🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CH · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 23 sources retrieved model claude-sonnet-5 ·

Switzerland

CH schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 41 claims · 23 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
41Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive, currently-in-force omnibus statute with an active, empowered supervisory authority; GDPR-aligned but not identical.

Primary frameworkFederal Act on Data Protection (FADP), revised version in force 1 September 2023
Traffic-light rationale — GreenA comprehensive, currently-in-force omnibus statute with an active, empowered supervisory authority; GDPR-aligned but not identical.

Sub-modules (5)

Regulator And AuthorityGreen

The FDPIC is the federal supervisory authority; cantons additionally maintain their own commissioners for cantonal/communal bodies, creating a partially federated oversight structure alongside the federal regime.

Claims: CLM-CH-1a2b3c4d

Act And InstrumentsGreen

The revFADP and its Ordinance constitute the primary instruments, in force since 1 September 2023, replacing the 1992 FADP and bringing Swiss law closer to GDPR standards.

Claims: CLM-CH-2b3c4d5e

Material ScopeGreen

The FADP applies as an omnibus law to processing of personal data by private persons and federal bodies irrespective of sector; cantonal acts govern cantonal/communal bodies separately.

Claims: CLM-CH-6f708192

Territorial ScopeGreen

The revFADP's territorial scope was broadened, GDPR-style, to capture processing with an effect in Switzerland even if the processing activity is initiated from abroad.

Claims: CLM-CH-3c4d5e6f

Regulator Registration And FilingAmber

There is no general controller-registration/filing regime; instead, non-Swiss controllers meeting territorial-scope criteria must designate and publish a Swiss representative, who is responsible for maintaining the controller's records of processing and producing them to the FDPIC on request.

Claims: CLM-CH-5e6f7081

Category narrative94 words

Switzerland's data protection regime is governed by the revised Federal Act on Data Protection (revFADP, FADP 2020), which entered into force on 1 September 2023 alongside its implementing Ordinance, replacing the 1992 FADP. The regime is enforced by the Federal Data Protection and Information Commissioner (FDPIC/EDÖB), an independent federal authority. The revFADP brings Switzerland into closer alignment with the GDPR while retaining distinctly Swiss features (e.g., no general administrative fining power for the FDPIC, personality-rights-based unlawfulness test). Territorial scope was significantly broadened to reach processing with an effect in Switzerland even where initiated abroad.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceThe Federal Data Protection and Information Commissioner (FDPIC) is the federal data protection authority responsible for supervising the FADP.
  2. ConfirmedInternational Association of Privacy ProfessionalsThe revised Swiss Federal Act on Data Protection came into force on 1 September 2023, bringing Switzerland's data protection regime into closer alignment with the EU GDPR.
  3. ConfirmedInternational Association of Privacy ProfessionalsThe revFADP applies to circumstances that have an effect in Switzerland even where the processing activity is initiated abroad, giving the FDPIC competence over any activity with Swiss impact regardless of origin.
  4. ProbableInternational Association of Privacy ProfessionalsWhere the revFADP's extraterritorial scope applies, the controller must appoint and publicly identify a Swiss representative, who is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC on request.
  5. ProbableOneTrust DataGuidanceThe FADP is an omnibus law applying to any processing of personal data by private persons and federal bodies, irrespective of sector, while cantonal acts separately govern cantonal and communal bodies.

#

Structurally different from GDPR's Art 6 lawful-basis model; sensitive-data protections exist but the consent architecture is comparatively lighter.

Primary frameworkFederal Act on Data Protection (FADP), revised version
Traffic-light rationale — AmberStructurally different from GDPR's Art 6 lawful-basis model; sensitive-data protections exist but the consent architecture is comparatively lighter.

Sub-modules (4)

Lawful BasesAmber

Swiss law does not treat the absence of a specified legal basis as per se unlawful; unlawfulness is instead assessed against breach of personality rights.

Claims: CLM-CH-708192a3

Special CategoriesGreen

The revFADP extended the definition of sensitive personal data to explicitly include genetic and biometric data, while retaining a risk-based rather than explicit-consent-centric approach.

Claims: CLM-CH-92a3b4c5

Pseudonymisation And AnonymisationAmber

Anonymised or aggregated data falls outside the FADP's personal-data scope because the person is no longer identifiable; pseudonymised data, by contrast, may still permit re-identification and generally remains in scope.

