Available only in Switzerland

Schweizerform is currently available exclusively for users in Switzerland. Account creation from your region is restricted.
Back to Blog

nFADP Compliance Checklist for Forms & Surveys

Thirteen checks that decide whether an online form survives a Swiss data protection review — purpose limitation, justification, impact assessment, privacy notice, record of processing, processor contracts, transfer basis, security, logging, retention, access requests inside 30 days, and breach process. Each with the article behind it and the evidence an auditor actually asks to see.

nFADP Compliance Checklist for Forms & Surveys

Most nFADP articles explain the law. This one assumes you have read those and now have to prove something. It is the list a reviewer works through when they sit down with one of your online forms — thirteen checks, the provision behind each, and the specific artefact you will be asked to produce. If you can answer all thirteen with a document rather than an opinion, a Swiss data protection review holds no surprises for you.

How to use this

Take one real form — the one collecting the most sensitive data, not the easiest one — and run it end to end. Compliance is assessed per processing activity, not per company, so a clean privacy notice on your website says nothing about the careers form. Score each item as evidence exists, exists but is stale, or does not exist. The third category is your work list; the second is what actually fails audits.

The explanatory companion to this piece is our nFADP guide for online forms, which covers why each duty exists. Here the emphasis is entirely on what you must be able to show.

Does the nFADP Apply to Your Form at All?

Almost certainly, and possibly even if you are not in Switzerland. The revised Federal Act on Data Protection (nFADP / nDSG, SR 235.1) governs the processing of personal data relating to natural persons by private controllers and federal bodies. Two scoping points catch people out. First, it reaches processing that has an effect in Switzerland regardless of where the controller sits — a German or Austrian company running a form aimed at Swiss respondents is inside its scope. Second, Art. 14 requires a private controller domiciled abroad to designate a representative in Switzerland where the processing relates to offering goods or services in Switzerland or monitoring behaviour here, is extensive, is carried out regularly, and presents a high risk. Under Art. 15 that representative maintains the record of processing activities and answers the FDPIC and data subjects.

Cantonal and communal bodies: wrong statute

If you are a school, a municipal administration or a cantonal office, the federal nFADP is largely not your law — cantonal data protection legislation is, along with your cantonal supervisory authority's practice. The checklist below still maps closely onto most cantonal regimes, but verify every article reference against your own cantonal act before relying on it.

Checks 1–4: Before the Form Goes Live

1. Purpose is specific, and every field serves it

Art. 6 requires processing that is lawful, in good faith and proportionate, with data collected only for a specific purpose that is recognisable to the data subject, and processed only in a way compatible with that purpose. In form terms this is a field-by-field test: for each question, name the purpose it serves. Date of birth on an event registration usually fails it; so does the phone number you have never once called. Evidence an auditor asks for: the field list with a stated purpose per field, and the deletion of the ones that had none.

2. You can name the justification — and it is usually not consent

Swiss law does not require a legal basis in the GDPR sense for private controllers; it requires that any infringement of personality rights be justified, under Art. 31, by consent, an overriding private or public interest, or by law. Contract performance and a genuine business interest carry most ordinary forms. Where you do rely on consent, Art. 6 para. 6 requires it to be given voluntarily for one or more specific processing operations after appropriate information, and Art. 6 para. 7 requires it to be explicit for sensitive personal data and for high-risk profiling. Evidence: a one-line justification recorded per form, and, where consent is used, the exact wording plus proof of how it was captured and how it can be withdrawn.

3. Impact assessment where the risk is high

Art. 22 requires a data protection impact assessment in advance where processing can entail a high risk to personality or fundamental rights, and states that a high risk exists in particular with extensive processing of sensitive personal data or systematic extensive monitoring of public areas. A patient intake form, a whistleblowing channel or a large health-related survey is squarely in that territory. Art. 23 then governs when the FDPIC must be consulted. Evidence: the assessment itself — planned processing, risk evaluation, protective measures — dated before launch, not reconstructed afterwards.

