revFADP
The revFADP is the revised Swiss Federal Act on Data Protection, which governs personal data processing.
The revised Federal Act on Data Protection (revFADP) governs personal data processing by private persons (individuals and companies) and federal bodies in Switzerland. It came into force on 1 September 2023 and is closely aligned with the GDPR.
How it works
The revFADP requires personal data to be processed lawfully, proportionately, and for a specific purpose. Organisations must ensure data security with appropriate technical and organisational measures. A data security breach likely to result in a high risk for data subjects must be reported to the FDPIC.
This report must be made as quickly as possible. Breaching the reporting duty is not itself a criminal offence; the FDPIC can order the notification. Breaching the minimum data security requirements, for example, can be punishable (Art.
61 let. c revFADP, fine up to CHF 250,000 against responsible individuals).
For example, attackers exfiltrate data from the HR department during a ransomware attack. The organisation must quickly clarify which data is affected. It must also determine the level of risk to its employees. If the risk is high, a report to the FDPIC is required. The affected individuals may also need to be informed.
What to look out for
- Keep a record of processing activities, unless an SME exemption applies.
- Establish a process for data protection incidents with clear responsibilities.
- Check cross-border processing for an adequate level of data protection, for example in cloud services.
- Formalise data processing agreements with service providers in writing.
- Remember that fines can be imposed on individuals personally.
Relevance for the SOC
The SOC itself processes personal data like usernames, IP addresses and behavioural data. This processing needs a clear security purpose and limited retention periods. It also requires a formal data processing agreement. Employee monitoring must also comply with the limits set by employment law.
Typical mistakes
Organisations often clarify too late whether personal data is affected during an incident. This leaves no basis for deciding whether to report the breach. A second mistake is keeping logs indefinitely without a defined retention period.
How we implement it
Data is stored either in Switzerland or the European Union. During an incident, we provide the facts for your notification decision.