/ch-fadp-expert
Swiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notification, individual criminal enforcement, Swiss transfer mechanisms, and key divergences from GDPR.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill ch-fadp-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/ch-fadp-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
Swiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notification, individual criminal enforcement, Swiss transfer mechanisms, and key divergences from GDPR.
SKILL.md
ch-fadp-expert.SKILL.mdname: ch-fadp-expert
description: Swiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notification, individual criminal enforcement, Swiss transfer mechanisms, and key divergences from GDPR.
allowed-tools: Read, Glob, Grep, Write
Swiss FADP Expert
Deep expertise in the Swiss Federal Act on Data Protection (nFADP) — Switzerland's comprehensive data protection law revised in 2023.
Expertise Areas
Framework Overview
**Swiss Federal Act on Data Protection (FADP)** — Revised 2023 (nFADP/nDSG) **Effective Date**: September 1, 2023 **Scope**: Protection of personality and fundamental rights relating to data processing **Articles**: 60+ articles across 10 sections
**Territorial Scope**:
- **Establishment**: Swiss law applies to controllers/processors established in Switzerland
- **Effects in Switzerland**: Offers goods/services to Swiss data subjects OR monitors behavior in Switzerland
- **Applies**: Even if organization not in Switzerland
**Material Scope**:
- Automated processing of personal data
- Manual processing in filing systems
- **Exemptions**: Personal/household use, purely professional activities with limited risk
**Switzerland is not an EU member state**. The FDPIC (Federal Data Protection and Information Commissioner) is the Swiss supervisory authority, not an EU Data Protection Authority. Swiss adequacy decisions are separate from EU adequacy.
**Enforcement Model**:
- **Individual criminal liability**: Responsible individuals face criminal sanctions up to CHF 250,000
- **Not entity-level fines**: Enforcement targets the responsible person, not the legal entity
- **FDPIC enforcement**: Administrative orders and compliance measures
Key Obligations
**Processing Records (RoPA)**
- Controllers must maintain records of processing activities
- **SME carve-out**: Organizations with fewer than 250 employees may be exempt from full records UNLESS processing is likely to result in high risk to personality rights
- **Content**: Similar to GDPR Article 30 but streamlined for Swiss context
**Privacy by Design and Default**
- Controllers must implement appropriate technical and organizational measures
- **Built-in privacy**: At time of determining processing means and during processing itself
- **Default settings**: Most protective configuration by default
- **Focus**: Data minimization, pseudonymization, transparency
**Transparency / Privacy Notice**
- Controllers must provide clear information about processing
- **Timing**: At collection or before processing begins
- **Content**: Identity of controller, purposes of processing, categories of data, recipients
- **Special categories**: Additional disclosure for sensitive data processing
- **Data subject rights**: Information about access, rectification, objection rights
**Data Subject Rights**
- **Right of Access**: Data subjects can request confirmation of processing and access to their data
- **Right to Rectification**: Inaccurate data must be corrected
- **Right to Erasure**: Data must be deleted if no longer necessary for processing purpose
- **Right to Data Portability**: Right to receive data in structured, commonly used format (more limited than GDPR)
- **Right to Object**: Can object to processing based on overriding private or public interest
- **Note**: Swiss FADP rights are somewhat more limited in scope than GDPR; no explicit right to restriction of processing
**Data Protection Impact Assessments**
- **Trigger threshold**: Processing likely to result in **high risk** to personality or fundamental rights
- **High-risk indicators**: Systematic profiling, large-scale processing of sensitive data, public monitoring
- **DSO consultation**: If DSO is appointed, they must be consulted on high-risk processing
- **Content**: Systematic description of processing, necessity/proportionality assessment, risk assessment, mitigation measures
**Breach Notification**
- **Trigger**: Breaches of security that pose a **high risk** to personality or fundamental rights
- **Timing**: Notify FDPIC **"as soon as possible"** — urgency determined by risk level
- **No fixed deadline**: Unlike GDPR which has a strict deadline, nFADP uses risk-based urgency
- **Content**: Nature of breach, categories of data subjects and data, likely consequences, mitigation measures
- **Data subject notification**: Required if high risk and not adequately mitigated
**Cross-Border Transfers**
- **Adequacy list**: FDPIC maintains countries with adequate protection (including EU under GDPR)
- **Swiss-approved SCCs**: Standard Contractual Clauses must be approved by FDPIC
- **EU SCCs alone are NOT sufficient**: European Union SCCs are not automatically valid under Swiss law
- **Derogations**: Explicit consent, performance of contract, important public interest, legal claims, vital interests, legitimate interests (with safeguards)
**Processor Agreements**
- Controllers must have written agreements with processors
- **Mandatory content**: Subject matter, duration, nature/purpose, data categories, controller obligations
- **Processor obligations**: Process only on controller instructions, ensure confidentiality, implement security measures, assist with breach notification, allow audits
- **Sub-processors**: Require controller authorization (general or specific)
**Data Security Officer (DSO)**
- **Voluntary appointment**: Unlike GDPR which requires DPO based on core activities, nFADP DSO appointment is entirely voluntary
- **Organizations may appoint**: Any controller can appoint a DSO
- **Same duties apply**: If appointed, DSO has similar monitoring, advisory, and cooperation functions
- **No GDPR Article 37 trigger**: No automatic requirement based on core activities or scale
**Sensitive Data**
**Special Categories** (require heightened protection):
- Health data
- Data about the intimate sphere
Read more
name: ch-fadp-expert description: Swiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notification, individual criminal enforcement, Swiss transfer mechanisms, and key divergences from GDPR. allowed-tools: Read, Glob, Grep, Write
Swiss FADP Expert
Deep expertise in the Swiss Federal Act on Data Protection (nFADP) — Switzerland's comprehensive data protection law revised in 2023.
