Skip to content
Dies ist eine Ubersetzung zur Orientierung. Die englische Version ist die massgebliche und rechtsverbindliche Version. Englische Version anzeigen
CHMEDIUM coverage

Switzerland — New Federal Act on Data Protection (nFADP/revDSG): AI Compliance Requirements

Switzerland's revised Federal Act on Data Protection (nFADP / revDSG, in force September 1, 2023) applies to any organization processing data of Swiss residents, including through AI systems. Although Switzerland is not EU, nFADP is largely GDPR-aligned. Key AI obligations: transparency about automated decisions that significantly affect individuals, DPIAs for high-risk AI processing, the right to contest automated decisions and request human review, and data security requirements. The FDPIC (edoeb.admin.ch) enforces the law. CYCLE 20 UPDATE (2026-08-22): Switzerland's Federal Council has moved past "monitoring" — verified via the Federal Chancellery's own regulation page and Pestalozzi law firm — it confirmed a deliberately LEAN regulatory approach (targeted adjustments for fundamental rights/sectoral needs rather than full EU-AI-Act-style alignment) and tasked the Federal Department of Justice and Police (with DETEC, FDFA, and other federal offices) to prepare a consultation-draft AI bill by END OF 2026, implementing the Council of Europe's AI Framework Convention with measures on transparency, data protection, non-discrimination, and oversight; a parallel non-binding-measures plan (including alignment with key trading partners) is due the same timeframe. No AI-specific statute exists yet — Switzerland remains nFADP-only for now, but a concrete legislative track (not mere monitoring) is now underway with a defined end-2026 consultation-draft milestone.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

September 1, 2023

Enforcement Begins

September 1, 2023

Maximum Penalty

CHF 250,000 (approx. USD $285,000) for intentional violations — enforced via criminal prosecution

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Automated Decision Transparency (nFADP Art. 21)

High Priority

nFADP Art. 21: controllers making automated decisions that significantly affect Swiss individuals must: (1) disclose the automated decision, (2) give them the right to request human review and state their position, (3) explain the logic. AI systems in hiring, credit, insurance, or customer scoring must implement transparency and appeal rights for Swiss residents.

Deadline: September 1, 2023

nFADP Art. 21

Data Protection Impact Assessment for High-Risk AI (Art. 22)

High Priority

nFADP Art. 22: conduct a DPIA for high-risk AI processing — large-scale processing of sensitive data or systematic monitoring. Document and conduct a formal DPIA for AI systems processing biometrics, health data, or behavioral profiling at scale for Swiss residents.

Deadline: September 1, 2023

nFADP Art. 22

Privacy Notice for AI Processing

Medium Priority

Provide clear privacy notices disclosing AI-driven data processing to Swiss residents. Include the existence of automated decision-making and individuals' right to contest. The FDPIC can investigate and issue recommendations.

Deadline: September 1, 2023

nFADP Art. 19 (duty to inform when collecting personal data); Art. 21 (automated decisions)

Who Does This Apply To?

Applies to any organisation processing the personal data of Swiss residents through AI, regardless of where the organisation is established — Switzerland's revised Federal Act on Data Protection (nFADP / revDSG, in force 1 September 2023) is largely GDPR-aligned and enforced by the FDPIC (edoeb.admin.ch). In scope: controllers making automated decisions that significantly affect Swiss individuals (Art. 21 requires disclosure of the decision, the right to request human review and state one's position, and an explanation of the logic — covering AI in hiring, credit, insurance, and customer scoring), high-risk AI processing such as large-scale sensitive-data or systematic-monitoring systems (a DPIA is required under Art. 22), and cross-border transfers of Swiss data to AI vendors (FDPIC adequacy or supplementary measures, mirroring the Schrems II framework on which Switzerland's 2024 GDPR adequacy decision is conditioned). Maximum exposure: CHF 250,000 (~USD $285,000) for intentional violations, enforced via criminal prosecution.

Recent Regulatory Guidance

guidance2024-12

FDPIC — Position paper on AI and data protection (2024-2025)

FDPIC issued a position paper clarifying the application of the nFADP to AI: (1) high-risk AI processing of Swiss-resident data requires DPIA before deployment; (2) automated decisions producing significant legal or similarly significant effects must be disclosed to data subjects, with the right to contest and request human review; (3) cross-border transfers of Swiss-resident data to AI vendors require FDPIC adequacy determination or supplementary measures (mirroring Schrems II framework); (4) while Switzerland is not EU, the FDPIC's enforcement expectations align with the EU AI Act Article 5 prohibitions; (5) Swiss government is actively monitoring EU AI Act for potential national AI legislation.

guidance2026

Federal Council — Lean AI Regulatory Approach; Consultation-Draft AI Bill Due End of 2026

The Federal Council confirmed Switzerland will take a deliberately lean, targeted-adjustment approach to AI regulation rather than full EU AI Act-style alignment. It tasked the Federal Department of Justice and Police (with DETEC, FDFA, and other federal offices) to prepare a consultation-draft AI bill by end of 2026, implementing the Council of Europe's AI Framework Convention (measures on transparency, data protection, non-discrimination, and oversight) — plus a parallel non-binding accompanying-measures plan including trading-partner alignment, due the same timeframe. No AI-specific statute is enacted or even in formal consultation yet; this is a defined legislative TRACK with a milestone, not current law.

Key Case Law & Precedent

EU Schrems II — Data Protection Commissioner v. Facebook Ireland (CJEU C-311/18)

Court of Justice of the European Union · 2020

While Switzerland is not bound by EU jurisprudence, FDPIC's nFADP cross-border-transfer regime explicitly mirrors the Schrems II framework — adequacy determinations, supplementary measures, and risk assessments for transfers to jurisdictions without nFADP-equivalent protection. The FDPIC cites Schrems II as the doctrinal anchor when assessing Swiss-controller transfers to third-country AI vendors. Switzerland's adequacy decision under GDPR (granted 2024) is conditional on continued FDPIC alignment with EU enforcement standards.

Outcome: Privacy Shield invalidated; SCCs upheld with supplementary measures requirement; Swiss-EU adequacy decision granted 2024

Case reference

Industry Playbooks covering Switzerland — New Federal Act on Data Protection (nFADP/revDSG)

These industry playbooks include jurisdiction-specific checklist items and guidance for Switzerland — New Federal Act on Data Protection (nFADP/revDSG).

Frequently Asked Questions

Does Switzerland — New Federal Act on Data Protection (nFADP/revDSG) apply to my business?

Switzerland's revised Federal Act on Data Protection (nFADP / revDSG, in force September 1, 2023) applies to any organization processing data of Swiss residents, including through AI systems. Although Switzerland is not EU, nFADP is largely… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Switzerland — New Federal Act on Data Protection (nFADP/revDSG) is: CHF 250,000 (approx. USD $285,000) for intentional violations — enforced via criminal prosecution. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Switzerland — New Federal Act on Data Protection (nFADP/revDSG)?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.fedlex.admin.ch/eli/cc/2022/491/en

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan