Since 1 September 2023, the revised Federal Act on Data Protection (FADP) has been in force in Switzerland. Many SMEs have updated their privacy policy – but the technical side is often neglected. Yet the law explicitly requires personal data to be protected by appropriate technical and organisational measures.
Note: this article is not legal advice. It shows what is sensible and common practice from an IT perspective.
What the FADP expects from IT
The law does not prescribe specific products. It requires protection appropriate to the risk. For a typical SME this means: customer data, personnel files and accounting must be protected against unauthorised access, loss and manipulation.
Two principles are now explicitly anchored:
- Privacy by design: systems are built from the start to process only the data that is needed.
- Privacy by default: the most data-friendly setting is active by default.
The key measures at a glance
- Clean up access rights. Who really needs access to the payroll folder? Roles instead of individual permissions, with regular reviews.
- Multi-factor authentication for email, remote access and cloud services. See our article on multi-factor authentication.
- Encryption of laptops, backups and connections.
- Backups with tested recovery – losing data is also a data protection breach. See backup & recovery.
- Logging, so that in an incident you can trace who accessed what and when.
- Updates installed promptly, outdated systems replaced.
Duty to report breaches
If an incident is likely to result in a high risk for the people affected, it must be reported to the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible. That only works if you notice the incident in the first place – for example through central monitoring of your systems.
Where is your data?
The FADP allows disclosure abroad if adequate protection is ensured there or additional safeguards have been agreed. Keeping data in Switzerland greatly simplifies these checks. See also our article on digital sovereignty.
Conclusion
Data protection is to a large extent clean IT work. If you want to know where your company stands, we are happy to carry out a security assessment with you.
Frequently asked questions
Does the FADP also apply to small companies?
Yes. The law applies to all private companies that process personal data, regardless of their size.
Do I need a record of processing activities?
Companies with fewer than 250 employees are generally exempt, unless they process sensitive personal data on a large scale or carry out high-risk profiling.
What penalties apply?
The FADP provides for fines of up to CHF 250,000. They are imposed on the responsible individuals, not on the company.



