🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
CH v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing23 sources retrieved model claude-sonnet-5 · 2026-08-03

Switzerland

CH schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 41 claims · 29 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
41Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 28 September 2026.

Lead Signal

Switzerland's revised Federal Act on Data Protection (revFADP) entered into force on 1 September 2023, and the Federal Data Protection and Information Commissioner (FDPIC) is understood to operate as the sole federal supervisory authority responsible for enforcing it. This cycle establishes the first full Data Protection Monitor baseline for Switzerland, drawing on structured claims spanning all ten modules of the framework. The most material development is not new legislative activity but a correction to the analytical record itself: a systemic review found that six foundational claims about the Swiss regime — including the FDPIC's supervisory role, the revFADP's entry into force, and its extended territorial scope — had been assigned an assertive confidence level on the strength of a single secondary source each, and confidence in each has been revised downward to a more qualified register. A related research gap has also been resolved: corroborating practitioner sources indicate that private-sector appointment of what Swiss law terms a data protection advisor remains voluntary under Article 10 FADP, while federal bodies are understood to be legally required to appoint a data protection officer under Article 25 of the Data Protection Ordinance. Read together, these two corrections mean the baseline Swiss claim-set entering this cycle's downstream state is materially more conservative and more precisely sourced than the raw research pass first produced it.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive, currently-in-force omnibus statute with an active, empowered supervisory authority; GDPR-aligned but not identical.

Primary frameworkFederal Act on Data Protection (FADP), revised version in force 1 September 2023
Traffic-light rationale — GreenA comprehensive, currently-in-force omnibus statute with an active, empowered supervisory authority; GDPR-aligned but not identical.

Sub-modules (5)

Regulator And AuthorityGreen

The FDPIC is the federal supervisory authority; cantons additionally maintain their own commissioners for cantonal/communal bodies, creating a partially federated oversight structure alongside the federal regime.

Claims (1):

  • The Federal Data Protection and Information Commissioner (FDPIC) is the federal data protection authority responsible for supervising the FADP.

Act And InstrumentsGreen

The revFADP and its Ordinance constitute the primary instruments, in force since 1 September 2023, replacing the 1992 FADP and bringing Swiss law closer to GDPR standards.

Claims (1):

  • The revised Swiss Federal Act on Data Protection came into force on 1 September 2023, bringing Switzerland's data protection regime into closer alignment with the EU GDPR.

Material ScopeGreen

The FADP applies as an omnibus law to processing of personal data by private persons and federal bodies irrespective of sector; cantonal acts govern cantonal/communal bodies separately.

Claims (1):

  • The FADP is an omnibus law applying to any processing of personal data by private persons and federal bodies, irrespective of sector, while cantonal acts separately govern cantonal and communal bodies.

Territorial ScopeGreen

The revFADP's territorial scope was broadened, GDPR-style, to capture processing with an effect in Switzerland even if the processing activity is initiated from abroad.

Claims (1):

  • The revFADP applies to circumstances that have an effect in Switzerland even where the processing activity is initiated abroad, giving the FDPIC competence over any activity with Swiss impact regardless of origin.

Regulator Registration And FilingAmber

There is no general controller-registration/filing regime; instead, non-Swiss controllers meeting territorial-scope criteria must designate and publish a Swiss representative, who is responsible for maintaining the controller's records of processing and producing them to the FDPIC on request.

Claims (1):

  • Where the revFADP's extraterritorial scope applies, the controller must appoint and publicly identify a Swiss representative, who is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC on request.
Category narrative94 words

Switzerland's data protection regime is governed by the revised Federal Act on Data Protection (revFADP, FADP 2020), which entered into force on 1 September 2023 alongside its implementing Ordinance, replacing the 1992 FADP. The regime is enforced by the Federal Data Protection and Information Commissioner (FDPIC/EDÖB), an independent federal authority. The revFADP brings Switzerland into closer alignment with the GDPR while retaining distinctly Swiss features (e.g., no general administrative fining power for the FDPIC, personality-rights-based unlawfulness test). Territorial scope was significantly broadened to reach processing with an effect in Switzerland even where initiated abroad.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidance — The Federal Data Protection and Information Commissioner (FDPIC) is the federal data protection authority responsible for supervising the FADP.observed
  2. ConfirmedInternational Association of Privacy Professionals — The revised Swiss Federal Act on Data Protection came into force on 1 September 2023, bringing Switzerland's data protection regime into closer alignment with the EU GDPR.observed
  3. ConfirmedInternational Association of Privacy Professionals — The revFADP applies to circumstances that have an effect in Switzerland even where the processing activity is initiated abroad, giving the FDPIC competence over any activity with Swiss impact regardless of origin.observed
  4. ProbableInternational Association of Privacy Professionals — Where the revFADP's extraterritorial scope applies, the controller must appoint and publicly identify a Swiss representative, who is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC on request.observed
  5. ProbableOneTrust DataGuidance — The FADP is an omnibus law applying to any processing of personal data by private persons and federal bodies, irrespective of sector, while cantonal acts separately govern cantonal and communal bodies.observed

#

Structurally different from GDPR's Art 6 lawful-basis model; sensitive-data protections exist but the consent architecture is comparatively lighter.

