Article 24 FADP notification obligation — "likely high risk" trigger and controller duty
Switzerland's breach notification regime is set out in Article 24 of the Federal Act on Data Protection (FADP), which entered into force on 1 September 2023. Article 24 paragraph 1 requires the controller to notify the Federal Data Protection and Information Commissioner (FDPIC) of a data security breach "as soon as possible" after becoming aware of it if the breach is likely to result in a high risk to the personality or fundamental rights of the data subject. A controller is defined in Article 4(i) FADP as the natural or legal person who, alone or jointly with others, determines the purposes and means of processing.
## Definition of "data security breach"
Article 5 letter h FADP defines a data security breach as personal data that are accidentally or unlawfully lost, deleted, destroyed or modified, or that are disclosed or made accessible to unauthorised persons. This definition closely parallels GDPR Article 4(12) ("a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data"). The FADP provision applies to both private-sector controllers and federal bodies.
## The "likely high risk" threshold
Notification to the FDPIC is mandatory only when the breach is likely to result in a high risk. Article 24(1) does not define "high risk"; the FDPIC's Guidelines on Data Breaches (published February 2025 and available at edoeb.admin.ch) interpret the standard as follows:
- Controllers must first assess whether the breach has already harmed the personality or fundamental rights of natural persons.
- The statutory criterion of "likelihood" requires controllers to include in the assessment the consequences of the breach that "can neither be conclusively measured nor can be predicted with certainty."
The Guidelines state that "the likely high risk mentioned in Article 24 paragraph 1 FADP must be identified without taking into account measures that the controller only plans, announces or initiates after the data security breach." However, the FDPIC's published practice permits controllers to credit immediate measures taken before reporting "where these measures demonstrably excluded or minimised the anticipated effects of any personal data breach" (for example, quickly regaining control of temporarily inaccessible data and establishing with sufficient certainty within hours, via logs, that no improper processing occurred). The Guidelines note that "in situations of doubt where a high risk cannot be sufficiently excluded, controllers" should report.
## Notification timeline: "as soon as possible"
Article 24(1) requires notification "as soon as possible" after the controller becomes aware of the breach. Unlike GDPR Article 33(1), which imposes a 72-hour deadline, the FADP does not fix a numeric time limit. The FDPIC's Guidelines interpret "as soon as possible" to mean the controller must notify without undue delay once the risk assessment confirming likely high risk is complete.
## Content of the notification
The FDPIC's Guidelines state that "the report must contain a description of the circumstances of the breach and the controller's assessment of its implications, and include in particular details of the type, time, duration and extent of the breach and its already known and anticipated effects on the data subjects." The FDPIC operates an online DataBreach reporting portal at edoeb.admin.ch/meldeportale/databreach for controllers to submit notifications.
## Controller vs. processor responsibilities
Article 24 places the notification duty on the controller. Where processing is carried out by a processor on behalf of the controller, the processor is obliged under Article 9 FADP (read with Article 7(8) of the Data Protection Ordinance) to inform the controller of any breach of data security. Critically, the processor's duty to inform the controller is not subject to a risk assessment; the FDPIC's Guidelines state that "the data processor must inform the controller of any breach of data security, regardless of whether it is likely to result in a high risk to the privacy or fundamental rights of the data subject."
## Enforcement and penalties
Controllers who fail to notify the FDPIC when required may face administrative measures under Article 51 FADP; the FDPIC may order the controller to take specified action, including (under Art. 24(4)) informing the data subjects directly. Intentional violation of the Art. 24 notification obligation may also trigger criminal penalties under Articles 60–63 FADP, which establish individual (not corporate) liability for intentional breaches; fines of up to CHF 250,000 may be imposed. There are no criminal penalties for negligent breaches of the notification duty (Arts. 60–63 apply to intentional offences only).
Source: Federal Act on Data Protection (FADP), Art. 24 Source: FDPIC Guidelines on Data Breaches (February 2025) Source: FDPIC DataBreach Reporting Portal Source: Swiss Federal Council — New Federal Act on Data Protection (effective 1 September 2023)
Article 24(4) FADP notification to data subjects — "necessary for protection" trigger and FDPIC order power
Article 24 paragraph 4 FADP establishes a separate obligation to inform data subjects directly about a breach, distinct from the controller's duty to notify the FDPIC under paragraph 1. The controller must inform affected data subjects when notification is "necessary to protect these persons" or when the FDPIC requests it. This Article 24(4) duty is triggered independently of the "likely high risk" threshold that governs reporting to the FDPIC; a controller may be required to inform data subjects even when no FDPIC notification was due, and vice versa.
## The "necessary for protection" standard
Article 24(4) does not define when notification to data subjects is "necessary to protect these persons." The FDPIC Guidelines on Data Breaches (published February 2025 and available at edoeb.admin.ch) interpret the provision as follows:
- The obligation to notify data subjects pursuant to paragraph 4 is to be interpreted independently of paragraph 1 and the concept of high risk used there. A controller might breach the 72-hour FDPIC reporting threshold under paragraph 1 without triggering a data-subject notification duty, or conversely be obliged to inform data subjects directly even when FDPIC notification was not required.
- "It must be assumed that data subjects require the protection referred to in Article 24 paragraph 4 FADP if they can or must take action themselves to minimise or avert harm from a data security breach." For example, if credentials (passwords, access tokens, payment-card numbers) have been exposed and data subjects must change passwords, monitor accounts, or request card reissuance, notification is necessary for their protection.
- The Guidelines state that "if the controller can credibly demonstrate that the data subjects are already sufficiently aware of a data breach and its consequences without requiring additional information and that they know what measures they can or must take to protect themselves, the duty to inform can be deemed to have been fulfilled." Where a breach is already public (widely reported in media, or disclosed by a processor or third party), and data subjects have received adequate actionable guidance, the controller's separate notification obligation may be satisfied.
## When the FDPIC orders notification
Even when the controller concludes that direct notification is not "necessary for protection," Article 24 paragraph 4 gives the FDPIC the power to order the controller to inform the data subjects. The FDPIC may issue such an order under its broader administrative-measures authority in Article 51 FADP. When the FDPIC orders notification, the controller must comply regardless of its own risk assessment.
The FDPIC's Guidelines note that Article 15 paragraph 1 of the Data Protection Ordinance (DPO) lists the information that may enable the FDPIC to take the steps required to help the persons affected by the breach, including ordering that they be informed. The FDPIC can exercise this power after receiving a notification under Article 24(1) or following its own investigation under Article 49 FADP.
## Content and method of data-subject notification
Neither Article 24(4) nor the DPO prescribes specific content for data-subject notifications. The FDPIC's Guidelines state that the notification should describe:
- the nature and scope of the breach (what personal data were affected, when the breach occurred or was discovered, how it happened);
- the anticipated effects on the data subject's personality or fundamental rights;
- what measures the data subject can or must take to minimise or avert harm (e.g., "change your password immediately," "monitor your bank statements for unauthorized transactions," "enable two-factor authentication"); and
- contact details for the controller so the data subject can obtain further information or exercise their rights under Articles 25–28 FADP (right of access, rectification, erasure, restriction).
There is no statutory timeline for data-subject notification under Article 24(4), but the FDPIC's Guidelines emphasize that notification should be prompt once the "necessary for protection" threshold is met, so that data subjects can take protective action without undue delay.
The controller may deliver notification by any effective means — email (if the controller has verified email addresses for the affected individuals), postal mail, direct messaging, or public notice if individual contact is impossible and publication is proportionate (for example, where the breach affects a large, unidentifiable population and the controller cannot feasibly identify all affected persons).
## Controller obligation; processor reporting
As with FDPIC notification under Article 24(1), the Article 24(4) duty to inform data subjects rests on the controller. Where a processor discovers the breach, the processor must inform the controller under Article 9 FADP (read with Article 7(8) DPO), and the controller then assesses whether Article 24(4) notification is required. The FDPIC's Guidelines state that "the data processor must inform the controller of any breach of data security, regardless of whether it is likely to result in a high risk to the privacy or fundamental rights of the data subject."
