Guide
nFADP: what really changes
The 12 structural changes between the old FADP (1992) and the new Act (2023).
- Scope narrowed to natural persons only (legal entities are excluded)
- Concept of high-risk profiling
- Mandatory register of processing activities
- Impact assessment (DPIA) for high-risk processing
- Breach notification to the FDPIC within 72 hours
- Privacy by design & by default
- Enhanced right to information (data obtained indirectly)
- Criminal sanctions of up to CHF 250,000
- Explicit consent for sensitive data
- International transfers: adequacy decision or SCCs + TIA
- DPO recommended (not mandatory except for specific sectors)
- Data portability
Use this resource in BeeLink
Create your organization and import this template into your compliance workspace in one click.
Create an accountIn the same category
Getting started with ISO 27001 in 30 days
A concrete, week-by-week plan to lay the foundations of an ISO 27001:2022-compliant ISMS.
FINMA Circ. 2023/1 for non-lawyers
A plain-language breakdown of the operational risks and resilience circular.
DORA: mapping your ICT third parties
The register to produce, criticality criteria, and contractual requirements.