Core data subject rights catalog — Articles 25, 28, and 32 FADP
The revised Federal Act on Data Protection of 25 September 2020 (FADP; also known as nFADP or revFADP), which entered into force on 1 September 2023, establishes a comprehensive catalog of individual rights for data subjects in Switzerland. These rights apply to the processing of personal data of natural persons—the 2023 revision removed the prior statute's coverage of legal entities—and are codified primarily in Chapter 4 (Articles 25–29) and Chapter 5 (Article 32) of the FADP. The Federal Data Protection and Information Commissioner (FDPIC) is the supervisory authority responsible for monitoring compliance.
## Right to information (access) — Article 25 FADP
Article 25 FADP grants data subjects the right to request information about whether a controller is processing personal data concerning them. This right is strictly personal and cannot be waived in advance (Art. 25(5) FADP).
When a data subject makes an access request, the controller must provide detailed information under Article 25(2), including:
- The identity and contact details of the controller;
- The personal data being processed;
- The purpose of the processing;
- The retention period or the criteria for determining it;
- The information available to the controller on the source of the personal data (if not collected from the data subject);
- Where applicable, the existence of automated individual decision-making and the logic involved;
- The recipients or categories of recipients to whom personal data is disclosed, including (for cross-border transfers) the country or international organization and any safeguards applied.
The controller must respond within 30 days of the request (Art. 25(7) FADP). If the deadline cannot be met, the controller must inform the data subject and set a new deadline. Information must be provided in writing and free of charge, unless an exception is provided by the Federal Council.
## Limitations on the right to information — Article 26 FADP
Article 26 FADP permits the controller to refuse, restrict, or defer an access request under certain conditions:
- A federal or cantonal statute requires the controller to maintain professional secrecy or another statutory confidentiality obligation (Art. 26(1)(a));
- Providing the information would adversely affect the interests of third parties (Art. 26(1)(b));
- The request is manifestly unfounded, in particular if it serves a purpose contrary to data protection or is manifestly frivolous (Art. 26(1)(c));
- The controller's own overriding interests require refusal, restriction, or deferral, provided the personal data is not disclosed to third parties (Art. 26(2)).
Article 27 FADP provides a separate exemption for periodically published media, which may refuse, restrict, or defer access to protect editorial confidentiality or sources.
## Right to data portability — Article 28 FADP
Article 28 FADP grants data subjects the right to obtain their personal data in a commonly used electronic format and to request its transfer to another controller. This right applies where:
- The data subject provided the personal data to the controller; and
- The processing is based on the data subject's consent or for the performance of a contract (Art. 28(1)).
The format must permit transmission with proportionate effort and enable the data subject to use the data automatically (Art. 21(1) Data Protection Ordinance). Data portability must be provided free of charge unless the Federal Council has provided for an exception (Art. 28(3)). The right is subject to the same limitations as the right to information under Article 26 FADP, as incorporated by Article 29 FADP.
## Right to rectification and erasure — Article 32 FADP
Article 32 FADP grants data subjects the right to request rectification of inaccurate personal data and deletion of unlawfully processed data. The controller may refuse rectification or deletion if prohibited by law or if the processing serves a public purpose. Data subjects may also request that the controller communicate the rectification or deletion to third parties, or mark disputed data as such.
This right is enforceable through civil action under Article 32(2) FADP, which cross-references Articles 28 ff. of the Swiss Civil Code (personality-rights protection), or through complaint to the FDPIC.
## Enforcement mechanisms and penalties
Data subjects who are denied a right may file a complaint with the FDPIC, which has authority under Article 49 FADP to open an investigation. If the FDPIC concludes that the FADP has been violated, it may issue binding orders under Article 51(1) FADP requiring the controller to adjust, suspend, or terminate processing; delete or destroy personal data; or fulfill its obligations under the statute.
The FADP imposes criminal penalties on natural persons (not the organization itself) for intentional violations. Articles 60–66 FADP provide that a person who intentionally provides false or incomplete information in response to an access request under Articles 25–27, or intentionally fails to fulfill disclosure obligations under Articles 19 and 21 FADP, may be fined up to CHF 250,000. These penalties apply to controllers and processors who intentionally violate the statute, not to organizations as entities.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1 Source: Ordinance on Data Protection of 31 August 2022, SR 235.11
Automated individual decision-making — Article 21 FADP information and review rights
Article 21 FADP establishes specific protections for data subjects when controllers make decisions based exclusively on automated processing that have legal consequences or a considerable adverse effect on the individual. Unlike GDPR Article 22, which creates a general prohibition subject to narrow exceptions, the Swiss approach is notification-based: the controller must inform the data subject about the automated individual decision and grant procedural safeguards, but the decision itself is not automatically forbidden.
## Scope — automated individual decisions under Article 21(1)
Article 21(1) FADP applies when three elements are present:
- Exclusively automated processing — the decision is made without meaningful human intervention in the decisional logic;
- Legal consequence or considerable adverse effect — the decision produces a binding legal result (approval or denial of a contract, a benefits determination, termination of a service) or a material impact on the data subject's interests, rights, or access to resources; and
- Individual determination — the decision concerns a specific data subject, not aggregate or statistical outputs.
Common examples include automated credit-scoring decisions that directly determine loan approval, algorithmic employment-screening tools that reject applicants without human review, and automated insurance underwriting that sets premium rates or denies coverage. By contrast, a recommendation system or a risk score that a human decision-maker considers alongside other factors does not trigger Article 21 if the human retains genuine discretion.
## Information obligation — Article 21(1) FADP
When an automated individual decision is made, the controller must inform the data subject that the decision was based exclusively on automated processing and that it has legal or considerable adverse consequences. This obligation is in addition to the general duty to inform under Article 19 FADP (which requires disclosure at the point of data collection that automated decision-making may occur). Article 21(1) requires notice when the decision is actually taken, enabling the data subject to understand that no human reviewed the outcome and to invoke the procedural rights in Article 21(2) and (3).
The statute does not prescribe a specific timeline for this notification. As a practical matter, notice should be provided simultaneously with or immediately following the communication of the decision itself, so the data subject can exercise review rights while the decision is still actionable.
## Right to be heard and right to human review — Article 21(2) and (3) FADP
Article 21(2) FADP grants the data subject the right, on request, to express their point of view regarding the automated individual decision. Article 21(3) FADP further provides that the data subject may request that the decision be reviewed by a natural person. These are procedural rights, not substantive rights to reversal: the controller must allow the individual to submit additional context, correct factual errors in the input data, or challenge the logic of the automated system, and a human being must then re-evaluate the decision in light of that input. The human review does not require the controller to reach a different outcome, but it does require genuine reconsideration — a purely formal or mechanical confirmation of the automated result would not satisfy Article 21(3).
The right to be heard and the right to human review are not automatic; the data subject must affirmatively request them. Controllers are not required to conduct human review of every automated decision, only those for which a data subject invokes Article 21(3).
## Exceptions — Article 21(4) FADP
Article 21(4) FADP exempts controllers from the information and procedural-review obligations under paragraphs (1) through (3) in two scenarios:
- The automated individual decision is directly connected with the conclusion or processing of a contract between the controller and the data subject, and the data subject's request is satisfied (Art. 21(4)(a) FADP); or
- A federal or cantonal statute expressly permits the automated decision and provides for the data subject's right to request review (Art. 21(4)(b) FADP).
The first exception mirrors GDPR Article 22(2)(a) but adds the requirement that the data subject's request — typically a request to enter into or perform a contract — must be satisfied by the automated decision. For example, an automated instant approval of an online purchase or subscription qualifies if the data subject requested that service and the decision grants it; an automated denial would not qualify for the exemption, because the data subject's request was not satisfied. The second exception defers to sector-specific legislation (such as social-insurance or tax-assessment statutes) that may already prescribe automated-decision procedures and review mechanisms.
