Swiss revFADP and Offshore Developers: Transfers, Contracts and the FDPIC
Founder & Lead Engineer, RAITHub
A Swiss company can use an offshore developer in Bangladesh under the revised Federal Act on Data Protection (revFADP), but Bangladesh is not on the Federal Council's list of adequate countries, so the transfer needs a safeguard, usually the EU Standard Contractual Clauses with Swiss adaptations. The vendor is a processor under Article 9, and wilful breaches carry fines of up to CHF 250,000 on individuals.
This guide is for founders, CTOs and data protection leads in Switzerland who are about to hire an offshore development team. RAITHub is a software studio in Dhaka, so we have an interest in the answer; we are the overseas vendor in this picture, and we have no office in Switzerland. Every point below is drawn from the Act, its Ordinance or the Federal Data Protection and Information Commissioner's (FDPIC) own pages, and linked so you can read them. This is general information, not legal advice. Confirm every point with your adviser and the FDPIC before you sign.
What is the revFADP, and does it reach an offshore vendor?
The revised Federal Act on Data Protection (SR 235.1), often called the nFADP or revFADP, has been in force since 1 September 2023 (FADP on Fedlex). It sits alongside the Data Protection Ordinance (DPO, SR 235.11), which fills in details such as the country list and breach documentation (DPO on Fedlex).
Its reach is wide. Article 3(1) says the Act "applies to circumstances that have an effect in Switzerland, even if they were initiated abroad". If a Dhaka team processes personal data about your Swiss customers, the Act is relevant to that work, whoever does it.
Two definitions frame everything else. A controller is the private person or federal body that "determines the purpose and the means of processing personal data" (Art. 5(j)). A processor "processes personal data on behalf of the controller" (Art. 5(k)). A development vendor that touches your data only to build and support your product is normally your processor. If it starts using the data for its own purposes, that picture changes, and your adviser should look again.
One practical note: the English text on Fedlex is a translation for information. The German, French and Italian versions are the authoritative ones, which is one more reason to have a Swiss adviser check the wording that matters to you.
Is Bangladesh on the Swiss list of adequate countries?
No, as far as we can verify. Article 16(1) FADP lets you disclose personal data abroad without more if "the Federal Council has decided that the legislation of the State concerned or the international body guarantees an adequate level of protection". The FDPIC explains that the Federal Council publishes that list in Annex 1 of the DPO (FDPIC, cross-border transfer of personal data).
The Annex 1 text we checked, in the Fedlex version with status 1 December 2025 (the annex was last amended with effect from 15 September 2024), lists the EU and EEA states, the United Kingdom, Canada, Israel, New Zealand, Argentina, Uruguay, the United States (only for organisations certified under the Swiss-U.S. Data Privacy Framework), Monaco, Andorra and several Crown dependencies, among others (DPO Annex 1). Bangladesh is not on it, and neither is Japan. The Federal Council can amend the annex, so check the current version on Fedlex before you rely on this.
Without an adequacy decision, Article 16(2) allows disclosure only where an adequate level of protection is guaranteed by one of five instruments:
- (a) a treaty under international law;
- (b) data protection clauses in an agreement between the controller or processor and its contractual partner, "notice of which has been given to the FDPIC beforehand";
- (c) specific guarantees drawn up by the competent federal body, again notified to the FDPIC beforehand;
- (d) "standard data protection clauses that the FDPIC has approved, issued or recognised beforehand"; or
- (e) binding corporate rules approved by the FDPIC or by the data protection authority of an adequate state.
Article 17 then lists narrow exceptions, such as explicit consent or a disclosure directly connected with a contract with the data subject. For an ongoing development relationship, those exceptions are a poor fit; the clauses route is the practical one.
Can a Swiss company use the EU Standard Contractual Clauses with an offshore developer?
Yes. The FDPIC states that it "has recognised the Standard data protection clauses of the EU (Standard Contractual Clauses, SCC) and of the Council of Europe (Model Contractual Clauses, MCC)", and that "use of such clauses does not need to be reported to the FDPIC" (FDPIC, cross-border transfer of personal data). Clauses you draft yourself are different: under Article 16(2)(b) they must be notified to the FDPIC beforehand.
The EU clauses were written for the GDPR, so they need Swiss adaptations when a transfer is governed by the FADP. The FDPIC publishes a paper on this, last updated 12 February 2025 (FDPIC paper on transfers based on standard data protection clauses). The adaptations it sets out include naming the FDPIC as the competent supervisory authority in Annex I.C, reading GDPR references as references to the FADP, and adding an annex so that data subjects in Switzerland can sue in the Swiss courts where they live. Have your adviser read the current version rather than relying on our summary.
The clauses are also only the paper. Your adviser will usually want an assessment of whether the law and practice in the destination country let the importer honour them; check the FDPIC paper for what it expects. That assessment is yours, and a vendor can help by describing honestly who can access what, from where.
