| name | ch-fadp-expert |
| title | Swiss FADP Expert |
| description | Swiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notification, individual criminal enforcement, Swiss transfer mechanisms, and key divergences from GDPR. |
| author | GRCEngClub |
| author_url | https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/frameworks/ch-fadp/skills/ch-fadp-expert |
| license | MIT |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | ch |
| practice | data-protection |
| language | en |
Swiss FADP Expert
Deep expertise in the Swiss Federal Act on Data Protection (nFADP) — Switzerland's comprehensive data protection law revised in 2023.
Expertise Areas
Framework Overview
Swiss Federal Act on Data Protection (FADP) — Revised 2023 (nFADP/nDSG)
Effective Date: September 1, 2023
Scope: Protection of personality and fundamental rights relating to data processing
Articles: 60+ articles across 10 sections
Territorial Scope:
- Establishment: Swiss law applies to controllers/processors established in Switzerland
- Effects in Switzerland: Offers goods/services to Swiss data subjects OR monitors behavior in Switzerland
- Applies: Even if organization not in Switzerland
Material Scope:
- Automated processing of personal data
- Manual processing in filing systems
- Exemptions: Personal/household use, purely professional activities with limited risk
Switzerland is not an EU member state. The FDPIC (Federal Data Protection and Information Commissioner) is the Swiss supervisory authority, not an EU Data Protection Authority. Swiss adequacy decisions are separate from EU adequacy.
Enforcement Model:
- Individual criminal liability: Responsible individuals face criminal sanctions up to CHF 250,000
- Not entity-level fines: Enforcement targets the responsible person, not the legal entity
- FDPIC enforcement: Administrative orders and compliance measures
Key Obligations
Processing Records (RoPA)
- Controllers must maintain records of processing activities
- SME carve-out: Organizations with fewer than 250 employees may be exempt from full records UNLESS processing is likely to result in high risk to personality rights
- Content: Similar to GDPR Article 30 but streamlined for Swiss context
Privacy by Design and Default
- Controllers must implement appropriate technical and organizational measures
- Built-in privacy: At time of determining processing means and during processing itself
- Default settings: Most protective configuration by default
- : Data minimization, pseudonymization, transparency