Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
Evidence request list. 56 controls, 56 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Accountability
Per nFADP: Privacy by Design and by Default + DPIA for high risk + Records of Processing Activities + accountability framework.
- Swiss nFADP evidence for SWISSNFADP-4
- FDPIC + DPIA + criminal penalties partial
Breach
Per nFADP: breach notification to FDPIC + affected subjects + enforcement including criminal penalties for natural persons up to CHF 250k.
- Swiss nFADP evidence for SWISSNFADP-8
- FDPIC + DPIA + criminal penalties partial
Criminal Penalties and Transition
Criminal penalties up to CHF 250,000 for willful violations of key provisions
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Penalty exposure register with mitigation actions
- Sanction history log and remediation evidence
- Legal review memoranda on enforcement risk
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Enforcement risk register reactive rather than predictive
- Legal hold processes not aligned with sanctions register triggers
Transitional provisions for adapting existing processing to the new Act
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Penalty exposure register with mitigation actions
- Sanction history log and remediation evidence
- Legal review memoranda on enforcement risk
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Enforcement risk register reactive rather than predictive
- Legal hold processes not aligned with sanctions register triggers
Cross Border Disclosure and Duty to Inform
Conditions for disclosing personal data abroad including adequacy and safeguards
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- Transfer impact assessments missing for legacy data flows
- Standard contractual clauses not aligned to the current EU template version
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- DPIA triggers not embedded in change management workflow
Controllers must inform data subjects upon collection including identity, purpose, and recipients
- Consent capture records with timestamps and scope
- Data subject request log with response evidence
- Privacy notice versions with change history
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Consent capture mechanisms do not record granularity required by law
- Data subject request workflow exceeds statutory response deadlines
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
Cross-Border Transfer and Disclosure
Personal data may be transferred abroad only if the destination ensures an adequate level of protection or where contractual safeguards, binding corporate rules, or other approved mechanisms apply.
- Transfer mapping covering Swiss originated data flows
- Executed Swiss compatible standard contractual clauses
- FDPIC notification records where required
- Transfer impact assessments documenting safeguards
- Adequacy reference for destination countries
- Standard clauses not adapted to Swiss requirements
- Adequacy reliance not refreshed for changes in destination law
- FDPIC notifications not made where required
Disclosure of personal data to third parties is only permitted where justified by data subject consent, statutory authorization, or another legitimate interest, with stricter rules for sensitive personal data and personality profiles.
- Inventory of third party data sharing with legal basis
- Consent capture records for shared sensitive data
- Data sharing agreements with recipients
- Privacy notice disclosure of recipient categories
- Review process for new sharing arrangements
- Third party sharing not documented in inventory
- Sensitive data shared under implied consent
- Privacy notice silent on data sharing
Cross-border transfer safeguards. Control from Switzerland FADP framework, domain: Switzerland FADP: Data Governance.
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Transfer impact assessment records
- Standard contractual clauses and adequacy decision references
- Transfer register with safeguards documented
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Transfer impact assessments missing for legacy data flows
- Standard contractual clauses not aligned to the current EU template version
- DPIA triggers not embedded in change management workflow
Data Subject Rights
Any person may request information from the controller about whether data concerning them is being processed, and is entitled to receive the data, purpose, categories, recipients, and origin in a form that allows verification.
- Documented access request workflow including SLAs
- Standard response templates compliant with FADP
- Verification procedure for requester identity
- Log of past access requests and responses
- Training records for staff handling requests
- Response timelines undefined or inconsistent
- Templates do not include all required disclosures
- Verification process leaks personal data to third parties
Data subjects may object to processing carried out by private persons or federal bodies, and may request blocking, rectification, or deletion of data where the legal basis for processing no longer applies.
- Workflow for objections and blocking requests
- Documented criteria for accepting or rejecting requests
- Records of past objection outcomes and rationale
- Customer facing channels for submitting requests
- Audit trail of blocked or deleted records
- No distinct workflow for objection requests
- Criteria for refusal not documented
- Blocked data still appears in derived systems
Complaints handling and resolution. Control from Switzerland FADP framework, domain: Switzerland FADP: Accountability & Compliance.
