LexVibe
Switzerland
In force since 1 September 2023

nFADP compliance for a fintech app

Swiss Federal Act on Data Protection (revised, SR 235.1). This page applies it to one kind of product (fintech app), so you get the obligations that are actually yours instead of a summary of the whole statute.

Does it apply to you?

Processing that affects people in Switzerland, including from abroad.

What a fintech app typically processes

  • identity verification and KYC documents
  • bank account or card data through a regulated provider
  • transaction history and fraud signals

Each of these is processing you have to disclose. Adding an SDK later adds to this list — which is why a policy written once goes stale.

Documents you need

The intersection of what nFADP requires and what a fintech app actually does:

  • Privacy policy
  • Data processing agreement (DPA)

Rights you must honour

nFADP gives people in Switzerland the right to:

  • Access a copy of their data
  • Correct inaccurate data
  • Have their data deleted
  • Receive their data in a portable format
  • Object to certain processing
  • Ask for human review of an automated decision

Cookies and trackers

Trackers may load by default, but the visitor needs a working way to opt out, and you must honour it.

See what your site is actually missing

Paste your URL. We fetch the live page, detect the trackers, payments and AI calls that really ship to visitors, and tell you which documents and consent you need. No signup.

No signup · result in seconds

Primary sources

Everything we track about nFADP

nFADP for other kinds of product

Other frameworks for a fintech app

This page is an engineering summary of publicly available regulatory requirements, generated from LexVibe's framework registry — not legal advice. Every framework links to its official text so you can check it yourself. For decisions about your own compliance posture, consult the primary sources and a lawyer qualified in the relevant jurisdiction.