ConsentPixel – Privacy · Verified

HomeRegulations › FADP (Switzerland)
Switzerland · Privacy Law

FADP Compliance (revDSG): Swiss Data Protection, Handled

Switzerland's revised Federal Act on Data Protection reaches businesses worldwide that serve Swiss visitors. ConsentPixel makes compliance a one-pixel install.

Jurisdiction: SwitzerlandIn force: Sept 1, 2023Model: Opt-out (general) · transparency-led
Sept 2023
revised FADP in force, no grace period
CHF 250k
max fine — on responsible individuals
Extraterritorial
applies to processing affecting Switzerland

Switzerland's revised Federal Act on Data Protection — the FADP, also known as the nFADP or revDSG — modernized Swiss privacy law and brought it close to the EU's GDPR. If your website reaches people in Switzerland, the FADP can apply no matter where your business sits. ConsentPixel — Privacy · Verified handles consent, documentation, and audit-ready records so FADP compliance comes down to installing one pixel.

What is the FADP?

The Federal Act on Data Protection is Switzerland's core privacy law governing how personal data of individuals in Switzerland is collected, processed, and transferred. The revised version entered into force on 1 September 2023, replacing a 1992 statute that predated the modern web. It's widely referred to as the nFADP (new FADP) in English and the revDSG in German.

The revised FADP was designed to stay compatible with the GDPR so data can continue to flow freely between Switzerland and the EU. It protects only natural persons (not companies), explicitly applies beyond Swiss borders to processing that affects people in Switzerland, and expands individual rights and transparency obligations.

A key practical point: the FADP generally follows an opt-out logic for ordinary personal data — you can process data if you inform people transparently and let them object — but it requires clear handling of sensitive data and strong transparency about tracking. In practice, a properly configured consent banner and clear privacy notices are how most websites meet these expectations.

Who must comply

  • Businesses and organizations established in Switzerland that process personal data.
  • Companies outside Switzerland whose processing affects individuals in Switzerland — the law has explicit extraterritorial reach.
  • Foreign controllers may need to appoint a representative in Switzerland in certain cases.
  • The law protects natural persons; it no longer covers data about legal entities.

What the FADP requires

  • Transparency: Inform individuals about what data you collect and why.
  • Lawful processing & proportionality: Process in good faith, for a recognizable purpose, no more than necessary.
  • Sensitive data care: Genetic and biometric data are now expressly sensitive.
  • Data subject rights: Provide access, correction, and the ability to object.
  • Records of processing: Maintain a register (with limited small-org exemptions).
  • Breach notification & DPIAs: Notify the authority of high-risk breaches; assess high-risk processing.
  • International transfers: Ensure adequate protection when transferring data abroad.

Penalties under the revised FADP are notable for falling primarily on responsible individuals rather than companies, with criminal fines of up to CHF 250,000 for willful violations such as breaching transparency duties.

How ConsentPixel makes you FADP-compliant

ConsentPixel — Privacy · Verified sits between your visitors and your trackers. It detects what's running, presents a geo-aware consent banner, enforces the visitor's choice, and keeps an immutable record of every decision. Here's how that maps to your obligations:

Geo-aware consent & transparency banner. Swiss visitors are informed about tracking and their choices are captured, applying the appropriate model for their location.

Auto-detecting scanner finds every cookie and tracker on your site, so your disclosures and consent categories are complete and accurate — not guesswork.

Signal passthrough drives Google Consent Mode v2, Microsoft UET, Meta Pixel, and IAB TCF 2.3 from a single consent event, so every platform respects the same choice.

GPC honoring recognizes Global Privacy Control opt-out signals and applies them automatically.

Document generator auto-creates Privacy Policy, Cookie Policy, Terms, and DPA documents to support your transparency obligations.

🔒

Immutable, tamper-evident logs record every consent decision — audit-ready proof of what each visitor saw and chose.

One pixel, under 5 minutes. Everything above ships from a single pixel install, with a public trust badge and verification page.

Why ConsentPixel

  • Auto-detection keeps disclosures honest as your tracker stack changes.
  • One pixel covers consent, documents, and signals together.
  • Audit-ready logs give defensible proof of transparency and choice.
  • Multi-regulation: the same install also addresses GDPR and UK GDPR — useful since the FADP tracks the GDPR closely.

Frequently asked questions

Does the FADP apply if I'm not in Switzerland?

It can. The revised FADP applies extraterritorially to processing that affects individuals in Switzerland, so a website outside Switzerland that serves Swiss visitors may fall within scope.

Is the FADP the same as the GDPR?

It's closely aligned but not identical. The FADP was revised to stay GDPR-compatible, but differs in penalties (which fall mainly on individuals), records requirements, and the opt-out logic for ordinary data.

Do I need a consent banner for Swiss visitors?

For non-essential tracking and advertising, a clear consent and transparency mechanism is the standard way to meet FADP obligations. ConsentPixel's geo-aware banner applies the appropriate approach automatically.

What are the penalties under the FADP?

The revised FADP provides for criminal fines of up to CHF 250,000, which generally target the responsible individuals within an organization rather than the company, and apply to willful violations.

Can ConsentPixel generate the privacy documents the FADP expects?

Yes. ConsentPixel auto-generates Privacy Policy, Cookie Policy, Terms, and DPA documents to support the transparency the FADP requires.

The bottom line

The FADP brings Switzerland in line with GDPR-grade expectations while keeping its own quirks — individual liability, a records register, and opt-out logic for ordinary data. Because it reaches any site serving Swiss visitors, a transparent, geo-aware consent layer with audit-ready logs is the most efficient path to compliance.

Make FADP compliance a one-pixel job

Install ConsentPixel to give Swiss visitors transparent, geo-aware consent, generate your privacy documents, and keep audit-ready logs.

Scan your site free Start free trial

This page is informational and is not legal advice. The FADP/revDSG is a Swiss federal law; consult qualified Swiss counsel for advice on your specific obligations.

Scroll to Top