## Criminal liability for non-compliance — Article 60 FADP
Intentional failure to inform a data subject about an automated individual decision under Article 21(1) FADP, or intentional refusal to allow the data subject to express their view or to obtain human review under Article 21(2) and (3), is a criminal offense punishable by a fine of up to CHF 250,000 under Article 60(1) FADP. The penalty applies to the natural person (employee, officer, or contractor) who committed the violation, not to the organization itself. Negligent violations are not penalized. As with other Article 60 offenses, prosecution is on complaint only (Art. 60(2) FADP) — the data subject must file a criminal complaint; the FDPIC does not prosecute ex officio.
## Relationship to GDPR Article 22
FADP Article 21 is narrower in scope than GDPR Article 22. The GDPR creates a general right not to be subject to automated decision-making with legal or similarly significant effects, subject to three exceptions (contract necessity, legal authorization, explicit consent). FADP Article 21 does not prohibit automated decisions; it requires transparency and procedural fairness when they occur. A controller processing Swiss personal data under FADP (but not GDPR) may therefore use automated individual decision-making more freely, provided it discloses the practice under Article 19, notifies the data subject when a decision is made under Article 21(1), and honors requests for human review under Article 21(3). Controllers subject to both GDPR and FADP must comply with the stricter GDPR standard.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 21 Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 60
Response timeline for access requests — Article 25(7) FADP 30-day deadline and extension procedure
Article 25(7) of the Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) establishes a 30-day statutory deadline for controllers to respond to a data subject's access request under Article 25(1) FADP. This deadline is a core operational requirement under Swiss data protection law. Unlike the GDPR's one-month deadline (which permits a two-month extension in certain circumstances), the Swiss regime provides a fixed initial period with a mandatory notification requirement for extensions.
## The 30-day clock — Article 25(7) first sentence
Article 25(7) FADP provides: "The controller shall provide information within 30 days of the request." The 30 days are calendar days, calculated from the date the controller receives the access request. The deadline applies regardless of the complexity of the request or the volume of personal data being processed.
A controller who fails to respond within 30 days without invoking the extension procedure under Article 25(7) second sentence is in breach of the FADP and may be subject to a complaint to the Federal Data Protection and Information Commissioner (FDPIC) under Article 49 FADP or to civil enforcement under Article 32(2) FADP (personality-rights protection via Art. 28 et seq. of the Swiss Civil Code).
## Extension procedure — Article 25(7) second sentence
Article 25(7) second sentence permits the controller to extend the deadline when the 30-day period cannot be met. The statute provides: "If the controller is unable to do so within that time, it shall inform the data subject accordingly and shall specify a new deadline."
This extension mechanism imposes three requirements on the controller:
1. Timely notification — The controller must inform the data subject of the delay before the expiration of the original 30-day deadline. A notice sent after day 30 does not cure the breach; the extension must be invoked proactively.
2. Specification of a new deadline — The controller must set a definite date by which it will provide the information. The FDPIC's published guidance explains: "If the controller is unable to provide the information within 30 days, it must inform you and let you know how long you may have to wait for the information to be provided."
3. Proportionality (implied from Article 6(2) FADP) — Article 25(7) does not specify permissible grounds for extension. In practice, extensions are appropriate when the data is dispersed across multiple systems, when the volume of data concerning the requester is objectively large (e.g., years of employment records, transaction logs), or when the controller must consult third parties under Article 25(2)(f) FADP (disclosure of recipients). Extensions that result from the controller's failure to maintain adequate records under Article 12 FADP or that appear designed to frustrate the data subject's rights are more vulnerable to challenge.
The statute does not cap the length of the extension. Controllers must be prepared to justify the extension timeline if challenged by the FDPIC or in civil proceedings.
## Form and fee — Article 25(6) FADP
Article 25(6) FADP provides that the controller shall provide the information "in writing and free of charge." The Federal Council is authorized to permit fees under Article 25(6) in cases of disproportionate effort, but the Data Protection Ordinance of 31 August 2022 (SR 235.11) does not currently establish such an exception. Controllers may not charge data subjects for responding to access requests under Article 25, even when the controller invokes an extension or when the data subject makes repeated requests. (Repeated manifestly unfounded requests may be refused entirely under Article 26(1)(c) FADP, but not monetized.)
"In writing" includes electronic formats (email, encrypted portal) if the data subject has submitted the request electronically, or if the controller's ordinary course of communication with the data subject is electronic.
## Relationship to Article 26 limitations and Article 28 portability
The 30-day deadline under Article 25(7) applies equally to portability requests under Article 28 FADP, because Article 29 FADP incorporates the Article 26 limitations regime by reference and Article 28(3) FADP cross-references the free-of-charge rule in Article 25. A controller that receives a portability request (data in commonly used electronic format, Art. 28(1) FADP) must respond within 30 days or invoke the extension procedure in the same manner as for an access request.
Article 26 FADP permits the controller to refuse, restrict, or defer an access request on certain grounds (professional secrecy, third-party interests, manifestly unfounded requests, or the controller's own overriding interests under Art. 26(2)). When a controller invokes Article 26, it should notify the data subject within the 30-day period and explain the legal basis for the refusal or deferral. A controller that defers a request under Article 26(2) (controller's overriding interests) is effectively invoking a form of extension, and the same specification-of-deadline principle applies.
## Criminal liability — Article 60(1)(a) FADP
Article 60(1)(a) FADP provides that a natural person who intentionally provides false or incomplete information in response to an access request under Articles 25–27 FADP is subject to a fine of up to CHF 250,000. This penalty applies to controllers (or their officers, employees, or agents) who deliberately withhold responsive personal data, misrepresent the purposes of processing, or fail to disclose recipients under Article 25(2)(g) FADP. Negligent non-compliance (e.g., missing the 30-day deadline through oversight) is not criminally penalized under Article 60, but may trigger administrative enforcement by the FDPIC under Article 51 FADP (binding orders to adjust processing or disclose data).
Prosecution under Article 60 FADP is on complaint only — the data subject must file a criminal complaint with the cantonal prosecutor; the FDPIC does not prosecute violations.
## Comparison to GDPR Article 15(3)
The Swiss 30-day deadline under Article 25(7) FADP is shorter than the GDPR's default one-month timeline under Article 15(3) GDPR, which permits a two-month extension "where necessary, taking into account the complexity and number of the requests" (Art. 15(3) second sentence GDPR). The GDPR's extension is self-executing if the controller notifies the data subject within one month; the Swiss regime requires the controller to specify a new deadline but does not impose a statutory cap on extension length. Controllers subject to both GDPR and FADP for the same data processing (e.g., a Swiss controller processing EU resident data, or an EU controller with a Swiss representative under Art. 14 FADP) should apply the shorter of the two deadlines to simplify compliance.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 25(6)–(7) Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 60(1)(a) Source: FDPIC, Knowing and asserting my rights — Right to information under Art. 25 FADP Source: Ordinance on Data Protection of 31 August 2022, SR 235.11
Right to object to processing — Article 30(2)(b) FADP applies to federal bodies only
Article 30(2)(b) of the Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) grants data subjects a right to object to the processing of their personal data. This right is a procedural safeguard that allows individuals to challenge processing they believe is unlawful or disproportionate. However, unlike GDPR Article 21—which grants a general right to object applicable to all controllers—the Swiss right to object under Article 30(2)(b) applies only to federal bodies (federal agencies, authorities, and administrative units), not to private controllers.
