
The Swiss Data Protection Law That Can Fine You CHF 250,000 Personally
Most foreign DTC brands assume GDPR compliance covers them in Switzerland. It doesn't. Under the nFADP, fines go to individuals — up to CHF 250,000 personally to directors and CEOs. A practical compliance guide for brands selling into Switzerland.
Imagine this. You run a Spanish DTC brand. You ship to Swiss customers from your warehouse in Madrid. You think your GDPR setup covers you because Switzerland is "basically the same."
One of your customers files a complaint with the Swiss data protection authority. They say your privacy policy doesn't tell them clearly what you do with their data, and you've been ignoring their access requests.
The Swiss authority opens a case. Investigation, evidence, hearing — the whole thing.
The fine doesn't go to your company. It goes to you. The CEO. The director. The natural person responsible.
Up to CHF 250,000.
This is not theoretical. It's the explicit design of Switzerland's revised Federal Act on Data Protection, in force since September 2023. And it's the part most foreign brands selling into Switzerland have completely missed.
What is the nFADP?
The nFADP — also called revFADP, or revDSG in German — is the new Swiss data protection law that came into force on 1 September 2023, replacing the 1992 act. It applies to every business that processes personal data of people in Switzerland, regardless of where the business is based. If you sell to Swiss customers, monitor their behavior with cookies and trackers, or run any kind of profiling on them, you fall under the nFADP. There is no transition period and there is no business-size exemption.
Surface-level, it looks like GDPR. Privacy notices, data subject rights, breach notifications, records of processing. The vocabulary is mostly the same. That similarity is exactly why most foreign DTC brands assume GDPR compliance equals nFADP compliance and move on.
It doesn't. And the differences are where the cost lives.
The one difference that should keep founders awake
Under GDPR, fines go to the company. Up to 4% of global annual revenue, or EUR 20 million, whichever is higher. Painful, but corporate.
Under the nFADP, fines go to natural persons. Articles 60 and 61 of the nFADP set criminal fines of up to CHF 250,000 for individuals — board members, managing directors, anyone with operational responsibility for data protection inside the company. The Swiss legislator made this choice deliberately. The criminal provisions, in their own words, target the natural persons responsible.
The company itself can be fined too, but only up to CHF 50,000, and only when identifying the actual responsible individual would require disproportionate investigation. The default is personal liability.
For a Spanish founder with a EUR 1.5M DTC brand, this changes the calculation entirely. The risk you carry as CEO is no longer abstract corporate exposure. It's your personal bank account.
One nuance worth knowing, because it cuts both ways: the nFADP only sanctions intentional violations, not negligence. Forgetting to update a privacy notice during a busy quarter is unlikely to land in court. Knowingly running an inadequate privacy policy because compliance felt expensive is a different story.
nFADP vs. GDPR: where they actually diverge
If you've already done GDPR work, you're 60% of the way there. The remaining 40% is where the audits happen.
| Topic | GDPR | nFADP |
|---|---|---|
| Who pays the fine | The company (up to 4% global revenue or EUR 20M) | The individual (up to CHF 250,000), company only as fallback (CHF 50,000) |
| Negligent violations | Sanctionable | Not sanctionable — only intent |
| Breach notification window | 72 hours | "As soon as possible" (undefined) |
| Foreign company representative | EU representative under Art. 27 | Swiss representative under Art. 14, narrower trigger |
| Records of processing | Mandatory above 250 employees | Mandatory above 250 employees, exceptions for low-risk SME processing |
| Cross-border transfer to non-adequate countries | SCCs, BCRs, derogations | SCCs/BCRs approved by FDPIC, plus a published Swiss list of adequate countries |
The Swiss representative requirement most foreign brands ignore
Article 14 of the nFADP requires foreign controllers to designate a representative inside Switzerland — a contact point for data subjects and the Federal Data Protection and Information Commissioner (FDPIC) — when processing meets all of these conditions:
- It relates to offering goods and services in Switzerland or monitoring behavior in Switzerland
- It is on a large scale
- It is regular
- It poses a high risk to the personality or fundamental rights of the data subjects
The threshold is narrower than the GDPR equivalent, but for any DTC brand running paid acquisition into Switzerland with the standard analytics, retargeting, and CRM stack, you almost certainly meet it. Most brands I talk to don't realize this exists.
The representative's name and address have to be published in your privacy policy. The representative also needs to hold a copy of your Record of Processing Activities. Several Swiss firms offer this as a service for around CHF 100–300 per month. It is a known, solvable problem — it just has to be solved.
