Data Protection Geneva, Cantonal LIPAD and Federal DSG
Introduction
The Canton of Geneva is a special case in Swiss data protection law: on top of the Federal Act on Data Protection (DSG), Geneva has its own Loi sur l'information du public, l'accès aux documents et la protection des données personnelles (LIPAD), in force since 2002, which bundles transparency, access to public records and data protection into one single act. Add a bilingual administration and the presence of dozens of international organisations around Lake Geneva, and the practical regime becomes considerably more complex than in most other cantons.
This article shows:
- when the LIPAD applies instead of the DSG, and when both apply in parallel;
- which duties Geneva administrative bodies, municipalities and hospitals face under LIPAD;
- how the Préposé cantonal à la protection des données et à la transparence (PPDT) operates as supervisory authority;
- what specifics apply to international organisations (UN, ICRC, WHO);
- where GDPR comes into play when Geneva entities interact with EU actors;
- and which concrete steps a Geneva-based company or municipality should take.
Legal anchors: LIPAD (RSG A 2 08), Federal Act on Data Protection (DSG), Data Protection Ordinance, GDPR (where applicable) and PPDT practice guidance.
LIPAD and DSG, who regulates what
Under Art. 3 LIPAD, the LIPAD applies to all public entities of the Canton of Geneva: cantonal administration, municipalities, autonomous public establishments (HUG, IMAD, SIG, TPG), legal persons under predominant public influence and private bodies entrusted with public tasks, in respect of those tasks. For all of them, the LIPAD is lex specialis; the DSG only applies in a subsidiary fashion or not at all, because Art. 2(1)(b) DSG limits federal data protection law to federal bodies.
For purely private actors in Geneva (SMEs, banks, law firms, online shops), the DSG applies without LIPAD overlay. The LIPAD only takes indirect effect when a private firm acts as data processor for a Geneva authority, then LIPAD requirements must be cascaded contractually to the processor (Art. 9 DSG combined with Art. 35 et seq. LIPAD).
Three conflict-of-laws rules matter:
- Dual nature: A hospital like HUG falls under LIPAD for its administrative activity; for its commercial activity (e.g. contract research for an EU sponsor), the GDPR may additionally apply.
- Private operation: A Geneva law firm is governed by the DSG, not the LIPAD, even when mandated by the City of Geneva; the city itself remains LIPAD-bound as controller.
- Transparency vs. data protection: Art. 24 et seq. LIPAD give any person a right of access to administrative documents, which can collide with third parties' access rights under Art. 39 LIPAD or Art. 25 DSG and requires balancing on a case-by-case basis.
Duties for Geneva administrative bodies
A public body in Geneva faces a dense compliance set. Art. 50 LIPAD requires every authority to appoint a Responsable LIPAD, the cantonal counterpart of the corporate Data Protection Officer. This person must act independently, keep a record of processing activities (Art. 56 LIPAD), notify high-risk new processing to the PPDT (Art. 57 LIPAD, analogous to the data protection impact assessment under Art. 22 DSG) and inform data subjects about their rights.
LIPAD also requires a public processing register (Catalogue des fichiers), a difference from the DSG, where the record under Art. 12 DSG is in principle internal. Geneva administrations therefore not only document their processing internally but actively publish it.
For data breaches, two parallel notification duties exist: Art. 24 DSG (to the FDPIC / EDÖB, where federal law is affected, rarely the case for purely cantonal processing), and Art. 50(2) LIPAD (to the PPDT) for breaches creating high risks to data subjects. In practice: a municipal authority that loses an encrypted USB stick containing social-assistance files notifies the PPDT, not the FDPIC.
Special rules apply to sensitive personal data, Art. 35 LIPAD defines them slightly more broadly than the DSG and includes, for example, données relatives aux mesures d'aide sociale.
The PPDT as supervisory authority
The Préposé cantonal à la protection des données et à la transparence (PPDT) is the independent supervisory authority under Art. 55 et seq. LIPAD. Unlike the FDPIC, the PPDT has a dual mandate: it supervises data protection and at the same time access to public documents (transparency regime, Art. 24 et seq. LIPAD).
Under Art. 47 et seq. LIPAD, the PPDT may:
- issue recommendations that are de facto binding on administrative entities;
- open investigations, either on complaint or ex officio;
- mediate disputes between citizens and authorities, particularly on access to documents;
- give opinions on draft laws and ordinances affecting personal data.
The PPDT does not have power to impose fines, unlike the FDPIC, which itself cannot issue fines either but can refer matters for criminal prosecution to the competent cantonal public prosecutor's office (Art. 60 et seq. DSG). In Geneva, a LIPAD violation typically leads to a public recommendation and possibly a political feedback loop via the Grand Conseil, the PPDT's public reporting is therefore an important compliance driver.
Recent focus areas for the PPDT include Microsoft 365 use in cantonal administration, biometric access controls in schools, bodycams of the Geneva police and web-analytics tools on cantonal websites.
International organisations around Lake Geneva
Geneva hosts some 40 international organisations (UN, WHO, ILO, ICRC, WTO, GAVI) and hundreds of NGOs. These actors operate under privileges and immunities and are not directly subject to either the DSG or the LIPAD. UN organisations have developed their own data-protection frameworks, notably the UN Personal Data Protection and Privacy Principles (2018) and the UN High-Level Committee on Management Data Protection Framework.
In practice, three recurring conflict areas arise:
- Service providers: An international organisation commissions a Swiss SME for IT support. The SME remains subject to the DSG even when its client enjoys immunity. The data processing agreement must accept Swiss law and FDPIC supervision in parallel with the internal data-protection rules required by the client.
- Local staff: Locally Recruited Staff are often hired under Swiss employment law; HR data are then subject to the DSG, while operational data fall under the organisation's internal regime.
- Cooperation with federal/cantonal authorities: When the Canton of Geneva or the federal government transfers data to an international organisation (e.g. health authorities to the WHO), Art. 16 et seq. DSG on cross-border disclosure apply, an adequate level of protection must exist, which for UN organisations is normally established via their recognition as subject of public international law or via standard contractual clauses.
For private-sector providers around Lake Geneva, this means: contracts with international organisations need dual-regime clauses that cleanly delineate DSG/LIPAD obligations from the client's internal regime.
GDPR interface and cross-border practice
Geneva sits geographically and economically at the EU border. Many Geneva-based firms have clients in France, Germany or Italy, bringing Art. 3(2) GDPR into play alongside the DSG. Any operator actively targeting EU residents (French-language newsletters, .fr domain, shipping to the EU) must comply with the GDPR in addition to the DSG and needs an EU representative under Art. 27 GDPR if it has no EU establishment.
Three practice areas are particularly relevant in Geneva:
- Cross-border commuters: About 100,000 people commute daily from France. HR data of cross-border workers are governed by Swiss employment law and the DSG, but payroll often also implicates French social-security law, a bilateral tension that DPAs must address explicitly.
- Private banking: Geneva wealth managers serving EU clients are subject to FINMA supervision (RS 2008/21, RS 2018/3) in parallel with the GDPR. Data exports to the EU for tax reporting via AEOI/CRS are legally founded (Art. 17 DSG) but still require documented safeguards.
- Commodity trading: The trading houses concentrated in Geneva have worldwide data flows. The Transfer Impact Assessment process post-Schrems II is essential, especially for third countries without an adequacy decision.
If you operate across borders, we recommend a single integrated data-protection register that maps GDPR and DSG requirements side by side (Art. 30 GDPR and Art. 12 DSG).
Concrete steps for Geneva actors
We recommend every Geneva actor a pragmatic six-step plan:
- Scope mapping: Clarify whether you are LIPAD-bound (public entity / public mandate), DSG-only (purely private activity), or also GDPR-bound (EU nexus). Often a combination applies.
- Appoint a Responsable LIPAD or DPO: mandatory for public entities under Art. 50 LIPAD; voluntary for SMEs but advisable as soon as sensitive personal data is processed regularly.
- Record of processing activities: public for LIPAD actors, internal for DSG actors, always supplemented with legal basis, purpose, retention period and recipients.
- Data Protection Impact Assessment (DPIA): before any new high-risk processing, especially profiling, biometric data, AI systems, bodycams or the merger of multiple databases.
- Cross-border clauses: for data flows Switzerland-EU-US use the relevant standard contractual clauses (CH-EU SCC, EU-US Data Privacy Framework) and document a TIA.
- Training: bilingual staff training (FR/EN, often DE for federal mandates), especially on phishing, document-access requests and data-subject access requests.
Whoever cleanly works through these six steps is prepared for a PPDT investigation, an FDPIC case or a GDPR access request.
How SIDD supports you
SIDD has supported companies, NGOs and administrative bodies around Lake Geneva for years in the parallel application of LIPAD, DSG and GDPR. Our mandates range from acting as external data-protection advisor (Swiss data-protection advisory) and external Data Protection Officer under the GDPR (GDPR DPO mandates) to acting as EU representative (EU representative under Art. 27 GDPR) for Geneva companies serving EU clients.
We work bilingually (French/German) and are equally familiar with the practice of the PPDT, the FDPIC and the CNIL. For ISO/IEC 27001 certification, penetration testing and awareness training, our teams in Geneva, Zurich and Bern are at your service (ISO 27001 / ISMS, privacy workshops).
Write to us via the contact form or request a non-binding quote via our quote form. We respond within 24 hours with an initial assessment of your situation across LIPAD, DSG and GDPR.
