Data Protection

The new Swiss Data Protection Law: Get ready

We help you assess the impact on your business and implement the steps towards compliance with the new Swiss Data Protection Act (nFADP).

Switzerland's largest law firm focused on tech companies
Expert advice on the new Swiss Data Protection Act (nFADP)
Compliance checks, workshops & ongoing support
Transparent flat-fee packages — know the cost before we start
Serving startups, scale-ups & established tech companies
Trusted by 1000+ clients
Trusted by 1'500+ tech companies & investors
Thomas Kuster
"Data protection is not just a legal checkbox — it's a trust signal for your customers and investors. Book a call with me and my team and we'll get you compliant, efficiently."

Thomas Kuster · Partner @ LEXR  ·  Book your free call →

Trusted by tech companies on their data protection journey

Yoko Spirig
The data privacy experts at LEXR provided us with a tailor-made compliance package and were very responsive to all of our questions.
Yoko Spirig
CEO, Ledgy
Sandro Matter
Tapping into LEXR’s expertise and leveraging their advice was a great experience – as great as it can be when dealing with such an uncharming topic like data privacy. We kicked it off with an overall assessment. After that, a clear action plan with specific sub-task ownership and a pragmatic, hands-on approach were the key ingredients for successfully revamping our data privacy setup in view of the revised Data Protection Act.
Sandro Matter
Co-Founder & CFO, vlot

How we solve your challenges

From a quick website check to a full company-wide compliance programme — the right solution for every stage.

The website is your company's business card. We ensure your privacy policy, cookie policy and imprint meet the requirements of the nFADP — with a flat-fee package so you know the cost upfront.

Data protection reaches far beyond your website — it covers HR, marketing, your app and every data-processing activity. Our Compliance Check tells you exactly what needs to be done and gives you an actionable roadmap.

We design tailor-made workshops and trainings on data protection for employees, management, founders and entrepreneurs — practical, up to date and adapted to your industry.

Our Data Protection Expert service provides you with on-demand help to implement open action points and handle day-to-day data protection questions, so you can focus on running your business.

Whenever a planned data-processing activity is likely to entail a high risk for data subjects, a DPIA is mandatory under the nFADP. We carry out the assessment, document the risks and, where required, liaise with the FDPIC.

The LEXR approach

How we deliver Data Protection, AI-amplified

Step 01

Matter in

Brief us in plain language — we scope it and route it to the right specialist.

Intake < 4h
Step 02 AI · Privileged

AI does the heavy lifting

Our own AI stack drafts, reviews and cross-checks — inside privilege.

60% fewer draft cycles
Step 03

Senior lawyer signs off

The specialist who built the strategy reviews and signs every output.

Lars Fidan Maximilian Krähenbühl Christian Meisser
Step 04

Output delivered

On scope, on the quoted price — delivered into your workflow.

Scope and price are fixed in writing before we start — AI absorbs the lift, not your budget.

Our nFADP services

Everything you need to comply with the new Swiss Data Protection Act — from a one-off check to ongoing expert support.

nFADP compliance reviewPrivacy & cookie policyRecords of processing activitiesData protection impact assessmentData breach notificationEmployee & management trainingData Processing Agreement (DPA)Ongoing Data Protection Expert retainer

Why LEXR

01

Advice & best practices

Personal advice from experienced Swiss and German legal advisors who are always up to date with the latest developments in data protection law — including every nFADP update.

02

Extensive hands-on experience

We regularly assist startups and established technology companies with their data protection obligations. Where possible we use proven standards; where necessary we tailor our approach to your specific business model.

03

Efficient & price-transparent

Whether a quick website check, a full compliance assessment or an individual workshop — we offer the right package at a transparent price. No billable-hour surprises.

nFADP FAQ

The questions founders and companies ask us most about the new Swiss Data Protection Act.

The revision was driven by two factors: a request from the business community for a modernised framework, and the need to keep up with technological developments. Crucially, the new provisions ensure compatibility with EU law and preserve Switzerland's adequacy status — meaning cross-border data transfers between Switzerland and the EU can continue without additional restrictions.

The Federal Council decided in August 2022 that the nFADP entered into force on 1 September 2023. Companies were given a transition period of one year to make the necessary arrangements. If you have not yet reviewed your data protection setup, now is the time.