A practical compliance checklist for Shopify and DTC stores
If you sell into Switzerland from outside the country, this is the minimum work to be on the right side of the nFADP. None of it is exotic. All of it is non-optional.
1. Privacy notice in the right languages
Your privacy policy needs to be available in the language your customer uses to buy from you. For most Swiss DTC, that means at minimum German and French, ideally Italian for Ticino, and English for international shoppers. A single English privacy policy on a store that sells in CHF, displays prices in German, and accepts TWINT does not pass the smell test.
2. Record of Processing Activities
You need an inventory of every processing activity, with the categories of data, purposes, retention periods, recipients, and any cross-border transfers. The nFADP grants exceptions for SMEs whose processing is low-risk, but the exception is narrower than people assume. Keep the document. You will be asked for it.
3. Cookie consent that actually consents
If your store uses Meta Pixel, Google Ads tracking, hotjar, or any analytics beyond first-party basics, you need affirmative consent before those scripts fire. Pre-ticked boxes don't count. "By using this site you accept" banners don't count. The consent has to be explicit, granular, and revocable. Most off-the-shelf Shopify cookie apps now support this — but the default config rarely does.
4. Cross-border transfer documentation
If your store stores customer data with vendors outside Switzerland — and almost every Shopify store does, between Shopify itself, Klaviyo, Meta, Google, customer service tools, and so on — you need to confirm those countries are on the FDPIC's adequacy list, or you have approved Standard Contractual Clauses in place. The list lives in Annex 1 of the Data Protection Ordinance and is publicly available on fedlex.admin.ch.
5. Breach notification process
If you suffer a data breach that poses a high risk to data subjects, you need to notify the FDPIC "as quickly as possible." The law deliberately doesn't define a hard window like GDPR's 72 hours. In practice this means: have an incident response plan, document the breach, decide whether risk is high, notify if yes. Not having a documented process is itself a sign of failed due diligence.
6. Swiss representative if Article 14 applies
Either confirm in writing that your processing doesn't trigger Art. 14, or appoint a representative. Pick one. The grey middle — assuming it doesn't apply because nobody has said anything yet — is exactly where personal liability lives.
What most foreign brands get wrong
I've reviewed the nFADP posture of brands at varying stages of Swiss market entry. The same three mistakes show up almost every time.
They confuse GDPR with nFADP. Their cookie banner says "GDPR-compliant." Their privacy policy mentions Brussels but not Bern. They've never heard of the FDPIC. The compliance work was done once, in 2018, for the EU market, and never revisited for Switzerland.
They translate the privacy policy badly or not at all. A privacy policy auto-translated into German with errors, run through Google Translate for French, and missing in Italian is worse than a single clean English version — because it signals carelessness. And carelessness is exactly the kind of pattern that turns a customer complaint into an FDPIC investigation.
They never assess Article 14. The Swiss representative question simply isn't on their radar. When they finally ask "do we need this?", the honest answer is usually yes and has been for two years.
The good news
None of this is hard. It is just work. And once it's done correctly, it stays done — Swiss data protection law isn't subject to the same constant amendment churn as some other jurisdictions.
Compared with the actual cost of the brand-building, paid acquisition, logistics, payments, and team you've already invested in to enter Switzerland, an additional CHF 2,000–5,000 of compliance work is rounding error. Compared with personal exposure to a CHF 250,000 fine on your own bank account, it is one of the cheapest forms of insurance you can buy.
The brands that win in Switzerland do the boring work upfront. They incorporate properly, accept TWINT, ship via Die Post, and run their nFADP setup before the first paid campaign goes live — not after the first complaint lands.
If you're running a brand expanding into Switzerland and you're not sure where you stand on the nFADP, the next move is a 90-minute audit with someone who has done this before. Get in touch — I'll tell you honestly whether you have a problem and what it costs to fix it.
This article is informational, not legal advice. For your specific compliance posture, consult a Swiss data protection lawyer or your Treuhand.
Keep reading

The World's Highest-Value Online Shopper Lives in Switzerland
Swiss MarketThe average Swiss online order in 2024 was $239 — more than double the global average, and the highest of any country on earth. So why do most European DTC brands skip this market entirely?

The Swiss eCommerce Stack: A Practical Map for Foreign DTC Brands
Swiss MarketForeign DTC brands underestimate Swiss market entry because it isn't one decision — it's six. Legal entity, payments, tax, logistics, compliance, localization. A practical map of the full Swiss eCommerce stack, with the configuration that separates a successful launch from a slow expensive failure.