CHschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC
Last updated · 10 categories · 41
claims · 29 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
41Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Standing brief, as of 28 September 2026.
Lead Signal
Switzerland's revised Federal Act on Data Protection (revFADP) entered into force on 1 September 2023, and the Federal Data Protection and Information Commissioner (FDPIC) is understood to operate as the sole federal supervisory authority responsible for enforcing it. This cycle establishes the first full Data Protection Monitor baseline for Switzerland, drawing on structured claims spanning all ten modules of the framework. The most material development is not new legislative activity but a correction to the analytical record itself: a systemic review found that six foundational claims about the Swiss regime — including the FDPIC's supervisory role, the revFADP's entry into force, and its extended territorial scope — had been assigned an assertive confidence level on the strength of a single secondary source each, and confidence in each has been revised downward to a more qualified register. A related research gap has also been resolved: corroborating practitioner sources indicate that private-sector appointment of what Swiss law terms a data protection advisor remains voluntary under Article 10 FADP, while federal bodies are understood to be legally required to appoint a data protection officer under Article 25 of the Data Protection Ordinance. Read together, these two corrections mean the baseline Swiss claim-set entering this cycle's downstream state is materially more conservative and more precisely sourced than the raw research pass first produced it.
Other Developments
Beyond the confidence-tier correction, the revFADP baseline itself carries several structurally significant features. The law is understood to extend Switzerland's territorial scope to processing that has an effect in Switzerland even where it is initiated abroad, and non-Swiss controllers meeting that threshold are understood to be required to designate and publish a Swiss representative responsible for maintaining records of processing activities and producing them to the FDPIC on request. Articles 22-23 of the revFADP are understood to mandate a Data Protection Impact Assessment for high-risk processing by both federal bodies and private persons. On lawful processing, Swiss law is understood not to treat the absence of a specified legal basis as per se unlawful, with unlawfulness instead assessed against breach of personality rights; Article 17 of the revFADP is understood to permit cross-border transfer legitimacy via consent, contractual necessity, overriding public interest, or public availability of the data, and the revFADP is understood to have extended the definition of sensitive personal data to include genetic and biometric data while retaining a risk-based rather than explicit-consent-centric approach. On data subject rights, Article 25 of the revFADP is understood to provide a more detailed access right than the prior 1992 law's single-sentence entitlement, the revised law explicitly states a right to erasure alongside rectification rights under Article 32, and it is understood to introduce a new right to data portability modelled on the GDPR — alongside a narrower objection right than GDPR Article 21, via an opt-out-style mechanism under Article 31(2)(b). On cross-border transfers, Switzerland's adequacy position with the European Union — recognised under Commission Decision 2000/518/EC of 26 July 2000 — is understood to remain current, and UK government adequacy regulations are reported to list Switzerland as holding full adequacy status for restricted transfers under the UK GDPR. On the enforcement side, the FDPIC is understood to have gained the authority to open investigations on its own initiative or on complaint and issue binding orders at the conclusion of an investigation, a marked strengthening from its previously recommendatory-only role; reports attribute to the FDPIC a recent enforcement notice against retailer Digitec Galaxus over cookie-consent practices, followed by the retailer's reported implementation of a one-click cookie opt-out, though the substance of that matter and of related items involving PostFinance's voice-recognition technology rests on paywalled title-level sourcing that has not been independently verified. The FDPIC is not understood to hold a general power to impose administrative sanctions directly on organisations; individual criminal fines of up to CHF 250,000 apply only to a limited set of enumerated offences under Article 63 of the revFADP.
Cross-Monitor Connections
Three items in this cycle's Swiss claim-set intersect with adjacent monitors and are flagged for tracking there rather than analysed further here. Reports attribute to Switzerland's financial regulator, FINMA, maintenance and amendment of an Ordinance on Data Processing applicable to supervised financial institutions, a development relevant to financial-integrity's financial-sector compliance surface. Switzerland's cross-border transfer mechanisms — adequacy, standard contractual clauses, binding corporate rules, and statutory derogations — intersect with payments-data flows between Switzerland and the EU/UK and are flagged for world-payments. And reports attribute to the FDPIC a press release addressing artificial intelligence and data protection, alongside the revFADP's automated-decision-making transparency duties under Article 21; the AI-Act-adjacent governance angle is flagged for the artificial-intelligence monitor, with the data-protection-specific profiling and transparency angle retained here.
Outlook
The Swiss baseline established this cycle is assessed as a comprehensively in-force, GDPR-adjacent omnibus regime that nonetheless retains materially distinct architecture — including a personality-rights-based lawfulness test rather than a GDPR Article 6-style legal-basis requirement, and an FDPIC that lacks general administrative fining power over organisations — and should not be read as a GDPR-equivalent regime for compliance purposes. Enforcement activity is assessed as trending upward in operational terms even as the underlying statutory toolkit remains structurally narrower than EU or UK peer regulators'. The clearest gaps carried forward concern sectoral overlays beyond the general FADP baseline — health, telecoms, credit-scoring, education and insurance-specific rules were not confirmed this cycle — and children- and vulnerable-groups protections, where no specific operative mechanism such as an age threshold or parental-consent rule was confirmed beyond a general legislative intent to align with European standards. These gaps are carried forward as research priorities for the next cycle rather than treated as settled absences.
trust tier: ai_unverified
Standing brief, as of 28 September 2026.
