10 min read
Swiss data protection terms, explained for small businesses
Controller, processor, disclosure abroad: the terms the Swiss FADP defines, each with a plain definition, an everyday example and the article it comes from.

A bike workshop in Thun switches to new scheduling software. The contract says “processing by a processor”, the provider’s privacy statement says “disclosure abroad”, the sales conversation offers “GDPR compliant”, and a week later a customer writes to say she is “exercising her right of access”. Four expressions, four different origins — and not one of them explains itself.
Most of these words are defined in the Swiss Federal Act on Data Protection (FADP), briefly and in one place. A few others that come up just as often are not in it at all. This post walks through the terms you actually meet when reading a contract or a privacy statement: what the statute says, what that looks like day to day in a small business, and why the word turns up where it does.
The words the act opens with
Article 5 FADP is a list of definitions. Eleven letters that carry the rest of the statute.
Personal data, under Art. 5 let. a FADP, is “all information relating to an identified or identifiable natural person”. Identifiable is enough: customer number 4711 next to a repair list is personal data as soon as the mapping to a name exists somewhere in the workshop. That is why the term sits at the top of almost every contract — it decides whether the act applies to a body of data at all. A data subject is the natural person whose data is being processed (let. b): the customer, the course participant, the employee.
Processing is broader than the English word suggests. Art. 5 let. d FADP covers “any operation relating to personal data, irrespective of the means and procedures used”, expressly including mere collection, recording, storage, archiving and deletion. A spreadsheet that has sat untouched on a drive for four years is therefore being processed. Disclosure is the special case beside it: the transmission of personal data or making it accessible (let. e). That is why contracts say “disclosure” rather than “sharing” — the statute knows one word and not the other.
Sensitive personal data is listed exhaustively in Art. 5 let. c FADP: data on religious, ideological, political or trade union views or activities; data on health, the intimate sphere or racial or ethnic origin; genetic data; biometric data that uniquely identifies a natural person; data on administrative and criminal proceedings and sanctions; and data on social assistance measures. A name is not on that list, nor is a phone number. “My knee still can’t take the load after the fall” in the comments box of a sign-up form is. The category appears in contracts because several other provisions attach to it — among them the form of consent, which under Art. 6 para. 7 let. a FADP has to be explicit here.
Profiling, under let. f, is automated processing used to evaluate personal aspects of a person — work performance, economic situation, health, preferences, behaviour, location. The button labelled “calculate customer segments” in a point-of-sale system is the term in its practical form.
Who decides, and who merely carries out
The single most important distinction in the act is between two roles, because it settles who answers to whom.
The controller, under Art. 5 let. j FADP, is the private person or federal body that “alone or jointly with others decides on the purpose and means of processing”. The processor processes personal data on the controller’s behalf (let. k). The bike workshop decides that it keeps appointments, which fields the form has and how long entries stay — it is the controller. The software provider carries out — it is the processor. The Federal Data Protection and Information Commissioner (FDPIC) lists cloud providers, web hosts, mailing companies, call centres, fiduciaries and IT support firms as typical processors.
Why the distinction is everywhere: it does not move the responsibility. The FDPIC states that the client remains responsible for data protection even when it outsources the processing — it has to select the processor carefully, instruct it appropriately and supervise it as far as necessary. Art. 9 para. 1 FADP ties outsourcing to two conditions: the data is processed only as the controller itself would be permitted to, and no statutory or contractual duty of confidentiality prohibits the transfer.
Sub-processing continues the same chain. Under Art. 9 para. 3 FADP a processor may transfer processing to a third party only with the controller’s prior authorisation. Where that authorisation is general, the processor informs the controller of every addition or replacement, and the controller may object. That is why so many providers keep a public list of their sub-processors: the list is what that authorisation looks like in practice.
The terms that appear in a privacy statement
Disclosure abroad means transmitting personal data to a recipient outside Switzerland. It is permitted where the Federal Council has established that the state concerned guarantees an adequate level of protection (Art. 16 para. 1 FADP); those states are listed in Annex 1 DPO, the Data Protection Ordinance. Absent such a decision, Art. 16 para. 2 FADP names the possible safeguards, among them standard data protection clauses approved, issued or recognised by the FDPIC. For a driving school in Olten whose appointment reminders go out through a foreign SMS gateway this is not theoretical: the state, and where applicable the safeguard, is part of what the data subject is informed about (Art. 19 para. 4 FADP).
Duty to inform is the technical name for what a privacy statement does. Art. 19 para. 2 FADP sets the minimum: the identity and contact details of the controller, the purpose of processing, and where applicable the recipients or categories of recipients. The FDPIC assigns the privacy statement expressly to this provision.
Right of access is the other side. Anyone may ask the controller whether personal data about them is being processed, and receives with it the data itself, the purpose, the retention period and the recipients, among other things (Art. 25 FADP). The information is provided free of charge as a rule and normally within 30 days; the Ordinance sets the same deadline and allows a contribution to costs of at most CHF 300 where the effort would be disproportionate (Art. 18 and 19 DPO). The request goes to the workshop, not to the software provider: where a controller has data processed by a processor, it remains under the duty to provide information (Art. 25 para. 4 FADP).
Record of processing activities is the internal list described in Art. 12 FADP: purpose, categories of data subjects and of data, categories of recipients, where possible the retention period, and for a disclosure abroad the state and the safeguards. It comes with an exception that often gets lost in conversation: undertakings and other private-law organisations employing fewer than 250 people on 1 January of a year, and natural persons, are exempt from keeping one — unless sensitive personal data is processed on a large scale or high-risk profiling takes place (Art. 24 DPO).
Data security is framed in Art. 8 FADP as a duty of controller and processor alike to ensure security appropriate to the risk through technical and organisational measures. What that means is spelled out in Art. 2 DPO: confidentiality, availability, integrity and traceability. Those four words are why providers’ security pages so often share the same structure.
Data protection by design and by default is the statutory wording for what a sales conversation calls “privacy by design” and “privacy by default”. Art. 7 FADP requires the controller to shape the processing from the planning stage onwards so that data protection rules are met, and to ensure through appropriate default settings that processing stays limited to the minimum required for the purpose, unless the data subject specifies otherwise. Day to day, that is the question of whether a checkbox ships ticked or empty.
Breach of data security is defined as a breach that leads to personal data being lost, deleted, destroyed or altered accidentally or unlawfully, or disclosed or made accessible to unauthorised persons (Art. 5 let. h FADP). The controller notifies the FDPIC as soon as possible of a breach that is likely to result in a high risk to the personality or fundamental rights of the data subject (Art. 24 para. 1 FADP); the processor in turn notifies the controller (para. 3). What belongs in a notification is listed in Art. 15 DPO.
Words that come up often and are not in the FADP
This is the part that saves the most time when reading a contract.
GDPR. This is the General Data Protection Regulation of the European Union; in German-speaking Switzerland the same regulation is usually called the DSGVO, which is simply its German abbreviation. The FDPIC writes that the GDPR does not apply directly in Switzerland, but that it may apply concretely to Swiss companies — for instance where they process data of people resident in the EU in order to offer goods or services there, or to monitor their behaviour. Asked whether a Swiss company has to comply with the GDPR, the FDPIC answers that Swiss companies are primarily subject to Swiss law and should therefore comply with the FADP. Whether the GDPR applies alongside it depends on the individual case.
DPO, data protection officer. The FADP does not use that title for private controllers. Art. 10 FADP speaks of a data protection advisor, and the FDPIC states that appointing one is voluntary for private controllers — companies, associations, SMEs. The function may also be carried out by several people in the business or by a legal entity, provided the conditions of Art. 10 FADP are met. In Switzerland “commissioner” is above all the title of the supervisory authority itself. The abbreviation is doubly confusing here: in Swiss sources, DPO usually stands for the Data Protection Ordinance, the implementing ordinance to the act.
“FADP compliant”, “certified”, “compliant”. None of these is a statutory designation. What the act does know is certification under Art. 13 FADP: manufacturers, controllers and processors may have their systems, products and services evaluated by recognised independent certification bodies; the Federal Council issues rules on this and on the introduction of a data protection quality mark. A certification is therefore a checkable statement — body, scope, date — and “compliant” without those three is a self-description.
“DPA” or “data processing agreement”. The expression comes from EU law. Art. 9 FADP says processing may be transferred by contract or by legislation and sets out the conditions; it does not prescribe a document under a particular name. Many providers use the expression anyway, because the same piece of paper is meant to serve both legal orders.
What makes a contract easier to read
Nearly all of these terms sit in one place: Art. 5 FADP for the definitions, Art. 6 to 12 FADP for the duties, Art. 25 FADP for the right of access, the Ordinance for the detail. The text is freely available on Fedlex in all official languages, and it is shorter than most of the contract annexes that cite it.
What helps most is a habit: a word in the contract that appears in the statute can be looked up there; a word that does not is either borrowed from another legal order or a phrase of the provider’s own. Both are fine — it just helps to know which one is in front of you. Whether a given provision applies to a given business depends on that business’s situation, and a glossary does not answer that. It only makes the sentence readable in which the question gets asked.
Sources
- 1.Bundesgesetz über den Datenschutz (DSG, SR 235.1), Stand 1. September 2023 (checked on 23 September 2026)
- 2.Datenschutzverordnung (DSV, SR 235.11), Stand 1. Dezember 2025 (checked on 23 September 2026)
- 3.EDÖB: FAQ Datenschutz (checked on 23 September 2026)
- 4.EDÖB: Outsourcing (Auftragsdatenbearbeitung) (checked on 23 September 2026)
- 5.EDÖB: Bekanntgabe von Personendaten ins Ausland (checked on 23 September 2026)
Follow our ideas
Look at our ideas and ask to be told once when one of them becomes an app. Or write to us – about an idea, about a task that deserves an app, or just to say hello.