
The law uses the word "may" for this role. Art. 10 para. 1 FADP: "Private controllers may appoint a data protection advisor." The FDPIC puts it even more plainly on its page about the role: unlike the European GDPR, the appointment is optional for private entities, only federal bodies are legally obliged to make one.
That answers the question in the title from a legal point of view. A data protection advisor is not mandatory for your SME in Switzerland, and there is no fine either. Art. 10 does not appear in the criminal provisions of the FADP, Art. 60 to 63. Fines apply to anyone who wilfully gives false information, who discloses data abroad without meeting the requirements, who hands processing to a processor without complying with Art. 9 paras. 1 and 2, or who disregards a ruling by the FDPIC. A missing advisory role is not on that list.
In practice the question stays open, it just is not about compliance. It is about who answers the data protection questions that already arrive at your company.
What the law expects from a data protection advisor
Art. 10 para. 2 FADP describes the tasks briefly. The data protection advisor is the point of contact for data subjects and for the authorities responsible for data protection in Switzerland. On top of that come training and advising the controller on data protection matters, and participating in the application of the data protection provisions.
Read that twice, because both directions are in there. Outwards, the role is an address: when a customer requests access to her data or the FDPIC asks a question, there is a person who answers. Inwards, it is advice and participation. It does not decide, the controller remains the controller. This role carries no liability and has no authority to give instructions. What it delivers is a judgement.
This is where the most common mistake sits. Many companies look for someone to "take over" data protection and then appoint a person who may neither decide nor get access to the decisions. We described the same pattern for security responsibility: the work can be delegated, the accountability cannot.
Advisor, officer, representative: three roles, three laws
The terms get mixed freely in proposals and templates, and that costs time in every discussion.
The data protection advisor is the Swiss role under Art. 10 FADP, optional for private entities.
The data protection officer comes from the GDPR. There it is mandatory in three cases: for public authorities and bodies, where the core activity consists of processing operations requiring regular and systematic monitoring of data subjects on a large scale, or where the core activity consists of large-scale processing of special categories of data or data on criminal convictions and offences (Art. 37(1) GDPR). Art. 37(6) expressly allows this person to be an external party working on the basis of a service contract rather than an employee.
The representative is something else again, namely an address in the respective legal area. The GDPR requires one in Art. 27 from controllers without an establishment in the Union, and the FADP requires one in Art. 14 the other way round from foreign companies that process data in Switzerland under certain conditions.
For a Swiss SME with customers or staff in the EU this means: Swiss optionality says nothing about whether the European obligation applies to you. That is a legal question and it belongs to a lawyer. The only thing our experience adds is an order of steps: first clarify which law applies to which processing, then decide who fills the role. The other way round you end up discussing headcount percentages before you know whether you are meeting an obligation or doing something voluntary.
The one benefit you can actually calculate
There is exactly one place in the FADP where an appointed data protection advisor gives you a tangible advantage, and it has to do with time.
For processing that may cause a high risk to the personality or fundamental rights of the data subject, you need a data protection impact assessment beforehand (Art. 22 FADP). If a high risk remains despite the measures you plan, you must consult the FDPIC in advance (Art. 23 para. 1). The FDPIC has two months for this, three in the case of complex processing (Art. 23 para. 2). And then comes para. 4: the private controller may refrain from consulting the FDPIC if it has consulted the data protection advisor under Art. 10.
Translated: an administrative procedure with a waiting period becomes an internal conversation with minutes. For a company that wants to introduce video surveillance or a new recruiting system, that is the difference between a project start in November and one in February. How to tell whether you fall under that obligation at all is described in our article on the data protection impact assessment.
One caveat: this shortcut only applies if the four conditions in Art. 10 para. 3 are met. And that is where it breaks down.
The condition that fails in an SME
Art. 10 para. 3 FADP names four conditions:
- The advisor performs the function towards the controller in a professionally independent manner and without instructions.
- The advisor performs no activities that are incompatible with those duties.
- The advisor has the necessary expertise.
- The controller publishes the advisor's contact details and notifies them to the FDPIC, in practice through the FDPIC's DPO portal.
Three of these are organisational work. The second is the sticking point, and precisely at the company size where most people start thinking about a data protection advisor.
