revFADP (revised Federal Act on Data Protection) and SOC: what the revised Swiss data-protection act requires from security operations

The revFADP (revised Federal Act on Data Protection, in force since 1 Sep 2023) requires appropriate technical and organisational measures. Controllers must document these measures and notify the FDPIC as soon as possible of data security breaches likely to result in a high risk to the persons concerned. A SOC delivers the detection, documented response and evidence trail needed for a credible FDPIC notification and for informing data subjects.

All

How this compares to neighbouring topics

This page covers revFADP (revised Federal Act on Data Protection) as a data-protection regime. For the sector-specific reporting duty for critical infrastructure, see SOC & ISG 24h reporting. For financial supervision, see SOC & FINMA requirements. For EU requirements affecting Swiss subsidiaries, see NIS2 for Swiss subsidiaries. For the full operating picture, see SOC as a Service Switzerland.

RegimeAddresseeNotifyDeadline
revDSG Art. 24All controllers (private and federal)FDPICas soon as possible
ISG Art. 74a-74fOperators of critical infrastructureBACS24 hours after discovery
FINMA Guidance 05/2020 / 03/2024Supervised institutionsFINMA24 hours from discovery (initial notification); full report within 72 hours
A ransomware incident with data exfiltration can trigger an FDPIC notification under revFADP (revised Federal Act on Data Protection) in parallel with ISG or FINMA notifications. Each deadline runs on its own clock.

What revDSG requires

  • Technical and organisational measures (TOMs) must provide data security proportionate to risk (Art. 8 revFADP, Art. 1 ff. DPO).
  • Notify the FDPIC of a data-security breach as soon as possible if it poses a likely high risk to data subjects. This covers risks to their personality or fundamental rights (Art. 24 revFADP).
  • Information of data subjects to the extent required for their protection or requested by the FDPIC.
  • Document the breach, its impact and the measures taken. Retain this documentation for at least two years from notification.
  • Records of processing activities for controllers and processors (with exceptions for SMEs under 250 employees with low-risk processing).
  • Processing on behalf only with contractual safeguards and instruction rights, including sub-processing.
Important

This page is a practice-focused summary, not legal advice. The authoritative sources are revFADP (revised Federal Act on Data Protection) and the Data Protection Ordinance (DPO) in their current version and the FDPIC's practice.

What counts as a data-security breach?

revFADP (revised Federal Act on Data Protection) defines a breach as a security breach affecting personal data. This includes unintentional or unlawful loss, deletion, destruction or alteration, and unauthorised disclosure or access. The notification duty depends on the risk to data subjects independently of the attack vector.

  • Ransomware with data exfiltration or with access to personal data during the attack.
  • Compromise of an account with access to personal data (mailbox, CRM, HR system).
  • Misdelivery or misconfiguration with public exposure (open bucket, wrong permissions).
  • Loss of a portable storage medium containing unencrypted personal data.
  • Incident at a processor with knock-on effect on the controller's personal data.

What the SOC delivers in the revFADP context

  • Detection of data exfiltration, mass access, anomalous mail forwarding and privilege escalation.
  • Playbooks that explicitly test the revFADP (revised Federal Act on Data Protection) notification threshold: which personal data was affected, how many data subjects, what level of risk?
  • Ticket and evidence trail with timestamps, so the point of discovery, the response and the impact can be evidenced to the FDPIC.
  • Template for the FDPIC notification containing the required fields (nature, timing, categories, approximate numbers, measures).
  • Coordination with legal, communications and processors within a defined escalation chain.
Bottom line

revFADP (revised Federal Act on Data Protection) sanctions a missing or unproven response to an incident. The incident itself carries no sanction. Without a SOC there is no timeline; without a timeline there is no credible notification.

Practice: what the FDPIC typically expects

  1. A clear point of discovery with a documented evidence trail and context for the date.
  2. Risk assessment against revFADP (revised Federal Act on Data Protection) criteria: data categories, number of subjects affected, likely consequences.
  3. Description of measures already taken and planned to contain the incident and prevent further damage.
  4. Clear internal responsibilities, including the data protection advisor where appointed.
  5. Evidence that the TOMs are proportionate to the risk of processing and justified. Best-in-class measures are optional.

For the economics, see SOC cost Switzerland and SOC ROI. On the make-or-buy question, see Managed SOC vs. in-house.

Legal basis and sources

  • revFADP (revised Federal Act on Data Protection) (SR 235.1), in particular Art. 24: Fedlex
  • Reporting data security breaches to the FDPIC: edoeb.admin.ch
  • FDPIC guide on reporting data security breaches under Art. 24 revFADP, version 1.2 of 23 April 2025 (German): edoeb.admin.ch
  • ISG (SR 128), Art. 74a-74f: Fedlex
  • FINMA Guidance 05/2020 (Art. 29 para. 2 FINMASA), refined by Guidance 03/2024: finma.ch

Frequently asked questions

Does revFADP set a fixed deadline like 72 hours?

revFADP (revised Federal Act on Data Protection) sets no fixed notification deadline. Unlike GDPR, it requires notification as soon as possible once a high risk to data subjects is apparent.

Is every incident notifiable?

Only breaches likely to result in a high risk to the personality or fundamental rights of data subjects require notification. The controller must assess and document the risk.

What happens if a required notification is missed?

The FDPIC can open investigations and issue orders. revFADP (revised Federal Act on Data Protection)'s criminal provisions primarily target individuals and apply to intentional breaches of information, disclosure and diligence duties. Breaching the reporting duty is not itself a criminal offence; the FDPIC can order the notification. Breaching the minimum data security requirements, for example, can be punishable (Art. 61 let. c revFADP, fine up to CHF 250,000 against responsible individuals).

How does revFADP affect cloud providers and processors?

Processors may only process on a contractual basis and must notify incidents to the controller without delay. The controller remains responsible for notifying the FDPIC. Sub-processing requires consent.

Is a good firewall enough as a TOM?

A good firewall alone is insufficient: revFADP (revised Federal Act on Data Protection) requires appropriate technical and organisational measures. Appropriate means risk-proportionate: for sensitive personal data or large-scale processing, detection and documented response are standard.

Continue reading in this cluster
SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland
Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.
SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor
FINMA requires supervised institutions to document detection and response capabilities and demonstrate operational resilience. Institutions must report material cyber incidents within 24 hours of assessment. FINMA Circular 2023/1 Operational Risks and Resilience is the authoritative reference. It has been in force since 1 Jan 2024 and replaced Circular 2008/21. A SOC delivers 24/7 detection, a ticket and evidence trail and audit-ready evidence. Institutions need all three to meet the requirements reliably.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.
SOC and cyber insurance: what Swiss insurers require
Cyber insurers in Switzerland and the EU increasingly require applicants to evidence security controls. MFA, EDR, segregated backups, a documented incident response plan and a patch process appear on nearly every proposal form. Missing 24/7 detection via a managed SOC or MDR is rarely a formal exclusion. It is a strong premium driver and, in many policies, the only realistic way to meet short policy notification deadlines.