Swiss FADP and Your Offshore Agency
SEO

Swiss FADP and Your Offshore Agency

The CHF 250,000 penalty lands on a person, not a company. Indonesia is absent from Annex 1, and the Article 14 representative rule is widely overstated.

Under Swiss data protection law, the fine for disclosing personal data abroad without adequate safeguards lands on a person, not on a company. Up to CHF 250,000, against the individual who was responsible. The company can be fined instead, but only up to CHF 50,000, and only where identifying the individual would take disproportionate investigative effort.

That single design choice explains most of what is different about selling marketing services into Switzerland. A Swiss procurement lead reading a vendor questionnaire is not managing a corporate compliance line item. They are managing personal exposure, and they know it even if the vendor does not.

Switzerland is also not in the European Union, does not run on the GDPR, and maintains its own binding adequacy list that differs from the European Commission's. Indonesia is not on it. Neither is Japan, and neither is South Korea. This article covers the criminal liability model, the adequacy question, the Article 14 representative rule that is almost universally overstated, what the commissioner has said about AI, and how to design an engagement so that most of this stops being a problem.

One thing this article is not. It is orientation, not Swiss legal advice. Anything touching Swiss personal data should be reviewed by qualified Swiss counsel.

The criminal liability model, stated precisely

The revised Federal Act on Data Protection took effect on 1 September 2023 with no transition period. Its criminal provisions sit in Articles 60 to 63.

Four features of that structure matter for vendor selection, and each one is routinely reported wrong.

Intentional conduct only. There is no criminal penalty for negligence under the FADP. That is narrower than many summaries imply, and it is genuinely reassuring for a well-run organisation. It also means that once you have been told something and choose not to act, the character of the exposure changes.

Individuals, not companies. The provisions target the responsible natural person. This is the inverse of the GDPR model, where the corporate entity absorbs the fine, and it is the single most important thing for a foreign vendor to understand about how their Swiss counterpart is thinking.

Two of the offences describe vendor selection directly. Disclosing personal data abroad without appropriate safeguards or a valid statutory exception is one of them. Engaging a third party to process personal data in breach of Article 9 is another. So the act of choosing a processor and designing the transfer is itself the regulated conduct, not merely a step on the way to it.

Cantonal prosecutors enforce it. The federal data protection commissioner investigates and issues orders. Criminal prosecution sits with cantonal authorities, which means the process is a criminal one rather than an administrative one.

Article 64 provides the corporate alternative. Where the fine under consideration would not exceed CHF 50,000 and investigating the individual would require disproportionate effort, the prosecuting authority may penalise the undertaking instead. Note the ceiling. The corporate route is capped well below the individual route, which is the opposite of how most people assume liability escalates.

Not the GDPR

Six Places Swiss Law Diverges, and Why Procurement Notices

A vendor answering Swiss questions with a GDPR statement has answered a different question.

Question
Switzerland, revised FADP
European Union, GDPR

Who pays the penalty

The responsible individual, up to CHF 250,000. Company only via Art. 64, capped at CHF 50,000

The undertaking, with turnover-based ceilings

Negligence

No criminal penalty. Intentional conduct only, Art. 60 to 63

Administrative fines available without intent

Who is protected

Natural persons only. Legal-person coverage from the 1992 act was dropped

Natural persons only

Breach notification

As soon as possible, with no fixed hour count in the statute

Within 72 hours where feasible

Data protection officer

Not mandatory. An adviser may be appointed voluntarily

Mandatory in defined circumstances

Who decides adequacy

The Swiss Federal Council, binding list in Annex 1 of the Ordinance

The European Commission

The one that surprises vendors

Two of the four criminal offences describe vendor selection itself: disclosing personal data abroad without appropriate safeguards or a valid exception, and engaging a third party to process personal data in breach of Article 9. Choosing the processor and designing the transfer are the regulated acts. A named person inside the client organisation carries that exposure, which is why the questionnaire is not a formality.