## Enforcement and penalties
Failure to inform data subjects when notification is "necessary for protection" or when the FDPIC has ordered it may result in administrative measures under Article 51 FADP, including a formal order to notify the data subjects (if not yet done) and potentially other remedial steps. Intentional violation of the Article 24(4) duty may also trigger criminal penalties under Articles 60–63 FADP: fines up to CHF 250,000 may be imposed on natural persons (corporate liability does not exist under FADP; only natural persons — officers, directors, employees — face criminal exposure). There are no criminal penalties for negligent breaches of the notification duty (Arts. 60–63 apply to intentional offenses only).
The FDPIC's Guidelines note that Article 24 paragraph 6 FADP provides that mandatory reports to the FDPIC (and voluntary notifications) may not be used in criminal proceedings against the person subject to the reporting obligation without that person's consent. This privilege does not extend to the breach itself or to subsequent conduct, only to the fact of notification.
Source: Federal Act on Data Protection (FADP), Art. 24 Source: FDPIC Guidelines on Data Breaches (February 2025), PDF pages 12–14 Source: FDPIC DataBreach Reporting Portal — data-subject notification guidance
Article 24(3) FADP breach register — mandatory recordkeeping for all data security breaches
Article 24 paragraph 3 of the Federal Act on Data Protection (FADP) imposes a recordkeeping obligation on controllers: the controller must maintain a register of all data security breaches, whether or not the breach met the "likely high risk" threshold that triggers mandatory notification to the FDPIC under Article 24(1) or direct notification to data subjects under Article 24(4). This register obligation applies to every data security breach as defined in Article 5 letter h FADP — personal data that are accidentally or unlawfully lost, deleted, destroyed, modified, disclosed, or made accessible to unauthorised persons — and operates independently of the risk assessment that governs external reporting.
## Scope: all breaches must be logged
Article 24(3) does not condition the recordkeeping duty on a risk threshold. The controller must log every data security breach of which it becomes aware, including:
- breaches that the controller assessed as not likely to result in a high risk (and therefore did not report to the FDPIC under Article 24(1));
- breaches that were contained or remediated before any harm occurred;
- unsuccessful or attempted breaches, to the extent they resulted in unauthorized access, loss, destruction, or modification of personal data (the Article 5(h) definition requires that the incident actually affected personal data, not merely the controller's systems);
- breaches discovered by a processor and reported to the controller under Article 9 FADP and Article 7(8) of the Data Protection Ordinance (DPO).
The FDPIC Guidelines on Data Breaches (published February 2025) state that the register must capture all incidents meeting the Article 5(h) definition, regardless of severity. This ensures that the controller maintains a complete audit trail for FDPIC inspection under Article 51 FADP (administrative investigation powers) and for its own internal accountability under Article 7 FADP (data security by design and by default).
## Required content of the breach register
Article 24 paragraph 3 FADP does not specify the minimum contents of the breach register. However, the FDPIC Guidelines recommend that the register include, for each breach:
- date and time the breach occurred (or was first discovered, if the occurrence date is unknown);
- nature of the breach — whether it involved loss, deletion, destruction, modification, unauthorized disclosure, or unauthorized access (matching the Article 5(h) categories);
- categories and approximate volume of personal data affected (e.g., "customer contact details: ~5,000 records," "employee health records: 120 individuals");
- circumstances of the breach — how it occurred (technical failure, human error, cyberattack, insider misconduct, physical theft);
- assessment of the likely risk to data subjects' personality or fundamental rights, documenting why the controller concluded the breach did or did not meet the "likely high risk" threshold for FDPIC notification;
- measures taken or planned to contain the breach, mitigate harm, and prevent recurrence;
- whether the breach was notified to the FDPIC under Article 24(1), to data subjects under Article 24(4), or neither (and the rationale if neither).
The Guidelines emphasize that the register must be sufficiently detailed to allow the FDPIC, during an investigation under Articles 49–51 FADP, to verify that the controller correctly assessed each breach and complied with its notification obligations. A bare log of incident dates without supporting analysis will not satisfy the Article 24(3) duty.
## Form and location: no mandated format
Article 24(3) does not prescribe a specific format or technical implementation for the breach register. The controller may maintain the register:
- in a dedicated breach-log database or incident-response platform;
- as part of its broader information-security incident log (permitted under Article 4 DPO, which requires logging of data storage, alteration, reading, disclosure, deletion, and destruction during automated processing), provided that data-security breaches under Article 5(h) are clearly identified and the Article 24(3) content is captured;
- in paper or electronic form, though electronic is recommended for searchability and retention.
The register must be accessible to the FDPIC on request. Article 51 paragraph 1 FADP authorizes the FDPIC to request documents and information during administrative investigations, and Article 24(3) implicitly requires the controller to produce the breach register when the FDPIC exercises that power.
## Retention period
Unable to confirm as of 2026-06-01.
The FADP and DPO do not specify a minimum retention period for the Article 24(3) breach register. The FDPIC Guidelines (February 2025) do not address retention duration. Controllers should apply a reasonable retention period aligned with general data-protection recordkeeping principles under Article 6 paragraph 3 FADP (personal data must be destroyed or anonymised as soon as they are no longer required for the purpose of processing) and any sector-specific retention obligations (e.g., financial-services recordkeeping rules). A retention period of at least three years is common practice to allow for FDPIC investigations and civil claims under Article 32 FADP (three-year statute of limitations for personality-rights claims under Articles 60(1) and 28a of the Swiss Civil Code). The controller should document its chosen retention policy in its internal processing regulations under Article 5 DPO (if the controller is subject to that requirement).
## Controller vs. processor responsibility
The Article 24(3) duty to maintain the breach register rests on the controller, not the processor. However, processors have a related obligation under Article 9 FADP (controller-processor contracts) read with Article 7(8) DPO: the processor must inform the controller of any data security breach without delay, and that duty is not subject to a risk assessment — the processor reports every breach to the controller, and the controller then logs it in the Article 24(3) register and assesses whether FDPIC or data-subject notification is required.
Where a processor maintains its own internal breach log for operational purposes, that log does not substitute for the controller's Article 24(3) register. The controller remains obliged to maintain its own register of all breaches affecting personal data for which it is controller, including breaches that occurred on the processor's systems.
## Enforcement and penalties
Failure to maintain the Article 24(3) breach register may result in administrative measures under Article 51 FADP. The FDPIC may order the controller to establish or complete the register and produce it for inspection. There is no standalone criminal penalty for failing to maintain the register (Articles 60–63 FADP criminalize specific intentional violations, such as intentional breach of the Article 24(1) notification duty or intentional violation of the Article 19 duty to inform data subjects about processing, but Article 24(3) recordkeeping is not enumerated). However, if the controller's failure to log breaches is part of a broader pattern of intentional disregard for Article 7 FADP data-security obligations, the FDPIC may refer the matter for criminal investigation under Article 61 FADP (intentional violation of data-security duties, punishable by fine up to CHF 250,000 for natural persons).
The Article 24(3) register also plays a defensive role: during an FDPIC investigation under Article 49 FADP (triggered by a data-subject complaint, a third-party report, or the FDPIC's own initiative), a complete, contemporaneous breach register demonstrates that the controller has systematically assessed and responded to data-security incidents. Conversely, the absence of a register — or a register that omits known breaches — is evidence of non-compliance and will weigh against the controller when the FDPIC exercises its Article 51 enforcement discretion.
Source: Federal Act on Data Protection (FADP), Art. 24 Source: FDPIC Guidelines on Data Breaches (February 2025)
Parallel breach notification obligations — when FADP Article 24 applies alongside GDPR Article 33 or other cross-border regimes
Switzerland's Article 24 FADP breach notification obligation operates independently of parallel duties under the EU GDPR, UK GDPR, or other data-protection regimes. Controllers operating in multiple jurisdictions—particularly those with both Swiss and EU/EEA data subjects, or with both Swiss and EU/UK establishments—frequently face concurrent breach notification duties to the FDPIC under Article 24 FADP and to one or more EU/EEA supervisory authorities under GDPR Article 33. Each regime's notification trigger, risk threshold, timeline, and content requirements apply separately; satisfying one does not satisfy the other.
