nLPD — Swiss Federal Data Protection Act: Compliance Guide for Swiss Companies

The nLPD (neue Datenschutzgesetz / Loi fédérale sur la protection des données) has been in force since 1 September 2023. Every Swiss private company processing personal data must comply. This guide covers obligations, deadlines, penalties, and how Abilene Advisors helps.

PFPDT — Swiss Federal Data Protection and Information CommissionerIn force: 1 September 2023

Quick answers

Definition

What is the nLPD?

The nLPD (neue Datenschutzgesetz, or Loi fédérale sur la Protection des Données) is Switzerland's revised federal data protection law, in force since September 1, 2023. It replaces the old DSG of 1992 and applies to all private companies processing personal data of Swiss residents.

Who it applies to

Who does the nLPD apply to in Switzerland?

The nLPD applies to all private-sector companies — Swiss-based or foreign — that process personal data of persons in Switzerland. Public-sector bodies (federal) are covered separately. Cantonal public bodies follow cantonal laws such as the LPrD in Vaud.

Key requirements

What are the key obligations under the nLPD?

Key nLPD obligations include: maintaining a Record of Processing Activities (RPA), conducting Data Protection Impact Assessments (DPIA) for high-risk processing, appointing a voluntary Data Protection Advisor, respecting data subject rights, and notifying breaches to the PFPDT.

Penalties

What are the penalties for nLPD non-compliance in Switzerland?

The nLPD imposes criminal fines of up to CHF 250,000 on natural persons (not companies) responsible for wilful violations. This includes failure to notify breaches, providing false information, or breaching data-subject rights. Companies may face reputational and civil liability.

Timeline

When did the nLPD take effect and what are the key deadlines?

The nLPD entered into force on 1 September 2023 — no transition period was granted. Companies should already have completed their gap analysis, updated their privacy notices, and established an RPA. DPIA processes must be operational for new high-risk processing activities.

Comparison

What is the difference between the nLPD and the GDPR?

The nLPD applies to companies processing data of Swiss residents; the GDPR applies to EU residents. Companies serving both must comply with both. Key differences: nLPD criminal fines apply to individuals (not companies); GDPR fines are corporate. Both require similar documentation and DPIAs.

In Switzerland

Does the nLPD apply to Swiss companies that only serve Swiss customers?

Yes. All Swiss private companies processing personal data of individuals in Switzerland must comply with the nLPD, regardless of whether they also process EU data. If they also serve EU residents, GDPR compliance is additionally required.

Our advisory

How can Abilene Advisors help with nLPD compliance?

Abilene Advisors provides nLPD gap analysis, Record of Processing Activities (RPA) development, DPIA facilitation, privacy notice drafting, and ongoing DPO-as-a-service for Swiss companies. Bilingual support in English and French.

Who must comply with the nLPD

  • Swiss private companies of all sizesNo SME exemption — all private entities processing personal data must comply.
  • Foreign companies targeting Swiss residentsCompanies outside Switzerland that actively market to or process data of Swiss persons.
  • Cloud service providers and data processorsProcessors handling Swiss personal data on behalf of controllers must meet nLPD requirements.
  • Organisations with automated decision-makingCompanies using algorithmic profiling or automated decisions affecting individuals have heightened obligations.

Core nLPD compliance requirements

  1. 1

    Record of Processing Activities (RPA)

    Maintain a written inventory of all personal data processing activities, including purpose, categories of data, retention periods, and recipients.

  2. 2

    Privacy notices update

    Update all privacy policies to meet nLPD transparency requirements: lawful basis, data categories, retention, and data-subject rights.

  3. 3

    Data Protection Impact Assessment (DPIA)

    Conduct a DPIA before launching high-risk processing activities (e.g. systematic profiling, large-scale sensitive data processing).

  4. 4

    Data breach notification

    Report personal data breaches to the PFPDT "as soon as possible" when likely to harm affected persons. No fixed 72h deadline — but promptness is expected.

  5. 5

    Data subject rights management

    Establish processes for handling access, correction, deletion, and portability requests from data subjects within 30 days.

  6. 6

    Cross-border transfer safeguards

    Ensure personal data transferred abroad goes to countries on the PFPDT adequacy list or is protected by standard contractual clauses (SCCs).

nLPD key dates

1 Sep 2023

nLPD enters into force

No transition period. All private companies must comply from this date.

Ongoing

PFPDT enforcement

The Federal Data Protection and Information Commissioner (PFPDT) can investigate and issue recommendations.

Dec 2024

PFPDT adequacy list updated

PFPDT updated the list of countries deemed to provide adequate data protection for cross-border transfers.

nLPD vs. related data protection frameworks

GDPR

The GDPR applies to EU residents' data. The nLPD applies to Swiss residents' data. Many Swiss companies must comply with both. Key differences: GDPR fines companies; nLPD fines individuals. GDPR has a DPO mandate for certain organisations; nLPD has a voluntary Data Protection Advisor.

LPrD

The LPrD is the Vaud cantonal data protection law for public-sector entities in Vaud. The nLPD applies to all Swiss private companies. Cantonal public bodies in Vaud follow the LPrD, not the nLPD — but both laws may apply simultaneously if a public body processes private-sector data.

nLPD — Frequently asked questions

Is a Data Protection Officer (DPO) mandatory under the nLPD?
No. The nLPD introduces a voluntary "Data Protection Advisor" (Conseiller à la protection des données) role — not a mandatory DPO like the GDPR requires for certain organisations. However, appointing one is strongly recommended for large-scale processing. Abilene Advisors offers an external DPO service.
What personal data categories have heightened protection under the nLPD?
The nLPD expands the definition of sensitive personal data to include: biometric data, genetic data, location data, and data revealing political views. Processing these requires explicit consent or a specific legal basis.
What happens if a company fails to conduct a mandatory DPIA?
Failure to conduct a DPIA when required can lead to PFPDT investigation and recommendations. In cases of wilful violation of notification obligations, the responsible individual may be fined up to CHF 250,000.
Does the nLPD apply to employee personal data?
Yes. Employee data is personal data under the nLPD. Swiss employers must comply with nLPD transparency, retention, and data-subject rights requirements for all HR data processing.
How do we handle cross-border data transfers post-nLPD?
Transfers to EU/EEA countries are generally permissible (GDPR adequacy is recognised). For other countries, use the PFPDT's list of adequate countries or implement standard contractual clauses (SCCs). The nLPD does not allow Binding Corporate Rules as a transfer mechanism.
What is the difference between nLPD and DSG?
The nLPD (neue Datenschutzgesetz) is the 2023 revision of the old DSG (Datenschutzgesetz) of 1992. The 1992 DSG has been fully replaced. The nLPD aligns Swiss data protection law more closely with the GDPR while maintaining distinct Swiss characteristics.

Need nLPD compliance support?

Abilene Advisors helps Swiss companies achieve nLPD compliance with practical, implementable solutions. Bilingual support in English and French.

Book a free consultation

Related resources

Regulation

LPrD — Vaud Cantonal Data Protection

The cantonal data protection law for public-sector entities in Vaud. Links up to the nLPD as a spoke.

Regulation

GDPR Compliance

EU data protection law. Swiss companies serving EU residents must comply alongside the nLPD.

Service

DPO as a Service — Switzerland

Abilene Advisors provides outsourced Data Protection Officer services for nLPD compliance.