Data Protection Trends 2025: Insights for Swiss Companies
EU AI Act: Duties with Extraterritorial Reach
The EU AI Act is the first horizontal AI regulation with clear extraterritorial reach and affects Swiss companies as soon as their AI systems are placed on the market in the EU or their outputs are used there. The prohibitions under Art. 5 AI Act have applied since 2 February 2025, and the obligations for GPAI models since 2 August 2025. Swiss providers should examine early on whether their systems qualify as high-risk AI within the meaning of Annex III. In parallel, the Swiss Federal Council signed the Council of Europe AI Convention on 5 September 2024; national implementation will be concretised in the coming legislative periods. From a data protection perspective, the Swiss DSG (Federal Act on Data Protection / FADP) remains applicable in any case to the processing of personal data; the DSG pillar guide (German-language pillar) classifies the duties.
Swiss SMEs (small and medium-sized enterprises) should also keep the AI-literacy duty of Art. 4 AI Act in mind: providers and deployers must ensure that their staff possess sufficient AI competence. This duty also applies to Swiss companies that provide AI systems in the EU or use their outputs there. In addition, FDPIC practice deserves attention: in its recommendations on generative AI, the FDPIC has clarified that the DSG remains fully applicable and that processing principles, transparency duties and the prohibition on discriminatory profiling also apply to AI-supported systems.
DORA and FINMA Circular 2023/01: ICT Risks Recalibrated
DORA (Regulation (EU) 2022/2554) on digital operational resilience in the financial sector has applied since 17 January 2025 and defines binding requirements for EU financial institutions covering ICT risk management, incident reporting, resilience testing and the management of third-party risks. For Swiss banks and insurers, DORA is directly relevant only via EU subsidiaries or service relationships; the national reference remains FINMA Circular 2023/01 on operational risks and resilience for banks. Both regimes converge on third-party risk, penetration testing and reportable cyber incidents. The FDPIC notification duty under Art. 24 DSG remains unaffected and is often more tightly clocked than the FINMA notification.
In practice, this convergence means that banks and insurers must align their ICT risk registers, incident classification and supplier contracts with all three regimes. A harmonised template for incident notifications reduces complexity in the event of a real case. FINMA further expects regular Threat-Led Penetration Testing (TLPT) at systemically important institutions; the EU counterpart is the TIBER-EU framework, which DORA has transposed into the binding framework. Those active in both spaces benefit from a shared testing architecture.
ISO/IEC 27001:2022: Transition Period Expired
ISO/IEC 27001:2022 has been the applicable standard since its publication in October 2022 and contains 93 Annex A controls in four theme categories. The transition period for existing certificates under ISO/IEC 27001:2013 ended on 31 October 2025; from November 2025 onwards, only certificates under the 2022 version remain valid. For Swiss companies this consolidation matters because, although Art. 8 DSG and Articles 1 to 6 DSV do not impose a certification obligation, a certified ISMS materially eases the proof of appropriate TOMs. SIDD works with CIS Cert (Quality Austria Group, ISO/IEC 17021-accredited) as certification partner.
The central innovations of the 2022 version concern the consolidation from 114 to 93 controls, the introduction of eleven new controls (for example A.5.7 Threat Intelligence, A.5.23 Cloud Services, A.8.28 Secure Coding) and the attribution of controls along five dimensions. The parallel standard ISO/IEC 27002:2022 provides the implementation guidance. Those currently building an ISMS should proceed directly under the 2022 version; a later migration costs additional effort. Linking with ISO 27701 (Privacy Information Management) further enables the integrated demonstration of data protection and information security.
Convergence of DSG and GDPR Enforcement
The enforcement practice of the FDPIC and EU supervisory authorities is converging in places but remains structurally different. In its most recent activity reports, the FDPIC notes a rising number of factual investigations, especially on cloud outsourcing, cookie banners and profiling. A concrete approximation is visible on the topics of cross-border disclosure and impact assessments. The sanctions architecture remains fundamentally different: while the GDPR permits administrative fines of up to EUR 20m or 4% of global annual turnover (Art. 83 GDPR), Art. 60 DSG targets primarily the natural person with up to CHF 250,000. The GDPR pillar guide develops the differences in depth.
Methodologically, both supervisory regimes approximate one another in the interpretation of DPIAs, the assessment of cookie-consent solutions and the requirements for processor contracts. In the reporting year the FDPIC has increasingly opened formal proceedings under Art. 49 DSG, signalling a clear shift from a purely advisory mandate to a consistent supervisory practice. Civil-law actions are also rising, especially in cases of collective breaches of personality. Companies should therefore not run their DSG and GDPR compliance in parallel but on an integrated basis, steering documentation, training and audit together.
Schrems Aftermath: Cross-Border Transfers and Transfer Impact Assessments
The Schrems II aftermath continues to shape transfer practice. Swiss controllers must ensure a safeguard under Art. 16 DSG for disclosures to third countries lacking an adequacy decision and conduct a Transfer Impact Assessment on a case-by-case basis. The FDPIC has recognised its own standard contractual clauses and accepts the EU SCCs with a Swiss annex. For transfers to the United States, the Swiss-US Data Privacy Framework (DPF) has applied since 15 September 2024 as an adequacy decision for certified US recipients. Uncertified recipients still require SCCs plus supplementary measures (encryption, pseudonymisation, contractual commitments).
A growing number of Swiss companies are relocating critical workloads to Swiss cloud regions or are adopting sovereign cloud offerings to avoid cross-border transfers. This strategy reduces transfer risk but does not replace the duty to classify data and to analyse data flows. Anyone deploying Microsoft 365, Google Workspace or AWS should actively steer data-residency configuration, encryption with customer-managed keys (Customer-Managed Keys, Hold Your Own Key) and contractual transparency duties regarding US authority requests.
Data Protection Advisor and EU Representative: Sharpening Roles
The role of the Data Protection Advisor under Art. 10 DSG is being increasingly professionalised in Swiss SMEs. Unlike the DPO under Art. 37 GDPR, appointment is voluntary but brings procedural advantages for impact assessments. Anyone processing personal data of EU data subjects without being established in the EU additionally needs an EU Representative under Art. 27 GDPR. SIDD offers both mandates separately: the Swiss mandate as Swiss DSG Data Protection Advisor and the EU mandate as External DPO under GDPR Art. 37. Organisational separation of the roles avoids conflicts of interest and ensures clean communication channels with each supervisory authority.
For the DPO role under Art. 37 GDPR, mandatory appointment is tied to three alternative criteria: public body, core activity involving large-scale regular monitoring, or large-scale processing of special categories of data. Breaches of the DPO duty are subject to fines under Art. 83(4) GDPR. Appointing an external DPO through a qualified mandate firm is the most efficient option for SMEs, as it secures methodology, currency and independence without internal personnel cost.
Cyber Resilience in the Banking Sector and NIS2 Reflex Effects
The Swiss financial sector is under twofold pressure: FINMA is sharpening expectations on operational resilience, and via EU group ties DORA and the NIS2 Directive radiate reflexively into Switzerland. NIS2 (Directive (EU) 2022/2555) significantly expands the circle of essential and important entities and requires, among other things, documented risk management, notification duties within 24/72 hours and training duties for senior management. Swiss subsidiaries in the EU are directly affected; Swiss head offices must at least mediately replicate the requirements to meet supplier and group expectations.
Within Switzerland, the Information Security Act (ISG) is evolving in parallel, subjecting federal authorities and critical infrastructure operators to a duty to notify cyber attacks to the Federal Office for Cybersecurity (BACS). The BACS notification duty for critical infrastructures has been in force since 1 April 2025. Switzerland thus operates two parallel reporting channels: the FDPIC for data protection breaches and BACS for cyber incidents at critical infrastructures. An integrated incident-response playbook addresses both duties and avoids duplicated work under time pressure.
Operational Consequences for the Next Quarters
The operational consequences can be bundled into four work packages: first an inventory of all AI systems with EU exposure; second the update of the records of processing activities (ROPA) and the TOMs under Art. 8 DSG; third the consolidation of cross-border transfers on the basis of Annex 1 DSV plus SCCs or the DPF; fourth the preparation of the ISO/IEC 27001:2022 migration where relevant. For implementation, the mandates Swiss DSG Data Protection Advisor, External DPO under GDPR Art. 37 and the support for an ISMS under ISO/IEC 27001 are available. A deeper overview is provided by the DSG pillar guide (German-language pillar).
A sensible roadmap sets priorities by risk and deadline: first the AI Act prohibitions under Art. 5 and the classification of high-risk AI, then the consolidation of cross-border transfers and notification processes, finally the ISO migration. Quarterly steering with senior management, legal, IT security and data protection is advisable as an accompanying measure. The investment in a clearly documented maturity level pays off not only in the supervisory situation but also through faster supplier approvals, shorter contract negotiations with EU clients and measurably reduced premiums for cyber insurance policies.
