Switzerland Data Privacy Law: The nDSG, the EDÖB and Your Rights

Search for Swiss data protection rules and most of what comes back in German is written for a German or EU reader. That is a problem, because Switzerland is not in the European Union, and its data protection statute is not the GDPR.
Switzerland's own law is the nDSG, the totally revised Federal Act on Data Protection, and it is structurally different from the GDPR in a way that surprises almost everyone who first encounters it. This hub orients across the whole area: who the law covers, what a business must actually do, who enforces it, and where the GDPR still reaches in from outside. It does not walk through any single mechanism in full depth. That detail lives in the two pages it hands off to.
Information last verified on 21 July 2026. This page provides general legal information about Swiss law and does not constitute legal advice in an individual case.
The nDSG, not the GDPR
Switzerland rewrote its data protection statute from scratch in a Totalrevision, and the result, generally called the nDSG, entered into force on 1 September 2023. It replaced a 1992 law that had none of the accountability duties a modern business now expects to face.
The nDSG is not a local implementation of the GDPR and does not track it line for line. The two statutes cover overlapping ground, information duties, breach notification, an access right, but they diverge on enforcement, on timing, and on the identity of who actually pays when something goes wrong. A reader coming from GDPR-focused search results should treat every specific figure as needing a Swiss-specific check rather than assuming that a German or EU answer carries over.
Art. 3 nDSG extends the law's reach with an effects test: it governs a situation affecting Switzerland even when the conduct causing it happened abroad. A company with no Swiss office can still be squarely inside the nDSG's scope if its processing affects someone in Switzerland.
The point almost everyone gets wrong: the EDÖB cannot fine you
The EDÖB, the federal data protection and transparency commissioner, is Switzerland's data protection regulator. Under Art. 49 to 51 nDSG, it can open an investigation, compel cooperation, and order a company to fix specific problems, adjust or stop processing, delete data, or appoint a representative.
Nowhere in that toolkit is a power to impose a monetary fine. The EDÖB cannot levy a GDPR-style administrative penalty against a company, in any amount, for any violation. Our nDSG overview sets out exactly what the regulator can order instead, and where the real financial exposure actually sits: cantonal criminal prosecution of the responsible individual under Art. 60 to 65 nDSG, for intentional conduct only, capped in Swiss francs rather than a percentage of global turnover.
Information duties, impact assessments, and the breach clock
A controller must generally tell people what it is doing with their data under Art. 19 to 21 nDSG, and must complete a data protection impact assessment before processing that may create a high risk under Art. 22 nDSG. Neither obligation is unique to Switzerland in concept, but each has its own Swiss wording and its own exceptions, which the nDSG overview page works through.
Breach notification is where the gap from GDPR habits is sharpest. Art. 24 nDSG requires notice to the EDÖB as quickly as possible, so rasch als möglich, but only when the breach is likely to create a high risk to the data subject. There is no fixed 72 hour deadline anywhere in Swiss law for this duty, and the trigger itself is narrower than the GDPR's default of notifying unless the risk is low. A business assuming either the GDPR's clock or its broader trigger applies here will misjudge its own obligations in both directions.
The access right, in one sentence
Art. 25 nDSG lets anyone ask a controller whether it processes their personal data and, if so, obtain specific details about it. The deadline, the fee rules, and the grounds a controller can lawfully use to refuse or limit a request are detailed mechanics with their own exceptions, and they sit entirely on our dedicated data access request page rather than here.
Criminal exposure sits with individuals, not the company
Art. 60 to 63 nDSG set fines of up to CHF 250000 against the individual responsible for specific intentional violations: giving false information under an access request, unlawfully disclosing data abroad, ignoring minimum security requirements, or breaching a professional secrecy duty. Every one of these provisions requires intent; ordinary negligence does not trigger them.
A narrower fallback in Art. 64 nDSG lets a court fine the business itself, up to CHF 50000, but only where identifying the responsible individual would take disproportionate investigative effort relative to the penalty at stake. Prosecution and judgment of all of this belongs to the cantons under Art. 65 nDSG, not the EDÖB, whose only role in a criminal matter is filing a complaint and participating as a private party. Our nDSG overview walks through this structure with worked figures.
The Swiss representative duty
A foreign controller with no Swiss establishment must appoint a Swiss representative under Art. 14 nDSG, but only where four conditions are met together: the processing relates to offering goods or services or monitoring behaviour of people in Switzerland, the processing is extensive, it is regular, and it creates a high risk to the data subject.