4. The privacy notice says what Art. 19 requires

Art. 19 obliges you to inform data subjects adequately about the collection, giving at minimum the identity and contact details of the controller, the purpose, and where applicable the recipients or categories of recipients. Art. 19 para. 4 adds the requirement almost everybody misses: where data is disclosed abroad, you must also state the country and, where applicable, the safeguards under Art. 16 para. 2 or the derogation under Art. 17 being relied on. Evidence: the notice linked from the form itself — not buried three clicks away on the corporate site — naming your form provider's country. Failure to inform is punishable under Art. 60 with a fine of up to CHF 250,000.

Checks 5–7: The Paperwork You Must Produce on Request

5. Record of processing activities — and the SME exemption you probably do not have

Art. 12 requires controllers and processors each to maintain a record of their processing activities, containing at least the controller's identity, the purpose, a description of the categories of data subjects and of personal data, the categories of recipients, where possible the retention period or the criteria for determining it, where possible a general description of the security measures under Art. 8, and — where data goes abroad — the country and the Art. 16 para. 2 safeguards.

The «under 250 employees» exemption is narrower than the summaries suggest

Art. 24 of the Data Protection Ordinance exempts companies and other private-law organisations employing fewer than 250 people on 1 January of a given year, plus natural persons, from keeping the record — unless they process sensitive personal data on a large scale or carry out high-risk profiling. A twelve-person clinic, a small HR consultancy running engagement surveys, an association collecting health details for a sports camp: each processes sensitive data, and the headcount exemption stops applying. Most Swiss SMEs that believe they are exempt have never tested themselves against the exception.

6. A processor contract for every provider in the chain

Art. 9 permits delegation to a processor by contract or by legislation, provided the data is processed only as you yourself could process it and no statutory or contractual duty of confidentiality prohibits the delegation, and requires you to satisfy yourself that the processor can ensure data security. Art. 9 para. 3 requires your prior authorisation before the processor delegates onward. Evidence: the agreement, the subprocessor list as it stood when you accepted it, and the same for the email service, the file storage and any AI feature. The detail is in our guide to data processing agreements for form tools.

7. A named basis for every transfer abroad

Art. 16 para. 1 allows disclosure abroad where the Federal Council has determined adequate protection — Annex 1 of the Data Protection Ordinance. Otherwise Art. 16 para. 2 safeguards apply, or in individual cases the Art. 17 derogations. Art. 61 lit. a makes an unlawful transfer punishable with a fine of up to CHF 250,000 against the responsible individual. Evidence: for each provider, its country and the instrument relied on, consistent with what your privacy notice says. Our cross-border transfer guide works through the test.

Checks 8–10: Security and the Documentation Duties Behind It

Art. 8 requires the controller and the processor to ensure security appropriate to the risk through technical and organisational measures, and Art. 7 requires data protection by design and by default from the planning stage onwards. The Data Protection Ordinance makes both concrete, and these three checks are where a technically competent reviewer spends their time.

  1. 8. Protection needs assessed and measures matched to them. Art. 1 DPO requires you to determine the protection needs of the data and define measures appropriate to the risk, judged on the nature of the data and the purpose, nature, scope and circumstances of the processing. Art. 2 DPO sets the four objectives: confidentiality, availability, integrity and traceability. Art. 3 DPO names the controls — access control, entry control, user control, and measures for availability and integrity. Evidence: a short written assessment per form category, and a security description you can map onto Art. 3.
  2. 9. Logging where Art. 4 DPO requires it. Where sensitive personal data is processed automatically on a large scale, or high-risk profiling is carried out, and preventive measures cannot ensure protection, storage, modification, reading, disclosure, deletion and destruction must be logged. Evidence: the log configuration, its retention period, and who reviews it.
  3. 10. Processing regulations where Art. 5 DPO requires them. A private controller and its private processor must maintain regulations for automated processing where they process sensitive personal data on a large scale or carry out high-risk profiling, covering internal organisation, the processing and control procedure, and the security measures — kept up to date and made available to your data protection adviser if you have appointed one under Art. 10. Evidence: the document, with a revision date inside the last year.