## Scope — federal bodies under Chapter 6 FADP
Article 30 is part of Chapter 6 of the FADP, which establishes special rules for federal bodies processing personal data. Chapter 6 (Articles 33–42) reflects the Swiss constitutional principle that public authorities must act within the limits of law when interfering with fundamental rights, including the right to informational self-determination. Federal bodies are subject to stricter requirements than private controllers: they must always have a legal basis for processing (Art. 34 FADP), and they must grant data subjects additional procedural rights, including the right to object under Article 30(2)(b) and the right to request restriction of processing under Article 30(2)(a).
Article 30(2)(b) provides that when a data subject objects to processing by a federal body, the body must either stop processing the personal data or explain why it is entitled to continue processing despite the objection. This procedural right ensures that federal bodies cannot ignore a data subject's concerns and must provide a reasoned justification when they continue processing over objection.
The FDPIC explains: "You have the right to object to the processing of your personal data by the controller at any time (Art. 30 para. 2 let. b FADP). After receiving your objection, the controller has to either stop processing the data or explain why it is entitled to continue to process the data against your wishes." This statement appears in the FDPIC's general guidance on data subject rights, but the statutory text itself limits the right to federal bodies, not private persons.
## No general right to object against private controllers
Private controllers in Switzerland—companies, organizations, and individuals—are not subject to Article 30(2)(b) FADP. The FADP does not grant data subjects a general right to object to processing by private controllers on grounds comparable to GDPR Article 21(1) (objection based on grounds relating to the data subject's particular situation when processing is based on legitimate interests or public task).
Swiss law instead follows a "permission subject to prohibition" model for private-sector processing. Under Article 31 FADP, private controllers may process personal data if:
- The data subject has consented;
- Processing is directly connected with the conclusion or performance of a contract with the data subject;
- Processing is necessary to protect overriding interests of the controller or a third party and the data subject's interests do not prevail; or
- A federal or cantonal statute permits or mandates the processing.
When processing falls within one of these grounds, the data subject has no statutory right to object under the FADP. The data subject's remedy is instead to challenge the processing as a violation of personality rights under Article 32 FADP and Articles 28 ff. of the Swiss Civil Code. Article 32(1) FADP provides: "Data subjects may request the controller to rectify or delete their personal data or to cease or refrain from unlawful processing or disclosure." This remedy is available when processing is unlawful—that is, when it violates the principles of Article 6 FADP (lawfulness, good faith, proportionality, purpose limitation, data accuracy) or lacks a valid ground under Article 31. But it is not an automatic objection right comparable to GDPR Article 21(1); the data subject must demonstrate that the processing is unlawful, not merely assert their particular situation.
## Comparison to GDPR Article 21
The absence of a general right to object for private controllers is a major divergence from the GDPR. GDPR Article 21(1) grants data subjects the right to object, on grounds relating to their particular situation, to processing based on legitimate interests (Art. 6(1)(f) GDPR) or public task (Art. 6(1)(e) GDPR). Once the data subject objects, the controller must cease processing unless it demonstrates compelling legitimate grounds that override the data subject's interests or the processing is necessary for the establishment, exercise, or defense of legal claims. GDPR Article 21(2) further provides an absolute right to object to direct marketing, with no balancing test.
Controllers subject to both GDPR and FADP—for example, a Swiss company processing EU resident data, or an EU company with a Swiss representative under Article 14 FADP—must honor GDPR Article 21 objections for EU data subjects and comply with the narrower Swiss regime for Swiss data subjects. In practice, many multinational controllers extend GDPR-style objection rights to Swiss data subjects as a matter of policy, even though FADP does not require it.
## Enforcement and remedies
A data subject who believes a federal body has unlawfully continued processing after an objection under Article 30(2)(b) FADP may file a complaint with the FDPIC under Article 49 FADP. The FDPIC has investigative authority under Article 50 and may issue binding orders under Article 51(1) requiring the federal body to adjust, suspend, or terminate processing. The data subject may also seek civil remedies under Article 32(2) FADP, which incorporates the personality-rights protections of Articles 28 ff. of the Swiss Civil Code.
When processing is by a private controller, the data subject's remedy is civil enforcement under Article 32 FADP (request for cessation of unlawful processing or disclosure) or a complaint to the FDPIC under Article 49. The FDPIC may investigate and issue binding orders under Article 51(1) if it concludes that the private controller has violated the FADP. Intentional failure by a private controller to comply with an FDPIC order may trigger criminal liability under Article 60 FADP (fines up to CHF 250,000 for the responsible natural person), but there is no standalone criminal penalty for refusing to honor a data subject's informal objection, because no such objection right exists in the statute.
## Practical implications
Practitioners advising Swiss clients or clients processing Swiss personal data should:
- Distinguish federal-body processing from private-sector processing. The right to object under Article 30(2)(b) applies only to federal bodies. Private controllers are not required to honor objections unless the underlying processing is unlawful under Article 31 or violates Article 6 principles.
- Cross-reference GDPR Article 21 for EU/EEA data subjects. Controllers subject to both GDPR and FADP should implement objection-handling procedures that apply GDPR Article 21 to EU residents and limit objection rights for Swiss residents to the Article 30(2)(b) federal-body context or to Article 32 unlawful-processing claims.
- Document legitimate-interest balancing. Although FADP does not grant an objection right, controllers relying on Article 31(2)(c) overriding interests should document their interest-balancing analysis (nature of data, purpose, data subject's reasonable expectations, safeguards) so they can demonstrate lawfulness if challenged under Article 32.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 30(2)(b) Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 32 Source: FDPIC, Knowing and asserting my rights
Right to restriction of processing — Article 32(2)(b) FADP for private controllers
Article 32(2)(b) of the Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) gives data subjects the right to request restriction of the processing of their personal data by a private controller in Switzerland. This right is triggered when the data subject disputes the proportionality of the processing or the accuracy of the personal data. The purpose is to temporarily suspend certain processing activities while the controller and data subject seek to resolve the dispute—commonly while verifying facts, correcting errors, or assessing the lawfulness of the activity. Restriction is distinct from erasure (permanent deletion, Art. 32(2)(c) FADP) or cessation (complete stop, Art. 32(2)(a)).
Legal provision and scope:
- Article 32(2)(b) allows the data subject to request restriction but does not define “restriction” or establish mandatory processes for how controllers must implement it. The official guidance from the Federal Data Protection and Information Commissioner (FDPIC) clarifies that restriction may be requested if the data subject disputes the proportionality of processing required by Article 6(2) FADP, or disputes the accuracy of the data under Article 6(5) FADP. Typical factual patterns include: ongoing disagreement about data corrections, or challenges to the controller’s legitimate interest balancing or necessity of processing (Art. 31(2)(c) FADP).
Operational considerations and best practices:
- The FADP and FDPIC do not mandate specific technical or procedural steps, such as flagging data in IT systems or sending formal notifications to the data subject. In operational practice, many Swiss controllers (especially multinationals) adopt approaches modelled on GDPR Article 18: freezing data for contested purposes, flagging restricted data, or suspending use/disclosure pending resolution. These are best practices, not legal obligations under Swiss law unless adopted by internal policy. Documentation of restriction requests and using clear internal workflows is advisable for compliance and audit purposes, but the FADP stops short of requiring these in statute or regulation as of June 2026.
Procedure and relationship to other rights:
- Restriction often arises in tandem with a rectification request (Art. 32(2)), or where the lawfulness of processing is challenged under Article 32(1). If rectification cannot be resolved promptly, restriction safeguards the data subject’s position while preventing further processing that could aggravate an accuracy or proportionality dispute.
