FDPIC (EDÖB), Tasks, Powers and Reporting Channels Explained

7 min readLast updated By Dr Iur Dr Econ Nino Jibuti

Introduction

With the entry into force of the DSG on 1 September 2023, the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) shifted from an advisory supervisor to an authority with genuine investigative and enforcement powers. Anyone still perceiving the FDPIC mainly as a sender of recommendations is underestimating today's regulatory reality. On 12 November 2025 the Federal Council signalled a further strengthening of the authority in terms of resources and procedural efficiency.

This article explains how the FDPIC is structured, what tasks it performs, what concrete powers it holds vis-à-vis controllers and processors, and which reporting channels exist, both for controllers (breach notification, DPIA consultation) and for data subjects (complaint, denunciation). The article covers:

  • its anchoring in Art. 43 et seq. DSG and in the Freedom of Information Act (BGÖ);
  • the election and independence of the head of the authority (currently Adrian Lobsiger, elected by the Federal Assembly);
  • core competences: investigation, ruling, recommendation, opinion, public information;
  • DSG fines addressed at natural persons (not companies!) with a ceiling of CHF 250,000;
  • formal reporting channels including online platforms and deadlines;
  • selected recent decisions and opinions shaping administrative practice.

The aim is an action-oriented overview for data protection officers, executive boards and legal departments that need to know when the FDPIC knocks, when they themselves must knock, and what happens if they do not.

Role and institutional status

Under Art. 43 DSG the FDPIC is an independent federal authority. The head is appointed by the Federal Council and confirmed by the United Federal Assembly. The term of office is four years and re-election is possible. This setup is intended to guarantee political independence, the FDPIC is not part of any department and not bound by instructions, which distinguishes it from most federal offices.

Structurally the authority counts roughly 50 staff organised in four practice areas (private-sector data protection, federal-body data protection, freedom of information, legal/international) plus central services. Compared with EU supervisory authorities (CNIL ~300, BfDI Germany ~290), the FDPIC is small in headcount, which shapes its prioritisation: it focuses on infringements with broad impact, sectoral priorities (health, finance, AI, telecoms) and on cases triggered by complaints or media coverage.

Beyond data protection, the FDPIC is responsible for the freedom-of-information regime under the BGÖ, i.e. access to federal administration documents. This dual role is deliberate and internationally unusual; it gives the authority a broad information-rights perspective. For companies, the data protection pillar is the relevant one, which is what this article focuses on.

Internationally, the FDPIC is an observer member of the European Data Protection Board (EDPB) and a full member of the Global Privacy Assembly. This network explains why Swiss practice and EU lines tend to converge quickly even though Switzerland is not bound by the GDPR.

Tasks under Art. 49 et seq. DSG

The FDPIC's tasks fall into four functions: advise, investigate, order, inform. In detail:

Advice and opinions: Controllers may consult the FDPIC under Art. 23 DSG, in particular when a Data Protection Impact Assessment (DPIA) reveals a high residual risk and the planned measures are insufficient. The opinion is delivered within two months, is not binding but a major compliance indicator in practice. The FDPIC also regularly comments on legislative proposals (consultations), cantonal initiatives and sectoral standards (e.g. on AI guidelines, cookies, cloud use).

Investigation: Under Art. 49 DSG the FDPIC may open proceedings ex officio or upon complaint. It has rights to information, file access and on-site inspections; controllers and processors are bound to cooperate. The threshold is low: sufficient indications of an infringement are enough.

Ruling: Where the FDPIC identifies an infringement, it may issue rulings under Art. 51 DSG, e.g. amend, suspend or terminate a processing operation, order the destruction or rectification of data, or order notification of data subjects. These rulings can be appealed to the Federal Administrative Court and at second instance to the Federal Supreme Court.

Information: The FDPIC publishes an annual activity report (Art. 57 DSG), conducts thematic consultations and maintains an extensive website of guidance (cookies, cloud, AI, cross-border transfers, breaches).

Sanctions and fines regime

The DSG sanctions architecture differs fundamentally from GDPR and is often misunderstood in practice. Three points are critical:

First: Under Art. 60 et seq. DSG, fines are addressed exclusively to natural persons, not companies. The addressee is the responsible person within the company, typically a member of executive management or the designated data protection officer. A corporate fine of up to CHF 50,000 under Art. 64 DSG is only available exceptionally where identifying the natural person would entail disproportionate effort.

Second: The ceiling is CHF 250,000 per infringement (Art. 60 DSG). That is nominally lower than the GDPR maximum (EUR 20 million / 4 % of group turnover) but lands on a person, not the company, with all the reputational and employment consequences for the individual concerned.

Third: Only selected intentional infringements are punishable, not every act of negligence. Covered are in particular breaches of information, access and cooperation duties (Art. 60 DSG), breaches of due-diligence duties for cross-border transfers or processing (Art. 61 DSG), and breaches of professional confidentiality (Art. 62 DSG). Fine proceedings are not run by the FDPIC itself but by the cantonal criminal-prosecution authorities, the FDPIC files a denunciation.

Important: addressing fines personally shifts the internal risk allocation. Executive boards must document data protection responsibilities clearly (CISO/DPO mandates, delegation chains), so that the CEO position is not addressed by default.

Reporting channels overview

The FDPIC runs several reporting channels that must be distinguished by trigger. Picking the wrong channel costs time and credibility.

  • Breach notification under Art. 24 DSG: Once the controller becomes aware of a data security breach likely to entail high risk to data subjects, it notifies as soon as possible. The FDPIC online platform captures the nature and scope of the breach, the data categories affected, the estimated number of data subjects, consequences and measures taken. We treat the workflow in detail in our piece on data breach reporting.
  • DPIA consultation under Art. 23 DSG: Where a DPIA reveals a high residual risk despite measures, the FDPIC must be consulted in advance. Deadline: two months for the opinion.
  • Complaints from data subjects or whistle-blowers: Via the online platform or in writing; anonymity is possible but complicates fact-finding.
  • Access requests under the BGÖ: Concern access to federal-administration documents, not personal data held by private actors.

A practical point: the FDPIC accepts informal preliminary contact, phone calls to the secretariat or emails sketching the facts. Particularly for complex incidents that are still under forensic investigation, an early heads-up with subsequent detail is in practice considered more serious than waiting for a final forensic conclusion.

How an investigation unfolds

When the FDPIC opens proceedings, they typically run through four phases. Knowing the sequence helps avoid procedural mistakes that cannot be corrected later.

Phase 1, preliminary review: Based on a complaint, a breach notification or its own perception, the FDPIC decides whether to formally open proceedings. In practice an initial questionnaire is sent with a short deadline (10–20 working days). Answers should be substantiated, complete and supported by documents (contracts, processing register, DPIA, security concepts).

Phase 2, investigation: The FDPIC may request files, conduct interviews, retain experts and undertake on-site inspections. Controllers and processors are bound by duties to cooperate and inform (Art. 49(3) DSG); refusal can carry criminal consequences.

Phase 3, ruling: If an infringement is confirmed, the FDPIC issues a reasoned ruling. This may order modification of processing, suspension or notification of data subjects. The ruling is preceded by a right to be heard, the addressee may comment on the intended orders.

Phase 4, appeal: Rulings can be appealed within 30 days to the Federal Administrative Court, whose decision can be brought before the Federal Supreme Court. We recommend bringing in counsel experienced in data protection and administrative law from Phase 1, not only when the ruling is on the table.

Recent practice and thematic priorities

FDPIC activity reports of the past few years and ongoing practice show clear thematic priorities that will continue to shape supervision in 2025/2026.

Artificial intelligence: The FDPIC issued several opinions on generative AI in 2023 and 2024 and emphasised transparency, purpose limitation and cross-border transfer requirements. The authority actively tracks OpenAI, Google and Meta products.

Cloud and cross-border transfers: The recognition of the Swiss-US Data Privacy Framework (September 2024), ongoing cloud migrations of federal and cantonal bodies, and sectoral FINMA requirements interact here. The FDPIC has urged authorities and hospitals to caution in several opinions.

Breach notifications: The number of notifications has surged since the DSG entered into force, from roughly 200 per year before 2023 to more than 1,200 in 2025. Common triggers: ransomware, mis-sent communications, compromised email accounts.

Historical anchors: The Helsana bonus-programme case (2018) and the earlier Logistep case (2010) remain emblematic for when a processing operation becomes unlawful due to lack of proportionality. Cite only these well-documented cases and avoid speculative references.

For a sound situation assessment we recommend the FDPIC's annual activity report as required reading for data protection officers, we analyse it in our briefings.

How SIDD supports you

SIDD represents and advises companies across all FDPIC touchpoints: preventively under our mandate as Swiss data protection advisor, reactively in breach notifications, DPIA consultations and ongoing FDPIC proceedings. Our practice includes drafting responses to the authority, supporting the right-to-be-heard, coordinating IT forensics and communications, and, where necessary, appealing rulings before the Federal Administrative Court.

For sectoral specialities (health, finance, AI), we combine data protection competence with our ISMS and information-security expertise (ISMS / ISO 27001, external CISO/ISB) and offer executive training on personal liability and escalation paths.

If concrete FDPIC correspondence is on your desk or if you want to test preventively whether your structures hold up under proceedings, contact us via the contact form or request a quote. We respond within one business day and respect attorney confidentiality in ongoing proceedings.

Need help putting this into practice? SIDD operates the matching service.
See service →

FDPIC (EDÖB), Tasks, Powers and Reporting Channels Explained

INSIGHT

Data Protection
24 May 2026
Dr. Dr. Nino Jibuti
The FDPIC explained: position, tasks and investigative powers under the FADP, reporting channels, how an investigation runs and current priorities.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.