Skip to content

Evidence request lists

Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)

Evidence request list. 56 controls, 56 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Accountability

SWISSNFADP-4
Privacy by Design, DPIA, Records of Processing

Per nFADP: Privacy by Design and by Default + DPIA for high risk + Records of Processing Activities + accountability framework.

Artefacts an auditor will ask for
  • Swiss nFADP evidence for SWISSNFADP-4
Where this commonly fails
  • FDPIC + DPIA + criminal penalties partial

Breach

SWISSNFADP-8
Breach Notification, Enforcement, Criminal Penalties

Per nFADP: breach notification to FDPIC + affected subjects + enforcement including criminal penalties for natural persons up to CHF 250k.

Artefacts an auditor will ask for
  • Swiss nFADP evidence for SWISSNFADP-8
Where this commonly fails
  • FDPIC + DPIA + criminal penalties partial

Criminal Penalties and Transition

FADP-18
Criminal Penalties (Articles 60-66)

Criminal penalties up to CHF 250,000 for willful violations of key provisions

Artefacts an auditor will ask for
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
  • Penalty exposure register with mitigation actions
  • Sanction history log and remediation evidence
  • Legal review memoranda on enforcement risk
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Enforcement risk register reactive rather than predictive
  • Legal hold processes not aligned with sanctions register triggers
FADP-19
Transitional Provisions

Transitional provisions for adapting existing processing to the new Act

Artefacts an auditor will ask for
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
  • Penalty exposure register with mitigation actions
  • Sanction history log and remediation evidence
  • Legal review memoranda on enforcement risk
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Enforcement risk register reactive rather than predictive
  • Legal hold processes not aligned with sanctions register triggers

Cross Border Disclosure and Duty to Inform

FADP-10
Cross-Border Disclosure (Articles 16-18)

Conditions for disclosing personal data abroad including adequacy and safeguards

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
Where this commonly fails
  • Transfer impact assessments missing for legacy data flows
  • Standard contractual clauses not aligned to the current EU template version
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • DPIA triggers not embedded in change management workflow
FADP-11
Duty to Inform (Article 19)

Controllers must inform data subjects upon collection including identity, purpose, and recipients

Artefacts an auditor will ask for
  • Consent capture records with timestamps and scope
  • Data subject request log with response evidence
  • Privacy notice versions with change history
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • Consent capture mechanisms do not record granularity required by law
  • Data subject request workflow exceeds statutory response deadlines
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence

Cross-Border Transfer and Disclosure

CH-FADP-07
Cross border data transfers

Personal data may be transferred abroad only if the destination ensures an adequate level of protection or where contractual safeguards, binding corporate rules, or other approved mechanisms apply.

Artefacts an auditor will ask for
  • Transfer mapping covering Swiss originated data flows
  • Executed Swiss compatible standard contractual clauses
  • FDPIC notification records where required
  • Transfer impact assessments documenting safeguards
  • Adequacy reference for destination countries
Where this commonly fails
  • Standard clauses not adapted to Swiss requirements
  • Adequacy reliance not refreshed for changes in destination law
  • FDPIC notifications not made where required
CH-FADP-08
Disclosure to third parties

Disclosure of personal data to third parties is only permitted where justified by data subject consent, statutory authorization, or another legitimate interest, with stricter rules for sensitive personal data and personality profiles.

Artefacts an auditor will ask for
  • Inventory of third party data sharing with legal basis
  • Consent capture records for shared sensitive data
  • Data sharing agreements with recipients
  • Privacy notice disclosure of recipient categories
  • Review process for new sharing arrangements
Where this commonly fails
  • Third party sharing not documented in inventory
  • Sensitive data shared under implied consent
  • Privacy notice silent on data sharing
CH-FADP-24
Cross-border transfer safeguards

Cross-border transfer safeguards. Control from Switzerland FADP framework, domain: Switzerland FADP: Data Governance.

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Transfer impact assessment records
  • Standard contractual clauses and adequacy decision references
  • Transfer register with safeguards documented
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Transfer impact assessments missing for legacy data flows
  • Standard contractual clauses not aligned to the current EU template version
  • DPIA triggers not embedded in change management workflow

Data Subject Rights

CH-FADP-04
Data subject access right

Any person may request information from the controller about whether data concerning them is being processed, and is entitled to receive the data, purpose, categories, recipients, and origin in a form that allows verification.