Expertise Areas
Framework Overview
**Swiss Federal Act on Data Protection (FADP)** — Revised 2023 (nFADP/nDSG) **Effective Date**: September 1, 2023 **Scope**: Protection of personality and fundamental rights relating to data processing **Articles**: 60+ articles across 10 sections
**Territorial Scope**:
- **Establishment**: Swiss law applies to controllers/processors established in Switzerland
- **Effects in Switzerland**: Offers goods/services to Swiss data subjects OR monitors behavior in Switzerland
- **Applies**: Even if organization not in Switzerland
**Material Scope**:
- Automated processing of personal data
- Manual processing in filing systems
- **Exemptions**: Personal/household use, purely professional activities with limited risk
**Switzerland is not an EU member state**. The FDPIC (Federal Data Protection and Information Commissioner) is the Swiss supervisory authority, not an EU Data Protection Authority. Swiss adequacy decisions are separate from EU adequacy.
**Enforcement Model**:
- **Individual criminal liability**: Responsible individuals face criminal sanctions up to CHF 250,000
- **Not entity-level fines**: Enforcement targets the responsible person, not the legal entity
- **FDPIC enforcement**: Administrative orders and compliance measures
Key Obligations
**Processing Records (RoPA)**
- Controllers must maintain records of processing activities
- **SME carve-out**: Organizations with fewer than 250 employees may be exempt from full records UNLESS processing is likely to result in high risk to personality rights
- **Content**: Similar to GDPR Article 30 but streamlined for Swiss context
**Privacy by Design and Default**
- Controllers must implement appropriate technical and organizational measures
- **Built-in privacy**: At time of determining processing means and during processing itself
- **Default settings**: Most protective configuration by default
- **Focus**: Data minimization, pseudonymization, transparency
**Transparency / Privacy Notice**
- Controllers must provide clear information about processing
- **Timing**: At collection or before processing begins
- **Content**: Identity of controller, purposes of processing, categories of data, recipients
- **Special categories**: Additional disclosure for sensitive data processing
- **Data subject rights**: Information about access, rectification, objection rights
**Data Subject Rights**
- **Right of Access**: Data subjects can request confirmation of processing and access to their data
- **Right to Rectification**: Inaccurate data must be corrected
- **Right to Erasure**: Data must be deleted if no longer necessary for processing purpose
- **Right to Data Portability**: Right to receive data in structured, commonly used format (more limited than GDPR)
- **Right to Object**: Can object to processing based on overriding private or public interest
- **Note**: Swiss FADP rights are somewhat more limited in scope than GDPR; no explicit right to restriction of processing
**Data Protection Impact Assessments**
- **Trigger threshold**: Processing likely to result in **high risk** to personality or fundamental rights
- **High-risk indicators**: Systematic profiling, large-scale processing of sensitive data, public monitoring
- **DSO consultation**: If DSO is appointed, they must be consulted on high-risk processing
- **Content**: Systematic description of processing, necessity/proportionality assessment, risk assessment, mitigation measures
**Breach Notification**
- **Trigger**: Breaches of security that pose a **high risk** to personality or fundamental rights
- **Timing**: Notify FDPIC **"as soon as possible"** — urgency determined by risk level
- **No fixed deadline**: Unlike GDPR which has a strict deadline, nFADP uses risk-based urgency
- **Content**: Nature of breach, categories of data subjects and data, likely consequences, mitigation measures
- **Data subject notification**: Required if high risk and not adequately mitigated
**Cross-Border Transfers**
- **Adequacy list**: FDPIC maintains countries with adequate protection (including EU under GDPR)
- **Swiss-approved SCCs**: Standard Contractual Clauses must be approved by FDPIC
- **EU SCCs alone are NOT sufficient**: European Union SCCs are not automatically valid under Swiss law
- **Derogations**: Explicit consent, performance of contract, important public interest, legal claims, vital interests, legitimate interests (with safeguards)
**Processor Agreements**
- Controllers must have written agreements with processors
- **Mandatory content**: Subject matter, duration, nature/purpose, data categories, controller obligations
- **Processor obligations**: Process only on controller instructions, ensure confidentiality, implement security measures, assist with breach notification, allow audits
- **Sub-processors**: Require controller authorization (general or specific)
**Data Security Officer (DSO)**
- **Voluntary appointment**: Unlike GDPR which requires DPO based on core activities, nFADP DSO appointment is entirely voluntary
- **Organizations may appoint**: Any controller can appoint a DSO
- **Same duties apply**: If appointed, DSO has similar monitoring, advisory, and cooperation functions
- **No GDPR Article 37 trigger**: No automatic requirement based on core activities or scale
**Sensitive Data**
**Special Categories** (require heightened protection):
- Health data
- Data about the intimate sphere
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