- There is no statutory deadline or required form for imposing restriction. Controllers should act with reasonable promptness and keep the data subject informed, but the 30-day deadline applicable to access requests (Art. 25(7)) is not expressly extended to restriction.
Enforcement and remedies:
- If a restriction request is denied, the data subject may submit a complaint to the FDPIC (Art. 49), who can investigate and issue binding orders (Art. 51). Civil remedies via the cantonal courts are also available under Article 32(2), which incorporates the protections of Articles 28 ff. of the Swiss Civil Code. It is common in practice—not formally required by statute—for courts to waive fees for certain data subject rights disputes by analogy to Art. 32(3) FADP (which only guarantees no-fee for access disputes), but this is not explicit in law or regulatory interpretation as of June 2026.
- Direct criminal liability does not attach solely for refusing a restriction request; however, intentional failure to comply with an FDPIC order can lead to a fine for the responsible natural person of up to CHF 250,000 under Article 63 FADP.
Relation to public bodies:
- The right to restrict processing under Article 30(2)(a) FADP applies separately to federal bodies (Swiss government agencies), and is broader in form—a subject can generally request restriction during a dispute over lawfulness or necessity. This is not available against private controllers, who are governed by Art. 32(2)(b).
Comparison to GDPR:
- Swiss restriction is narrower than GDPR Article 18: under Swiss law, it applies only where proportionality or accuracy is disputed, and does not cover all the conditions set out in the GDPR (e.g., legal claims, objection pending, etc.). Many organizations choose to harmonize their restriction procedures for data subjects globally using GDPR as a best-practice floor, but under Swiss law, this is not required.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 32(2) Source: FDPIC, Knowing and asserting my rights Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 30(2)(a) Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 63
Right to rectification of inaccurate personal data — Article 32(2) FADP and the Article 6(5) accuracy principle
Article 32(2) of the Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) grants data subjects the right to request rectification of inaccurate personal data held by a controller. This right is the procedural mechanism for enforcing the accuracy principle codified in Article 6(5) FADP, which requires that "personal data must be accurate and, if necessary for the purposes of processing, kept up to date." Rectification is the least disruptive remedy in the data-subject-rights toolkit — the controller corrects the error and continues processing lawfully — but when accuracy disputes cannot be resolved, the data subject may escalate to restriction under Article 32(2)(b) FADP (suspend processing while the dispute is pending) or erasure under Article 32(2)(c) (permanent deletion).
## Statutory right — Article 32(2) FADP
Article 32(2) FADP provides that data subjects may request the controller to:
- (a) cease processing or disclosure that is unlawful or violates the personality of the data subject;
- (b) restrict the processing of personal data;
- (c) have personal data deleted or destroyed.
The statute does not explicitly list "rectification" as a separate paragraph within Article 32(2), but the Federal Data Protection and Information Commissioner (FDPIC) has clarified that rectification is a core data-subject right under the FADP. The FDPIC states: "In accordance with the Federal Act on Data Protection (FADP), any person may request information from the controller of a data file as to whether their personal data is being processed and may, if necessary, have the data corrected or destroyed." The right to correction is grounded in the accuracy principle of Article 6(5) FADP and is enforceable through the civil-enforcement mechanism of Article 32(2) (personality-rights protection under Arts. 28 ff. of the Swiss Civil Code).
## Substantive obligation — Article 6(5) FADP accuracy principle
Article 6(5) FADP provides: "Personal data must be accurate and, if necessary for the purposes of processing, kept up to date." This is one of the six core principles governing all personal-data processing under Swiss law, codified in Article 6 (Principles):
- Lawfulness (Art. 6(1)) — processing must comply with the statute;
- Good faith (Art. 6(2)) — processing must be conducted in good faith and be proportionate;
- Purpose limitation (Art. 6(3)) — data may be processed only for the purpose indicated at the time of collection;
- Data minimization (Art. 6(2)) — the purpose cannot be achieved by other reasonably available means that interfere less with the personality of the data subject;
- Accuracy (Art. 6(5)) — data must be correct and current;
- Retention limitation (Art. 6(4)) — personal data may be retained in a form that permits identification of data subjects for no longer than is required for the purpose of processing.
Article 6(5) is a continuing obligation. The controller must maintain data accuracy not only at the point of collection but throughout the retention period, updating records as necessary when the purpose of processing requires current information. For example:
- Employment records — an employer processing employee addresses for payroll and benefits must update address data when an employee moves, or the payroll deposits and tax forms will go to the wrong location;
- Credit reporting — a credit bureau must correct erroneous default records when a disputed debt is resolved, or the data subject's creditworthiness profile is materially false;
- Medical records — a hospital maintaining allergy or medication records must correct documented allergies when a patient reports an error, because inaccurate data poses a risk to health and safety.
The accuracy principle under Article 6(5) does not require the controller to verify the truth of every data point proactively. Controllers may rely on data provided by the data subject or by authoritative third-party sources (government registries, employers, financial institutions) unless they have reason to know the data is incorrect. The obligation is to maintain accuracy once errors are identified and to update data when the purpose requires currency.
## Scope — what qualifies as "inaccurate"
Data is inaccurate under Article 6(5) FADP when it is factually false, incomplete in a way that materially distorts the truth, or outdated such that it no longer reflects the current reality relevant to the processing purpose. Examples include:
- Factually false — a database records the data subject's date of birth as 1 January 1985 when the correct date is 15 March 1987;
- Incomplete — a credit report lists a loan default but omits the fact that the debt was subsequently paid and the default was withdrawn;
- Outdated — an HR system lists the data subject's job title as "Junior Analyst" when they were promoted to "Senior Analyst" two years ago and the job-title field is used for internal org charts and external employment verifications.
Data is not inaccurate merely because the data subject disputes the controller's interpretation of accurate facts, or because the data subject disagrees with a decision based on the data. For example:
- A performance review states "Employee missed three project deadlines in Q2." If the employee did in fact miss three deadlines, the statement is accurate even if the employee disputes whether the delays were their fault or whether the review is fair.
- An insurance underwriting model scores the data subject as "high risk" based on accurate claim history. The data subject may challenge the proportionality of the processing under Article 6(2) FADP or request restriction under Article 32(2)(b) while disputing the risk assessment, but the underlying data (the claim history) is not inaccurate if the claims actually occurred.
Practitioners should distinguish factual accuracy disputes (which trigger the right to rectification) from legal or evaluative disputes (which may trigger objection under Art. 30(2)(b) FADP for federal bodies, restriction under Art. 32(2)(b), or civil enforcement under Art. 32(2)(a) for unlawful processing).
## Procedure — how data subjects request rectification
The FADP does not prescribe a specific form or procedure for rectification requests. Best practices drawn from FDPIC guidance and operational necessity include:
1. Identification of the inaccurate data — The data subject should specify which data is incorrect and provide the correct information. A general statement that "my file contains errors" without identifying the disputed data points does not allow the controller to comply. For example: "Your database lists my employment start date as 1 June 2020; the correct date is 1 July 2020."
2. Proof or supporting documentation — When the controller reasonably cannot verify the correction from its own records or authoritative sources, it may request that the data subject provide evidence. For example, if the data subject disputes a recorded address, the controller may ask for a utility bill or government ID showing the correct address. However, the burden of proof is context-dependent:
- When the controller collected the data from the data subject (e.g., a web-form submission, an account sign-up), and the data subject now asserts they provided different information, the controller may rely on its contemporaneous records unless the data subject provides persuasive evidence of an error (e.g., a screenshot of the submitted form, a confirmation email).