Artefacts an auditor will ask for
  • Documented access request workflow including SLAs
  • Standard response templates compliant with FADP
  • Verification procedure for requester identity
  • Log of past access requests and responses
  • Training records for staff handling requests
Where this commonly fails
  • Response timelines undefined or inconsistent
  • Templates do not include all required disclosures
  • Verification process leaks personal data to third parties
CH-FADP-13
Right to object and request blocking

Data subjects may object to processing carried out by private persons or federal bodies, and may request blocking, rectification, or deletion of data where the legal basis for processing no longer applies.

Artefacts an auditor will ask for
  • Workflow for objections and blocking requests
  • Documented criteria for accepting or rejecting requests
  • Records of past objection outcomes and rationale
  • Customer facing channels for submitting requests
  • Audit trail of blocked or deleted records
Where this commonly fails
  • No distinct workflow for objection requests
  • Criteria for refusal not documented
  • Blocked data still appears in derived systems
CH-FADP-28
Complaints handling and resolution

Complaints handling and resolution. Control from Switzerland FADP framework, domain: Switzerland FADP: Accountability & Compliance.

Artefacts an auditor will ask for
  • Centralised log aggregation configuration
  • Log retention policy and archival evidence
  • SIEM use-case catalogue and alert tuning history
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • AI inventory missing shadow deployments by business units
  • Bias and safety testing not performed at required cadence
FADP-12
Right of Access (Article 25)

Right to request information about whether and what personal data is being processed

Artefacts an auditor will ask for
  • Consent capture records with timestamps and scope
  • Data subject request log with response evidence
  • Privacy notice versions with change history
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • Consent capture mechanisms do not record granularity required by law
  • Data subject request workflow exceeds statutory response deadlines
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
FADP-13
Right to Data Portability (Article 28)

Right to receive personal data in a commonly used electronic format or have it transferred

Artefacts an auditor will ask for
  • Consent capture records with timestamps and scope
  • Data subject request log with response evidence
  • Privacy notice versions with change history
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • Consent capture mechanisms do not record granularity required by law
  • Data subject request workflow exceeds statutory response deadlines
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence

FDPIC Cooperation and Enforcement

CH-FADP-15
Cooperation with the FDPIC

Controllers and processors must cooperate with the Federal Data Protection and Information Commissioner, including providing information and access during investigations and complying with recommendations issued by the FDPIC.

Artefacts an auditor will ask for
  • Procedure for handling FDPIC inquiries
  • Designated FDPIC liaison contact
  • Records of past FDPIC correspondence and outcomes
  • Process for implementing FDPIC recommendations
  • Internal tracker for open regulator actions
Where this commonly fails
  • No documented liaison or escalation path
  • FDPIC recommendations closed informally without records
  • Cross border regulator engagement not coordinated
CH-FADP-20
Sanctions and remedies under the FADP

The FADP provides for civil and criminal penalties for breaches, including fines for failure to provide required information, ensure data security, or comply with FDPIC orders, with sanctions imposed on responsible individuals.

Artefacts an auditor will ask for
  • Risk register tracking FADP exposure
  • Insurance coverage analysis for civil and criminal sanctions
  • Board level reporting on regulatory risk
  • Remediation tracker for prior FDPIC findings
  • Training records for officers and directors on sanction exposure
Where this commonly fails
  • Sanctions exposure not quantified
  • Insurance excludes criminal sanctions
  • Officer level briefings not conducted
CH-FADP-27
Regulatory reporting and cooperation

Regulatory reporting and cooperation. Control from Switzerland FADP framework, domain: Switzerland FADP: Accountability & Compliance.

Artefacts an auditor will ask for
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
  • Centralised log aggregation configuration
  • Log retention policy and archival evidence
  • SIEM use-case catalogue and alert tuning history
Where this commonly fails
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
CH-FADP-29
Enforcement and penalties awareness

Enforcement and penalties awareness. Control from Switzerland FADP framework, domain: Switzerland FADP: Accountability & Compliance.

