6.4 FADP and Other Non-U.S. Intersections

Key Takeaways

  • The revised Swiss Federal Act on Data Protection (revFADP / nFADP), in force 1 September 2023, applies to circumstances that have an effect in Switzerland even if they were initiated abroad
  • Swiss sensitive personal data is a defined list that includes health, intimacy, racial or ethnic origin, genetic and identifying biometric data, and certain proceedings, sanctions, and social-assistance data
  • A controller must notify the FDPIC as soon as possible of a data-security breach likely to cause a high risk to personality or fundamental rights — not a blanket 72-hour clock and not every low-risk incident
  • The Swiss-U.S. DPF, usable for certified importers from 15 September 2024, is an adequacy-style path under Swiss transfer rules; uncertified U.S. importers still need Swiss-adapted SCCs or another FADP safeguard
  • Canada's PIPEDA, Quebec's Law 25, and the UK GDPR are other non-U.S. laws a U.S. multinational will hit; CIPP/US requires that recognition, not CIPP/C or CIPP/E depth
Last updated: August 2026

FADP and Other Non-U.S. Intersections

CIPP/US is a United States credential. BoK 2.6.1 still requires the U.S. professional to recognize how U.S. programs intersect non-U.S. privacy law. The outline names two statutes expressly: the GDPR (previous sections) and Switzerland's Federal Act on Data Protection (FADP). Canada and the United Kingdom appear here only as other laws a U.S. multinational walks into — not as a second certification.

The revised FADP in force

Parliament adopted the revised FADP on 25 September 2020. The revised Act and its ordinances entered into force on 1 September 2023 with no multi-year private-sector grace period. English-language practice calls it revFADP or nFADP (new FADP). The official purpose is protection of the personality and fundamental rights of natural persons whose personal data are processed. Legal-person data, which the old Act covered, dropped out — a GDPR-like shift candidates should not reverse.

Article 3 is the extra-territorial hook. The Act applies to circumstances that have an effect in Switzerland, even if they were initiated abroad. That effects doctrine is broader wording than GDPR Article 3(2)'s offering/monitoring pair. A U.S. controller with no Swiss office can still be in scope if its processing produces effects in Switzerland — for example, offering services to persons in Switzerland, monitoring them, or running processing that lands on Swiss persons or Swiss infrastructure. Do not tell an examiner the FADP stops at the cantonal border or applies only to Swiss federal agencies.

Sensitive personal data is a defined Swiss list (Article 5), not a carbon copy of GDPR Article 9. It includes data on religious, philosophical, political, or trade-union views or activities; data on health, the intimate sphere, or racial or ethnic origin; genetic data; biometric data that uniquely identifies a natural person; data on administrative or criminal proceedings or sanctions; and data on social-assistance measures. Processing sensitive data raises the FADP's high-risk and consent/justification temperature the same way special-category processing does under the GDPR, but you must use the Swiss list on a Swiss fact pattern (social-assistance and proceedings data are easy misses).

Other operational duties a U.S. examiner can fairly expect at this depth: records of processing in defined situations, a data protection impact assessment when processing may lead to a high risk to personality or fundamental rights, privacy by design and by default, and — where Article 14's conditions are met — a representative in Switzerland for a controller with no Swiss establishment that processes personal data of persons in Switzerland in connection with offering goods or services or monitoring, when that processing is extensive, regular, or high-risk. The Swiss representative is analogous to GDPR Article 27, not identical to it, and DPF certification does not delete it by itself.

High-risk breach notice to the FDPIC

Article 24 is the breach rule the BoK expects you to contrast with U.S. state notice and with GDPR Article 33.

  • The controller notifies the Federal Data Protection and Information Commissioner (FDPIC) of a breach of data security that is likely to lead to a high risk to the data subject's personality or fundamental rights, as quickly as possible ("as soon as possible" / "as quickly as possible" in official English).
  • The notice states at least the nature of the breach, its consequences, and the measures taken or planned.
  • The processor notifies the controller as quickly as possible — not the FDPIC in the first instance.
  • The controller informs the data subject if that is required for the subject's protection or if the FDPIC so requests.

Two contrasts matter. First, the Swiss threshold is high risk, not the GDPR's "risk" to the supervisory authority. Low-risk incidents stay out of the FDPIC inbox. Second, Swiss law uses as soon as possible, not a fixed 72-hour clock. Do not import Article 33's 72 hours onto a pure FADP question. Do not send the Swiss notice to the FTC, and do not assume an FDPIC filing satisfies GDPR Article 33 for EU data subjects in the same incident — a multinational logs each statute's authority, threshold, and clock.

How the FADP intersects the Swiss-U.S. DPF

Swiss transfer rules (FADP Article 16 and related provisions) allow disclosure abroad if the Federal Council has found adequate protection or if safeguards exist (including adapted SCCs and binding corporate rules). Switzerland's recognition of the Swiss-U.S. Data Privacy Framework entered into force on 15 September 2024. From that date, a U.S. organization that has self-certified to the Swiss-U.S. DPF on the Commerce list may receive Swiss personal data in reliance on that recognition, consistent with Swiss law.