If you already work with EU vendors, the structure will feel familiar; outsourcing under GDPR covers the EU side, and the Singapore PDPA vendor guide shows how another regulator approaches the same question.
What does Article 9 ask of a processor?
Article 9 is short, and each paragraph maps to something you can put in the contract:
- 9(1): processing may be assigned to a processor if "the data is processed only in the manner in which the controller itself is permitted to do it" and no statutory or contractual duty of confidentiality prohibits it.
- 9(2): "The controller must satisfy itself in particular that the processor is able to guarantee data security." Due diligence is your duty, not a courtesy.
- 9(3): "The processor may only assign processing to a third party with prior approval from the controller." Sub-processors need your sign-off first.
- 9(4): the processor may claim the same grounds for justification as the controller.
Article 8 adds that controllers and processors must "guarantee a level of data security appropriate to the risk by taking suitable technical and organisational measures", and Article 12 requires processors, as well as controllers, to keep a record of processing activities. The table maps each clause you should expect to the provision it comes from.
| Clause | Where it comes from | What to ask the vendor for |
|---|---|---|
| Scope and instructions | FADP 5(k), 9(1)(a) | A written list of data categories and purposes, and a promise to process only on your instructions. |
| Transfer mechanism | FADP 16(2)(d) | The EU SCCs with Swiss adaptations, signed as part of the bundle, or clauses your adviser drafts and notifies under 16(2)(b). |
| Named countries | FADP 16, 19(4) | Where the data is stored and from where it may be accessed, so your privacy notice can name the states concerned. |
| Data security | FADP 8, 9(2) | Access control, encryption, multi-factor sign-in on production, and confidentiality duties on every team member. |
| Sub-processors | FADP 9(3) | A list of sub-processors and your prior approval before any new one, with the same terms flowed down. |
| Breach notice to you | FADP 24(3) | Notice "as quickly as possible", a named contact on each side, and help with your assessment. |
| Records of processing | FADP 12 | A processor-side record you can request, covering the processing done for you. |
| Deletion or return | FADP 6 (principles) | Deletion or return at the end of the purpose or contract, with written confirmation and no copies on laptops. |
Put the IP assignment and NDA in the same bundle; the offshore IP assignment checklist covers those clauses.
How fast must a data breach be reported to the FDPIC?
"As quickly as possible", with no fixed number of hours. That is the English wording of Article 24, and it applies both to the vendor telling you and to you telling the FDPIC. The trigger for the FDPIC is a breach "likely to lead to a high risk to the data subject's personality or fundamental rights" (Art. 24(1)). Reports go through the FDPIC's reporting portals.
| Step | Who | What the text says |
|---|---|---|
| Tell you about any breach of data security | Vendor (processor) | "As quickly as possible", for any breach, not only high-risk ones (FADP 24(3)) |
| Decide whether the risk is high | You (controller) | The high-risk test is yours to apply (FADP 24(1)) |
| Notify the FDPIC | You | As quickly as possible, stating at minimum the nature of the breach, its consequences and the measures taken or planned (FADP 24(1)–(2)) |
| Inform affected people | You | If required for their protection, or if the FDPIC asks (FADP 24(4)) |
| Keep the record | You | Document the incident, its effects and the measures taken, and keep it for at least two years from the report (DPO Art. 15) |
Note the asymmetry in the first row. The vendor reports every breach to you, and you decide what reaches the regulator. In engineering terms, the vendor's job is to make that first row fast and the rest possible: logs showing which records were touched, and by whom. Designing a SaaS audit log covers what to record.
Who pays the CHF 250,000 fine: the company or the person?
Usually the person. This is the part of the revFADP that surprises people used to the GDPR. Article 61 reads: "On complaint, a fine not exceeding 250,000 francs shall be imposed on private persons who wilfully" disclose data abroad in breach of Articles 16 and 17, assign processing to a processor without meeting Article 9(1) and (2), or fail to meet the minimum data security requirements.
Three details matter for a vendor decision:
- It is wilful conduct. The offence needs intent, which is why a documented, reasoned vendor choice is worth having on file.
- Businesses are a fallback. Under Article 64(2), where a fine of up to 50,000 francs is under consideration and finding the responsible individuals would be disproportionate, the authority may order the business to pay instead.
- The window is long. Prosecution is subject to a five-year limitation period (Art. 66).
Two of the three Article 61 offences, a transfer without a safeguard and a processor chosen without checking its security, are exactly what this contract bundle addresses.
Can the data stay in Switzerland while the team works from Dhaka?
Often, yes, and it shrinks the problem. Host production in Switzerland, for example in the AWS Europe (Zurich) region, eu-central-2 (AWS Regions), and let the team build against synthetic data. This is engineering guidance; whether remote access to a Swiss-hosted system counts as disclosure abroad in your set-up is a question for your adviser.