- Centralised log aggregation configuration
- Log retention policy and archival evidence
- SIEM use-case catalogue and alert tuning history
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- AI inventory missing shadow deployments by business units
- Bias and safety testing not performed at required cadence
Right to request information about whether and what personal data is being processed
- Consent capture records with timestamps and scope
- Data subject request log with response evidence
- Privacy notice versions with change history
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Consent capture mechanisms do not record granularity required by law
- Data subject request workflow exceeds statutory response deadlines
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
Right to receive personal data in a commonly used electronic format or have it transferred
- Consent capture records with timestamps and scope
- Data subject request log with response evidence
- Privacy notice versions with change history
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Consent capture mechanisms do not record granularity required by law
- Data subject request workflow exceeds statutory response deadlines
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
FDPIC Cooperation and Enforcement
Controllers and processors must cooperate with the Federal Data Protection and Information Commissioner, including providing information and access during investigations and complying with recommendations issued by the FDPIC.
- Procedure for handling FDPIC inquiries
- Designated FDPIC liaison contact
- Records of past FDPIC correspondence and outcomes
- Process for implementing FDPIC recommendations
- Internal tracker for open regulator actions
- No documented liaison or escalation path
- FDPIC recommendations closed informally without records
- Cross border regulator engagement not coordinated
The FADP provides for civil and criminal penalties for breaches, including fines for failure to provide required information, ensure data security, or comply with FDPIC orders, with sanctions imposed on responsible individuals.
- Risk register tracking FADP exposure
- Insurance coverage analysis for civil and criminal sanctions
- Board level reporting on regulatory risk
- Remediation tracker for prior FDPIC findings
- Training records for officers and directors on sanction exposure
- Sanctions exposure not quantified
- Insurance excludes criminal sanctions
- Officer level briefings not conducted
Regulatory reporting and cooperation. Control from Switzerland FADP framework, domain: Switzerland FADP: Accountability & Compliance.
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- Centralised log aggregation configuration
- Log retention policy and archival evidence
- SIEM use-case catalogue and alert tuning history
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
Enforcement and penalties awareness. Control from Switzerland FADP framework, domain: Switzerland FADP: Accountability & Compliance.
- Internal audit charter and annual audit plan
- Audit working papers and finding registers
- Supervisory correspondence and response logs
- Annual training plan with completion records
- Awareness campaign content and attestations
- Competency assessment results
- Training completion tracked but not role-tailored
- Awareness messaging not tested for retention or behavioural change
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Enforcement risk register reactive rather than predictive
FDPIC Supervision and Enforcement
Independence, functions, and powers of the Federal Data Protection and Information Commissioner
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Documentation exists but lacks evidence of periodic refresh
Investigatory powers and ability to issue orders for compliance
- Internal audit charter and annual audit plan
- Audit working papers and finding registers
- Supervisory correspondence and response logs
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Documentation exists but lacks evidence of periodic refresh
Federal Bodies and Breach Notification
Specific rules for data processing by federal government bodies
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Documentation exists but lacks evidence of periodic refresh
Obligation to notify the FDPIC of data security breaches as quickly as possible
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- Incident response plan with tested playbooks
- Incident tickets with timeline and root-cause analysis
- Breach notification templates and regulator submission logs
- Notification timelines exceed statutory thresholds in practice
- Root-cause analysis not consistently completed for severity 2 incidents
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
Federal Bodies and Sector Specific Rules
Federal bodies may process personal data only if there is a statutory basis, with additional rules on automated decisions, linkage of data files, and disclosure to other federal bodies or cantonal authorities.