Primary frameworkFederal Act on Data Protection (FADP), revised version
Traffic-light rationale — AmberStructurally different from GDPR's Art 6 lawful-basis model; sensitive-data protections exist but the consent architecture is comparatively lighter.

Sub-modules (4)

Lawful BasesAmber

Swiss law does not treat the absence of a specified legal basis as per se unlawful; unlawfulness is instead assessed against breach of personality rights.

Claims (1):

  • Unlike the EU GDPR, Swiss law does not provide that processing of personal data without a specified legal basis is per se illegitimate; legitimacy instead turns on absence of a breach of personality rights.

Special CategoriesGreen

The revFADP extended the definition of sensitive personal data to explicitly include genetic and biometric data, while retaining a risk-based rather than explicit-consent-centric approach.

Claims (1):

  • The FADP's definition of sensitive personal data was extended in the revision process to cover biometric and genetic data, while maintaining a risk-based approach rather than the EU's explicit-consent concept for such data.

Pseudonymisation And AnonymisationAmber

Anonymised or aggregated data falls outside the FADP's personal-data scope because the person is no longer identifiable; pseudonymised data, by contrast, may still permit re-identification and generally remains in scope.

Claims (1):

  • Anonymised or aggregated data is not personal data under the FADP because the person is not identifiable, whereas pseudonymised data may still permit re-identification and is generally treated as personal data.
Category narrative80 words

Unlike the GDPR's positive lawful-basis requirement, Swiss law does not require a specified legal basis for processing to be lawful per se; processing is only unlawful if it breaches personality rights under the Civil Code/FADP principles. The revFADP nonetheless expanded the definition of sensitive personal data to include genetic and biometric data and retains a risk-based (rather than explicit-consent-centric) approach to sensitive data. Consent functions primarily as a derogation basis for cross-border transfer and is not a universal processing gateway.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ProbableOneTrust DataGuidance — Unlike the EU GDPR, Swiss law does not provide that processing of personal data without a specified legal basis is per se illegitimate; legitimacy instead turns on absence of a breach of personality rights.observed
  2. ProbableOneTrust DataGuidance — Under Article 17 of the revised FADP, a cross-border data transfer may be legitimate where the data subject has consented, in addition to contractual necessity, overriding public interest, or the data having been made publicly accessible by the subject.observed
  3. ProbableInternational Association of Privacy Professionals — The FADP's definition of sensitive personal data was extended in the revision process to cover biometric and genetic data, while maintaining a risk-based approach rather than the EU's explicit-consent concept for such data.observed
  4. ProbableOneTrust DataGuidance — Anonymised or aggregated data is not personal data under the FADP because the person is not identifiable, whereas pseudonymised data may still permit re-identification and is generally treated as personal data.observed

#

Core rights are present and GDPR-inspired, but the objection right is narrower and exact response-window detail is unconfirmed.

Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 25, 30-32
Traffic-light rationale — AmberCore rights are present and GDPR-inspired, but the objection right is narrower and exact response-window detail is unconfirmed.

Sub-modules (5)

Access RightGreen

Article 25 of the revFADP provides a more detailed subject-access right than the prior law's single-sentence entitlement to know whether data is processed.

Claims (1):

  • Article 25 of the revised FADP provides a more detailed access right for data subjects than the prior 1992 FADP's general information-request entitlement.

Rectification And ErasureGreen

The revFADP explicitly states a right to erasure (previously only implicit) alongside rectification rights under Art 32.

Claims (1):

  • The revised FADP explicitly states a right to erasure, whereas the old FADP only implicitly recognised it, and introduces rectification rights under Article 32.

Restriction And ObjectionAmber

A right equivalent to GDPR Art 21 does not exist per se; Swiss law provides a narrower opt-out-style objection right under Art 31(2)(b) revFADP.

Claims (1):

  • A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; instead, Article 31(2)(b) of the revised FADP provides a data subject right to object to processing, essentially limited to an opt-out right.

Data PortabilityGreen

The right to data portability, copied from the GDPR, is entirely new to Swiss law under the revFADP.

Claims (1):

  • The right to data portability, copied from the GDPR, is completely new to Swiss law under the revised FADP.

Deadlines And Response WindowsRed

Available sources did not confirm a specific statutory response-time window (analogous to the GDPR's one-month period) for Swiss data subject requests.

