Switzerland's nDSG: The Federal Data Protection Act Explained

A Swiss business that reads about a European regulator fining a company millions of euros for a data breach, then assumes a similar fine is waiting for it at home, has drawn the wrong lesson twice over. Switzerland is not in the European Union, its data protection statute is not the GDPR, and its data protection regulator cannot fine anyone at all.
That does not mean there is no real exposure. It runs through a different door: cantonal criminal prosecution of the individuals responsible, not administrative fines against the company. This page works through what the nDSG actually requires, what its regulator can and cannot do, and where a Swiss business ends up caught by the GDPR anyway.
Information last verified on 21 July 2026. This page provides general legal information about Swiss law and does not constitute legal advice in an individual case.
What changed on 1 September 2023, and what changed again since
Switzerland's data protection statute was overhauled in a Totalrevision, a full rewrite rather than a set of amendments, and the rewritten law, generally called the nDSG, entered into force on 1 September 2023. It replaced a 1992 statute that predated modern cross-border data flows and had none of the accountability duties businesses now expect.
The current consolidated text is not identical to the version that commenced in 2023. Effective 1 April 2025, Art. 24 nDSG gained a new paragraph letting the EDÖB forward a breach report to the Bundesamt für Cybersicherheit for incident analysis, with the controller's consent. The core consumer facing mechanics, access rights, deadlines, fees, and the criminal provisions, did not change between the two dates.
The nDSG applies to any natural or legal person processing personal data, and Art. 3 nDSG extends it beyond Swiss borders through an effects test: the statute governs a situation that has an effect in Switzerland even if it was set in motion abroad. A foreign company whose processing affects someone in Switzerland does not escape the nDSG simply because its servers and staff sit elsewhere.
The single most misunderstood point: the EDÖB cannot fine anyone
The EDÖB, the Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragte, is Switzerland's federal data protection and transparency commissioner. Its powers under Art. 49 to 51 nDSG are investigative and corrective, not punitive.
Art. 49 nDSG lets the EDÖB open an investigation on its own initiative or after a complaint, and Art. 50 nDSG lets it compel cooperation, demand documents, inspect premises, and call witnesses if a party will not cooperate voluntarily. Art. 51 nDSG lets it order specific fixes: adjusting, suspending or stopping processing, deleting data, blocking a cross-border transfer, or requiring a company to meet a specific duty such as completing an impact assessment or appointing a Swiss representative. Where a business already fixed the problem during the investigation, the EDÖB can settle for a formal warning instead.
Nowhere in Art. 49 to 51 does the EDÖB get a power to impose a monetary penalty. It cannot levy a fine against a company for a data breach, the way an EU supervisory authority can under the GDPR. A business that has heard otherwise has heard a widely repeated error.
Where the real exposure actually sits
The fines exist, they are simply not the EDÖB's to impose. Art. 60 to 63 nDSG set criminal fines of up to CHF 250000 for specific violations, among them giving false or incomplete information under the access-right provisions, unlawfully disclosing data across borders, delegating processing improperly, failing to meet minimum data security requirements, breaching a professional secrecy duty, or disobeying an EDÖB order.
Every one of those provisions is limited to intentional conduct. Each carries the word vorsätzlich, intentionally, as its mental state requirement, and none extends to negligent or merely careless handling of data. A business that suffers a breach through an honest security failure is not automatically exposed to this fine track; the statute is aimed at deliberate violations.
The fine also does not attach to the company as such. Art. 60 to 63 name private Personen, meaning the responsible natural persons inside the business, typically an officer or manager who made the relevant decision, as the addressee. Art. 65 nDSG assigns prosecution and judgment of these offences to the cantons, not the EDÖB. The regulator's only role in a criminal matter is to file a complaint with the competent cantonal prosecutor and participate as a private party in the proceeding.
A separate and narrower mechanism, Art. 64 nDSG, lets a court fine the business itself, up to CHF 50000, but only as a fallback where the fine in view is CHF 50000 or less and identifying which individual is responsible would require investigative effort disproportionate to the penalty at stake. It is a fallback for cases too small to justify chasing down a specific person, not a general corporate fine track sitting alongside the EDÖB.
Breach notification: not the GDPR's 72 hours
Art. 24 nDSG requires a controller to notify the EDÖB of a data security breach as quickly as possible, so rasch als möglich, when it is likely to create a high risk to the personality or fundamental rights of the data subject. Both halves of that test matter for a business trying to work out whether a given incident triggers the duty.
The trigger is narrower than it looks at first glance. The GDPR's default is to notify unless the breach is unlikely to create a risk. The nDSG's default runs the other way: notify only where the breach is likely to create a high risk. A minor incident that would still need reporting under the GDPR's broader trigger may fall below the nDSG's threshold entirely.
The timing is also not the fixed 72 hour clock a business used to the GDPR might expect. So rasch als möglich is a qualitative standard, not a numeric deadline, and no version of the nDSG or its implementing ordinance sets a 72 hour figure for this duty. A controller should still move promptly once it identifies a qualifying breach, since as quickly as possible is not the same thing as at its own convenience, but it should not treat 72 hours as a Swiss statutory line, because that line does not exist here.