Regulatory Status
Switzerland's data protection regime is anchored in the revised Federal Act on Data Protection, which entered into force on 1 September 2023 and is enforced by the Federal Data Protection and Information Commissioner (FDPIC) as sole federal supervisory authority. The regime is assessed as comprehensively in force and functionally GDPR-adjacent, while retaining materially distinct architecture: a personality-rights-based lawfulness test rather than a GDPR Article 6-style legal-basis requirement, and an FDPIC that lacks general administrative fining power over organisations, with individual criminal fines of up to CHF 250,000 reserved for a limited set of enumerated offences. Switzerland holds dual adequacy status, recognised by the European Commission under Commission Decision 2000/518/EC since 26 July 2000 and by the UK government under its post-Brexit adequacy regulations. The FDPIC's enforcement posture has strengthened structurally through binding-order authority introduced by the revFADP, and its operational activity is showing an uptick, including matters involving Digitec Galaxus's cookie-consent practices, PostFinance's voice-recognition technology, and an investigation into bodycam use by transport operator BLT.
Outlook
Switzerland's overall regulatory risk posture is assessed as moderate, with a trajectory of stability accompanied by incremental clarification rather than material legislative change this cycle. Confirmed gaps remain in sectoral overlays beyond the general FADP baseline, in operative child- and vulnerable-groups protections, and in independent verification of several 2025-2026 enforcement matters that currently rest on paywalled title-level sourcing; these gaps are treated as genuine research priorities for subsequent cycles rather than as settled absences.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Traffic-light rationale — GreenA comprehensive, currently-in-force omnibus statute with an active, empowered supervisory authority; GDPR-aligned but not identical.
Sub-modules (5)
Regulator And AuthorityGreen
The FDPIC is the federal supervisory authority; cantons additionally maintain their own commissioners for cantonal/communal bodies, creating a partially federated oversight structure alongside the federal regime.
Claims (1):
The Federal Data Protection and Information Commissioner (FDPIC) is the federal data protection authority responsible for supervising the FADP.
Act And InstrumentsGreen
The revFADP and its Ordinance constitute the primary instruments, in force since 1 September 2023, replacing the 1992 FADP and bringing Swiss law closer to GDPR standards.
Claims (1):
The revised Swiss Federal Act on Data Protection came into force on 1 September 2023, bringing Switzerland's data protection regime into closer alignment with the EU GDPR.
Material ScopeGreen
The FADP applies as an omnibus law to processing of personal data by private persons and federal bodies irrespective of sector; cantonal acts govern cantonal/communal bodies separately.
Claims (1):
The FADP is an omnibus law applying to any processing of personal data by private persons and federal bodies, irrespective of sector, while cantonal acts separately govern cantonal and communal bodies.
Territorial ScopeGreen
The revFADP's territorial scope was broadened, GDPR-style, to capture processing with an effect in Switzerland even if the processing activity is initiated from abroad.
Claims (1):
The revFADP applies to circumstances that have an effect in Switzerland even where the processing activity is initiated abroad, giving the FDPIC competence over any activity with Swiss impact regardless of origin.
Regulator Registration And FilingAmber
There is no general controller-registration/filing regime; instead, non-Swiss controllers meeting territorial-scope criteria must designate and publish a Swiss representative, who is responsible for maintaining the controller's records of processing and producing them to the FDPIC on request.
Claims (1):
Where the revFADP's extraterritorial scope applies, the controller must appoint and publicly identify a Swiss representative, who is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC on request.
Category narrative94 words
Switzerland's data protection regime is governed by the revised Federal Act on Data Protection (revFADP, FADP 2020), which entered into force on 1 September 2023 alongside its implementing Ordinance, replacing the 1992 FADP. The regime is enforced by the Federal Data Protection and Information Commissioner (FDPIC/EDÖB), an independent federal authority. The revFADP brings Switzerland into closer alignment with the GDPR while retaining distinctly Swiss features (e.g., no general administrative fining power for the FDPIC, personality-rights-based unlawfulness test). Territorial scope was significantly broadened to reach processing with an effect in Switzerland even where initiated abroad.
no periodic updates on record for this sub-brief
Sources and claims (5)
ConfirmedOneTrust DataGuidance — The Federal Data Protection and Information Commissioner (FDPIC) is the federal data protection authority responsible for supervising the FADP.observed
ConfirmedInternational Association of Privacy Professionals — The revised Swiss Federal Act on Data Protection came into force on 1 September 2023, bringing Switzerland's data protection regime into closer alignment with the EU GDPR.observed
ConfirmedInternational Association of Privacy Professionals — The revFADP applies to circumstances that have an effect in Switzerland even where the processing activity is initiated abroad, giving the FDPIC competence over any activity with Swiss impact regardless of origin.observed
ProbableInternational Association of Privacy Professionals — Where the revFADP's extraterritorial scope applies, the controller must appoint and publicly identify a Swiss representative, who is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC on request.observed
ProbableOneTrust DataGuidance — The FADP is an omnibus law applying to any processing of personal data by private persons and federal bodies, irrespective of sector, while cantonal acts separately govern cantonal and communal bodies.observed
Traffic-light rationale — AmberStructurally different from GDPR's Art 6 lawful-basis model; sensitive-data protections exist but the consent architecture is comparatively lighter.
