“Does this concern me?” That is the first question an SME owner asks when faced with cyber regulations. And it is the right question, because the answer depends far less on the size of the company than on what it does and who it serves.

This article serves as an entry point. You will find your sector, see what applies to you, and know where to dig further. One clarification before we start: this is an orientation summary, not legal advice. On borderline cases, a lawyer or your branch’s supervisory authority remain the right people to consult.

The common baseline: the FADP, for everyone

Let us start with the most important point, because it defuses half the questions.

The new Federal Act on Data Protection applies to every Swiss company that processes personal data. No headcount threshold, no revenue threshold, no list of sectors concerned. If you have customers, suppliers or employees, you process personal data, so you are concerned.

The core obligations are the same for a hair salon and for a fifty-person company: informing people about what you do with their data, securing that data with proportionate measures, responding to access requests, and reporting to the FDPIC any breach that presents a high risk. The detail is covered in our article on your FADP obligations.

What the sector changes, then, is not the principle. It is the intensity of the measures expected, and above all one specific point: the register of processing activities.

What actually tips a sector over?

Article 12(5) FADP and Article 24 DPO exempt companies with fewer than 250 employees on 1 January of the year from the register of processing activities. That is good news for the vast majority of French-speaking Swiss SMEs.

But the exemption falls away in two cases:

  1. large-scale processing of sensitive personal data;
  2. high-risk profiling.

Sensitive personal data includes in particular health data, religious or political opinions, trade union membership, genetic and biometric data, as well as information on criminal or administrative proceedings.

It is this definition, and this definition alone, that explains why some sectors are more exposed than others. A medical practice, a physiotherapy practice, a pension fund, a trustee handling debt collection files, a staffing agency or a social service ordinarily process sensitive data. The exemption probably does not apply to them, even with three employees.

Reporting to the NCSC does not concern your SME

Since 1 April 2025, a duty to report cyberattacks to the National Cyber Security Centre has existed in Swiss law, with sanctions applicable since 1 October 2025. It rests on the Information Security Act and targets only operators of critical infrastructure, not ordinary SMEs. Many business owners think the opposite. Voluntary reporting remains obviously possible, and is even encouraged: the NCSC received 64,733 voluntary reports in 2025, against 62,954 in 2024.

Which obligations apply to your sector?

The table below summarises what is added to the FADP baseline depending on your activity. Read it as guidance, not as an exhaustive list.

SectorRegister of processing activitiesRules that are addedMain point of vigilance
Retail and e-commerceExemption applicable in principleGDPR if you actively target the EU marketPayment data, customer accounts, foreign e-commerce providers
Professional services (trustees, lawyers, consultants)Often mandatory (debt collection, sensitive files)Professional secrecy and professional dutiesAccess to your clients’ data, contractual requirements from your principals
Healthcare and practicesMandatory in practiceCantonal and professional rules specific to healthcareLarge-scale health data, patient files, business software providers
Industry and manufacturingExemption applicable in principleCRA and RED / EN 18031 if you sell products in the EUConnected products, production systems, requirements from your European customers
Construction and tradesExemption applicable in principleNo sector-specific cyber rulePayment fraud, site data, dependency on an IT provider
Public and semi-public sectorCantonal regime applicableCantonal data protection lawsCantonal law rather than the FADP for cantonal public bodies
IT and service providersDepending on the data processed for your clientsNIS2 passed on by contract, client requirementsProcessor status, duty to report any breach to your principal

Retail, professional services and healthcare

Retail and e-commerce. The FADP baseline is enough in most cases. The question that keeps coming up is the GDPR: a website accessible from Europe is not enough to make it apply to you, you need to actively target that market, for instance with prices in euros or delivery to the EU. We detail this split in FADP or GDPR, which applies. The real risk, here, remains operational: payment data and customer accounts are a direct target, as shown in our article on data theft and leaks.

Professional services. Trustees, lawyers, consulting firms and property managers face two constraints at once. First, professional secrecy or the duty of discretion specific to their activity. Second, the FADP, with an important nuance: as soon as a file contains debt collection proceedings, or a criminal or administrative procedure, it falls under sensitive personal data. A trustee handling debt recovery should therefore consider the register to be applicable.

Healthcare and practices. This is the most regulated sector. Health data is sensitive by definition, and a practice processes it at scale even with a small patient base. The register of processing activities is required in practice. On top of that come cantonal and professional rules specific to healthcare, which vary from canton to canton: they should be checked with your canton’s public health department, not in a general article like this one.

Industry, construction and IT

Industry and manufacturing. If your products include digital elements and are sold in the European Union, two texts concern you directly. Regulation (EU) 2024/2847, known as the CRA, requires reporting of actively exploited vulnerabilities from September 2026, with its main obligations applying from late 2027. And the RED Directive, with the EN 18031 standards, has been mandatory since 1 August 2025 for connected radio equipment sold in the EU. Both topics have their own dedicated articles: the CRA and the RED Directive and the EN 18031 standards. On the production side, the security of industrial systems falls rather under the IEC 62443 framework.

Construction and trades. No sector-specific cyber regulation targets these trades. The FADP baseline applies, and that is all. This does not mean the risk is low: payment fraud and email identity spoofing hit these companies hard, often because IT is entirely delegated to a provider without anyone checking what is actually in place.

IT and service providers. You are in a particular position: your obligations come as much from your clients as from the law. If you process data on behalf of a client, you are a processor, and you must report any breach to them with no risk-threshold condition. If you supply European companies subject to NIS2, expect security requirements to arrive by contract. This is the mechanism described in our article on supply chain attacks.

Public sector, semi-public sector, finance and insurance

Public and semi-public sector. Cantonal and municipal public bodies do not, in principle, fall under the federal FADP, but under cantonal data protection law. In Fribourg, it is the cantonal LPrD that applies, with its own supervisory authority: see data protection in the canton of Fribourg. Private companies working for a public authority remain subject to the FADP, and are often subject to security requirements in public procurement.

Finance and insurance. This sector is subject to prudential supervision that adds its own requirements regarding system security, risk management and incident reporting, on top of the FADP. These rules evolve regularly and depend on the exact status of the institution. We deliberately do not detail them here: the source to consult is the supervisory authority you report to, or your usual legal counsel.

The baseline covers most of the path

Whatever your sector, the same measures come up again and again: data inventory, restricted access, two-factor authentication, tested backups, an incident procedure. Sector obligations are added on top, they never replace these foundations. That is encouraging, because it means the same effort serves both compliance and real security. The 2025 SME Cybersecurity Survey is a reminder of the urgency: 42% of Swiss SMEs consider their protection sufficient, against 55% a year earlier.

Where to start in your case?

Three questions are enough to place yourself.

  1. Do you process sensitive personal data? Health, debt collection, political or religious opinions, trade union membership, biometric data. If so, the register of processing activities probably concerns you, whatever your size. The FADP test answers in five questions.
  2. Do you sell products or services in the European Union? If so, look at the CRA, the RED Directive and the GDPR depending on what you sell and to whom.
  3. Do your clients impose security requirements on you? A supplier questionnaire, a contractual clause, a requested audit. This is often how NIS2 and European requirements reach you, well before any Swiss legal obligation.

If you answer no to all three, your roadmap comes down to the FADP baseline and basic security measures. That is already a lot, and it is achievable.

To place your company in three minutes, the cyber check-up gives you a score and your three priorities. The full set of texts applicable to Swiss companies is gathered in the Regulations pillar.