The new Swiss Data Protection Law: Get ready
We help you assess the impact on your business and implement the steps towards compliance with the new Swiss Data Protection Act (nFADP).
"Data protection is not just a legal checkbox — it's a trust signal for your customers and investors. Book a call with me and my team and we'll get you compliant, efficiently."
Thomas Kuster · Partner @ LEXR · Book your free call →
Trusted by tech companies on their data protection journey
The data privacy experts at LEXR provided us with a tailor-made compliance package and were very responsive to all of our questions.
Tapping into LEXR’s expertise and leveraging their advice was a great experience – as great as it can be when dealing with such an uncharming topic like data privacy. We kicked it off with an overall assessment. After that, a clear action plan with specific sub-task ownership and a pragmatic, hands-on approach were the key ingredients for successfully revamping our data privacy setup in view of the revised Data Protection Act.
How we solve your challenges
From a quick website check to a full company-wide compliance programme — the right solution for every stage.
The website is your company's business card. We ensure your privacy policy, cookie policy and imprint meet the requirements of the nFADP — with a flat-fee package so you know the cost upfront.
Data protection reaches far beyond your website — it covers HR, marketing, your app and every data-processing activity. Our Compliance Check tells you exactly what needs to be done and gives you an actionable roadmap.
We design tailor-made workshops and trainings on data protection for employees, management, founders and entrepreneurs — practical, up to date and adapted to your industry.
Our Data Protection Expert service provides you with on-demand help to implement open action points and handle day-to-day data protection questions, so you can focus on running your business.
Whenever a planned data-processing activity is likely to entail a high risk for data subjects, a DPIA is mandatory under the nFADP. We carry out the assessment, document the risks and, where required, liaise with the FDPIC.
How we deliver Data Protection, AI-amplified
Matter in
Brief us in plain language — we scope it and route it to the right specialist.
Intake < 4hAI does the heavy lifting
Our own AI stack drafts, reviews and cross-checks — inside privilege.
60% fewer draft cyclesSenior lawyer signs off
The specialist who built the strategy reviews and signs every output.
Output delivered
On scope, on the quoted price — delivered into your workflow.
Scope and price are fixed in writing before we start — AI absorbs the lift, not your budget.
Our nFADP services
Everything you need to comply with the new Swiss Data Protection Act — from a one-off check to ongoing expert support.
Find your perfect flat fee plan
Website Privacy Compliance
Privacy policy, cookie policy and imprint — fully nFADP-compliant at a transparent flat fee.
Book your free call →Data Protection Compliance Check
A comprehensive assessment of your data protection setup with an actionable remediation plan.
Book your free call →Data Protection Workshops & Trainings
Tailored workshops for employees, management or founders — practical and up to date.
Book your free call →Data Protection Expert Subscription
Your certified data protection expert on a monthly retainer for ongoing questions and implementation.
Book your free call →Why LEXR
Advice & best practices
Personal advice from experienced Swiss and German legal advisors who are always up to date with the latest developments in data protection law — including every nFADP update.
Extensive hands-on experience
We regularly assist startups and established technology companies with their data protection obligations. Where possible we use proven standards; where necessary we tailor our approach to your specific business model.
Efficient & price-transparent
Whether a quick website check, a full compliance assessment or an individual workshop — we offer the right package at a transparent price. No billable-hour surprises.
nFADP FAQ
The questions founders and companies ask us most about the new Swiss Data Protection Act.
The revision was driven by two factors: a request from the business community for a modernised framework, and the need to keep up with technological developments. Crucially, the new provisions ensure compatibility with EU law and preserve Switzerland's adequacy status — meaning cross-border data transfers between Switzerland and the EU can continue without additional restrictions.
The Federal Council decided in August 2022 that the nFADP entered into force on 1 September 2023. Companies were given a transition period of one year to make the necessary arrangements. If you have not yet reviewed your data protection setup, now is the time.
The nFADP expands information obligations, introduces mandatory records of processing activities for companies above a certain size, requires data protection impact assessments for high-risk processing, and mandates breach notification to the FDPIC in certain cases. It also strengthens data subjects' rights.
Yes. The maximum fine for violations increases from CHF 10'000 to CHF 250'000. Importantly, the penalties target natural persons — specifically management, board members and those actually responsible — not just companies. This means executives can be held personally liable for non-compliance.
A DPIA must be carried out whenever a planned data-processing activity is likely to entail a high risk for the rights of data subjects — for example, extensive processing of sensitive personal data such as health information. The assessment must describe the processing, evaluate the risks and identify protective measures. If a high residual risk remains, an opinion must be obtained from the FDPIC.
The nFADP applies to any organisation that processes personal data of persons in Switzerland, regardless of where the company is based. If you are a Swiss company or an international company with Swiss customers or employees, you need to comply.
Our standard turnaround for a website compliance review is a few business days. A full company-wide compliance check is scoped on a free call and typically completed within two to three weeks. We adapt to your timeline.
Meet your data protection team
Let's get you compliant
Book your free call and become one of our 1'000+ happy clients.
