- When the controller collected the data from a third party (e.g., a credit bureau, an employer reference, a public registry), and the data subject challenges its accuracy, the controller should investigate by re-verifying with the source or examining its records. If the third-party source confirms the data or if the controller's records are ambiguous, the data subject may need to provide documentation.
3. Timeline — The FADP does not set a deadline for controllers to complete rectification, in contrast to the 30-day deadline for access requests under Article 25(7) FADP. The FDPIC has not published specific guidance on rectification timelines as of June 2026. Controllers should apply a reasonable-time standard: rectification of simple factual errors (name spelling, date of birth, address) should be completed within a few business days; rectification requiring investigation or third-party verification may take longer but should be pursued diligently. If the controller cannot complete rectification promptly, it should notify the data subject and, if the data subject requests, restrict processing under Article 32(2)(b) FADP while the accuracy dispute is resolved.
4. Notification to recipients — Article 32(1) FADP provides that data subjects may request the controller to "communicate the rectification or deletion to third parties" to whom the controller has disclosed the personal data. This right ensures that corrections propagate downstream. For example, if a controller rectifies an erroneous employment termination date in its HR system and had previously disclosed that date to a reference-check service or a background-screening vendor, the data subject may request that the controller notify those recipients of the correction. The controller must honor such a request unless disclosure to the third party was anonymous or the effort is disproportionate.
## Disputed accuracy — marking data or restricting processing
When the controller and data subject cannot agree on whether data is inaccurate, Article 32(1) FADP provides that the data subject may request that the controller mark the disputed data as such. This is an intermediate remedy: the controller retains the data (and may continue processing it if lawful under Article 31 FADP), but the data is flagged so that downstream recipients and future processors understand that the accuracy is contested. For example, a credit bureau that cannot verify whether a disputed loan default was valid may mark the entry as "disputed by data subject" so that lenders reviewing the report can weigh the contested item appropriately.
Alternatively, the data subject may invoke the right to restriction under Article 32(2)(b) FADP, which the FDPIC has clarified applies "if you dispute the proportionality of the data processing or the accuracy of the data." Restriction suspends active use of the data while the dispute is pending — for example, the controller stops using the disputed data for automated decision-making, profiling, or disclosure to third parties, but retains it in storage for verification or potential litigation. See the dedicated section on restriction of processing in this guide for operational details.
## Relationship to GDPR Article 16
GDPR Article 16 grants EU data subjects a right to rectification of inaccurate personal data "without undue delay." The GDPR also grants a right to have incomplete personal data completed, "including by means of providing a supplementary statement." Swiss law under FADP Article 6(5) and Article 32(2) is substantively similar but does not explicitly reference "completion" of incomplete data as a separate right. In practice, Swiss controllers should treat materially incomplete data (data that distorts the truth by omission) as inaccurate under Article 6(5) and subject to rectification, aligning with the GDPR standard.
The GDPR imposes a duty on the controller under Article 19 to communicate any rectification to each recipient to whom the personal data has been disclosed, unless this is impossible or involves disproportionate effort. Swiss law grants the data subject a request right under Article 32(1) FADP to have the controller communicate rectification to third parties; it is not an automatic duty. Controllers subject to both GDPR and FADP — for example, a Swiss company processing EU resident data, or an EU company with a Swiss representative under Article 14 FADP — should apply the stricter GDPR Article 19 notification duty for EU data subjects and honor Article 32(1) requests from Swiss data subjects. Many multinational controllers extend automatic rectification notification to all recipients globally to simplify compliance.
## Enforcement and remedies
A data subject whose rectification request is denied may pursue three remedies:
1. Complaint to the FDPIC — Article 49 FADP permits any person to file a complaint with the Federal Data Protection and Information Commissioner if they believe the FADP has been violated. The FDPIC has investigative authority under Article 50 and may issue binding orders under Article 51(1) requiring the controller to rectify inaccurate data, adjust processing, or delete data. FDPIC complaints are free and do not require legal representation.
2. Civil enforcement — Article 32(2) FADP incorporates the personality-rights protections of Articles 28 ff. of the Swiss Civil Code. The data subject may petition the competent cantonal court for an injunction requiring the controller to rectify inaccurate data, cease unlawful processing, or delete data. Under Article 32(3) FADP, the court applies a simplified procedure, and no court fees are charged for disputes relating to the right of access under Articles 25–27 FADP. Courts frequently apply the fee waiver by analogy to other data-subject-rights disputes under Article 32(2), including rectification claims, though the statutory text does not mandate this extension.
3. Criminal liability for intentional false information — Article 60(1)(a) FADP provides that a natural person who intentionally provides false or incomplete information in response to an access request under Articles 25–27 FADP is subject to a fine of up to CHF 250,000. This penalty applies when the controller deliberately provides inaccurate data in response to an Article 25 access request (for example, falsely stating that no data is being processed, or omitting material data from the response). Article 60 does not directly penalize refusal to rectify inaccurate data, because rectification is governed by Article 32(2), not Articles 25–27. However, intentional failure to comply with an FDPIC order under Article 51 FADP (including an order to rectify data) may trigger criminal penalties under Article 63 FADP: a fine of up to CHF 250,000 for the responsible natural person, prosecuted on complaint.
## Practical implications for controllers
Controllers processing Swiss personal data should:
- Implement correction workflows — Establish procedures to receive, log, verify, and process rectification requests. Assign responsibility to a data-protection officer, privacy team, or designated contact for timely response.
- Verify before correcting — When a data subject asserts that data is inaccurate, investigate the claim by checking source records, re-verifying with third-party data providers, or requesting supporting documentation from the data subject. Do not automatically overwrite data without verification, as this may introduce new inaccuracies or create liability if the original data was correct.
- Document disputes — When accuracy cannot be confirmed, use the Article 32(1) disputed-data marking mechanism or invoke restriction under Article 32(2)(b) to preserve the data for potential litigation while signaling the dispute to downstream recipients.
- Notify recipients when requested — Honor Article 32(1) requests to communicate rectification to third parties unless disclosure was anonymous or notification is disproportionately burdensome. For controllers subject to GDPR Article 19, automate recipient notification globally.
- Maintain accuracy proactively — Article 6(5) is a continuing obligation. Implement data-quality controls, periodic reviews of high-risk data (credit records, health data, employment records), and update mechanisms so data remains current for its processing purpose.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 6(5) Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 32 Source: FDPIC, Right to information
Right to erasure of personal data — Article 32(2)(c) FADP and grounds for refusal
Article 32(2)(c) of the Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) gives data subjects in Switzerland the right to request erasure (deletion or destruction) of their personal data. This erasure right forms part of the set of individual remedies available when processing is unlawful or no longer justified. While the structure of the FADP is inspired by the GDPR, the substantive and procedural scope of erasure under Swiss law is distinct and must be understood on its own statutory terms.
## Statutory right — Article 32(2)(c) FADP Article 32(2) FADP allows the data subject to ask the controller to:
- (a) cease unlawful or personality-violating processing or disclosure;
- (b) restrict processing;
- (c) have personal data deleted or destroyed.
Erasure is typically available when processing is unlawful, the purpose for collection and retention has expired, or the legal ground for processing (such as consent) has been withdrawn and there is no other justification under Article 31. If the controller finds that none of the legal grounds listed in Article 31 FADP remain, it must erase the data at the data subject’s request.
## Refusal grounds — legal retention duties and overriding interests The FADP provides for exceptions where erasure may be refused:
- Statutory retention requirements: Where a controller is obligated by law to retain certain personal data (for example, minimum retention periods for tax or commercial records under the Swiss Code of Obligations), it may deny erasure until those legal duties lapse. This is supported by the general principle in Article 6(4) FADP that retention must not exceed what is necessary for the processing purpose and must stop when a legal ground ceases to exist. The FADP itself does not enumerate a list of retention requirements; controllers must refer to applicable sectoral statutes.
- Overriding legitimate interests of the controller or third parties: If continued retention is justified by the controller’s own interests, or those of a third party, and the data subject’s interests do not override these, erasure can be refused according to Article 31(2)(c) FADP. An example is the retention of data for defense against potential legal claims during statutory limitation periods.
- Protection of third-party or public interests: Under Article 6(2) FADP, processing, including denial of erasure, must remain proportionate, weighing the rights of the data subject against those of others and the public.
Controllers are required to inform data subjects if an erasure request is denied and must, on request, mark disputed data as such or consider other remedies under Article 32(1) FADP.
## Operational considerations and limitations The statute does not specify a formal mechanism or deadline for responding to erasure requests. While many controllers align their response timelines with the 30-day period prescribed for access requests in Article 25(7) FADP, this is a best practice rather than a legal obligation. The scope of erasure is not defined in technical detail—permanent deletion or irreversible anonymization are established approaches, but the FADP does not mandate a particular destruction standard.
If erasure is carried out and the controller has disclosed the personal data to third parties, the data subject may request that these recipients be notified of the erasure or correction (Article 32(1) FADP). This is not automatic and is required only where notification is proportionate and possible.
## Enforcement A data subject whose erasure request is wrongly refused may file a complaint with the Federal Data Protection and Information Commissioner (FDPIC), or request a civil injunction through the cantonal courts under Article 32(2) FADP. Intentional disregard of an FDPIC order to erase data can result in a fine for the responsible person, up to CHF 250,000, as per Article 63 FADP.
## Note on GDPR comparison Unlike the GDPR’s “right to be forgotten” (Art. 17), FADP Art. 32(2)(c) does not expressly address public search de-listing or online erasure of published information. When public availability is at issue, data subjects may need to invoke broader personality rights under the Swiss Civil Code; such remedies are not directly grounded in FADP Article 32(2)(c).
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 32(2)(c)
Verification of data subject identity for rights requests — FADP requirements and FDPIC guidance
Swiss controllers must verify the identity of a data subject before granting rights requests—such as access, rectification, erasure, or portability—under the Federal Act on Data Protection of 25 September 2020 (FADP). The statute does not prescribe a detailed authentication protocol, but both Article 25 FADP and official guidance from the Federal Data Protection and Information Commissioner (FDPIC) require "appropriate" verification to ensure that only the data subject receives information or exercises rights over their personal data.
## Legal basis for identity checks
Article 25 FADP (right to information/access) and Article 32(1)-(2) FADP (rectification, cessation, restriction, erasure) provide rights to the individual concerned (the data subject). Controllers must take "appropriate steps" to confirm identity before fulfilling such requests. The FDPIC explicitly states: "If you request access to your data, the controller must check your identity in an appropriate manner. If it cannot confirm your identity, it may refuse to provide information." The law allows refusal until identity is reasonably established; this is not limited to access requests, but the explicit language in the statute and FDPIC guidance is clearest for Article 25.
The FADP does not enumerate precisely how identity must be checked. The FDPIC does not require a specific form of ID or a uniform procedure, and emphasizes proportionality (Art. 6(2) FADP): controllers should not collect or retain excessive identity information. The FDPIC’s guidance states that requesting official ID or additional verification can be appropriate “if there is doubt" as to the requester's identity—especially for requests concerning especially sensitive personal data.
## Proportionality, data minimization, and process limitations
Controllers must choose verification procedures that are neither excessive nor insufficient in the context. For known customers, employees, or account holders, relying on existing credentials may be sufficient. If the relationship is arm’s-length or remote, controllers may ask for supplementary evidence, but must avoid overcollection. The FADP does not establish a statutory requirement to delete copies of ID documents after use, but general data minimization and purpose limitation principles (Art. 6(2)-(3) FADP) imply that retention beyond what is necessary is discouraged; the FDPIC guidance does not specify a timeline for such deletion.
## Refusing manifestly unfounded or unverifiable requests
Under Article 26(1)(c) FADP, a controller may refuse to act on a request it deems manifestly unfounded, including when it cannot reasonably verify the requester’s identity. The FDPIC guidance confirms this point: "The controller may decline to respond to your request if serious doubts as to your identity remain even after reasonable verification steps." Any refusal must be communicated to the requester. Where the request is for access (Art. 25), the controller must respond or explain its refusal within the 30-day deadline of Article 25(7) FADP. For other rights requests, such as rectification or erasure, the FADP does not specify an exact statutory response time, but best practice is prompt notification.
## Third-party requests and representation
When a request is made by a party acting on behalf of the data subject (e.g., a parent, legal guardian, or authorized representative), the FDPIC expects controllers to require evidence of the third party's identity and their authority to act (such as a power of attorney or evidence of parental responsibility). The statute is silent on detail, but controllers should ensure that authorizations are documented and sufficient before proceeding.
If the controller refuses a request for lack of verification, the data subject or their representative may file a complaint with the FDPIC (Art. 49 FADP). The FADP does not provide for a specific penalty relating only to misuse of identity documents, but criminal fines under Article 63 FADP may apply for intentional, unlawful violations of the Act more broadly.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1 Source: FDPIC, Knowing and asserting my rights
Notification of recipients after rectification or erasure — Article 32(1) FADP
Article 32(1) of the Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) gives data subjects the right to request that the controller notify third parties (recipients) about rectification or erasure of their personal data, or the cessation of unlawful processing. This right addresses the downstream propagation of data corrections and deletions when personal data has been disclosed to others.
## Statutory scope — what Article 32(1) requires
Article 32(1) FADP provides: "If the controller has disclosed personal data, the data subject may request that the rectification, destruction, or cessation of processing or disclosure be communicated to third parties or that the data be marked as disputed." The right is on request—controllers are not required to notify every recipient automatically. Only those third parties to whom data was actually disclosed fall within scope; internal departments or personnel within the same entity are generally not considered "third parties" for this purpose. The FADP does not specify a deadline or form for such notifications, leaving the operational details to the controller's reasonable judgment, informed by proportionality and context.
When erasure or rectification is carried out due to a data subject request (and not merely as routine data maintenance), the controller must, at the data subject's request, inform each recipient unless (1) the disclosure was anonymous, (2) notification would be impossible or require disproportionate effort, or (3) there is a statutory or overriding legitimate interest against notification. For example, notification can be refused where it would breach secrecy obligations or expose third parties to risk—these are evaluated under the FADP’s proportionality principle (Art. 6(2)).
## Practical application—recipient mapping and documentation
Controllers should keep records of all third-party disclosures. If no record is kept, and the recipients cannot be reasonably identified, the controller may decline notification on the grounds of impossibility. Best practice (especially for cross-border data transfers or onward sharing in cloud/SaaS environments) is to maintain up-to-date records of data flows so proper notification—if requested—can be carried out promptly and accurately. The FADP does not require companies to build new technical systems solely for this purpose, but notification must be feasible where records exist.
## Interaction with restriction and disputed marking
If the data subject disputes the accuracy of data and rectification is not agreed, Article 32(1) also allows the data subject to request that disputed data be marked as such for all third-party recipients. The same practical and legal limitations apply as for notification following rectification or erasure.
## Comparison to GDPR
While GDPR Article 19 imposes an automatic duty to notify recipients of rectification or erasure (unless impossible or disproportionate), Swiss law makes notification contingent on a request. Multinational controllers subject to both GDPR and FADP should consider adopting GDPR's higher standard as a global baseline, but are not required to under Swiss law alone.
