Swiss Federal Act on Data Protection (DSG), The Complete Guide

7 min readLast updated By Dominic Staiger

Introduction

The revised Swiss Federal Act on Data Protection (DSG, initially often also called «nDSG») entered into force on 1 September 2023 together with the Data Protection Ordinance (DSV). It replaces the 1992 version and aligns Switzerland on the key points with the European data protection standard, without being a pure GDPR copy. Almost three years after entry into force, application practice has consolidated: the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) has fully assumed its supervisory role, the fines regime has been sharpened in several Federal Supreme Court decisions, and the breach notification under Art. 24 DSG has become operational routine.

This guide offers the overall view of the DSG in practice-oriented form. It provides:

  • the material, personal and territorial scope;
  • key definitions (personal data, sensitive data, controller, processor);
  • the eight data processing principles;
  • data subject rights and information duties;
  • controller and processor duties (register, AVV, DPIA);
  • the data security and breach notification architecture;
  • sanctions, fines and the role of the FDPIC;
  • interfaces with GDPR, ISG and FINMA regulation.

For deeper dives on individual topics, our articles on data protection advisor duties, breach notification, cookie handling, AVV and FDPIC practice are linked from our topic pages. This guide forms the common thread.

Scope and definitions

The material scope covers under Art. 2 DSG the processing of personal data of natural persons by private persons and federal bodies. Legal persons are no longer protected, a deliberate alignment with the GDPR. Cantonal authorities remain subject to cantonal data protection laws, which were also revised in many cantons in 2024/2025.

The personal scope binds controllers and processors based in Switzerland and, via the market principle in Art. 3 DSG, foreign actors processing data of persons in Switzerland, provided the processing has effect in Switzerland. The DSG thus has extraterritorial reach, comparable to Art. 3 GDPR.

The key definitions in Art. 5 DSG are:

  • Personal data: Any information relating to an identified or identifiable natural person. Pseudonymous data is covered if re-identification is possible with reasonable effort.
  • Sensitive personal data: Religious, philosophical, political, trade-union activities/views; health, intimate sphere, race; administrative and criminal proceedings; social welfare measures; genetic and biometric data (new since the 2023 revision).
  • Controller: The party determining the purposes and means of processing.
  • Processor: The party processing on behalf of and on instructions from the controller.
  • Processing: Any handling of data, collection, storage, use, transmission, destruction.

Profiling and high-risk profiling are defined separately in Art. 5(f) and (g), a novelty compared with the old DSG that shapes the applicability of DPIA and consent requirements.

The data processing principles

Art. 6 DSG anchors eight principles that must underlie every processing operation. They act as general clauses and serve as benchmarks in an FDPIC review.

  1. Lawfulness: Processing must rest on a permissible legal basis (statutory duty, overriding interest, contract, consent).
  2. Good faith: Processing must be decent and traceable for the data subject.
  3. Proportionality: Processing must be suitable, necessary and proportionate in the narrow sense. Particularly relevant for tracking and AI.
  4. Purpose limitation: Processing only for the purpose stated at collection, evident from circumstances or required by law.
  5. Recognisability: Collection and purpose must be recognisable (information duty under Art. 19 DSG).
  6. Accuracy: Data must be factually accurate; inaccurate data must be corrected or deleted (Art. 6(5) DSG).
  7. Consent: Where required, it must be voluntary, informed and for a specific case; for sensitive data and high-risk profiling, explicit (Art. 6(7) DSG).
  8. Data security: Adequate technical and organisational measures under Art. 8 DSG and Art. 1 et seq. DSV.

These principles are not soft law, their breach can lead to FDPIC prohibition and, in qualified cases, fines for the natural person.

Data subject rights

Art. 25 et seq. DSG govern data subject rights. They are the operational mainstay for every data protection advisor and the most frequent trigger for FDPIC proceedings.

Right of access (Art. 25): Every person can request free of charge whether data about them is processed and obtain information on purposes, retention, recipients and source. Deadline: 30 days, extendable to 3 months for complex requests. Refusal only on narrowly defined grounds (Art. 26 DSG): overriding third-party interest, statutory secrecy, abusive or manifestly unfounded request.

Right to data portability (Art. 28): Newer than the access right. The person can request data they themselves provided in a common electronic format and have it transferred to another controller.

Rectification (Art. 32(1)): Inaccurate data must be corrected.

Destruction / blocking (Art. 32(2)): For unlawful or purpose-incompatible processing the person may request destruction or blocking.

Objection (Art. 30(2)): Against processing where the overriding interest no longer holds.