Sub-modules (4)
Lawful BasesAmber
Swiss law does not treat the absence of a specified legal basis as per se unlawful; unlawfulness is instead assessed against breach of personality rights.
Claims (1):
Unlike the EU GDPR, Swiss law does not provide that processing of personal data without a specified legal basis is per se illegitimate; legitimacy instead turns on absence of a breach of personality rights.
Consent ThresholdsGreen
Consent is one of several grounds (alongside contractual necessity, overriding public interest, and public availability of the data) that can legitimize a cross-border transfer under Art 17 revFADP.
Claims (1):
Under Article 17 of the revised FADP, a cross-border data transfer may be legitimate where the data subject has consented, in addition to contractual necessity, overriding public interest, or the data having been made publicly accessible by the subject.
Special CategoriesGreen
The revFADP extended the definition of sensitive personal data to explicitly include genetic and biometric data, while retaining a risk-based rather than explicit-consent-centric approach.
Claims (1):
The FADP's definition of sensitive personal data was extended in the revision process to cover biometric and genetic data, while maintaining a risk-based approach rather than the EU's explicit-consent concept for such data.
Pseudonymisation And AnonymisationAmber
Anonymised or aggregated data falls outside the FADP's personal-data scope because the person is no longer identifiable; pseudonymised data, by contrast, may still permit re-identification and generally remains in scope.
Claims (1):
Anonymised or aggregated data is not personal data under the FADP because the person is not identifiable, whereas pseudonymised data may still permit re-identification and is generally treated as personal data.
Category narrative80 words
Unlike the GDPR's positive lawful-basis requirement, Swiss law does not require a specified legal basis for processing to be lawful per se; processing is only unlawful if it breaches personality rights under the Civil Code/FADP principles. The revFADP nonetheless expanded the definition of sensitive personal data to include genetic and biometric data and retains a risk-based (rather than explicit-consent-centric) approach to sensitive data. Consent functions primarily as a derogation basis for cross-border transfer and is not a universal processing gateway.
no periodic updates on record for this sub-brief
Sources and claims (4)
ProbableOneTrust DataGuidance — Unlike the EU GDPR, Swiss law does not provide that processing of personal data without a specified legal basis is per se illegitimate; legitimacy instead turns on absence of a breach of personality rights.observed
ProbableOneTrust DataGuidance — Under Article 17 of the revised FADP, a cross-border data transfer may be legitimate where the data subject has consented, in addition to contractual necessity, overriding public interest, or the data having been made publicly accessible by the subject.observed
ProbableInternational Association of Privacy Professionals — The FADP's definition of sensitive personal data was extended in the revision process to cover biometric and genetic data, while maintaining a risk-based approach rather than the EU's explicit-consent concept for such data.observed
ProbableOneTrust DataGuidance — Anonymised or aggregated data is not personal data under the FADP because the person is not identifiable, whereas pseudonymised data may still permit re-identification and is generally treated as personal data.observed
Traffic-light rationale — AmberCore rights are present and GDPR-inspired, but the objection right is narrower and exact response-window detail is unconfirmed.
Sub-modules (5)
Access RightGreen
Article 25 of the revFADP provides a more detailed subject-access right than the prior law's single-sentence entitlement to know whether data is processed.
Claims (1):
Article 25 of the revised FADP provides a more detailed access right for data subjects than the prior 1992 FADP's general information-request entitlement.
Rectification And ErasureGreen
The revFADP explicitly states a right to erasure (previously only implicit) alongside rectification rights under Art 32.
Claims (1):
The revised FADP explicitly states a right to erasure, whereas the old FADP only implicitly recognised it, and introduces rectification rights under Article 32.
Restriction And ObjectionAmber
A right equivalent to GDPR Art 21 does not exist per se; Swiss law provides a narrower opt-out-style objection right under Art 31(2)(b) revFADP.
Claims (1):
A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; instead, Article 31(2)(b) of the revised FADP provides a data subject right to object to processing, essentially limited to an opt-out right.
Data PortabilityGreen
The right to data portability, copied from the GDPR, is entirely new to Swiss law under the revFADP.
Claims (1):
The right to data portability, copied from the GDPR, is completely new to Swiss law under the revised FADP.
Deadlines And Response WindowsRed
Available sources did not confirm a specific statutory response-time window (analogous to the GDPR's one-month period) for Swiss data subject requests.
Absence provenance: unavailable. Searched: FADP data subject access request deadline response window, revFADP Article 25 response time days.
