Some controllers based outside Switzerland have to appoint a representative in Switzerland under Article 14 of the revised FADP. Engage Compliance arranges that appointment through a vetted Swiss partner and coordinates the whole thing for you.
The short answer: if you are a private controller based abroad and your processing of data about people in Switzerland is large scale, regular, high risk to their personality, and tied to offering goods or services or monitoring behavior there, all four at once, you need a representative established in Switzerland under FADP Article 14. Most companies do not clear all four conditions, so the first job is usually to check whether you are caught at all.
Engage Compliance is established in Amsterdam, and the Swiss representative has to sit in Switzerland, so we do not perform this role from our own entity. We arrange the appointment through a vetted Swiss partner, put the mandate and the record-keeping in place, and stay your single point of contact for it.
Key takeaways
- FADP Article 14 has been in force since 1 September 2023 and applies to private controllers based abroad, never to processors or public bodies.
- The test has four cumulative conditions, so all four have to be met before the duty bites. It is the narrowest of the European representative regimes.
- The Swiss representative must be established in Switzerland. Engage Compliance is Amsterdam-based, so we arrange and coordinate the Swiss appointment through a vetted Swiss partner rather than performing it ourselves.
- Under Article 15 the representative holds a record of the controller’s own processing activities and tells data subjects how to exercise their rights. That is a document-custody duty, not just a mailbox.
- There is no specific penalty for failing to appoint. Enforcement is a two-step route through a Commissioner ruling, and only wilful non-compliance with that ruling is criminal.
- An EU or UK representative does not cover Switzerland, and voluntary appointment is possible for controllers who want to get ahead of the obligation.
Who needs a Swiss representative
Article 14 catches private controllers with a registered office or domicile abroad who process the personal data of people in Switzerland, but only where all four of these conditions are met together:
- The processing is connected with offering goods or services to people in Switzerland, or with monitoring their behavior.
- It is extensive, meaning large scale.
- It is carried out regularly.
- It poses a high risk to the personality of the data subjects.
These are cumulative. If your processing fails even one of the four, you have no Article 14 obligation. The tests for large scale, regular and high risk are qualitative and are not defined by a number in the Act, so this is a judgment about your actual processing rather than a headcount or turnover threshold. A US SaaS product with a modest Swiss user base and no high-risk processing has no Swiss obligation at all, which is why the honest first step is usually to check whether you are caught before talking about the appointment itself.
Who is exempt
Exemption here works by construction, not by a carve-out you have to argue for.
- Processors are not caught. Article 14 names private controllers only.
- Federal and public bodies are not caught.
- Any controller that fails even one of the four cumulative conditions is not caught.
Because the regime is so narrow, a lot of companies that carry an EU or UK representative will not need a Swiss one. The value of a proper scoping exercise is often that it qualifies you out.
When it applies from
The revised Federal Act on Data Protection has been in force since 1 September 2023, and there are no staged dates still to come. The obligation is live now.
Where the representative must be established
The representative has to be established in Switzerland. Article 14 makes the representative the contact point for data subjects and for the Federal Data Protection and Information Commissioner, and the controller has to publish the representative’s name and address.
This is the part that decides how we deliver the service. Engage Compliance is established in Amsterdam, and an Amsterdam entity cannot serve as a Swiss representative. So for Switzerland we work with a vetted partner established there. We arrange the appointment, set up the mandate and the record-keeping, and coordinate it for you, and the partner holds the Swiss establishment the law requires. We are always clear in writing about which entity does what.
What the penalty is
There is no specific criminal penalty in the FADP for failing to appoint a representative. The Act’s criminal provisions do not list the Article 14 duty, so this is not a “fail to appoint and you are automatically fined” regime.
Enforcement runs in two steps instead. The Commissioner can issue a ruling ordering a controller to appoint a representative. Only wilful non-compliance with that ruling becomes a criminal matter, under Article 63, and the fine there runs up to CHF 250,000. Swiss data protection fines also default to the responsible individual rather than the company. So the accurate way to describe the risk is that there is no specific penalty for the failure to appoint on its own, with a real criminal exposure sitting behind a Commissioner ruling that is ignored.
What Engage delivers, and what the partner delivers
- Scoping. We run the four-condition test against your actual processing and tell you plainly whether you are caught. If you are not, we say so and stop there.
- The Swiss appointment. Our vetted Swiss partner provides the representative established in Switzerland, which is the part that legally has to sit in the country.
- The mandate. We put the appointment in a written contract. The FADP does not require writing, but a contract is how the appointment is evidenced and how the duties and authority are set out.
- The Article 15 record. The representative holds a record of your processing activities and keeps it available to the Commissioner. We set that up and keep it fed with accurate, current information from you.
- Data subject handling. The representative tells people in Switzerland how to exercise their rights and routes their contacts to your named internal owner.
- A single point of contact. You deal with Engage Compliance throughout. We coordinate the partner rather than handing you a separate relationship to manage.
Voluntary appointment is also possible. If you are not strictly caught yet but want to get ahead of it, the Commissioner has confirmed a controller can appoint a representative as a precautionary step, and we can arrange that on the same basis.
Where you also need a named DPO, we keep that separate from the representative role and say which entity holds which.
What it costs
Pricing is scoped to the mandate, because it depends on your processing and on the partner arrangement in Switzerland. Tell us what you process and where your Swiss users sit, and we will give you a quote. Talk to us and we will scope it.
Sources and references
- Federal Act on Data Protection (SR 235.1), Articles 14 and 15, fedlex.admin.ch
- Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)