Switzerland

Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)

56 controls. 321 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

56 controls 321 frameworks share controls with it Switzerland verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CH-FADP-01Scope and applicability of the Federal Act on Data Protection0
CH-FADP-02Principles of lawful processing107
CH-FADP-03Sensitive personal data and personality profiles0
CH-FADP-04Data subject access right107
CH-FADP-05Data accuracy and rectification107
CH-FADP-06Information security obligations0
CH-FADP-07Cross border data transfers0
CH-FADP-08Disclosure to third parties0
CH-FADP-09Notification of data files to the FDPIC65
CH-FADP-10Personality protection0
CH-FADP-11Outsourcing to processors0
CH-FADP-12Federal body specific obligations0
CH-FADP-13Right to object and request blocking133
CH-FADP-14Automated individual decisions and personality profiling0
CH-FADP-15Cooperation with the FDPIC121
CH-FADP-16Record keeping and accountability136
CH-FADP-17Workplace and employment data136
CH-FADP-18Sector specific rules63
CH-FADP-19Transparency and proactive information103
CH-FADP-20Sanctions and remedies under the FADP0
CH-FADP-21Data protection impact assessments178
CH-FADP-22Privacy by design and default58
CH-FADP-23Data processing agreements58
CH-FADP-24Cross-border transfer safeguards74
CH-FADP-25Compliance monitoring and auditing73
CH-FADP-26Training and awareness programs0
CH-FADP-27Regulatory reporting and cooperation0
CH-FADP-28Complaints handling and resolution0
CH-FADP-29Enforcement and penalties awareness0
FADP-1Purpose (Article 1)0
FADP-10Cross-Border Disclosure (Articles 16-18)53
FADP-11Duty to Inform (Article 19)102
FADP-12Right of Access (Article 25)102
FADP-13Right to Data Portability (Article 28)60
FADP-14Processing by Federal Bodies0
FADP-15Data Breach Notification167
FADP-16FDPIC Independence and Functions98
FADP-17Investigations and Enforcement0
FADP-18Criminal Penalties (Articles 60-66)0
FADP-19Transitional Provisions0
FADP-2Scope of Application (Article 2)0
FADP-3Territorial Scope (Article 3)0
FADP-4Exceptions (Article 4)0
FADP-5Definitions (Article 5)148
FADP-6Processing Principles (Articles 6-8)0
FADP-7Data Protection Impact Assessment (Articles 9-10)170
FADP-8Data Processing by Processors (Articles 11-13)0
FADP-9Data Protection Advisor (Articles 14-15)98
SWISSNFADP-1Scope, Extraterritorial Reach, Lawful Processing Principles0
SWISSNFADP-2Sensitive Data, Profiling, Children0
SWISSNFADP-3Data Subject Rights0
SWISSNFADP-4Privacy by Design, DPIA, Records of Processing0
SWISSNFADP-5Security of Processing0
SWISSNFADP-6Cross-Border Transfer and Processor Management0
SWISSNFADP-7DPO, FDPIC Cooperation, Notification0
SWISSNFADP-8Breach Notification, Enforcement, Criminal Penalties0

Tell me when Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • ISO management system documentation
  • External certification reports and surveillance audit findings
  • Nonconformity register with closure evidence
  • AI system inventory with risk classification
  • Model evaluation reports including bias and safety testing
  • AI ethics committee review records
  • Statutory mapping document linking definitions to internal terms

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition