Swiss FADP representative: four combined criteria, separate from GDPR
Use this guide to prepare a Swiss Article 14 assessment and compare the representative contact workflow. It does not determine whether your organisation meets the combined criteria. Establish the Swiss offering or monitoring connection, scale, regularity and risk before treating an appointment as required. FDPIC guidance describes four combined Article 14 criteria for private controllers outside Switzerland: offering/monitoring connection, large-scale processing, regular processing and high risk. Assess all four using Swiss facts. The GDPR representative exception test is a different legal analysis.
Evidence retrieved 2026-10-06. Source versions and topic-specific limits are listed below.
Sourced criteria · CH
What changes the service scope?
Decision or task
What the source describes
What to prepare
What connects the processing to Switzerland?
The guidance describes processing linked to offering goods/services or monitoring behaviour of people in Switzerland. [1][2]
Record actual offering/monitoring and covered processing; avoid inferring scope from site accessibility alone.
Is processing both large-scale and regular?
The guidance distinguishes large-scale processing from isolated instances, and regular processing from occasional or limited-period processing. [1][3][4]
Assess both conditions independently across ongoing/planned covered processing.
Does the processing present high risk?
The guidance identifies risk to personality rights and factors including data volume/type, purpose, new technologies, foreign disclosures and access. [1][5]
Prepare the actual risk facts and specialist assessment; do not copy the GDPR low-risk exception unchanged.
What is the representative contact workflow?
The guidance describes a contact role for affected people/FDPIC and publication of representative name/address; voluntary notification to FDPIC is distinguished from a mandatory notification. [6][7]
Define published contact, receipt/escalation and evidence access; check the cited service-address qualification.
The deciding Swiss scale, regularity and risk facts remain incomplete. This is regulator guidance, not an automated legal opinion about your organisation.
Swiss criteria and representative handoff
Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.
What connects the processing to Switzerland?
Record actual offering/monitoring and covered processing; avoid inferring scope from site accessibility alone.
Useful evidence: Swiss offering/monitoring description and processing map.
Conditional: Swiss criteria, mandate and contact assessment — Preparation tasks to agree: Record actual offering/monitoring and covered processing; avoid inferring scope from site accessibility alone. Assess both conditions independently across ongoing/planned covered processing. Prepare the actual risk facts and specialist assessment; do not copy the GDPR low-risk exception unchanged. Define published contact, receipt/escalation and evidence access; check the cited service-address qualification. This package remains conditional until the deciding facts and exclusions are agreed.
Questions for providers
Which exact actor, product or processing facts support the quoted scope, and what is still unresolved?
How will the listed records reach the responsible people, and who owns each change or authority request?
Which tasks and entities are excluded from the agreement, and which additional services need a separate assessment?
Sources and data dates
Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.