nFADP one year on: the 5 most common mistakes
One year after the new Federal Act on Data Protection (nFADP) came into force, we audited around a hundred Swiss organizations. Here are the mistakes that come up most often — and how to fix them without spending a whole quarter on it.
1. An incomplete processing register
Art. 12 nFADP requires most companies to keep a register of processing activities. Yet in 7 out of 10 cases, this register exists but overlooks HR processing, video surveillance, or marketing SaaS tools (HubSpot, Mailchimp, etc.).
To do: identify every piece of software in use, including free tools, and document purpose + legal basis + retention period.
2. The phantom DPO
Appointing a DPO (Data Protection Officer) without giving them time, budget, or access to decision-making bodies is effectively the same as not having one. The FDPIC treats this as de facto non-compliance.
3. Uncontracted subprocessors
Every provider that processes data on your behalf must be bound by a data processing agreement (DPA) specifying instructions, security, sub-subprocessors, and data location. A simple purchase order is not enough.
4. Untracked transfers outside Switzerland
Using AWS Frankfurt or Google Workspace means transferring data. If the destination country lacks an adequacy decision, you need Standard Contractual Clauses (SCCs) and a transfer impact assessment (TIA).
5. No data breach procedure
You have 72 hours to notify the FDPIC in the event of a high-risk breach. Without a written procedure, tested at least once a year, you won't meet the deadline.
How BeeLink helps
BeeLink's nFADP module pre-fills your processing register, generates DPAs from templates validated by Swiss lawyers, and automatically triggers the notification workflow in the event of an incident.
Ready to structure your compliance?
BeeLink centralizes your frameworks, questionnaires, policies and audit evidence in a single interface.
Try for free