Category narrative83 words
The revFADP substantially strengthens data subject rights compared to the 1992 law, introducing an explicit right to erasure and a wholly new right to data portability modelled on the GDPR, alongside a more detailed access right (Art 25) and rectification rights (Art 32). The objection right, however, remains narrower than GDPR Art 21 — Swiss law provides an opt-out-style objection right rather than a general right to object on grounds relating to particular circumstances. Statutory response-deadline specifics were not confirmed in available sources.
no periodic updates on record for this sub-brief
Sources and claims (4)
ProbableOneTrust DataGuidance — Article 25 of the revised FADP provides a more detailed access right for data subjects than the prior 1992 FADP's general information-request entitlement.observed
ConfirmedOneTrust DataGuidance — The revised FADP explicitly states a right to erasure, whereas the old FADP only implicitly recognised it, and introduces rectification rights under Article 32.observed
ProbableOneTrust DataGuidance — A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; instead, Article 31(2)(b) of the revised FADP provides a data subject right to object to processing, essentially limited to an opt-out right.observed
ConfirmedOneTrust DataGuidance — The right to data portability, copied from the GDPR, is completely new to Swiss law under the revised FADP.observed
Core accountability infrastructure (DPIA, security, retention, breach notification) is in force and GDPR-adjacent, but breach-notification timing and DPO-threshold specifics carry residual uncertainty.
Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 6-9, 22-24
Traffic-light rationale — AmberCore accountability infrastructure (DPIA, security, retention, breach notification) is in force and GDPR-adjacent, but breach-notification timing and DPO-threshold specifics carry residual uncertainty.
Sub-modules (7)
Accountability And DpiaGreen
Articles 22 and 23 of the revFADP mandate federal bodies and private persons to conduct a Data Protection Impact Assessment where data processing poses high risks to personality or fundamental rights; the FDPIC has published a factsheet with templates and flowcharts.
Claims (1):
Articles 22 and 23 of the revFADP mandate federal bodies and private individuals to conduct a Data Protection Impact Assessment if data processing poses high risks to personality or fundamental rights.
Dpo RequirementsAmber
No universal mandatory DPO-appointment threshold analogous to GDPR member-state gold-plating was confirmed; the FDPIC operates a reporting portal for DPOs, suggesting appointment is encouraged/registrable rather than confirmed as strictly mandatory across all controllers in the sources reviewed.
Claims (1):
The FDPIC operates a dedicated reporting portal for data protection officers, but a universally mandatory DPO-appointment threshold was not confirmed in the sources reviewed for this run.
Ropa RequirementsGreen
Controllers, including the Swiss representative for foreign controllers, are required to maintain records of processing activities and provide them to the FDPIC upon request.
Claims (1):
The Swiss representative appointed by a non-Swiss controller is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC upon request.
Joint Controller ArrangementsRed
No source reviewed specified a distinct statutory joint-controller regime analogous to GDPR Art 26.
Article 7 of the FADP requires that personal data be protected against unauthorised processing through adequate technical and organisational measures.
Claims (1):
Article 7 of the FADP requires that personal data be protected against unauthorised processing through adequate technical and organisational measures.
Breach NotificationAmber
The revFADP introduces an obligation to notify the FDPIC of a data breach as soon as possible where it is likely to result in high risk to the data subject's personality or fundamental rights; no fixed numerical deadline equivalent to the GDPR's 72 hours was confirmed as of the guidance reviewed.
Claims (1):
Controllers are obliged to inform the FDPIC of a data breach as soon as possible when it is likely to result in a high risk to the data subject's personality or fundamental rights, with no confirmed fixed statutory time limit equivalent to the GDPR's 72 hours.
Retention And DisposalGreen
Article 6(4) of the revised FADP clarifies that data must either be deleted or anonymised once the purpose for its collection has been achieved.
Claims (1):
Article 6(4) of the revised FADP requires that all personal data be either deleted or anonymised once the purpose for its collection has been achieved.
Category narrative96 words
The revFADP introduces mandatory DPIAs for high-risk processing (Arts 22-23), strengthened security-of-processing obligations (Art 7 FADP baseline), an explicit purpose-limitation-driven retention/disposal duty (Art 6(4)), and a new breach-notification obligation owed to the FDPIC 'as soon as possible' where a breach is likely to result in high risk, though no fixed numerical deadline (unlike the GDPR's 72 hours) was confirmed. Records-of-processing obligations attach to controllers (and, for foreign controllers, their Swiss representative). DPO appointment does not appear to carry a universal mandatory threshold as under some GDPR member-state laws; the FDPIC operates a voluntary DPO reporting portal.
no periodic updates on record for this sub-brief
Sources and claims (6)
ConfirmedOneTrust DataGuidance — Articles 22 and 23 of the revFADP mandate federal bodies and private individuals to conduct a Data Protection Impact Assessment if data processing poses high risks to personality or fundamental rights.observed
UncertainOneTrust DataGuidance — The FDPIC operates a dedicated reporting portal for data protection officers, but a universally mandatory DPO-appointment threshold was not confirmed in the sources reviewed for this run.observed
ProbableInternational Association of Privacy Professionals — The Swiss representative appointed by a non-Swiss controller is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC upon request.observed
ProbableOneTrust DataGuidance — Article 7 of the FADP requires that personal data be protected against unauthorised processing through adequate technical and organisational measures.observed
ProbableInternational Association of Privacy Professionals — Controllers are obliged to inform the FDPIC of a data breach as soon as possible when it is likely to result in a high risk to the data subject's personality or fundamental rights, with no confirmed fixed statutory time limit equivalent to the GDPR's 72 hours.observed
ProbableOneTrust DataGuidance — Article 6(4) of the revised FADP requires that all personal data be either deleted or anonymised once the purpose for its collection has been achieved.observed
Traffic-light rationale — GreenRobust bidirectional adequacy status (EU since 2000; UK full adequacy) plus a GDPR-mirroring transfer-mechanism toolkit.