## When parallel obligations arise
Parallel breach notification obligations arise whenever a single data-security breach falls within the territorial and material scope of both FADP and GDPR (or another regime). Common scenarios include:
- Swiss controller with EU data subjects: A controller established in Switzerland (or whose processing falls within the scope of Article 3 FADP) suffers a breach affecting personal data of individuals habitually resident in the EU. The Swiss controller must assess notification under Article 24(1) FADP (to the FDPIC if "likely high risk" to personality or fundamental rights) and under GDPR Article 33(1) (to the lead or concerned EU supervisory authority unless the breach is "unlikely to result in a risk" to rights and freedoms). The GDPR applies extraterritorially under Article 3(2) when the processing relates to offering goods or services to EU data subjects or monitoring their behaviour, even if the controller has no EU establishment.
- Swiss controller with both Swiss and EU data subjects: A breach affecting a mixed population (e.g., a Swiss e-commerce platform's customer database) triggers both FADP Article 24 (for Swiss residents) and GDPR Article 33 (for EU residents). The controller must conduct two separate risk assessments—one under the FADP "likely high risk" standard (Art. 24(1) FADP) and one under the GDPR "unlikely to result in a risk" threshold (Art. 33(1) GDPR)—because the thresholds differ and the definitions are not identical.
- EU/EEA controller with Swiss establishment or Swiss data subjects: A controller established in the EU but with a Swiss branch or representative, or whose processing otherwise falls within Article 3 FADP, must notify the FDPIC under Article 24 FADP in addition to its GDPR Article 33 notification to the lead EU supervisory authority. The EU Commission's adequacy decision for Switzerland (adopted 15 January 2024 and recognising Switzerland as providing adequate data protection under the GDPR) does not exempt EU controllers from complying with FADP when FADP applies—it permits transfers of personal data from the EU to Switzerland without additional safeguards, but does not merge the two regimes' breach-notification rules.
- UK GDPR, CCPA/CPRA, LGPD, PIPL, and other regimes: Controllers subject to both FADP and the UK's Data Protection Act 2018 / UK GDPR (Article 33 UK GDPR mirrors GDPR Art. 33), or to California's CPRA breach-notification duties (Cal. Civ. Code § 1798.82 for California residents), or to Brazil's LGPD Article 48, or to China's PIPL Articles 57–58, face the same parallel-obligation analysis. Each regime's notification duty applies independently when its jurisdictional triggers are met.
## Distinct risk thresholds and timelines
FADP Article 24(1) requires notification to the FDPIC only when the breach is "likely to result in a high risk" to the data subject's personality or fundamental rights. The FDPIC's Guidelines on Data Breaches (published February 2025) interpret this as a forward-looking likelihood assessment incorporating both harm that has already occurred and consequences "that can neither be conclusively measured nor can be predicted with certainty." The FADP does not impose a numeric time limit; Article 24(1) requires notification "as soon as possible" after the controller becomes aware of the breach and completes its risk assessment.
GDPR Article 33(1) requires notification to the supervisory authority unless the breach is "unlikely to result in a risk" to the rights and freedoms of natural persons—a lower, more permissive threshold than FADP's "likely high risk." In practice, most breaches that meet the FADP notification threshold will also meet the GDPR threshold, but the reverse is not always true: a breach that triggers GDPR notification (because it is not "unlikely to result in a risk") may fall below the FADP "likely high risk" bar and therefore not require FDPIC notification. The GDPR imposes a 72-hour deadline (Art. 33(1): "without undue delay and, where feasible, not later than 72 hours after having become aware of it"), which is stricter than FADP's "as soon as possible" standard.
Consequently, a controller subject to both regimes may be required to notify an EU supervisory authority within 72 hours under GDPR Article 33 even when it has determined that the breach does not meet the FADP Article 24(1) "likely high risk" threshold and therefore does not notify the FDPIC. Conversely, if a breach meets the FADP "likely high risk" trigger, the controller must notify the FDPIC "as soon as possible" under Article 24(1) and (if GDPR also applies) notify the relevant EU supervisory authority within 72 hours under GDPR Article 33(1).
## Parallel supervisory authority competence
The FDPIC's guidance on Standard Contractual Clauses (published August 2021 and updated for the revised FADP, available at edoeb.admin.ch) confirms the principle of parallel supervisory jurisdiction:
> "However, for data transfers that are subject to both the FADP and the GDPR, there are two parallel supervisory authorities. Where the data transfers are subject to the FADP, the FDPIC is the competent supervisory body. However, for transfers within the scope of the GDPR, the competence [lies with the relevant EU/EEA supervisory authority]."
The FDPIC guidance further states that when using the EU's Standard Contractual Clauses (SCCs) for cross-border transfers subject to both FADP and GDPR, Annex I.C should designate the FDPIC as the supervisory authority for data transfers covered by the FADP and an EU data protection authority for data transfers covered by the GDPR. This dual-designation principle applies equally to breach notification: where both regimes apply, the controller must notify both the FDPIC (under FADP Art. 24) and the relevant EU/EEA supervisory authority (under GDPR Art. 33), because each authority supervises compliance with its own regime.
## One-stop-shop does not eliminate parallel FADP obligations
Under GDPR Article 56 (the "one-stop-shop" mechanism), a controller or processor with establishments in multiple EU/EEA member states must deal primarily with a single lead supervisory authority for cross-border processing. The EDPB's Guidelines 9/2022 on personal data breach notification (adopted 4 April 2023, version 2.0) explain that when a breach involves cross-border processing, the controller notifies the lead supervisory authority (or, at minimum, the local supervisory authority where the breach took place), and the lead authority coordinates with concerned supervisory authorities under the consistency mechanism (Arts. 63–65 GDPR).
Switzerland is not part of the GDPR's one-stop-shop mechanism. Although the EU Commission has recognised Switzerland as adequate under the GDPR (adequacy decision of 15 January 2024), Switzerland is not an EU/EEA member state, and the FDPIC is not a supervisory authority within the GDPR Chapter VI cooperation framework. Therefore:
- A controller with its main establishment in Switzerland and EU establishments must notify the FDPIC under FADP Article 24 (if the "likely high risk" threshold is met) and separately notify the lead EU supervisory authority under GDPR Article 33 (if the GDPR "unlikely to result in a risk" threshold is not met). The one-stop-shop designates the lead authority within the EU/EEA but does not displace the FDPIC's supervisory competence over FADP compliance.
- Conversely, an EU-based controller with a Swiss establishment or whose processing falls within Article 3 FADP must notify its lead EU supervisory authority under GDPR Article 33 and the FDPIC under FADP Article 24 (when the respective thresholds are met). The FDPIC is the supervisory authority for FADP compliance; the lead EU authority has no power to receive or evaluate FADP notifications on behalf of the FDPIC.
## Practical coordination: content and timing
Notification content is similar but not identical. Both FADP Article 24(1) (as interpreted by the FDPIC Guidelines) and GDPR Article 33(3) require the controller to describe the nature of the breach, the categories and approximate number of data subjects and records affected, the contact details of the data protection officer or other contact point, the likely consequences, and the measures taken or proposed. The FDPIC's DataBreach online portal (available at edoeb.admin.ch/meldeportale/databreach) and EU member-state breach-notification forms accept similar information. A controller may draft a single factual breach description and adapt it to each authority's form, provided that the controller applies the correct risk assessment and legal standard for each notification.
Timing coordination: When both FADP and GDPR apply, the controller should aim to notify both authorities within the stricter timeline—GDPR's 72-hour deadline—to avoid a finding of "undue delay" under either regime. The FDPIC's "as soon as possible" standard is flexible and does not prohibit parallel notification; the FDPIC has stated that phased notification is acceptable when all information is not immediately available (FDPIC Guidelines on Data Breaches, February 2025). The controller may submit an initial notification to both the FDPIC and the relevant EU supervisory authority within 72 hours, then provide supplementary information in phases as the investigation progresses.
Data-subject notification: The controller must separately assess whether data-subject notification is required under FADP Article 24(4) (when notification is "necessary to protect" the data subjects or when the FDPIC orders it) and under GDPR Article 34(1) (when the breach is "likely to result in a high risk" to the rights and freedoms of natural persons). These are distinct thresholds. The controller may send a single data-subject notification that complies with both regimes, provided it includes the information required by each (nature of the breach, contact point, likely consequences, measures to mitigate, and—under GDPR Art. 34(2)—the categories of data affected and the approximate number of individuals, if not already communicated).
## No mutual recognition or exemption
There is no automatic exemption or mutual-recognition mechanism under which notification to the FDPIC satisfies GDPR Article 33, or vice versa. The EU adequacy decision for Switzerland (15 January 2024) recognises that Switzerland's FADP provides an "adequate" level of protection under GDPR standards for the purpose of cross-border data transfers (GDPR Art. 45), but it does not establish that FADP Article 24 and GDPR Article 33 are equivalent or that a controller may choose one regime over the other. Each regime's breach-notification obligation applies independently when its jurisdictional and material-scope conditions are met.
The controller must document both risk assessments (the FADP "likely high risk" assessment and the GDPR "unlikely to result in a risk" assessment) in its Article 24(3) FADP breach register and in its GDPR Article 33(5) internal breach documentation. During an FDPIC investigation under Article 51 FADP or an EU supervisory authority investigation, the controller must be able to demonstrate that it correctly applied the relevant threshold to each regime's notification obligation.
Source: Federal Act on Data Protection (FADP), Art. 24 Source: FDPIC Guidelines on Standard Contractual Clauses (SCC) — parallel supervisory authority competence (PDF pages 3–4) Source: European Commission — Adequacy decision for Switzerland (15 January 2024) Source: EDPB Guidelines 9/2022 on personal data breach notification under GDPR — cross-border breach coordination
"Likely high risk" assessment methodology — FDPIC criteria and examples of high-risk breach scenarios under Article 24(1) FADP
Article 24 paragraph 1 FADP conditions the duty to notify the FDPIC on whether the data security breach "is likely to result in a high risk to the personality or fundamental rights of the data subject." This threshold determines whether the controller must report to the FDPIC; breaches that fall below the "likely high risk" bar need not be reported externally (though the controller must still log every breach in the Article 24(3) register). The FDPIC Guidelines on Data Breaches (published February 2025 and available at edoeb.admin.ch) provide detailed interpretative criteria and examples to guide controllers' risk assessments.
## Two-step risk assessment: harm already occurred + likely future consequences
When assessing high risk under Article 24(1) FADP, the FDPIC Guidelines state that "data controllers should firstly clarify the extent to which the data security breach that has occurred has already harmed the personality or fundamental rights of natural persons. Secondly, the criterion of 'likelihood' … requires controllers to include in their assessment the consequences of the data breach for the persons potentially affected, which can neither be conclusively measured nor can be predicted with certainty."
This framework requires controllers to evaluate:
- Harm that has already materialized — whether the breach has demonstrably injured the data subject's personality or fundamental rights (for example, unauthorized disclosure of health records has already resulted in third-party knowledge of the data subject's medical condition; stolen credentials have already been used to access the data subject's account).
- Likely future consequences that cannot yet be measured or predicted with certainty — whether the breach creates a substantial probability of future harm even if none has yet occurred (for example, credentials exposed in a breach have not yet been misused but are now available to attackers; personal data disclosed to unauthorized persons could be republished, used for identity fraud, or sold).
The Guidelines emphasize that "the level of harm to those most severely affected is what counts." The controller must assess the worst-case scenario for the individuals at greatest risk, not the average or aggregate risk across all affected data subjects. If even a small subset of the affected population faces a high risk of severe harm, the breach meets the Article 24(1) threshold.
## The role of post-breach measures: ex-ante vs. ex-post mitigation
Article 24 paragraph 1 FADP requires the risk assessment to be conducted "without taking into account measures that the controller only plans, announces or initiates after the data security breach," according to the FDPIC Guidelines. The controller may not credit reactive mitigation measures—steps the controller announces or begins implementing only after discovering the breach—when assessing whether the breach is "likely to result in a high risk."
However, the FDPIC's prior practice (which the Guidelines state the FDPIC continues to apply) permits controllers to credit immediate measures taken even before submitting the report in good time where these measures demonstrably excluded or minimised the anticipated effects of any personal data breach. The Guidelines give the example of "a controller [that] quickly regained control of personal data that had been made temporarily inaccessible by taking immediate measures and was able to establish with sufficient certainty within hours on the basis of logs or other evidence that the data had not been processed improperly." In such cases the controller may conclude that the breach does not meet the "likely high risk" threshold because the immediate containment demonstrably prevented harm.
The distinction is temporal and evidentiary:
- Immediate containment before reporting — measures taken within hours (log analysis confirming no unauthorized access occurred; immediate revocation of exposed credentials; retrieval of data before third-party disclosure) may be credited if the controller can demonstrate with certainty that they eliminated the risk.
- Reactive measures announced or initiated after the breach — password resets, breach notifications to data subjects, engagement of forensic investigators, patches deployed in response to the breach — do not reduce the "likely high risk" for purposes of the Article 24(1) reporting decision. The controller must assess the breach based on the risk at the time it occurred and was discovered, not the residual risk after mitigation.
The Guidelines warn that "in situations of doubt where a high risk cannot be sufficiently excluded, controllers" should report. The FDPIC interprets the statute to favor disclosure when the risk assessment is uncertain.
## Key risk factors: sensitivity of data and nature of harm
The FDPIC Guidelines identify several risk factors controllers should weigh when assessing the severity of harm. The following criteria increase the likelihood that a breach will be deemed high-risk:
Particularly sensitive personal data (Article 5 letter c FADP)
"If particularly sensitive personal data in accordance with Article 5 letter c FADP are affected, e.g. health data, biometric data or data on social assistance measures, a high risk must be assumed in many cases," the Guidelines state. Article 5(c) FADP defines particularly sensitive personal data as:
- religious, ideological, political, or trade-union-related views or activities;
- health, the intimate sphere, or racial or ethnic origin;
- social assistance measures;
- administrative or criminal proceedings and sanctions.
A breach involving any of these categories creates a presumption of high risk because disclosure or unauthorized access to such data threatens the data subject's dignity, autonomy, and fundamental rights (Art. 1 FADP protects the personality and fundamental rights of natural persons whose data are processed).
The FDPIC's list is illustrative, not exhaustive. Controllers should assess whether the nature and context of the data — even if not enumerated in Article 5(c) — creates a similar risk profile. For example, the Guidelines state that "a breach involving data that do not fall into this category, such as (copies of) identity documents or credit card details, can also pose a high risk."
Identity documents and financial credentials
The FDPIC Guidelines explicitly flag copies of identity documents (passports, national ID cards, driver's licenses) and credit card details as posing high risk even though they are not "particularly sensitive personal data" under Article 5(c) FADP. Unauthorized disclosure of these data enables:
- identity fraud — opening accounts, applying for credit, or accessing services in the data subject's name;
- financial fraud — unauthorized transactions using stolen credit-card numbers or banking credentials;
- credential stuffing — using stolen usernames and passwords (or password hashes) to gain unauthorized access to the data subject's accounts on other platforms.
When a breach exposes identity documents, payment-card data, or authentication credentials, the controller should presume "likely high risk" unless immediate containment measures (see above) demonstrably prevented third-party access.
Volume and context: large-scale breaches and vulnerable populations
Although the FDPIC Guidelines do not establish a numeric threshold, the scale of the breach is a relevant factor. A breach affecting a large population increases both the absolute number of individuals at high risk and the likelihood that some subset will suffer severe harm. However, the Guidelines emphasize that the "level of harm to those most severely affected is what counts" — the controller must not dilute the risk assessment by averaging across a large, heterogeneous population. A breach affecting ten individuals may meet the "likely high risk" threshold if those ten individuals' particularly sensitive data were exposed.
The vulnerability of the affected population also matters. Breaches affecting children, elderly persons, persons with disabilities, or individuals in precarious circumstances (recipients of social assistance, asylum seekers, victims of domestic violence) may pose higher risk because these populations face disproportionate consequences from data misuse. The FDPIC has not published sector-specific guidance, but controllers should apply this principle when assessing breaches involving vulnerable data subjects.
Nature of the breach: unauthorized access vs. disclosure vs. loss
The type of incident under Article 5 letter h FADP affects the risk assessment:
- Unauthorized access — personal data were accessed by unauthorized persons (cyberattack, insider snooping, misconfigured database exposed to the internet). High risk if the data were exfiltrated or if logs cannot confirm that access did not occur; lower risk if logs prove access was fleeting and no copying occurred.
- Unauthorized disclosure — personal data were disclosed to unauthorized recipients (misdirected email, data published on the internet, shared with a processor without a valid controller-processor contract under Article 9 FADP). High risk if the disclosure is irrevocable (publication) or if the recipient is adversarial; lower risk if the recipient is trustworthy and has agreed to delete the data.
- Loss or destruction — personal data were lost or destroyed (ransomware encryption, accidental deletion, theft of unencrypted device). High risk if the data are sensitive and the loss is permanent (no backups, no recovery possible); lower risk if backups exist and the data can be restored without unauthorized third-party access.
- Modification — personal data were altered (database records tampered with, integrity compromised). High risk if the modification undermines the accuracy or reliability of data used for decisions affecting the data subject (financial records, health records, criminal-justice data).
Ransomware incidents warrant special attention. The FDPIC's position (reflected in enforcement practice, though not yet codified in published guidelines as of 2026-06-02) is that ransomware encryption constitutes a data security breach under Article 5(h) (data "lost" or "made accessible to unauthorised persons") and that controllers should presume "likely high risk" when sensitive data are encrypted by ransomware, because:
- the attacker typically exfiltrates data before encrypting it (double-extortion model);
- even if exfiltration cannot be confirmed, the encryption itself renders the data inaccessible to the controller and thus harms the data subject's rights (inability to exercise access, rectification, or erasure rights under Arts. 25–28 FADP);
- threat actors commonly publish or sell exfiltrated data when the ransom is not paid.
Controllers facing ransomware incidents should conduct forensic log analysis to determine whether exfiltration occurred, but should report to the FDPIC under Article 24(1) unless logs affirmatively exclude data theft.
## Illustrative high-risk scenarios (FDPIC practice)
The FDPIC has not published a comprehensive list of per-se high-risk breach types. However, the Guidelines and enforcement decisions to date suggest the following scenarios typically meet the "likely high risk" threshold:
- Health-data breaches — unauthorized access to or disclosure of medical records, health-insurance claims, prescription histories, mental-health records, genetic data, or disability records. Presume high risk.
- Biometric-data breaches — fingerprints, facial-recognition templates, iris scans, voiceprints. Presume high risk because biometric identifiers are immutable and their compromise is permanent.
- Credential breaches — usernames and passwords (plaintext or weakly hashed), API keys, OAuth tokens, session cookies. High risk if the credentials grant access to sensitive accounts or if credential reuse is likely.
- Financial-data breaches — credit-card numbers, bank-account details, payment-card CVVs, account PINs. High risk because of fraud potential.
- Children's data — any breach involving personal data of children (persons under 16, per the Swiss legal definition of capacity). High risk due to children's vulnerability and the heightened protection afforded under Article 6 paragraph 6 letter g FADP (processing children's data must be "particularly respectful of the welfare of the child").
- Social-assistance and welfare records — data on receipt of unemployment benefits, disability benefits, housing assistance, or other social-support programs. High risk because disclosure stigmatizes the data subject and threatens dignity.
- Criminal and administrative-proceedings data — records of arrests, prosecutions, convictions, or administrative sanctions. High risk because of reputational harm and because such data fall within Article 5(c) FADP "particularly sensitive" category.
- Large-scale credential stuffing or account takeover — even when the underlying data are not particularly sensitive, a breach that enables unauthorized access to a large number of user accounts poses high risk.
Conversely, the following scenarios typically fall below the "likely high risk" threshold (and therefore do not trigger FDPIC notification under Article 24(1), though they must still be logged under Article 24(3)):
- Misdirected email containing routine business contact information (names, work email addresses, job titles) sent to a trustworthy recipient who promptly deletes it and confirms deletion.
- Temporary loss of access to non-sensitive data due to technical failure, where the controller restores access within hours, logs confirm no unauthorized third-party access occurred, and the data are not particularly sensitive.
- Disclosure of pseudonymous or aggregated data that cannot be re-identified without disproportionate effort (though controllers should be cautious — technological advances reduce the effort required for re-identification, and the FDPIC applies a forward-looking assessment).
## Documenting the risk assessment
The controller must document its risk assessment for every data security breach, regardless of whether it reports to the FDPIC. The Article 24(3) breach register must include the controller's rationale for concluding that the breach did or did not meet the "likely high risk" threshold. During an FDPIC investigation under Articles 49–51 FADP, the FDPIC will scrutinize the controller's risk assessment and may conclude that the controller should have reported. A contemporaneous, evidence-based risk analysis is the controller's defense.
The risk assessment should identify:
- the categories and approximate volume of personal data affected (e.g., "2,400 customer records containing names, email addresses, and plaintext passwords");
- the sensitivity of the data (particularly sensitive under Art. 5(c)? financial credentials? identity documents?);
- the nature of the breach (unauthorized access, disclosure, loss, modification);
- the evidence of harm already occurred or likely to occur (logs showing exfiltration? data published online? credentials used for unauthorized account access?);
- the measures taken before or immediately after discovery that reduced risk (immediate revocation of credentials? log analysis excluding unauthorized access? retrieval of data before third-party disclosure?);
- the level of harm to the most severely affected individuals (worst-case scenario for the subset of data subjects at greatest risk);
- the conclusion — likely high risk (report to FDPIC) or not (do not report, but log in Art. 24(3) register).
If the controller concludes that the breach is not likely to result in a high risk and therefore does not report to the FDPIC, that decision is reviewable. The FDPIC may, during a subsequent investigation, disagree with the controller's assessment and find that the controller violated Article 24(1) by failing to report. The documented risk assessment is critical evidence of the controller's good-faith compliance effort.
Source: FDPIC Guidelines on Data Breaches (February 2025), PDF pages 9–12 Source: Federal Act on Data Protection (FADP), Art. 24 Source: Federal Act on Data Protection (FADP), Art. 5 — definitions including "particularly sensitive personal data"
Processor breach notification to controller under Swiss FADP Art. 9 and DPO Art. 7(8) — unconditional reporting duty
Processors (natural or legal persons processing personal data on behalf of the controller, per Article 5(l) FADP) have a direct, statutory duty to notify the controller of any data security breach, regardless of severity or risk. This obligation is set out in Article 9 of the Federal Act on Data Protection (FADP), which governs controller–processor relationships, and is implemented in more detail by Article 7(8) of the Data Protection Ordinance (DPO).
## Article 9 FADP — statutory processor duties
Article 9(1) requires that any processing by a processor must be governed by a contract or other legal act, in which "the processor may only process personal data as the controller is permitted to do and only to the extent instructed by the controller." Article 9(2) specifies that the contract must include, among other things, a requirement that the processor "must notify the controller as soon as possible if it ascertains a data security breach." Unlike the duty to notify the FDPIC under Article 24(1) (which is triggered only by breaches likely to result in high risk), the processor’s obligation to inform the controller applies to all data security breaches as defined by Article 5(h) FADP — i.e., any accidental or unlawful loss, deletion, destruction, modification, disclosure, or unauthorized access to personal data.
## Article 7(8) DPO — implementing the breach reporting duty
Article 7(8) DPO clarifies the timing: "The processor shall inform the controller without delay as soon as it ascertains a breach of data security." The DPO uses the phrase "without delay" ("unverzüglich" in German), which the FDPIC interprets as immediate reporting once the processor is aware of the breach, allowing only time for the basic internal fact-finding needed to establish that a breach, as defined by Article 5(h), has in fact occurred. The law does not set a numeric deadline, but the expectation is prompt relay, typically in hours, not days.
## Scope — unconditional duty, no risk-assessment threshold
The processor must report any breach — including incidents the processor believes may ultimately be evaluated by the controller as "low risk." There is no discretion for the processor to screen incidents based on anticipated impact; the controller makes the risk assessment and determines whether notification to the FDPIC (Art. 24(1)), data subjects (Art. 24(4)), or other regulatory bodies is required. This is stricter than the GDPR, where Article 33(2) requires processors to notify controllers without undue delay, but the Swiss regime’s guidance makes clear that the processor may not withhold low-severity breaches.
## Required content and recommended best practices
While neither the FADP nor the DPO specifies the minimum content for processor-to-controller breach reports, the FDPIC's Guidelines on Data Breaches (February 2025) recommend that the notification include:
- Description of the breach (nature, date, time, data involved, how identified)
- Initial assessment of the scope (number/types of data subjects, data categories)
- Any immediate containment/mitigation actions taken
- Point of contact for additional follow-up
Controllers are encouraged to specify reporting formats and escalation contacts in their contracts and data-protection instructions. Where a processor is subject to multiple regimes (e.g., GDPR and FADP), it should also notify the controller in a manner compatible with both Art. 33(2) GDPR and Swiss law.
## Consequences of non-compliance
Failure by a processor to promptly report a data security breach to the controller is a violation of contractual and statutory duty. Depending on contract terms, this can result in:
- Claims for damages against the processor (civil liability for resulting harm)
- Possible administrative action or civil sanctions on the controller, who remains legally responsible for complying with Art. 24 FADP notification timelines
- Termination or suspension of the data processing agreement
The FADP does not directly impose administrative fines on processors for failure to report, but the controller may seek indemnification or other contractual remedies. The breach may also inform the FDPIC’s risk evaluation of the processor in future investigations or contract approvals.
Source: Federal Act on Data Protection (FADP), Art. 9 Source: Data Protection Ordinance (DPO), Art. 7(8) Source: FDPIC Guidelines on Data Breaches (February 2025), PDF page 7
FDPIC investigation procedure — Article 51 FADP powers following breach notification
After a controller notifies the Federal Data Protection and Information Commissioner (FDPIC) of a data security breach under Article 24 of the Federal Act on Data Protection (FADP), the FDPIC may initiate an administrative investigation using the powers set out in Articles 49 and 51 FADP. The scope and operation of this process are defined primarily by statute, not by detailed regulatory guidance, and practitioners should be aware of the specific legal authority and limits.
How investigations start:
- Article 49 FADP allows the FDPIC to initiate an investigation following a breach notification, a complaint, or on its own motion. There is no statutory deadline for the FDPIC to commence such inquiries.
Key FDPIC investigatory powers under Article 51 FADP:
- The FDPIC may require the controller, processor, or any other person to provide documents and information it needs to clarify the facts (Art. 51(1)). The statute does not enumerate specific document types (such as a breach register), but in practice, the information required is determined by the facts of the case.
- The FDPIC may conduct inspections on-site at the premises of the controller or processor, including the review of data processing activities and information systems (Art. 51(2)). The law does not specify whether advance notice is required.
- The FDPIC is authorized to order interim measures as necessary during the investigation to secure evidence or prevent imminent harm (Art. 51(3)).
Rights and procedure:
- The parties to the investigation have the right to be heard, and may provide statements or evidence relevant to the facts (Art. 51(4) FADP). General rules from the Swiss Federal Act on Administrative Procedure (APA) also apply, including the right to appeal.
Outcomes and remedies:
- At the conclusion of the investigation, the FDPIC may issue a formal order requiring remedial action (for example, to notify affected data subjects, modify practices, or implement security measures), or may close the case with findings or recommendations (Art. 51(5)).
- Any person affected by a formal order may challenge it by appealing to the Swiss Federal Administrative Court within 30 days (Art. 53 FADP, Art. 44 APA).
- If the FDPIC suspects an intentional criminal violation (Arts. 60–63 FADP), it may refer the case to criminal prosecution authorities.
Transparency:
- The FDPIC may publish anonymized summaries of decisions and orders, contributing to transparency in enforcement (Art. 58(1) FADP).
While the FADP sets out a robust process, much of the detail (such as timelines, documentation required, and procedure specifics) is left to discretion or standard Swiss administrative law, not spelled out directly in the FADP. Parties should pay close attention to statutory text, as routine practices may evolve.
Source: Federal Act on Data Protection (FADP), Arts. 49, 51, 53, 58 Source: Federal Act on Administrative Procedure (APA), Arts. 29, 44
Criminal and administrative penalties for failing to notify a data breach under Swiss FADP
Swiss law imposes both criminal and administrative consequences when a controller fails to notify a notifiable breach under the Federal Act on Data Protection (FADP).
## Criminal penalties: Article 60 FADP Article 60 FADP imposes criminal fines of up to CHF 250,000 on any natural person who intentionally violates notification obligations, including the duty to notify the FDPIC under Article 24 or, where applicable, to inform data subjects. Only intentional violations are criminalized—negligence is not penalized under Article 60. The law applies to individuals, not legal entities: "If the notification obligation under Article 24 is intentionally not fulfilled, the persons responsible are liable to a fine" (Art. 60(1)). According to Article 64 FADP, where identifying the responsible individual would require disproportionate effort, the fine may be imposed on the enterprise itself.
## Administrative enforcement: Article 51 FADP Where a controller fails to comply with Article 24 (for example, by not notifying the FDPIC), the Federal Data Protection and Information Commissioner (FDPIC) has the authority under Article 51 to order remedial and corrective measures. These include ordering notification to the FDPIC or to affected data subjects, requiring changes to data security measures, or other steps necessary to restore compliance. These administrative powers exist independently of potential criminal penalties.
The FADP does not contain a "double jeopardy" provision barring both tracks: administrative orders and criminal penalties may result from the same notification failure, but criminal penalties require a finding of intention.
## Statutory citations
- Article 24 sets out the notification duty.
- Article 60 defines criminal liability for intentional failures.
- Article 64 allows a fine against a company if identifying the natural person would require disproportionate investigative effort.
- Article 51 sets out the FDPIC’s enforcement and remedial powers.
The FDPIC Guidelines on Data Breaches (February 2025) provide interpretive guidance but do not enumerate enforcement statistics or case law trends as of 2026.
Source: Federal Act on Data Protection (FADP), Arts. 24, 51, 60, 64 Source: FDPIC Guidelines on Data Breaches (February 2025)
Article 24(6) FADP privilege — use of breach notifications in criminal proceedings and limitations
Article 24 paragraph 6 of the Swiss Federal Act on Data Protection (FADP) provides a specific protection for controllers and processors who file mandatory or voluntary breach notifications to the Federal Data Protection and Information Commissioner (FDPIC) or affected data subjects:
> "Neither reports and notifications required under this Article nor voluntary notifications may be used in criminal proceedings against the persons subject to the reporting obligation, unless these persons have consented."
This is a formal privilege against self-incrimination, designed to encourage timely and full disclosure of data security breaches. For practitioners, the critical points are:
- Scope of protection: The privilege covers the fact and content of filing a breach notification under Article 24 FADP—whether to the FDPIC or to data subjects—if that notification is mandatory or voluntary. It does not apply to every document generated during incident response, nor to other records or evidence surrounding the breach itself.
- Natural person focus: Article 24(6) primarily protects natural persons (e.g., employees or officers responsible for notification) from self-incrimination. Per Article 60 FADP, criminal penalties (up to CHF 250,000) apply to intentional notification failures of individuals, not legal entities. Article 64 permits fines against a company only if identifying the individual is disproportionate.
- Waiver: The privilege may be waived if the notifying person provides consent. Absent consent, the notification (the act of notification and its direct content) cannot be used as evidence in criminal proceedings for breach of notification duty or other criminal charges linked to the breach.
- Limitations: The privilege attaches only to the notification or report itself—not to the underlying facts of the breach, other documents (incident investigation files, logs, correspondence), or subsequent remedial actions. Authorities may still obtain and use independent evidence of the breach in criminal or administrative prosecution.
- Administrative proceedings: Article 24(6) FADP does not prohibit use of notification reports in administrative enforcement by the FDPIC (e.g., under Article 51 FADP), only criminal proceedings. The FDPIC may review and act upon notifications for compliance purposes, but cannot transmit the notification to criminal prosecutors as incriminating evidence absent consent.
This privilege is critical for in-house counsel and DPOs designing breach response plans: prompt, candid notification under Article 24 is shielded from use against the notifier in criminal prosecution, but all surrounding facts and evidence are still available to both the FDPIC and law enforcement. Practitioners should document separate investigation files and consider privilege/litigation-hold strategy accordingly.
FDPIC breach notification content and submission process — required information, online portal, and confirmation of receipt
Switzerland's Federal Act on Data Protection (FADP) Article 24(1) requires controllers to notify the Federal Data Protection and Information Commissioner (FDPIC) of data security breaches that are likely to result in a high risk to the personality or fundamental rights of data subjects. The law does not enumerate every item that must appear in a breach notification, but the FDPIC has published Guidelines and operates an online reporting portal, both of which specify required content and procedural steps as of 2026.
Required content of the notification:
The FDPIC's official "Data Breach" Guidelines (February 2025) and the reporting portal at edoeb.admin.ch set out what controllers must provide. The notification should include:
- Contact details for the controller (and, if available, for a designated contact person or DPO)
- Description and timing of the data security breach (what happened, when, how discovered)
- Categories and approximate volume of personal data and data subjects affected
- Nature of the breach (e.g., unauthorized access, disclosure, loss, alteration)
- Assessment of actual and anticipated effects on data subjects (potential harm)
- Immediate and planned remedial measures (to contain the breach, protect data subjects, prevent recurrence)
- Risk assessment underpinning the notification (why the controller concluded the “likely high risk” threshold is met)
- Whether the breach has been or will be reported to data subjects, other authorities, or law enforcement
If not all information is available when first reporting, the controller should update the notification as more details emerge—the FDPIC Guidelines allow for phased or supplementary notifications.
Submission process and use of the notification portal:
All breach notifications are filed through the FDPIC’s DataBreach Reporting Portal: https://www.edoeb.admin.ch/edoeb/en/home/meldeportale/databreach.html. The portal guides the controller through a structured online form, requesting the items above, with mandatory fields for core information (controller contact, breach type/description, impacted data categories, and risk assessment).
On submission, the FDPIC portal issues an electronic acknowledgment of receipt. This confirmation does not constitute legal approval or closure; it only confirms receipt for compliance and recordkeeping. The controller should retain this acknowledgment as evidence of timely notification and may be required to present it to the FDPIC during investigation or enforcement action (see Article 51 FADP).
Reporting by email or physical mail is also permissible if the portal is unavailable, but electronic reporting is standard practice as of 2026. Notifications can be submitted in German, French, or Italian; English is not officially required but may help in complex, cross-border cases.
If the breach facts materially change (for example, scope or risk is reassessed, additional categories of data subjects are identified, or remediation is completed), the controller should submit an updated notification through the portal referencing the original report.
Source: FDPIC DataBreach Reporting Portal Source: FDPIC Guidelines on Data Breaches (February 2025), Sections II.3 and Annex
Internal breach response procedures under Swiss FADP — controller duties for internal notification, escalation, and documentation
Switzerland’s Federal Act on Data Protection (FADP, in force since 1 September 2023) does not spell out prescriptive requirements for internal breach notification or escalation procedures within a controller’s organization, but the law and the Federal Data Protection and Information Commissioner (FDPIC) Guidelines on Data Breaches outline expectations that all controllers establish and document a robust internal process for breach assessment, risk evaluation, and decision-making.
Internal reporting lines and initial assessment:
Article 7 FADP imposes a duty of data security “by design and by default,” requiring controllers to take appropriate technical and organisational measures to protect personal data. The FDPIC Guidelines (February 2025, Section II.1) explicitly state that controllers must implement internal rules to ensure that staff, including non-IT personnel, can promptly recognize and report possible data security breaches to the appropriate person or team designated by the controller (often the DPO, CISO, or designated data-protection lead). The Guidelines recommend that controllers issue internal instructions specifying who should be notified, the timelines for internal escalation, and basic action steps for containment and evidence preservation when a potential breach is discovered.
Risk assessment and documentation:
The controller must have a defined internal procedure for conducting a risk assessment under Article 24(1)—determining whether a breach is "likely to result in a high risk to the personality or fundamental rights of the data subject." The FDPIC guidance emphasizes contemporaneous documentation: a written record of the breach circumstances, individuals involved in the assessment, timeline, and key facts/evidence informing the risk decision (FDPIC Guidelines II.2). This documentation is required for the Article 24(3) breach register and may be requested by the FDPIC in an investigation (Article 51 FADP).
Decision-making and escalation chain:
Although the FADP does not require a fixed chain of approval (such as board-level sign-off), the FDPIC recommends that controllers designate specific individuals responsible for notification decisions and that escalation procedures are tested via internal drills. The process should allow for prompt internal escalation when breaches involve "particularly sensitive personal data" (Art. 5(c) FADP), large-scale incidents, or cross-border implications (see parallel obligations section). Delays caused by unclear internal roles can lead to late notification and possible penalties.
Retrospective review and improvement:
The FDPIC Guidelines further recommend periodic review and updating of internal breach-response procedures, incorporating lessons learned from past incidents, near-misses, or external regulatory findings. Controllers should ensure that employee training addresses breach identification and internal reporting obligations (FDPIC Guidelines II.1, II.5).
No numeric internal deadlines, but expectation of urgency:
Neither the FADP nor the FDPIC fix numeric internal deadlines for reporting up the chain, but both expect that internal reports and risk assessment are performed with urgency, enabling external notification to the FDPIC "as soon as possible" if required under Article 24(1). Where breaches fall under parallel notification regimes (GDPR, UK GDPR), controllers should align their internal timelines to meet the strictest applicable standard (e.g., 72 hours under GDPR).
Source: Federal Act on Data Protection (FADP), Arts. 7, 24, 51 Source: FDPIC Guidelines on Data Breaches (February 2025), Sections II.1, II.2, II.5
Breach notification and delegation in corporate groups — FADP Article 24 duties for parent, subsidiary, and group DPO
Swiss Federal Act on Data Protection (FADP, revised 2023) Article 24 imposes the data security breach notification obligation directly on the controller — the natural or legal person who determines the purposes and means of processing (Art. 5(i) FADP). In group structures, practitioners routinely ask whether a Swiss subsidiary or affiliate can delegate its breach notification duties, either upward to the parent company, laterally to a group DPO or privacy lead, or even outward to an EU/EEA group entity where parallel GDPR obligations also arise.
Statutory basis and controller responsibility: Article 24 FADP does not provide for substitution or delegation of the notification obligation to another legal entity. The duty to notify the Federal Data Protection and Information Commissioner (FDPIC) always applies to the Swiss controller, regardless of intra-group arrangements. The FDPIC Guidelines (February 2025) confirm that “the responsibility for compliance with data protection law, including the duty to notify a data security breach, always lies with the controller as defined in Article 5(i) FADP.” This is consistent with the definition of controller in both Swiss and EU law.
Role of group data protection officers and centralized functions: The FADP and FDPIC Guidelines permit group data protection officers (DPOs) or privacy leads to prepare and submit breach notifications on behalf of Swiss affiliates, provided that these actions are authorized by the Swiss controller and clearly documented. The notification must reference the specific Swiss legal entity subject to Article 24 FADP. The FDPIC’s online DataBreach Reporting Portal requires entry of the controller’s Swiss company details. Group DPOs can serve as points of contact on notifications as long as the Swiss controller is identified as the responsible entity.
Foreign parent notification or one-stop notification: Notifying the EU lead authority under GDPR Article 33 (for multinational groups) does not satisfy the Swiss notification requirement. The FDPIC explicitly states in its Guidelines: “Parallel notification obligations must be fulfilled separately for each legal regime; a report to an EU authority under GDPR Article 33 does not replace notification to the FDPIC under Article 24 FADP, even within a group.” Swiss and EU obligations are independent; where a breach affects both EU and Swiss data subjects, notifications must be submitted separately to the FDPIC and the relevant EU supervisory authority.
Documentation and recordkeeping: The Swiss controller must keep its own Article 24(3) breach register, even when group-wide logs exist. Group functions (such as a centralized breach response team) may assist with maintaining the register, but the obligation to ensure completeness and availability to the FDPIC remains with the Swiss entity.
Conclusion: While operational delegation is permissible, legal responsibility under Article 24 FADP for both breach notification and recordkeeping is non-delegable and attaches to each controller in Switzerland. Centralized group structures may support fulfillment but do not displace the statutory duty. Failure to properly notify exposes the local Swiss controller — and responsible individuals — to administrative and criminal sanctions.
