FADP: how Swiss data protection law has changed
The key changes that have applied since 1 September 2023
To increase data security and give citizens new rights, the Swiss Parliament revised the Federal Act on Data Protection (FADP). The new obligations have applied since 1 September 2023. Here is an overview of the key changes.
Data privacy | Refline AG
FADP: how Swiss data protection law has changed

The former Swiss Data Protection Act dated back to 1992 and had long since fallen behind technological development. That is why data protection law was revised from the ground up. The goal was to bring Swiss data protection back in line with the EU level and the modernised data protection conventions of the Council of Europe. The revised Federal Act on Data Protection (FADP) and the new Data Protection Ordinance (DPO) came into force on 1 September 2023, with no transition period.

FADP: an overview of the most important rules

The revised Data Protection Act introduces new requirements and strengthens the rights of the people concerned. It also restricts some existing rules. And it makes data processing more transparent. That has consequences for data protection in recruiting, too.

The most important changes are:

1. Exclusive protection of natural persons: The FADP only protects the data of natural persons. Legal entities are no longer covered.


2. Particularly sensitive personal data: Under the FADP, particularly sensitive personal data now also include genetic and biometric data such as fingerprints or retina scans, as well as data on ethnic origin. This triggers legal consequences for the data protection impact assessment, for consent and for disclosure to third parties.


3. Extended duty to inform: When collecting personal data, you are obliged to inform the data subject. You must inform them of the purpose of processing, who is responsible, and how they can be contacted.


4. Data protection-friendly default settings and technical data protection: The FADP introduces a stricter duty of care. It distinguishes between two terms: privacy by design and privacy by default. Privacy by design refers to compliance with data protection requirements during data processing. These must already be observed during planning to minimise risk. Privacy by default ensures that personal data can only be processed for the specific intended purpose through default settings.


5. Data protection impact assessment: If data processing poses a high risk, especially to the fundamental rights or personality of a data subject, a data protection impact assessment is mandatory under the FADP. This must outline the planned processing, any risks, and countermeasures.


6. Reporting data breaches: If a data breach occurs, you as the responsible person must report it promptly. The Federal Data Protection and Information Commissioner (FDPIC) must be informed whether there is a risk to the personality of the data subject. The affected person must also be informed if necessary.


7. Penalties under the FADP: The catalogue of penalties has been expanded and fines can reach CHF 250,000. The fine is imposed on the responsible natural person, not on the company. Where a fine of no more than CHF 50,000 is being considered and identifying the responsible person would take disproportionate effort, the authority can convict the business instead. The FDPIC can still take administrative measures, such as prohibiting processing or requiring deletion. It can now also open investigations on its own initiative and issue binding rulings. Anyone who wants to challenge them has to go to the Federal Administrative Court.


8. Profiling: The term has been added to the law. Profiling is the automated processing of personal data in order to evaluate personal aspects of a person, such as their work performance, their reliability or their behaviour.

The guide to the FADP

You now know what applies. Unsure what that means in day-to-day recruiting? Here is the solution: our guide gives you all the relevant information on the three most important recruiting obligations under the FADP, clearly laid out and including practical tips to help you implement what you've learned in your recruiting process. Your advantage: you save time reading complex legal texts. Plus, the guide includes a helpful checklist to walk you through the key points step by step.

Data protection duties, solved with Refline

Or simpler still: put it into practice directly with Refline.


Why make it complicated when it can be simple? With Refline’s e-recruiting solution you build every data protection function straight into your application process. From automated consent to timely deletion: Refline makes sure you are always on the safe side. That way you meet the legal requirements correctly, efficiently and without the stress.