  • Data processing agreements are required for all processors — including pre-nDSG service relationships.
  • Appointing a data protection adviser is optional but beneficial — provides DPIA consultation exemption.
  • AI review checks completeness, consistency, and currency — legal adequacy requires qualified Swiss professionals.

This article is for informational purposes only. The nDSG and its ordinances are subject to interpretation by the FDPIC and Swiss courts. Consult a qualified Swiss data protection professional or legal adviser for guidance specific to your organisation's processing activities.

ndsg-complianceswiss-data-protectionfadp-switzerlandfdpicswiss-privacyndsg-documentation

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required