## Enforcement
If a controller refuses notification, the data subject may file a complaint with the Federal Data Protection and Information Commissioner (FDPIC) under Article 49 FADP, or seek civil enforcement under Article 32(2). Deliberate failure to comply with an FDPIC order to notify recipients may lead to fines under Article 63 FADP.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 32(1)
Right to lodge a complaint with the FDPIC — Article 49 FADP procedure and outcomes
Article 49 of the revised Federal Act on Data Protection of 25 September 2020 (FADP; revFADP), in force since 1 September 2023, gives data subjects an explicit right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) when they believe that the FADP or its implementing ordinances have been violated by a controller or processor. This right complements the personal remedies of rectification, erasure, or restriction under Article 32 and creates a public-administrative channel for oversight when individual rights requests are refused, delayed, or inadequately resolved.
Statutory rule — Article 49 FADP Article 49(1) FADP provides: "Any person may file a complaint with the Commissioner if they believe that their personality rights have been violated by the processing of personal data or that the FADP or implementing provisions have otherwise been breached." There is no requirement for the complainant to be a Swiss resident or citizen; the right is open to any person, and the threshold is subjective—if the complainant alleges a violation, the FDPIC must consider admissibility and the merits. The complaint is free of charge, and legal representation is not required.
Scope and procedure A data subject may submit a complaint to the FDPIC in writing, by email, or using online forms provided by the Commissioner. Submissions should identify the complainant, the controller (or processor), and the nature of the data processing and alleged legal violation. The FDPIC may request further information. Article 49(2) FADP provides that the Commissioner will investigate if there is an "indication" of a breach. During investigation, the FDPIC has powers under Articles 50–51 FADP to request records, conduct interviews, and undertake on-site reviews. The procedure is informal compared to judicial proceedings: orders and remedial actions by the FDPIC under Article 51(1) are binding unless appealed to the Federal Administrative Court (Article 53 FADP).
Commissioner’s outcomes and remedies If the FDPIC finds a violation, it can order the controller or processor to rectify, suspend, or terminate data processing, to delete or destroy data, or to fulfill the statutory rights of the data subject. These binding orders, made under Article 51(1) FADP, must be complied with unless overturned on appeal. While the FDPIC cannot award damages or impose fines for the original violation itself, intentional non-compliance with a binding order is a criminal offense under Article 63 FADP and is penalized by fine. Civil compensation for privacy invasions is only available by separate judicial action under Article 32(4) FADP and the Swiss Civil Code.
Practical notes
- Complaints may be submitted in German, French, Italian, or English.
- There is no statutory deadline for the FDPIC’s decision, but proceedings are designed to be prompt and accessible.
- Use of the complaint channel does not prevent recourse to cantonal courts (Article 32 FADP) for civil enforcement.
- The FDPIC complaint channel is also used for systemic or large-scale breaches, not only refused rights requests.
Broken link repair: The previous link to the "File a complaint" page on the FDPIC website has moved. The currently official resource is now at: https://www.edoeb.admin.ch/edoeb/en/home/der-edoeb/kontakt/adressen.html. This URL leads to the FDPIC’s official contact page, which includes practical guidance for making complaints and current contact modalities. The legal substance of rights under Article 49 FADP is unchanged as of June 2026.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 49–51 Source: FDPIC, official contact and complaints submission
Right to have personal data marked as disputed — Article 32(1) FADP
Article 32(1) of the Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) states that a data subject may request personal data to be "marked as disputed" when there is a disagreement with a controller about the accuracy or lawfulness of processing. The relevant text provides: "If the controller has disclosed personal data, the data subject may request that the rectification, destruction or cessation of processing or disclosure be communicated to third parties or that the data be marked as disputed." This right operates independently of rights to rectification or erasure and is available when the parties cannot agree whether the data is inaccurate or should be deleted.
The statute does not specify the technical form or minimum content for such a "disputed" mark. The controller must, at minimum, record this status internally, though Article 32(1) explicitly links this right to situations of prior disclosure to third parties. Where a controller has disclosed the data and the data subject requests it, the controller is required by Article 32(1) to inform third parties that the data is disputed, but FADP is silent as to any further obligations for recipients once notified.
The FADP does not set a specific timeline, duration, or process for resolving the dispute or removing the disputed status; these operationalities are not described in statute and cannot be confirmed from published guidance as of June 2026. Consequently, how long the disputed mark remains visible, whether it is propagated downstream by recipients, and the precise manner of communication are governed by the controller’s practices and general statutory good faith (Art. 6(2) FADP) and documentation principles.
If a data subject believes the controller has failed to honor a request to mark data as disputed, Article 32(1) does not name a specific remedy unique to this situation. However, under the FADP framework, general remedies include complaint to the Federal Data Protection and Information Commissioner (FDPIC) or seeking civil enforcement. The statute itself provides no criminal penalty specifically for failure to mark data as disputed.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 32(1)
Judicial enforcement and simplified procedure for access rights — Article 32(3) FADP and cost waiver in cantonal courts
Article 32(3) of the Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) provides a mechanism for data subjects in Switzerland to enforce their right of access (Arts. 25–27 FADP) before the civil courts. This article establishes that, in disputes relating specifically to the right of access, Swiss cantonal courts must apply a simplified procedure ("vereinfachtes Verfahren" / "procédure simplifiée" / "procedura semplificata") and may not charge any court fees to the parties.
Scope — Access disputes only: Article 32(3) states: "The court applies a simplified procedure for disputes relating to the right of access under Articles 25—27. No court fees may be charged." The cost waiver and the mandatory use of the simplified procedure are limited to access cases—there is no statutory obligation for courts to extend these procedural benefits to other data subject rights (such as rectification or erasure). While in practice some courts may exercise discretion to waive fees in related privacy proceedings, this is not prescribed by the FADP or verified in federal guidance as of June 2026.
Nature of the simplified procedure: Under Article 243 of the Swiss Code of Civil Procedure (CCP, SR 272), the simplified procedure applies to less complex cases and mandates streamlined evidence and argument presentation. The process is designed to be accessible and efficient, and Article 32(3) FADP explicitly triggers this in the data-access context. However, the CCP does not create special rules solely for FADP enforcement but applies the same simplified model used for small claims, tenancy, and certain statutory matters. Parties are not required to have legal representation, and courts may more actively assist with fact-finding than in ordinary procedure. Appeals from access-rights claims may result in costs unless specifically waived by the appellate court.
Enforcement and remedies: If the data subject is successful, the court may order the controller to provide access or otherwise comply with Articles 25–27. Article 32(4) FADP further enables a data subject whose personal rights have been infringed to claim compensation for damages (including moral damages) as provided by Articles 28 ff. of the Swiss Civil Code, but monetary awards are rare and hinge on proof of actual harm. The court’s decision is enforceable under standard civil rules.
Relationship to administrative routes: Prior to filing in civil court, data subjects are encouraged—but not required—to seek resolution directly with the controller or file a complaint with the Federal Data Protection and Information Commissioner (FDPIC, Art. 49 FADP). Judicial enforcement is available in parallel if voluntary or administrative resolution fails.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 32(3)-(4) Source: Swiss Code of Civil Procedure, SR 272, Art. 243 et seq. Source: FDPIC, official contact and complaints submission
Children’s rights and parental representation under Swiss FADP — age, consent, and exercising data subject rights
Swiss data protection law—the Federal Act on Data Protection of 25 September 2020 (SR 235.1, often called the revised FADP or "revFADP")—does not contain dedicated provisions for children’s data subject rights or parental representation, nor does it specify an age threshold for a child’s independent exercise of data subject rights.