Absence provenance: unavailable. Searched: FADP data subject access request deadline response window, revFADP Article 25 response time days.

Category narrative83 words

The revFADP substantially strengthens data subject rights compared to the 1992 law, introducing an explicit right to erasure and a wholly new right to data portability modelled on the GDPR, alongside a more detailed access right (Art 25) and rectification rights (Art 32). The objection right, however, remains narrower than GDPR Art 21 — Swiss law provides an opt-out-style objection right rather than a general right to object on grounds relating to particular circumstances. Statutory response-deadline specifics were not confirmed in available sources.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ProbableOneTrust DataGuidance — Article 25 of the revised FADP provides a more detailed access right for data subjects than the prior 1992 FADP's general information-request entitlement.observed
  2. ConfirmedOneTrust DataGuidance — The revised FADP explicitly states a right to erasure, whereas the old FADP only implicitly recognised it, and introduces rectification rights under Article 32.observed
  3. ProbableOneTrust DataGuidance — A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; instead, Article 31(2)(b) of the revised FADP provides a data subject right to object to processing, essentially limited to an opt-out right.observed
  4. ConfirmedOneTrust DataGuidance — The right to data portability, copied from the GDPR, is completely new to Swiss law under the revised FADP.observed

#

Core accountability infrastructure (DPIA, security, retention, breach notification) is in force and GDPR-adjacent, but breach-notification timing and DPO-threshold specifics carry residual uncertainty.

Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 6-9, 22-24
Traffic-light rationale — AmberCore accountability infrastructure (DPIA, security, retention, breach notification) is in force and GDPR-adjacent, but breach-notification timing and DPO-threshold specifics carry residual uncertainty.

Sub-modules (7)

Accountability And DpiaGreen

Articles 22 and 23 of the revFADP mandate federal bodies and private persons to conduct a Data Protection Impact Assessment where data processing poses high risks to personality or fundamental rights; the FDPIC has published a factsheet with templates and flowcharts.

Claims (1):

  • Articles 22 and 23 of the revFADP mandate federal bodies and private individuals to conduct a Data Protection Impact Assessment if data processing poses high risks to personality or fundamental rights.

Dpo RequirementsAmber

No universal mandatory DPO-appointment threshold analogous to GDPR member-state gold-plating was confirmed; the FDPIC operates a reporting portal for DPOs, suggesting appointment is encouraged/registrable rather than confirmed as strictly mandatory across all controllers in the sources reviewed.

Claims (1):

  • The FDPIC operates a dedicated reporting portal for data protection officers, but a universally mandatory DPO-appointment threshold was not confirmed in the sources reviewed for this run.

Ropa RequirementsGreen

Controllers, including the Swiss representative for foreign controllers, are required to maintain records of processing activities and provide them to the FDPIC upon request.

Claims (1):

  • The Swiss representative appointed by a non-Swiss controller is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC upon request.

Joint Controller ArrangementsRed

No source reviewed specified a distinct statutory joint-controller regime analogous to GDPR Art 26.

Absence provenance: unavailable. Searched: FADP joint controller arrangement Article, revFADP joint controllership.

Security MeasuresGreen

Article 7 of the FADP requires that personal data be protected against unauthorised processing through adequate technical and organisational measures.

Claims (1):

  • Article 7 of the FADP requires that personal data be protected against unauthorised processing through adequate technical and organisational measures.

Breach NotificationAmber

The revFADP introduces an obligation to notify the FDPIC of a data breach as soon as possible where it is likely to result in high risk to the data subject's personality or fundamental rights; no fixed numerical deadline equivalent to the GDPR's 72 hours was confirmed as of the guidance reviewed.

Claims (1):

  • Controllers are obliged to inform the FDPIC of a data breach as soon as possible when it is likely to result in a high risk to the data subject's personality or fundamental rights, with no confirmed fixed statutory time limit equivalent to the GDPR's 72 hours.

Retention And DisposalGreen

Article 6(4) of the revised FADP clarifies that data must either be deleted or anonymised once the purpose for its collection has been achieved.

Claims (1):

  • Article 6(4) of the revised FADP requires that all personal data be either deleted or anonymised once the purpose for its collection has been achieved.
Category narrative96 words

The revFADP introduces mandatory DPIAs for high-risk processing (Arts 22-23), strengthened security-of-processing obligations (Art 7 FADP baseline), an explicit purpose-limitation-driven retention/disposal duty (Art 6(4)), and a new breach-notification obligation owed to the FDPIC 'as soon as possible' where a breach is likely to result in high risk, though no fixed numerical deadline (unlike the GDPR's 72 hours) was confirmed. Records-of-processing obligations attach to controllers (and, for foreign controllers, their Swiss representative). DPO appointment does not appear to carry a universal mandatory threshold as under some GDPR member-state laws; the FDPIC operates a voluntary DPO reporting portal.