Intersection rules for the exam:

  • Swiss-U.S. DPF is a separate Commerce box from EU-U.S. DPF and the UK Extension. EU-only certification does not move Swiss HR files.
  • DPF does not repeal the FADP. The Swiss controller (or the U.S. company, if it is itself the FADP controller) still owes Swiss lawful-processing, sensitive-data, DPIA, and Article 24 duties.
  • An uncertified U.S. importer needs another FADP safeguard — typically Swiss-adapted 2021 SCCs — plus an assessment of U.S. law analogous to a TIA.
  • Trump v. Slaughter review of the EU-U.S. adequacy file is not, as of August 2026, a published Swiss withdrawal of the Swiss-U.S. DPF. Do not invent one. Dual-track the Swiss flows the same way you dual-track EU flows: DPF if certified, adapted SCCs as fallback.

Scenario. A Zurich hospital sends patient billing data to an uncertified U.S. revenue-cycle vendor. The FADP applies (health data, effect in Switzerland). The vendor is not on the Swiss-U.S. DPF list, so Article 16 adequacy is unavailable. The hospital needs Swiss-adapted SCCs (or another safeguard) and a transfer assessment. If attackers later exfiltrate the U.S. file and the incident is likely a high risk to patients' personality rights, the hospital notifies the FDPIC as soon as possible and informs patients if needed for their protection; the U.S. vendor notifies the hospital immediately. A parallel GDPR clock may also run if some patients are in the EEA — that is a second notice, not a substitute.

Other non-U.S. laws a U.S. multinational actually hits

Stay at intersection depth. These are not CIPP/C or CIPP/E outlines.

Canada — PIPEDA. The Personal Information Protection and Electronic Documents Act is the federal private-sector statute for commercial activity (and for federal works, undertakings, and businesses). It is a consent-and-fair-information-principles statute overseen by the Office of the Privacy Commissioner of Canada (OPC). Breach notification is triggered by a real risk of significant harm (RROSH) to the OPC and to individuals. Some provinces have substantially similar private-sector laws; PIPEDA still matters to a U.S. retailer that takes Canadian orders.

Quebec — Law 25. Law 25 (2021, chapter 25) modernized Quebec's private-sector privacy act. Core private-sector duties — a designated person in charge of personal information, privacy impact assessments for certain projects, default privacy settings, tighter consent, and breach notice to the Commission d'accès à l'information (CAI) and to individuals when there is a risk of serious injury — are in force (most provisions 22 September 2023). Law 25 is the Canadian statute most likely to surprise a U.S. company that thought "PIPEDA covers Canada." It is still not a CIPP/C exam inside CIPP/US.

United Kingdom — UK GDPR. After Brexit, the UK GDPR and the Data Protection Act 2018 are the UK regime, supervised by the ICO. Article 3-style extra-territorial reach, lawful bases, DPIA/DPO/representative analogues, and a restricted-transfer rule all still exist. Transfer tools are the IDTA, the UK Addendum to the EU SCCs, the UK Extension to the EU-U.S. DPF (from 12 October 2023) for certified U.S. importers, and UK derogations. The EU has its own adequacy decision for the United Kingdom; that decision helps EU-to-UK flows. It does not make a U.S. company "adequate."

RegimeWhy a U.S. company hits itTransfer / notice hook to remember
Swiss FADPEffects in Switzerland; BoK-namedSwiss-U.S. DPF or adapted SCCs; FDPIC high-risk notice ASAP
PIPEDACanadian commercial activityOPC + individuals if RROSH
Quebec Law 25Persons in Quebec; not "just PIPEDA"CAI + individuals if risk of serious injury
UK GDPRUK establishment or UK targetingIDTA / Addendum / UK Extension to DPF

Exam traps

  • Do not date the revised FADP to 2020 (adoption) instead of 1 September 2023 (in force).
  • Do not paste GDPR's 72-hour, any-risk supervisory notice onto Article 24.
  • Do not treat EU-U.S. DPF certification as Swiss-U.S. DPF certification.
  • Do not turn this section into a CIPP/C walkthrough of every PIPEDA principle or a CIPP/E walkthrough of every UK GDPR recital.
Loading diagram...
FADP Core Duties and Other Non-U.S. Intersections
Test Your Knowledge

Which statement about the revised Swiss Federal Act on Data Protection is accurate for the CIPP/US exam?

A
B
C
D
Test Your Knowledge

Under FADP Article 24, when must a controller notify the Federal Data Protection and Information Commissioner of a data-security breach?

A
B
C
D
Test Your Knowledge

How should a U.S. multinational treat the Swiss-U.S. Data Privacy Framework together with other non-U.S. laws on a CIPP/US fact pattern?

A
B
C
D