Artefacts an auditor will ask for
  • Internal audit charter and annual audit plan
  • Audit working papers and finding registers
  • Supervisory correspondence and response logs
  • Annual training plan with completion records
  • Awareness campaign content and attestations
  • Competency assessment results
Where this commonly fails
  • Training completion tracked but not role-tailored
  • Awareness messaging not tested for retention or behavioural change
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Enforcement risk register reactive rather than predictive

FDPIC Supervision and Enforcement

FADP-16
FDPIC Independence and Functions

Independence, functions, and powers of the Federal Data Protection and Information Commissioner

Artefacts an auditor will ask for
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Documentation exists but lacks evidence of periodic refresh
FADP-17
Investigations and Enforcement

Investigatory powers and ability to issue orders for compliance

Artefacts an auditor will ask for
  • Internal audit charter and annual audit plan
  • Audit working papers and finding registers
  • Supervisory correspondence and response logs
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Documentation exists but lacks evidence of periodic refresh

Federal Bodies and Breach Notification

FADP-14
Processing by Federal Bodies

Specific rules for data processing by federal government bodies

Artefacts an auditor will ask for
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Documentation exists but lacks evidence of periodic refresh
FADP-15
Data Breach Notification

Obligation to notify the FDPIC of data security breaches as quickly as possible

Artefacts an auditor will ask for
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
  • Incident response plan with tested playbooks
  • Incident tickets with timeline and root-cause analysis
  • Breach notification templates and regulator submission logs
Where this commonly fails
  • Notification timelines exceed statutory thresholds in practice
  • Root-cause analysis not consistently completed for severity 2 incidents
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence

Federal Bodies and Sector Specific Rules

CH-FADP-12
Federal body specific obligations

Federal bodies may process personal data only if there is a statutory basis, with additional rules on automated decisions, linkage of data files, and disclosure to other federal bodies or cantonal authorities.

Artefacts an auditor will ask for
  • Statutory basis register for federal body processing activities
  • Approval records for linkage of data files
  • Disclosure logs to other federal bodies
  • Automated decision making oversight evidence
  • Periodic legal review of statutory mandates
Where this commonly fails
  • Statutory basis references stale legislation
  • Linkage of data files lacks documented authorization
  • Automated decisions implemented without human review path
CH-FADP-18
Sector specific rules

Specific sectors such as banking, healthcare, and telecommunications are subject to additional confidentiality and processing rules beyond the FADP, requiring coordinated compliance across legal frameworks.

Artefacts an auditor will ask for
  • Mapping of sector specific legal requirements to FADP obligations
  • Privacy program structure addressing sector overlays
  • Coordination procedure with regulated business units
  • Records of regulator interactions in relevant sectors
  • Periodic legal review covering sector specific updates
Where this commonly fails
  • Sector specific overlays managed in legal silo without privacy coordination
  • Banking secrecy or medical secrecy treated independently of FADP
  • No central tracker for sector specific obligations

Governance

SWISSNFADP-7
DPO, FDPIC Cooperation, Notification

Per nFADP: DPO + FDPIC engagement + processing notification where required + training.

Artefacts an auditor will ask for
  • Swiss nFADP evidence for SWISSNFADP-7
Where this commonly fails
  • FDPIC + DPIA + criminal penalties partial

Governance, Records and Accountability

CH-FADP-09
Notification of data files to the FDPIC

Owners of data files who regularly process sensitive personal data or personality profiles or who regularly disclose personal data to third parties must register their data files with the Federal Data Protection and Information Commissioner.

Artefacts an auditor will ask for
  • Data file inventory with assessment of notification obligation
  • FDPIC notification submissions for applicable data files
  • Annual review of notification status
  • Internal procedure for triggering notifications upon new data files
  • Confirmation records from FDPIC where issued
Where this commonly fails
  • Notification obligation not assessed for legacy data files
  • No process for triggering new notifications
  • Notifications not refreshed after material changes
CH-FADP-16
Record keeping and accountability

Persons processing personal data should maintain records sufficient to demonstrate compliance with the Act, including purposes, categories, retention, and protective measures applied to the data.

Artefacts an auditor will ask for
  • Records of processing activities tailored to FADP
  • Annual compliance attestations from business units
  • Documentation of decisions involving sensitive data and personality profiles
  • Internal audit reports covering FADP compliance
  • Process documentation for keeping records current
Where this commonly fails
  • Records limited to GDPR Article 30 view without FADP specifics
  • No annual attestation cycle
  • Internal audit excludes Swiss processing scope
CH-FADP-25
Compliance monitoring and auditing

Compliance monitoring and auditing. Control from Switzerland FADP framework, domain: Switzerland FADP: Accountability & Compliance.

