This article gives technical pointers. It is not legal advice: for your situation, consult a lawyer.
The new Federal Act on Data Protection (nFADP) has been in force since 1st September 2023. It applies to any business that processes personal data, whatever its size: a customer file, patient records or employee data are enough.
What the law requires on security
Technical and organisational measures appropriate to the risk. The key word is “appropriate”: a three-person practice is not expected to do what a bank does. But something is expected, and you must be able to show it.
The technical foundation
- One account per person, never a shared password, and two-factor authentication on e-mail and remote access
- Limited access rights: everyone sees what they need
- Encryption of laptops and backups: a stolen computer must not become a data leak
- Tested backups, including one copy out of reach
- Updates done on time, and an antivirus that someone monitors
- A record of logins: knowing who logged in, from where, and when
- Departures handled the same day: accounts closed, shared credentials changed
- Wiping disks before giving away or recycling a device
Knowing where the data is
E-mail, online storage, management software, backup: for each one, with which provider, in which country. It is as much a technical question as a legal one, and many businesses cannot answer it. The inventory is quick.
In the event of a data security breach
If a breach poses a high risk to the people concerned, it must be reported to the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible. Hence the value of having decided in advance who does what: contain, establish the facts, assess the risk with a lawyer, report if necessary.
Not to be confused: the obligation to report a cyberattack to the Federal Office for Cybersecurity (NCSC) within 24 hours, in force since 1st April 2025, only applies to operators of critical infrastructure. An ordinary SME is not subject to it; it can, however, voluntarily report an incident to the NCSC, which also publishes useful recommendations.
What is for the lawyer, not the IT technician
The record of processing activities (from which some small businesses are exempt), informing the people concerned, contracts with processors, impact assessments where required, transfers abroad. We provide the technical facts; the lawyer assesses them.
Where to start
With what protects the most for the least effort: two-factor authentication, laptop encryption, and a restore test. Then a written review, which also serves as proof that you have dealt with it.
In short: the nFADP asks for nothing exotic on the technical side: it is good security practice, applied and documented. See Data security & nFADP and the security audit.