- Statutory basis register for federal body processing activities
- Approval records for linkage of data files
- Disclosure logs to other federal bodies
- Automated decision making oversight evidence
- Periodic legal review of statutory mandates
- Statutory basis references stale legislation
- Linkage of data files lacks documented authorization
- Automated decisions implemented without human review path
Specific sectors such as banking, healthcare, and telecommunications are subject to additional confidentiality and processing rules beyond the FADP, requiring coordinated compliance across legal frameworks.
- Mapping of sector specific legal requirements to FADP obligations
- Privacy program structure addressing sector overlays
- Coordination procedure with regulated business units
- Records of regulator interactions in relevant sectors
- Periodic legal review covering sector specific updates
- Sector specific overlays managed in legal silo without privacy coordination
- Banking secrecy or medical secrecy treated independently of FADP
- No central tracker for sector specific obligations
Governance
Per nFADP: DPO + FDPIC engagement + processing notification where required + training.
- Swiss nFADP evidence for SWISSNFADP-7
- FDPIC + DPIA + criminal penalties partial
Governance, Records and Accountability
Owners of data files who regularly process sensitive personal data or personality profiles or who regularly disclose personal data to third parties must register their data files with the Federal Data Protection and Information Commissioner.
- Data file inventory with assessment of notification obligation
- FDPIC notification submissions for applicable data files
- Annual review of notification status
- Internal procedure for triggering notifications upon new data files
- Confirmation records from FDPIC where issued
- Notification obligation not assessed for legacy data files
- No process for triggering new notifications
- Notifications not refreshed after material changes
Persons processing personal data should maintain records sufficient to demonstrate compliance with the Act, including purposes, categories, retention, and protective measures applied to the data.
- Records of processing activities tailored to FADP
- Annual compliance attestations from business units
- Documentation of decisions involving sensitive data and personality profiles
- Internal audit reports covering FADP compliance
- Process documentation for keeping records current
- Records limited to GDPR Article 30 view without FADP specifics
- No annual attestation cycle
- Internal audit excludes Swiss processing scope
Compliance monitoring and auditing. Control from Switzerland FADP framework, domain: Switzerland FADP: Accountability & Compliance.
- Internal audit charter and annual audit plan
- Audit working papers and finding registers
- Supervisory correspondence and response logs
- Centralised log aggregation configuration
- Log retention policy and archival evidence
- SIEM use-case catalogue and alert tuning history
- Internal audit coverage skews to financial controls rather than full scope
- Log retention periods inconsistent across systems
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
Training and awareness programs. Control from Switzerland FADP framework, domain: Switzerland FADP: Accountability & Compliance.
- Annual training plan with completion records
- Awareness campaign content and attestations
- Competency assessment results
- Centralised log aggregation configuration
- Log retention policy and archival evidence
- SIEM use-case catalogue and alert tuning history
- Training completion tracked but not role-tailored
- Awareness messaging not tested for retention or behavioural change
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- AI inventory missing shadow deployments by business units
Processing Principles and Impact Assessment
Principles of lawfulness, good faith, proportionality, purpose limitation, and accuracy
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Documentation exists but lacks evidence of periodic refresh
Requirements for conducting DPIAs when processing carries high risk to data subjects
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Documentation exists but lacks evidence of periodic refresh
Processors and Contracts
Processing of personal data may be assigned to third parties by agreement or by law, provided the controller ensures the processor maintains the same security and data protection obligations as the controller.
- Data processing agreements with FADP aligned obligations
- Vendor due diligence questionnaires and review records
- Processor security attestation evidence
- Audit logs of processor activity where available
- Subprocessor approvals and inventories
- Processor agreements inherited from foreign templates without FADP alignment
- No vendor due diligence prior to onboarding
- Subprocessor changes proceed without approval
Data processing agreements. Control from Switzerland FADP framework, domain: Switzerland FADP: Data Governance.
