Compliance Node Overview
Switzerland's revised Bundesgesetz über den Datenschutz (nDSG - neues Datenschutzgesetz / revFADP - revised Federal Act on Data Protection, SR 235.1), passed by the Swiss Federal Assembly on 25 September 2020 and entering into force on 1 September 2023, is Switzerland's primary federal data protection legislation replacing the prior Federal Act on Data Protection of 19 June 1992 (altDSG / SR 235.1 old). Switzerland is not an EU member state and is not subject to the EU GDPR directly; however, the nDSG was substantially redesigned to align with EU GDPR principles to preserve and strengthen the EU's adequacy decision for Switzerland. The European Commission has maintained Switzerland's adequacy status under both the old DSG and, following a review, under the nDSG. The nDSG applies to private persons (individuals and legal entities) and federal bodies (cantonal bodies are governed by cantonal data protection laws). Enforcement: the Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB - Federal Data Protection and Information Commissioner) is Switzerland's independent federal data protection and freedom of information authority. The EDÖB is not a member of the EU EDPB but engages in cooperation with EU data protection authorities through bilateral arrangements and the Council of Europe. The nDSG significantly strengthens Swiss data protection law compared to the prior altDSG: it introduces mandatory Data Protection Officers (for certain categories of controllers), mandatory Data Protection Impact Assessments (DPIA equivalent), mandatory breach notification to the EDÖB, new data subject rights (including right to explanation for automated decisions), stricter requirements for profiling, and substantially higher fines. Key differences from GDPR: (1) The nDSG does not apply to legal entities - only natural persons' data is protected (GDPR protects only natural persons; the nDSG alignment here is intentional); (2) Criminal sanctions: the nDSG provides criminal penalties (fines up to CHF 250,000) for wilful violations by responsible individuals, not administrative fines as under GDPR; (3) Age of consent: the nDSG does not have a specific age of consent for information society services equivalent to GDPR Art. 8 - consent capacity follows general Swiss civil law (capacity to act - Handlungsfähigkeit - from age 18, with minors of sufficient discernment capable of some consent); (4) Transfer mechanisms: Switzerland maintains its own adequacy country list for international data transfers; EU Standard Contractual Clauses may be used with Swiss-specific adaptations as transfer mechanisms for Switzerland; (5) Sensitive data: the nDSG protects a broader category of sensitive data than GDPR, including data on social assistance, administrative and criminal proceedings, and membership of religious organisations.
Pillar: Cybersecurity · Authority: Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB - Federal Data Protection and Information Commissioner, Switzerland) · Version: 1.0.0 · Last updated:
Primary source: https://www.edoeb.admin.ch/
SHA-256 integrity: 31aa2d4487e9f5d4d197b0e9d3351d546e0c49cab7a8abe428bb9a0b6f93421a
Primary Citations — 6 traced to source
- Bundesgesetz über den Datenschutz (nDSG / revFADP - revised Federal Act on Data Protection, SR 235.1, Switzerland) - passed 25 September 2020; in force 1 September 2023; replaces altDSG (prior Federal Act on Data Protection, 19 June 1992); key provisions: mandatory DSFA for high-risk processing; breach notification to EDÖB for high-risk breaches; right to explanation for automated decisions; criminal sanctions up to CHF 250,000 for responsible persons; expanded sensitive data categories (social assistance, criminal proceedings, religious membership); EU adequacy status maintained
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB - Federal Data Protection and Information Commissioner, Switzerland) - independent federal supervisory authority; issues guidance on nDSG compliance, AI and data protection, DSFA methodology, and international data transfers; breach notifications via EDÖB electronic system (edoeb.admin.ch); not an EU EDPB member but cooperates with EU DPAs bilaterally and through Council of Europe; issues adequacy list for Swiss international data transfers
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access