WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Europe

Switzerland Privacy & Data Protection Laws

Every regime below can apply to a business handling Switzerland residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Instead of GDPR's three itemized triggers, Art. 3 uses a broad 'effects doctrine': the Act applies to circumstances that have an effect in Switzerland, even if initiated abroad — official guidance treats this as reaching foreign controllers who offer goods/services to, or monitor, persons in Switzerland, but the statute itself frames it as a general causation test rather than discrete triggers. Exemptions are narrow: purely personal/household use, parliamentary deliberations, and diplomatic-immunity institutional beneficiaries — there is no general nonprofit, government, small-business, or health/financial exemption; federal bodies are themselves covered.

SR 235.1, Art. 2 (scope) and Art. 3 (territorial scope)Read regulation →

Cross-Border Data Transfer · 1

Art. 16 permits disclosure abroad only where the destination state guarantees adequate protection — and Switzerland maintains its OWN adequacy list, in Annex 1 to the Data Protection Ordinance, decided by the Federal Council. It largely overlaps with the EU's but is not identical and does not update in lockstep, so a controller subject to both regimes cannot assume an EU adequacy decision carries over. Where the destination is not listed, Art. 16(2) allows safeguards — standard clauses approved or recognised by the FDPIC, binding corporate rules, a treaty, or specific contractual clauses notified in advance to the FDPIC — and Art. 17 supplies narrow derogations, including disclosure necessary to establish, exercise, or enforce legal rights before a foreign court or, under the revised Act, another competent foreign authority. Businesses relying on the EU SCCs for Swiss data typically need the FDPIC's recognised adaptations rather than the EU text as-is.

SR 235.1, Arts. 16-17; Annex 1 to the Data Protection Ordinance (SR 235.11)Read regulation →

Data Security & Breach Notification · 1

Switzerland's trigger is deliberately narrower than the GDPR's and its clock is deliberately looser. Art. 24(1) requires notifying the FDPIC only where the breach is likely to result in a HIGH risk to the personality or fundamental rights of the data subject — so the many breaches that would be reportable in the EU under the 'any risk' test are not reportable here — and it sets no fixed hour count, requiring notification 'as soon as possible' instead of within 72 hours. Art. 24(4) requires informing affected individuals where that is necessary for their protection or where the FDPIC demands it. A business already running a GDPR breach process should not assume it can simply reuse the EU deadline as a Swiss one, in either direction: the Swiss threshold is higher but the Swiss timing standard is open-ended and the FDPIC's February 2025 guide sets out expectations on content that the statute does not.

SR 235.1, Art. 24; FDPIC guidance on reporting data security breaches (published February 7, 2025)Read regulation →

Other Europe jurisdictions