Artefacts an auditor will ask for
  • Internal audit charter and annual audit plan
  • Audit working papers and finding registers
  • Supervisory correspondence and response logs
  • Centralised log aggregation configuration
  • Log retention policy and archival evidence
  • SIEM use-case catalogue and alert tuning history
Where this commonly fails
  • Internal audit coverage skews to financial controls rather than full scope
  • Log retention periods inconsistent across systems
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
CH-FADP-26
Training and awareness programs

Training and awareness programs. Control from Switzerland FADP framework, domain: Switzerland FADP: Accountability & Compliance.

Artefacts an auditor will ask for
  • Annual training plan with completion records
  • Awareness campaign content and attestations
  • Competency assessment results
  • Centralised log aggregation configuration
  • Log retention policy and archival evidence
  • SIEM use-case catalogue and alert tuning history
Where this commonly fails
  • Training completion tracked but not role-tailored
  • Awareness messaging not tested for retention or behavioural change
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • AI inventory missing shadow deployments by business units

Processing Principles and Impact Assessment

FADP-6
Processing Principles (Articles 6-8)

Principles of lawfulness, good faith, proportionality, purpose limitation, and accuracy

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Documentation exists but lacks evidence of periodic refresh
FADP-7
Data Protection Impact Assessment (Articles 9-10)

Requirements for conducting DPIAs when processing carries high risk to data subjects

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Documentation exists but lacks evidence of periodic refresh

Processors and Contracts

CH-FADP-11
Outsourcing to processors

Processing of personal data may be assigned to third parties by agreement or by law, provided the controller ensures the processor maintains the same security and data protection obligations as the controller.

Artefacts an auditor will ask for
  • Data processing agreements with FADP aligned obligations
  • Vendor due diligence questionnaires and review records
  • Processor security attestation evidence
  • Audit logs of processor activity where available
  • Subprocessor approvals and inventories
Where this commonly fails
  • Processor agreements inherited from foreign templates without FADP alignment
  • No vendor due diligence prior to onboarding
  • Subprocessor changes proceed without approval
CH-FADP-23
Data processing agreements

Data processing agreements. Control from Switzerland FADP framework, domain: Switzerland FADP: Data Governance.

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence

Processors and Data Protection Advisors

FADP-8
Data Processing by Processors (Articles 11-13)

Rules for engaging processors including contractual requirements and security obligations

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Third-party risk assessment dossier per vendor
  • Signed contracts with required protection clauses
  • Ongoing assurance reports (SOC 2, ISO, audit findings)
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Documentation exists but lacks evidence of periodic refresh
FADP-9
Data Protection Advisor (Articles 14-15)

Appointment of representative for foreign controllers and data protection advisors

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Documentation exists but lacks evidence of periodic refresh

Purpose, Scope and Definitions

FADP-1
Purpose (Article 1)

Protection of the personality and fundamental rights of persons whose personal data is processed

Artefacts an auditor will ask for
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
  • Statutory mapping document linking definitions to internal terms
  • Scope statement signed by accountable owner
  • Glossary version control with effective dates
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Internal terminology drifts from statutory definitions
  • Scope statement not refreshed after recent acquisitions or divestments
FADP-2
Scope of Application (Article 2)

Applies to private persons and federal bodies processing data of natural persons

Artefacts an auditor will ask for
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
  • Statutory mapping document linking definitions to internal terms
  • Scope statement signed by accountable owner
  • Glossary version control with effective dates
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Internal terminology drifts from statutory definitions
  • Scope statement not refreshed after recent acquisitions or divestments
FADP-3
Territorial Scope (Article 3)

Applies to matters that produce effects in Switzerland even if initiated abroad

Artefacts an auditor will ask for
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
  • Statutory mapping document linking definitions to internal terms
  • Scope statement signed by accountable owner
  • Glossary version control with effective dates
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Internal terminology drifts from statutory definitions
  • Scope statement not refreshed after recent acquisitions or divestments
FADP-4
Exceptions (Article 4)

Exceptions for data processing by natural persons for exclusively personal use

Artefacts an auditor will ask for
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
  • Statutory mapping document linking definitions to internal terms
  • Scope statement signed by accountable owner
  • Glossary version control with effective dates
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Internal terminology drifts from statutory definitions
  • Scope statement not refreshed after recent acquisitions or divestments
FADP-5
Definitions (Article 5)

Defines personal data, data subject, processing, controller, processor, and other key terms

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
  • Internal terminology drifts from statutory definitions
  • Scope statement not refreshed after recent acquisitions or divestments

Rights

SWISSNFADP-3
Data Subject Rights

Per nFADP: data subject rights including access + rectification + erasure + restriction + portability + object + automated decision review.