Sources: revised Federal Act on Data Protection, in force 1 September 2023, Art. 60 to 64 • Federal Data Protection and Information Commissioner guidance • Data Protection Ordinance Annex 1
Created by Arfadia • arfadia.com/blog

Adequacy: a separate Swiss decision, not a copy of Brussels

Annex 1 of the Data Protection Ordinance holds the binding list of states and territories recognised as offering adequate protection. It was last updated on 15 September 2024 and covers 43 entries. Assessment work sits with the Federal Office of Justice, and the list is decided by the Federal Council.

The word binding matters here, because the previous regime worked differently. Under the old Swiss framework the data exporter assessed adequacy itself. Under the revised act, the Annex 1 list governs, which removes discretion in both directions.

The list includes the whole European Union and European Economic Area, the United Kingdom, Canada for certain sectors, Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, Monaco, New Zealand, Uruguay and several smaller jurisdictions. The United States appears only for recipients certified under the Swiss-US Data Privacy Framework, effective from 15 September 2024.

Japan and South Korea are absent, despite both being recognised by the European Union. That absence is the clearest available evidence that a GDPR-compliant transfer posture is not automatically a Swiss-compliant one, and it is worth putting in front of any vendor who thinks the two regimes are interchangeable.

Indonesia is not on the list. We state that first in every Swiss engagement rather than waiting for a questionnaire, because the consequence is specific and manageable rather than dramatic. Transfers to Indonesia are permitted. They require Swiss-adapted contractual safeguards, a transfer assessment, and where relevant supplementary technical measures. What they do not permit is a shrug and a link to a GDPR policy page.

Article 14: the rule almost everyone overstates

Search for Swiss representative requirements and you will find a large number of compliance summaries stating that foreign controllers and processors handling Swiss data must appoint a representative in Switzerland. That is broader than the law.

The commissioner's own guidance is narrower on two axes. First, the duty applies to private controllers domiciled abroad. Processors are not covered by it, and public bodies are outside the private-controller scope. Second, the duty arises only where all four statutory conditions in Article 14 paragraph 1 are met together, not where any one of them applies.

The four conditions: the processing relates to offering goods or services in Switzerland or to monitoring the behaviour of people in Switzerland; the processing is large-scale rather than an isolated case; it is regular rather than occasional or time-limited; and it poses a high risk to the personality rights of data subjects.

Two details make the test stricter than it first appears, and neither shows up in the summaries. The high-risk assessment for Article 14 is made on gross risk, meaning without crediting the mitigation measures the controller has already taken or plans to take. That is a tougher standard than the impact-assessment test elsewhere in the act. And Swiss legal commentary describes the combined conditions as rarely satisfied in practice, applying to a small number of foreign controllers.

There is also a quirk in the enforcement route. Failing to designate a representative is not itself among the offences in Articles 60 and following. What is punishable, under Article 63, is failing to comply with a commissioner's order, including an order to designate one. So the exposure arises from defying the regulator rather than from the initial omission.

Why does an agency care about getting this right? Because overstating it is a form of misrepresentation. Telling a Swiss buyer that a rule binds them when the commissioner says it usually does not is bad advice dressed as caution, and Swiss unfair competition law takes a dim view of misleading statements about services and qualifications. Voluntary appointment remains available to any controller that wants it as a precaution, and framing it that way is both accurate and useful.

What the commissioner has actually said about AI

This one needs care, because we found the claim reported wrongly in two opposite directions during cross-validation.

The commissioner issued a statement on 9 November 2023, updated on 8 May 2025, confirming that the FADP is drafted technology-neutrally and therefore applies directly to AI-supported data processing. The substance covers transparency about the purpose, functionality and data sources of AI processing; the duty to inform users when they are communicating with a machine and whether their input is used to improve the system; the right to object to automated processing and to request human review of automated decisions; data protection impact assessments where processing carries high risk; and a position that blanket real-time facial recognition and social scoring are not permissible.

What we found in the research corpus was one model asserting that this guidance was issued on 24 September 2025 and covered prompt logging and automated context retrieval specifically, and two other models asserting that no FADP guidance on AI existed at all. Both are wrong. The guidance exists, the dates are November 2023 and May 2025, and it addresses AI processing generally rather than generative engine optimisation or prompt logging in particular.

