revFADP (revised Federal Act on Data Protection) and SOC: what the revised Swiss data-protection act requires from security operations
The revFADP (revised Federal Act on Data Protection, in force since 1 Sep 2023) requires appropriate technical and organisational measures. Controllers must document these measures and notify the FDPIC as soon as possible of data security breaches likely to result in a high risk to the persons concerned. A SOC delivers the detection, documented response and evidence trail needed for a credible FDPIC notification and for informing data subjects.
How this compares to neighbouring topics
This page covers revFADP (revised Federal Act on Data Protection) as a data-protection regime. For the sector-specific reporting duty for critical infrastructure, see SOC & ISG 24h reporting. For financial supervision, see SOC & FINMA requirements. For EU requirements affecting Swiss subsidiaries, see NIS2 for Swiss subsidiaries. For the full operating picture, see SOC as a Service Switzerland.
| Regime | Addressee | Notify | Deadline |
|---|---|---|---|
| revDSG Art. 24 | All controllers (private and federal) | FDPIC | as soon as possible |
| ISG Art. 74a-74f | Operators of critical infrastructure | BACS | 24 hours after discovery |
| FINMA Guidance 05/2020 / 03/2024 | Supervised institutions | FINMA | 24 hours from discovery (initial notification); full report within 72 hours |
What revDSG requires
- Technical and organisational measures (TOMs) must provide data security proportionate to risk (Art. 8 revFADP, Art. 1 ff. DPO).
- Notify the FDPIC of a data-security breach as soon as possible if it poses a likely high risk to data subjects. This covers risks to their personality or fundamental rights (Art. 24 revFADP).
- Information of data subjects to the extent required for their protection or requested by the FDPIC.
- Document the breach, its impact and the measures taken. Retain this documentation for at least two years from notification.
- Records of processing activities for controllers and processors (with exceptions for SMEs under 250 employees with low-risk processing).
- Processing on behalf only with contractual safeguards and instruction rights, including sub-processing.
This page is a practice-focused summary, not legal advice. The authoritative sources are revFADP (revised Federal Act on Data Protection) and the Data Protection Ordinance (DPO) in their current version and the FDPIC's practice.
What counts as a data-security breach?
revFADP (revised Federal Act on Data Protection) defines a breach as a security breach affecting personal data. This includes unintentional or unlawful loss, deletion, destruction or alteration, and unauthorised disclosure or access. The notification duty depends on the risk to data subjects independently of the attack vector.
- Ransomware with data exfiltration or with access to personal data during the attack.
- Compromise of an account with access to personal data (mailbox, CRM, HR system).
- Misdelivery or misconfiguration with public exposure (open bucket, wrong permissions).
- Loss of a portable storage medium containing unencrypted personal data.
- Incident at a processor with knock-on effect on the controller's personal data.
What the SOC delivers in the revFADP context
- Detection of data exfiltration, mass access, anomalous mail forwarding and privilege escalation.
- Playbooks that explicitly test the revFADP (revised Federal Act on Data Protection) notification threshold: which personal data was affected, how many data subjects, what level of risk?
- Ticket and evidence trail with timestamps, so the point of discovery, the response and the impact can be evidenced to the FDPIC.
- Template for the FDPIC notification containing the required fields (nature, timing, categories, approximate numbers, measures).
- Coordination with legal, communications and processors within a defined escalation chain.
revFADP (revised Federal Act on Data Protection) sanctions a missing or unproven response to an incident. The incident itself carries no sanction. Without a SOC there is no timeline; without a timeline there is no credible notification.
Practice: what the FDPIC typically expects
- A clear point of discovery with a documented evidence trail and context for the date.
- Risk assessment against revFADP (revised Federal Act on Data Protection) criteria: data categories, number of subjects affected, likely consequences.
- Description of measures already taken and planned to contain the incident and prevent further damage.
- Clear internal responsibilities, including the data protection advisor where appointed.
- Evidence that the TOMs are proportionate to the risk of processing and justified. Best-in-class measures are optional.
For the economics, see SOC cost Switzerland and SOC ROI. On the make-or-buy question, see Managed SOC vs. in-house.
Placement in SOC operations
SOC as a Service Switzerland explains how ongoing SOC operations incorporate revFADP (revised Federal Act on Data Protection)-compliant practices.
Legal basis and sources
- revFADP (revised Federal Act on Data Protection) (SR 235.1), in particular Art. 24: Fedlex
- Reporting data security breaches to the FDPIC: edoeb.admin.ch
- FDPIC guide on reporting data security breaches under Art. 24 revFADP, version 1.2 of 23 April 2025 (German): edoeb.admin.ch
- ISG (SR 128), Art. 74a-74f: Fedlex
- FINMA Guidance 05/2020 (Art. 29 para. 2 FINMASA), refined by Guidance 03/2024: finma.ch
Frequently asked questions
Does revFADP set a fixed deadline like 72 hours?
revFADP (revised Federal Act on Data Protection) sets no fixed notification deadline. Unlike GDPR, it requires notification as soon as possible once a high risk to data subjects is apparent.
Is every incident notifiable?
Only breaches likely to result in a high risk to the personality or fundamental rights of data subjects require notification. The controller must assess and document the risk.
What happens if a required notification is missed?
The FDPIC can open investigations and issue orders. revFADP (revised Federal Act on Data Protection)'s criminal provisions primarily target individuals and apply to intentional breaches of information, disclosure and diligence duties. Breaching the reporting duty is not itself a criminal offence; the FDPIC can order the notification. Breaching the minimum data security requirements, for example, can be punishable (Art. 61 let. c revFADP, fine up to CHF 250,000 against responsible individuals).
How does revFADP affect cloud providers and processors?
Processors may only process on a contractual basis and must notify incidents to the controller without delay. The controller remains responsible for notifying the FDPIC. Sub-processing requires consent.
Is a good firewall enough as a TOM?
A good firewall alone is insufficient: revFADP (revised Federal Act on Data Protection) requires appropriate technical and organisational measures. Appropriate means risk-proportionate: for sensitive personal data or large-scale processing, detection and documented response are standard.
Related terms
- revFADP The revFADP is the revised Swiss Federal Act on Data Protection, which governs personal data processing.
- GDPR The EU's General Data Protection Regulation governs how organisations process the personal data of individuals inside the EU.
- ISO 27001 ISO 27001 is the international standard for information security management systems. Certification confirms that risks are managed systematically.
- Data Loss Prevention (DLP) Data Loss Prevention (DLP) detects and prevents confidential data from leaving an organisation without authorisation.