Skip to content

Blog

nFADP and cloud in Switzerland: three duties your company must check

Processor contract, transfers, processing register: what Swiss nFADP requires of your cloud provider. Not legal advice. Hikube (Hidora SA) provides a DPA; it does not certify your file.

Hidora article published 21 August 2026. Figures, prices and comparisons are as of that date.

Processing agreements, international transfers, records of activities: what every Swiss company must check before signing with a cloud provider.

Unlike the European GDPR, which penalises the company, the nFADP targets the natural person responsible for the processing directly, the executive, the IT lead, or whoever was given that duty. The personal fine can reach CHF 250,000 (art. 60 nFADP). Yet most Swiss companies have still not checked whether their cloud provider meets the three obligations the nFADP has imposed on them since September 2023.

This is not a topic reserved for legal specialists. The nFADP applies to any organisation processing data about natural persons in Switzerland, as soon as it delegates that processing to a third party. Choosing a cloud provider is not a neutral technical decision: it is a compliance decision that engages the executive's personal liability.

What the nFADP changed for Swiss companies in September 2023

The new Federal Act on Data Protection came into force on 1 September 2023, with no transition period. Companies had to be compliant from day one. Three structural changes bear directly on cloud hosting.

First change: the nFADP explicitly introduces the notion of processor (art. 5 lit. k nFADP). Any person or organisation that processes personal data on behalf of another entity, following its instructions, is a processor. A cloud provider hosting your customer data, your HR data or your financial data is your processor in the meaning of the law.

Second change: delegated processing must be formalised in a contract (art. 9 nFADP). That was not explicitly required under the old 1992 act. On this point the nFADP aligns Switzerland with the European GDPR and requires the controller to make sure contractually that the processor meets the same obligations it does.

Third change: the rules on transfers abroad are tightened (art. 16 nFADP). The list of countries with adequate protection is now maintained by the Federal Council, and any transfer to a country not on it requires documented safeguards. This bears directly on companies using cloud providers whose parent company sits outside Switzerland or the EU.

One point often missed: the nFADP applies to any set of circumstances that has effects in Switzerland, even when the processing takes place abroad (art. 3 para. 1 nFADP). A Swiss company hosting its data on American servers remains subject to the nFADP for that data.

The three nFADP obligations tied directly to your cloud provider

1. The processing agreement is mandatory (art. 9 nFADP)

As soon as a cloud provider processes personal data on your behalf, a processing agreement must be concluded. That contract must guarantee that the provider processes your data only on your instructions and within the limits you are yourself allowed to observe. It must also provide that the provider cannot bring in a further processor without your prior agreement.

In practice, large providers such as AWS, Azure and Google Cloud offer standardised Data Processing Addendums (DPAs). Those documents answer GDPR requirements, but they have to be checked clause by clause against the specifics of the Swiss nFADP. A GDPR DPA does not automatically amount to nFADP compliance; the two texts differ notably on penalties and on certain documentation requirements.

Without a compliant processing agreement, the controller is exposed to a personal fine. It is the natural person charged with data protection who answers to the FDPIC, not the company as a legal entity.

2. Transferring to a US provider requires specific safeguards (art. 16 nFADP)

The United States is not on the list of countries with adequate protection published by the Federal Council. Entrusting personal data to AWS, Microsoft Azure or Google Cloud amounts to transferring that data to a country without adequate protection under art. 16 nFADP. The transfer is legally possible, but only under conditions.

Two safeguards are mainly used. The first is the Swiss-U.S. Data Privacy Framework, an adequacy mechanism adopted in 2024, which permits transfers to American companies that have joined it. Its legal solidity remains contested, however: the NOYB association has announced its intention to challenge it in court, as it did with the Privacy Shield struck down in 2020. The second safeguard, more robust, is to sign standard contractual clauses recognised by the FDPIC with the provider, and to document that step in the record of processing activities.

A point many companies miss: servers physically located in Europe do not change this analysis. An American provider running servers in Frankfurt or Zurich remains a company subject to US law, including the CLOUD Act. The FDPIC considers that this does constitute a transfer to a country without adequate protection.

3. Your record of processing activities must include your cloud provider (art. 12 nFADP)

The record of processing activities is mandatory for every organisation, except SMEs whose processing presents a low risk to the persons concerned (art. 12 nFADP). For each processing activity delegated to a cloud provider, the record must state the identity of the processor, the categories of data processed, the country of processing, and the safeguards in place if that country lacks adequate protection.

This requirement is stricter than GDPR on one precise point: the nFADP requires the recipient country to be named explicitly, where GDPR often settles for categories of recipients. If your record lists "AWS" as a processor without stating "United States" and the corresponding art. 16 para. 2 safeguards, it is not nFADP compliant.

