{
 "jurisdiction_id": "CH",
 "jurisdiction": "Switzerland",
 "url": "https://dataprotection.gi/jurisdictions/switzerland/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 41,
  "sub_modules": 57,
  "source_register": 23
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/switzerland/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "A comprehensive, currently-in-force omnibus statute with an active, empowered supervisory authority; GDPR-aligned but not identical.",
   "claims": [
    {
     "statement": "The Federal Data Protection and Information Commissioner (FDPIC) is the federal data protection authority responsible for supervising the FADP.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/switzerland-federal-data-protection-act-draft/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The revised Swiss Federal Act on Data Protection came into force on 1 September 2023, bringing Switzerland's data protection regime into closer alignment with the EU GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/revised-swiss-data-protection-law-soon-in-effect-with-new-scope-obligations-implications",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The revFADP applies to circumstances that have an effect in Switzerland even where the processing activity is initiated abroad, giving the FDPIC competence over any activity with Swiss impact regardless of origin.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/revised-swiss-data-protection-law-soon-in-effect-with-new-scope-obligations-implications",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where the revFADP's extraterritorial scope applies, the controller must appoint and publicly identify a Swiss representative, who is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC on request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/revised-swiss-data-protection-law-soon-in-effect-with-new-scope-obligations-implications",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FADP is an omnibus law applying to any processing of personal data by private persons and federal bodies, irrespective of sector, while cantonal acts separately govern cantonal and communal bodies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/switzerland-federal-data-protection-act-draft/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/switzerland/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Structurally different from GDPR's Art 6 lawful-basis model; sensitive-data protections exist but the consent architecture is comparatively lighter.",
   "claims": [
    {
     "statement": "Unlike the EU GDPR, Swiss law does not provide that processing of personal data without a specified legal basis is per se illegitimate; legitimacy instead turns on absence of a breach of personality rights.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/switzerland_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Article 17 of the revised FADP, a cross-border data transfer may be legitimate where the data subject has consented, in addition to contractual necessity, overriding public interest, or the data having been made publicly accessible by the subject.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/switzerland_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FADP's definition of sensitive personal data was extended in the revision process to cover biometric and genetic data, while maintaining a risk-based approach rather than the EU's explicit-consent concept for such data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/revision-of-the-swiss-data-protection-act-evolution-but-not-revolution",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Anonymised or aggregated data is not personal data under the FADP because the person is not identifiable, whereas pseudonymised data may still permit re-identification and is generally treated as personal data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/switzerland-federal-data-protection-act-draft/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/switzerland/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core rights are present and GDPR-inspired, but the objection right is narrower and exact response-window detail is unconfirmed.",
   "claims": [
    {
     "statement": "Article 25 of the revised FADP provides a more detailed access right for data subjects than the prior 1992 FADP's general information-request entitlement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/switzerland_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The revised FADP explicitly states a right to erasure, whereas the old FADP only implicitly recognised it, and introduces rectification rights under Article 32.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/switzerland-revised-fadp-high-risk-profiling",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; instead, Article 31(2)(b) of the revised FADP provides a data subject right to object to processing, essentially limited to an opt-out right.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/switzerland_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The right to data portability, copied from the GDPR, is completely new to Swiss law under the revised FADP.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/switzerland-revised-fadp-high-risk-profiling",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/switzerland/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability infrastructure (DPIA, security, retention, breach notification) is in force and GDPR-adjacent, but breach-notification timing and DPO-threshold specifics carry residual uncertainty.",
   "claims": [
    {
     "statement": "Articles 22 and 23 of the revFADP mandate federal bodies and private individuals to conduct a Data Protection Impact Assessment if data processing poses high risks to personality or fundamental rights.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/switzerland-fdpic-releases-factsheet-procedure",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FDPIC operates a dedicated reporting portal for data protection officers, but a universally mandatory DPO-appointment threshold was not confirmed in the sources reviewed for this run.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/switzerland-fdpic-launches-new-reporting-portal-dpos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Swiss representative appointed by a non-Swiss controller is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC upon request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/revised-swiss-data-protection-law-soon-in-effect-with-new-scope-obligations-implications",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 7 of the FADP requires that personal data be protected against unauthorised processing through adequate technical and organisational measures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/switzerland_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers are obliged to inform the FDPIC of a data breach as soon as possible when it is likely to result in a high risk to the data subject's personality or fundamental rights, with no confirmed fixed statutory time limit equivalent to the GDPR's 72 hours.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/revised-swiss-data-protection-law-soon-in-effect-with-new-scope-obligations-implications",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 6(4) of the revised FADP requires that all personal data be either deleted or anonymised once the purpose for its collection has been achieved.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/switzerland_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/switzerland/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Robust bidirectional adequacy status (EU since 2000; UK full adequacy) plus a GDPR-mirroring transfer-mechanism toolkit.",
   "claims": [
    {
     "statement": "Cross-border transfers from Switzerland may rely on adequacy, Standard Contractual Clauses or Binding Corporate Rules under Article 16 of the revised FADP, or derogations under Article 17 including consent, contractual necessity, overriding public interest, or public availability of the data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/switzerland_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Switzerland is considered by the European Commission as providing an adequate level of data protection, per Commission Decision 2000/518/EC of 26 July 2000, and remains on the Commission's current list of adequate countries.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / Official Journal of the European Union",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32000D0518",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The UK government's adequacy regulations list Switzerland among the jurisdictions with 'full adequacy' for restricted transfers under UK GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "ICO",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/adequacy-regulations/is-the-restricted-transfer-covered-by-adequacy-regulations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FDPIC establishes and maintains its own list of third countries considered to provide an adequate level of protection for personal data transferred from Switzerland.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/switzerland-federal-data-protection-act-draft/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FDPIC has updated its guidelines/templates concerning Standard Contractual Clauses available for use by Swiss data exporters.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/switzerland-fdpic-updates-sccs-guidelines",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/switzerland/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Confirmed financial-sector and employment overlays; several other sectoral sub-modules carry no confirmed findings.",
   "claims": [
    {
     "statement": "FINMA maintains and has amended an Ordinance on Data Processing applicable to supervised financial institutions, operating alongside the general FADP regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/switzerland-finma-amends-finma-ordinance-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Federal Code of Obligations contains restrictions on the processing of employee data, supplementing the general FADP framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/switzerland-federal-data-protection-act-draft/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/switzerland/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Active FDPIC cookie/consent enforcement interest confirmed at title level; several adtech sub-modules lack confirmed Swiss-specific rules.",
   "claims": [
    {
     "statement": "The FDPIC has published guidelines addressing the use of cookies and trackers, including English-language versions of that guidance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/switzerland-fdpic-publishes-cookie-guidelines",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FDPIC issued an enforcement notice concerning Digitec Galaxus's cookie-consent practices, after which the retailer implemented a one-click cookie opt-out mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/switzerland-fdpic-announces-digitec-galaxus-implements",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Postal marketing in Switzerland operates on an opt-out mechanism; use of a recipient's publicly available postal address for marketing purposes is permitted absent objection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/switzerland_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/switzerland/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric/genetic categorisation and FDPIC AI engagement are confirmed; the profiling/ADM regime is structurally narrower than the GDPR and carries residual ambiguity.",
   "claims": [
    {
     "statement": "A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; Article 31(2)(b) of the revised FADP instead provides a data subject right to object, essentially limited to an opt-out right.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/switzerland_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 21 of the revFADP concerns automated individual decision-making, and willful provision of false or incomplete information in that context is subject to criminal penalty under Article 60.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/revised-swiss-data-protection-law-soon-in-effect-with-new-scope-obligations-implications",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FDPIC has issued a press release specifically addressing artificial intelligence and data protection.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/switzerland-fdpic-issues-press-release-ai-and-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FDPIC issued a decision concerning PostFinance's use of voice-recognition biometric technology.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/switzerland-fdpic-issues-decision-postfinance-voice",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Genetic data was brought within the FADP's sensitive personal data category as part of the revision process leading to the revFADP.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/revision-of-the-swiss-data-protection-act-evolution-but-not-revolution",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 2(2)(c) of the FADP provides that the Act may not apply to processing of personal data in the frame of administrative, civil, or criminal proceedings once pending, though FADP requirements still apply to police investigations carried out prior to such proceedings becoming pending.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/switzerland_-_third_country_assessment_guidance_note_dataguidance.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/switzerland/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "General legislative intent to protect minors is confirmed, but no specific operative mechanism (age threshold, parental consent procedure, profiling ban) was substantiated by available sources.",
   "claims": [
    {
     "statement": "The revFADP's revision was explicitly framed as seeking to include provisions complying with European standards on, among other things, the protection of minors.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/switzerland-revised-fadp-high-risk-profiling",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/switzerland/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Strengthened FDPIC investigative/order powers and an active enforcement docket are confirmed; the no-administrative-fine model and gaps in collective-redress and funding/capacity data warrant amber rather than green.",
   "claims": [
    {
     "statement": "Under the revised FADP, the FDPIC's position is strengthened such that it will be able to open an investigation, ex officio or following a complaint, against a controller and processor, and to issue an order at the end of the investigation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/switzerland-revised-fadp-high-risk-profiling",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Unlike most European data protection supervisory authorities, the FDPIC is not authorised to impose administrative sanctions directly on organisations; individuals may instead be fined up to CHF 250,000 for a limited range of enumerated criminal offences under Article 63 and related provisions of the revFADP.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/switzerland-revised-fadp-high-risk-profiling",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Recent FDPIC enforcement matters include an enforcement notice issued to Digitec Galaxus, a decision concerning PostFinance's voice-recognition system, an investigation opened into BLT's bodycam use, and an Administrative Court ruling confirming an FDPIC processing ban.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/switzerland-fdpic-issues-enforcement-notice-digitec",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Swiss Civil Code is listed as a governing text alongside the FADP and its Ordinance for data subject rights matters, providing a civil personality-rights avenue for redress.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/switzerland-data-subject-rights-0",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Digitec Galaxus implemented a one-click cookie opt-out mechanism, as reported by the FDPIC in mid-February 2026, following prior enforcement engagement.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/switzerland-fdpic-announces-digitec-galaxus-implements",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}