Sub-modules (6)
Transfer MechanismsGreen
Available mechanisms include adequacy, SCCs and BCRs under Art 16 revFADP, and derogations under Art 17 (consent, contract necessity, overriding public interest, public availability of data).
Claims (1):
Cross-border transfers from Switzerland may rely on adequacy, Standard Contractual Clauses or Binding Corporate Rules under Article 16 of the revised FADP, or derogations under Article 17 including consent, contractual necessity, overriding public interest, or public availability of the data.
Adequacy ReceivedGreen
Switzerland has held an EU adequacy decision since 2000 (Commission Decision 2000/518/EC) and is listed by the UK government as a 'full adequacy' jurisdiction for restricted transfers.
Claims (2):
Switzerland is considered by the European Commission as providing an adequate level of data protection, per Commission Decision 2000/518/EC of 26 July 2000, and remains on the Commission's current list of adequate countries.
The UK government's adequacy regulations list Switzerland among the jurisdictions with 'full adequacy' for restricted transfers under UK GDPR.
Adequacy GrantedGreen
The FDPIC maintains its own list of third countries considered to provide adequate protection for outbound Swiss data transfers.
Claims (1):
The FDPIC establishes and maintains its own list of third countries considered to provide an adequate level of protection for personal data transferred from Switzerland.
Sccs And BcrsAmber
The FDPIC has issued and periodically updated guidance/templates on Standard Contractual Clauses for use by Swiss controllers.
Claims (1):
The FDPIC has updated its guidelines/templates concerning Standard Contractual Clauses available for use by Swiss data exporters.
Transfer Impact AssessmentRed
No FDPIC-specific formal Transfer Impact Assessment obligation equivalent to post-Schrems II EU practice was confirmed in this research pass, though FDPIC guidance on third-country transfers exists generally.
Absence provenance: unavailable. Searched: FDPIC transfer impact assessment guidance third country.
Data LocalisationRed
No general private-sector data-localisation mandate was confirmed for Switzerland in this research pass.
Absence provenance: unavailable. Searched: Switzerland data localisation requirement FADP, Swiss data residency mandate.
Category narrative81 words
Switzerland offers multiple cross-border transfer mechanisms mirroring the GDPR: adequacy (its own FDPIC-maintained country list plus reliance on the general adequacy concept), Standard Contractual Clauses and Binding Corporate Rules under Art 16 revFADP, and derogations under Art 17 (consent, contractual necessity, overriding public interest, public availability). Switzerland itself has held an EU adequacy decision since 2000 (2000/518/EC) and is listed by the UK as a 'full adequacy' jurisdiction. Data-localisation mandates in the private sector were not confirmed in this research pass.
no periodic updates on record for this sub-brief
Sources and claims (5)
ProbableOneTrust DataGuidance — Cross-border transfers from Switzerland may rely on adequacy, Standard Contractual Clauses or Binding Corporate Rules under Article 16 of the revised FADP, or derogations under Article 17 including consent, contractual necessity, overriding public interest, or public availability of the data.observed
ConfirmedEUR-Lex / Official Journal of the European Union — Switzerland is considered by the European Commission as providing an adequate level of data protection, per Commission Decision 2000/518/EC of 26 July 2000, and remains on the Commission's current list of adequate countries.observed
ConfirmedICO — The UK government's adequacy regulations list Switzerland among the jurisdictions with 'full adequacy' for restricted transfers under UK GDPR.observed
ProbableOneTrust DataGuidance — The FDPIC establishes and maintains its own list of third countries considered to provide an adequate level of protection for personal data transferred from Switzerland.observed
UncertainOneTrust DataGuidance — The FDPIC has updated its guidelines/templates concerning Standard Contractual Clauses available for use by Swiss data exporters.observed
Traffic-light rationale — AmberConfirmed financial-sector and employment overlays; several other sectoral sub-modules carry no confirmed findings.
Sub-modules (7)
Financial Sector OverlayAmber
FINMA maintains a Data Processing Ordinance that has been amended over time and applies additional sector rules to supervised financial institutions, layered on top of the general FADP baseline.
Claims (1):
FINMA maintains and has amended an Ordinance on Data Processing applicable to supervised financial institutions, operating alongside the general FADP regime.
Health Sector OverlayRed
No health-sector-specific data protection overlay was confirmed in this research pass beyond the general FADP baseline.
Absence provenance: unavailable. Searched: Switzerland health data protection sectoral law FADP.
Telecoms And EprivacyRed
No specific e-privacy/telecoms overlay content was confirmed in this research pass, though the general Telecommunications Act framework was referenced tangentially.
Switzerland lacks dedicated omnibus sectoral data-protection statutes, but sector-specific instruments layer additional obligations onto the FADP baseline: FINMA maintains an ordinance on data processing applicable to supervised financial institutions, and the Federal Code of Obligations restricts employer processing of employee data. Health, telecoms/e-privacy, credit-scoring, education and insurance-specific overlays were not confirmed with sufficient specificity in this research pass.
no periodic updates on record for this sub-brief
Sources and claims (2)
UncertainOneTrust DataGuidance — FINMA maintains and has amended an Ordinance on Data Processing applicable to supervised financial institutions, operating alongside the general FADP regime.observed
ProbableOneTrust DataGuidance — The Federal Code of Obligations contains restrictions on the processing of employee data, supplementing the general FADP framework.observed
Traffic-light rationale — AmberActive FDPIC cookie/consent enforcement interest confirmed at title level; several adtech sub-modules lack confirmed Swiss-specific rules.
