EnglishDeutsch
Switzerland flag

Switzerland

Switzerland's nDSG: The Federal Data Protection Act Explained

By Recording Law Editorial Team16 min read
Switzerland's nDSG: The Federal Data Protection Act Explained

Frequently Asked Questions

Can the EDÖB fine a company for a data breach in Switzerland?

No. The EDÖB's powers under Art. 49 to 51 nDSG are limited to investigating and ordering corrective measures or a formal warning. Actual fines run through cantonal criminal prosecution of the individuals responsible under Art. 60 to 63 nDSG, or in narrow cases a subsidiary company fine under Art. 64 nDSG.

What is the maximum fine under the nDSG?

Up to CHF 250000 against the individual responsible under Art. 60 to 63 nDSG, for intentional conduct only. A separate, narrower fallback lets a court fine the company up to CHF 50000 under Art. 64 nDSG where identifying the responsible individual would take disproportionate effort.

Does a data breach have to be reported within 72 hours in Switzerland?

No. That is the GDPR's rule. The nDSG requires notification to the EDÖB as quickly as possible when a breach is likely to create a high risk, with no fixed hourly deadline and a narrower trigger than the GDPR's default.

Is the GDPR the law that governs data protection in Switzerland?

No. Switzerland is not an EU member and the GDPR is not Swiss law. The nDSG is Switzerland's own statute. A Swiss business with no EU establishment can still be caught directly by the GDPR if it offers goods or services to, or monitors, people located in the EU.

Does the nDSG apply to a company based outside Switzerland?

It can. Art. 3 nDSG applies the law to matters that have an effect in Switzerland, regardless of where the processing happens or where the company is established. A business with no Swiss presence can still fall under the nDSG if its processing affects people here, and our access request page covers what that means for a request sent abroad.

Can a company be fined under the nDSG for a careless mistake?

No. The criminal provisions in Art. 60 to 63 nDSG all require intentional conduct, so negligence and ordinary carelessness fall outside them. They are also mostly Antragsdelikte under Art. 60 Abs. 1 and Art. 61, which means the affected person generally has to lodge a criminal complaint before a prosecution begins.

When does a foreign company need a representative in Switzerland under the nDSG?

Only when all four conditions in Art. 14 nDSG are met together: offering goods or services or monitoring behaviour of people in Switzerland, extensive processing, regular processing, and high risk to the data subject. There is no fixed headcount threshold.

When did the nDSG take effect and is it still the same today?

The totally revised nDSG entered into force on 1 September 2023. The current consolidated text is not identical to that version; effective 1 April 2025 it gained a provision letting the EDÖB forward a breach report to the Bundesamt für Cybersicherheit with the controller's consent, though the core rights and duties for businesses and individuals did not change.

Sources and References

  1. Art. 3 nDSG, Räumlicher Geltungsbereich(fedlex.admin.ch).gov
  2. Art. 14 und 15 nDSG, Vertretung(fedlex.admin.ch).gov
  3. Art. 19 bis 21 nDSG, Informationspflichten(fedlex.admin.ch).gov
  4. Art. 22 nDSG, Datenschutz-Folgenabschätzung(fedlex.admin.ch).gov
  5. Art. 24 nDSG, Meldung von Verletzungen der Datensicherheit(fedlex.admin.ch).gov
  6. Art. 25 nDSG, Auskunftsrecht(fedlex.admin.ch).gov
  7. Art. 26 nDSG, Einschränkungen des Auskunftsrechts(fedlex.admin.ch).gov
  8. Art. 18 und 19 DSV, Frist und Ausnahme von der Kostenlosigkeit(fedlex.admin.ch).gov
  9. Art. 49 bis 51 nDSG, Untersuchung, Befugnisse und Verwaltungsmassnahmen(fedlex.admin.ch).gov
  10. Art. 60 bis 64 nDSG, Strafbestimmungen(fedlex.admin.ch).gov
  11. Art. 65 nDSG, Zuständigkeit(fedlex.admin.ch).gov
  12. EDÖB, EU-Angemessenheitsbeschluss betreffend die Schweiz(edoeb.admin.ch).gov
  13. EDÖB, Aufgaben und Befugnisse des Beauftragten(edoeb.admin.ch).gov
Share: