Data Protection in Switzerland: the Legal Framework in Detail
Legal Sources and Scope of the DSG
The Swiss DSG (Federal Act on Data Protection / FADP) is the central Swiss data protection statute and has applied in its fully revised form since 1 September 2023. Together with the Swiss Data Protection Ordinance (DSV) and the Ordinance on Data Protection Certifications (VDSZ), it forms the binding legal framework. The DSG applies to every private person and every federal body that processes personal data with effects in Switzerland (Art. 3(1) DSG, market-location principle). Addressees are both controllers and processors. A deeper overview of structure and duties is provided by our DSG pillar guide (German-language pillar); this article focuses on the legal classification of the core duties.
Substantively, the DSG covers only personal data of natural persons; data of legal entities are no longer protected since the full revision. Personally, the scope extends to all private controllers and federal bodies, while cantonal bodies remain subject to the cantonal data protection acts. Territorially, the DSG applies under the effects principle even when the controller has no seat in Switzerland, provided that the processing affects persons resident in Switzerland. Conceptually, this reach mirrors Art. 3(2) GDPR, which facilitates parallel compliance.
Processing Principles under Art. 6 DSG
The processing principles in Art. 6 DSG are the normative backbone of every lawful data processing. They require lawfulness (para. 1), processing in good faith and proportionality (para. 2), purpose limitation with recognisability (para. 3), data accuracy (para. 5), and express consent for sensitive personal data and for high-risk profiling (para. 7). Unlike the GDPR, the DSG does not list exhaustive legal bases; a civil-law breach of personality is only assumed where processing violates the principles or contradicts the express wish of the data subject and is not justified by consent, overriding interest or statute (Art. 30, 31 DSG).
Sensitive personal data are defined exhaustively in Art. 5(c) DSG and include, among others, religious, political and trade-union views, health data, biometric data uniquely identifying a person and genetic data. Their processing demands a particularly careful justification. The purpose-limitation principle operates dynamically: any later extension of the purpose requires its own legal basis. Finally, privacy by design and privacy by default under Art. 7 DSG require data-protection-friendly defaults to be embedded in the architecture of a system from the outset.
Information and Access Duties (Art. 19, 25 DSG)
The information duty in Art. 19 DSG obliges the controller to inform the data subject actively when collecting personal data, irrespective of whether the data are obtained directly or indirectly. The notice must cover the identity and contact details of the controller, the processing purpose, the recipients or categories of recipients and, in the case of cross-border disclosure, the destination state together with the applicable safeguards. Mirroring this, Art. 25 DSG grants the data subject a right of access; the response is due within 30 days and is in principle free of charge. Refusal or restriction is only permitted under the narrow conditions of Art. 26 DSG. The standard of diligence for both duties is high: the privacy notice is the primary instrument for fulfilling Art. 19 DSG.
Further rights of the data subject include the right to data release and data portability (Art. 28 DSG), the rectification of inaccurate data (Art. 32(1) DSG) and the civil-law claims for breach of personality under Art. 32(2) DSG in conjunction with Art. 28 ZGB. Where an automated individual decision produces legal effect, Art. 21 DSG requires prior information and the option to request human review. Those who map these duties cleanly into their technical processes avoid the most common FDPIC complaints and reduce the criminal-law risk under Art. 60 DSG.
Data Security and TOMs (Art. 8 DSG)
Art. 8 DSG requires the controller and the processor to implement appropriate technical and organizational measures (TOMs) so that data security is commensurate with the risk. The DSV concretises the requirements in Articles 1 to 6: confidentiality, integrity, availability and traceability of processing must be protected. Decisive criteria are the state of the art, the nature and purpose of the processing and the risk to the personality of the data subject. A breach of data security must be notified to the FDPIC as quickly as possible under Art. 24 DSG where it is likely to lead to a high risk. The mapping logic to ISO/IEC 27001:2022 (for example A.5.7, A.5.23, A.8.8) is developed in depth in our article on data-security best practices.
The DSV distinguishes eight control objectives: access control, data-carrier control, storage control, user control, access-rights control, transmission control, input control and disclosure control. These are complemented by recovery, availability, integrity and security-evaluation controls. The list is not exhaustive but defines the control dimensions an FDPIC investigation will examine. The duty to carry out a Data Protection Impact Assessment (DPIA) under Art. 22 DSG complements the TOM concept where a planned processing is likely to entail a high risk; the result must be retained for ten years (Art. 14(4) DSV).
Processor Engagements, Joint Responsibility and the Data Protection Advisor
Processor engagements are governed by Art. 9 DSG. A transfer is permissible where it is foreseen contractually or by statute, where the processor can guarantee data security and where no statutory or contractual duty of secrecy stands in the way. Sub-processor relationships require prior authorisation. Unlike the GDPR, appointing a Data Protection Advisor (Art. 10 DSG, Swiss DSG-specific role, distinct from the EU DPO) is voluntary for private controllers; it nevertheless brings procedural advantages for Data Protection Impact Assessments (Art. 23(4) DSG). Those who supply the EU market regularly must additionally observe the GDPR requirements; the GDPR pillar guide sets out the differences in detail.
The DSG does not expressly recognise joint controllership; in practice, organisations resort to a clear allocation of processing phases or to parallel responsibility. Anyone qualifying as a joint controller in the EU (Art. 26 GDPR) must in any case regulate the allocation of duties transparently. The Data Protection Advisor advises senior management, trains staff and acts as the contact point for the FDPIC. Independence must be ensured organisationally; a dual role as IT lead or managing director is to be avoided in view of conflicts of interest.
Cross-Border Disclosure (Art. 16, 17 DSG)
A disclosure of personal data abroad is only permissible where the destination state ensures an adequate level of protection (Art. 16(1) DSG). The list of recognised states is set out in Annex 1 of the DSV. Where recognition is missing, the disclosure can be supported by one of the safeguards in Art. 16(2) DSG, in particular the FDPIC standard contractual clauses (SCCs) or binding corporate rules (BCRs). Exceptions are governed exhaustively by Art. 17 DSG. The risks of a cross-border disclosure must be examined within a Data Protection Impact Assessment (Art. 22 DSG) as soon as a high risk arises; this is particularly relevant for cloud services with US parent companies.
For the United States, the Swiss-US Data Privacy Framework (DPF) has been recognised since 15 September 2024 as an adequate level of protection for certified recipients. Anyone transferring to a US group structure outside the DPF or serving other third countries requires SCCs plus a documented Transfer Impact Assessment. This assessment analyses the access rights of state authorities at the destination and defines supplementary measures, for example encryption with customer-controlled key management or contractual transparency duties. Disclosure to foreign authorities outside formal mutual legal assistance is additionally backstopped by Art. 271 Swiss Criminal Code (StGB).
Sanctions, FDPIC Supervision and Investigation
The sanctions under the DSG operate primarily in criminal law against the natural person. Wilful breaches of the information, access and diligence duties as well as of the duties relating to cross-border disclosure are punishable on complaint with a fine of up to CHF 250,000 (Art. 60 et seq. DSG). Subsidiarily, the enterprise can be charged up to CHF 50,000 where investigating the responsible individual would entail disproportionate effort (Art. 64(2) DSG). The FDPIC conducts investigations under Art. 49 DSG ex officio or on complaint and may issue binding orders under Art. 51 DSG, for example to adjust or stop a processing activity. The sanctions architecture thus differs fundamentally from the administrative-fine logic of Art. 83 GDPR.
In practice, the reputational damage component frequently weighs more heavily than the fine itself. A publicly known FDPIC order or a major data breach erodes the basis of trust with clients, partners and the regulator. Added to this are civil-law claims of data subjects under Art. 32 DSG in conjunction with Art. 28 ZGB and potential collective actions through the EU representative-action system where Swiss processing affects EU data subjects. Clean documentation of processing activities and TOMs is therefore not only an obligation but active risk protection.
Implementation in Practice: Next Steps
Compliant implementation of the DSG calls for a pragmatic, documented approach: Records of Processing Activities (ROPA) under Art. 12 DSG, a complete privacy notice in line with Art. 19 DSG, an access-request process within 30 days, a notification process for data-security breaches, a TOM concept under Art. 8 DSG and contracts with processors under Art. 9 DSG. For deeper topics we refer to the DSG pillar guide (German-language pillar). Companies that need support with implementation will find at SIDD the mandates Swiss DSG Data Protection Advisor, External DPO under GDPR Art. 37, as well as support for an ISMS under ISO/IEC 27001.
A staged approach is advisable: first an inventory of all processing activities and identification of high-risk operations; second the closure of documentary gaps (records, privacy notice, contracts); third the build-up of operational processes (access requests, breach notification, impact assessments); fourth the establishment of a continuous review. External support secures the methodology and relieves internal resources. The investment typically pays off within a few business years through reduced reputational risk, accelerated supplier reviews and a clearly defined maturity level vis-a-vis the regulator and business partners.