Claims: CLM-CH-a3b4c5d6

Category narrative80 words

Unlike the GDPR's positive lawful-basis requirement, Swiss law does not require a specified legal basis for processing to be lawful per se; processing is only unlawful if it breaches personality rights under the Civil Code/FADP principles. The revFADP nonetheless expanded the definition of sensitive personal data to include genetic and biometric data and retains a risk-based (rather than explicit-consent-centric) approach to sensitive data. Consent functions primarily as a derogation basis for cross-border transfer and is not a universal processing gateway.

Sources and claims (4)
  1. ProbableOneTrust DataGuidanceUnlike the EU GDPR, Swiss law does not provide that processing of personal data without a specified legal basis is per se illegitimate; legitimacy instead turns on absence of a breach of personality rights.
  2. ProbableOneTrust DataGuidanceUnder Article 17 of the revised FADP, a cross-border data transfer may be legitimate where the data subject has consented, in addition to contractual necessity, overriding public interest, or the data having been made publicly accessible by the subject.
  3. ProbableInternational Association of Privacy ProfessionalsThe FADP's definition of sensitive personal data was extended in the revision process to cover biometric and genetic data, while maintaining a risk-based approach rather than the EU's explicit-consent concept for such data.
  4. ProbableOneTrust DataGuidanceAnonymised or aggregated data is not personal data under the FADP because the person is not identifiable, whereas pseudonymised data may still permit re-identification and is generally treated as personal data.

#

Core rights are present and GDPR-inspired, but the objection right is narrower and exact response-window detail is unconfirmed.

Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 25, 30-32
Traffic-light rationale — AmberCore rights are present and GDPR-inspired, but the objection right is narrower and exact response-window detail is unconfirmed.

Sub-modules (5)

Access RightGreen

Article 25 of the revFADP provides a more detailed subject-access right than the prior law's single-sentence entitlement to know whether data is processed.

Claims: CLM-CH-b4c5d6e7

Rectification And ErasureGreen

The revFADP explicitly states a right to erasure (previously only implicit) alongside rectification rights under Art 32.

Claims: CLM-CH-c5d6e7f8

Restriction And ObjectionAmber

A right equivalent to GDPR Art 21 does not exist per se; Swiss law provides a narrower opt-out-style objection right under Art 31(2)(b) revFADP.

Claims: CLM-CH-d6e7f809

Data PortabilityGreen

The right to data portability, copied from the GDPR, is entirely new to Swiss law under the revFADP.

Claims: CLM-CH-e7f8091a

Deadlines And Response WindowsRed

Available sources did not confirm a specific statutory response-time window (analogous to the GDPR's one-month period) for Swiss data subject requests.

Absence provenance: not recorded. Searched: FADP data subject access request deadline response window, revFADP Article 25 response time days.

Category narrative83 words

The revFADP substantially strengthens data subject rights compared to the 1992 law, introducing an explicit right to erasure and a wholly new right to data portability modelled on the GDPR, alongside a more detailed access right (Art 25) and rectification rights (Art 32). The objection right, however, remains narrower than GDPR Art 21 — Swiss law provides an opt-out-style objection right rather than a general right to object on grounds relating to particular circumstances. Statutory response-deadline specifics were not confirmed in available sources.

Sources and claims (4)
  1. ProbableOneTrust DataGuidanceArticle 25 of the revised FADP provides a more detailed access right for data subjects than the prior 1992 FADP's general information-request entitlement.
  2. ConfirmedOneTrust DataGuidanceThe revised FADP explicitly states a right to erasure, whereas the old FADP only implicitly recognised it, and introduces rectification rights under Article 32.
  3. ProbableOneTrust DataGuidanceA right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; instead, Article 31(2)(b) of the revised FADP provides a data subject right to object to processing, essentially limited to an opt-out right.
  4. ConfirmedOneTrust DataGuidanceThe right to data portability, copied from the GDPR, is completely new to Swiss law under the revised FADP.

#

Core accountability infrastructure (DPIA, security, retention, breach notification) is in force and GDPR-adjacent, but breach-notification timing and DPO-threshold specifics carry residual uncertainty.

Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 6-9, 22-24
Traffic-light rationale — AmberCore accountability infrastructure (DPIA, security, retention, breach notification) is in force and GDPR-adjacent, but breach-notification timing and DPO-threshold specifics carry residual uncertainty.

Sub-modules (7)

Accountability And DpiaGreen

Articles 22 and 23 of the revFADP mandate federal bodies and private persons to conduct a Data Protection Impact Assessment where data processing poses high risks to personality or fundamental rights; the FDPIC has published a factsheet with templates and flowcharts.

Claims: CLM-CH-f8091a2b

Dpo RequirementsAmber

No universal mandatory DPO-appointment threshold analogous to GDPR member-state gold-plating was confirmed; the FDPIC operates a reporting portal for DPOs, suggesting appointment is encouraged/registrable rather than confirmed as strictly mandatory across all controllers in the sources reviewed.

Claims: CLM-CH-091a2b3c

Ropa RequirementsGreen

Controllers, including the Swiss representative for foreign controllers, are required to maintain records of processing activities and provide them to the FDPIC upon request.

Claims: CLM-CH-1a2b3c4e

Joint Controller ArrangementsRed

No source reviewed specified a distinct statutory joint-controller regime analogous to GDPR Art 26.

Absence provenance: not recorded. Searched: FADP joint controller arrangement Article, revFADP joint controllership.

Security MeasuresGreen

Article 7 of the FADP requires that personal data be protected against unauthorised processing through adequate technical and organisational measures.

Claims: CLM-CH-2b3c4e5f

Breach NotificationAmber

The revFADP introduces an obligation to notify the FDPIC of a data breach as soon as possible where it is likely to result in high risk to the data subject's personality or fundamental rights; no fixed numerical deadline equivalent to the GDPR's 72 hours was confirmed as of the guidance reviewed.

Claims: CLM-CH-3c4e5f60

Retention And DisposalGreen

Article 6(4) of the revised FADP clarifies that data must either be deleted or anonymised once the purpose for its collection has been achieved.

Claims: CLM-CH-4e5f6071

Category narrative96 words

The revFADP introduces mandatory DPIAs for high-risk processing (Arts 22-23), strengthened security-of-processing obligations (Art 7 FADP baseline), an explicit purpose-limitation-driven retention/disposal duty (Art 6(4)), and a new breach-notification obligation owed to the FDPIC 'as soon as possible' where a breach is likely to result in high risk, though no fixed numerical deadline (unlike the GDPR's 72 hours) was confirmed. Records-of-processing obligations attach to controllers (and, for foreign controllers, their Swiss representative). DPO appointment does not appear to carry a universal mandatory threshold as under some GDPR member-state laws; the FDPIC operates a voluntary DPO reporting portal.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidanceArticles 22 and 23 of the revFADP mandate federal bodies and private individuals to conduct a Data Protection Impact Assessment if data processing poses high risks to personality or fundamental rights.
  2. UncertainOneTrust DataGuidanceThe FDPIC operates a dedicated reporting portal for data protection officers, but a universally mandatory DPO-appointment threshold was not confirmed in the sources reviewed for this run.
  3. ProbableInternational Association of Privacy ProfessionalsThe Swiss representative appointed by a non-Swiss controller is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC upon request.
  4. ProbableOneTrust DataGuidanceArticle 7 of the FADP requires that personal data be protected against unauthorised processing through adequate technical and organisational measures.
  5. ProbableInternational Association of Privacy ProfessionalsControllers are obliged to inform the FDPIC of a data breach as soon as possible when it is likely to result in a high risk to the data subject's personality or fundamental rights, with no confirmed fixed statutory time limit equivalent to the GDPR's 72 hours.
  6. ProbableOneTrust DataGuidanceArticle 6(4) of the revised FADP requires that all personal data be either deleted or anonymised once the purpose for its collection has been achieved.

#

Robust bidirectional adequacy status (EU since 2000; UK full adequacy) plus a GDPR-mirroring transfer-mechanism toolkit.

Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 16-17; EU Commission Decision 2000/518/EC
Traffic-light rationale — GreenRobust bidirectional adequacy status (EU since 2000; UK full adequacy) plus a GDPR-mirroring transfer-mechanism toolkit.

Sub-modules (6)

Transfer MechanismsGreen

Available mechanisms include adequacy, SCCs and BCRs under Art 16 revFADP, and derogations under Art 17 (consent, contract necessity, overriding public interest, public availability of data).

Claims: CLM-CH-5f607182

Adequacy ReceivedGreen

Switzerland has held an EU adequacy decision since 2000 (Commission Decision 2000/518/EC) and is listed by the UK government as a 'full adequacy' jurisdiction for restricted transfers.

Claims: CLM-CH-60718293, CLM-CH-718293a4

Adequacy GrantedGreen

The FDPIC maintains its own list of third countries considered to provide adequate protection for outbound Swiss data transfers.

Claims: CLM-CH-8293a4b5

Sccs And BcrsAmber

The FDPIC has issued and periodically updated guidance/templates on Standard Contractual Clauses for use by Swiss controllers.

Claims: CLM-CH-93a4b5c6

Transfer Impact AssessmentRed

No FDPIC-specific formal Transfer Impact Assessment obligation equivalent to post-Schrems II EU practice was confirmed in this research pass, though FDPIC guidance on third-country transfers exists generally.

Absence provenance: not recorded. Searched: FDPIC transfer impact assessment guidance third country.

Data LocalisationRed

No general private-sector data-localisation mandate was confirmed for Switzerland in this research pass.

Absence provenance: not recorded. Searched: Switzerland data localisation requirement FADP, Swiss data residency mandate.

Category narrative81 words

Switzerland offers multiple cross-border transfer mechanisms mirroring the GDPR: adequacy (its own FDPIC-maintained country list plus reliance on the general adequacy concept), Standard Contractual Clauses and Binding Corporate Rules under Art 16 revFADP, and derogations under Art 17 (consent, contractual necessity, overriding public interest, public availability). Switzerland itself has held an EU adequacy decision since 2000 (2000/518/EC) and is listed by the UK as a 'full adequacy' jurisdiction. Data-localisation mandates in the private sector were not confirmed in this research pass.

Sources and claims (5)
  1. ProbableOneTrust DataGuidanceCross-border transfers from Switzerland may rely on adequacy, Standard Contractual Clauses or Binding Corporate Rules under Article 16 of the revised FADP, or derogations under Article 17 including consent, contractual necessity, overriding public interest, or public availability of the data.
  2. ConfirmedEUR-Lex / Official Journal of the European UnionSwitzerland is considered by the European Commission as providing an adequate level of data protection, per Commission Decision 2000/518/EC of 26 July 2000, and remains on the Commission's current list of adequate countries.
  3. ConfirmedICOThe UK government's adequacy regulations list Switzerland among the jurisdictions with 'full adequacy' for restricted transfers under UK GDPR.
  4. ProbableOneTrust DataGuidanceThe FDPIC establishes and maintains its own list of third countries considered to provide an adequate level of protection for personal data transferred from Switzerland.
  5. UncertainOneTrust DataGuidanceThe FDPIC has updated its guidelines/templates concerning Standard Contractual Clauses available for use by Swiss data exporters.

#

Confirmed financial-sector and employment overlays; several other sectoral sub-modules carry no confirmed findings.

Primary frameworkFADP baseline plus FINMA Ordinance on Data Processing; Code of Obligations (employment)
Traffic-light rationale — AmberConfirmed financial-sector and employment overlays; several other sectoral sub-modules carry no confirmed findings.

Sub-modules (7)

Financial Sector OverlayAmber

FINMA maintains a Data Processing Ordinance that has been amended over time and applies additional sector rules to supervised financial institutions, layered on top of the general FADP baseline.

Claims: CLM-CH-a4b5c6d7

Health Sector OverlayRed

No health-sector-specific data protection overlay was confirmed in this research pass beyond the general FADP baseline.

Absence provenance: not recorded. Searched: Switzerland health data protection sectoral law FADP.

Telecoms And EprivacyRed

No specific e-privacy/telecoms overlay content was confirmed in this research pass, though the general Telecommunications Act framework was referenced tangentially.

Absence provenance: not recorded. Searched: Switzerland telecommunications act eprivacy cookie law.

Employment DataGreen

The Federal Code of Obligations contains restrictions on the processing of employee data by employers, supplementing the general FADP.

Claims: CLM-CH-b5c6d7e8

Credit And ScoringRed

No dedicated Swiss credit-scoring regulatory overlay was confirmed in this research pass.

Absence provenance: not recorded. Searched: Switzerland credit scoring data protection regulation.

EducationRed

No education-sector-specific data protection overlay was confirmed in this research pass.

Absence provenance: not recorded. Searched: Switzerland education sector data protection FADP.

InsuranceRed

No insurance-sector-specific data protection overlay was confirmed in this research pass.

Absence provenance: not recorded. Searched: Switzerland insurance sector data protection FADP FINMA.

Category narrative58 words

Switzerland lacks dedicated omnibus sectoral data-protection statutes, but sector-specific instruments layer additional obligations onto the FADP baseline: FINMA maintains an ordinance on data processing applicable to supervised financial institutions, and the Federal Code of Obligations restricts employer processing of employee data. Health, telecoms/e-privacy, credit-scoring, education and insurance-specific overlays were not confirmed with sufficient specificity in this research pass.

Sources and claims (2)
  1. UncertainOneTrust DataGuidanceFINMA maintains and has amended an Ordinance on Data Processing applicable to supervised financial institutions, operating alongside the general FADP regime.
  2. ProbableOneTrust DataGuidanceThe Federal Code of Obligations contains restrictions on the processing of employee data, supplementing the general FADP framework.

#

Active FDPIC cookie/consent enforcement interest confirmed at title level; several adtech sub-modules lack confirmed Swiss-specific rules.

Primary frameworkFADP (general) plus FDPIC guidance on cookies/trackers
Traffic-light rationale — AmberActive FDPIC cookie/consent enforcement interest confirmed at title level; several adtech sub-modules lack confirmed Swiss-specific rules.

Sub-modules (6)

Cookies And TrackersAmber

The FDPIC has published cookie guidelines addressing tracker consent practices for Swiss-facing digital services.

Claims: CLM-CH-c6d7e8f9

Dark PatternsAmber

The FDPIC issued an enforcement notice to Digitec Galaxus concerning its cookie-consent interface, and the retailer subsequently implemented a one-click cookie opt-out mechanism.

Claims: CLM-CH-d7e8f900

Opt Out SignalsRed

No Swiss-specific recognition of browser-based opt-out signals (e.g., Global Privacy Control) was confirmed in this research pass.

Absence provenance: not recorded. Searched: Switzerland Global Privacy Control opt-out signal FADP.

Clean Rooms And DcrRed

No Swiss-specific data clean-room / data-collaboration-room regulatory content was confirmed.

Absence provenance: not recorded. Searched: Switzerland data clean room regulation FADP.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context advertising concept exists under the FADP baseline; no confirmed Swiss equivalent was located.

Absence provenance: not recorded. Searched: Switzerland cross-context advertising data sharing rules.

Direct MarketingGreen

Postal direct marketing is permitted on an opt-out basis where the recipient's address has been made publicly available and no objection has been registered.

Claims: CLM-CH-e8f9001a

Category narrative73 words

The FDPIC has issued cookie guidelines and has taken direct enforcement interest in dark-pattern-style consent practices, including an enforcement notice to a major Swiss e-commerce retailer (Digitec Galaxus) that was followed by the company's implementation of a one-click cookie opt-out. Direct-marketing rules permit postal marketing on an opt-out basis where the recipient's address is publicly available. Opt-out signal standards (e.g., GPC), clean-room/data-collaboration rules, and cross-context-advertising-specific rules were not confirmed in this research pass.

Sources and claims (3)
  1. UncertainOneTrust DataGuidanceThe FDPIC has published guidelines addressing the use of cookies and trackers, including English-language versions of that guidance.
  2. UncertainOneTrust DataGuidanceThe FDPIC issued an enforcement notice concerning Digitec Galaxus's cookie-consent practices, after which the retailer implemented a one-click cookie opt-out mechanism.
  3. ProbableOneTrust DataGuidancePostal marketing in Switzerland operates on an opt-out mechanism; use of a recipient's publicly available postal address for marketing purposes is permitted absent objection.

#

Biometric/genetic categorisation and FDPIC AI engagement are confirmed; the profiling/ADM regime is structurally narrower than the GDPR and carries residual ambiguity.

Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 2(2)(c), 21, 31
Traffic-light rationale — AmberBiometric/genetic categorisation and FDPIC AI engagement are confirmed; the profiling/ADM regime is structurally narrower than the GDPR and carries residual ambiguity.

Sub-modules (6)

Profiling RestrictionsAmber

A right equivalent to GDPR Article 21 does not exist per se; Swiss law instead provides a narrower opt-out-style objection right under Art 31(2)(b) revFADP.

Claims: CLM-CH-f900112b

Automated Decision Making TransparencyAmber

Article 21 of the revFADP imposes information duties on controllers in respect of automated individual decision-making, with willful provision of false information in that context subject to criminal sanction.

