Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Should You Treat Switzerland Like GDPR Territory?Privacy & Data Protection
6 min readFor Third-Party Risk Managers

Should You Treat Switzerland Like GDPR Territory?

You're processing data for customers or employees in Switzerland. Your legal team asks whether you need to comply with the revised Swiss Federal Act on Data Protection (revFADP). Your GDPR program is already running. Do you extend it to cover Switzerland, build a separate compliance track, or wait to see what enforcement looks like?

This isn't an academic question. The revFADP introduces fines up to CHF 250,000 and applies extraterritorially to foreign companies whose data processing impacts Switzerland. Your choice affects vendor contracts, data processing registers, consent mechanisms, and cross-border transfer protocols.

Here's how to decide.

The Decision You're Facing

You need to determine your compliance posture for Swiss data protection obligations. Three paths exist:

Path A: Extend your GDPR compliance program to cover Switzerland with minimal adjustments
Path B: Build a Switzerland-specific compliance track separate from GDPR
Path C: Implement a hybrid approach with shared infrastructure and targeted divergences

Your choice depends on four factors: the nature of your data processing activities in Switzerland, your profiling practices, your organizational structure, and your Impact Tolerance for regulatory interpretation.

Key Factors That Affect Your Choice

Geographic footprint and processing volume. The revFADP applies to foreign companies if their data processing impacts Switzerland, using the same extraterritorial reach as GDPR. If you're targeting Swiss residents with goods or services, or monitoring their behavior, you're likely in scope. The law also requires you to designate a Swiss representative if your processing is extensive, regular, and presents high risk to individuals.

Profiling intensity. The revFADP defines profiling identically to GDPR: automated processing that evaluates personal aspects like work performance, economic situation, health, preferences, interests, reliability, behavior, or location. But here's where it diverges. Under GDPR, profiling triggers specific obligations around automated decision-making. Under revFADP, the concept of "high-risk profiling" creates additional complexity. High-risk profiling exists when data combinations allow assessment of essential personality aspects. While Parliament declined to require explicit consent for all high-risk profiling, the debates left enough ambiguity that many controllers will seek explicit consent anyway to avoid violation of personal privacy.

Data categories you process. The revFADP expands special category data to include ethnicity, genetic data, and biometric data that uniquely identifies individuals. If you process these categories for Swiss residents, you face stricter obligations. One practical relief: the law no longer applies to legal entity data, eliminating a Swiss peculiarity that created compliance overhead in B2B contexts.

Group data flows. If you transfer personal data within a corporate group, the revFADP offers limited relief. You get exceptions to information duties and access rights, but only if the processing is "relevant and necessary for economic competition." This narrow group privilege means intra-company transfers still require case-by-case justification analysis.

Path A: Extend Your GDPR Program

Choose this path if:

  • Your data processing activities in Switzerland mirror your EU operations
  • You don't perform creditworthiness checks on Swiss residents
  • Your profiling practices already assume you need explicit consent for high-risk scenarios
  • You maintain a single data processing register that covers all jurisdictions
  • Your privacy notices already exceed minimum GDPR requirements

What you gain: Operational simplicity. One set of consent flows, one processing register structure, one vendor assessment protocol. Your team doesn't context-switch between regulatory regimes.

What you must adjust: Information obligations under revFADP don't include an exhaustive list of required disclosures. Your GDPR-compliant privacy notice likely covers the minimum (controller identity, purposes, recipients, cross-border transfers, automated decisions), but you should verify it addresses data categories when you collect data indirectly. The revFADP also grants data subjects a right to data portability in "common electronic format," which your GDPR tooling should already support.

Risk consideration: You're betting that Swiss enforcement will align with GDPR interpretation, particularly around profiling justifications. Given the Federal Data Protection and Information Commissioner's (FDPIC) limited enforcement history with the revised law, you're making an informed but not guaranteed assumption.

