Everything you need to know about the nLPD
The new Swiss Federal Act on Data Protection (nLPD) came into force on September 1, 2023. Inspired by the European GDPR, it strengthens the rights of data subjects and the obligations of Swiss and foreign companies that process data of Swiss residents. With Data Comply One, manage your nLPD compliance like your GDPR, from the same platform.
Sep 1, 2023
Effective date
CHF 250k
Max criminal fine (individuals)
Switzerland
Scope + extraterritorial
GDPR-aligned
Inspired by the GDPR
What is the nLPD?
The new Swiss Federal Act on Data Protection (nLPD) modernised the Swiss legal framework and aligned it with European standards (GDPR), while keeping Swiss specificities. It applies to any processing of personal data of Swiss residents, including by foreign companies.
Strengthens rights of data subjects
Expands transparency obligations
Introduces personal criminal sanctions
Imposes data breach notification
Mandates a register of processing activities
Who is concerned by the nLPD?
Every Swiss or foreign organisation processing personal data of Swiss residents is concerned, regardless of size or industry.
Swiss companies of every size
Foreign companies processing Swiss data
Public bodies and associations
Subprocessors and providers
Healthcare professionals
Your nLPD obligations
The nLPD imposes specific obligations that overlap with the GDPR but also have unique Swiss elements.
Maintain a register of processing activities (over 250 employees or high-risk processing)
Carry out a DPIA for high-risk processing
Notify data breaches to the FDPIC
Designate a Data Protection Advisor (CPD) in some cases
Respect transparency and information duties
Frame international data transfers
Sanctions and inspections
The nLPD introduces personal criminal sanctions for company directors and employees, which is one of its main specificities.
Criminal fines up to CHF 250,000 for individuals
No corporate fine but individuals can be prosecuted
Administrative measures from the FDPIC
Reputational damage in case of public sanction
Simplifiez votre conformité nLPD avec Data Comply One
nLPD with Data Comply One
Use the platform to manage your nLPD compliance the same way as your GDPR. Same register, same workflows.
Discover the platformOutsourced DPA
A Swiss-recognised expert handles your nLPD compliance.
Schedule a chatnLPD e-learning
Train your Swiss teams on the new act.
View the programGDPR + nLPD audit
Identify gaps with both regulations in one go.
Request an auditFAQ nLPD
Prêt à piloter votre conformité nLPD ?
30 minutes pour évaluer vos enjeux, sans engagement.
Ils nous font confiance
Plus de 1 000 entreprises et organisations nous font confiance








































































































































































Découvrir les autres réglementations européennes
Construisez une vision globale de votre conformité multi-réglementaire.
RGPD
Protection des données personnelles UE.
DécouvrirNIS 2
Cybersécurité européenne · entités essentielles & importantes.
DécouvrirDORA
Résilience opérationnelle numérique · secteur financier.
DécouvrirAI Act
Gouvernance des systèmes d'intelligence artificielle.
DécouvrirData Act
Partage et accès aux données B2B / B2G.
DécouvrirDécouvrir les autres solutions DCO
Combinez plusieurs solutions pour une approche globale de votre conformité.
DPO externalisé
Un DPO désigné CNIL pour piloter votre RGPD.
DécouvrirRSSI externalisé
Un RSSI dédié pour la cybersécurité (NIS 2 · DORA).
DécouvrirPlateforme logicielle
Le logiciel tout-en-un de pilotage de la conformité.
DécouvrirFormation e-learning
Sensibilisez vos équipes avec Daia (RGPD · IA · Cyber).
Découvrir