There is no numeric threshold anywhere in Art. 14 or Art. 15, no specific count of customers or records that triggers the duty on its own. It is a cumulative, qualitative test, and a business should not look for a headcount figure that does not exist in the statute.
Where the GDPR still reaches in
Switzerland's own adequacy status runs one direction only. The European Commission first recognised Swiss data protection as adequate in 2000 and reaffirmed that recognition on 15 January 2024, which lets personal data flow from the EU into Switzerland without extra contractual safeguards. It does not mean Switzerland has adopted the GDPR, and it does not shield a Swiss business from the GDPR's own reach.
A Swiss business with no EU establishment can still be caught directly by the GDPR under its own extraterritorial rule, if it offers goods or services to, or monitors the behaviour of, people located in the EU. A Swiss retailer running a German-language storefront that ships into Germany is a plausible example; a business serving only Swiss customers generally is not. This distinction, and what compliance looks like on each side of it, is covered in the nDSG overview page.
Where to go from here
A reader who wants the full structure of enforcement, the EDÖB's real powers, the criminal fine tiers, and the GDPR comparison in depth should read the nDSG overview. A reader who specifically wants to know how to exercise or respond to an access request, the deadline, the fee, and the lawful grounds for refusal, should read data access requests.
Both pages sit inside our broader guide to Swiss law, which covers the codes, courts and institutions behind this cluster and the rest of our Swiss coverage.
Frequently Asked Questions
Does the GDPR apply to a business operating only in Switzerland?
No, not as domestic law. A purely Swiss business with no EU establishment and no dealings with people in the EU is governed by the nDSG, not the GDPR. The GDPR can still apply directly if the business offers goods or services to, or monitors the behaviour of, people located in the EU.
Who enforces data protection law in Switzerland?
The EDÖB investigates and can order corrective measures, but it cannot impose fines. Criminal fines are prosecuted by cantonal authorities against the individual responsible, not by the EDÖB itself. Most of these offences are also Antragsdelikte: Art. 60 Abs. 1 and Art. 61 nDSG punish only auf Antrag, meaning the affected person generally has to lodge a criminal complaint rather than expecting a prosecution to begin on its own. Refusing to cooperate with an EDÖB investigation under Art. 60 Abs. 2 is one of the exceptions and is pursued without a complaint.
Where should I start if I think a Swiss company mishandled my data?
Start by understanding what the EDÖB can and cannot do, covered on our nDSG overview page, and if you specifically want to see what data a company holds on you, our data access request page covers how to make that request.
Is Swiss data protection law weaker than the GDPR because Switzerland is not in the EU?
Not uniformly. Some nDSG rules are narrower than the GDPR, such as its breach notification trigger, while others, like its criminal exposure for individuals, have no direct GDPR equivalent at all. The two systems diverge rather than one simply being stricter.
Does a Swiss company need to worry about the GDPR at all?
Only if it offers goods or services to, or monitors the behaviour of, people located in the EU. A business with no such dealings is governed by the nDSG alone.
What is the nDSG?
The nDSG is Switzerland's totally revised Federal Act on Data Protection, in force since 1 September 2023 and updated since. It is Switzerland's own statute, separate from and structurally different than the GDPR.
Can I be fined personally under Swiss data protection law?
Yes, if you are the individual found responsible for an intentional violation under Art. 60 to 63 nDSG, prosecuted by the canton where the offence occurred. Our nDSG overview page sets out the specific violations and figures involved.
Sources and References
- Art. 3 nDSG, Räumlicher Geltungsbereich(fedlex.admin.ch).gov
- Art. 14 und 15 nDSG, Vertretung(fedlex.admin.ch).gov
- Art. 19 bis 21 nDSG, Informationspflichten(fedlex.admin.ch).gov
- Art. 22 nDSG, Datenschutz-Folgenabschätzung(fedlex.admin.ch).gov
- Art. 24 nDSG, Meldung von Verletzungen der Datensicherheit(fedlex.admin.ch).gov
- Art. 25 nDSG, Auskunftsrecht(fedlex.admin.ch).gov
- Art. 49 bis 51 nDSG, Untersuchung, Befugnisse und Verwaltungsmassnahmen(fedlex.admin.ch).gov
- Art. 60 bis 64 nDSG, Strafbestimmungen(fedlex.admin.ch).gov
- Art. 65 nDSG, Zuständigkeit(fedlex.admin.ch).gov
- EDÖB, EU-Angemessenheitsbeschluss betreffend die Schweiz(edoeb.admin.ch).gov
- EDÖB, Aufgaben und Befugnisse des Beauftragten(edoeb.admin.ch).gov