Data Protection Zurich, DSG and Cantonal IDG

6 min readLast updated By Dominic Staiger

Introduction

Data protection in the Canton of Zurich follows a two-track logic: private companies, foundations and cooperatives are subject to the revised Federal Act on Data Protection (DSG); cantonal administrations, municipalities, schools, hospitals, pension funds and other public bodies are subject to the cantonal Information and Data Protection Act (IDG ZH, LS 170.4). The two regimes live side by side in practice and overlap wherever private processors act for the public sector, public bodies pass data on to private parties, or joint data pools (such as school IT or a cantonal cloud) arise.

This article bundles what management, in-house legal and IT leads in the greater Zurich area need to know in practice:

  • scope and specifics of the IDG ZH;
  • role of the Data Protection Commissioner of the Canton of Zurich;
  • interfaces between federal, cantonal and municipal levels;
  • typical case constellations from the activity reports;
  • cloud, AI and cantonal practice;
  • practical obligations for companies with ZH exposure.

The piece is aimed at private companies headquartered or primarily active in Zurich, at public bodies and at processors regularly accepting mandates from the city or canton of Zurich.

The IDG ZH at a glance

The Zurich Information and Data Protection Act has been in force since 2008 and combines two regulatory objectives in one statute: the processing of personal data by public bodies (data protection) and public access to official documents (the principle of transparency). Like the federal BGÖ it assumes that official information is in principle accessible unless overriding public or private interests stand in the way (sections 20 et seq. IDG ZH).

The IDG ZH applies to the canton, the municipalities, the independent agencies of cantonal or municipal law (hospitals, pension funds, EWZ, BVK, ZKB in its public-law arm) and to private parties insofar as they have been entrusted with public tasks and process personal data for that purpose (section 3 IDG ZH). This "functional" extension is decisive: a private company that, for instance, manages school-absence data or operates a mobility app on behalf of the canton can be subject to the IDG to that extent.

Core duties are proportionality (section 8), purpose limitation (section 9), accuracy (section 7), disclosure restrictions (sections 16-19) and information and access rights (sections 13, 20, 26). For sensitive personal data (section 3 lit. b IDG ZH) a heightened protection standard applies, including a clear statutory basis for processing.

Tasks of the ZH Data Protection Commissioner

The Data Protection Commissioner of the Canton of Zurich is an independent supervisory and advisory authority with her own secretariat. Her tasks flow from sections 31-36 IDG ZH:

  1. supervision of all public bodies of the canton and the municipalities;
  2. advice to these bodies and to citizens;
  3. opinions on legislative drafts with data-protection relevance;
  4. handling of complaints from data subjects;
  5. annual activity report to the cantonal parliament;
  6. prior checking of high-risk processing (section 10 IDG ZH).

By international comparison the authority is rather slim, but it is very active in publishing: practical guidance on school IT, health data, body cameras, video surveillance, open data and AI deployment effectively constitutes the yardstick against which private companies in similar constellations are also measured, not least because the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) regularly tracks parallel lines.

An important point for companies: anyone acting as a processor for a Zurich public body is de facto subject to the cantonal commissioner's oversight. In practice the commissioner requests information about security measures, sub-processor chains and data flows directly from the private provider. Constructive cooperation and well-documented controls pay off.

Notable lines from ZH practice

Recent activity reports and opinions of the ZH Data Protection Commissioner reveal lines that have come to shape Swiss data-protection practice as a whole:

  • Cloud migration in the public sector: clear demand for a risk analysis, contractual safeguards, lock-in avoidance and, for sensitive data, customer-managed keys or Swiss data residency.
  • AI in schools and administration: sceptical position on the use of generative AI without a sound DPIA, clear purpose limitation and pupil information. See further ChatGPT at Work.
  • Video surveillance in public spaces: restrictive practice aligned with FDPIC guidance; demand for a clear statutory basis, proportionality and short retention.
  • Body cams and police IT: differentiated stance demanding clear recording triggers and auditable logs.
  • Open data publications: consistent anonymisation as the standard, complemented by a re-identification risk assessment.

These lines are indirectly relevant to private companies. Anyone serving a public body is bound through procurement requirements, and in proceedings before the FDPIC the ZH practice is often referenced.

Federal-cantonal-municipal interfaces

Depending on the task, private companies must serve several supervisors in parallel. Examples:

Healthtech processing patient data on behalf of the University Hospital: the controller remains the hospital under IDG ZH; the healthtech is a processor under Art. 9 DSG and is also subject in practice to ZH supervision, with EPDG (federal law) applying additionally for the electronic patient record. If the same solution is sold to German clinics, GDPR and the state data-protection authorities are added.

EdTech for Zurich school municipalities: the controller is the school municipality (a public body); the EdTech is a processor. The ZH commissioner has published clear expectations on data location, sub-processors and telemetry. For federal bodies and cantonal universities, FDPIC oversight may additionally apply.

FinTech cooperating with ZKB: ZKB is a public-law institution with its own ZKB Act; in its banking operations BankG and FINMA law apply (private data-protection regime: DSG); in the public-mandate area IDG ZH may come into play. The FinTech partner should expect both contractual packages.

In contracts with ZH counterparties we generally recommend a clear allocation matrix that captures which regime applies, who fulfils which notification duty and how data breaches are escalated (FDPIC, ZH commissioner, cantonal bodies, BACS where there is a cyber dimension).

Cloud, AI and cantonal practice

Microsoft 365, Google Workspace and AWS are broadly deployed in the Canton of Zurich across both private and public sectors. The ZH commissioner has worked out a differentiated position: cloud is not categorically excluded, but it requires documented transfer-risk analyses, contractual safeguards, technical protective measures and, for sensitive personal data, additional structural measures such as pseudonymisation or European/Swiss data localisation with customer-managed keys.

For private companies operating under the DSG the technical line is the same but the supervisor (FDPIC) is somewhat more accommodating: since the EU-US Data Privacy Framework adequacy decision of 2023 and its Swiss recognition in summer 2024, transfers to DPF-certified US providers are in principle permissible. A transfer-risk analysis remains advisable, especially for sensitive sectors (health, finance, authorities).

For AI deployment, whether generative AI in administration, recruiting or customer interaction, the ZH practice requires a data-protection impact assessment, a clear processing basis and in particular no training data flow to third-party models without explicit justification. Comparable requirements arise under the EU AI Act, which in any event binds Zurich providers with EU market exposure (see AI Act High-Risk Systems).

Practical obligations for ZH companies

What should Zurich companies concretely do?

  1. Build a record of processing activities under Art. 12 DSG, with separate columns for "as controller" and "as processor"; flag public-sector mandates separately.
  2. Publish a current privacy notice under Art. 19 DSG covering identity, purposes, recipients, third-country transfers, retention periods and rights.
  3. Conclude or update data-processing agreements with every service provider, especially cloud and marketing tools (see DPA Switzerland).
  4. Appoint an external data-protection adviser under Art. 10 DSG and notify the FDPIC to unlock the DPIA relief under Art. 22(5) DSG.
  5. Implement an incident-response plan with defined escalation steps for the FDPIC (72 h), the ZH commissioner (public-sector mandates), FINMA (finance), BACS (critical infrastructure) and EU supervisors.
  6. Train personnel at least annually with a documented attendance list.
  7. Maintain a separate list of third-country transfers with their mechanism (DPF, SCC, BCR) and last TIA date.
  8. For ZH public-sector mandates, check procurement requirements early and keep a dedicated IDG compliance folder.

For holding structures headquartered in Zurich with foreign subsidiaries we recommend a group-wide data-protection governance with central advice and local contacts.

How SIDD supports you

SIDD is rooted in the greater Zurich area and serves mandates ranging from SMEs to listed groups, as well as processors for cantonal and municipal clients. We know the expectations of the Data Protection Commissioner of the Canton of Zurich from numerous proceedings and consultations and bring experience from parallel FINMA, FDPIC and EU GDPR mandates.

Concretely we offer an external Swiss data-protection adviser under Art. 10 DSG, an EU GDPR DPO for your EU exposure, an ISMS / ISO 27001 build-out for the parallel security requirements, and data-protection workshops for your teams. Write to us via the contact form or request a concrete quote for your Zurich organisation.

Need help putting this into practice? SIDD operates the matching service.
See service →

Data Protection Zurich, DSG and Cantonal IDG

INSIGHT

Data Protection
24 May 2026
Dr. Dominic Staiger
Data protection in the canton of Zurich: the IDG ZH for public bodies, the FADP for private companies, the cantonal authority's role, cloud and AI.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.