Traffic-light rationale — GreenA comprehensive, currently-in-force omnibus statute with an active, empowered supervisory authority; GDPR-aligned but not identical.
Sub-modules (5)
Regulator And AuthorityGreen
The FDPIC is the federal supervisory authority; cantons additionally maintain their own commissioners for cantonal/communal bodies, creating a partially federated oversight structure alongside the federal regime.
Claims: CLM-CH-1a2b3c4d
Act And InstrumentsGreen
The revFADP and its Ordinance constitute the primary instruments, in force since 1 September 2023, replacing the 1992 FADP and bringing Swiss law closer to GDPR standards.
Claims: CLM-CH-2b3c4d5e
Material ScopeGreen
The FADP applies as an omnibus law to processing of personal data by private persons and federal bodies irrespective of sector; cantonal acts govern cantonal/communal bodies separately.
Claims: CLM-CH-6f708192
Territorial ScopeGreen
The revFADP's territorial scope was broadened, GDPR-style, to capture processing with an effect in Switzerland even if the processing activity is initiated from abroad.
Claims: CLM-CH-3c4d5e6f
Regulator Registration And FilingAmber
There is no general controller-registration/filing regime; instead, non-Swiss controllers meeting territorial-scope criteria must designate and publish a Swiss representative, who is responsible for maintaining the controller's records of processing and producing them to the FDPIC on request.
Claims: CLM-CH-5e6f7081
Category narrative94 words
Switzerland's data protection regime is governed by the revised Federal Act on Data Protection (revFADP, FADP 2020), which entered into force on 1 September 2023 alongside its implementing Ordinance, replacing the 1992 FADP. The regime is enforced by the Federal Data Protection and Information Commissioner (FDPIC/EDÖB), an independent federal authority. The revFADP brings Switzerland into closer alignment with the GDPR while retaining distinctly Swiss features (e.g., no general administrative fining power for the FDPIC, personality-rights-based unlawfulness test). Territorial scope was significantly broadened to reach processing with an effect in Switzerland even where initiated abroad.
Sources and claims (5)
ConfirmedOneTrust DataGuidance — The Federal Data Protection and Information Commissioner (FDPIC) is the federal data protection authority responsible for supervising the FADP.
ConfirmedInternational Association of Privacy Professionals — The revised Swiss Federal Act on Data Protection came into force on 1 September 2023, bringing Switzerland's data protection regime into closer alignment with the EU GDPR.
ConfirmedInternational Association of Privacy Professionals — The revFADP applies to circumstances that have an effect in Switzerland even where the processing activity is initiated abroad, giving the FDPIC competence over any activity with Swiss impact regardless of origin.
ProbableInternational Association of Privacy Professionals — Where the revFADP's extraterritorial scope applies, the controller must appoint and publicly identify a Swiss representative, who is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC on request.
ProbableOneTrust DataGuidance — The FADP is an omnibus law applying to any processing of personal data by private persons and federal bodies, irrespective of sector, while cantonal acts separately govern cantonal and communal bodies.
Traffic-light rationale — AmberStructurally different from GDPR's Art 6 lawful-basis model; sensitive-data protections exist but the consent architecture is comparatively lighter.
Sub-modules (4)
Lawful BasesAmber
Swiss law does not treat the absence of a specified legal basis as per se unlawful; unlawfulness is instead assessed against breach of personality rights.
Claims: CLM-CH-708192a3
Consent ThresholdsGreen
Consent is one of several grounds (alongside contractual necessity, overriding public interest, and public availability of the data) that can legitimize a cross-border transfer under Art 17 revFADP.
Claims: CLM-CH-8192a3b4
Special CategoriesGreen
The revFADP extended the definition of sensitive personal data to explicitly include genetic and biometric data, while retaining a risk-based rather than explicit-consent-centric approach.
Claims: CLM-CH-92a3b4c5
Pseudonymisation And AnonymisationAmber
Anonymised or aggregated data falls outside the FADP's personal-data scope because the person is no longer identifiable; pseudonymised data, by contrast, may still permit re-identification and generally remains in scope.
