nFADP

nFADP one year on: the 5 most common mistakes

BeeLink Team·Sep 12, 2026 6 min

One year after the new Federal Act on Data Protection (nFADP) came into force, we audited around a hundred Swiss organizations. Here are the mistakes that come up most often — and how to fix them without spending a whole quarter on it.

1. An incomplete processing register

Art. 12 nFADP requires most companies to keep a register of processing activities. Yet in 7 out of 10 cases, this register exists but overlooks HR processing, video surveillance, or marketing SaaS tools (HubSpot, Mailchimp, etc.).

To do: identify every piece of software in use, including free tools, and document purpose + legal basis + retention period.

2. The phantom DPO

Appointing a DPO (Data Protection Officer) without giving them time, budget, or access to decision-making bodies is effectively the same as not having one. The FDPIC treats this as de facto non-compliance.

3. Uncontracted subprocessors

Every provider that processes data on your behalf must be bound by a data processing agreement (DPA) specifying instructions, security, sub-subprocessors, and data location. A simple purchase order is not enough.

4. Untracked transfers outside Switzerland

Using AWS Frankfurt or Google Workspace means transferring data. If the destination country lacks an adequacy decision, you need Standard Contractual Clauses (SCCs) and a transfer impact assessment (TIA).

5. No data breach procedure

You have 72 hours to notify the FDPIC in the event of a high-risk breach. Without a written procedure, tested at least once a year, you won't meet the deadline.

How BeeLink helps

BeeLink's nFADP module pre-fills your processing register, generates DPAs from templates validated by Swiss lawyers, and automatically triggers the notification workflow in the event of an incident.

Ready to structure your compliance?

BeeLink centralizes your frameworks, questionnaires, policies and audit evidence in a single interface.

Try for free