In a company with 60 people there is rarely anyone without an operational role. The obvious candidates are the IT manager, the head of HR, the marketing lead or the CFO. The thing is: the IT manager selects the systems and sets the permissions. HR runs the recruiting system. Marketing decides on tracking and newsletter lists. Whoever designs the processing is reviewing their own work when they put on the advisor hat, and para. 3 lit. b rules out exactly that.
Then there is the first condition, which often gets skimmed over. "Without instructions from the controller" means that management may not overrule this person on technical data protection questions. In an SME that is not a formality, it is a small question of power. It can be solved, with an external data protection advisor or with an internal role that has no responsibility for the processing systems. It cannot be organised away by appointing someone and hoping nobody asks.
Nobody checks the expertise in advance, by the way. There is no admission procedure and no mandatory certification for this role. The FDPIC states that knowledge of data protection legislation and of the technical standards for data security is required. Whether it is there shows in the first serious case.
What you owe the role
Few people know this part. The Data Protection Ordinance sets out three duties of the controller towards the data protection advisor in Art. 23 DPO: provide the necessary resources, grant access to all information, documents, records of processing activities and personal data the person needs for their tasks, and grant the right to inform the highest management or administrative body in important cases.
Those three points are the actual decision. Appointing a data protection advisor takes fifteen minutes. Resources, access and a direct channel to management or the board of directors cost attention, and they change how decisions get made in your company.
If the role has no time, gets no access and has to escalate through three levels on an uncomfortable finding, you have a line in the org chart and no data protection. It is the same mechanism we know from security mandates and described for cyber liability on the board: a report that reaches the highest body is the measure. Everything else is paper. That is why we attach this role to an existing reporting line when building an ISMS, rather than placing it next to one.
What a data protection advisor costs, and what to measure it against
The usual cost question is "what does an external data protection advisor cost". The more useful calculation runs the other way: what does it cost to keep answering these questions in an unstructured way, by a different person each time and from scratch each time?
An indicator comes from the obligation right next to the role. Art. 12 FADP requires a record of processing activities, and Art. 24 DPO exempts companies with fewer than 250 employees as of 1 January. That exemption falls away if sensitive personal data is processed on a large scale or if high-risk profiling takes place. If your company falls out of the exemption, a data protection advisor has ongoing work and a benefit you can demonstrate. If it does not, you need someone responsible rather than someone formally appointed.
What you can leave out: certification courses for several employees before it is even clear who carries the role. And software that promises compliance. A consent manager answers no access request, a policy generator creates no independence.
The most common quiet double payment in our experience is a different one: data protection support you already pay for through a fiduciary, legal or IT mandate, without anyone having named the role. Look through the running contracts before you create a new position.
And if you want to sort out the basics first instead of filling a role straight away: our overview of the revised Data Protection Act and the article on personal liability for managing directors set out which duties apply regardless of this role.
Three questions before you appoint anyone
Take the last data protection questions that came in at your company. An access request, a customer questionnaire, a query about a new tool. Then write down: who answered them, by name? Is that person responsible for one of the systems involved? And could they have informed management directly about an uncomfortable finding, without asking anyone for permission first?
If all three answers are clean, you already have the data protection advisor in practice and only need to appoint them and notify the FDPIC. Hesitation on the second or third question shows you where the problem sits: with the position, not with the knowledge. That is the more uncomfortable finding and the cheaper one, because a decision solves it and no budget.
If you want to know how to attach this properly in your organisation, without creating a position nobody can fill: an initial conversation is free of obligation.
One question does interest us. Who in your company is allowed to say today that a planned processing operation will not go ahead like that?
Frequently asked questions
Is a data protection advisor mandatory in Switzerland?
Not for private companies. Art. 10 para. 1 FADP says "may", and the article does not appear in the criminal provisions of the FADP. Only federal bodies must appoint a data protection advisor. If you have an establishment or customers in the EU, also check the three mandatory cases in Art. 37(1) GDPR.
What does a data protection advisor give an SME?
One concrete advantage. If a high risk remains after a data protection impact assessment, you must consult the FDPIC and wait two to three months for its opinion. Whoever has properly appointed a data protection advisor under Art. 10 para. 3 FADP may consult that person instead and skip the wait (Art. 23 para. 4 FADP).
Who may act as a data protection advisor in a company?
Anyone with the necessary expertise, employed internally or externally. The sticking point is incompatibility under Art. 10 para. 3 FADP: whoever selects or runs the systems in question is reviewing their own work. For their own processing operations, IT management, HR and marketing are therefore ruled out.