## Statutory silence and general capacity rules
Unlike the GDPR (Art. 8), which requires parental consent for information society services offered to children under a set age (between 13 and 16 as chosen by each EU country), the revised FADP neither sets an express age of consent for data processing nor provides a bespoke mechanism for handling data subject requests made by—or on behalf of—minors. Article 4 FADP defines the data subject simply as the identified or identifiable natural person whose data is processed, with no mention of age. The Federal Data Protection and Information Commissioner (FDPIC) guidance also does not identify special procedures for child requests as of June 2026.
In practice, the capacity of minors to exercise rights under the FADP (access, rectification, erasure, etc.) falls back to general Swiss civil law: under the Swiss Civil Code (SR 210), minors (persons under 18) may generally act through their legal representative (parent or guardian), but may exercise their rights directly to the extent that they are "capable of judgment" (Art. 19(2) CC). This principle means that a child who understands the nature and consequences of the data processing and of making a request may exercise rights in their own name, but controllers may—and usually do—require proof of parental authority for younger children or where the controller doubts the minor’s capacity for judgment.
## Operational guidance and best practices
As of June 2026, the FDPIC has not published sector-specific rules or formal guidance for controllers receiving requests from or about children. Most organizations handling children’s data (e.g., in education, health, online platforms) apply a judgment-based approach: requests from very young children are routinely handled by parents/guardians, while older minors may act on their own if they demonstrate sufficient understanding. Controllers should record their verification and decision process. Data minimization (Art. 6(2) FADP) and proportionality principles apply—controllers should not collect more information than needed to verify identity and representation, and once a right is exercised, additional information (such as ID or parental verification) should be deleted when no longer necessary.
## Cross-border implications and comparison to GDPR
For groups subject to both GDPR and FADP, GDPR Art. 8 requirements (parental consent for children under relevant ages for ISS) apply to EU data subjects, but not to Swiss residents under Swiss law alone. For cross-border online services or apps targeting both markets, harmonizing practices to meet the stricter standard is advised for operational streamlining.
## Enforcement and open questions
Failure to provide for a child’s rights in line with civil capacity may be challenged before the FDPIC (Art. 49 FADP), but as of June 2026, there are no reported decisions establishing a contrary rule.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1 Source: Swiss Civil Code, SR 210, Art. 19–19c Source: FDPIC, Knowing and asserting my rights
Right to data portability — Article 28 FADP, technical format and preconditions
Article 28 of the revised Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1), effective 1 September 2023, grants data subjects in Switzerland a qualified right to portability of their personal data. This right allows a data subject to receive data they have provided to a controller in a commonly used electronic format or, where technically feasible, to have it transmitted directly to another controller of their choice.
Scope and preconditions — Article 28(1) FADP Article 28(1) FADP confers the right to obtain a copy of personal data in a commonly used electronic format only where both of the following conditions are met: (1) the processing is either based on the data subject’s consent or is directly connected with the conclusion or performance of a contract, and (2) the data subject supplied the data to the controller. This is narrower than the GDPR Art. 20 right, which also applies where processing is based on legitimate interests or legal obligations. Data "provided" by the data subject includes personal data actively furnished (such as filling in a form or uploading a document), but not data generated or derived by the controller.
Format and technical requirements — Article 28(2) FADP and Ordinance The law requires the controller to supply the data in a structured, commonly used electronic format that allows for further use by the data subject or for onward transfer to another controller with reasonable effort (Art. 21 Data Protection Ordinance, SR 235.11). The format must be machine-readable—examples include CSV, XML, or JSON for databases and raw text for documents. There is no requirement to use a specific format, but the choice must not frustrate the reuse of data. Where technically feasible, the controller must transmit the data directly to another controller if requested by the data subject (Art. 28(2) FADP).
Exclusions and limitations The portability right applies only to data the data subject has "provided"—not to inferred, observed, or derived data (e.g., profiles, risk assessments created by the controller) unless these are routinely transferred in comparable business contexts. The right may be refused if the request is manifestly unfounded (Art. 26(1)(c)), if disproportionate, or where involving professional secrecy/law mandates (Article 26(1)-(2) FADP applies by incorporation via Article 29).
Procedural requirements and timeline Portability requests must be fulfilled without delay; the recommended best practice is to apply the Article 25(7) FADP 30-day deadline for access—while Article 28 sets no unique timeline, this aligns with FDPIC expectations. Requests must be free of charge unless the Federal Council provides for exceptions (which it has not done as of June 2026).
Comparison to GDPR GDPR Article 20 is broader in scope but substantively similar in form; both require controllers to supply data in usable formats. Swiss controllers handling both EU and Swiss data should harmonize portability procedures to the higher (GDPR) standard unless this places undue technical burden on Swiss-only operations.
Remedies and enforcement If a controller fails to comply, data subjects may complain to the FDPIC (Art. 49) or pursue civil remedies (Art. 32(2)). There is no criminal liability for non-compliance with portability per se, but intentional violation of an FDPIC order is penalized under Article 63 FADP.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 28 Source: Ordinance on Data Protection of 31 August 2022, SR 235.11, Art. 21 Source: FDPIC, Knowing and asserting my rights
Media and journalistic exemption — Article 27 FADP limits on data subject rights for published media
Article 27 of the Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1), effective since 1 September 2023, provides a specific exemption for controllers processing personal data in the context of periodically published media, when such processing is performed for journalistic purposes. This exemption allows controllers—such as newspapers, broadcasters, and online media outlets—to refuse, restrict, or defer the exercise of certain data subject rights where doing so is necessary to protect editorial secrecy or journalistic confidentiality.
## Statutory scope — Article 27(1) and (2) FADP
Under Article 27(1) FADP, a controller may refuse, restrict, or defer a data subject’s request for information (access), rectification, erasure, or data portability if compliance would:
- Require the disclosure of information about sources;
- Reveal the content of unpublished material;
- Threaten editorial secrecy or professional confidentiality.
The exemption is limited to processing carried out for journalistic purposes in periodically published media; it does not automatically apply to all personal data processing by a media organization. Routine business functions outside of editorial or journalistic activity, such as subscriptions or HR management, are not covered by this exemption and remain subject to full data subject rights under the statute. Article 27(2) FADP requires that the refusal or restriction be justified as necessary to protect these interests, but does not provide further procedural or evidentiary details.
The statute does not define a formal process for invoking the exemption or require controllers to issue detailed written justifications. Operationally, controllers should assess whether honoring a rights request would actually jeopardize protected interests and document their reasoning in case of challenge. Where Article 27 is invoked, it is best practice for controllers to state the legal ground and the category of protected interest (e.g., source confidentiality) in their response to the data subject.
## Remedies and procedural notes
If a data subject disagrees with a controller’s invocation of the Article 27 exemption, the FADP does not set a specific procedure for contesting the refusal. However, the data subject may file a complaint with the Federal Data Protection and Information Commissioner (FDPIC) under Article 49 FADP. The FDPIC will consider whether the exemption was correctly applied, but Article 27 itself is silent as to the standard or limited grounds for review. Civil remedies under Article 32 FADP may also be available if misuse of the exemption is alleged, though Article 27 does not expressly regulate court procedures.
## Comparative context
Article 27 FADP is the Swiss implementation of safeguards for freedom of expression and information, roughly paralleling GDPR Article 85, which requires EU Member States to reconcile privacy with journalistic freedoms. Unlike the GDPR, Article 27 FADP spells out the exemption directly in the federal statute, but the practical boundaries and operational requirements remain to be further clarified by case law or guidance as of June 2026.
Source: Federal Act on Data Protection of 25 September 2020, SR 235.1, Art. 27