On 1 September 2023, Switzerland's revised Federal Act on Data Protection (nFADP / revDSG / nLPD) came into full effect. For any company handling personal data for identity verification and client onboarding, the changes are not cosmetic — they impose new documentation duties, technical requirements, and notification obligations. This whitepaper explains the five most impactful changes and the practical steps to take.
The revised law modernises Swiss data protection, aligning it more closely with the GDPR while retaining crucial Swiss specificities. For Swiss companies — especially those processing sensitive and biometric data during identity verification — compliance is now a continuous, demonstrable obligation rather than a one-time registration.
The five changes below — accountability, privacy by design, privacy by default, data subject rights, and breach notification — each describe what changed, what it means for your business, and the concrete steps you can take today.
Under the old law, data controllers registered their data collections. The revised law replaces this with a general principle of accountability: you must not only comply — you must be able to demonstrate compliance at any time. This applies to all processing of personal data, including employee data, client data, and especially sensitive data processed during identity verification.
If you use (or provide) KYC services, you must document:
The nFADP explicitly requires that data protection be built into the design of systems and processes from the outset, not added later. Technical and organisational measures must be integrated into the development lifecycle.
An identity verification platform must be architected with privacy at its core:
Systems must be pre-configured so that, by default, only the minimum necessary personal data is processed. The user should not have to adjust settings to protect their privacy; the most privacy-friendly setting must be the standard one.
In an onboarding flow, this translates to:
The revised law strengthens and clarifies the rights individuals have over their data: access, rectification, erasure, restriction of processing, data portability, and the right to object. Requests must be answered within 30 days, free of charge, and in a commonly used electronic format where applicable.
For a verification provider or a bank using one, this means a customer can request all personal data held (including voice recordings or video stills), ask for their biometric profile to be deleted, or request the transfer of their verification record to another provider. Your platform must isolate, extract, and delete personal data per individual without breaking the audit logs required by other laws (e.g., GwG retention) — careful separation of "compliance data" you must keep from "personal data" you must erase on request.
The nFADP introduces a mandatory obligation to notify the Federal Data Protection and Information Commissioner (FDPIC) of data breaches likely to result in a high risk to the personality or fundamental rights of the data subject. Notification must occur as soon as possible, and the data subject must also be informed in certain cases.
A breach in a KYC context could include unauthorised access to a database of verified identities, leakage of voice biometric templates, or video recordings accessed by an unauthorised employee. Because biometric data is particularly sensitive, a breach involving it will almost always require FDPIC notification. You need a well-rehearsed incident response plan with immediate containment, forensic analysis, and communication within hours, not days.
The revised Swiss Data Protection Act is not a bureaucratic burden — it is an opportunity. Companies that embed accountability, privacy by design, and user respect into their identity verification processes will win trust, reduce regulatory risk, and differentiate themselves in a crowded market. VerfiX is built from the ground up on these principles, offering Swiss-hosted, privacy-first KYC and KYB for regulated organisations.
VerfiX provides API-first, Swiss-hosted identity verification through voice biometrics and video identification. Data never leaves Switzerland. Our products are designed for compliance with FINMA, GwG, and the nFADP. Incubated by Trust Valley, Lausanne — the VerfiX team is led by Ahmed Alsultan (Founder & CEO), Petter Stähle (Co-Founder & Technology Lead), and Manel Mhamdi (Co-Founder & Business Development).
Talk to us about Swiss-hosted KYC, KYB, and AML that meets the nFADP from day one.