Sub-modules (6)
Cookies And TrackersAmber
The FDPIC has published cookie guidelines addressing tracker consent practices for Swiss-facing digital services.
Claims (1):
The FDPIC has published guidelines addressing the use of cookies and trackers, including English-language versions of that guidance.
Dark PatternsAmber
The FDPIC issued an enforcement notice to Digitec Galaxus concerning its cookie-consent interface, and the retailer subsequently implemented a one-click cookie opt-out mechanism.
Claims (1):
The FDPIC issued an enforcement notice concerning Digitec Galaxus's cookie-consent practices, after which the retailer implemented a one-click cookie opt-out mechanism.
Opt Out SignalsRed
No Swiss-specific recognition of browser-based opt-out signals (e.g., Global Privacy Control) was confirmed in this research pass.
Absence provenance: unavailable. Searched: Switzerland Global Privacy Control opt-out signal FADP.
Clean Rooms And DcrRed
No Swiss-specific data clean-room / data-collaboration-room regulatory content was confirmed.
Absence provenance: unavailable. Searched: Switzerland data clean room regulation FADP.
Cross Context AdvertisingRed
No CPRA-style 'sale'/'share' cross-context advertising concept exists under the FADP baseline; no confirmed Swiss equivalent was located.
Absence provenance: unavailable. Searched: Switzerland cross-context advertising data sharing rules.
Direct MarketingGreen
Postal direct marketing is permitted on an opt-out basis where the recipient's address has been made publicly available and no objection has been registered.
Claims (1):
Postal marketing in Switzerland operates on an opt-out mechanism; use of a recipient's publicly available postal address for marketing purposes is permitted absent objection.
Category narrative73 words
The FDPIC has issued cookie guidelines and has taken direct enforcement interest in dark-pattern-style consent practices, including an enforcement notice to a major Swiss e-commerce retailer (Digitec Galaxus) that was followed by the company's implementation of a one-click cookie opt-out. Direct-marketing rules permit postal marketing on an opt-out basis where the recipient's address is publicly available. Opt-out signal standards (e.g., GPC), clean-room/data-collaboration rules, and cross-context-advertising-specific rules were not confirmed in this research pass.
no periodic updates on record for this sub-brief
Sources and claims (3)
UncertainOneTrust DataGuidance — The FDPIC has published guidelines addressing the use of cookies and trackers, including English-language versions of that guidance.observed
UncertainOneTrust DataGuidance — The FDPIC issued an enforcement notice concerning Digitec Galaxus's cookie-consent practices, after which the retailer implemented a one-click cookie opt-out mechanism.observed
ProbableOneTrust DataGuidance — Postal marketing in Switzerland operates on an opt-out mechanism; use of a recipient's publicly available postal address for marketing purposes is permitted absent objection.observed
Biometric/genetic categorisation and FDPIC AI engagement are confirmed; the profiling/ADM regime is structurally narrower than the GDPR and carries residual ambiguity.
Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 2(2)(c), 21, 31
Traffic-light rationale — AmberBiometric/genetic categorisation and FDPIC AI engagement are confirmed; the profiling/ADM regime is structurally narrower than the GDPR and carries residual ambiguity.
Sub-modules (6)
Profiling RestrictionsAmber
A right equivalent to GDPR Article 21 does not exist per se; Swiss law instead provides a narrower opt-out-style objection right under Art 31(2)(b) revFADP.
Claims (1):
A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; Article 31(2)(b) of the revised FADP instead provides a data subject right to object, essentially limited to an opt-out right.
Automated Decision Making TransparencyAmber
Article 21 of the revFADP imposes information duties on controllers in respect of automated individual decision-making, with willful provision of false information in that context subject to criminal sanction.
Claims (1):
Article 21 of the revFADP concerns automated individual decision-making, and willful provision of false or incomplete information in that context is subject to criminal penalty under Article 60.
Ai Risk AssessmentsAmber
The FDPIC has issued a press release addressing the intersection of artificial intelligence and data protection, indicating active regulatory attention though no confirmed dedicated Swiss AI-specific statutory risk-assessment regime.
Claims (1):
The FDPIC has issued a press release specifically addressing artificial intelligence and data protection.
Biometric RegimeAmber
The FDPIC issued a decision addressing PostFinance's use of voice-recognition (biometric) technology, reflecting active enforcement engagement with biometric processing; biometric data is also now expressly a sensitive-data category under the revFADP.
Claims (1):
The FDPIC issued a decision concerning PostFinance's use of voice-recognition biometric technology.
Genetic DataGreen
Genetic data was brought within the FADP's sensitive personal data category as part of the FADP revision.
Claims (1):
Genetic data was brought within the FADP's sensitive personal data category as part of the revision process leading to the revFADP.
State Surveillance CarveoutsAmber
Article 2(2)(c) of the FADP provides that the Act may not apply to processing of personal data within the frame of administrative, civil or criminal proceedings once pending, though the requirements of the FADP still apply to investigations carried out by police prior to such proceedings becoming pending.
