Data protection advisor — Art. 10 FADP voluntary appointment for private controllers, mandatory for federal bodies
Under the revised Federal Act on Data Protection (FADP), which entered into force on 1 September 2023, the appointment of a data protection advisor (Datenschutzberater / conseiller à la protection des données) is voluntary for private companies but mandatory for federal bodies. This marks a significant divergence from the EU GDPR, which imposes DPO appointment requirements on many private controllers based on processing scale, sensitivity, and monitoring activities.
Private-sector appointment (Art. 10 para. 1–3 FADP)
Private controllers may designate a data protection advisor. The statute does not require the advisor to be an employee; the role may be filled by an external consultant or legal entity. Article 10 para. 3 FADP requires that the advisor be able to carry out their function independently and not be bound by the data controller's instructions. The FDPIC has stated in official guidance that data-protection advice should be separate from the business's other activities to preserve this independence, and that the advisor's place in the organizational hierarchy should reflect this; the FDPIC recommends that the advisor report to the executive board and have the right to escalate important cases to top-level management.
DPIA exemption benefit of notification
Private companies that notify the FDPIC of their data protection advisor pursuant to Art. 10 para. 3 FADP unlock a significant compliance benefit: after conducting a data protection impact assessment (DPIA) under Art. 22 FADP, the controller may rely solely on the advisor's internal opinion and is not required to consult the FDPIC, even when the residual risk to data subjects' privacy or fundamental rights remains high. Without a notified advisor, controllers must seek the FDPIC's opinion whenever the DPIA shows that significant risk persists despite proposed safeguards. Notification is submitted through the FDPIC's online portal; the FDPIC's operational guidance indicates that controllers need a CH-Login or FED-Login (for federal-administration users), with each account tied to exactly one controller entity.
Federal-body appointment (Art. 10 para. 4 FADP)
Federal bodies—agencies and instrumentalities of the Swiss federal government—must appoint a data protection advisor and notify the FDPIC. The same statutory independence requirements apply.
Advisor responsibilities and access
The statute itself does not prescribe detailed duties. The FDPIC's published guidance states that the data protection advisor's primary task is to monitor and control data processing activities within the organization, but the advisor should not have decision-making authority over those processes and should not be responsible for an information system—the advisor's role is advisory and oversight, not operational. The controller must provide the advisor with the resources necessary to fulfill their duties and ensure the advisor has access to required information, documents, data-processing records, and personal data; the FDPIC notes that access should be proportionate to the task and that the advisor does not necessarily need access to personal data when performing general checks of internal rules or procedures.
No DPO mandate for private entities
Unlike the GDPR, the FADP imposes no DPO appointment requirement on private companies, regardless of the scale or nature of processing. The voluntary regime gives companies flexibility in governance structure. The FDPIC has observed in public commentary that meeting the FADP's substantive obligations—maintaining a register of processing activities, conducting DPIAs, managing breach notifications under Art. 24 FADP—is difficult without someone assigned to data-protection oversight, and the commissioner has recommended that even companies choosing not to appoint a formal advisor designate at least one person responsible for data protection in the operational phase. That recommendation, however, is not a statutory obligation.
Cross-reference to ROPA reporting
The data protection advisor notification portal is distinct from the DataReg portal used for reporting entries from the register of processing activities (ROPA) under Art. 12 FADP. Federal bodies are obliged to report ROPA entries to the FDPIC; private controllers are exempt from the ROPA reporting obligation as of 1 September 2023, though they remain obligated to maintain the register itself if they meet the statutory thresholds (more than 250 employees, or processing of sensitive personal data on a large scale, or high-risk profiling).
Source: Art. 10 FADP — FDPIC official page on data protection advisors Source: FDPIC FAQ on voluntary appointment for private controllers Source: FDPIC explanation of Art. 12 FADP ROPA reporting exemption for private controllers
Register of processing activities (ROPA) — Art. 12 FADP maintenance requirement and SME exemptions
Article 12 of the Federal Act on Data Protection (FADP), in force since 1 September 2023, requires both data controllers and data processors to maintain a register of processing activities (Verzeichnis der Bearbeitungstätigkeiten / répertoire des activités de traitement / ROPA). This parallels the GDPR Article 30 obligation but includes statutory exemptions tailored for Swiss SMEs and different reporting rules for public versus private entities.
Baseline obligation — controllers and processors
Both the controller (the entity that determines the purposes and means of processing, Art. 5(j) FADP) and the processor (the entity that processes personal data on behalf of the controller, Art. 5(k) FADP) must keep a register. The Federal Data Protection and Information Commissioner (FDPIC) has stated in published guidance that the register is "a general description of the processing activities" that serves two statutory functions: transparency and documentation of compliance with the FADP's substantive obligations.
SME exemption — Art. 12 FADP and the Data Protection Ordinance (DPO)
The FADP and its implementing Data Protection Ordinance (DPO, SR 235.11) provide a partial exemption for private controllers and processors that meet size and risk thresholds. According to the FDPIC's official guidance and the KMU (Swiss Federal Office for SMEs) explanatory materials, private entities with fewer than 250 employees are exempt from maintaining a ROPA provided their data processing presents a limited risk of harm to the data subject's personality rights or fundamental rights.
Two exceptions to the exemption eliminate the benefit for many SMEs:
- Large-scale processing of sensitive personal data (Art. 5(c) FADP defines sensitive data: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health, sexual life or orientation, genetic data, biometric data for unique identification, data on administrative/criminal proceedings or sanctions, and data on social-assistance measures). The ordinance does not set a numerical threshold for "large scale"; the FDPIC has indicated in sectoral guidance (e.g., clubs and associations, health-sector employers) that this is a facts-and-circumstances analysis turning on the volume of data subjects, the geographic scope, and the duration of processing. An employer processing health data for 100 employees may meet the threshold; a club processing membership data for 1,000 individuals whose religious affiliation is recorded may also meet it.
- High-risk profiling (Art. 5(f) FADP defines profiling as "any automated processing of personal data that consists of using such data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects relating to that person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements"; Art. 5(g) defines high-risk profiling as profiling that entails a high risk to the data subject's personality or fundamental rights because it leads to linking of data in a manner that allows an evaluation of essential aspects of the data subject's personality). Controllers and processors engaging in high-risk profiling must maintain the ROPA regardless of company size or employee count.
The FDPIC's published technical and organizational measures guidance (TOM_EN.pdf, January 2024) notes that the exemption is narrow: "Clubs and associations with fewer than 250 employees (including volunteers) whose processing activities involve only a low risk of breaches of personality rights are generally exempt from keeping records, unless they process a large volume of sensitive personal data or carry out high-risk profiling." In practice, entities processing health data, conducting employee monitoring, or using automated decision-making tools usually fall outside the exemption.
Mandatory content — Art. 12 paras. 2 and 3 FADP
When the obligation applies, the register must contain minimum information specified by statute. For controllers, the ROPA must include (Art. 12 para. 2 FADP):
- Identity and contact details of the controller;
- Purposes of the processing;
- Categories of data subjects and categories of personal data processed;
- Categories of recipients to whom personal data are disclosed, including processors;
- Where personal data are disclosed abroad: the countries or international organizations involved and the safeguards ensuring an appropriate level of protection under Art. 16 FADP (adequacy decision, standard contractual clauses, binding corporate rules, or derogations);
- The time limits for erasure of the different categories of data (or criteria for determining those limits);
- A general description of the technical and organizational measures ensuring data security under Art. 8 para. 3 FADP.
For processors, the ROPA must include (Art. 12 para. 3 FADP):
- Identity and contact details of the processor and, where applicable, of the controller on whose behalf the processor is acting;
- Categories of processing carried out on behalf of the controller;
- Where personal data are disclosed abroad, the same cross-border transfer information required of controllers.
The FDPIC has noted that the cross-border disclosure entries are mandatory whenever data are made accessible outside Switzerland—this includes cloud hosting in foreign data centers, remote access by employees abroad, and disclosure to foreign processors or controllers—and the register must specify not only the country but also the legal safeguard relied upon (e.g., "USA — Swiss-U.S. Data Privacy Framework adequacy decision (Federal Council Decision of 15 September 2024)"; "UK — EU Commission adequacy decision for UK under GDPR, recognized by Switzerland"; "India — standard contractual clauses pursuant to Art. 16 para. 2 let. d FADP").
Federal bodies: reporting obligation vs. private entities: exemption from reporting
Article 12 FADP draws a sharp distinction between federal bodies (agencies and instrumentalities of the Swiss federal government) and private controllers/processors. Federal bodies are required to report entries from their ROPA to the FDPIC using the DataReg portal (https://datareg.edoeb.admin.ch). The FDPIC publishes federal-body entries in a publicly accessible register pursuant to Art. 56 FADP.
Private controllers and processors are exempt from the reporting obligation as of 1 September 2023. The FDPIC's DataReg guidance states plainly: "Federal bodies are obliged to report entries from the register of processing activities to the FDPIC in accordance with Article 12 FADP. Private individuals were exempted from the reporting obligation when the revised Data Protection Act (FADP) came into force on 1 September 2023." This marks a significant reduction in administrative burden compared to the prior law (the old FADP required certain private data files to be registered). Private entities must still maintain the register and produce it upon request by the FDPIC during an investigation under Art. 49 ff. FADP, but they do not file it proactively.
Relationship to DPIA and data protection advisor
The ROPA is a standing inventory of processing activities; it is conceptually distinct from the data protection impact assessment (DPIA) required by Art. 22 FADP for processing that is likely to result in a high risk to the data subject's personality or fundamental rights. A DPIA is a prospective risk analysis conducted before the controller begins a specific high-risk processing operation. The ROPA documents all processing activities—high-risk and routine—and must be kept current. The FDPIC's guidance recommends that controllers cross-reference DPIA outcomes in the ROPA's "general description of security measures" field when a DPIA has been completed for a given processing activity, to aid auditability.
Private controllers that have notified the FDPIC of a data protection advisor under Art. 10 para. 3 FADP may rely on the advisor's internal opinion after conducting a DPIA, rather than consulting the FDPIC, even when residual risk remains high. This DPIA-consultation exemption does not reduce the ROPA maintenance obligation, but it simplifies the workflow for controllers that have designated and notified an advisor.
No obligation = no penalty, but "encouraged" by the FDPIC
Entities that fall within the SME exemption (fewer than 250 employees, low-risk processing, no large-scale sensitive data or high-risk profiling) are not legally required to maintain a ROPA. The FDPIC has nonetheless publicly recommended that even exempt controllers maintain at least a minimal internal inventory of processing activities, observing that "keeping records is a useful way of keeping an adequate eye on the processing procedures" and that meeting other FADP obligations—breach notification under Art. 24, data-subject rights under Arts. 25–28, cross-border transfer safeguards under Art. 16—is difficult without documented knowledge of what data the entity processes and where. This recommendation does not create a legal obligation, and the FDPIC has no enforcement authority to compel a ROPA from an exempt entity absent a separate FADP violation.
Source: FDPIC — DataReg: Report of processing activities Source: FDPIC — Cross-border transfer of personal data (Art. 12 FADP ROPA requirements) Source: FDPIC — Data protection in clubs and associations (Art. 12 exemption criteria) Source: FDPIC — Technical and Organizational Measures (TOM) guidance, January 2024 Source: Swiss Federal Office for SMEs (KMU) — New Federal Act on Data Protection
Data protection impact assessment (DPIA) — Art. 22 FADP high-risk triggers and Art. 23 FDPIC consultation requirement
Articles 22 and 23 of the Federal Act on Data Protection (FADP), in force since 1 September 2023, require both private controllers and federal bodies to conduct a data protection impact assessment (DPIA) when planned processing is likely to result in a high risk to the personality or fundamental rights of data subjects. The DPIA is a prospective risk analysis that must be completed before the processing begins, documenting the planned processing, evaluating the risks, and specifying measures to protect data subjects' rights. When residual risk remains high despite those measures, the controller must seek a prior opinion from the Federal Data Protection and Information Commissioner (FDPIC) under Article 23 FADP—unless the controller has notified a data protection advisor under Article 10 para. 3 FADP and may rely on that advisor's internal opinion instead.
Obligation trigger — high-risk processing (Art. 22 para. 1 FADP)
A DPIA is mandatory when "the planned processing of personal data is likely to result in a high risk to the personality or fundamental rights of the data subjects." The FDPIC has published an official factsheet on DPIA procedure (August 2023) that provides a three-step risk-assessment framework to determine whether a DPIA is required:
Step 1: Absolute risk factors (Art. 22 para. 2 FADP)
Two categories of processing automatically trigger the DPIA obligation regardless of other circumstances:
- Large-scale processing of sensitive personal data (Art. 5(c) FADP defines sensitive data: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health, sexual life or orientation, genetic data, biometric data for unique identification, data on administrative/criminal proceedings or sanctions, and data on social-assistance measures). The statute does not quantify "large scale"; the FDPIC's guidance indicates this is a facts-and-circumstances analysis turning on the number of data subjects, geographic scope, and duration. Processing health data for 100 employees or membership data involving religious affiliation for 1,000 club members may meet the threshold.
- Systematic large-scale surveillance of public areas (Art. 22 para. 2(b) FADP). The FDPIC's published guidance on AI and data protection notes that video surveillance using facial recognition or behavior analysis typically falls within this category.
If either absolute risk factor is present, the controller must conduct a DPIA. The FDPIC's factsheet states: "If at least one of the absolute risk factors is present, a DPIA must be carried out."
Step 2: Well-known risk factors
If no absolute risk factor applies, the FDPIC recommends checking for "well-known" risk indicators derived from EDPB guidelines and Convention 108+ commentary, including:
- Systematic and extensive evaluation or scoring (including profiling and predicting behavior, especially where that influences legal or similarly significant effects);
- Automated decision-making with legal or similarly significant effects;
- Large-scale monitoring;
- Processing of data concerning vulnerable data subjects (children, employees, patients, asylum seekers);
- Innovative use or application of technological or organizational solutions (e.g., facial recognition, geolocation tracking, internet-of-things devices);
- Processing that prevents data subjects from exercising a right, using a service, or performing a contract.
The FDPIC's factsheet advises: "If any well-known risk factors apply, a DPIA should be carried out in case of doubt."
Step 3: General definition of high risk (Art. 22 para. 2 first sentence FADP)
If no absolute or well-known factor applies, the controller must evaluate whether "a high risk may arise from the nature, scope, circumstances and purpose of the processing, in particular when using new technologies." The FDPIC's guidance emphasizes that the legislative history (dispatch to the FADP) states a "high risk" is to be assumed when the specific characteristics of the planned processing indicate that the data subject's informational self-determination—the freedom to control their own data—will or may be restricted to a significant degree.
Timing — privacy by design (Art. 7 FADP)
The DPIA and the preliminary risk assessment that determines whether a DPIA is needed must be conducted as early as possible, during project planning, "even if the details of data processing have not yet been defined." Article 7 FADP (privacy by design and by default) requires that data-protection risks be assessed and mitigated at the design stage, before the processing goes live. The FDPIC's factsheet notes that if a processing operation is already ongoing and the controller plans to modify it, the DPIA must "indicate the main differences between the existing operation and the data processing that is planned."
DPIA content — Art. 22 para. 3 FADP and FDPIC factsheet
The statute does not prescribe detailed DPIA contents, but the FDPIC's August 2023 factsheet provides a structured framework that controllers should follow to meet the statutory obligation. A compliant DPIA includes:
- Description of the planned processing: purpose, categories of data subjects, categories of personal data, recipients (including processors and cross-border disclosures), retention periods, and a general description of technical and organizational measures ensuring data security.
- Description and assessment of potentially high initial risks: identification of specific risks to data subjects' personality or fundamental rights arising from the nature, scope, circumstances, and purpose of the processing, evaluated by likelihood and severity.
- Planned measures to reduce the potentially high initial risks: technical and organizational safeguards (encryption, access controls, pseudonymization, training, contractual commitments from processors) designed to bring the risk down.
- Remaining end risks: after applying the planned measures, an assessment of whether residual risk to data subjects' rights remains high. This determination governs the Art. 23 FDPIC-consultation requirement.
FDPIC consultation requirement — Art. 23 FADP high residual risk
If the DPIA shows that the planned processing still results in a high risk to data subjects' personality or fundamental rights despite the measures the controller plans to put in place, the controller must seek a prior opinion from the FDPIC. Article 23 FADP requires the FDPIC to deliver its opinion within two months. The FDPIC will examine the DPIA and inform the controller of any objections; the controller may not begin the processing until the FDPIC has issued its opinion or the two-month period has expired without objection.
Data protection advisor exemption — Art. 23 para. 2 FADP
Article 23 para. 2 FADP provides a carve-out for private controllers that have notified the FDPIC of their data protection advisor pursuant to Art. 10 para. 3 FADP. These controllers may rely solely on the advisor's internal opinion and are not required to consult the FDPIC, even when residual risk remains high. The FDPIC has stated in published guidance that the advisor must be able to carry out their function independently and not be bound by the controller's instructions, and that the advisor should report to the executive board with escalation rights to top-level management. Federal bodies do not benefit from this exemption; they must always consult the FDPIC when high residual risk persists.
Voluntary submission — no FDPIC obligation to act
The FDPIC's factsheet notes that if the controller voluntarily submits a DPIA to the FDPIC when not required to do so (for example, because residual risk is not high, or the controller has a notified data protection advisor), "the FDPIC is not required to act on it and take a substantive position." However, the FDPIC may, within the scope of its advisory activities, comment on residual risks that are no longer high. Article 59 para. 1(e) FADP authorizes the FDPIC to charge a fee for this advisory service; the Data Protection Ordinance specifies the fee schedule.
Relationship to ROPA and breach notification
The DPIA is a prospective risk analysis for a specific planned processing operation; it is conceptually distinct from the register of processing activities (ROPA) required by Art. 12 FADP, which is a standing inventory of all processing activities (high-risk and routine). The FDPIC's guidance recommends that controllers cross-reference DPIA outcomes in the ROPA's "general description of security measures" field when a DPIA has been completed for a given processing activity, to aid auditability and demonstrate compliance with the privacy-by-design obligation.
The DPIA is also distinct from the data security breach notification obligation under Art. 24 FADP. A DPIA evaluates prospective risk before processing begins; a breach notification addresses realized harm after a security incident. The FDPIC's April 2025 guidelines on breach notification note that "high risk" in the Art. 24 context (breach notification trigger) and the Art. 22 context (DPIA trigger) serve different purposes and require different analyses. Controllers conducting high-risk processing identified in a DPIA should document the expected security measures in the DPIA and ensure those measures are actually implemented; if a breach occurs despite those measures, the Art. 24 breach-notification analysis evaluates whether the breach is likely to result in a high risk given the circumstances of the incident and the effectiveness of any immediate remedial measures.
Criminal sanctions for willful non-compliance
Article 60 ff. FADP establishes criminal penalties for intentional violations of statutory obligations. Although the FADP does not impose a specific penalty for failure to conduct a required DPIA, Article 61(1)(c) FADP criminalizes the intentional violation of the duty of care in data processing (Art. 8 FADP), which includes the obligation to implement appropriate technical and organizational measures to ensure data security. The FDPIC's October 2022 guidance on the new FADP notes that the criminal sanctions under the FADP "will not normally be imposed on a legal entity, but rather on the natural person who is actually responsible for compliance with the FADP"—typically a person in a managerial position. Fines of up to CHF 250,000 may be imposed on the responsible natural person; legal entities can be fined up to CHF 50,000 as a subsidiary measure only. Willfully launching high-risk processing without a DPIA and without the required FDPIC consultation (when the Art. 23 obligation applies and no notified data protection advisor exemption exists) exposes the responsible manager to potential criminal liability.
Convention 108+ and EU GDPR alignment
The DPIA requirement under Art. 22 FADP aligns Switzerland's data-protection framework with Convention 108+ (the Council of Europe's modernized data-protection convention) and the EU GDPR Article 35 DPIA obligation. Switzerland ratified Convention 108+ concurrently with the revised FADP's entry into force on 1 September 2023. The FDPIC's August 2023 factsheet cross-references EDPB Guidelines 4/2019 on data protection by design and default (Art. 25 GDPR) and notes that the well-known risk factors in the factsheet's Step 2 analysis are derived from EDPB guidance on DPIA triggers under GDPR Article 35. Controllers processing data of both Swiss and EU data subjects can often use a single DPIA covering both regimes, provided the analysis addresses the requirements of both the FADP and the GDPR and the controller documents any regime-specific differences (e.g., the GDPR's mandatory consultation obligation under Art. 36 GDPR applies to all controllers, whereas the FADP Art. 23 consultation obligation permits private controllers with a notified advisor to rely on internal opinion).
Source: FDPIC — Factsheet on the data protection impact assessment (DPIA) in accordance with Articles 22 and 23 FADP (PDF, August 2023) Source: FDPIC — Data protection impact assessment Source: FDPIC — New FDPIC's role (Art. 23 FDPIC consultation requirement) Source: FDPIC — Research and data protection (Art. 22 DPIA triggers in research context) Source: FDPIC — AI and data protection (DPIA requirement for high-risk AI processing)
DPIA review and updating obligation — when controllers must revise a completed assessment
Controllers must review and update an existing data protection impact assessment (DPIA) when the nature, scope, context, or purpose of the processing changes in a way that affects the original risk analysis. Although Article 22 FADP does not expressly impose a statutory duty to update a completed DPIA, the Federal Data Protection and Information Commissioner (FDPIC) has stated in published guidance that when a data processing operation is already ongoing and the controller plans to modify it, the controller must "check the position and indicate in the DPIA the main differences between the existing operation and the data processing that is planned." This updating requirement flows from the broader obligation under Article 7 FADP (privacy by design and by default) to implement appropriate technical and organizational measures throughout the lifecycle of processing, not solely at the design stage.
Trigger for DPIA updates — material changes to processing
The FDPIC's August 2023 factsheet on DPIA procedure does not prescribe a fixed update schedule (such as annual or biennial review cycles), nor does it establish quantitative thresholds for when a change is sufficiently material to trigger an update. Instead, the FDPIC instructs controllers to conduct a facts-and-circumstances analysis: whether the planned change modifies the "nature, scope, circumstances and purpose" of the processing in a manner that could alter the risk to data subjects' personality or fundamental rights. The FDPIC's published guidance on privacy by design and by default cross-references EDPB Guidelines 4/2019 on Article 25 GDPR, which state that "the obligation to maintain, review and update, as necessary, the processing operation also applies to pre-existing systems" and that "a DPIA, or an update to an existing DPIA, may then additionally be required" when risks or processing parameters change.
Examples of changes likely to require a DPIA update, drawn from the FDPIC's sectoral guidance (research, AI, clubs and associations, and technical/organizational measures) and the EDPB Guidelines that the FDPIC explicitly cross-references, include:
- Adoption of new technologies affecting the processing — for example, migrating from on-premises storage to a cloud platform in a third country; deploying facial recognition, behavioral analytics, or machine-learning models where previously the controller used manual or rule-based processes; introducing Internet-of-Things devices or wearable sensors; or implementing algorithmic profiling that creates new high-risk processing under Article 5(g) FADP.
- Expansion of processing purposes — using personal data collected for one purpose (employee contact details for payroll) for a new purpose (targeted marketing or performance monitoring) that was not contemplated in the original DPIA and that may entail higher risk to data subjects' rights.
- Increase in scale or scope — processing that previously affected a limited number of data subjects (pilot project involving 50 employees) is scaled to the entire organization (5,000 employees), crossing the threshold for "large-scale processing of sensitive personal data" under Article 22 para. 2(a) FADP; or adding new categories of sensitive data (health data, biometric data, data on criminal proceedings) to a processing operation originally scoped for non-sensitive data.
- Changes to cross-border transfer arrangements — disclosing personal data to a new third country that was not addressed in the original DPIA, or switching from one transfer safeguard to another (for example, replacing standard contractual clauses with reliance on a newly adopted adequacy decision under Article 16 FADP, or vice versa if an adequacy decision is revoked). The FDPIC has noted in guidance on international transfers that the cross-border element is a key risk factor in the DPIA analysis, especially when foreign law may grant public authorities broad access to the data.
- Significant security incidents or new threat landscape — a high-profile data breach affecting similar processing in the same sector, or the emergence of new vulnerabilities in the technology stack (for example, discovery of a cryptographic weakness in the encryption algorithm the controller relies upon, or public disclosure of previously unknown surveillance capabilities by a foreign government in the destination country for a cross-border transfer), may change the likelihood or severity of risks identified in the original DPIA and require reassessment.
- Regulatory or supervisory guidance developments — publication of new FDPIC guidelines, EDPB opinions, or CJEU / Swiss Federal Supreme Court judgments that clarify or alter the risk calculus for a specific type of processing. For example, after the CJEU's Schrems II decision in July 2020 invalidated the EU-U.S. Privacy Shield and imposed supplementary-measure obligations for transfers to the United States, controllers relying on pre-Schrems II DPIAs for U.S. transfers were expected to update those DPIAs to reflect the heightened legal-access risk.
No automatic sunset or periodic refresh mandate under FADP
Unlike some data-protection regimes (certain U.S. state laws and sectoral frameworks mandate annual or biennial privacy-impact-assessment updates), the Swiss FADP does not impose a statutory deadline for DPIA review. The FDPIC has stated that the updating obligation is event-driven, not time-driven: controllers must monitor their processing operations and reassess when changes occur, but they are not required to refresh a DPIA solely because a calendar interval has elapsed if the processing, risks, and safeguards remain unchanged. That said, the FDPIC's guidance on technical and organizational measures recommends that controllers document the date of each DPIA and the date of any updates to facilitate auditability during an FDPIC investigation under Article 49 ff. FADP and to demonstrate compliance with the privacy-by-design obligation.
Relationship to the Art. 23 FDPIC consultation requirement
When a controller updates a DPIA and the revised assessment shows that high residual risk to data subjects' rights persists despite the new or modified safeguards, the controller must determine whether the Article 23 FDPIC consultation obligation applies. If the controller is a private entity that has notified the FDPIC of a data protection advisor under Article 10 para. 3 FADP, the controller may rely solely on the advisor's internal opinion and is not required to consult the FDPIC. Federal bodies do not benefit from this exemption and must always consult the FDPIC when high residual risk remains.
The FDPIC's August 2023 factsheet notes that if the controller voluntarily submits an updated DPIA to the FDPIC when not required to do so (because residual risk is not high, or the controller has a notified advisor), "the FDPIC is not required to act on it and take a substantive position." However, the FDPIC may, within the scope of its advisory activities, comment on the updated risk analysis; Article 59 para. 1(e) FADP authorizes the FDPIC to charge a fee for this service.
Documented revision history and version control
The FDPIC's published guidance on technical and organizational measures (TOM, January 2024) and the FDPIC's cross-reference to EDPB Guidelines 4/2019 both recommend that controllers maintain version control for DPIAs, clearly marking the date of the original assessment, the dates of subsequent updates, the triggering change or event for each update, and the person or team responsible for the update. This documentation serves three compliance functions:
- Demonstrating privacy by design — Article 7 FADP requires controllers to implement data-protection safeguards "at the time of the determination of the means for processing and at the time of the processing itself." A documented DPIA update history shows that the controller reassessed risks when processing evolved, satisfying the ongoing design obligation.
- Supporting data-subject rights responses — when a data subject exercises the right of access under Article 25 FADP and requests information about the logic and consequences of automated decision-making (Article 25 para. 2(g) FADP) or the right to object under Article 30 FADP, the updated DPIA provides the factual foundation for the controller's response, including the specific safeguards in place.
- Audit trail for FDPIC investigations — Article 49 ff. FADP grants the FDPIC broad investigatory powers, including the right to demand production of the DPIA and supporting documentation. A well-maintained update history demonstrates compliance and may reduce the scope or duration of the investigation.
Practical consequence of failure to update
The FADP does not impose a standalone penalty for failing to update a DPIA, but failure to update may constitute a violation of the Article 8 FADP duty of care (obligation to ensure data security through appropriate technical and organizational measures) or the Article 7 FADP privacy-by-design obligation. Article 61(1)(c) FADP criminalizes the intentional violation of the duty of care, punishable by a fine of up to CHF 250,000 on the responsible natural person (typically a person in a managerial position). The FDPIC's October 2022 guidance on the new FADP notes that criminal sanctions will "not normally be imposed on a legal entity, but rather on the natural person who is actually responsible for compliance with the FADP."
Moreover, if a controller continues high-risk processing based on an outdated DPIA that no longer reflects current risks, and a data security breach occurs as a result, the controller's failure to update the DPIA may be cited by the FDPIC as evidence of inadequate risk management, potentially supporting a finding of unlawful processing and triggering supervisory orders under Article 51 FADP (the FDPIC may order that processing be modified, suspended, or discontinued, or that data be deleted). The breach-notification obligation under Article 24 FADP is evaluated separately, but the FDPIC has noted in April 2025 breach-notification guidelines that "high risk" in the Article 24 context (breach notification trigger) and Article 22 context (DPIA trigger) serve different purposes; nevertheless, a current DPIA helps the controller conduct the Article 24 breach-risk assessment more accurately.
Alignment with GDPR Article 35 and Convention 108+
Switzerland's DPIA framework aligns with Convention 108+ (ratified by Switzerland on 1 September 2023) and the EU GDPR Article 35 DPIA obligation. The EDPB Guidelines on DPIA (WP 248 rev.01, endorsed by the EDPB) state that "DPIAs are living documents" and that "controllers should... continually assess the level of risk" and update the DPIA when processing changes. Controllers processing data of both Swiss and EU data subjects can often use a single, unified DPIA and update cycle covering both regimes, provided the documentation addresses the requirements of both the FADP and the GDPR and the controller notes any regime-specific divergences (for example, the GDPR Article 36 mandatory consultation obligation applies to all controllers, whereas FADP Article 23 permits private controllers with a notified advisor to rely on internal opinion).
Source: FDPIC — Data protection impact assessment Source: FDPIC — Factsheet on the data protection impact assessment (DPIA) in accordance with Articles 22 and 23 FADP (PDF, August 2023) Source: FDPIC — Technical and Organizational Measures (TOM) guidance (PDF, January 2024)
FDPIC fees for DPIA consultation and advisory services — Art. 59 FADP cost recovery for prior consultation under Art. 23
The Federal Data Protection and Information Commissioner (FDPIC) is required by statute to charge a fee when a controller seeks the FDPIC's opinion on a data protection impact assessment (DPIA) under Article 23 FADP or requests related advisory services under Article 59 FADP. This statutory fee obligation applies both to mandatory prior consultation when a DPIA shows high residual risk (Art. 23 para. 1 FADP) and to voluntary submissions when controllers seek the FDPIC's advisory opinion even though residual risk is not high or the controller has a notified data protection advisor and is exempt from the consultation requirement. The fee structure and legal basis are set out in Article 59 FADP and the Data Protection Ordinance (DPO, SR 235.11).
Statutory fee mandate — Art. 59 para. 1(e) FADP
Article 59 FADP authorizes the FDPIC to charge fees for specific services provided to private controllers and federal bodies. Article 59 para. 1(e) FADP states that the FDPIC must charge a fee "for the prior consultation provided for in Article 23." The FDPIC's August 2023 factsheet on DPIA procedure confirms this obligation: "The FDPIC's opinion is subject to a fee (Art. 59 FADP)." The statutory fee mandate is non-discretionary for Art. 23 consultations.
The fee requirement reflects a cost-recovery principle. Unlike some EU Member State supervisory authorities that fund DPIA consultation from general budget appropriations, Switzerland requires the requesting controller to bear the direct cost of the FDPIC's review and opinion. The FDPIC has stated in published guidance on its role under the revised FADP that the commissioner has "additional duties and powers" as of 1 September 2023, and the fee regime ensures that advisory and consultation services do not divert resources from the FDPIC's core supervisory and investigatory functions under Articles 49–53 FADP.
Mandatory consultation — Art. 23 para. 1 FADP and the two-month review deadline
When a controller conducts a DPIA and the assessment shows that high residual risk to data subjects' personality or fundamental rights remains despite the planned safeguards, Article 23 para. 1 FADP requires the controller to seek a prior opinion from the FDPIC before beginning the processing. Article 23 para. 2 FADP establishes that the FDPIC must deliver its opinion within two months. The FDPIC's August 2023 factsheet explains the scope of the review: "The FDPIC checks whether the DPIA submitted shows and explains all the high end risks in a clear and comprehensible manner. Furthermore, it examines whether the planned processing, taking account of the identified risks, is compatible with the requirements of the data protection legislation as a whole, in that it is acceptable to the data subjects in terms of its planned scope and detail, and thus justifiable overall."