A processor that discovers a breach must notify the controller as quickly as possible, and the controller must inform the affected data subject where that protects them or where the EDÖB requires it. Since 1 April 2025, the EDÖB may also forward a breach report to the Bundesamt für Cybersicherheit for incident analysis, but only with the controller's consent.
Access requests: free as a rule, thirty days as a rule
Art. 25 nDSG gives anyone the right to ask a controller whether their personal data is being processed, and if so, to receive specific information: the controller's identity, the data itself, the purpose, the retention period or the criteria for setting it, the data's origin where known, and whether an automated decision was involved.
The statute says access must ordinarily be given within 30 days, and Art. 18 of the implementing ordinance, the DSV, makes that operational: if the controller cannot meet 30 days, it must tell the requester and give a new deadline. It is a default with a built-in extension mechanism, not an absolute ceiling with no way to move it.
Access is free as the rule, under Art. 25 nDSG, but Art. 19 DSV allows a narrow exception: where giving access would take disproportionate effort, the controller may ask the requester to contribute to the cost, capped at CHF 300, and it must state that amount before responding and give the requester ten days to confirm the request still stands.
Art. 26 nDSG lets a controller refuse, limit or defer access in specific situations: a formal statutory duty of confidentiality, overriding third party interests, or a request that is manifestly unfounded or querulous. A private controller can also rely on its own overriding interest if the data are not passed to third parties, and a federal body can rely on an overriding public interest such as protecting an ongoing investigation. A refusal must state why access was limited; a business does not get to say nothing.
Ongoing duties beyond a request
Art. 19 to 21 nDSG require a controller to proactively inform a data subject when collecting their data, covering the controller's identity, the purpose, and, if data go abroad, the destination country and the safeguard relied on. Where data are not collected directly from the subject, the same information generally must be given within a month.
Art. 22 nDSG requires a prior data protection impact assessment before processing that may create a high risk, expressly including large scale processing of sensitive personal data and systematic large scale surveillance of public areas. A controller using a certified system or following a vetted code of conduct can skip a fresh assessment for that processing.
Art. 21 nDSG gives a data subject the right to be told about, and in some cases to contest, a decision made exclusively by automated processing that produces a legal effect or significantly affects them. That right does not apply where the automated decision is directly tied to a contract with the data subject and grants what they asked for, or where they expressly consented to fully automated handling.
A worked example
A Swiss online retailer suffers a breach exposing customer names, addresses and order histories, but not payment card numbers or passwords. The retailer needs to assess, under Art. 24 nDSG, whether this breach is likely to create a high risk to those customers, not simply whether a breach occurred at all.
An exposure of names and shipping addresses alone is a materially different risk than an exposure that also included passwords or financial account numbers, so the retailer's own risk assessment, not a fixed list of triggering data types, decides whether notification to the EDÖB is required. If it decides notification is warranted, it must notify the EDÖB as quickly as possible, describing the nature of the breach, its consequences, and the measures taken or planned, and it must inform affected customers if doing so protects them or the EDÖB asks for it.
If the retailer later discovers an employee deliberately suppressed the breach to avoid the paperwork, that individual, not the company, is the one facing potential Art. 61 nDSG exposure, of up to CHF 250000, and any prosecution would run through the canton where the offence occurred, not through the EDÖB.
Where the GDPR bites a Swiss business anyway
Switzerland is not an EU or EEA member, and the GDPR is not Swiss domestic law. The two systems run in parallel, and the European Commission has recognized Switzerland's data protection regime as adequate since 2000, and the Commission issued a new adequacy decision on 15 January 2024. That recognition lets personal data flow from the EU into Switzerland without extra safeguards; it does not make the GDPR Swiss law.
A purely domestic Swiss business, with no EU establishment and no dealings with people in the EU, generally has no direct GDPR exposure at all. The GDPR reaches a Swiss business only through its own extraterritorial rule, catching a controller with no EU establishment that offers goods or services to people in the EU, or monitors their behaviour, regardless of where the business itself is based. A Swiss retailer that ships to German customers and runs a German language storefront is a plausible candidate for this rule; a Swiss business serving only Swiss customers generally is not.
The Swiss representative requirement
A foreign controller with no establishment in Switzerland must appoint a Swiss representative, but only where Art. 14 nDSG's four conditions are all met together: the processing relates to offering goods or services or monitoring behaviour of people in Switzerland, the processing is extensive, it is regular, and it creates a high risk to the data subject.
There is no numeric threshold in Art. 14, no specific count of data subjects or employees that triggers the duty. It is a qualitative, cumulative test, and a business should not assume it is safe simply because it processes fewer than some particular number of Swiss records; equally, a business should not assume the duty applies just because it has some Swiss customers, since all four conditions have to be satisfied.