Claims: CLM-CH-00112b3c

Ai Risk AssessmentsAmber

The FDPIC has issued a press release addressing the intersection of artificial intelligence and data protection, indicating active regulatory attention though no confirmed dedicated Swiss AI-specific statutory risk-assessment regime.

Claims: CLM-CH-112b3c4e

Biometric RegimeAmber

The FDPIC issued a decision addressing PostFinance's use of voice-recognition (biometric) technology, reflecting active enforcement engagement with biometric processing; biometric data is also now expressly a sensitive-data category under the revFADP.

Claims: CLM-CH-2b3c4e60

Genetic DataGreen

Genetic data was brought within the FADP's sensitive personal data category as part of the FADP revision.

Claims: CLM-CH-3c4e6071

State Surveillance CarveoutsAmber

Article 2(2)(c) of the FADP provides that the Act may not apply to processing of personal data within the frame of administrative, civil or criminal proceedings once pending, though the requirements of the FADP still apply to investigations carried out by police prior to such proceedings becoming pending.

Claims: CLM-CH-4e607182

Category narrative104 words

The revFADP does not replicate a general GDPR Article 21-style objection right but does impose information duties on controllers regarding automated individual decision-making (Art 21 revFADP information obligations, distinct numbering from the GDPR). Biometric and genetic data were brought within the sensitive-data category by the revision, and the FDPIC has demonstrated active enforcement interest in biometric processing (e.g., a decision concerning PostFinance's voice-recognition system) and has issued a press release specifically addressing AI and data protection. State-surveillance carve-outs exist via Art 2(2)(c) FADP, which disapplies the Act to processing within pending administrative, civil, or criminal proceedings (though pre-proceeding police investigatory processing remains in scope).

Sources and claims (6)
  1. ProbableOneTrust DataGuidanceA right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; Article 31(2)(b) of the revised FADP instead provides a data subject right to object, essentially limited to an opt-out right.
  2. ProbableInternational Association of Privacy ProfessionalsArticle 21 of the revFADP concerns automated individual decision-making, and willful provision of false or incomplete information in that context is subject to criminal penalty under Article 60.
  3. UncertainOneTrust DataGuidanceThe FDPIC has issued a press release specifically addressing artificial intelligence and data protection.
  4. UncertainOneTrust DataGuidanceThe FDPIC issued a decision concerning PostFinance's use of voice-recognition biometric technology.
  5. ProbableInternational Association of Privacy ProfessionalsGenetic data was brought within the FADP's sensitive personal data category as part of the revision process leading to the revFADP.
  6. ProbableOneTrust DataGuidanceArticle 2(2)(c) of the FADP provides that the Act may not apply to processing of personal data in the frame of administrative, civil, or criminal proceedings once pending, though FADP requirements still apply to police investigations carried out prior to such proceedings becoming pending.

#

General legislative intent to protect minors is confirmed, but no specific operative mechanism (age threshold, parental consent procedure, profiling ban) was substantiated by available sources.

Primary frameworkFederal Act on Data Protection (FADP), revised version (general provisions)
Traffic-light rationale — RedGeneral legislative intent to protect minors is confirmed, but no specific operative mechanism (age threshold, parental consent procedure, profiling ban) was substantiated by available sources.

Sub-modules (5)

Age VerificationRed

No specific statutory age-of-consent threshold for data processing under the FADP was confirmed in this research pass.

Absence provenance: not recorded. Searched: Swiss FADP minors children data protection special categories genetic biometric Article 5.

Minor Profiling BansRed

No minor-specific profiling ban was confirmed in this research pass.

Absence provenance: not recorded. Searched: Switzerland minor profiling ban FADP.

Education SettingsRed

No education-setting-specific children's-data rules were confirmed in this research pass.

Absence provenance: not recorded. Searched: Switzerland education data protection children FADP.

Dependent AdultsRed

No dependent-adult-specific data protection provisions were confirmed in this research pass.

Absence provenance: not recorded. Searched: Switzerland dependent adults elderly data protection FADP.

Category narrative53 words

The revFADP's legislative history explicitly cites the protection of minors as one of the European-standard alignment goals of the revision. However, specific mechanisms — an age-of-consent threshold for data processing, statutory parental-consent procedures, minor-specific profiling bans, education-setting rules, and dependent-adult protections — were not confirmed with the specificity available in this research pass.

