Swiss Data Protection (nDSG): Documentation Review Under the New Federal Act
Switzerland's nDSG closely aligns with GDPR while maintaining Swiss-specific requirements. Here's what documentation you need, key differences from GDPR, and how to review for compliance.
Switzerland's new Federal Act on Data Protection (nDSG/nFADP) took effect on 1 September 2023, replacing the 1992 data protection law. The revision was driven by two objectives: aligning Swiss data protection with GDPR to maintain the EU's adequacy decision (critical for cross-border data flows) and modernising protections for Swiss residents in the digital age.
The nDSG shares significant common ground with GDPR but differs in key areas — most notably, criminal sanctions target individuals (not just organisations), there are no administrative fines comparable to GDPR's percentage-of-turnover penalties, and the Federal Data Protection and Information Commissioner (FDPIC) has enhanced investigative but limited sanctioning powers. These differences create a distinct documentation landscape that organisations operating in Switzerland must navigate.
nDSG Core Principles
| Principle | Requirement | Documentation Implication |
|---|---|---|
| Lawfulness | Processing must be lawful and in good faith | Legal basis documented for each processing activity |
| Purpose limitation | Data collected for specific, recognisable purposes | Purpose statements in privacy notices and processing records |
| Proportionality | Processing limited to what is necessary | Justification for data elements collected |
| Accuracy | Data must be accurate | Data quality procedures |
| Storage limitation | Data deleted when no longer necessary | Retention policy with defined periods |
| Security | Appropriate technical and organisational measures | Security documentation |
| Transparency | Data subjects informed about processing | Privacy notices and disclosures |
Required nDSG Documentation
1. Privacy Notice (Informationspflicht)
Required under Articles 19-21 nDSG. Must be provided at the time of collection.
| Element | Requirement |
|---|---|
| Identity of controller | Name and contact details |
| Purpose of processing | Specific purposes for each type of data |
| Recipients | Categories of recipients, including processors |
| Cross-border transfers | Countries and safeguards (if data is transferred abroad) |
| Data subject rights | Right to information, correction, deletion, data portability, objection |
| Automated individual decisions | If applicable — the logic involved and potential consequences |
| Source of data | If not collected from the data subject directly |
Key nDSG difference from GDPR: The nDSG does not require disclosure of the legal basis for processing (GDPR Article 13(1)(c)). However, best practice — and alignment with GDPR for organisations operating across both jurisdictions — suggests including it.
2. Records of Processing Activities (Article 12)
Mandatory for controllers and processors. Exemption for enterprises with fewer than 250 employees whose processing does not pose a high risk.
| Field | Detail |
|---|---|
| Controller/processor identity | Name, contact details, DPO contact (if appointed) |
| Processing purposes | Per processing activity |
| Data subject categories | Employees, customers, suppliers, etc. |
| Personal data categories | Types of data processed |
| Recipients | Categories of recipients |
| Retention periods | Per processing activity |
| Security measures | General description of technical and organisational measures |
| Cross-border transfers | Countries, safeguards, and legal mechanism |
3. Data Protection Impact Assessment (DPIA — Article 22)
Required when processing is likely to result in a high risk to the personality or fundamental rights of data subjects.
| Element | Requirement |
|---|---|
| Processing description | Detailed description of planned processing |
| Risk assessment | Assessment of risks to data subjects' rights |
| Measures | Planned measures to address identified risks |
| FDPIC consultation | Required if risks cannot be sufficiently mitigated (Article 23) |
4. Cross-Border Transfer Documentation
The nDSG restricts transfers to countries without adequate data protection:
| Document | Purpose |
|---|---|
| Adequacy assessment | Verification that the receiving country is on the Federal Council's adequacy list |
| Appropriate safeguards | Where no adequacy: standard contractual clauses, binding corporate rules, or other approved mechanisms |
| Transfer impact assessment | Assessment of the legal framework in the receiving country |
| Transfer register | Record of all cross-border transfers with legal basis |
| Data subject notification | Information about transfers in the privacy notice |
Swiss-specific: The Federal Council maintains its own adequacy list, separate from the EU's. The lists largely overlap but are not identical.