Artefacts an auditor will ask for
  • Swiss nFADP evidence for SWISSNFADP-3
Where this commonly fails
  • FDPIC + DPIA + criminal penalties partial

Scope

SWISSNFADP-1
Scope, Extraterritorial Reach, Lawful Processing Principles

Per Switzerland new Federal Act on Data Protection (nFADP/nDSG) effective 1 Sep 2023: scope. Requirements include (a) determine scope including extraterritorial reach where processing affects Swiss data subjects + (b) lawful processing principles including good faith + proportionality + purpose limitation + accuracy + (c) align with FDPIC (Federal Data Protection and Information Commissioner).

Artefacts an auditor will ask for
  • Swiss nFADP evidence for SWISSNFADP-1
Where this commonly fails
  • FDPIC + DPIA + criminal penalties partial

Scope and Processing Principles

CH-FADP-01
Scope and applicability of the Federal Act on Data Protection

The Federal Act on Data Protection regulates the processing of personal data by private persons and federal bodies, with extraterritorial application where processing affects data subjects in Switzerland.

Artefacts an auditor will ask for
  • Documented analysis of Swiss processing activities and data subject locations
  • Mapping of corporate entities and federal body interactions to FADP scope
  • Privacy governance memo confirming FADP applicability
  • Inventory of Swiss data subjects and product offerings
  • Decision log for designation of Swiss representative where applicable
Where this commonly fails
  • Scope analysis predates Swiss expansion or new product launches
  • No identification of Swiss representative obligations
  • Federal bodies and private sector requirements conflated
CH-FADP-02
Principles of lawful processing

Personal data must be processed lawfully, in good faith, and in proportion to the purpose, with collection in a manner recognizable to data subjects and processing limited to declared or evident purposes.

Artefacts an auditor will ask for
  • Privacy policy describing processing purposes for Swiss data subjects
  • Internal procedure documenting application of principles in design decisions
  • Records of purpose limitation analysis for new processing activities
  • Proportionality assessment templates
  • Training materials covering FADP processing principles
Where this commonly fails
  • Purpose creep with no formal reassessment
  • Privacy notice does not clearly state processing purposes
  • No proportionality analysis on file for high impact processing
CH-FADP-05
Data accuracy and rectification

Controllers must take all reasonable steps to ensure that personal data is accurate and up to date, with mechanisms for data subjects to rectify incorrect data and to have unlawfully processed data destroyed or corrected.

Artefacts an auditor will ask for
  • Documented accuracy validation procedures by data set
  • Rectification workflow with audit trail
  • Periodic data quality review evidence
  • Customer facing self service correction tools where applicable
  • Records of erasure or correction tickets and outcomes
Where this commonly fails
  • No periodic data quality review
  • Rectifications handled informally without records
  • Self service tools do not propagate corrections to downstream systems
CH-FADP-19
Transparency and proactive information

Controllers must provide data subjects with sufficient information about data processing in a manner that allows them to assert their rights, with clear notice when sensitive data is collected.

Artefacts an auditor will ask for
  • Swiss privacy notice covering all required elements
  • Layered notices for product specific contexts
  • Translations into German, French, and Italian where appropriate
  • Stakeholder review evidence for clarity and accuracy
  • Records of updates and notification to data subjects
Where this commonly fails
  • Privacy notice available only in English
  • Layered notices missing for sensitive collection points
  • Notice updates not communicated to existing data subjects

Security

SWISSNFADP-5
Security of Processing

Per nFADP: appropriate technical + organisational measures + risk-based + integrity + confidentiality + availability.

Artefacts an auditor will ask for
  • Swiss nFADP evidence for SWISSNFADP-5
Where this commonly fails
  • FDPIC + DPIA + criminal penalties partial

Security of Processing

CH-FADP-06
Information security obligations

Persons processing personal data must protect that data against unauthorized processing through appropriate technical and organizational measures, proportionate to the risk and state of the art.

