DSG Fines, Who Is Personally Liable, and How Much
Introduction
Unlike the GDPR, the Federal Act on Data Protection (DSG) does not sanction breaches with administrative fines against the company but with criminal fines against natural persons. Art. 60–66 DSG create a distinct risk profile: instead of the large corporate fines issued in Brussels or Dublin, Switzerland exposes the responsible individual, typically a member of the management board or an operational decision-maker, to a personal fine of up to CHF 250,000.
This construction is unusual by international standards and is regularly underestimated in practice. It demands a different governance: personal responsibilities must be clearly assigned, training duties documented, and decisions on processing activities verifiably stored. This article walks through the central criminal provisions, the constellations in which they apply, the evidentiary practice, and the comparison with the GDPR.
- Legal basis: Art. 60–66 DSG, Art. 6 VStrR, Art. 102 StGB.
- Fine ceiling: up to CHF 250,000 per offence and person.
- Addressees: natural persons; exceptionally companies (Art. 64 DSG, max. CHF 50,000).
- Prosecution: complaint-based by data subjects or the Federal Data Protection and Information Commissioner (FDPIC / EDÖB).
- Statute of limitations: 5 years (Art. 109 StGB).
- Mens rea: intent or dolus eventualis required, negligence usually does not suffice.
The provision is more than a theoretical risk: since the law entered into force several cantonal prosecutors have actively pursued criminal complaints based on data-protection violations. The reporting threshold is low.
The criminal provisions at a glance
Art. 60 DSG addresses breaches of information, access and cooperation duties. A responsible person who wilfully breaches Art. 19 DSG (information duty), Art. 25 DSG (right of access) or Art. 49 ff. DSG (cooperation with the FDPIC) can be fined up to CHF 250,000. The threshold is intent or dolus eventualis, systematically ignoring access requests qualifies as dolus eventualis.
Art. 61 DSG sanctions breaches of duty of care: unlawful cross-border disclosure (Art. 16–18 DSG), breach of the processor requirements (Art. 9 DSG), failure to meet the minimum security standard (Art. 8 DSG in conjunction with Art. 1–6 DSV). Again: fines up to CHF 250,000.
Art. 62 DSG sanctions the breach of professional secrecy, again with CHF 250,000. This provision particularly affects fiduciary, legal, medical and IT-service employees.
Art. 63 DSG (disregard of orders) provides for fines up to CHF 250,000 where binding orders of the FDPIC or courts are ignored.
Art. 64 DSG opens, exceptionally, fines against the company itself, but only where identifying the responsible natural person would require disproportionate effort. Cap: CHF 50,000. This subsidiary corporate fine remains rare and is not the primary sanction framework.
Who counts as a responsible person
The central question is which individual inside the company is the addressee of the criminal provision. The DSG does not answer this exhaustively; the general rules on principal liability (Art. 6 VStrR, Art. 29 StGB) and corporate criminal liability (Art. 102 StGB) apply alongside.
Typical addressee groups:
- Members of the executive board: for strategic decisions such as SaaS procurement, new processing activities or reorganisation of data flows.
- Heads of business units with operational data authority: HR head for employee data, marketing head for profiling, IT head for technical security measures.
- Data protection officer / DPO: in narrow constellations, where they actively instruct or tolerate breaches.
- Board of directors: in cases of structural failure, documented warnings without follow-up, or wilful neglect.
- Processors: individual employees acting in breach of instructions.
What matters is not the formal place in the org chart but the actual decision authority over the disputed processing. Someone who was "not officially in charge" but tolerated or directed the processing can be held responsible. A complete responsibility matrix inside the Records of Processing Activities is therefore not just a duty under Art. 12 DSG but a personal safeguard for the individual employees concerned.
Frequent fact patterns
Enforcement practice so far points to a small number of fact patterns that are reported more frequently than others. Four are particularly relevant.
Breach of the information duty (Art. 19 DSG): a privacy notice that omits important recipients, such as US cloud providers or marketing partners, fulfils the offence. Complaints typically come from former employees or unhappy customers who, in an access procedure, are informed of additional recipients not listed in the notice.
Ignored access requests (Art. 25 DSG): whoever fails to answer an access request within 30 days (Art. 25(7) DSG) risks not just a complaint to the FDPIC but a criminal complaint under Art. 60 DSG. Most known criminal proceedings originate here.
Unlawful cross-border disclosure (Art. 16–18 DSG): transfers to US providers without SCCs, without a Swiss Addendum or without a TIA. Particularly in M&A transactions where due-diligence data is loaded into data rooms of unclear third-country exposure.