Claims: CLM-CH-a3b4c5d6
Category narrative80 words
Unlike the GDPR's positive lawful-basis requirement, Swiss law does not require a specified legal basis for processing to be lawful per se; processing is only unlawful if it breaches personality rights under the Civil Code/FADP principles. The revFADP nonetheless expanded the definition of sensitive personal data to include genetic and biometric data and retains a risk-based (rather than explicit-consent-centric) approach to sensitive data. Consent functions primarily as a derogation basis for cross-border transfer and is not a universal processing gateway.
Sources and claims (4)
ProbableOneTrust DataGuidance — Unlike the EU GDPR, Swiss law does not provide that processing of personal data without a specified legal basis is per se illegitimate; legitimacy instead turns on absence of a breach of personality rights.
ProbableOneTrust DataGuidance — Under Article 17 of the revised FADP, a cross-border data transfer may be legitimate where the data subject has consented, in addition to contractual necessity, overriding public interest, or the data having been made publicly accessible by the subject.
ProbableInternational Association of Privacy Professionals — The FADP's definition of sensitive personal data was extended in the revision process to cover biometric and genetic data, while maintaining a risk-based approach rather than the EU's explicit-consent concept for such data.
ProbableOneTrust DataGuidance — Anonymised or aggregated data is not personal data under the FADP because the person is not identifiable, whereas pseudonymised data may still permit re-identification and is generally treated as personal data.
Traffic-light rationale — AmberCore rights are present and GDPR-inspired, but the objection right is narrower and exact response-window detail is unconfirmed.
Sub-modules (5)
Access RightGreen
Article 25 of the revFADP provides a more detailed subject-access right than the prior law's single-sentence entitlement to know whether data is processed.
Claims: CLM-CH-b4c5d6e7
Rectification And ErasureGreen
The revFADP explicitly states a right to erasure (previously only implicit) alongside rectification rights under Art 32.
Claims: CLM-CH-c5d6e7f8
Restriction And ObjectionAmber
A right equivalent to GDPR Art 21 does not exist per se; Swiss law provides a narrower opt-out-style objection right under Art 31(2)(b) revFADP.
Claims: CLM-CH-d6e7f809
Data PortabilityGreen
The right to data portability, copied from the GDPR, is entirely new to Swiss law under the revFADP.
Claims: CLM-CH-e7f8091a
Deadlines And Response WindowsRed
Available sources did not confirm a specific statutory response-time window (analogous to the GDPR's one-month period) for Swiss data subject requests.
Absence provenance: not recorded. Searched: FADP data subject access request deadline response window, revFADP Article 25 response time days.
Category narrative83 words
The revFADP substantially strengthens data subject rights compared to the 1992 law, introducing an explicit right to erasure and a wholly new right to data portability modelled on the GDPR, alongside a more detailed access right (Art 25) and rectification rights (Art 32). The objection right, however, remains narrower than GDPR Art 21 — Swiss law provides an opt-out-style objection right rather than a general right to object on grounds relating to particular circumstances. Statutory response-deadline specifics were not confirmed in available sources.
Sources and claims (4)
ProbableOneTrust DataGuidance — Article 25 of the revised FADP provides a more detailed access right for data subjects than the prior 1992 FADP's general information-request entitlement.
ConfirmedOneTrust DataGuidance — The revised FADP explicitly states a right to erasure, whereas the old FADP only implicitly recognised it, and introduces rectification rights under Article 32.
ProbableOneTrust DataGuidance — A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; instead, Article 31(2)(b) of the revised FADP provides a data subject right to object to processing, essentially limited to an opt-out right.
ConfirmedOneTrust DataGuidance — The right to data portability, copied from the GDPR, is completely new to Swiss law under the revised FADP.
Core accountability infrastructure (DPIA, security, retention, breach notification) is in force and GDPR-adjacent, but breach-notification timing and DPO-threshold specifics carry residual uncertainty.
Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 6-9, 22-24
Traffic-light rationale — AmberCore accountability infrastructure (DPIA, security, retention, breach notification) is in force and GDPR-adjacent, but breach-notification timing and DPO-threshold specifics carry residual uncertainty.
Sub-modules (7)
Accountability And DpiaGreen
Articles 22 and 23 of the revFADP mandate federal bodies and private persons to conduct a Data Protection Impact Assessment where data processing poses high risks to personality or fundamental rights; the FDPIC has published a factsheet with templates and flowcharts.