Artefacts an auditor will ask for
  • Information security policy and standards covering Swiss processing
  • Risk assessment for Swiss data processing systems
  • Independent assurance such as ISO IEC 27001 or SOC 2
  • Penetration test and vulnerability scan results
  • Records of remediation tracking for identified weaknesses
Where this commonly fails
  • Security controls inherited from group standard without Swiss risk review
  • Penetration tests exclude Swiss hosted assets
  • Remediation backlog with aged findings
CH-FADP-21
Data protection impact assessments

Data protection impact assessments. Control from Switzerland FADP framework, domain: Switzerland FADP: Data Governance.

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence
CH-FADP-22
Privacy by design and default

Privacy by design and default. Control from Switzerland FADP framework, domain: Switzerland FADP: Data Governance.

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Data protection impact assessment register and outputs
  • Appointment and reporting line evidence for the data protection advisor
  • FDPIC correspondence and notification records
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • DPIA triggers not embedded in change management workflow
  • Advisor reporting line does not preserve independence

Sensitive

SWISSNFADP-2
Sensitive Data, Profiling, Children

Per nFADP: sensitive personal data including health + biometric + genetic + religious + political + sexual orientation + criminal + (b) profiling with high risk + (c) children's data.

Artefacts an auditor will ask for
  • Swiss nFADP evidence for SWISSNFADP-2
Where this commonly fails
  • FDPIC + DPIA + criminal penalties partial

Sensitive Data and Profiling

CH-FADP-03
Sensitive personal data and personality profiles

Processing of sensitive personal data and personality profiles requires explicit consent or another statutory basis, with stricter safeguards including limitations on disclosure to third parties.

Artefacts an auditor will ask for
  • Inventory of sensitive data and personality profile processing activities
  • Explicit consent capture records with timestamp and language
  • Access controls and encryption for sensitive data stores
  • DPIA equivalent assessments for sensitive processing
  • Internal policy prohibiting unnecessary collection of sensitive data
Where this commonly fails
  • Sensitive data captured in free text without flagging
  • Personality profiles built from analytics without explicit basis
  • Sensitive data shared with vendors without consent
CH-FADP-10
Personality protection

Personal data processing must not unlawfully infringe the personality rights of data subjects, with civil law remedies available for unlawful processing, including injunctions, damages, and rectification.

Artefacts an auditor will ask for
  • Internal procedure for handling personality rights complaints
  • Litigation register including past Swiss personality rights matters
  • Insurance documentation for civil liabilities
  • Customer facing complaint channel
  • Records of injunction or damage settlements
Where this commonly fails
  • No defined intake for personality rights claims
  • Insurance excludes personality rights damages
  • Legal team unaware of Swiss specific remedies
CH-FADP-14
Automated individual decisions and personality profiling

Decisions producing legal effects or significantly affecting a data subject and based exclusively on automated processing must be subject to safeguards, including transparency, the right to express a view, and human review.

Artefacts an auditor will ask for
  • Inventory of automated decisioning systems affecting Swiss data subjects
  • Notice provided to data subjects about automated decisions
  • Process for requesting human review
  • DPIA or equivalent assessment for automated decisioning
  • Audit logs of automated decisions and overrides
Where this commonly fails
  • Notice missing or buried in generic privacy policy
  • Human review channel not staffed
  • No DPIA for credit scoring or risk scoring
CH-FADP-17
Workplace and employment data

Employers may process employee personal data only to the extent necessary for the employment relationship, with additional protections for sensitive data, monitoring, and the personality rights of employees.

Artefacts an auditor will ask for
  • Employee privacy notice in language of the workplace
  • Workplace monitoring policy referencing Swiss law
  • Necessity assessment for monitoring tools
  • Consultation evidence with employee representatives where applicable
  • Retention schedule for employment records
Where this commonly fails
  • Monitoring policy generic and not Swiss specific
  • No necessity test for monitoring tools
  • Sensitive HR data retained beyond statutory limits

Transfer

SWISSNFADP-6
Cross-Border Transfer and Processor Management

Per nFADP: cross-border transfer including FDPIC list + SCCs + BCRs + consent + adequacy.

Artefacts an auditor will ask for
  • Swiss nFADP evidence for SWISSNFADP-6
Where this commonly fails
  • FDPIC + DPIA + criminal penalties partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.