Path B: Build a Switzerland-Specific Track

Choose this path if:

  • You perform creditworthiness checks on Swiss residents
  • Your profiling practices rely on overriding legitimate interest rather than consent
  • You process data within a corporate group and need to use the narrow group privilege
  • You face specific Swiss regulatory scrutiny in your sector
  • You want maximum flexibility to interpret ambiguous revFADP provisions differently from GDPR

What you gain: Precision. Article 30 para. 2 lit. c revFADP sets special conditions for credit checks: no special category data, no high-risk profiling, disclosure only to parties with contractual need, data not older than ten years, data subject must be of legal age. If credit assessment is core to your business, you need Swiss-specific workflows that verify these conditions.

What you must build: A separate data processing register that captures revFADP-specific elements. While GDPR requires "where applicable" for retention periods and security measures, revFADP asks for these "if possible." This linguistic difference matters when the FDPIC reviews your documentation. You'll also need distinct consent language that addresses high-risk profiling explicitly, even though the legal requirement remains contested.

Operational cost: Your third-party risk team now assesses vendors against two frameworks. Your data subject request queue requires jurisdiction routing. Your breach notification protocols split between the FDPIC and relevant supervisory authorities. This overhead makes sense only if you're processing data in ways that genuinely diverge from GDPR norms.

Path C: Implement a Hybrid Approach

Choose this path if:

  • You process significant volumes of Swiss data but want to use GDPR infrastructure
  • You perform some activities (like profiling or group transfers) that benefit from Swiss-specific interpretation
  • You're willing to maintain documentation that satisfies both regimes simultaneously
  • You have mature GRC platform capabilities that support jurisdiction-specific control variants

What you gain: Efficiency where regulations converge, precision where they diverge. Your core privacy framework (data protection impact assessments, privacy-by-design, privacy-by-default, breach notification) serves both jurisdictions. Your consent management platform flags Swiss residents for explicit consent on high-risk profiling. Your processing register includes both GDPR and revFADP fields but populates them from shared data sources.

Where to customize:

  • Consent flows for profiling: Add explicit consent requirements for Swiss residents when high-risk profiling exists
  • Creditworthiness checks: Build Switzerland-specific validation that confirms the four Article 30 conditions
  • Group transfer justifications: Document how each intra-group flow meets the "relevant and necessary for economic competition" standard
  • Representative designation: Assess whether your Swiss processing volume, regularity, and risk profile trigger the representative requirement

Implementation pattern: Use your GRC platform's control objective mapping to link GDPR controls to revFADP obligations. Where obligations align (breach notification, Individual Rights, processing registers), map one control to both requirements. Where they diverge (profiling consent, credit checks, group transfers), create Switzerland-specific control variants with distinct testing procedures.

Summary Matrix

Factor Path A: GDPR Extension Path B: Swiss-Specific Path C: Hybrid
Best for Standard data processing mirroring EU operations Credit checks, contested profiling interpretations Significant Swiss presence with selective divergences
Processing register Single GDPR-based register Separate Swiss register Shared register with jurisdiction flags
Consent mechanism GDPR consent flows Swiss-specific consent for profiling Jurisdiction-aware consent platform
Vendor assessment Single GDPR questionnaire Dual assessment protocol GDPR baseline + Swiss supplements
Operational complexity Low High Medium
Regulatory risk Moderate (assumes alignment) Low (maximum precision) Low to moderate (targeted precision)
Implementation cost Minimal incremental Substantial Moderate

Your decision hinges on whether the ambiguities in revFADP profiling requirements and the narrow group privilege create enough operational difference to justify separate compliance infrastructure. For most organizations processing standard customer or employee data, Path A or Path C delivers compliance without doubling your privacy program overhead. If you're in credit services or rely heavily on intra-group data flows, Path B's precision may justify the cost.

The FDPIC's enforcement approach over the next 18 months will clarify whether Switzerland truly operates as GDPR-aligned territory or carves its own interpretation path. Until then, your choice reflects how much regulatory divergence risk you're willing to accept in exchange for operational simplicity.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like