Skip to content
All Blogs

revFADP two years on: Is your Swiss data governance actually defensible?

Published
revFADP two years on: Is your Swiss data governance actually defensible?
revFADP two years on: Is your Swiss data governance actually defensible?
2:25

 

 


TL;DR

 

The revised Federal Act on Data Protection has been in force since September 2023. Two years in, plenty of Swiss organisations have the policies — a privacy notice, a processing register, a breach process — but couldn't prove any of it holds up if the FDPIC came knocking. This blog covers what "defensible" data governance actually looks like under Swiss law, and where it quietly differs from the GDPR. 

Policy is not proof

The revised FADP (revFADP) modernised Swiss data protection and is enforced by the Federal Data Protection and Information Commissioner (FDPIC). Its requirements are now familiar: records of processing activities, privacy by design and by default, data protection impact assessments for high-risk processing, and breach notification to the FDPIC. The trap is that most organisations can describe these controls but can't demonstrate them on demand.

The Swiss-specific nuances that catch people out

Teams that treat revFADP as "GDPR-lite" make avoidable mistakes. Swiss breach notification is framed around reporting "as soon as possible" rather than a fixed 72-hour clock. Enforcement can fall on responsible individuals with criminal fines rather than on the company through administrative penalties — a materially different incentive structure. And the law reaches organisations abroad that process the data of people in Switzerland. Governance built only around EU assumptions leaves gaps precisely where Swiss law diverges.

Closing the gap between claim and evidence

Defensible data governance means your processing register reflects reality, your DPIAs are linked to the processing that triggered them, and your breach process produces a timestamped, reconstructable record. This is where 6clicks helps Swiss organisations turn data-protection policy into provable practice: mapping revFADP obligations to controls, capturing evidence against them, and keeping oversight continuous so an FDPIC enquiry is answered from a system of record. With Sovereign GRC Infrastructure, that record can stay resident in Switzerland — a meaningful advantage when the data itself is the subject of the obligation.

 

If you're not certain your revFADP program would survive scrutiny, book a strategy call with 6clicks and find the gaps before a regulator does.

Frequently asked questions

They're closely aligned but not identical. Key differences include breach-notification timing, individual criminal liability, and the removal of legal persons from the law's protection. 

The FDPIC supervises and investigates; certain violations can lead to fines against responsible individuals. 

A processing register or DPIA that exists on paper but doesn't match actual data flows — and no evidence trail to prove ongoing compliance. 

 

 

Ready to transform GRC with 6clicks?

Let’s show you how it works for your team.

awards-mobile-v3