Skip to content

/ch-fadp-expert

Swiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notification, individual criminal enforcement, Swiss transfer mechanisms, and key divergences from GDPR.

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill ch-fadp-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/ch-fadp-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

Swiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notification, individual criminal enforcement, Swiss transfer mechanisms, and key divergences from GDPR.

SKILL.md

ch-fadp-expert.SKILL.md
name: ch-fadp-expert
description: Swiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notification, individual criminal enforcement, Swiss transfer mechanisms, and key divergences from GDPR.
allowed-tools: Read, Glob, Grep, Write

Swiss FADP Expert

Deep expertise in the Swiss Federal Act on Data Protection (nFADP) — Switzerland's comprehensive data protection law revised in 2023.

Expertise Areas

Framework Overview

**Swiss Federal Act on Data Protection (FADP)** — Revised 2023 (nFADP/nDSG) **Effective Date**: September 1, 2023 **Scope**: Protection of personality and fundamental rights relating to data processing **Articles**: 60+ articles across 10 sections

**Territorial Scope**:

  • **Establishment**: Swiss law applies to controllers/processors established in Switzerland
  • **Effects in Switzerland**: Offers goods/services to Swiss data subjects OR monitors behavior in Switzerland
  • **Applies**: Even if organization not in Switzerland

**Material Scope**:

  • Automated processing of personal data
  • Manual processing in filing systems
  • **Exemptions**: Personal/household use, purely professional activities with limited risk

**Switzerland is not an EU member state**. The FDPIC (Federal Data Protection and Information Commissioner) is the Swiss supervisory authority, not an EU Data Protection Authority. Swiss adequacy decisions are separate from EU adequacy.

**Enforcement Model**:

  • **Individual criminal liability**: Responsible individuals face criminal sanctions up to CHF 250,000
  • **Not entity-level fines**: Enforcement targets the responsible person, not the legal entity
  • **FDPIC enforcement**: Administrative orders and compliance measures

Key Obligations

**Processing Records (RoPA)**

  • Controllers must maintain records of processing activities
  • **SME carve-out**: Organizations with fewer than 250 employees may be exempt from full records UNLESS processing is likely to result in high risk to personality rights
  • **Content**: Similar to GDPR Article 30 but streamlined for Swiss context

**Privacy by Design and Default**

  • Controllers must implement appropriate technical and organizational measures
  • **Built-in privacy**: At time of determining processing means and during processing itself
  • **Default settings**: Most protective configuration by default
  • **Focus**: Data minimization, pseudonymization, transparency

**Transparency / Privacy Notice**

  • Controllers must provide clear information about processing
  • **Timing**: At collection or before processing begins
  • **Content**: Identity of controller, purposes of processing, categories of data, recipients
  • **Special categories**: Additional disclosure for sensitive data processing
  • **Data subject rights**: Information about access, rectification, objection rights

**Data Subject Rights**

  • **Right of Access**: Data subjects can request confirmation of processing and access to their data
  • **Right to Rectification**: Inaccurate data must be corrected
  • **Right to Erasure**: Data must be deleted if no longer necessary for processing purpose
  • **Right to Data Portability**: Right to receive data in structured, commonly used format (more limited than GDPR)
  • **Right to Object**: Can object to processing based on overriding private or public interest
  • **Note**: Swiss FADP rights are somewhat more limited in scope than GDPR; no explicit right to restriction of processing

**Data Protection Impact Assessments**

  • **Trigger threshold**: Processing likely to result in **high risk** to personality or fundamental rights
  • **High-risk indicators**: Systematic profiling, large-scale processing of sensitive data, public monitoring
  • **DSO consultation**: If DSO is appointed, they must be consulted on high-risk processing
  • **Content**: Systematic description of processing, necessity/proportionality assessment, risk assessment, mitigation measures

**Breach Notification**

  • **Trigger**: Breaches of security that pose a **high risk** to personality or fundamental rights
  • **Timing**: Notify FDPIC **"as soon as possible"** — urgency determined by risk level
  • **No fixed deadline**: Unlike GDPR which has a strict deadline, nFADP uses risk-based urgency
  • **Content**: Nature of breach, categories of data subjects and data, likely consequences, mitigation measures
  • **Data subject notification**: Required if high risk and not adequately mitigated

**Cross-Border Transfers**

  • **Adequacy list**: FDPIC maintains countries with adequate protection (including EU under GDPR)
  • **Swiss-approved SCCs**: Standard Contractual Clauses must be approved by FDPIC
  • **EU SCCs alone are NOT sufficient**: European Union SCCs are not automatically valid under Swiss law
  • **Derogations**: Explicit consent, performance of contract, important public interest, legal claims, vital interests, legitimate interests (with safeguards)

**Processor Agreements**

  • Controllers must have written agreements with processors
  • **Mandatory content**: Subject matter, duration, nature/purpose, data categories, controller obligations
  • **Processor obligations**: Process only on controller instructions, ensure confidentiality, implement security measures, assist with breach notification, allow audits
  • **Sub-processors**: Require controller authorization (general or specific)

**Data Security Officer (DSO)**

  • **Voluntary appointment**: Unlike GDPR which requires DPO based on core activities, nFADP DSO appointment is entirely voluntary
  • **Organizations may appoint**: Any controller can appoint a DSO
  • **Same duties apply**: If appointed, DSO has similar monitoring, advisory, and cooperation functions
  • **No GDPR Article 37 trigger**: No automatic requirement based on core activities or scale

**Sensitive Data**

**Special Categories** (require heightened protection):

  • Health data
  • Data about the intimate sphere
Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked