What is the nLPD (revised FADP)?

The nLPD is the revised Swiss Federal Act on Data Protection (FADP, nDSG in German), in force since 1 September 2023. It sets the rules for processing personal data in Switzerland and is supervised by the FDPIC.

Written by Ugo Balducci. Last updated

What the nLPD means

The revised Federal Act on Data Protection (SR 235.1) replaced the 1992 Act on 1 September 2023. In French it is the nLPD, in German the nDSG, in English the revised FADP. It protects the personal data of natural persons and applies to private companies and federal bodies that process it. The Federal Data Protection and Information Commissioner (FDPIC) supervises it.

The Act brought Swiss law closer to the GDPR. It introduced privacy by design and by default, records of processing activities, data protection impact assessments for high-risk processing, and the duty to report breaches that are likely to create a high risk to the FDPIC as soon as possible. Cross-border disclosure is allowed (art. 16) to countries the Federal Council lists as adequate in Annex 1 of the Data Protection Ordinance, which include the EU and EEA states, or with safeguards such as standard contractual clauses. Wilful breaches of certain duties can lead to criminal fines of up to CHF 250,000 on the responsible individuals.

Why it matters when choosing where software runs

Under the nLPD you stay the controller when a provider runs your software. Article 9 lets you entrust processing to a processor by contract or by law, only for processing you could do yourself, only where no secrecy obligation forbids it, and only once you have made sure the processor can guarantee data security. The processor may use a sub-processor only with your prior authorisation. Where the data sits also matters: disclosure to a country outside the adequacy list needs extra safeguards, which is part of data residency.

The Act provides for voluntary certification under article 13, but it does not replace your own checks. What you can always review is the agreement, the security measures, the location of the data and how breaches are reported to you.

How Pilae handles it

Pilae acts as your processor under article 9. Our standard DPA covers the revised FADP and the GDPR in one agreement, is signed at onboarding before any data moves, and names every sub-processor. You choose where your data lives: your premises, Zurich, or any other of the 12 Pilae Cloud regions, including five in the EU. We give you the facts your record of processing needs, report breaches affecting your data without delay, and keep an audit trail you can export to your SIEM. Security measures are built to ISO 27001 controls.

The full breakdown by article is on the Swiss nLPD page, and the page for data protection officers covers the questions a DPO usually asks first.

Related on this site

Tell us what you need to run.

Thirty minutes with an engineer, a written plan and a fixed price for the first workload.