nDSG Liability for Managing Directors: Who Really Pays

Most managing directors believe that in the event of a data protection breach, the company pays in the end. This is the most expensive misconception in the revised Data Protection Act.

Since September 1, 2023, the nDPA (revised Data Protection Act) has been in force in Switzerland, and it has inverted this logic. The fine no longer lands on the company; it lands on the responsible natural person. Up to 250,000 Swiss francs, and you cannot pass it on to the company. The nDPA liability affects you personally as managing director. This is stated by the Federal Data Protection and Information Commissioner (FDPIC, Penal Provisions).

The usual response to this news is to buy a large compliance program. More tools and an external data protection advisor on a permanent mandate. In our experience, this is the wrong answer to the wrong fear. What the law actually punishes is narrower and cheaper to secure than most people think.

Why you are suddenly liable, not the company

Under the old data protection law, the fine amount was symbolic. 10,000 Swiss francs, and in practice, little ever happened. For most SMEs, data protection was therefore just a footnote.

The nDPA changed two things. First, the amount: up to 250,000 francs. Second, and this is the real point, the recipient of the fine. Punishment is primary given to the natural person responsible for the breach. Not an anonymous company, but a human being with a name.

Who is this person? This is not decided by the FDPIC, but by the cantonal public prosecutor's office on a case-by-case basis. Often it is the person who made the decision or deliberately ignored the duty. In an SME without its own data protection function, this is often the managing director themselves, because the responsibility converges with them and no one else formally bears it.

There is an exception that reassures many and yet is no real way out. If identifying the guilty person would involve disproportionate effort, the company can be fined instead of the person, but then only up to 50,000 francs. This is not a protective shield. It is the prosecutor's last resort if they cannot clearly assign responsibility to a person. I would not rely on that.

The point is not that panic is now appropriate. The point is that the question has shifted. Previously it was: What does this cost the company? Today it is: Who in this building bears the name that ultimately ends up on the ruling?

GDPR punishes the company, the nDPA punishes the person

Many Swiss companies inherited their idea of data protection from the European GDPR. There, the figures are huge, up to four percent of global turnover, and they hit the company as a whole.

Switzerland does it more quietly and personally. Smaller amounts, but directly to the responsible person. This changes the character of the punishment. A company books a fine as an expense item. A person who is supposed to pay 250,000 francs privately experiences that differently. That is exactly what the legislature intended: data protection should be an executive matter, not a delegable residual risk.

What is actually punishable, and what is not

This is where most fears dissolve if you look closely.

Only intent is punishable. Anyone who breaches a duty negligently because they simply did not know it or made a mistake does not commit a criminal offense under the nDPA. It is exclusively about consciously committed acts. This is a crucial boundary, and it changes where you should direct your energy.

And the punishable duties are a manageable list, not an endless catalog. These include, among others:

  • The duty to inform when you obtain personal data, and the duty to provide information when a data subject asks what data you have about them.
  • Certain obligations when transferring data abroad.
  • Compliance with a minimum level of data security.
  • Professional secrecy regarding secret personal data.

That is it in essence. Nowhere does it say that you need a perfect, seamless management system to remain free of prosecution. It says that you must not willfully violate a handful of clear duties. If you haven't sorted out the basics of the law yet, it's worth checking out our overview of the revised Data Protection Act first.

The wrong reaction: buying a program to combat fear

As soon as the words personal liability are mentioned, everything sells easier. The data protection consultant, the tool, the three-day assessment, the 120-page catalog of measures. Fear is an excellent salesperson.

Only the thickest binder won't protect you from the one thing that is actually punishable: deliberately ignoring something. On the contrary. An bloated program that nobody lives generates paperwork documenting that you knew about a problem. That is not your friend in front of a prosecutor.

We see the same pattern in security all the time. Companies buy tools to soothe a feeling instead of addressing the actual risk. In data protection, the risk is not incompleteness. The risk is intent. And budget doesn't help against intent, but an attitude and a cleanly regulated process of responsibility do. If you want to understand why more tools rarely mean more protection, you can find the longer version in our post on building a pragmatic ISMS without despairing.

What a managing director should do instead

The good news: What actually helps is smaller and cheaper than what is being sold to you. It's not about completeness, it's about responsibility that can be named and proven.

Explicitly assign responsibility and document it. If no one is officially responsible, it's you by default. Appoint a responsible person, give them the necessary authority, and document it. That is the difference between "the boss deliberately let it run" and "responsibility was regulated."

Know what personal data you have in the first place. You cannot fulfill a duty for data you don't know exists. A simple record of processing activities is sufficient for most SMEs. No tool is necessary; a spreadsheet is often enough.

Make sure you can respond to an inquiry. This is the duty that is most likely to land on the desk in day-to-day business, often from an angry ex-employee. Anyone who does not react here is moving towards intent the fastest.

Maintain a reasonable minimum level of data security. No major zero-trust project. The usual basics that you need for cybersecurity anyway.

Do not ignore a reported problem. This is the most important rule and the cheapest. If someone reports a data protection issue to you, doing nothing is the moment when a mistake turns into intent. Reacting does not have to mean solving everything immediately. It means not deliberately ignoring it.

These five points are not a compliance program. They are the basic equipment that gets you out of personal liability without making a six-figure investment.

Delegation protects you, turning a blind eye does not

A common misconception is that as a managing director, you are automatically liable for everything. It is not that simple. Because only intent is punishable, the concrete role in the violation decides who will be prosecuted.

If you properly delegate responsibility to a competent person, give them the necessary resources and authority, and do not deliberately breach a duty yourself, your personal exposure drops. Not because you buy your way out, but because the intent then lies with the person who actually acted or omitted to act. Delegation is not a trick in the nDPA, it is the intended path.

What brings you back into liability is the opposite of delegation: deliberately turning a blind eye. Anyone who knows about a reported gap but has never regulated the responsibility can hardly refer to someone else afterwards. That is exactly why the two cheapest measures, named responsibility and documented response, are also the most effective.

And that is where data protection and cost discipline coincide. The expensive option is to buy a program out of fear that ultimately does not protect you. The cheap option is to clarify responsibility and take a handful of duties seriously. More protection for less money is not a marketing line here, but simply how the law works.

The case we see time and again

In our experience, the typical emergency does not begin with a hacker attack, but with an email. A person requests information about their data, receives no answer, follows up, is ignored, and contacts the FDPIC.

Up to this point, almost nothing had happened. No data loss, no leak. Only an unanswered request that sat on a desk for too long. It is precisely this neglect that moves a harmless situation close to intent. The damage is rarely caused by the original omission. It is caused by deliberately turning a blind eye afterwards.

You know the same mechanics from executive responsibility in cyber topics. We described them in detail when it came to liability on the board of directors. The legal basis is different, the pattern is the same: responsibility that no one actively bears ultimately falls back on the person at the top.

If you want to know where your company really stands regarding these few duties instead of drowning in a generic questionnaire, we can look at it together in an initial consultation without obligation. Usually, the situation is more sober than fear suggests, and the gaps are concrete and closeable. Read more about this on our page about compliance.

The honest question

Imagine an inquiry comes in tomorrow, and in six months it lands on the prosecutor's desk. The question is not: Did we have the perfect data protection program?

The question is: Could we show who was responsible and that we did not deliberately ignore the issue?

Your answer to this won't cost you a six-figure budget. It costs you a clear allocation of responsibility and the discipline not to ignore a reported problem. That is the entire nDPA liability for managing directors, condensed to the essentials.