Claims: CLM-CH-f8091a2b
Dpo RequirementsAmber
No universal mandatory DPO-appointment threshold analogous to GDPR member-state gold-plating was confirmed; the FDPIC operates a reporting portal for DPOs, suggesting appointment is encouraged/registrable rather than confirmed as strictly mandatory across all controllers in the sources reviewed.
Claims: CLM-CH-091a2b3c
Ropa RequirementsGreen
Controllers, including the Swiss representative for foreign controllers, are required to maintain records of processing activities and provide them to the FDPIC upon request.
Claims: CLM-CH-1a2b3c4e
Joint Controller ArrangementsRed
No source reviewed specified a distinct statutory joint-controller regime analogous to GDPR Art 26.
Article 7 of the FADP requires that personal data be protected against unauthorised processing through adequate technical and organisational measures.
Claims: CLM-CH-2b3c4e5f
Breach NotificationAmber
The revFADP introduces an obligation to notify the FDPIC of a data breach as soon as possible where it is likely to result in high risk to the data subject's personality or fundamental rights; no fixed numerical deadline equivalent to the GDPR's 72 hours was confirmed as of the guidance reviewed.
Claims: CLM-CH-3c4e5f60
Retention And DisposalGreen
Article 6(4) of the revised FADP clarifies that data must either be deleted or anonymised once the purpose for its collection has been achieved.
Claims: CLM-CH-4e5f6071
Category narrative96 words
The revFADP introduces mandatory DPIAs for high-risk processing (Arts 22-23), strengthened security-of-processing obligations (Art 7 FADP baseline), an explicit purpose-limitation-driven retention/disposal duty (Art 6(4)), and a new breach-notification obligation owed to the FDPIC 'as soon as possible' where a breach is likely to result in high risk, though no fixed numerical deadline (unlike the GDPR's 72 hours) was confirmed. Records-of-processing obligations attach to controllers (and, for foreign controllers, their Swiss representative). DPO appointment does not appear to carry a universal mandatory threshold as under some GDPR member-state laws; the FDPIC operates a voluntary DPO reporting portal.
Sources and claims (6)
ConfirmedOneTrust DataGuidance — Articles 22 and 23 of the revFADP mandate federal bodies and private individuals to conduct a Data Protection Impact Assessment if data processing poses high risks to personality or fundamental rights.
UncertainOneTrust DataGuidance — The FDPIC operates a dedicated reporting portal for data protection officers, but a universally mandatory DPO-appointment threshold was not confirmed in the sources reviewed for this run.
ProbableInternational Association of Privacy Professionals — The Swiss representative appointed by a non-Swiss controller is responsible for maintaining the controller's record of processing activities and providing it to the FDPIC upon request.
ProbableOneTrust DataGuidance — Article 7 of the FADP requires that personal data be protected against unauthorised processing through adequate technical and organisational measures.
ProbableInternational Association of Privacy Professionals — Controllers are obliged to inform the FDPIC of a data breach as soon as possible when it is likely to result in a high risk to the data subject's personality or fundamental rights, with no confirmed fixed statutory time limit equivalent to the GDPR's 72 hours.
ProbableOneTrust DataGuidance — Article 6(4) of the revised FADP requires that all personal data be either deleted or anonymised once the purpose for its collection has been achieved.
Traffic-light rationale — GreenRobust bidirectional adequacy status (EU since 2000; UK full adequacy) plus a GDPR-mirroring transfer-mechanism toolkit.
Sub-modules (6)
Transfer MechanismsGreen
Available mechanisms include adequacy, SCCs and BCRs under Art 16 revFADP, and derogations under Art 17 (consent, contract necessity, overriding public interest, public availability of data).
Claims: CLM-CH-5f607182
Adequacy ReceivedGreen
Switzerland has held an EU adequacy decision since 2000 (Commission Decision 2000/518/EC) and is listed by the UK government as a 'full adequacy' jurisdiction for restricted transfers.
Claims: CLM-CH-60718293, CLM-CH-718293a4
Adequacy GrantedGreen
The FDPIC maintains its own list of third countries considered to provide adequate protection for outbound Swiss data transfers.
Claims: CLM-CH-8293a4b5
Sccs And BcrsAmber
The FDPIC has issued and periodically updated guidance/templates on Standard Contractual Clauses for use by Swiss controllers.
Claims: CLM-CH-93a4b5c6
Transfer Impact AssessmentRed
No FDPIC-specific formal Transfer Impact Assessment obligation equivalent to post-Schrems II EU practice was confirmed in this research pass, though FDPIC guidance on third-country transfers exists generally.
Absence provenance: not recorded. Searched: FDPIC transfer impact assessment guidance third country.
Data LocalisationRed
No general private-sector data-localisation mandate was confirmed for Switzerland in this research pass.
Absence provenance: not recorded. Searched: Switzerland data localisation requirement FADP, Swiss data residency mandate.
Category narrative81 words
Switzerland offers multiple cross-border transfer mechanisms mirroring the GDPR: adequacy (its own FDPIC-maintained country list plus reliance on the general adequacy concept), Standard Contractual Clauses and Binding Corporate Rules under Art 16 revFADP, and derogations under Art 17 (consent, contractual necessity, overriding public interest, public availability). Switzerland itself has held an EU adequacy decision since 2000 (2000/518/EC) and is listed by the UK as a 'full adequacy' jurisdiction. Data-localisation mandates in the private sector were not confirmed in this research pass.
Sources and claims (5)
ProbableOneTrust DataGuidance — Cross-border transfers from Switzerland may rely on adequacy, Standard Contractual Clauses or Binding Corporate Rules under Article 16 of the revised FADP, or derogations under Article 17 including consent, contractual necessity, overriding public interest, or public availability of the data.
ConfirmedEUR-Lex / Official Journal of the European Union — Switzerland is considered by the European Commission as providing an adequate level of data protection, per Commission Decision 2000/518/EC of 26 July 2000, and remains on the Commission's current list of adequate countries.
ConfirmedICO — The UK government's adequacy regulations list Switzerland among the jurisdictions with 'full adequacy' for restricted transfers under UK GDPR.
ProbableOneTrust DataGuidance — The FDPIC establishes and maintains its own list of third countries considered to provide an adequate level of protection for personal data transferred from Switzerland.
UncertainOneTrust DataGuidance — The FDPIC has updated its guidelines/templates concerning Standard Contractual Clauses available for use by Swiss data exporters.
Traffic-light rationale — AmberConfirmed financial-sector and employment overlays; several other sectoral sub-modules carry no confirmed findings.
Sub-modules (7)
Financial Sector OverlayAmber
FINMA maintains a Data Processing Ordinance that has been amended over time and applies additional sector rules to supervised financial institutions, layered on top of the general FADP baseline.
Claims: CLM-CH-a4b5c6d7
Health Sector OverlayRed
No health-sector-specific data protection overlay was confirmed in this research pass beyond the general FADP baseline.
Absence provenance: not recorded. Searched: Switzerland health data protection sectoral law FADP.
Telecoms And EprivacyRed
No specific e-privacy/telecoms overlay content was confirmed in this research pass, though the general Telecommunications Act framework was referenced tangentially.
The Federal Code of Obligations contains restrictions on the processing of employee data by employers, supplementing the general FADP.
Claims: CLM-CH-b5c6d7e8
Credit And ScoringRed
No dedicated Swiss credit-scoring regulatory overlay was confirmed in this research pass.
Absence provenance: not recorded. Searched: Switzerland credit scoring data protection regulation.
EducationRed
No education-sector-specific data protection overlay was confirmed in this research pass.
Absence provenance: not recorded. Searched: Switzerland education sector data protection FADP.
InsuranceRed
No insurance-sector-specific data protection overlay was confirmed in this research pass.
Absence provenance: not recorded. Searched: Switzerland insurance sector data protection FADP FINMA.
Category narrative58 words
Switzerland lacks dedicated omnibus sectoral data-protection statutes, but sector-specific instruments layer additional obligations onto the FADP baseline: FINMA maintains an ordinance on data processing applicable to supervised financial institutions, and the Federal Code of Obligations restricts employer processing of employee data. Health, telecoms/e-privacy, credit-scoring, education and insurance-specific overlays were not confirmed with sufficient specificity in this research pass.
Sources and claims (2)
UncertainOneTrust DataGuidance — FINMA maintains and has amended an Ordinance on Data Processing applicable to supervised financial institutions, operating alongside the general FADP regime.
ProbableOneTrust DataGuidance — The Federal Code of Obligations contains restrictions on the processing of employee data, supplementing the general FADP framework.
Traffic-light rationale — AmberActive FDPIC cookie/consent enforcement interest confirmed at title level; several adtech sub-modules lack confirmed Swiss-specific rules.
Sub-modules (6)
Cookies And TrackersAmber
The FDPIC has published cookie guidelines addressing tracker consent practices for Swiss-facing digital services.
Claims: CLM-CH-c6d7e8f9
Dark PatternsAmber
The FDPIC issued an enforcement notice to Digitec Galaxus concerning its cookie-consent interface, and the retailer subsequently implemented a one-click cookie opt-out mechanism.
Claims: CLM-CH-d7e8f900
Opt Out SignalsRed
No Swiss-specific recognition of browser-based opt-out signals (e.g., Global Privacy Control) was confirmed in this research pass.
Absence provenance: not recorded. Searched: Switzerland Global Privacy Control opt-out signal FADP.
Clean Rooms And DcrRed
No Swiss-specific data clean-room / data-collaboration-room regulatory content was confirmed.
Absence provenance: not recorded. Searched: Switzerland data clean room regulation FADP.
Cross Context AdvertisingRed
No CPRA-style 'sale'/'share' cross-context advertising concept exists under the FADP baseline; no confirmed Swiss equivalent was located.
Absence provenance: not recorded. Searched: Switzerland cross-context advertising data sharing rules.
Direct MarketingGreen
Postal direct marketing is permitted on an opt-out basis where the recipient's address has been made publicly available and no objection has been registered.
Claims: CLM-CH-e8f9001a
Category narrative73 words
The FDPIC has issued cookie guidelines and has taken direct enforcement interest in dark-pattern-style consent practices, including an enforcement notice to a major Swiss e-commerce retailer (Digitec Galaxus) that was followed by the company's implementation of a one-click cookie opt-out. Direct-marketing rules permit postal marketing on an opt-out basis where the recipient's address is publicly available. Opt-out signal standards (e.g., GPC), clean-room/data-collaboration rules, and cross-context-advertising-specific rules were not confirmed in this research pass.
Sources and claims (3)
UncertainOneTrust DataGuidance — The FDPIC has published guidelines addressing the use of cookies and trackers, including English-language versions of that guidance.
UncertainOneTrust DataGuidance — The FDPIC issued an enforcement notice concerning Digitec Galaxus's cookie-consent practices, after which the retailer implemented a one-click cookie opt-out mechanism.
ProbableOneTrust DataGuidance — Postal marketing in Switzerland operates on an opt-out mechanism; use of a recipient's publicly available postal address for marketing purposes is permitted absent objection.
Biometric/genetic categorisation and FDPIC AI engagement are confirmed; the profiling/ADM regime is structurally narrower than the GDPR and carries residual ambiguity.
Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 2(2)(c), 21, 31
Traffic-light rationale — AmberBiometric/genetic categorisation and FDPIC AI engagement are confirmed; the profiling/ADM regime is structurally narrower than the GDPR and carries residual ambiguity.
Sub-modules (6)
Profiling RestrictionsAmber
A right equivalent to GDPR Article 21 does not exist per se; Swiss law instead provides a narrower opt-out-style objection right under Art 31(2)(b) revFADP.
Claims: CLM-CH-f900112b
Automated Decision Making TransparencyAmber
Article 21 of the revFADP imposes information duties on controllers in respect of automated individual decision-making, with willful provision of false information in that context subject to criminal sanction.
Claims: CLM-CH-00112b3c
Ai Risk AssessmentsAmber
The FDPIC has issued a press release addressing the intersection of artificial intelligence and data protection, indicating active regulatory attention though no confirmed dedicated Swiss AI-specific statutory risk-assessment regime.
Claims: CLM-CH-112b3c4e
Biometric RegimeAmber
The FDPIC issued a decision addressing PostFinance's use of voice-recognition (biometric) technology, reflecting active enforcement engagement with biometric processing; biometric data is also now expressly a sensitive-data category under the revFADP.
Claims: CLM-CH-2b3c4e60
Genetic DataGreen
Genetic data was brought within the FADP's sensitive personal data category as part of the FADP revision.
Claims: CLM-CH-3c4e6071
State Surveillance CarveoutsAmber
Article 2(2)(c) of the FADP provides that the Act may not apply to processing of personal data within the frame of administrative, civil or criminal proceedings once pending, though the requirements of the FADP still apply to investigations carried out by police prior to such proceedings becoming pending.
Claims: CLM-CH-4e607182
Category narrative104 words
The revFADP does not replicate a general GDPR Article 21-style objection right but does impose information duties on controllers regarding automated individual decision-making (Art 21 revFADP information obligations, distinct numbering from the GDPR). Biometric and genetic data were brought within the sensitive-data category by the revision, and the FDPIC has demonstrated active enforcement interest in biometric processing (e.g., a decision concerning PostFinance's voice-recognition system) and has issued a press release specifically addressing AI and data protection. State-surveillance carve-outs exist via Art 2(2)(c) FADP, which disapplies the Act to processing within pending administrative, civil, or criminal proceedings (though pre-proceeding police investigatory processing remains in scope).
Sources and claims (6)
ProbableOneTrust DataGuidance — A right equivalent to Article 21 of the GDPR does not exist per se under Swiss law; Article 31(2)(b) of the revised FADP instead provides a data subject right to object, essentially limited to an opt-out right.
ProbableInternational Association of Privacy Professionals — Article 21 of the revFADP concerns automated individual decision-making, and willful provision of false or incomplete information in that context is subject to criminal penalty under Article 60.
UncertainOneTrust DataGuidance — The FDPIC has issued a press release specifically addressing artificial intelligence and data protection.
UncertainOneTrust DataGuidance — The FDPIC issued a decision concerning PostFinance's use of voice-recognition biometric technology.
ProbableOneTrust DataGuidance — Article 2(2)(c) of the FADP provides that the Act may not apply to processing of personal data in the frame of administrative, civil, or criminal proceedings once pending, though FADP requirements still apply to police investigations carried out prior to such proceedings becoming pending.
General legislative intent to protect minors is confirmed, but no specific operative mechanism (age threshold, parental consent procedure, profiling ban) was substantiated by available sources.
Primary frameworkFederal Act on Data Protection (FADP), revised version (general provisions)
Traffic-light rationale — RedGeneral legislative intent to protect minors is confirmed, but no specific operative mechanism (age threshold, parental consent procedure, profiling ban) was substantiated by available sources.
Sub-modules (5)
Age VerificationRed
No specific statutory age-of-consent threshold for data processing under the FADP was confirmed in this research pass.
Absence provenance: not recorded. Searched: Swiss FADP minors children data protection special categories genetic biometric Article 5.
Parental ConsentAmber
The revFADP's revision process was explicitly framed as seeking alignment with European standards on the protection of minors, though the specific parental-consent mechanism was not detailed in sources reviewed.
Claims: CLM-CH-6071829e
Minor Profiling BansRed
No minor-specific profiling ban was confirmed in this research pass.
Absence provenance: not recorded. Searched: Switzerland minor profiling ban FADP.
Education SettingsRed
No education-setting-specific children's-data rules were confirmed in this research pass.
Absence provenance: not recorded. Searched: Switzerland education data protection children FADP.
Dependent AdultsRed
No dependent-adult-specific data protection provisions were confirmed in this research pass.
Absence provenance: not recorded. Searched: Switzerland dependent adults elderly data protection FADP.
Category narrative53 words
The revFADP's legislative history explicitly cites the protection of minors as one of the European-standard alignment goals of the revision. However, specific mechanisms — an age-of-consent threshold for data processing, statutory parental-consent procedures, minor-specific profiling bans, education-setting rules, and dependent-adult protections — were not confirmed with the specificity available in this research pass.
Sources and claims (1)
ProbableOneTrust DataGuidance — The revFADP's revision was explicitly framed as seeking to include provisions complying with European standards on, among other things, the protection of minors.
Strengthened FDPIC investigative/order powers and an active enforcement docket are confirmed; the no-administrative-fine model and gaps in collective-redress and funding/capacity data warrant amber rather than green.