The practical position that follows is unglamorous but defensible. There is no Swiss guidance written specifically about prompt logs or AI-visibility measurement. So design against the general rules: keep personal data out of tracked prompts and logs wherever the deliverable does not require it, state retention periods, list sub-processors and access countries, and treat any AI tool that trains on inputs as a transfer question rather than as a tooling preference.

Marketing activity FADP exposure Control that actually reduces it
Auditing public pages and AI answersLowDo not append personal identifiers the task does not need. Most SEO and GEO work sits here by design
Keyword and competitor researchLowAggregate query data only. No personal data is required to do this work properly
Analytics and search-console accessLow to mediumKeep accounts in the client's own ownership and grant named access rather than exporting data sets offshore
Digital PR contact listsMediumDocument source, purpose, access and retention before building the list, not after a question is asked
Tracked prompts and AI logsMediumExclude personal data at the point of entry. State retention. Check whether the tool trains on inputs, since that is a transfer question
Uploading Swiss customer records into an AI toolHighProhibit without documented approval and a lawful basis on file. This is one of the acts Art. 60 to 63 describe
Processing Swiss personal data in IndonesiaHighSwiss-adapted contractual safeguards, a transfer assessment and Swiss legal review, since Indonesia is not on the Annex 1 list

The pattern in that table is worth stating plainly, because it is genuinely good news for a well-scoped engagement. SEO and GEO work is mostly content, entity and public-answer auditing, and it sits at the low-exposure end. That is a design property rather than a loophole. The exposure appears at the moment somebody decides it would be convenient to move Swiss customer records offshore for analysis. Convenience is the risk factor here, not geography.

Design, not paperwork

Reduce the Question Instead of Arguing It

The strongest answer to a Swiss transfer question is an engagement where very little personal data is in scope at all.

Client-owned accounts, named access

Analytics and search-console properties stay in the client's ownership. The agency receives named user access rather than exported data sets, which keeps the data resident where it already was.

Minimisation at the point of entry

Personal data is excluded from working sets, tracked prompts and logs wherever the deliverable does not require it. Filtering at ingestion is easier to evidence than cleaning up afterwards.

Sub-processors and access countries listed

Named in writing before work starts, with retention periods stated. Any AI tool that trains on inputs is treated as a transfer question rather than as a tooling choice.

Swiss-adapted safeguards, not GDPR templates

Contractual clauses referencing the FADP and Annex 1 rather than a European template with Switzerland written in the margin, plus a documented transfer assessment.

A named accountable contact

Provided whether or not the law compels one, because the Swiss liability model puts a person on the client side of the table and symmetry is a reasonable expectation.

Incident support matched to the Swiss trigger

Notification as soon as possible rather than a 72-hour clock, so escalation paths and response commitments are written to the Swiss standard rather than the European one.

And one exemption worth knowing

Under commissioner guidance, organisations below 250 employees are generally exempt from maintaining a formal record of processing activities, subject to conditions relating to risk. That covers a large share of Swiss businesses, and it is a useful thing for a vendor to know before demanding documentation the client is not required to hold.

Sources: revised FADP, in force 1 September 2023 • Federal Data Protection and Information Commissioner guidance, including the January 2024 guide • Data Protection Ordinance Annex 1, updated 15 September 2024
Created by Arfadia • arfadia.com/blog

The questions a Swiss buyer will actually ask

They are shorter than most vendors expect, and they are answerable.

Where is our data processed, and which countries have access. Is that country on the Annex 1 list. If not, what safeguards apply and have you done a transfer assessment. Who is the accountable person on your side. What happens in the first 24 hours of an incident. Do any of your tools train on our inputs. What is your retention period, and can we require deletion.

None of those requires a legal department to answer, and all of them are worse to answer late than early. The vendor that volunteers this in the first proposal is not being unusually virtuous. It is recognising that a Swiss buyer carries personal exposure and that reducing their uncertainty is the actual service being purchased alongside the marketing work.

Tessar Napitupulu covers how regulation and procurement shape search and AI visibility programmes across jurisdictions, including the transfer questions that decide whether a foreign agency gets shortlisted, in Cited or Silent, available as a free gated edition, with retailer editions on Amazon, Google Play and Apple Books.