The factsheet states that "the FDPIC must notify the data controller of any objections and proposed amendments within the two-month period specified in Article 23 paragraph 2 FADP." The factsheet adds that "the opinion of the FDPIC should be regarded as a recommendation" — the FDPIC's Art. 23 opinion is advisory, not a legally binding order. The controller may proceed with the processing after the two-month period expires or after receiving the FDPIC's opinion, whichever comes first, even if the FDPIC has raised objections. However, if the controller disregards the FDPIC's objections and the processing subsequently gives rise to an FADP violation, the FDPIC may open an investigation under Article 49 ff. FADP and issue a legally binding order under Article 51 FADP requiring the controller to modify, suspend, or discontinue the processing.
Private controllers with a notified data protection advisor — exemption from mandatory consultation but voluntary submission remains fee-based
Article 23 para. 2 FADP provides a carve-out for private controllers that have notified the FDPIC of their data protection advisor pursuant to Art. 10 para. 3 FADP. These controllers may rely solely on the advisor's internal opinion and are not required to consult the FDPIC, even when the DPIA shows high residual risk. The statute does not extend this exemption to federal bodies, which remain subject to the mandatory consultation obligation when high residual risk persists.
The FDPIC's August 2023 factsheet addresses the scenario in which a controller voluntarily submits a DPIA to the FDPIC when not required to do so — for example, because residual risk is not high, or the controller has a notified advisor and is exempt from mandatory consultation. The factsheet states: "If the controller voluntarily submits the DPIA to the FDPIC, the latter is not required to act on it and take a substantive position. However, the FDPIC may, within the scope of its advisory activities, comment in certain cases on residual risks that are no longer high. The FDPIC must charge a fee for this advice (see Art. 59 para. 1 let. e FADP)."
This creates an asymmetry: mandatory consultation under Art. 23 para. 1 FADP triggers the two-month deadline and the fee; voluntary submission when the Art. 23 obligation does not apply gives the FDPIC discretion whether to respond substantively, but if the FDPIC does provide an advisory opinion, the Art. 59 fee applies. Controllers considering voluntary submission should contact the FDPIC in advance to confirm whether the FDPIC will review the DPIA and what fee will apply.
Fee amounts and the Data Protection Ordinance
The FADP itself does not specify the fee amounts for Art. 23 consultation. Article 59 para. 3 FADP delegates fee-setting authority to the Data Protection Ordinance (DPO, SR 235.11), which was adopted by the Federal Council and entered into force on 1 September 2023. The publicly available FDPIC guidance on DPIA procedure and the FDPIC's website do not publish a fee table or specific fee amounts for Art. 23 DPIA consultation.
Unable to confirm as of 2026-06-02.
Controllers should contact the FDPIC directly at the outset of a mandatory Art. 23 consultation or before making a voluntary submission to obtain a fee estimate. The FDPIC's general contact information and DPIA submission process are described on the FDPIC's website at edoeb.admin.ch.
Timing of fee payment and invoicing
The publicly available FDPIC guidance does not specify the exact invoicing and payment procedures for Art. 23 consultation fees. Based on general Swiss federal administrative practice, fees for advisory services are typically invoiced after the service is provided. For an Art. 23 DPIA consultation, this would mean the FDPIC issues an invoice after delivering its written opinion. Controllers are not required to pay the fee upfront before submitting the DPIA, and the two-month review deadline established by Art. 23 para. 2 FADP runs from the date of submission regardless of payment status. Unpaid fees owed to the FDPIC are enforceable as public-law debts under Swiss federal administrative procedure.
Distinction from investigation costs and from private right-of-action litigation costs
The Art. 59 FADP fee regime applies to advisory and consultation services provided at the controller's request (DPIA consultation under Art. 23, codes-of-conduct opinions under Art. 11 FADP, certification opinions under Art. 13 FADP). It is distinct from the investigation and enforcement functions under Articles 49–53 FADP, which the FDPIC conducts on its own initiative or in response to a complaint. When the FDPIC opens an investigation under Art. 49 FADP and issues a legally binding order under Art. 51 FADP, the publicly available guidance does not indicate that the FDPIC charges the investigated controller a fee for the investigation itself; the FDPIC's investigatory and enforcement work appears to be funded from the FDPIC's general budget, not cost-recovery fees from investigated entities.
The Art. 59 fee regime is also distinct from private civil litigation under Article 32 FADP, which grants data subjects a private right of action to seek injunctive relief, damages, and satisfaction payments from controllers. Controllers that face both an FDPIC Art. 23 consultation (triggering the Art. 59 fee) and a concurrent civil lawsuit by a data subject will incur separate costs for each proceeding; the FDPIC fee does not cover or offset the controller's litigation costs in the civil action.
Relationship to EU GDPR Article 36 prior consultation
The Swiss FADP Art. 23 prior-consultation requirement aligns structurally with EU GDPR Article 36 prior consultation, which also requires controllers to seek the supervisory authority's opinion when a DPIA shows high residual risk. However, the EU GDPR does not authorize supervisory authorities to charge controllers a fee for Art. 36 consultation; GDPR Article 57(4) states that supervisory-authority tasks "shall be provided free of charge to the data subject and, where applicable, to the data protection officer." EDPB Guidelines on DPIA (WP 248 rev.01) confirm that Art. 36 consultation is a zero-cost supervisory service in the EU.
This creates a compliance-cost divergence for controllers processing data of both Swiss and EU data subjects. A controller can often use a single DPIA covering both FADP and GDPR obligations, but the consultation regime differs: under GDPR, the EU supervisory authority will review the DPIA without charge; under FADP, the FDPIC will charge a statutory fee under Art. 59. Controllers managing cross-border EU-Swiss processing should budget for the Swiss Art. 59 fee when high-risk processing requires DPIA consultation in both regimes.
Source: FDPIC — Factsheet on the data protection impact assessment (DPIA) in accordance with Articles 22 and 23 FADP (PDF, August 2023) Source: FDPIC — New FDPIC's role (Art. 59 fee authority for advisory services) Source: FDPIC — Data protection impact assessment (Art. 23 consultation requirement)
DPIA required content — Art. 22 FADP and FDPIC's recommended structure for a compliant assessment
The Federal Act on Data Protection (FADP), in force since 1 September 2023, establishes a duty for controllers and processors to conduct a data protection impact assessment (DPIA) whenever planned processing is likely to result in a high risk to the personality or fundamental rights of data subjects (Art. 22 FADP). While Article 22 FADP mandates the DPIA, it does not provide a detailed, prescriptive list of required contents. Instead, the Federal Data Protection and Information Commissioner (FDPIC) has published official guidance that sets out the expected elements of a compliant DPIA under Swiss law.
Statutory minimum requirements — Art. 22 para. 3 FADP Article 22 para. 3 FADP requires the DPIA to contain a "description of the planned processing, an assessment of the risks to the personality or fundamental rights of the data subjects, and the measures planned to protect these rights." This minimal statutory definition leaves substantial room for interpretation and best-practice overlay.
FDPIC factsheet — recommended structure The FDPIC's August 2023 factsheet, published with the revised FADP, sets out the authority's expectations for the content and structure of a DPIA. A compliant DPIA should include:
- Description of the planned processing: This should address the purposes, categories of data subjects (e.g., employees, customers), categories of personal data (including any sensitive data per Art. 5(c) FADP), recipients (including processors and both domestic and international data transfers), retention periods, and a general description of technical and organizational measures for data security.
- Assessment of risks: Identify and analyze potential risks to data subjects' personality or fundamental rights resulting from the nature, scope, context, and purposes of the processing. The risk assessment must consider both the likelihood and severity of possible impact.
- Planned safeguards: List technical and organizational measures to mitigate identified risks. These can include encryption, access controls, staff training, pseudonymization, and strict contractual protections with processors.
- Residual risk and necessity of consultation: Evaluate whether, after safeguards, any high residual risk (as referred to in FDPIC guidance) remains. If so, the Art. 23 FADP prior-consultation requirement is triggered (unless the controller is a private entity with a notified data protection advisor under Art. 10 FADP).