Primary frameworkFederal Act on Data Protection (FADP), revised version, Arts 49-51, 60-63
Traffic-light rationale — AmberStrengthened FDPIC investigative/order powers and an active enforcement docket are confirmed; the no-administrative-fine model and gaps in collective-redress and funding/capacity data warrant amber rather than green.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
The FDPIC may open investigations ex officio or following complaint and issue binding orders, but is not authorised to impose administrative fines on organisations; instead, individuals may be fined up to CHF 250,000 for a limited set of enumerated criminal offences under the revFADP.
Claims: CLM-CH-71829eaf, CLM-CH-829eafb0
Enforcement Activity IndexAmber
Recent FDPIC enforcement activity includes an enforcement notice to Digitec Galaxus, a decision on PostFinance's biometric voice recognition, an investigation into BLT's bodycam use, and Administrative Court confirmation of an FDPIC processing ban.
Claims: CLM-CH-9eafb0c1
Regulator Funding And CapacityRed
No specific FDPIC headcount or budget figures were confirmed in this research pass.
Absence provenance: not recorded. Searched: FDPIC budget headcount staffing capacity.
Collective Redress And Class ActionsRed
No dedicated collective-redress or class-action mechanism for data protection claims was confirmed for Switzerland in this research pass.
Absence provenance: not recorded. Searched: Switzerland collective redress class action data protection.
Private Right Of ActionAmber
Data subjects may pursue civil claims for breach of personality rights under the Swiss Civil Code, which operates alongside the FADP as a governing text for data subject rights enforcement.
Claims: CLM-CH-afb0c1d2
Recent Developments 180DAmber
Within the last 180 days, reported FDPIC activity includes Digitec Galaxus's implementation of a one-click cookie opt-out (reported mid-February 2026) and the opening of an FDPIC investigation into BLT's use of bodycams (reported late February 2026).
Claims: CLM-CH-b0c1d2e3
Category narrative163 words
The FDPIC can open investigations ex officio or on complaint against controllers and processors and, since the revFADP, may issue binding orders at the conclusion of an investigation — a marked strengthening from its prior merely-recommendatory role. Unlike most European DPAs, the FDPIC is not authorised to impose administrative fines directly on organisations; instead, the revFADP creates criminal offences punishable by fines of up to CHF 250,000 against responsible individuals (not the entity) for a limited, enumerated set of violations. Recent enforcement activity includes an enforcement notice to Digitec Galaxus over cookie-consent practices (with subsequent remediation), a decision concerning PostFinance's biometric voice-recognition system, an investigation opened into BLT's use of bodycams, and Administrative Court confirmation of an FDPIC processing ban — though full text of these matters was paywalled and not independently verified beyond title level. Data subjects may also pursue civil claims for breach of personality rights under the Swiss Civil Code. No dedicated collective-redress/class-action mechanism for data protection claims was confirmed.
Sources and claims (5)
ConfirmedOneTrust DataGuidance — Under the revised FADP, the FDPIC's position is strengthened such that it will be able to open an investigation, ex officio or following a complaint, against a controller and processor, and to issue an order at the end of the investigation.
ConfirmedOneTrust DataGuidance — Unlike most European data protection supervisory authorities, the FDPIC is not authorised to impose administrative sanctions directly on organisations; individuals may instead be fined up to CHF 250,000 for a limited range of enumerated criminal offences under Article 63 and related provisions of the revFADP.
UncertainOneTrust DataGuidance — Recent FDPIC enforcement matters include an enforcement notice issued to Digitec Galaxus, a decision concerning PostFinance's voice-recognition system, an investigation opened into BLT's bodycam use, and an Administrative Court ruling confirming an FDPIC processing ban.
ProbableOneTrust DataGuidance — The Swiss Civil Code is listed as a governing text alongside the FADP and its Ordinance for data subject rights matters, providing a civil personality-rights avenue for redress.
UncertainOneTrust DataGuidance — Digitec Galaxus implemented a one-click cookie opt-out mechanism, as reported by the FDPIC in mid-February 2026, following prior enforcement engagement.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Switzerland
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 41 claim(s), 23 source(s) in the cumulative register.