Sources and claims (1)
  1. ProbableOneTrust DataGuidanceThe revFADP's revision was explicitly framed as seeking to include provisions complying with European standards on, among other things, the protection of minors.

#

Strengthened FDPIC investigative/order powers and an active enforcement docket are confirmed; the no-administrative-fine model and gaps in collective-redress and funding/capacity data warrant amber rather than green.

Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 49-51, 60-63
Traffic-light rationale — AmberStrengthened FDPIC investigative/order powers and an active enforcement docket are confirmed; the no-administrative-fine model and gaps in collective-redress and funding/capacity data warrant amber rather than green.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The FDPIC may open investigations ex officio or following complaint and issue binding orders, but is not authorised to impose administrative fines on organisations; instead, individuals may be fined up to CHF 250,000 for a limited set of enumerated criminal offences under the revFADP.

Claims: CLM-CH-71829eaf, CLM-CH-829eafb0

Enforcement Activity IndexAmber

Recent FDPIC enforcement activity includes an enforcement notice to Digitec Galaxus, a decision on PostFinance's biometric voice recognition, an investigation into BLT's bodycam use, and Administrative Court confirmation of an FDPIC processing ban.

Claims: CLM-CH-9eafb0c1

Regulator Funding And CapacityRed

No specific FDPIC headcount or budget figures were confirmed in this research pass.

Absence provenance: not recorded. Searched: FDPIC budget headcount staffing capacity.

Collective Redress And Class ActionsRed

No dedicated collective-redress or class-action mechanism for data protection claims was confirmed for Switzerland in this research pass.

Absence provenance: not recorded. Searched: Switzerland collective redress class action data protection.

Private Right Of ActionAmber

Data subjects may pursue civil claims for breach of personality rights under the Swiss Civil Code, which operates alongside the FADP as a governing text for data subject rights enforcement.

Claims: CLM-CH-afb0c1d2

Recent Developments 180DAmber

Within the last 180 days, reported FDPIC activity includes Digitec Galaxus's implementation of a one-click cookie opt-out (reported mid-February 2026) and the opening of an FDPIC investigation into BLT's use of bodycams (reported late February 2026).

Claims: CLM-CH-b0c1d2e3

Category narrative163 words

The FDPIC can open investigations ex officio or on complaint against controllers and processors and, since the revFADP, may issue binding orders at the conclusion of an investigation — a marked strengthening from its prior merely-recommendatory role. Unlike most European DPAs, the FDPIC is not authorised to impose administrative fines directly on organisations; instead, the revFADP creates criminal offences punishable by fines of up to CHF 250,000 against responsible individuals (not the entity) for a limited, enumerated set of violations. Recent enforcement activity includes an enforcement notice to Digitec Galaxus over cookie-consent practices (with subsequent remediation), a decision concerning PostFinance's biometric voice-recognition system, an investigation opened into BLT's use of bodycams, and Administrative Court confirmation of an FDPIC processing ban — though full text of these matters was paywalled and not independently verified beyond title level. Data subjects may also pursue civil claims for breach of personality rights under the Swiss Civil Code. No dedicated collective-redress/class-action mechanism for data protection claims was confirmed.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceUnder the revised FADP, the FDPIC's position is strengthened such that it will be able to open an investigation, ex officio or following a complaint, against a controller and processor, and to issue an order at the end of the investigation.
  2. ConfirmedOneTrust DataGuidanceUnlike most European data protection supervisory authorities, the FDPIC is not authorised to impose administrative sanctions directly on organisations; individuals may instead be fined up to CHF 250,000 for a limited range of enumerated criminal offences under Article 63 and related provisions of the revFADP.
  3. UncertainOneTrust DataGuidanceRecent FDPIC enforcement matters include an enforcement notice issued to Digitec Galaxus, a decision concerning PostFinance's voice-recognition system, an investigation opened into BLT's bodycam use, and an Administrative Court ruling confirming an FDPIC processing ban.
  4. ProbableOneTrust DataGuidanceThe Swiss Civil Code is listed as a governing text alongside the FADP and its Ordinance for data subject rights matters, providing a civil personality-rights avenue for redress.
  5. UncertainOneTrust DataGuidanceDigitec Galaxus implemented a one-click cookie opt-out mechanism, as reported by the FDPIC in mid-February 2026, following prior enforcement engagement.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Switzerland
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 41 claim(s), 23 source(s) in the cumulative register.