Frequently confused with the GDPR, and where the two actually diverge
The GDPR's supervisory authorities can impose administrative fines directly, set under its Art. 83 as the higher of a fixed statutory ceiling or a percentage of worldwide annual turnover. The nDSG gives its regulator no fining power at all, and routes real financial exposure through cantonal criminal courts against individuals, capped in Swiss francs, not a percentage of revenue.
The GDPR's breach notification default is to report unless the risk is low. The nDSG's default is the reverse, report only if a high risk is likely, and its timing standard is qualitative rather than a fixed clock. The GDPR's access deadline is one month, extendable by two further months. The nDSG's is 30 days as a rule, extendable with notice, and unlike the GDPR it also permits a capped fee in a defined circumstance.
Treating the two statutes as interchangeable, in either direction, is where businesses get into trouble: assuming Swiss law is as strict as the GDPR in areas where it is narrower, or assuming Switzerland has no meaningful data protection regime because it sits outside the EU.
This page is part of our broader Swiss data privacy law coverage, itself part of the guide to Swiss law.
Frequently Asked Questions
Can the EDÖB fine a company for a data breach in Switzerland?
No. The EDÖB's powers under Art. 49 to 51 nDSG are limited to investigating and ordering corrective measures or a formal warning. Actual fines run through cantonal criminal prosecution of the individuals responsible under Art. 60 to 63 nDSG, or in narrow cases a subsidiary company fine under Art. 64 nDSG.
What is the maximum fine under the nDSG?
Up to CHF 250000 against the individual responsible under Art. 60 to 63 nDSG, for intentional conduct only. A separate, narrower fallback lets a court fine the company up to CHF 50000 under Art. 64 nDSG where identifying the responsible individual would take disproportionate effort.
Does a data breach have to be reported within 72 hours in Switzerland?
No. That is the GDPR's rule. The nDSG requires notification to the EDÖB as quickly as possible when a breach is likely to create a high risk, with no fixed hourly deadline and a narrower trigger than the GDPR's default.
Is the GDPR the law that governs data protection in Switzerland?
No. Switzerland is not an EU member and the GDPR is not Swiss law. The nDSG is Switzerland's own statute. A Swiss business with no EU establishment can still be caught directly by the GDPR if it offers goods or services to, or monitors, people located in the EU.
Does the nDSG apply to a company based outside Switzerland?
It can. Art. 3 nDSG applies the law to matters that have an effect in Switzerland, regardless of where the processing happens or where the company is established. A business with no Swiss presence can still fall under the nDSG if its processing affects people here, and our access request page covers what that means for a request sent abroad.
Does the nDSG require a foreign company to appoint a Swiss representative?
Sometimes. Art. 14 and Art. 15 nDSG set a cumulative test rather than a headcount or revenue threshold: the processing must concern goods or services offered in Switzerland or the monitoring of behaviour here, and be extensive, regular and high risk. There is no numeric cut off, so the answer turns on the nature of the processing rather than the size of the company.
When does a foreign company need a representative in Switzerland under the nDSG?
Only when all four conditions in Art. 14 nDSG are met together: offering goods or services or monitoring behaviour of people in Switzerland, extensive processing, regular processing, and high risk to the data subject. There is no fixed headcount threshold.
When did the nDSG take effect and is it still the same today?
The totally revised nDSG entered into force on 1 September 2023. The current consolidated text is not identical to that version; effective 1 April 2025 it gained a provision letting the EDÖB forward a breach report to the Bundesamt für Cybersicherheit with the controller's consent, though the core rights and duties for businesses and individuals did not change.
Sources and References
- Art. 3 nDSG, Räumlicher Geltungsbereich(fedlex.admin.ch).gov
- Art. 14 und 15 nDSG, Vertretung(fedlex.admin.ch).gov
- Art. 19 bis 21 nDSG, Informationspflichten(fedlex.admin.ch).gov
- Art. 22 nDSG, Datenschutz-Folgenabschätzung(fedlex.admin.ch).gov
- Art. 24 nDSG, Meldung von Verletzungen der Datensicherheit(fedlex.admin.ch).gov
- Art. 25 nDSG, Auskunftsrecht(fedlex.admin.ch).gov
- Art. 26 nDSG, Einschränkungen des Auskunftsrechts(fedlex.admin.ch).gov
- Art. 18 und 19 DSV, Frist und Ausnahme von der Kostenlosigkeit(fedlex.admin.ch).gov
- Art. 49 bis 51 nDSG, Untersuchung, Befugnisse und Verwaltungsmassnahmen(fedlex.admin.ch).gov
- Art. 60 bis 64 nDSG, Strafbestimmungen(fedlex.admin.ch).gov
- Art. 65 nDSG, Zuständigkeit(fedlex.admin.ch).gov
- EDÖB, EU-Angemessenheitsbeschluss betreffend die Schweiz(edoeb.admin.ch).gov
- EDÖB, Aufgaben und Befugnisse des Beauftragten(edoeb.admin.ch).gov