Checks 11–13: While the Form Is Live

11. Retention is a decision, and deletion is evidenced

Art. 6 para. 4 requires personal data to be destroyed or anonymised as soon as it is no longer necessary for the purpose of processing. That obligation has no grace period and no «we might need it someday» exception, and it is the item most often failed by organisations whose other paperwork is immaculate. Responses accumulate in the platform, in the linked spreadsheet, in email notifications and in exports on laptops. Evidence: a retention period per form category, the mechanism enforcing it, and proof that a past cohort was actually deleted — including from backups, with the backup expiry window stated. Our post on form data retention covers how to set the periods.

12. You can answer an access request within 30 days

Art. 25 gives every person the right to know whether personal data about them is being processed and to receive the information needed to exercise their rights — including the data itself, the purpose, the retention period or the criteria for it, the origin, the recipients, and the Art. 19 para. 4 information about transfers abroad. The information is free of charge (Art. 25 para. 6), the right cannot be waived in advance (Art. 25 para. 5), and remaining with a processor does not relieve you of it (Art. 25 para. 4). Art. 25 para. 7 sets 30 days as the rule, and Art. 18 DPO makes it 30 days from receipt, with a duty to inform the person and state a new deadline if you cannot meet it. Art. 28 adds the right to receive data in a common electronic format, or have it transferred, where processing is automated and rests on consent or a contract. Evidence: a named owner, a written procedure, and the log of past requests with dates showing the deadline was met.

13. A breach process that starts before the breach

Art. 24 para. 1 requires the controller to notify the FDPIC as soon as possible of a data security breach likely to result in a high risk to the personality or fundamental rights of the data subject, stating at minimum the nature of the breach, its consequences and the measures taken or planned. Art. 24 para. 3 obliges your processor to report a breach to you as soon as possible — a statutory duty, not merely a contractual one. Art. 24 para. 4 governs informing the affected person. Evidence: the written procedure with names and out-of-hours contacts, your provider's notification commitment, and the assessment template you would fill in at hour one. The interaction with encryption is covered in our post on breach notification and encryption.

The Evidence Table

The compressed version. Print it, fill the third column with a file path, and the gaps become obvious.

CheckProvisionWhat an auditor asks to see
Purpose and minimisationArt. 6 nFADPField list with a purpose per field
Justification / consentArt. 31, Art. 6 paras. 6–7Recorded justification; consent wording and withdrawal path
Impact assessmentArt. 22–23 nFADPDated assessment predating launch
Privacy noticeArt. 19, incl. para. 4Notice linked from the form, naming destination countries
Record of processingArt. 12 nFADP; Art. 24 DPOThe record, or a defensible exemption analysis
Processor contractsArt. 9 nFADPAgreement plus dated subprocessor list
Transfer basisArt. 16–17 nFADPProvider country and instrument, per provider
Security measuresArt. 7–8; Art. 1–3 DPOProtection-needs assessment and security description
LoggingArt. 4 DPOLog configuration, retention, reviewer
Processing regulationsArt. 5 DPOCurrent document with revision date
Retention and deletionArt. 6 para. 4 nFADPPeriods, enforcement mechanism, proof of a past deletion
Access requestsArt. 25, 28; Art. 18 DPOProcedure and request log showing the 30-day deadline met
Breach processArt. 24 nFADPWritten procedure and provider notification commitment

The Five Failures That Actually Sink Reviews

  • Documents that describe a system you no longer run. A record of processing listing a form tool you migrated away from eighteen months ago is worse than none: it proves the process is not maintained.
  • Company-level answers to form-level questions. «We have a privacy policy» does not answer what the careers form collects, who receives it or how long it is kept.
  • Retention as an aspiration. A stated period nobody enforces, with four years of responses still in the account and in a linked spreadsheet.
  • Free-text fields that quietly upgrade the risk class. One «anything else we should know?» box on a registration form turns an ordinary processing activity into one handling health data — which changes the impact-assessment, record-keeping and processing-regulations answers at once.
  • Assuming the SME exemption applies. Art. 24 DPO is a conditional exemption, and sensitive data at scale removes it. This is the single most common false negative in Swiss SME self-assessments.