For more on the contractual requirements that apply to financial institutions, which come on top of the nFADP, see our article on the cloud obligations FINMA imposes on Swiss financial institutions.

Three misconceptions about the nFADP and the cloud

Misconception 1: "My provider has servers in Switzerland, so I am nFADP compliant"

What the law actually says, the nFADP assesses the jurisdiction that applies to the provider, not the physical location of the servers. A provider whose parent company is American remains subject to the CLOUD Act, which lets US authorities access data hosted anywhere in the world. The FDPIC considers that this constitutes a transfer to the United States under art. 16 nFADP. A compliant processing agreement and documented safeguards remain mandatory, even if the datacenters are in Zurich.

Misconception 2: "We are GDPR compliant, so we are nFADP compliant"

What the law actually says, the nFADP and GDPR are largely aligned, but differ on two points that matter for the cloud. First, the nFADP penalises natural persons rather than the company; the executive's personal liability is directly engaged, up to CHF 250,000. Second, the record of processing activities under the nFADP requires the recipient country to be named explicitly in case of a transfer abroad (art. 12 nFADP), a stricter requirement than GDPR on that precise point. Both deserve a specific check, even in an organisation already compliant with GDPR.

Misconception 3: "The nFADP only concerns large companies"

What the law actually says, the nFADP applies to any organisation processing data about natural persons in Switzerland, with no size threshold. The SME exception covers only the record of activities, and only where the processing presents a low risk. As soon as an SME uses a cloud CRM, an HR tool or an ERP hosted abroad to handle customer or staff data, the processing (art. 9) and transfer (art. 16) obligations apply in full. The size of the organisation does not reduce the risk of a personal fine for the executive.

Frequently asked questions

Does the nFADP apply if my cloud provider is run by an American company with servers in Switzerland?

Yes. The nFADP assesses the jurisdiction that applies to the provider, not only the physical location of the servers. An American company remains subject to the CLOUD Act, which constitutes a transfer to a country without adequate protection under art. 16 nFADP. A compliant processing agreement and specific safeguards documented in your record remain mandatory, whatever the datacenter address.

What does an executive risk if the company breaches the nFADP with its cloud provider?

Unlike GDPR, the nFADP penalises the natural person responsible for the processing, not the company. The personal fine can reach CHF 250,000 (art. 60 nFADP) for a deliberate breach of the duties of information, diligence or processing. The FDPIC also holds injunction powers allowing it to order the modification, suspension or cessation of non-compliant processing.

What is the difference between the nFADP and GDPR when choosing a cloud provider?

The two texts align on the broad principles but differ on two points tied directly to the cloud. The nFADP penalises natural persons rather than the company, which engages the executive's personal liability directly. And the nFADP requires the recipient country to be written explicitly into the record of processing when data is transferred abroad, an obligation more precise than GDPR. For an organisation already GDPR compliant, those two specific points are the main angles to verify.

In short: three key points

Your cloud provider is your processor, which requires a written contract

Art. 9 nFADP requires a processing agreement as soon as a provider handles personal data on your behalf. That contract is not a formality: it is the first document the FDPIC will ask for during an inspection, and its absence can be enough to engage the executive's personal liability. Checking that your current DPA meets the specifics of the Swiss nFADP, and not only GDPR, is the first action to take. For an overview of what is at stake with sovereign cloud for Swiss companies, our companion article covers the three dimensions of sovereignty.

Hosting data with an American provider is not forbidden, but requires documented safeguards

The United States is not on the Federal Council's list of countries with adequate protection. Using AWS, Azure or GCP for personal data about Swiss residents is legally possible, but conditional on putting in place standard contractual clauses recognised by the FDPIC and documenting them in the record of processing activities. It is not forbidden, it is conditional, and that condition is often missing from contracts signed without prior legal review.

The executive's personal liability is the nFADP's real differentiator

The nFADP does not penalise the company: it targets the natural person in charge of data protection. Up to CHF 250,000 in personal fines. That choice by the Swiss legislator turns cloud compliance from an IT question into a governance question the executive cannot delegate without active follow-up. An annual audit of your cloud contracts against nFADP requirements is the simplest measure to contain that personal risk.

Want to check that your cloud infrastructure is nFADP compliant? The Hikube team supplies what a host can supply: location, DPA, isolation, a subprocessor register. Infrastructure does not make an organisation nFADP compliant: the impact assessment, the legal bases and the register stay with you. The evidence is on security and compliance. Talk to our team.

Ready to run on 100% Swiss infrastructure?

14-day trial, no credit card. GPUs included.