Frequently Asked Questions


Does GDPR compliance cover us for Switzerland?

No. Switzerland is outside the European Union and runs its own revised Federal Act on Data Protection, in force since 1 September 2023 with no transition period. The European Commission recognises Switzerland as adequate, which eases transfers into Switzerland, but that does not place Switzerland under the GDPR. The regimes diverge on points that matter operationally: penalties target individuals rather than companies, there is no criminal penalty for negligence, breach notification is required as soon as possible rather than within a fixed 72 hours, a data protection officer is optional, and the adequacy list is decided by the Swiss Federal Council rather than by the Commission.


Who is personally liable under Swiss data protection law?

The responsible natural person, up to CHF 250,000, for intentional conduct only. Articles 60 to 63 of the revised FADP describe four offences and there is no criminal penalty for negligence. Two of those offences apply directly to vendor selection: disclosing personal data abroad without appropriate safeguards or a valid exception, and engaging a third party to process personal data in breach of Article 9. Under Article 64 a company can be penalised instead, but only up to CHF 50,000 and only where identifying the responsible individual would require disproportionate investigative effort. Cantonal prosecutors handle enforcement rather than the federal commissioner.


Is Indonesia on Switzerland's adequacy list?

No. The binding list sits in Annex 1 of the Data Protection Ordinance, was last updated on 15 September 2024, and covers 43 states and territories including the whole EU and EEA, the United Kingdom, Canada for certain sectors, Andorra, Argentina, Israel, New Zealand, Uruguay and several smaller jurisdictions, plus the United States only for recipients certified under the Swiss-US Data Privacy Framework. Japan and South Korea are absent even though the European Union recognises both. Transfers to Indonesia remain permitted but require Swiss-adapted contractual safeguards, a documented transfer assessment and, where relevant, supplementary technical measures.


Do we need to appoint a Swiss representative?

Probably not, and most published summaries overstate this. The commissioner's guidance limits Article 14 to private controllers domiciled abroad, so processors are outside it, and the duty arises only where all four statutory conditions are met together: the processing relates to offering goods or services in Switzerland or monitoring behaviour of people in Switzerland, it is large-scale, it is regular, and it poses a high risk to personality rights. The high-risk test here is assessed on gross risk, without crediting mitigations. Swiss legal commentary describes the combined conditions as rarely satisfied. Failing to designate is also not itself an offence under Articles 60 and following; defying a commissioner's order to designate is punishable under Article 63.


How quickly must a Swiss data breach be reported?

As soon as possible, with no fixed hour count written into the statute. That is a meaningful difference from the GDPR's 72-hour standard, and it cuts both ways. There is no clock to hide behind, and the expectation is that notification follows promptly once a reportable breach is identified rather than at the end of a permitted window. Practically, an agency serving Swiss clients should write escalation paths, response commitments and first-24-hour actions to the Swiss trigger rather than reusing a European incident-response plan with a 72-hour assumption baked into it.


Does Swiss law say anything about AI and prompt logs?

It says something about AI and nothing specific about prompt logs. The commissioner issued a statement on 9 November 2023, updated on 8 May 2025, confirming the FADP is technology-neutral and applies directly to AI-supported data processing. It covers transparency about purpose, functionality and data sources, the duty to tell users when they are communicating with a machine and whether their input improves the system, the right to object to automated processing and request human review, and impact assessments for high-risk processing. It treats blanket real-time facial recognition and social scoring as impermissible. No guidance addresses generative engine optimisation or prompt logging specifically, so design against the general rules rather than citing a document that does not exist.


Is SEO or GEO work high-risk under the FADP?

Mostly no, and that is a design property rather than a loophole. Auditing public pages and AI answers, keyword and competitor research, and analysing aggregate visibility metrics all sit at the low-exposure end because none of them requires personal data to be done properly. Exposure rises with digital PR contact lists, with tracked prompts and logs if personal data is allowed into them, and sharply with uploading Swiss customer records into an AI tool or moving Swiss personal data offshore for analysis. The risk factor is convenience rather than geography, and a well-scoped engagement can run with very little personal data in scope.