The nFADP expands information obligations, introduces mandatory records of processing activities for companies above a certain size, requires data protection impact assessments for high-risk processing, and mandates breach notification to the FDPIC in certain cases. It also strengthens data subjects' rights.

Yes. The maximum fine for violations increases from CHF 10'000 to CHF 250'000. Importantly, the penalties target natural persons — specifically management, board members and those actually responsible — not just companies. This means executives can be held personally liable for non-compliance.

A DPIA must be carried out whenever a planned data-processing activity is likely to entail a high risk for the rights of data subjects — for example, extensive processing of sensitive personal data such as health information. The assessment must describe the processing, evaluate the risks and identify protective measures. If a high residual risk remains, an opinion must be obtained from the FDPIC.

The nFADP applies to any organisation that processes personal data of persons in Switzerland, regardless of where the company is based. If you are a Swiss company or an international company with Swiss customers or employees, you need to comply.

Our standard turnaround for a website compliance review is a few business days. A full company-wide compliance check is scoped on a free call and typically completed within two to three weeks. We adapt to your timeline.

Let's get you compliant

Book your free call and become one of our 1'000+ happy clients.

Dive deeper into data protection

Data ProtectionAI Features in Your SaaS? What the EU AI Act Means for YouTeam LEXR · Mar 2026Read more →Data ProtectionYou Need to Fix These 5 Points in Your SaaS Agreements Now!Nadine Saalbach · Sep 2025Read more →Data ProtectionNavigating the EU AI Act: A Comprehensive Analysis and Compliance GuideTeam LEXR · May 2024Read more →Data ProtectionNew EU Regulations: A Blueprint for Growth in the Digital SectorTeam LEXR · May 2024Read more →Data ProtectionCybersecurity and data protection: keeping your company's data safeTeam LEXR · Apr 2024Read more →Data ProtectionFrom concept to compliance: Legal Bases for AI training explainedTeam LEXR · Mar 2024Read more →Data ProtectionData Processing Agreements: Navigating the Essentials for Data Protection Compliance (Part 2)Team LEXR · Feb 2024Read more →Data ProtectionData Processing Agreements: Navigating the Essentials for Data Protection Compliance (Part 1)Team LEXR · Jan 2024Read more →Data ProtectionPseudonymisation versus anonymisation: a practical privacy guideTeam LEXR · Dec 2023Read more →Data ProtectionHow to handle data breaches – a privacy best practice guideTeam LEXR · Sep 2023Read more →Data ProtectionNavigating AI tools and data protection: A guide for compliant company practicesTeam LEXR · Jul 2023Read more →Data ProtectionThe new Swiss Data Protection Act comes into force: What tech companies need to do nowTeam LEXR · Jun 2023Read more →Data ProtectionNavigating Privacy Rules for App Developers: App Store Compliance and Privacy RequirementsTeam LEXR · Apr 2023Read more →Data ProtectionKYC for FinTech companies: Data protection guide part 3 - Manage the dataTeam LEXR · Mar 2023Read more →Data ProtectionKYC for FinTech companies: Data protection guide part 2 - Follow the dataTeam LEXR · Feb 2023Read more →Data ProtectionKYC for FinTech companies - Guide to a data protection compliant implementationTeam LEXR · Feb 2023Read more →Data ProtectionChecklist: How to write a privacy policy for the new FADP and GDPR?Team LEXR · Jun 2021Read more →Data ProtectionData Processing Agreement I: Determine whether you are a Controller or a ProcessorTeam LEXR · Apr 2021Read more →Data ProtectionSchrems II impact on privacy shield & SCCsTeam LEXR · Jul 2020Read more →Data ProtectionGDPR impact on AdTech and Real-Time Bidding (RTB)Team LEXR · May 2020Read more →Data ProtectionConfidential Computing and GDPRTeam LEXR · Mar 2020Read more →Data ProtectionThe License to Kill and the right to be forgotten - Gaming in the Age of GDPRTeam LEXR · Mar 2020Read more →Data ProtectionEmployee awareness as the key to security and data privacyTeam LEXR · Feb 2020Read more →Data ProtectionThe Internet of Things in the GDPR eraTeam LEXR · Jan 2020Read more →Data ProtectionGDPR in Switzerland - What it means for businessesTeam LEXR · Dec 2018Read more →