Claims (1):
Article 2(2)(c) of the FADP provides that the Act may not apply to processing of personal data in the frame of administrative, civil, or criminal proceedings once pending, though FADP requirements still apply to police investigations carried out prior to such proceedings becoming pending.
Category narrative104 words
The revFADP does not replicate a general GDPR Article 21-style objection right but does impose information duties on controllers regarding automated individual decision-making (Art 21 revFADP information obligations, distinct numbering from the GDPR). Biometric and genetic data were brought within the sensitive-data category by the revision, and the FDPIC has demonstrated active enforcement interest in biometric processing (e.g., a decision concerning PostFinance's voice-recognition system) and has issued a press release specifically addressing AI and data protection. State-surveillance carve-outs exist via Art 2(2)(c) FADP, which disapplies the Act to processing within pending administrative, civil, or criminal proceedings (though pre-proceeding police investigatory processing remains in scope).
no periodic updates on record for this sub-brief
Sources and claims (6)
ProbableOneTrust DataGuidance — A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; Article 31(2)(b) of the revised FADP instead provides a data subject right to object, essentially limited to an opt-out right.observed
ProbableInternational Association of Privacy Professionals — Article 21 of the revFADP concerns automated individual decision-making, and willful provision of false or incomplete information in that context is subject to criminal penalty under Article 60.observed
UncertainOneTrust DataGuidance — The FDPIC has issued a press release specifically addressing artificial intelligence and data protection.observed
UncertainOneTrust DataGuidance — The FDPIC issued a decision concerning PostFinance's use of voice-recognition biometric technology.observed
ProbableInternational Association of Privacy Professionals — Genetic data was brought within the FADP's sensitive personal data category as part of the revision process leading to the revFADP.observed
ProbableOneTrust DataGuidance — Article 2(2)(c) of the FADP provides that the Act may not apply to processing of personal data in the frame of administrative, civil, or criminal proceedings once pending, though FADP requirements still apply to police investigations carried out prior to such proceedings becoming pending.observed
General legislative intent to protect minors is confirmed, but no specific operative mechanism (age threshold, parental consent procedure, profiling ban) was substantiated by available sources.
Primary frameworkFederal Act on Data Protection (FADP), revised version (general provisions)
Traffic-light rationale — RedGeneral legislative intent to protect minors is confirmed, but no specific operative mechanism (age threshold, parental consent procedure, profiling ban) was substantiated by available sources.
Sub-modules (5)
Age VerificationRed
No specific statutory age-of-consent threshold for data processing under the FADP was confirmed in this research pass.
Absence provenance: unavailable. Searched: Swiss FADP minors children data protection special categories genetic biometric Article 5.
Parental ConsentAmber
The revFADP's revision process was explicitly framed as seeking alignment with European standards on the protection of minors, though the specific parental-consent mechanism was not detailed in sources reviewed.
Claims (1):
The revFADP's revision was explicitly framed as seeking to include provisions complying with European standards on, among other things, the protection of minors.
Minor Profiling BansRed
No minor-specific profiling ban was confirmed in this research pass.
Absence provenance: unavailable. Searched: Switzerland minor profiling ban FADP.
Education SettingsRed
No education-setting-specific children's-data rules were confirmed in this research pass.
Absence provenance: unavailable. Searched: Switzerland education data protection children FADP.
Dependent AdultsRed
No dependent-adult-specific data protection provisions were confirmed in this research pass.
The revFADP's legislative history explicitly cites the protection of minors as one of the European-standard alignment goals of the revision. However, specific mechanisms — an age-of-consent threshold for data processing, statutory parental-consent procedures, minor-specific profiling bans, education-setting rules, and dependent-adult protections — were not confirmed with the specificity available in this research pass.
no periodic updates on record for this sub-brief
Sources and claims (1)
ProbableOneTrust DataGuidance — The revFADP's revision was explicitly framed as seeking to include provisions complying with European standards on, among other things, the protection of minors.observed
Strengthened FDPIC investigative/order powers and an active enforcement docket are confirmed; the no-administrative-fine model and gaps in collective-redress and funding/capacity data warrant amber rather than green.
Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 49-51, 60-63
Traffic-light rationale — AmberStrengthened FDPIC investigative/order powers and an active enforcement docket are confirmed; the no-administrative-fine model and gaps in collective-redress and funding/capacity data warrant amber rather than green.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
The FDPIC may open investigations ex officio or following complaint and issue binding orders, but is not authorised to impose administrative fines on organisations; instead, individuals may be fined up to CHF 250,000 for a limited set of enumerated criminal offences under the revFADP.
Claims (2):
Under the revised FADP, the FDPIC's position is strengthened such that it will be able to open an investigation, ex officio or following a complaint, against a controller and processor, and to issue an order at the end of the investigation.
Unlike most European data protection supervisory authorities, the FDPIC is not authorised to impose administrative sanctions directly on organisations; individuals may instead be fined up to CHF 250,000 for a limited range of enumerated criminal offences under Article 63 and related provisions of the revFADP.
Enforcement Activity IndexAmber
Recent FDPIC enforcement activity includes an enforcement notice to Digitec Galaxus, a decision on PostFinance's biometric voice recognition, an investigation into BLT's bodycam use, and Administrative Court confirmation of an FDPIC processing ban.
Claims (1):
Recent FDPIC enforcement matters include an enforcement notice issued to Digitec Galaxus, a decision concerning PostFinance's voice-recognition system, an investigation opened into BLT's bodycam use, and an Administrative Court ruling confirming an FDPIC processing ban.
Regulator Funding And CapacityRed
No specific FDPIC headcount or budget figures were confirmed in this research pass.
No dedicated collective-redress or class-action mechanism for data protection claims was confirmed for Switzerland in this research pass.
Absence provenance: unavailable. Searched: Switzerland collective redress class action data protection.
Private Right Of ActionAmber
Data subjects may pursue civil claims for breach of personality rights under the Swiss Civil Code, which operates alongside the FADP as a governing text for data subject rights enforcement.
Claims (1):
The Swiss Civil Code is listed as a governing text alongside the FADP and its Ordinance for data subject rights matters, providing a civil personality-rights avenue for redress.
Recent Developments 180DAmber
Within the last 180 days, reported FDPIC activity includes Digitec Galaxus's implementation of a one-click cookie opt-out (reported mid-February 2026) and the opening of an FDPIC investigation into BLT's use of bodycams (reported late February 2026).
Claims (1):
Digitec Galaxus implemented a one-click cookie opt-out mechanism, as reported by the FDPIC in mid-February 2026, following prior enforcement engagement.
Category narrative163 words
The FDPIC can open investigations ex officio or on complaint against controllers and processors and, since the revFADP, may issue binding orders at the conclusion of an investigation — a marked strengthening from its prior merely-recommendatory role. Unlike most European DPAs, the FDPIC is not authorised to impose administrative fines directly on organisations; instead, the revFADP creates criminal offences punishable by fines of up to CHF 250,000 against responsible individuals (not the entity) for a limited, enumerated set of violations. Recent enforcement activity includes an enforcement notice to Digitec Galaxus over cookie-consent practices (with subsequent remediation), a decision concerning PostFinance's biometric voice-recognition system, an investigation opened into BLT's use of bodycams, and Administrative Court confirmation of an FDPIC processing ban — though full text of these matters was paywalled and not independently verified beyond title level. Data subjects may also pursue civil claims for breach of personality rights under the Swiss Civil Code. No dedicated collective-redress/class-action mechanism for data protection claims was confirmed.
no periodic updates on record for this sub-brief
Sources and claims (5)
ConfirmedOneTrust DataGuidance — Under the revised FADP, the FDPIC's position is strengthened such that it will be able to open an investigation, ex officio or following a complaint, against a controller and processor, and to issue an order at the end of the investigation.observed
ConfirmedOneTrust DataGuidance — Unlike most European data protection supervisory authorities, the FDPIC is not authorised to impose administrative sanctions directly on organisations; individuals may instead be fined up to CHF 250,000 for a limited range of enumerated criminal offences under Article 63 and related provisions of the revFADP.observed
UncertainOneTrust DataGuidance — Recent FDPIC enforcement matters include an enforcement notice issued to Digitec Galaxus, a decision concerning PostFinance's voice-recognition system, an investigation opened into BLT's bodycam use, and an Administrative Court ruling confirming an FDPIC processing ban.observed
ProbableOneTrust DataGuidance — The Swiss Civil Code is listed as a governing text alongside the FADP and its Ordinance for data subject rights matters, providing a civil personality-rights avenue for redress.observed
UncertainOneTrust DataGuidance — Digitec Galaxus implemented a one-click cookie opt-out mechanism, as reported by the FDPIC in mid-February 2026, following prior enforcement engagement.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
21.74
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Switzerland
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 41 claim(s) (41 category placement(s)), 29 source(s) in the cumulative register.
regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, and cross_border_and_adequacy modules rest on a mix of T1 (FDPIC homepage, EUR-Lex adequacy decision, EDPB, ICO adequacy list) and T2 (IAPP) sources with good coverage. sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress rely more heavily on T3 secondary reporting (OneTrust DataGuidance), several of which returned only paywalled title-level content rather than full substantive text; those claims are flagged Uncertain with absent_field_provenance. children_and_vulnerable_groups and several sectoral_watch sub-modules (health, telecoms/eprivacy, credit, education, insurance) had no confirmed findings and are carried as explicit gaps (traffic_light=red, empty claims[], absent_field_provenance).
Unresolved questions (7):
Precise statutory response-time window for Swiss data subject access/rectification requests (analogous to GDPR's one-month period) was not confirmed.
Whether Switzerland's DPO-appointment regime carries a mandatory threshold (as opposed to voluntary/registrable practice via the FDPIC portal).
Full substantive content of several 2025-2026 FDPIC enforcement matters (Digitec Galaxus, PostFinance, BLT bodycams, Administrative Court ruling) — search results returned only paywalled title-level metadata.
Existence and scope of any formal Swiss Transfer Impact Assessment obligation post-Schrems II.
Sector-specific health, telecoms/eprivacy, credit-scoring, education, and insurance overlays beyond the general FADP baseline.
Whether any Swiss collective-redress or class-action mechanism applies to data protection claims.
Specific age-of-consent threshold and parental-consent mechanism for minors' data processing.