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidance — Articles 22 and 23 of the revFADP mandate federal bodies and private individuals to conduct a Data Protection Impact Assessment if data processing poses high risks to personality or fundamental rights.observed
  2. UncertainOneTrust DataGuidance — The FDPIC operates a dedicated reporting portal for data protection officers, but a universally mandatory DPO-appointment threshold was not confirmed in the sources reviewed for this run.observed
  3. ProbableInternational Association of Privacy Professionals — The Swiss representative appointed by a non-Swiss controller is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC upon request.observed
  4. ProbableOneTrust DataGuidance — Article 7 of the FADP requires that personal data be protected against unauthorised processing through adequate technical and organisational measures.observed
  5. ProbableInternational Association of Privacy Professionals — Controllers are obliged to inform the FDPIC of a data breach as soon as possible when it is likely to result in a high risk to the data subject's personality or fundamental rights, with no confirmed fixed statutory time limit equivalent to the GDPR's 72 hours.observed
  6. ProbableOneTrust DataGuidance — Article 6(4) of the revised FADP requires that all personal data be either deleted or anonymised once the purpose for its collection has been achieved.observed

#

Robust bidirectional adequacy status (EU since 2000; UK full adequacy) plus a GDPR-mirroring transfer-mechanism toolkit.

Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 16-17; EU Commission Decision 2000/518/EC
Traffic-light rationale — GreenRobust bidirectional adequacy status (EU since 2000; UK full adequacy) plus a GDPR-mirroring transfer-mechanism toolkit.

Sub-modules (6)

Transfer MechanismsGreen

Available mechanisms include adequacy, SCCs and BCRs under Art 16 revFADP, and derogations under Art 17 (consent, contract necessity, overriding public interest, public availability of data).

Claims (1):

  • Cross-border transfers from Switzerland may rely on adequacy, Standard Contractual Clauses or Binding Corporate Rules under Article 16 of the revised FADP, or derogations under Article 17 including consent, contractual necessity, overriding public interest, or public availability of the data.

Adequacy ReceivedGreen

Switzerland has held an EU adequacy decision since 2000 (Commission Decision 2000/518/EC) and is listed by the UK government as a 'full adequacy' jurisdiction for restricted transfers.

Claims (2):

  • Switzerland is considered by the European Commission as providing an adequate level of data protection, per Commission Decision 2000/518/EC of 26 July 2000, and remains on the Commission's current list of adequate countries.
  • The UK government's adequacy regulations list Switzerland among the jurisdictions with 'full adequacy' for restricted transfers under UK GDPR.

Adequacy GrantedGreen

The FDPIC maintains its own list of third countries considered to provide adequate protection for outbound Swiss data transfers.

Claims (1):

  • The FDPIC establishes and maintains its own list of third countries considered to provide an adequate level of protection for personal data transferred from Switzerland.

Sccs And BcrsAmber

The FDPIC has issued and periodically updated guidance/templates on Standard Contractual Clauses for use by Swiss controllers.

Claims (1):

  • The FDPIC has updated its guidelines/templates concerning Standard Contractual Clauses available for use by Swiss data exporters.

Transfer Impact AssessmentRed

No FDPIC-specific formal Transfer Impact Assessment obligation equivalent to post-Schrems II EU practice was confirmed in this research pass, though FDPIC guidance on third-country transfers exists generally.

Absence provenance: unavailable. Searched: FDPIC transfer impact assessment guidance third country.

Data LocalisationRed

No general private-sector data-localisation mandate was confirmed for Switzerland in this research pass.

Absence provenance: unavailable. Searched: Switzerland data localisation requirement FADP, Swiss data residency mandate.

Category narrative81 words

Switzerland offers multiple cross-border transfer mechanisms mirroring the GDPR: adequacy (its own FDPIC-maintained country list plus reliance on the general adequacy concept), Standard Contractual Clauses and Binding Corporate Rules under Art 16 revFADP, and derogations under Art 17 (consent, contractual necessity, overriding public interest, public availability). Switzerland itself has held an EU adequacy decision since 2000 (2000/518/EC) and is listed by the UK as a 'full adequacy' jurisdiction. Data-localisation mandates in the private sector were not confirmed in this research pass.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ProbableOneTrust DataGuidance — Cross-border transfers from Switzerland may rely on adequacy, Standard Contractual Clauses or Binding Corporate Rules under Article 16 of the revised FADP, or derogations under Article 17 including consent, contractual necessity, overriding public interest, or public availability of the data.observed
  2. ConfirmedEUR-Lex / Official Journal of the European Union — Switzerland is considered by the European Commission as providing an adequate level of data protection, per Commission Decision 2000/518/EC of 26 July 2000, and remains on the Commission's current list of adequate countries.observed
  3. ConfirmedICO — The UK government's adequacy regulations list Switzerland among the jurisdictions with 'full adequacy' for restricted transfers under UK GDPR.observed
  4. ProbableOneTrust DataGuidance — The FDPIC establishes and maintains its own list of third countries considered to provide an adequate level of protection for personal data transferred from Switzerland.observed
  5. UncertainOneTrust DataGuidance — The FDPIC has updated its guidelines/templates concerning Standard Contractual Clauses available for use by Swiss data exporters.observed

