nDSG Privacy Compliance: How to Review Content for Switzerland's New Data Protection Act
Switzerland's revised nDSG took effect September 2023 with GDPR-level standards. Learn how to review privacy content, consent forms, and data communications.
Switzerland's revised Federal Act on Data Protection (nDSG, new Datenschutzgesetz) came into force on September 1, 2023, replacing the original 1992 data protection law with a modernized framework that closely aligns with the EU's General Data Protection Regulation while maintaining distinctly Swiss characteristics. The Federal Data Protection and Information Commissioner (FDPIC) enforces the nDSG with enhanced powers — including the authority to impose criminal penalties of up to CHF 250,000 on individuals responsible for violations.
For organizations operating in Switzerland, the nDSG's content implications are significant: privacy notices must be updated, consent mechanisms must be revised, cross-border transfer disclosures must be enhanced, and data breach notifications must follow new requirements. Every piece of content that addresses personal data processing must now meet the nDSG's standards.
Key nDSG Provisions Affecting Content
What Changed From the Old Law
| Area | Old DSG | New nDSG |
|---|---|---|
| Scope | Data processing by Swiss entities | Applies to processing that has effects in Switzerland (extraterritorial) |
| Information duty | Limited transparency requirements | Comprehensive duty to inform for all data collection |
| Cross-border transfers | Basic requirements | Enhanced consent or adequate protection requirements |
| Breach notification | No mandatory notification | Mandatory notification to FDPIC for high-risk breaches |
| Profiling | Not specifically addressed | Specific provisions for profiling and automated decisions |
| Penalties | Civil remedies | Criminal penalties up to CHF 250,000 for responsible individuals |
| Data Protection Impact Assessment | Not required | Required for high-risk processing |
Content-Specific Obligations
The nDSG establishes several content obligations:
Article 19 — Duty to inform: When collecting personal data, the controller must inform the data subject of:
- The identity and contact details of the controller
- The purpose of processing
- Recipients or categories of recipients
- If data is transferred abroad: the country and the safeguards in place
- If the data is not collected directly from the individual: the categories of data and source
Article 21 — Automated individual decisions: When making decisions based solely on automated processing (including profiling) that produce legal effects or significantly affect the individual, the individual must be informed and given the right to be heard.
Article 24 — Breach notification: Breach notifications to the FDPIC must include specific content: nature of the breach, consequences, measures taken. If the breach poses a high risk to individuals, they must also be notified.
Common Privacy Content Compliance Issues
1. Privacy Notice Gaps
Many organizations that updated their privacy notices for GDPR compliance assumed these would suffice for the nDSG. Key gaps include:
- Missing controller identification specific to the Swiss entity (not just the EU parent)
- Cross-border transfer disclosures that reference GDPR adequacy decisions without addressing Swiss-specific adequacy (Switzerland maintains its own adequacy list)
- Failure to address nDSG-specific rights (the right to data portability, the right to object to automated decisions)
- Privacy notices only available in English when they should also be in German, French, or Italian depending on the audience
2. Cross-Border Transfer Disclosures
The nDSG's approach to cross-border transfers is similar to the GDPR but not identical:
- The Swiss Federal Council maintains its own list of countries with adequate protection
- Standard Contractual Clauses used for GDPR transfers may need adaptation for nDSG compliance
- Consent for cross-border transfers must be informed — the individual must understand the risks
- The destination country must be specifically named, not just "various countries"
3. Consent Requirements
While the nDSG does not require consent as the default legal basis (Swiss law uses a broader "legitimate purpose" approach), consent is required for:
- Processing sensitive personal data (including health, religious, political, and biometric data)
- Profiling with a high risk to the individual
- Cross-border transfers to countries without adequate protection (as an alternative to other safeguards)
Where consent is required, it must be informed, voluntary, and — for sensitive data — explicit.
4. Multi-Language Requirements
Switzerland has four official languages (German, French, Italian, and Romansh). Privacy content should be available in:
- German, French, and Italian at minimum for consumer-facing organizations
- The language of the canton where the individual is located, where known
- Multiple languages if the target audience is linguistically diverse
An nDSG Content Review Checklist
- Privacy notice identifies the Swiss controller with contact details
- Processing purposes are specified and current
- Recipients or recipient categories are disclosed
- Cross-border transfers specify destination countries (not just "various countries")
- Swiss-specific adequacy status is referenced (not just EU adequacy)
- Safeguards for non-adequate country transfers are disclosed
- Data subject rights under nDSG are described: access, correction, deletion, portability, objection
- Right to object to automated decisions is included where applicable
- Consent for sensitive data is explicit and specific
- Breach notification templates include all Article 24 required elements
- Privacy content is available in German, French, and Italian where appropriate
- Multi-language versions are substantively equivalent
- Data Protection Impact Assessment is documented for high-risk processing
- FDPIC contact information is available for complaints
Building a Privacy Content Review Process
Organizations operating in Switzerland should implement:
- Content audit: Identify all privacy-related content (privacy notices, consent forms, breach notification templates, cookie notices)
- nDSG gap analysis: Compare existing content against nDSG-specific requirements, not just GDPR
- Pre-publication review: AI-assisted scanning for privacy notice completeness, cross-border transfer disclosure, and consent adequacy
- Multi-language verification: Ensure German, French, and Italian versions are substantively equivalent
- Periodic review: Update privacy content when processing activities, cross-border arrangements, or FDPIC guidance changes
TeamBench enables organizations to build nDSG-specific content reviewers that evaluate privacy communications against Swiss data protection standards. Custom criteria can check privacy notice completeness, cross-border transfer disclosure, consent adequacy, and multi-language consistency — creating a scalable quality gate for every piece of privacy-related content.
With the nDSG introducing criminal penalties for responsible individuals, the personal stakes of non-compliant privacy content have never been higher in Switzerland.