5. Data Breach Notification Documentation
Article 24 nDSG requires notification to the FDPIC for breaches likely to result in a high risk to data subjects:
| Document | Purpose |
|---|---|
| Breach response plan | Detection, assessment, containment, notification, review procedures |
| FDPIC notification | Notification "as soon as possible" (no specific hour deadline like GDPR's 72 hours) |
| Data subject notification | When necessary for their protection, or when the FDPIC requires it |
| Breach register | Record of all breaches, including those not notified |
6. Data Processing Agreement (Article 9)
Required when engaging processors:
| Element | Requirement |
|---|---|
| Processing scope | What processing the processor performs |
| Security requirements | Technical and organisational measures |
| Sub-processor management | Prior approval requirements for sub-processors |
| Breach notification | Processor must notify controller of breaches |
| Data return/deletion | Requirements upon termination |
| Audit rights | Controller's right to verify compliance |
7. DPO Documentation (Optional Under nDSG)
Unlike GDPR, the nDSG does not mandate DPO appointment. However, appointing a data protection adviser under Article 10 provides benefits:
| Document | Purpose |
|---|---|
| Adviser appointment | Formal appointment with defined responsibilities |
| Independence documentation | Adviser must operate independently and without instructions |
| Notification to FDPIC | Publication of adviser's contact details |
| Exemption from FDPIC consultation | Organisations with an adviser may be exempt from mandatory FDPIC consultation for DPIAs |
Key Differences: nDSG vs GDPR
| Aspect | nDSG | GDPR |
|---|---|---|
| Sanctions | Criminal sanctions on individuals (fines up to CHF 250,000) | Administrative fines on organisations (up to €20M or 4% turnover) |
| DPO | Optional (data protection adviser) | Mandatory in specified circumstances |
| Breach notification | "As soon as possible" to FDPIC | Within 72 hours to DPA |
| Legal basis disclosure | Not required in privacy notice | Required in privacy notice |
| SME exemption | Enterprises <250 employees exempt from processing records (if low risk) | Enterprises <250 employees exempt from processing records (if low risk) |
| Adequacy list | Federal Council list (separate from EU) | European Commission list |
| Enforcement | FDPIC investigative powers; criminal prosecution by cantonal authorities | DPA enforcement with administrative fines |
| Profiling | "High-risk profiling" concept with stricter requirements | "Profiling" and "automated decision-making" |
Common nDSG Compliance Gaps
Gap 1: Privacy Notices Not Updated for nDSG
Privacy notices drafted under the old FADP that don't include nDSG-required elements: cross-border transfer information, automated decision-making disclosure, and data subject rights under the new law.
Gap 2: No Data Processing Agreements
Engaging processors (cloud providers, SaaS platforms, payroll providers) without written agreements meeting Article 9 requirements. This is particularly common for services contracted before the nDSG took effect.
Gap 3: Cross-Border Transfers Without Assessment
Data transferred to non-adequate countries without implementing appropriate safeguards. Common with US-based cloud services — the Swiss-US Data Privacy Framework must be specifically relied upon and documented.
Gap 4: No Breach Response Plan
Despite Article 24's notification requirements, many organisations have no documented breach response plan. When a breach occurs, the lack of a plan leads to delayed and inadequate response.
Gap 5: Criminal Liability Not Addressed
The nDSG imposes criminal sanctions on individuals — typically the person responsible for the violation within the organisation. Many organisations have not documented responsibilities clearly enough to identify who bears this liability.
Reviewing nDSG Documentation
Privacy Notice Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Completeness | 3 | All Article 19 elements present |
| Transparency | 3 | Written clearly for the intended audience |
| Cross-border transfers | 2 | All transfers disclosed with countries and safeguards |
| Currency | 2 | Reflects current processing activities |
| Multilingual | 1 | Available in relevant languages (German, French, Italian, English) |
Cross-Border Transfer Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Adequacy verification | 3 | Receiving country checked against Federal Council list |
| Safeguards documented | 3 | Where no adequacy, appropriate safeguards implemented |
| Transfer register complete | 2 | All transfers documented with legal mechanism |
| Privacy notice updated | 1 | Transfers disclosed in privacy notice |
Frequently Asked Questions
Does the nDSG apply to companies outside Switzerland?
Yes — the nDSG applies to processing that has effects in Switzerland, regardless of where the controller or processor is located. Foreign companies processing data of Swiss residents must comply and may need to appoint a Swiss representative.
Who faces criminal liability under the nDSG?
Criminal sanctions apply to the natural person responsible for the violation — typically a manager, DPO, or the person who made the decision leading to the violation. Organisations can be fined up to CHF 50,000 if identifying the responsible individual would require disproportionate effort. This is fundamentally different from GDPR, where fines target the organisation.
Do we need a DPO under the nDSG?
No — the nDSG does not mandate DPO appointment. However, appointing a data protection adviser under Article 10 provides a benefit: exemption from mandatory FDPIC consultation for DPIAs. For organisations that also process EU personal data, a DPO may still be required under GDPR.
How does the Swiss-US Data Privacy Framework work?
The Swiss-US DPF provides an adequacy mechanism for transfers to US organisations that have self-certified under the framework. Organisations relying on the Swiss-US DPF should document: verification that the US recipient is certified, the scope of certification, and ongoing monitoring of certification status.
Can AI review help with nDSG documentation?
AI review can check privacy notices for Article 19 completeness, verify processing records contain all required fields, assess data processing agreements for Article 9 compliance, and check cross-border transfer documentation. Legal adequacy under Swiss law requires qualified Swiss data protection professionals.
Key Takeaways
- The nDSG took effect 1 September 2023 — all documentation should be updated from the old FADP.
- Criminal sanctions target individuals, not just organisations — clear documentation of responsibilities is essential.
- Privacy notices must include cross-border transfer information and automated decision-making disclosure.
- The Federal Council maintains its own adequacy list — verify against this list, not the EU list.
- Data processing agreements are required for all processors — including pre-nDSG service relationships.
- Appointing a data protection adviser is optional but beneficial — provides DPIA consultation exemption.
- AI review checks completeness, consistency, and currency — legal adequacy requires qualified Swiss professionals.
This article is for informational purposes only. The nDSG and its ordinances are subject to interpretation by the FDPIC and Swiss courts. Consult a qualified Swiss data protection professional or legal adviser for guidance specific to your organisation's processing activities.