Source: Federal Act on Data Protection (FADP), Arts. 5(i), 24 Source: FDPIC Guidelines on Data Breaches (February 2025), Section II.1, II.3 Source: FDPIC DataBreach Reporting Portal — required controller entity detail
Breach notification obligations for federal bodies (Bundesorgane) under Articles 33–35 FADP
Switzerland's Federal Act on Data Protection (FADP, SR 235.1) contains a separate set of breach notification rules for federal bodies—defined in Article 2(b) FADP as federal authorities, offices, and other public-law institutions at the federal level, and entities entrusted with federal public tasks. Articles 33–35 FADP, effective 1 September 2023, establish the obligations and procedures applicable to these entities, which differ materially from those for private-sector controllers (Articles 24–26 FADP).
Article 33(1) FADP requires federal bodies to inform the Federal Data Protection and Information Commissioner (FDPIC) immediately upon detecting or suspecting a data security breach. The duty arises if the breach is either:
- likely to result in a high risk to the personality or fundamental rights of data subjects (mirroring the private-sector standard), or
- if the FDPIC requests notification after becoming aware of a breach (including through third parties or the media).
Additionally, federal bodies must document all breaches internally (Art. 33(2)), including cases not escalated to the FDPIC, in a manner comparable to the breach register under Article 24(3) FADP for private controllers.
Article 34 FADP specifies the content of breach notifications submitted by federal bodies to the FDPIC. At minimum, notifications must include:
- Description and circumstances of the breach, time and place, categories of affected personal data and data subjects;
- Likely consequences and actual harm, as far as known or anticipated;
- Measures taken or planned to address the breach and mitigate risk.
Federal bodies must update their notification if subsequent facts emerge that materially change the risk assessment or mitigation steps.
Article 35 FADP addresses breach notifications to data subjects by federal bodies. Where such notification is necessary to protect those persons or is ordered by the FDPIC, the federal body must promptly inform those affected. If notification would endanger public interests (for instance, investigations, security measures, or national defense), the federal body may delay or limit notification in consultation with the FDPIC. The FDPIC can also require the federal body to notify or take alternative protective measures under Article 35(3).
Failure to comply with Articles 33–35 may result in administrative orders from the FDPIC under Article 51 FADP (not criminal sanctions; criminal penalties do not apply to federal bodies as they do to private controllers).
This public-sector-specific legal regime is critical for federal offices, agencies, public-law corporations, federal contractors, and anyone operating under mandate of Swiss federal law. It is distinct from cantonal or municipal practice, which is governed by separate cantonal data-protection acts.
Source: Federal Act on Data Protection (FADP), Arts. 33–35 Source: FDPIC Guidelines — Data Breach Reporting by Federal Bodies
Notification deadlines and late reporting under Swiss FADP Article 24 — "as soon as possible" and FDPIC tolerance for delay
Swiss Federal Act on Data Protection (FADP) Article 24(1) requires controllers to notify the Federal Data Protection and Information Commissioner (FDPIC) of certain data breaches "as soon as possible" after becoming aware of an incident that is likely to result in a high risk to the data subject's personality or fundamental rights. Article 24 does not set a strict numeric deadline (such as the GDPR’s 72 hours), which leads to questions about what constitutes timely notification and how the FDPIC responds to delays.
Text and interpretive guidance:
- Article 24(1) FADP triggers the notification obligation at the point the controller is "aware" of both the breach and the fact that it meets the "likely high risk" test. The statute intentionally omits a fixed timeframe, reflecting Swiss legislative preference for a context-sensitive, risk-based approach.
- The FDPIC Guidelines on Data Breaches (February 2025, II.2) clarify that notification must occur "without undue delay" following the internal risk assessment that confirms the likely high risk standard is met. The Guidelines state: "Notification must be made as soon as the controller has sufficient information for a meaningful initial report."
- The FDPIC explicitly allows phased or supplementary reporting: initial notification should be submitted even if full details are unavailable, with updates provided as soon as additional information emerges (FDPIC Guidelines, II.3; DataBreach Reporting Portal instructions). This builds in procedural flexibility but emphasizes urgency.
What counts as undue delay?
- The FDPIC expects notification as soon as possible after the controller's risk assessment is completed, not after incident resolution or full forensic analysis. Undue delay may be found where internal investigation continues for days or weeks after the risk threshold is known. Only time required for reliable initial fact-finding (who, what, when, risk) is excusable; delays due to internal approvals, legal review, or an attempt to contain reputational damage are not.
- The Guidelines do not prescribe a maximum period, but the FDPIC's enforcement statements indicate that notifications submitted more than several days after determining a high risk will be scrutinized. In practice, the authority has accepted short delays when controllers document exceptional circumstances (e.g., criminal procedure or simultaneous law enforcement investigation impeding immediate notification), but routine organizational delay is not tolerated.
Consequences for late notification:
- Article 51 FADP empowers the FDPIC to issue corrective orders where notification was late or incomplete. Article 60 imposes criminal fines up to CHF 250,000 for intentional late or non-notification by responsible individuals.
- The FDPIC weighs documented evidence that the controller acted diligently. Good-faith efforts, prompt initial notification with follow-up submissions, and comprehensive breach registers mitigate the risk of sanction for moderate delay. There is no safe harbor for lateness, but a reasoned, documented process substantially reduces enforcement severity.
Best practices:
- Controllers should document the timeline from breach awareness to risk assessment and notification, retaining evidence of the decision process.
- Initial notifications should be filed with key facts as soon as the threshold is met, followed by updates if necessary.
- Internal escalation and approval protocols must not delay external notification; responsibility for compliance should be clearly assigned in policy.
Source: Federal Act on Data Protection (FADP), Art. 24 Source: FDPIC Guidelines on Data Breaches (February 2025), Sections II.2, II.3 Source: FDPIC DataBreach Reporting Portal
Extraterritorial application of Swiss FADP Article 24 — breach notification duties for foreign controllers and representatives
The revised Swiss Federal Act on Data Protection (FADP), effective 1 September 2023, applies not only to Swiss-established controllers, but also to certain non-Swiss (foreign) controllers under Article 3(1)-(2) FADP. Article 3(1) states that the FADP applies to situations with an effective link to Switzerland, and Article 3(2) mirrors the GDPR’s extraterritorial reach: the law applies to processing of personal data that has effects in Switzerland, even if the processing takes place abroad.
Who is a foreign controller under FADP? A controller is any natural or legal person determining the purposes and means of processing (Art. 5(i) FADP). A controller without a Swiss establishment but offering goods or services in Switzerland, or monitoring behaviour in Switzerland, will fall within scope if the processing has actual effects in Switzerland (Art. 3(2) FADP).
Breach notification duties for foreign controllers Foreign controllers caught by FADP’s extraterritorial reach have the same Article 24 obligations as Swiss controllers: they must notify the FDPIC “as soon as possible” if a breach is likely to result in a high risk to the personality or fundamental rights of individuals in Switzerland. The FDPIC’s Guidelines on Data Breaches (Feb. 2025, I.1) are explicit: “Controllers established abroad who process personal data of individuals in Switzerland in connection with the offering of goods or services, or the monitoring of behaviour, are subject to the notification obligations under Article 24 if a data security breach is likely to have effects in Switzerland.”
Role of the Swiss representative FADP Article 14 obliges many foreign controllers to appoint a Swiss representative if they process personal data of people in Switzerland on a large scale. However, the statute is clear that appointing a representative does not relieve the foreign controller from its legal duties; the representative acts as a point of contact but is not itself the controller for Article 24 compliance. The FDPIC Guidelines (II.4) confirm that breach notification must be made by or in the name of the controller, but the representative may submit the report on behalf of the foreign entity. The notification must identify the actual foreign controller, not just the Swiss representative.
Interaction with EU/UK notification Notifying an EU or UK supervisory authority under GDPR/UK GDPR does not satisfy Swiss FADP obligations. Notification to the FDPIC is required whenever the breach has effects on individuals in Switzerland, regardless of parallel EU/UK reporting.
Practical considerations Foreign controllers should ensure their Swiss representative is empowered to coordinate with the FDPIC and has access to all facts needed for prompt breach notification. Timelines ("as soon as possible") and risk threshold ("likely high risk") are identical to those for Swiss entities. Documentation and registration requirements (Art. 24(3) breach register) also apply.
Source: Federal Act on Data Protection (FADP), Arts. 3, 14, 24 Source: FDPIC Guidelines on Data Breaches (Feb. 2025), Sections I.1, II.4