Do we need a formal record of processing activities?

Often not, depending on size and risk. Commissioner guidance provides that organisations below 250 employees are generally exempt from maintaining a formal record of processing activities, subject to conditions relating to the risk of the processing. That covers a large share of Swiss businesses. It is worth knowing before a vendor demands documentation the client is not legally required to hold, and worth checking against your actual processing rather than assuming the exemption applies. As with everything here, confirm with qualified Swiss counsel rather than treating an article as advice.

Sources & References:

  • Revised Federal Act on Data Protection (revFADP / nDSG), in force 1 September 2023 with no transition period. Criminal provisions Art. 60 to 63: four offences, intentional conduct only, no criminal penalty for negligence, ceiling CHF 250,000 against the responsible natural person. Offences include disclosing personal data abroad without appropriate safeguards or a valid exception, and engaging a third party to process personal data in breach of Art. 9(1) and (2). Art. 64: undertaking may be fined up to CHF 50,000 where identifying the individual would require disproportionate investigative effort. Enforcement by cantonal prosecuting authorities.
  • Federal Data Protection and Information Commissioner (FDPIC / EDÖB), guidance on representatives under Article 14 FADP: duty applies to private controllers domiciled abroad where all four conditions of Art. 14(1) are fulfilled together, namely processing connected with offering goods or services in Switzerland or monitoring behaviour of people in Switzerland, large-scale processing, regular processing, and high risk to the personality of data subjects. High-risk assessment for Art. 14 made on gross risk, without accounting for mitigation measures. Voluntary designation permitted.
  • Swiss legal commentary (onlinekommentar.ch) on Art. 14 FADP: combined conditions described as rarely satisfied in practice; breach of the designation duty is not covered by the penal provisions of Art. 60 et seq.; failure to comply with an FDPIC order to designate a representative is punishable under Art. 63.
  • Data Protection Ordinance (DPO), Annex 1: binding list of states and territories with adequate data protection, maintained with assessment work by the Federal Office of Justice, last updated 15 September 2024, 43 entries. Includes the EU and EEA, United Kingdom, Canada for certain sectors, Andorra, Argentina, Faroe Islands, Gibraltar, Guernsey, Isle of Man, Israel, Jersey, Monaco, New Zealand, Uruguay and further jurisdictions; United States only for recipients certified under the Swiss-US Data Privacy Framework. Japan and South Korea absent. Indonesia absent.
  • FDPIC statement on the applicability of the FADP to AI-supported data processing, issued 9 November 2023, updated 8 May 2025: FADP drafted technology-neutrally and directly applicable to AI processing; transparency regarding purpose, functionality and data sources; duty to inform users when communicating with a machine and whether input is used to improve the system; right to object to automated processing and to request human review; data protection impact assessment for high-risk processing; blanket real-time facial recognition and social scoring treated as impermissible.
  • FDPIC guidance, January 2024: organisations below 250 employees generally exempt from maintaining a formal record of processing activities, subject to risk-related conditions.
  • Further FADP divergences from the GDPR, cross-validated across four independent research passes against PwC, DLA Piper and EY comparative analyses: protection limited to natural persons, with legal-person coverage from the 1992 act removed; breach notification as soon as possible with no fixed 72-hour deadline; data protection officer not mandatory under Art. 10.
  • Corrected during cross-validation: one research pass dated the FDPIC AI statement to 24 September 2025 and attributed prompt-logging and automated-context-retrieval specifics to it; two other passes stated no FADP guidance on AI existed. Both positions are inaccurate. The statement exists with the dates given above and addresses AI processing generally, not generative engine optimisation or prompt logging. A separate pass asserted that foreign controllers and processors targeting Switzerland must appoint a representative, which is broader than the commissioner's guidance and is not reproduced here.
  • This article is orientation on Swiss data protection as it affects marketing procurement. It is not Swiss legal advice. Engagements involving Swiss personal data should be reviewed by qualified Swiss counsel.
0 Comments 0 Comments
0 Comments 0 Comments