FADP Compliance with ConsentX
Federal Act on Data Protection (revised nFADP)
Switzerland
Revised FADP in force since September 2023
Europe & UK
Who must comply
The FADP applies to private individuals, organisations and federal bodies that process personal data. It can also apply to organisations outside Switzerland when their processing produces effects in Switzerland. Organisations that process Swiss users' personal data should assess their obligations based on the nature, purpose and risk of their processing activities.
Penalties
The revised FADP provides for fines of up to CHF 250,000 in certain cases. The law can impose penalties on the responsible natural person rather than simply treating the organisation as the sole recipient of the fine.
Key obligations
- Provide clear and accessible information about the collection and use of personal data
- Identify the controller and explain the purposes of processing
- Inform individuals about relevant recipients and international data transfers
- Respect data subject rights, including access, correction and deletion
- Maintain appropriate technical and organisational security measures
- Keep records of processing activities where required
- Conduct a Data Protection Impact Assessment (DPIA) where processing is likely to create a high risk to personality or fundamental rights
- Report qualifying personal data security breaches to the FDPIC
- Provide appropriate safeguards for international data transfers
- Address requirements relating to profiling and automated individual decisions
- Obtain consent where the FADP specifically requires it, particularly for certain processing involving sensitive personal data or high-risk activities
How ConsentX helps
Geo-aware consent banner that can adapt privacy experiences for Swiss visitors
Transparent purpose and recipient disclosures to support FADP transparency requirements
Easy consent and preference controls for visitors
Consent and preference receipts that provide evidence of user choices
Prior-script blocking to help prevent selected trackers from running before the applicable user choice
Region rule engine to configure Switzerland separately from other jurisdictions
DSAR and privacy request workflows to help manage data subject requests
Audit-ready records to support internal compliance documentation
Get FADP ready with ConsentX
Make your website privacy experience easier to manage across Switzerland and other jurisdictions.
This page is a plain-English summary for general information and is not legal advice. Confirm your specific obligations with qualified Swiss data protection counsel.
How to comply with FADP using ConsentX
- 1
Scan your website
Run a free scan to identify cookies, trackers and other technologies operating on your website. Understand what data is collected and which third parties may receive it.
- 2
Show a geo-aware privacy experience
Deploy the ConsentX banner to provide visitors with a privacy experience tailored to their region and the applicable requirements.
- 3
Control trackers and scripts
Use prior-script blocking to help prevent selected non-essential tracking technologies from loading before the applicable user choice or privacy control is provided.
- 4
Record user choices
Store consent and preference events in tamper-evident receipts, giving your team an auditable record of user choices and privacy interactions.
- 5
Manage data subject requests
Use the ConsentX DSAR workflow to organise privacy requests, track deadlines and maintain a central record of request handling.