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
Processors and Data Protection Advisors
Rules for engaging processors including contractual requirements and security obligations
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Third-party risk assessment dossier per vendor
- Signed contracts with required protection clauses
- Ongoing assurance reports (SOC 2, ISO, audit findings)
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Documentation exists but lacks evidence of periodic refresh
Appointment of representative for foreign controllers and data protection advisors
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Documentation exists but lacks evidence of periodic refresh
Purpose, Scope and Definitions
Protection of the personality and fundamental rights of persons whose personal data is processed
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Statutory mapping document linking definitions to internal terms
- Scope statement signed by accountable owner
- Glossary version control with effective dates
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Internal terminology drifts from statutory definitions
- Scope statement not refreshed after recent acquisitions or divestments
Applies to private persons and federal bodies processing data of natural persons
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Statutory mapping document linking definitions to internal terms
- Scope statement signed by accountable owner
- Glossary version control with effective dates
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Internal terminology drifts from statutory definitions
- Scope statement not refreshed after recent acquisitions or divestments
Applies to matters that produce effects in Switzerland even if initiated abroad
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Statutory mapping document linking definitions to internal terms
- Scope statement signed by accountable owner
- Glossary version control with effective dates
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Internal terminology drifts from statutory definitions
- Scope statement not refreshed after recent acquisitions or divestments
Exceptions for data processing by natural persons for exclusively personal use
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Statutory mapping document linking definitions to internal terms
- Scope statement signed by accountable owner
- Glossary version control with effective dates
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Internal terminology drifts from statutory definitions
- Scope statement not refreshed after recent acquisitions or divestments
Defines personal data, data subject, processing, controller, processor, and other key terms
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
- Internal terminology drifts from statutory definitions
- Scope statement not refreshed after recent acquisitions or divestments
Rights
Per nFADP: data subject rights including access + rectification + erasure + restriction + portability + object + automated decision review.
- Swiss nFADP evidence for SWISSNFADP-3
- FDPIC + DPIA + criminal penalties partial
Scope
Per Switzerland new Federal Act on Data Protection (nFADP/nDSG) effective 1 Sep 2023: scope. Requirements include (a) determine scope including extraterritorial reach where processing affects Swiss data subjects + (b) lawful processing principles including good faith + proportionality + purpose limitation + accuracy + (c) align with FDPIC (Federal Data Protection and Information Commissioner).
- Swiss nFADP evidence for SWISSNFADP-1
- FDPIC + DPIA + criminal penalties partial
Scope and Processing Principles
The Federal Act on Data Protection regulates the processing of personal data by private persons and federal bodies, with extraterritorial application where processing affects data subjects in Switzerland.
- Documented analysis of Swiss processing activities and data subject locations
- Mapping of corporate entities and federal body interactions to FADP scope
- Privacy governance memo confirming FADP applicability
- Inventory of Swiss data subjects and product offerings
- Decision log for designation of Swiss representative where applicable
- Scope analysis predates Swiss expansion or new product launches
- No identification of Swiss representative obligations
- Federal bodies and private sector requirements conflated
Personal data must be processed lawfully, in good faith, and in proportion to the purpose, with collection in a manner recognizable to data subjects and processing limited to declared or evident purposes.
- Privacy policy describing processing purposes for Swiss data subjects
- Internal procedure documenting application of principles in design decisions
- Records of purpose limitation analysis for new processing activities
- Proportionality assessment templates
- Training materials covering FADP processing principles
- Purpose creep with no formal reassessment
- Privacy notice does not clearly state processing purposes
- No proportionality analysis on file for high impact processing
Controllers must take all reasonable steps to ensure that personal data is accurate and up to date, with mechanisms for data subjects to rectify incorrect data and to have unlawfully processed data destroyed or corrected.
- Documented accuracy validation procedures by data set
- Rectification workflow with audit trail
- Periodic data quality review evidence
- Customer facing self service correction tools where applicable
- Records of erasure or correction tickets and outcomes
- No periodic data quality review
- Rectifications handled informally without records
- Self service tools do not propagate corrections to downstream systems
Controllers must provide data subjects with sufficient information about data processing in a manner that allows them to assert their rights, with clear notice when sensitive data is collected.
