GDPR, nFADP, Cloud Act: the comparison for Swiss SMEs

GDPR, nFADP, Cloud Act — these three acronyms come up regularly in data protection discussions, often mixed up or confused. Yet they refer to very different legal realities, with distinct implications for a Swiss SME. GDPR comes from the European Union. nFADP is Swiss law. The Cloud Act is American. Each has its own scope and specific consequences for your data and hosting. Here is a clear comparison of what applies to you, why, and what it actually changes.

The GDPR — the European regulation many Swiss SMEs do not realise applies to them

What is the GDPR?

The General Data Protection Regulation (GDPR) entered into force in the European Union in May 2018. It establishes a unified framework for the protection of the personal data of EU residents.

Does it apply to Swiss SMEs?

Yes — in certain cases. The GDPR has extraterritorial scope: it applies to any organisation, even outside the EU, that processes the personal data of European residents in the context of offering goods or services, or of monitoring their behaviour. In practice, if your Swiss SME sells products or services to customers in France, Germany or another EU country, uses tracking cookies on a website accessible from the EU, or processes data of employees residing in the EU, then the GDPR applies to you, even if your business is based in Switzerland.

What the GDPR requires

  • Explicit consent for data processing
  • Right to erasure, right of access and data portability for data subjects
  • Notification of data breaches within 72 hours
  • Appointment of a DPO (Data Protection Officer) in some cases
  • Data processing contracts with all processors

Penalties

Up to EUR 20 million or 4% of annual worldwide turnover — whichever is higher.

The nFADP — the modernised Swiss law

What is the nFADP?

The new Federal Act on Data Protection (nFADP) entered into force on 1 September 2023. It replaces the 1992 FADP and modernises the Swiss framework, broadly aligning with GDPR principles while remaining a distinct law.

Does it apply to Swiss SMEs?

Yes — to all of them. Unlike the GDPR, which applies only when processing data of EU residents, the nFADP applies to any organisation that processes personal data of natural persons in Switzerland, regardless of size. A 3-person SME is just as concerned as a large group.

What the nFADP requires

  • Record of processing activities (for businesses processing sensitive data on a large scale)
  • Notification of data breaches to the Federal Data Protection and Information Commissioner as soon as possible
  • Privacy by design and privacy by default
  • Strict framework for transfers of data to third countries
  • Data processing contracts with processors

Key differences from the GDPR

Criterion GDPR nFADP
Scope Data of EU residents Data of persons in Switzerland
Threshold No size threshold No size threshold
DPO mandatory In some cases Not mandatory
Notification deadline 72 hours As soon as possible
Penalties Up to 4% of worldwide turnover Up to CHF 250,000 (criminal, natural person)
Extraterritorial scope Yes Limited

Penalties

The nFADP provides for criminal penalties of up to CHF 250,000 — but they target the responsible natural persons, not companies directly. This is an important difference from the GDPR.

The Cloud Act — the US law that concerns everyone

What is the Cloud Act?

The Clarifying Lawful Overseas Use of Data Act (Cloud Act) is a US law adopted in 2018. It allows US authorities to require US technology companies to provide data stored on their servers — including servers located outside the United States.

Does it apply to Swiss SMEs?

Not directly — but indirectly, yes. The Cloud Act does not apply to Swiss companies as such. It applies to US companies. But if you use US cloud services — AWS, Microsoft Azure, Google Cloud, Microsoft 365, Salesforce, and many others — your data is potentially accessible to US authorities, even if the servers are physically in Switzerland or Europe.

What this means in practice

  • Data hosted with a US provider may be transferred to US authorities without your consent
  • This may create a conflict with the nFADP and GDPR, which strictly regulate transfers to third countries
  • Standard contractual clauses and data processing agreements do not protect against the Cloud Act

The difference with an independent Swiss host

An independent Swiss host — not owned by a US company, with no US subsidiaries — is not subject to the Cloud Act. Your data remains under Swiss jurisdiction and can only be transferred under applicable Swiss law.

Comparison of the three frameworks

Criterion GDPR nFADP Cloud Act
Origin European Union Switzerland United States
Entered into force May 2018 September 2023 April 2018
Applies to Swiss SMEs If EU data Always Indirectly
Objective Protect data Protect data Access for US authorities
Geographic scope Extraterritorial Mainly Swiss Extraterritorial
Hosting impact Regulates transfers outside the EU Regulates transfers outside Switzerland Risk of transfer to the US
Protection by contract Partially Partially No

What this changes for your hosting

If you are subject to the GDPR

You must ensure that your hosting providers offer adequate safeguards for the data of EU residents. Hosting in Switzerland is compatible with the GDPR if appropriate contractual guarantees are in place — Switzerland has been recognised as an adequate country by the European Commission since 2000, although this recognition is regularly reviewed.

If you are subject to the nFADP

You must document where your data is, which subprocessors are involved, and under what conditions. Hosting in Switzerland with an independent Swiss operator considerably simplifies this documentation and reduces compliance risks.

If you use US cloud services

You are exposed to the Cloud Act, regardless of server location. The only way to avoid this exposure is not to use services operated by US companies for sensitive data.

In practice: what to do

Map your processing: identify what data you process, where it comes from (Swiss residents, EU residents, others) and where it is hosted. This is the foundation of any compliance approach.

Identify your exposure:

  • Do you have customers in France or Germany? The GDPR applies.
  • Do you process data of persons in Switzerland? The nFADP applies.
  • Do you use AWS, Azure or Google Cloud? The Cloud Act is a reality.

Choose a suitable host: for the most sensitive data, an independent Swiss host offers the simplest coverage: nFADP respected, GDPR compatibility facilitated, Cloud Act exposure nil.

Document and contract: whatever your host, explicit data processing contracts are essential — both for the GDPR and for the nFADP.

In summary

GDPR, nFADP and Cloud Act are not interchangeable. For a typical Swiss SME, the nFADP always applies, the GDPR applies if you have customers or employees in the EU, and the Cloud Act applies indirectly if you use US services. The good news: choosing an independent Swiss host is the simplest answer to these three issues at once. Your data stays in Switzerland, under Swiss jurisdiction, out of reach of the Cloud Act, in a framework compatible with the nFADP and facilitating GDPR compliance. If you would like to review your situation or discuss your hosting options, contact us.

AlpineDC has dedicated rooms in Lausanne and Crissier, with an autonomous AS198385 network and multi-operator connectivity. Our infrastructures are exclusively located in Switzerland and operated by a local team.