Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
Switzerland's revised Federal Act on Data Protection (nFADP/nDSG, Datenschutzgesetz, in force September 1, 2023) modernises Swiss data protection law to align with the EU GDPR and maintain the EU adequacy decision. The Federal Data Protection and Information Commissioner (FDPIC/EDÖB) oversees enforcement. Key changes from the former law: privacy by design and default, DPIA requirements, breach notification, enhanced data subject rights (including portability), profiling provisions, and increased penalties. Switzerland is not an EU member but maintains EU adequacy status.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (29)
Accountability
| Code | Title |
|---|---|
| CH-nFADP-15 | Code of conduct and certifications |
Automated Decisions
| Code | Title |
|---|---|
| CH-nFADP-11 | Automated individual decisions and profiling |
Chapter 1 — Scope and Application (Articles 1–4)
| Code | Title |
|---|---|
| FADP-1 | Purpose (Article 1) |
| FADP-2 | Scope of Application (Article 2) |
| FADP-3 | Territorial Scope (Article 3) |
| FADP-4 | Exceptions (Article 4) |
Chapter 2 — General Provisions (Articles 5–18)
| Code | Title |
|---|---|
| FADP-10 | Cross-Border Disclosure (Articles 16–18) |
| FADP-5 | Definitions (Article 5) |
| FADP-6 | Processing Principles (Articles 6–8) |
| FADP-7 | Data Protection Impact Assessment (Articles 9–10) |
| FADP-8 | Data Processing by Processors (Articles 11–13) |
| FADP-9 | Data Protection Advisor (Articles 14–15) |
Chapter 3 — Data Subject Rights (Articles 19–24)
| Code | Title |
|---|---|
| FADP-11 | Duty to Inform (Article 19) |
| FADP-12 | Right of Access (Article 25) |
| FADP-13 | Right to Data Portability (Article 28) |
Chapter 4 — Specific Processing Situations
| Code | Title |
|---|---|
| FADP-14 | Processing by Federal Bodies |
| FADP-15 | Data Breach Notification |
Chapter 5 — Federal Data Protection Commissioner
| Code | Title |
|---|---|
| FADP-16 | FDPIC Independence and Functions |
| FADP-17 | Investigations and Enforcement |
Chapters 6–10 — Penalties and Final Provisions
| Code | Title |
|---|---|
| FADP-18 | Criminal Penalties (Articles 60–66) |
| FADP-19 | Transitional Provisions |
Children Data
| Code | Title |
|---|---|
| CH-nFADP-19 | Children's data and consent age |
DPIA
| Code | Title |
|---|---|
| CH-nFADP-05 | Data protection impact assessment |
Data Lifecycle
| Code | Title |
|---|---|
| CH-nFADP-21 | Retention and deletion |
Data Protection Framework
Constitutional and regulatory privacy protections
Data Subject Rights
| Code | Title |
|---|---|
| CH-nFADP-10 | Data subject rights including access and portability |
Enforcement
| Code | Title |
|---|---|
| CH-nFADP-17 | Criminal sanctions and director liability |
Federal Bodies
| Code | Title |
|---|---|
| CH-nFADP-22 | Disclosure of personal data by federal bodies |
Governance
| Code | Title |
|---|---|
| CH-nFADP-12 | Data protection advisor designation |
Incident Response
| Code | Title |
|---|---|
| CH-nFADP-08 | Notification of data security breaches |
Information Security
| Code | Title |
|---|---|
| CH-nFADP-07 | Data security |
International Transfers
| Code | Title |
|---|---|
| CH-nFADP-09 | Cross border data transfers |
Interoperability
| Code | Title |
|---|---|
| CH-nFADP-18 | Recognition of GDPR aligned controls |
Principles
| Code | Title |
|---|---|
| CH-nFADP-02 | Principles of processing |
Privacy by Design
| Code | Title |
|---|---|
| CH-nFADP-04 | Privacy by design and by default |
Processor Management
| Code | Title |
|---|---|
| CH-nFADP-13 | Engagement of processors |
Records
| Code | Title |
|---|---|
| CH-nFADP-06 | Records of processing activities |
Regulator Cooperation
| Code | Title |
|---|---|
| CH-nFADP-20 | Cooperation with cantonal authorities |
Regulator Powers
| Code | Title |
|---|---|
| CH-nFADP-16 | FDPIC investigations and corrective powers |
Scope
| Code | Title |
|---|---|
| CH-nFADP-01 | Scope, definitions, and extraterritorial reach |
Sensitive Data
| Code | Title |
|---|---|
| CH-nFADP-03 | Sensitive personal data |
Transparency
| Code | Title |
|---|---|
| CH-nFADP-14 | Information obligations on data collection |
Your Compliance Coverage
If you comply with Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023), you already cover:
EU AI Act
22%
9 controls mapped
Compare →Pakistan Personal Data Protection Bill 2023
22%
9 controls mapped
Compare →EU Network Code on Cybersecurity for the Electricity Sector
22%
9 controls mapped
Compare →+ 635 more: Ethiopia Personal Data Protection Proclamation (No. 1321/2024) (22%), Panama Law on Personal Data Protection (Law No. 81 of 2019) (22%)
See all 638 mapped frameworks ↓Maps to 638 other frameworks
Frequently Asked Questions
What is Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)?
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) is a compliance framework from Switzerland with 29 domains and 41 controls. Switzerland's revised Federal Act on Data Protection (nFADP/nDSG, Datenschutzgesetz, in force September 1, 2023) modernises Swiss data protection law to align with the EU GDPR and maintain the EU adequacy decision. The Federal Data Protection and Information Commissioner (FDPIC/EDÖB) oversees enforcement. Key changes from the former law: privacy by design and default, DPIA requirements, breach notification, enhanced data subject rights (including portability), profiling provisions, and increased penalties. Switzerland is not an EU member but maintains EU adequacy status. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) have?
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) has 41 controls organised across 29 domains. The largest domains are Chapter 2 — General Provisions (Articles 5–18) (6 controls), Chapter 1 — Scope and Application (Articles 1–4) (4 controls), Chapter 3 — Data Subject Rights (Articles 19–24) (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) map to?
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) maps to 638 other compliance frameworks. The top mapping partners are EU AI Act (22% coverage), Pakistan Personal Data Protection Bill 2023 (22% coverage), EU Network Code on Cybersecurity for the Electricity Sector (22% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) compliance?
Start your Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 41 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required