The FADP for a Swiss SME, without exaggeration.
The revised act came into force on 1 September 2023. Here is what it actually requires, what it does not, and what exposes you to a sanction.
Many commercial publications wave the CHF 250,000 fine around without mentioning that it covers only three intentional behaviours. We prefer the exact version: it is less spectacular, but it lets you decide where to put your money.
What the law requires
- Security measures proportionate to the risk, and documented.
- A written contract with every processor that touches your data.
- Notification of a breach that creates a high risk for individuals.
- A written justification of your choices, which you can produce.
What it does not require
- No certification, no particular ISO standard.
- No record of processing below 250 staff, save in specific cases.
- No data protection officer for an ordinary SME.
The facts, in short
| Maximum fine | CHF 250,000 |
| Party liable | the individual |
| Condition | intentional breach |
| Breach notification | as soon as possible |
The article 61 fine covers only three intentional behaviours, and falls on the responsible individual.
Where do you stand?
Three questions, immediate answer, no email address.
Answer the three questions to see what applies to your situation.
The guides in this section
The guides in this section are being written.
Would you rather we handled it?
The compliance review does this sorting for you, in thirty minutes, and you leave with the written list of your gaps, ranked by severity.
Request a review