Coming into force in September 2023, the new Federal Act on Data Protection (FADP) modernised Switzerland’s rules on the processing of personal data. Nearly three years later, the activity report from the Federal Data Protection and Information Commissioner (FDPIC, the federal authority responsible for enforcing this law) offers a first concrete assessment. And it holds a few valuable lessons for SME leaders.
Numbers that speak for themselves
Over the period covered, the FDPIC reports having received more than 2,000 notifications of possible data protection violations. A data breach refers to any incident that exposes personal data to unauthorised access, loss, or disclosure: a leak following a hack, an email sent to the wrong recipient, a lost laptop.
Facing these reports, the authority intervened 156 times with the parties concerned, conducted 22 preliminary reviews, and opened 9 formal investigations. Most cases were settled amicably, without contentious proceedings. The FDPIC also notes that a ruling by the Federal Administrative Court, issued in October 2025, confirmed its practice, reinforcing legal certainty in the application of the revised law.
The often misunderstood point: who pays the fine
This is arguably the most important point for an SME, and the one most often misread. Unlike the European GDPR (the General Data Protection Regulation, applicable across the European Union), the FADP does not provide for administrative fines imposed directly on the company by an authority.
The FDPIC itself does not impose fines. Its role is to investigate, recommend, and, if needed, order compliance measures. Financial penalties fall under criminal law: they can reach CHF 250,000 and are handed down by the criminal courts. Crucially, they target the individual responsible for the breach, meaning an executive or an employee, not the company as such.
In other words, in Switzerland, the risk is not only institutional: it can be personal. This particularity deserves to be known by anyone who decides how data is processed within a company.
The FDPIC’s underlying concerns
Beyond the statistics, the report points to underlying trends. The FDPIC observes that public administration and organisations know how to handle obvious technical threats, such as data leaks, but struggle more to grasp the surveillance potential of large-scale data processing. It also notes a weakening of the principle of transparency after twenty years in force, with a growing number of exceptions restricting access to official documents.
For an SME, the implicit message is clear: compliance is not just about checking boxes after an incident. It requires thinking ahead about what you collect, why, and for how long.
What this means concretely for your business
The FADP applies to nearly every company, regardless of size, as soon as it processes personal data: customers, employees, suppliers. Several obligations are within your immediate reach. You can keep a record of your processing activities (a list of what you collect and how you use it), draft a clear privacy policy, and above all know how to respond in the event of a breach, since the law requires notifying the FDPIC without delay of breaches likely to pose a high risk to the people concerned.
You can largely get these steps started yourself. But they are not enough to guarantee your compliance. The difficulty is not knowing the principles, it is applying them to your reality: exactly what processing you carry out, which subcontractors are involved, what sensitive data you handle, and what level of risk results from it. These answers are specific to each company and cannot be improvised from a generic template.
In conclusion
The FDPIC’s report confirms a pragmatic Swiss approach, built on dialogue and compliance rather than systematic sanctions. But it also reminds us that responsibility can fall on individuals, and that data protection is an ongoing effort. Laying the groundwork yourself is essential and within reach. To turn that groundwork into solid compliance tailored to your business, a professional assessment of your data processing remains the surest way to move forward with confidence.