- Swiss privacy notice covering all required elements
- Layered notices for product specific contexts
- Translations into German, French, and Italian where appropriate
- Stakeholder review evidence for clarity and accuracy
- Records of updates and notification to data subjects
- Privacy notice available only in English
- Layered notices missing for sensitive collection points
- Notice updates not communicated to existing data subjects
Security
Per nFADP: appropriate technical + organisational measures + risk-based + integrity + confidentiality + availability.
- Swiss nFADP evidence for SWISSNFADP-5
- FDPIC + DPIA + criminal penalties partial
Security of Processing
Persons processing personal data must protect that data against unauthorized processing through appropriate technical and organizational measures, proportionate to the risk and state of the art.
- Information security policy and standards covering Swiss processing
- Risk assessment for Swiss data processing systems
- Independent assurance such as ISO IEC 27001 or SOC 2
- Penetration test and vulnerability scan results
- Records of remediation tracking for identified weaknesses
- Security controls inherited from group standard without Swiss risk review
- Penetration tests exclude Swiss hosted assets
- Remediation backlog with aged findings
Data protection impact assessments. Control from Switzerland FADP framework, domain: Switzerland FADP: Data Governance.
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
Privacy by design and default. Control from Switzerland FADP framework, domain: Switzerland FADP: Data Governance.
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Data protection impact assessment register and outputs
- Appointment and reporting line evidence for the data protection advisor
- FDPIC correspondence and notification records
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- DPIA triggers not embedded in change management workflow
- Advisor reporting line does not preserve independence
Sensitive
Per nFADP: sensitive personal data including health + biometric + genetic + religious + political + sexual orientation + criminal + (b) profiling with high risk + (c) children's data.
- Swiss nFADP evidence for SWISSNFADP-2
- FDPIC + DPIA + criminal penalties partial
Sensitive Data and Profiling
Processing of sensitive personal data and personality profiles requires explicit consent or another statutory basis, with stricter safeguards including limitations on disclosure to third parties.
- Inventory of sensitive data and personality profile processing activities
- Explicit consent capture records with timestamp and language
- Access controls and encryption for sensitive data stores
- DPIA equivalent assessments for sensitive processing
- Internal policy prohibiting unnecessary collection of sensitive data
- Sensitive data captured in free text without flagging
- Personality profiles built from analytics without explicit basis
- Sensitive data shared with vendors without consent
Personal data processing must not unlawfully infringe the personality rights of data subjects, with civil law remedies available for unlawful processing, including injunctions, damages, and rectification.
- Internal procedure for handling personality rights complaints
- Litigation register including past Swiss personality rights matters
- Insurance documentation for civil liabilities
- Customer facing complaint channel
- Records of injunction or damage settlements
- No defined intake for personality rights claims
- Insurance excludes personality rights damages
- Legal team unaware of Swiss specific remedies
Decisions producing legal effects or significantly affecting a data subject and based exclusively on automated processing must be subject to safeguards, including transparency, the right to express a view, and human review.
- Inventory of automated decisioning systems affecting Swiss data subjects
- Notice provided to data subjects about automated decisions
- Process for requesting human review
- DPIA or equivalent assessment for automated decisioning
- Audit logs of automated decisions and overrides
- Notice missing or buried in generic privacy policy
- Human review channel not staffed
- No DPIA for credit scoring or risk scoring
Employers may process employee personal data only to the extent necessary for the employment relationship, with additional protections for sensitive data, monitoring, and the personality rights of employees.
- Employee privacy notice in language of the workplace
- Workplace monitoring policy referencing Swiss law
- Necessity assessment for monitoring tools
- Consultation evidence with employee representatives where applicable
- Retention schedule for employment records
- Monitoring policy generic and not Swiss specific
- No necessity test for monitoring tools
- Sensitive HR data retained beyond statutory limits
Transfer
Per nFADP: cross-border transfer including FDPIC list + SCCs + BCRs + consent + adequacy.
- Swiss nFADP evidence for SWISSNFADP-6
- FDPIC + DPIA + criminal penalties partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.