#

Confirmed financial-sector and employment overlays; several other sectoral sub-modules carry no confirmed findings.

Primary frameworkFADP baseline plus FINMA Ordinance on Data Processing; Code of Obligations (employment)
Traffic-light rationale — AmberConfirmed financial-sector and employment overlays; several other sectoral sub-modules carry no confirmed findings.

Sub-modules (7)

Financial Sector OverlayAmber

FINMA maintains a Data Processing Ordinance that has been amended over time and applies additional sector rules to supervised financial institutions, layered on top of the general FADP baseline.

Claims (1):

  • FINMA maintains and has amended an Ordinance on Data Processing applicable to supervised financial institutions, operating alongside the general FADP regime.

Health Sector OverlayRed

No health-sector-specific data protection overlay was confirmed in this research pass beyond the general FADP baseline.

Absence provenance: unavailable. Searched: Switzerland health data protection sectoral law FADP.

Telecoms And EprivacyRed

No specific e-privacy/telecoms overlay content was confirmed in this research pass, though the general Telecommunications Act framework was referenced tangentially.

Absence provenance: unavailable. Searched: Switzerland telecommunications act eprivacy cookie law.

Employment DataGreen

The Federal Code of Obligations contains restrictions on the processing of employee data by employers, supplementing the general FADP.

Claims (1):

  • The Federal Code of Obligations contains restrictions on the processing of employee data, supplementing the general FADP framework.

Credit And ScoringRed

No dedicated Swiss credit-scoring regulatory overlay was confirmed in this research pass.

Absence provenance: unavailable. Searched: Switzerland credit scoring data protection regulation.

EducationRed

No education-sector-specific data protection overlay was confirmed in this research pass.

Absence provenance: unavailable. Searched: Switzerland education sector data protection FADP.

InsuranceRed

No insurance-sector-specific data protection overlay was confirmed in this research pass.

Absence provenance: unavailable. Searched: Switzerland insurance sector data protection FADP FINMA.

Category narrative58 words

Switzerland lacks dedicated omnibus sectoral data-protection statutes, but sector-specific instruments layer additional obligations onto the FADP baseline: FINMA maintains an ordinance on data processing applicable to supervised financial institutions, and the Federal Code of Obligations restricts employer processing of employee data. Health, telecoms/e-privacy, credit-scoring, education and insurance-specific overlays were not confirmed with sufficient specificity in this research pass.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. UncertainOneTrust DataGuidance — FINMA maintains and has amended an Ordinance on Data Processing applicable to supervised financial institutions, operating alongside the general FADP regime.observed
  2. ProbableOneTrust DataGuidance — The Federal Code of Obligations contains restrictions on the processing of employee data, supplementing the general FADP framework.observed

#

Active FDPIC cookie/consent enforcement interest confirmed at title level; several adtech sub-modules lack confirmed Swiss-specific rules.

Primary frameworkFADP (general) plus FDPIC guidance on cookies/trackers
Traffic-light rationale — AmberActive FDPIC cookie/consent enforcement interest confirmed at title level; several adtech sub-modules lack confirmed Swiss-specific rules.

Sub-modules (6)

Cookies And TrackersAmber

The FDPIC has published cookie guidelines addressing tracker consent practices for Swiss-facing digital services.

Claims (1):

  • The FDPIC has published guidelines addressing the use of cookies and trackers, including English-language versions of that guidance.

Dark PatternsAmber

The FDPIC issued an enforcement notice to Digitec Galaxus concerning its cookie-consent interface, and the retailer subsequently implemented a one-click cookie opt-out mechanism.

Claims (1):

  • The FDPIC issued an enforcement notice concerning Digitec Galaxus's cookie-consent practices, after which the retailer implemented a one-click cookie opt-out mechanism.

Opt Out SignalsRed

No Swiss-specific recognition of browser-based opt-out signals (e.g., Global Privacy Control) was confirmed in this research pass.

Absence provenance: unavailable. Searched: Switzerland Global Privacy Control opt-out signal FADP.

Clean Rooms And DcrRed

No Swiss-specific data clean-room / data-collaboration-room regulatory content was confirmed.