Breach of professional secrecy (Art. 62 DSG): in fiduciary and healthcare contexts in particular, for example when employees use unsecured cloud tools (private Dropbox, ChatGPT with plaintext) for client data.
In all four constellations, the sanction addressee is the natural person who acted or failed to act, not the company. Personal exposure makes the Swiss approach, from the perspective of responsible individuals, sharper than the GDPR logic.
Evidentiary practice and proceedings
Criminal prosecution typically follows a complaint by the data subject or a referral by the FDPIC. The cantonal prosecutor at the place of the act, usually the company seat or the place where processing occurs, has jurisdiction.
Evidence routinely used:
- Correspondence: emails of the accused person directing, commissioning or tolerating the disputed processing.
- Minutes: management meetings, board minutes, architecture reviews where privacy risks were raised but not handled.
- Records of Processing Activities: missing recipients or legal bases indicate a lack of due care.
- Access responses: late or refused responses document the objective side of the offence.
- Whistleblower statements: former employees report on internal discussions.
The subjective side (intent / dolus eventualis) is frequently inferred from the combination of knowledge and inaction. Anyone who received a written risk warning and did not act is acting with dolus eventualis. From a defence perspective the key is therefore: document risk warnings, prove escalation paths, justify decisions. A board member who in proceedings can only argue "I had no idea" has no defence, the burden of proof for due diligence effectively lies with the accused in practice.
Comparison with the GDPR
The GDPR sanctions through administrative fines against the company (Art. 83 GDPR), with the well-known ceilings of EUR 10 / 20 million or 2 / 4 % of global group turnover. Personal liability of natural persons is not systematically provided for by the GDPR but can be added by national criminal provisions (e.g. § 42 BDSG Germany, § 63 DSG Austria).
Structural differences:
- Addressee: GDPR targets the company; DSG targets primarily the natural person.
- Quantum: GDPR up to EUR 20 million / 4 %; DSG up to CHF 250,000 / person.
- Procedure: GDPR as administrative procedure (supervisory authority); DSG as criminal procedure (prosecutor).
- Mens rea: GDPR, negligence suffices; DSG, intent or dolus eventualis required.
- Insurability: GDPR fines may, depending on the policy, be insurable; personal criminal fines under DSG are generally not insurable (Art. 60 ff. StGB are strictly personal).
For an internationally active Swiss company this means: in an EU incident, GDPR risk hits the company and DSG risk hits the acting individuals cumulatively. D&O policies generally cover only defence costs, not the fine itself, the personal financial exposure remains. This asymmetry makes the Swiss model particularly relevant for management boards and justifies tighter personal governance than would seem necessary under pure GDPR logic.
Prevention and defence
From the perspective of management boards and privacy officers, the personal criminal rule translates into concrete prevention and documentation duties that should be anchored in the internal control system (ICS).
Preventative measures:
- Clear responsibility matrix: who decides on which processing, on which legal basis, and through which escalation chain?
- Documented decisions: architecture reviews, vendor onboardings and DPIA outcomes retained with date and responsibility statement.
- Training of key roles: HR, marketing, IT and sales leaders receive annual training with proof, they are the most frequent addressees of a criminal complaint.
- Access and complaint process: with response deadlines, escalation paths and per-request documentation.
- Sub-processor and third-country control: quarterly review, documented.
In proceedings: immediately mandate defence counsel specialised in data-protection criminal law. Present internal risk documentation, training records and escalation minutes. Distinguish between organisational failure (subsidiary corporate fine Art. 64 DSG, max. CHF 50,000) and individual intent. In many proceedings, substantial proof of due diligence rebuts intent and leads to discontinuation.
How SIDD supports you
SIDD supports management boards, directors and data-protection leads in preventing personal liability risks arising from Art. 60–66 DSG. Our Swiss data-protection advisory covers the creation of the responsibility matrix, the documentation of decisions on processing activities and the implementation of an access and complaint process that reliably meets the 30-day deadline in Art. 25 DSG.
For training key roles we run targeted privacy workshops with proof of attendance, both for executive boards and for HR, marketing and IT leads, who are the most frequent addressees of criminal complaints in practice. The Priverion platform documents training participation, access cases and risk decisions in a way that holds up in defence proceedings.
If you are already confronted with a criminal complaint or an FDPIC inquiry, book a short-term appointment via our contact form. For a preventative risk analysis of your current data-protection governance, request a quote.