A 90-Minute First Pass

If the full list is more than you can start on today, this sequence gets you from «no idea» to a defensible work plan in an afternoon.

1

List every live form (15 min)

Website, intranet, campaign landing pages, QR codes on paper, the tools individual teams signed up for. Note the owner and the platform for each. The forms nobody remembers are where the exposure lives.

2

Classify by data category (15 min)

Ordinary personal data, or sensitive under Art. 5 lit. c — health, religious, philosophical, political or trade-union views, intimate life, ethnicity, genetic or biometric data, criminal or administrative proceedings, social assistance. Include what free-text fields realistically attract.

3

Take the sensitive ones through all thirteen checks (30 min)

Mark each item evidence-exists, stale or missing. Do not fix anything yet — a complete gap list is worth more than two closed items.

4

Kill fields and forms (15 min)

The cheapest compliance work is deletion. Remove questions nobody analyses and retire duplicate forms. Every field removed is thirteen checks you no longer have to pass for it.

5

Set retention and diarise deletion (10 min)

Give each surviving form a period and put the first deletion run in the calendar with a named owner. This closes the item that fails most often.

6

Write the gap list into a dated plan (5 min)

Item, owner, deadline. A documented, in-progress remediation plan is a materially better position in front of a supervisory authority than an undocumented clean intention.

Does a Zero-Knowledge Platform Shorten This List?

It shortens some items and removes none. You still owe the purpose test, the justification, the privacy notice, the record of processing, the processor contract, the retention decision and the access-request procedure — end-to-end encryption is not a compliance exemption, and any vendor implying otherwise is overselling.

What it does change is the weight of three checks. The security assessment gets shorter because the confidentiality objective in Art. 2 DPO is met architecturally rather than by trusting the provider's access controls. The transfer analysis gets simpler because what leaves your control is ciphertext rather than readable content. And the breach process changes shape, because a provider-side incident exposes data nobody can read — which is a different Art. 24 conversation. Where the platform genuinely cannot help you is retention discipline and answering access requests: those stay yours, and no architecture does them for you.


Bottom Line

nFADP compliance for forms is not a certificate and there is no «declaration of conformity» to file — Switzerland has no such registration for ordinary form processing. What exists is an evidentiary position: thirteen questions, each answerable with a document, per processing activity. Organisations that fail reviews rarely fail because they misread an article; they fail because nobody could produce the record, the retention proof or the dated assessment when asked.

So start with the form that would embarrass you most, run the thirteen checks, and write down what is missing. Then delete the fields you never needed, because the fastest route through a compliance checklist is having less to be compliant about.

Schweizerform is built so that several of these checks are shorter by construction: end-to-end encrypted submissions the operator cannot read, Swiss hosting, retention controls per form, and EN / DE / FR / IT throughout. If you are choosing a platform on data protection grounds, our roundup of form tools hosted in Switzerland compares the options instead of pitching one.

Disclaimer: This article is general information and marketing content, not legal advice, and it is not an audit methodology endorsed by any authority. References to the nFADP, the Data Protection Ordinance and cantonal data protection law are simplified and reflect the position at the time of writing (July 2026); provisions, ordinance thresholds and supervisory practice change. Whether a specific processing activity complies depends on your role, your sector and your data — have your setup assessed by qualified data protection counsel rather than relying on any single checklist, including this one.