Absence provenance: unavailable. Searched: Switzerland data clean room regulation FADP.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context advertising concept exists under the FADP baseline; no confirmed Swiss equivalent was located.

Absence provenance: unavailable. Searched: Switzerland cross-context advertising data sharing rules.

Direct MarketingGreen

Postal direct marketing is permitted on an opt-out basis where the recipient's address has been made publicly available and no objection has been registered.

Claims (1):

  • Postal marketing in Switzerland operates on an opt-out mechanism; use of a recipient's publicly available postal address for marketing purposes is permitted absent objection.
Category narrative73 words

The FDPIC has issued cookie guidelines and has taken direct enforcement interest in dark-pattern-style consent practices, including an enforcement notice to a major Swiss e-commerce retailer (Digitec Galaxus) that was followed by the company's implementation of a one-click cookie opt-out. Direct-marketing rules permit postal marketing on an opt-out basis where the recipient's address is publicly available. Opt-out signal standards (e.g., GPC), clean-room/data-collaboration rules, and cross-context-advertising-specific rules were not confirmed in this research pass.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — The FDPIC has published guidelines addressing the use of cookies and trackers, including English-language versions of that guidance.observed
  2. UncertainOneTrust DataGuidance — The FDPIC issued an enforcement notice concerning Digitec Galaxus's cookie-consent practices, after which the retailer implemented a one-click cookie opt-out mechanism.observed
  3. ProbableOneTrust DataGuidance — Postal marketing in Switzerland operates on an opt-out mechanism; use of a recipient's publicly available postal address for marketing purposes is permitted absent objection.observed

#

Biometric/genetic categorisation and FDPIC AI engagement are confirmed; the profiling/ADM regime is structurally narrower than the GDPR and carries residual ambiguity.

Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 2(2)(c), 21, 31
Traffic-light rationale — AmberBiometric/genetic categorisation and FDPIC AI engagement are confirmed; the profiling/ADM regime is structurally narrower than the GDPR and carries residual ambiguity.

Sub-modules (6)

Profiling RestrictionsAmber

A right equivalent to GDPR Article 21 does not exist per se; Swiss law instead provides a narrower opt-out-style objection right under Art 31(2)(b) revFADP.

Claims (1):

  • A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; Article 31(2)(b) of the revised FADP instead provides a data subject right to object, essentially limited to an opt-out right.

Automated Decision Making TransparencyAmber

Article 21 of the revFADP imposes information duties on controllers in respect of automated individual decision-making, with willful provision of false information in that context subject to criminal sanction.

Claims (1):

  • Article 21 of the revFADP concerns automated individual decision-making, and willful provision of false or incomplete information in that context is subject to criminal penalty under Article 60.

Ai Risk AssessmentsAmber

The FDPIC has issued a press release addressing the intersection of artificial intelligence and data protection, indicating active regulatory attention though no confirmed dedicated Swiss AI-specific statutory risk-assessment regime.

Claims (1):

  • The FDPIC has issued a press release specifically addressing artificial intelligence and data protection.

Biometric RegimeAmber

The FDPIC issued a decision addressing PostFinance's use of voice-recognition (biometric) technology, reflecting active enforcement engagement with biometric processing; biometric data is also now expressly a sensitive-data category under the revFADP.

Claims (1):

  • The FDPIC issued a decision concerning PostFinance's use of voice-recognition biometric technology.

Genetic DataGreen

Genetic data was brought within the FADP's sensitive personal data category as part of the FADP revision.

Claims (1):

  • Genetic data was brought within the FADP's sensitive personal data category as part of the revision process leading to the revFADP.

State Surveillance CarveoutsAmber

Article 2(2)(c) of the FADP provides that the Act may not apply to processing of personal data within the frame of administrative, civil or criminal proceedings once pending, though the requirements of the FADP still apply to investigations carried out by police prior to such proceedings becoming pending.

Claims (1):

  • Article 2(2)(c) of the FADP provides that the Act may not apply to processing of personal data in the frame of administrative, civil, or criminal proceedings once pending, though FADP requirements still apply to police investigations carried out prior to such proceedings becoming pending.
Category narrative104 words

The revFADP does not replicate a general GDPR Article 21-style objection right but does impose information duties on controllers regarding automated individual decision-making (Art 21 revFADP information obligations, distinct numbering from the GDPR). Biometric and genetic data were brought within the sensitive-data category by the revision, and the FDPIC has demonstrated active enforcement interest in biometric processing (e.g., a decision concerning PostFinance's voice-recognition system) and has issued a press release specifically addressing AI and data protection. State-surveillance carve-outs exist via Art 2(2)(c) FADP, which disapplies the Act to processing within pending administrative, civil, or criminal proceedings (though pre-proceeding police investigatory processing remains in scope).