- Synthetic data by default. Development and staging run on generated records, never a copy of production.
- No standing production access. Access for a live incident is requested, approved by you, time-limited and logged.
- Tenant isolation in the database. Row-level security keeps one customer's rows away from another's even if application code slips; see the Postgres row-level security guide.
- Access that expires on its own. In PostgreSQL, an incident role can be read-only, limited to named tables and set to stop working at a fixed time:
-- Read-only incident access, approved by the client, expiring automatically.
CREATE ROLE incident_20270301 LOGIN PASSWORD 'rotate-me'
VALID UNTIL '2027-03-01 18:00:00+01';
GRANT CONNECT ON DATABASE app TO incident_20270301;
GRANT USAGE ON SCHEMA public TO incident_20270301;
GRANT SELECT ON public.orders, public.order_events TO incident_20270301;
-- No INSERT, UPDATE or DELETE, and no access to customer contact tables.
For the wider checklist, SaaS security practices covers secrets, sessions and dependency updates.
How much working time overlaps between Zurich and Dhaka?
About 4 hours in winter and 5 in summer, with both sides on a 9:00 to 18:00 day. Dhaka is UTC+6 with no daylight saving, so the shared window is 9:00 to 13:00 Zurich time in winter and 9:00 to 14:00 in summer. That is enough for a morning incident call; everything else runs on written daily handoffs. The working week is agreed per client.
Why RAITHub for this
- We sign your paper. RAITHub signs DPAs and SCCs, including the Swiss-adapted SCCs your adviser prepares, and follows your controls. NDA is standard, and the client owns the IP.
- We are honest about where data goes. We will tell you in writing which people, in which country, can access which systems, so your transfer assessment and privacy notice rest on facts.
- Access control we have shipped. Sundor Skin runs 146 PostgreSQL tables with row-level security, 88 permission codes and 12 staff roles, covered by 530+ tests.
- Synthetic data first. Builds default to generated data, so most of the team never needs production access.
- A clear next step. Multi-tenant products run under SaaS development; integration-heavy work under API and backend development.
When you don't need us
- Your policy requires data processing in Switzerland only, with no access from abroad. Then use a Swiss team, or keep the offshore team strictly on synthetic data with no incident role.
- You need a certified vendor. RAITHub holds no SOC 2 or ISO 27001 certification. If your procurement rules require one, choose a certified vendor.
- You need legal advice. RAITHub has no legal expertise. Have a Swiss data protection lawyer prepare the SCC adaptations and review the bundle.
- You want a developer placed in your team. RAITHub does not offer staff augmentation.
For the wider vendor-risk view, see is it safe to hire a Bangladesh software agency, and for the security review your enterprise customers will send, answering a first security questionnaire without SOC 2.
Sources checked on 1 October 2026: the FADP (SR 235.1) in the English version on Fedlex dated 1 September 2023, the DPO (SR 235.11) in the English version with status 1 December 2025, and the FDPIC's cross-border transfer page. Article numbers refer to those texts. General information only; confirm with your adviser and the FDPIC.
If none of those rule us out, book the free 15-minute technical audit. Bring a list of the personal data your product holds, and we will tell you on the call what the team would and would not need to see.
Frequently asked questions
Can a Swiss company send personal data to a developer in Bangladesh?
Yes, with a safeguard. Bangladesh is not on the Federal Council's adequacy list in Annex 1 of the DPO, so the transfer usually rests on standard data protection clauses the FDPIC has recognised, such as the EU SCCs with Swiss adaptations. This is general information; confirm with your adviser.
Do I need to notify the FDPIC when I use the EU SCCs?
No. The FDPIC says use of the clauses it has recognised does not need to be reported. Clauses you draft yourself must be notified to the FDPIC beforehand under Article 16(2)(b).
What must a processor contract include under the revFADP?
At minimum, processing only as you are permitted to do it, data security the processor can guarantee, and your prior approval for sub-processors (Article 9). In practice, add breach notice, permitted countries, records of processing and deletion at the end.
How fast must a breach be reported under the Swiss FADP?
As quickly as possible. There is no fixed hour limit in the Act. The processor tells the controller about any breach, and the controller notifies the FDPIC where the breach is likely to lead to a high risk for the people affected.
Are revFADP fines imposed on the company or on individuals?
Mainly on individuals. Article 61 provides fines of up to CHF 250,000 on private persons who act wilfully. A business can be ordered to pay a fine of up to CHF 50,000 where tracing the responsible people would be disproportionate.
Is RAITHub certified for Swiss data protection?
No. RAITHub holds no SOC 2 or ISO 27001 certification and makes no compliance claim. It signs DPAs and SCCs, follows your controls, and describes in writing who can access what, from where.
Related posts
Ready to discuss your project?
Book a free 15-minute technical audit with our engineering team.