- Ownership and review schedule: The guidance recommends documenting the responsible person/team for each DPIA, revision history, and triggers for review/updates (e.g., when scope of processing or technology changes).
Format and flexibility Although the FDPIC factsheet outlines these elements, it does not prescribe a mandatory template or form. Controllers may adapt the format to their sector or specific data processing. The key requirement is that the DPIA addresses every element above to demonstrate compliance if requested by the FDPIC during an investigation (Art. 49 ff. FADP).
Alignment with EU practice The FDPIC's recommended content substantially mirrors the structure set out in the EU GDPR Article 35 and EDPB Guidelines 4/2019, meaning organizations operating in both Switzerland and the EU can generally use a single DPIA as long as both regimes’ specificities (such as FDPIC consultation triggers) are clearly documented.
Source: FDPIC — Factsheet on the data protection impact assessment (DPIA) in accordance with Articles 22 and 23 FADP (PDF, August 2023) Source: Federal Act on Data Protection (FADP), Art. 22
Record of processing activities — Art. 12 FADP required content and recommended structure
Article 12 of the Federal Act on Data Protection (FADP, "Datenschutzgesetz" or DSG), in effect since 1 September 2023, defines the minimum required content for a compliant Record of Processing Activities (ROPA). The ROPA functions as a detailed inventory of all personal data processing activities by both controllers (who determine purposes and means, Art. 5(j) FADP) and processors (who process on behalf of controllers, Art. 5(k) FADP). This Swiss requirement is similar to Article 30 GDPR but diverges in the details: the elements below map directly to statutory obligations under Swiss law.
Required elements — controllers (Art. 12(2) FADP)
- Identity and contact details of the controller;
- Purposes of processing;
- Categories of data subjects and of personal data processed;
- Categories of recipients, including processors;
- If personal data are disclosed abroad: countries or international organizations, and the safeguards for transfers (such as an adequacy decision, standard contractual clauses, or BCRs);
- Time limits for erasure, or criteria for defining those limits;
- General description of technical and organizational measures for data security (per Art. 8(3) FADP).
Required elements — processors (Art. 12(3) FADP)
- Identity and contact details of the processor and, if applicable, the controller;
- Categories of processing carried out on behalf of the controller;
- Where data are disclosed abroad: countries/organizations, and applicable safeguards.
Recommended structure and FDPIC practice points
- Each processing activity (e.g., employee payroll, customer management, CCTV) should be listed as a distinct line item, with purpose, categories, and transfer information completed for each.
- When cross-border transfers occur, the register must state both the country and the legal mechanism or safeguard (e.g., "USA – standard contractual clauses per Art. 16(2) lit. d FADP").
- The ROPA is an internal compliance document but must be provided to the Federal Data Protection and Information Commissioner (FDPIC) upon request during an investigation (Art. 49 ff. FADP).
- There is no mandatory template, but the FDPIC's DataReg portal for federal bodies provides a best-practice model. For SMEs, the FDPIC recommends at least the statutory minimum plus brief process descriptions for high-risk or large-scale activities.
Examples of common entries:
- "Staff management – Employees – Name, contact details, AVS number, salary, health data (absence) – Payroll provider (CH), authorities (CH), cloud storage (USA – SCCs) – Data deleted 10 years after end of employment – Access controls, encryption."
- "Customer support – Users – Contact details, service history – CRM vendor (DE), analytics tool (IE) – Data deleted 2 years after last interaction – Pseudonymization, audit logging."
The FDPIC's guidance mirrors the structure above: purpose-driven, modular, cross-border fields explicit, technical and organizational measures described clearly, and review triggers documented (e.g., annual audit, product change, new transfer mechanism).
Source: Federal Act on Data Protection (FADP), Art. 12 — required ROPA content Source: FDPIC — DataReg: Report of processing activities (register examples, DataReg portal guidance)
Can the same advisor serve for both Swiss FADP and EU/UK GDPR compliance?
A frequent scenario in multinational groups is the desire to centralize privacy governance by appointing a single person or entity to serve as both the data protection advisor under Switzerland’s Federal Act on Data Protection (FADP, Art. 10) and as the data protection officer (DPO) under the EU or UK GDPR. Swiss law does not prohibit this structure, but it does not expressly address or endorse it either.
Statutory framework under the revised Swiss FADP
Article 10 FADP, in force since 1 September 2023, allows private controllers to voluntarily appoint a “data protection advisor” (Datenschutzberater). The law requires that the advisor be able to carry out their function independently, not be bound by instructions, and have access to the highest management level within the organization. The advisor can be an employee or an external service provider. There is no Swiss-specific nationality, residence, or exclusive-appointment requirement. The guidance published by the Swiss Federal Data Protection and Information Commissioner (FDPIC) does not specify any territorial or conflict-of-interest constraint on using the same person or legal entity for other jurisdictions as well. Instead, the focus is on actual independence and effective ability to fulfill the advisory duties within the Swiss controller’s structure.
Cross-jurisdictional context
The EU and UK GDPR permit group-wide DPO appointments, provided the DPO is “easily accessible from each establishment” (GDPR Art. 37(2), Art. 37(6), and EDPB Guidelines 8/2020). For Swiss FADP compliance, the key criteria are independence, sufficient expertise, access to management, and ability to act free from conflict within the Swiss entity—even if other group entities also draw on the same individual. Swiss law does not require a separate adviser for each company or legal regime, nor does it bar shared advisers, so long as these core requirements are fulfilled. The FDPIC’s published materials are silent on the precise scenario of a combined DPO/adviser appointment, but nothing in Art. 10 FADP or official FDPIC commentary precludes it.
Practical recommendations
Although Swiss law does not prohibit the dual appointment, controllers should document the advisor’s independence for each legal entity and ensure that the individual has adequate resources and reporting lines to perform separate FADP and GDPR obligations if both apply. The absence of a statutory residency or exclusivity restriction means a cross-border DPO/adviser model is feasible if the function is substantively fulfilled for each regime.
Unable to confirm as of 2026-06-15 if the FDPIC has ever formally approved or challenged such a dual appointment in practice.
Source: FDPIC — Data protection advisor guidance and statutory page
DPIA documentation — retention, production to FDPIC and data subjects, and audit obligations under Art. 22 and 49 FADP
Controllers and processors subject to Switzerland’s Federal Act on Data Protection (FADP, in force since 1 September 2023) must document every data protection impact assessment (DPIA) completed under Art. 22 FADP. The FADP does not state an exact retention period for DPIAs, but Art. 7 and Art. 8(3) FADP (privacy by design/default and technical-organizational measures) require documentation sufficient to demonstrate compliance throughout the processing lifecycle and for as long as necessary for audit or investigation. The FDPIC’s January 2024 guidance recommends retaining DPIAs and version histories for the life of the processing and a reasonable period after, analogizing to Swiss commercial law’s 10-year business records retention norm—but this is not a statutory requirement, only a best practice.
Production to the FDPIC
Under Art. 49 ff. FADP, the Federal Data Protection and Information Commissioner (FDPIC) may demand "all necessary information," which includes completed DPIAs, whenever investigating or auditing compliance. The controller must provide the full DPIA, supporting materials, and details of safeguards implemented. If the DPIA is incomplete or missing, the FDPIC can require additional measures and may issue a binding order under Art. 51 FADP.
Production to data subjects
Data subjects have a right of access under Art. 25 FADP to "the available information on the processing of their personal data," which may, on request, include a summary of DPIA findings or general risk mitigations. There is no statutory right for data subjects to receive the full text of a DPIA; where access is likely to reveal confidential information, Art. 26(2) FADP allows the controller to restrict or redact such details to protect third-party privacy and trade secrets. In practice, most controllers provide a summary or extract, not the entire assessment.
Retention and deletion
The FADP is silent on precise deadlines, but best practice is to retain DPIAs for as long as the processing continues, plus any additional period necessary to demonstrate compliance in an audit or legal proceeding. When retention is no longer required, Art. 6(4) FADP (data minimization) requires secure deletion or anonymization. Controllers should document their rationale and protocols for both retention and destruction.
Non-compliance risks
Failure to document, retain, or produce a DPIA when required may expose the controller or responsible persons to enforcement action (Art. 49–51 FADP) and, if negligent or intentional, criminal liability for breach of the duty of care (Art. 61(1)(c) FADP). Criminal fines of up to CHF 250,000 may be imposed on responsible individuals.
_FDPIC guidance is not legally binding, but influential in investigations._
Source: Federal Act on Data Protection (FADP), Arts. 7, 8, 22, 25, 26, 49–51, 61 Source: FDPIC — Technical and Organizational Measures (TOM) guidance, January 2024
DPIA triggers: large-scale sensitive data and high-risk profiling under Art. 22 FADP
Article 22 of the Federal Act on Data Protection (FADP), effective since 1 September 2023, makes a data protection impact assessment (DPIA) mandatory when "the planned processing of personal data is likely to result in a high risk to the personality or fundamental rights of the data subjects." Swiss law defines two key automatic triggers: (1) large-scale processing of sensitive personal data and (2) high-risk profiling. These are areas where the law departs from GDPR terminology and relies on the Federal Data Protection and Information Commissioner (FDPIC) to provide interpretive guidance.
1. Large-scale processing of sensitive personal data (Art. 22(2)(a) FADP) Sensitive data, as defined in Art. 5(c) FADP, includes details like health, religious or political opinions, trade-union membership, genetic and biometric data, and data on criminal proceedings. The FADP does not quantify "large scale" in terms of number of data subjects or geographic scope. The FDPIC's August 2023 DPIA factsheet clarifies that this is a "facts-and-circumstances" test: factors include the number of data subjects affected, the amount and nature of data processed, the duration, and the extent of geographic coverage. Practical examples from the FDPIC include a hospital processing patient health data, an employer handling health data for a large workforce, or an association recording members' religious affiliations over many years.
2. High-risk profiling (Art. 5(f) and Art. 22(2), (3) FADP) Profiling is defined in Art. 5(f) FADP as any automated data processing aimed at evaluating personal aspects—such as behaviour, interests, or location. Profiling becomes "high-risk" when the linking and evaluation of data can impact a person’s "essential aspects," threatening personality or fundamental rights. While the GDPR speaks to "automated decision-making with legal or similarly significant effect," the FADP’s focus is broader: employee monitoring systems, customer credit-scoring, or AI-driven evaluation tools may all trigger a DPIA if they aggregate or connect multiple categories of data and the results meaningfully affect individuals. The FDPIC guidance recommends conducting a DPIA by default where there is doubt about whether profiling crosses the "high risk" threshold.
Practical overlays from FDPIC guidance The FDPIC’s factsheet and sectoral publications reiterate:
- If either absolute risk trigger (large-scale sensitive data or high-risk profiling) is present, a DPIA is compulsory—independent of any additional contextual risks.
- There is no set threshold (e.g., 1000 data subjects); sector, data type, and processing duration all matter.
- Use illustrative examples: health insurers evaluating member data, marketing agencies compiling multi-source profiles on thousands of consumers, or HR departments using automated employee monitoring systems for performance or behavioral metrics.
Relationship to general "high risk" evaluation and GDPR If neither absolute trigger applies, controllers still must review whether the planned processing is likely to generate high risk based on “nature, scope, circumstances or purpose.” The Swiss model is closely aligned with EU GDPR Art. 35 but sets its own profiling threshold.
Data protection advisor (DPA) independence, resources, and protection guarantees — Art. 10 FADP requirements
Art. 10 FADP — Guaranteeing the independence and effectiveness of the data protection advisor
Article 10 of the revised Federal Act on Data Protection (FADP), in force as of 1 September 2023, establishes both the grounds for appointing a data protection advisor (DPA, or "Datenschutzberater/in" / "conseiller à la protection des données") and the core guarantees necessary for their independence and effectiveness. These guarantees closely track—but are not identical to—the requirements for data protection officers (DPOs) under the EU GDPR.
Independence
Article 10(3) FADP states: “The data protection advisor may not be bound by the controller’s or processor’s instructions in the performance of his or her duties.” This is a strict requirement: the advisor must be able to evaluate and advise on processing activities, risk assessments, and DPIAs free from interference or pressure from management or business units. Official guidance from the Federal Data Protection and Information Commissioner (FDPIC) further requires organizational safeguards: the advisor must report directly to the highest management level (e.g., the executive board) and have the right to escalate issues at any time. The FDPIC states that combining the DPA role with an operational responsibility (e.g., IT, HR) creates unresolvable conflicts of interest and is not compliant with the law.
Resource provision and access
The controller or processor is required to provide the data protection advisor with the necessary resources, including time, budget, support staff, and access to all relevant data and documentation needed to carry out their role. The FDPIC’s published guidance (Art. 10 FADP DPA appointment page) states this must be documented internally and advises that periodic review of resources is good practice, especially for larger or dynamic organizations. The advisor is entitled to ongoing training and must have sufficient authority to prompt internal investigations and recommend corrective actions.
Protections against retaliation or dismissal
While the FADP does not set out specific labor-law protections from dismissal or discipline for the DPA (as is the case for DPOs under some EU Member State implementations), the FDPIC’s advisory materials make clear that termination or replacement of an advisor for “compliance activity or differing legal opinions” is a violation of the spirit of Art. 10 FADP and would be scrutinized as possible indirect obstruction. Any such action risks sanctions under Art. 61(1)(c) FADP (intentional violation of data protection duty of care).
Confidentiality and legal privilege
The FADP does not create special legal privilege for communications with the DPA. However, Art. 10(3) and the FDPIC’s guidance require the advisor to maintain confidentiality concerning internal matters and investigation results, without using this obligation to limit the reporting rights or independence of the DPA.
Remediation for breaches of independence
If the FDPIC discovers, through a complaint or ex officio investigation, that an appointed DPA is bound by instructions, lacks adequate resources, or has been removed in retaliation for compliance activity, the authority may order the controller to remediate, including by appointment of a new DPA, reinstatement, or direct reporting lines. Obstruction may constitute a breach of FADP’s duty of care, exposing responsible individuals to fines up to CHF 250,000 (Art. 61(1)(c) FADP).
Source: Federal Act on Data Protection (FADP), Art. 10 Source: FDPIC — Data protection advisor guidance
DPA notification to the FDPIC — process, required details, and legal consequences under Art. 10 FADP
Under Article 10 of the revised Swiss Federal Act on Data Protection (FADP), effective from 1 September 2023, controllers in the private sector may—and federal bodies must—notify the Federal Data Protection and Information Commissioner (FDPIC) of the appointment of a data protection advisor (DPA). Notification is required for federal entities (Art. 10(4) FADP) and optional for private controllers (Art. 10(1)-(3) FADP). Private controllers who notify unlock the exemption from mandatory FDPIC consultation when a DPIA reveals high residual risk (Art. 23(2) FADP).
How to notify and required information The FDPIC provides an official notification portal for DPA registration (see FDPIC "Data protection advisor" page). While the portal is referenced as the main route in official guidance, neither the statute nor guidance confirms it as the exclusive mechanism. To initiate notification, the organization accesses the portal, which requests the following details:
- Name and contact details (business address, email) of the advisor.
- Relationship to the controller (internal employee, external consultant, legal entity, or natural person).
- Confirmation that the advisor meets statutory independence and resource requirements (Art. 10(3) FADP: not bound by instructions, has access to management, sufficient resources).
- If relevant, the contact point for privacy matters (which may be distinct from the advisor), as suggested in FDPIC FAQs.
The FAQ indicates that the portal will prompt for current details and requires organizations to ensure information is accurate. The process may require an account (e.g., CH-Login or FED-Login), but the publicly available guidance does not specify a technical prerequisite for login or clarify whether a separate notification is needed for each group entity—this should be verified directly in the portal if group-wide arrangements are planned.
Legal effect and update obligations The date on which the FDPIC confirms notification is generally treated, per guidance and common practice, as the date on which the DPIA-consultation carve-out becomes available, but this is not explicitly stated in the statute or official FAQs. The controller must keep the registry up-to-date: a change in the advisor’s identity or contact data must be promptly updated through the same mechanism. The FDPIC FAQ stresses that timely updates are required to benefit from the exemption and to ensure the advisor is recognized.
Currently, there is no publicly documented statutory fee for notifying or updating DPA details (see FDPIC FAQ)—fee requirements only attach to DPIA consultation or advisory opinions under Art. 23 and Art. 59 FADP.
Source: FDPIC — Data protection advisor official notification portal Source: Swiss Federal Act on Data Protection (FADP), Art. 10 Source: FDPIC — FAQ for businesses and associations, DPA notification process
Integrating DPIA and ROPA — Cross-referencing risk assessments in processing records under FDPIC guidance
Integration of DPIA and ROPA documentation under the revised Swiss FADP
The Federal Act on Data Protection (FADP), effective 1 September 2023, imposes distinct but interconnected obligations to (1) maintain a record of processing activities (ROPA — Art. 12 FADP) and (2) conduct data protection impact assessments (DPIAs — Art. 22 FADP) for high-risk processing. While the statute outlines each requirement separately, the Federal Data Protection and Information Commissioner (FDPIC) has issued guidance urging controllers to explicitly cross-reference completed DPIAs in the ROPA to support transparency, auditability, and evidence of compliance.
Recommended practice: Cross-referencing DPIAs in the ROPA
The FDPIC’s published guidance (notably the TOM/EN.pdf technical and organizational measures document) states that, where a processing activity listed in the ROPA was subject to a DPIA, the controller should note in the ROPA’s security-measures or remarks field:
- That a DPIA was conducted;
- The date of the DPIA (and of the latest update, if applicable);
- A brief reference or internal file location for the DPIA documentation.
This allows both the organization and the FDPIC (should an investigation occur under Art. 49 ff. FADP) to quickly map ROPA entries to their corresponding risk assessments. Since the DPIA is prospective and process-specific, and the ROPA is comprehensive and continuously maintained, this linkage ensures a robust, documented compliance trail.
Why this matters for Swiss compliance risk
The FDPIC emphasizes that, unlike under the GDPR, Swiss law does not prescribe a statutory template for the ROPA or DPIA, but controllers must be able to "demonstrate compliance" (Art. 7, Art. 8(3) FADP) at any time. During an audit or investigation, the ability to show that high-risk activities in the ROPA were flagged and that DPIAs were performed—and to produce updated DPIAs that correspond with ROPA entries—can materially impact whether the FDPIC identifies a breach of the law or finds sufficient evidence of good-faith compliance.
Practical implementation
The TOM guidance encourages organizations to establish a version-controlled, referenceable document trail: each ROPA entry for a high-risk activity should note, for example, “DPIA completed 2025-10-04, see internal file ref: DPIA/EmployeeMonitoring/2025” in the security measures section. When processing changes and an updated DPIA is required, the ROPA should be promptly updated to reflect the new date and location. This internal cross-referencing also facilitates effective data subject rights responses under Art. 25 FADP—for instance, when a data subject requests information about the logic and consequences of automated decision-making, the organization can efficiently retrieve and summarize DPIA findings relevant to the corresponding processing activity.
While there is no formal penalty for failing to cross-reference, failure to demonstrate this linkage may raise concerns in an FDPIC investigation and complicate the controller’s legal position regarding documentation duties under Art. 7 and 49 ff. FADP.
Source: FDPIC — Technical and Organizational Measures (TOM) guidance, January 2024
Data protection advisor qualifications and expertise — statutory and FDPIC expectations under Art. 10 FADP
Under Switzerland’s Federal Act on Data Protection (FADP), effective since 1 September 2023, there are no statutory academic, professional, or certification requirements for a person or entity to serve as a data protection advisor (DPA, Datenschutzberater/in) for a private controller or a federal body. Article 10 FADP, which governs appointment, states only that the advisor "must be able to carry out their function independently and must not be bound by instructions." The law is silent about minimum qualifications, experience, or sectoral expertise.
FDPIC guidance — Focus on capability, independence, and ongoing training The Federal Data Protection and Information Commissioner (FDPIC), in its published FAQ and technical guidance, does not prescribe formal credentials for the DPA. The FDPIC advises that the advisor "must possess the professional and organizational knowledge necessary for the performance of their tasks" but does not require a data protection degree, Swiss residence, prior legal experience, or a particular certification (such as CIPP/E or equivalent). The role may be filled by an employee or an external consultant, natural person or legal entity, provided independence is demonstrable (see the separate section on advisor-independence-protection).
Best practice, reflected in FDPIC recommendations, is to appoint an advisor with proven expertise in Swiss data protection law, privacy governance structures, data security, and risk management—commensurate with the scale and risk of the controller’s processing activities. The FDPIC encourages organizations to ensure ongoing training for the advisor, taking into account legal and technological developments, and to document the advisor’s skills and continuing education as part of the compliance file (see TOM guidance, January 2024). For multinational groups, the advisor need not be uniquely Swiss-qualified, but must possess knowledge of Swiss data-protection rules and sector-specific requirements for the relevant controller.
Key expectations from FDPIC commentary:
- There is no nationality, residence, or exclusive-appointment rule.
- The advisor must have “necessary professional and organizational knowledge” (FDPIC DPA FAQ).
- Ongoing training, resource allocation, and periodic review of the advisor’s capabilities are strongly recommended as good practice.
- Independence and access to management are essential—conflicts of interest or insufficient authority may invalidate the appointment (see Art. 10(3) FADP and FDPIC guidance).
The absence of formal qualification requirements diverges from the GDPR (Art. 37(5)), which requires DPOs to have “expert knowledge of data protection law and practices.” However, any appointment under Swiss law remains subject to challenge by the FDPIC if the advisor cannot demonstrate effective knowledge and independence in audits or investigations (Art. 49 ff. FADP).
_Source: Federal Act on Data Protection (FADP), Art. 10 Source: FDPIC — Data protection advisor FAQ and role guidance Source: FDPIC — Technical and Organizational Measures (TOM) guidance, January 2024_
DPIA exemptions under Art. 22(4) FADP — statutorily exempt processing and the FDPIC 'whitelist'
Article 22(4) of Switzerland’s Federal Act on Data Protection (FADP), in force since 1 September 2023, authorizes the Federal Council to exempt certain categories of data processing from the obligation to conduct a data protection impact assessment (DPIA). This creates a regulatory mechanism for issuing a prescriptive list of processing operations—analogous to the GDPR's Art. 35(5) authority for member state exemptions—where a DPIA is not required even if processing appears high-risk based on other criteria.
Statutory provision and ordinance delegation Art. 22(4) FADP states: “The Federal Council may stipulate that, in certain cases, a data protection impact assessment is not required.” This authority is implemented through the Data Protection Ordinance (DPO, SR 235.11), which could specify exempt classes of processing based on sector, purpose, technology, or other defined characteristics. However, as of June 2026, there is no published list of blanket DPIA exemptions in the text of the DPO, and the FDPIC has not maintained or published a sector-wide 'whitelist' of DPIA-exempt activities for private controllers or federal bodies.
FDPIC official guidance — case-by-case analysis remains the rule The Federal Data Protection and Information Commissioner (FDPIC), in its August 2023 factsheet and online commentary, explicitly notes that, at present, all assessments of DPIA necessity are to be conducted on a case-by-case basis using the risk factors in Art. 22(2) FADP and the guidance provided by the FDPIC. The factsheet states: “The Federal Council may provide for exceptions (Art. 22 para. 4 FADP). However, no such exceptions exist for the time being.” This means that controllers cannot rely on a regulatory 'whitelist' to dispense with DPIA obligations and must analyse each processing operation individually for the likelihood of high risk.
Consequences and regulatory context In practice, the absence of a statutory or regulatory DPIA exemption list means alignment with the GDPR is incomplete: under GDPR, certain processing on the 'SA whitelist' is exempt from DPIA, but in Switzerland, no analogous whitelist is in force as of 2026. Controllers and processors must document their DPIA decision-making process—whether triggering a DPIA, documenting a risk assessment that finds low risk, or recording why an exemption would not apply even if one were later added by ordinance.
If in the future the Federal Council amends the DPO to publish exempt categories, the FDPIC will likely update its guidance and provide sector-specific examples. Controllers should regularly review the DPO and FDPIC publications for any updates to this regime.
Source: Federal Act on Data Protection (FADP), Art. 22(4)—no current DPIA exemption list Source: FDPIC — Factsheet on DPIA requirements under Art. 22 and regulatory exceptions