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ProbableOneTrust DataGuidance — A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; Article 31(2)(b) of the revised FADP instead provides a data subject right to object, essentially limited to an opt-out right.observed
  2. ProbableInternational Association of Privacy Professionals — Article 21 of the revFADP concerns automated individual decision-making, and willful provision of false or incomplete information in that context is subject to criminal penalty under Article 60.observed
  3. UncertainOneTrust DataGuidance — The FDPIC has issued a press release specifically addressing artificial intelligence and data protection.observed
  4. UncertainOneTrust DataGuidance — The FDPIC issued a decision concerning PostFinance's use of voice-recognition biometric technology.observed
  5. ProbableInternational Association of Privacy Professionals — Genetic data was brought within the FADP's sensitive personal data category as part of the revision process leading to the revFADP.observed
  6. ProbableOneTrust DataGuidance — Article 2(2)(c) of the FADP provides that the Act may not apply to processing of personal data in the frame of administrative, civil, or criminal proceedings once pending, though FADP requirements still apply to police investigations carried out prior to such proceedings becoming pending.observed

#

General legislative intent to protect minors is confirmed, but no specific operative mechanism (age threshold, parental consent procedure, profiling ban) was substantiated by available sources.

Primary frameworkFederal Act on Data Protection (FADP), revised version (general provisions)
Traffic-light rationale — RedGeneral legislative intent to protect minors is confirmed, but no specific operative mechanism (age threshold, parental consent procedure, profiling ban) was substantiated by available sources.

Sub-modules (5)

Age VerificationRed

No specific statutory age-of-consent threshold for data processing under the FADP was confirmed in this research pass.

Absence provenance: unavailable. Searched: Swiss FADP minors children data protection special categories genetic biometric Article 5.

Minor Profiling BansRed

No minor-specific profiling ban was confirmed in this research pass.

Absence provenance: unavailable. Searched: Switzerland minor profiling ban FADP.

Education SettingsRed

No education-setting-specific children's-data rules were confirmed in this research pass.

Absence provenance: unavailable. Searched: Switzerland education data protection children FADP.

Dependent AdultsRed

No dependent-adult-specific data protection provisions were confirmed in this research pass.

Absence provenance: unavailable. Searched: Switzerland dependent adults elderly data protection FADP.

Category narrative53 words

The revFADP's legislative history explicitly cites the protection of minors as one of the European-standard alignment goals of the revision. However, specific mechanisms — an age-of-consent threshold for data processing, statutory parental-consent procedures, minor-specific profiling bans, education-setting rules, and dependent-adult protections — were not confirmed with the specificity available in this research pass.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ProbableOneTrust DataGuidance — The revFADP's revision was explicitly framed as seeking to include provisions complying with European standards on, among other things, the protection of minors.observed

#

Strengthened FDPIC investigative/order powers and an active enforcement docket are confirmed; the no-administrative-fine model and gaps in collective-redress and funding/capacity data warrant amber rather than green.

Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 49-51, 60-63
Traffic-light rationale — AmberStrengthened FDPIC investigative/order powers and an active enforcement docket are confirmed; the no-administrative-fine model and gaps in collective-redress and funding/capacity data warrant amber rather than green.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The FDPIC may open investigations ex officio or following complaint and issue binding orders, but is not authorised to impose administrative fines on organisations; instead, individuals may be fined up to CHF 250,000 for a limited set of enumerated criminal offences under the revFADP.

Claims (2):

  • Under the revised FADP, the FDPIC's position is strengthened such that it will be able to open an investigation, ex officio or following a complaint, against a controller and processor, and to issue an order at the end of the investigation.
  • Unlike most European data protection supervisory authorities, the FDPIC is not authorised to impose administrative sanctions directly on organisations; individuals may instead be fined up to CHF 250,000 for a limited range of enumerated criminal offences under Article 63 and related provisions of the revFADP.

Enforcement Activity IndexAmber

Recent FDPIC enforcement activity includes an enforcement notice to Digitec Galaxus, a decision on PostFinance's biometric voice recognition, an investigation into BLT's bodycam use, and Administrative Court confirmation of an FDPIC processing ban.

Claims (1):

  • Recent FDPIC enforcement matters include an enforcement notice issued to Digitec Galaxus, a decision concerning PostFinance's voice-recognition system, an investigation opened into BLT's bodycam use, and an Administrative Court ruling confirming an FDPIC processing ban.

Regulator Funding And CapacityRed

No specific FDPIC headcount or budget figures were confirmed in this research pass.

Absence provenance: unavailable. Searched: FDPIC budget headcount staffing capacity.

Collective Redress And Class ActionsRed

No dedicated collective-redress or class-action mechanism for data protection claims was confirmed for Switzerland in this research pass.

Absence provenance: unavailable. Searched: Switzerland collective redress class action data protection.

Private Right Of ActionAmber

Data subjects may pursue civil claims for breach of personality rights under the Swiss Civil Code, which operates alongside the FADP as a governing text for data subject rights enforcement.

Claims (1):

  • The Swiss Civil Code is listed as a governing text alongside the FADP and its Ordinance for data subject rights matters, providing a civil personality-rights avenue for redress.

Recent Developments 180DAmber

Within the last 180 days, reported FDPIC activity includes Digitec Galaxus's implementation of a one-click cookie opt-out (reported mid-February 2026) and the opening of an FDPIC investigation into BLT's use of bodycams (reported late February 2026).

Claims (1):

  • Digitec Galaxus implemented a one-click cookie opt-out mechanism, as reported by the FDPIC in mid-February 2026, following prior enforcement engagement.
Category narrative163 words

The FDPIC can open investigations ex officio or on complaint against controllers and processors and, since the revFADP, may issue binding orders at the conclusion of an investigation — a marked strengthening from its prior merely-recommendatory role. Unlike most European DPAs, the FDPIC is not authorised to impose administrative fines directly on organisations; instead, the revFADP creates criminal offences punishable by fines of up to CHF 250,000 against responsible individuals (not the entity) for a limited, enumerated set of violations. Recent enforcement activity includes an enforcement notice to Digitec Galaxus over cookie-consent practices (with subsequent remediation), a decision concerning PostFinance's biometric voice-recognition system, an investigation opened into BLT's use of bodycams, and Administrative Court confirmation of an FDPIC processing ban — though full text of these matters was paywalled and not independently verified beyond title level. Data subjects may also pursue civil claims for breach of personality rights under the Swiss Civil Code. No dedicated collective-redress/class-action mechanism for data protection claims was confirmed.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidance — Under the revised FADP, the FDPIC's position is strengthened such that it will be able to open an investigation, ex officio or following a complaint, against a controller and processor, and to issue an order at the end of the investigation.observed
  2. ConfirmedOneTrust DataGuidance — Unlike most European data protection supervisory authorities, the FDPIC is not authorised to impose administrative sanctions directly on organisations; individuals may instead be fined up to CHF 250,000 for a limited range of enumerated criminal offences under Article 63 and related provisions of the revFADP.observed
  3. UncertainOneTrust DataGuidance — Recent FDPIC enforcement matters include an enforcement notice issued to Digitec Galaxus, a decision concerning PostFinance's voice-recognition system, an investigation opened into BLT's bodycam use, and an Administrative Court ruling confirming an FDPIC processing ban.observed
  4. ProbableOneTrust DataGuidance — The Swiss Civil Code is listed as a governing text alongside the FADP and its Ordinance for data subject rights matters, providing a civil personality-rights avenue for redress.observed
  5. UncertainOneTrust DataGuidance — Digitec Galaxus implemented a one-click cookie opt-out mechanism, as reported by the FDPIC in mid-February 2026, following prior enforcement engagement.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct21.74
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Switzerland
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 41 claim(s) (41 category placement(s)), 29 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressprivate right of action
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, and cross_border_and_adequacy modules rest on a mix of T1 (FDPIC homepage, EUR-Lex adequacy decision, EDPB, ICO adequacy list) and T2 (IAPP) sources with good coverage. sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress rely more heavily on T3 secondary reporting (OneTrust DataGuidance), several of which returned only paywalled title-level content rather than full substantive text; those claims are flagged Uncertain with absent_field_provenance. children_and_vulnerable_groups and several sectoral_watch sub-modules (health, telecoms/eprivacy, credit, education, insurance) had no confirmed findings and are carried as explicit gaps (traffic_light=red, empty claims[], absent_field_provenance).

Unresolved questions (7):

  • Precise statutory response-time window for Swiss data subject access/rectification requests (analogous to GDPR's one-month period) was not confirmed.
  • Whether Switzerland's DPO-appointment regime carries a mandatory threshold (as opposed to voluntary/registrable practice via the FDPIC portal).
  • Full substantive content of several 2025-2026 FDPIC enforcement matters (Digitec Galaxus, PostFinance, BLT bodycams, Administrative Court ruling) — search results returned only paywalled title-level metadata.
  • Existence and scope of any formal Swiss Transfer Impact Assessment obligation post-Schrems II.
  • Sector-specific health, telecoms/eprivacy, credit-scoring, education, and insurance overlays beyond the general FADP baseline.
  • Whether any Swiss collective-redress or class-action mechanism applies to data protection claims.
  • Specific age-of-consent threshold and parental-consent mechanism for minors' data processing.

Escalate to primary-source review: yes