Protection from automated individual decisions (Art. 21): Where decisions have legal effect or significantly affect the person, they have the right to human review, subject to the conditions.

Operationally, all rights should arrive through a defined channel (email inbox, web form), be triaged by the DPO, documented and answered within deadline. The access register is a standard asset in the data protection management system.

Controller duties

The core controller duties are spread across Art. 7–24 DSG and complement each other.

  • Privacy by design / default (Art. 7): Data protection must be integrated into systems and processes from the outset; defaults must be privacy-friendly.
  • Data security (Art. 8): Adequate technical and organisational measures, calibrated to state of the art, implementation cost and risk. Concretised in Art. 1–6 DSV.
  • Processing by processors (Art. 9): Processing by third parties only with contract, authorisation of further sub-processors, ensuring data security. Depth in our AVV guide.
  • Data protection advisor (Art. 10): Voluntary, but with procedural benefit in DPIA consultation.
  • Processing register (Art. 12): Required for controllers and processors, with exception for companies under 250 employees without high data risks.
  • Information duty (Art. 19–21): Detailed information at data collection; privacy notice as standard tool.
  • Data Protection Impact Assessment (Art. 22): Mandatory for likely high risk; FDPIC consultation under Art. 23 where high residual risk remains.
  • Cross-border transfer (Art. 16–18): Only with adequate level of protection or appropriate safeguards (FDPIC adequacy decision, SCC, BCR, Swiss-US DPF).
  • Breach notification (Art. 24): As soon as possible where high risk is likely; information of data subjects where required. Workflow in our 5-step guide.

Fulfilling all these duties yields a functioning data protection compliance stack. Weaknesses typically lie not in legal understanding but in documented implementation, and that documentation is exactly what the FDPIC reviews in proceedings.

Sanctions and fines

The sanction architecture (Art. 60–66 DSG) is a Swiss particularity. Three points stand out:

Personal addressing: Fines hit natural persons, not companies (exception Art. 64 for de minimis cases). The addressee is the natural person responsible for the processing, typically a board member, the DPO or the actual handler. This construction shifts risk from the company to the individual.

Maximum fine: Up to CHF 250,000 per infringement. Nominally lower than the GDPR maximum but lands on the individual.

Punishable infringements: Only intentional breaches of selected duties, information and access duties (Art. 60), due diligence in cross-border transfers and processing (Art. 61), breach of professional secrecy (Art. 62), disregard of FDPIC rulings (Art. 63).

Beyond fines, the DSG provides civil-law claims (personality protection under Art. 28 CC, damages, satisfaction) and administrative orders by the FDPIC (modification, suspension, termination of processing). The combination of these three pathways is the real risk, not the nominal fine ceiling.

We treat the fines regime in detail in our article DSG fines and liability.

Interfaces with GDPR, ISG, FINMA

The DSG does not stand alone. For Swiss companies with international reach or regulatory duties, several regimes apply in parallel.

GDPR: Applies as soon as a Swiss actor processes personal data of persons in the EU (market principle, Art. 3 GDPR). In such cases the DSG continues to apply in parallel, with an EU representative under Art. 27 GDPR. Depth in our GDPR Switzerland guide.

ISG (Information Security Act): For KRITIS operators since April 2025 with cyber reporting duty to the BACS (formerly NCSC). Content overlaps with the DSG breach duty but must be addressed separately. More in NCSC/BACS reporting duty.

FINMA regulation: For supervised banks, insurers and financial market actors, circulars apply additionally (in particular FINMA Circular 2008/21 on operational risks, FINMA Supervisory Notice 03/2024 on cyber risks) plus outsourcing regulation.

EU AI Act: In force since August 2024, with staggered application phases through 2027. Market effect on Swiss providers of AI systems placed in the EU. Interface analysis in AI Act, DSG, GDPR interface.

Sectoral law: KVG (health insurance), BÜPF (telecoms surveillance), GebüV (business records), GwG (anti-money laundering) each contain specific data-processing rules that supplement or modify the DSG.

A robust data protection management system reflects these interfaces and ensures that a processing operation is aligned with all applicable regimes. Anyone working through only the DSG regularly misses the GDPR layer in international business and the FINMA layer in regulated sectors.

How SIDD supports you

SIDD has been the advisory partner for Swiss companies seeking to build or maintain a robust data protection stack since the DSG entered into force. Our standard package combines an inventory against the DSG framework, build of the processing register, AVV landscape, information notices, breach playbook and training plan, auditable within 12 to 16 weeks.

Through our mandates as Swiss data protection advisor and as EU Data Protection Officer we take on the ongoing function after the build is complete. For companies with EU reach we add the Art. 27 EU representation, for regulated actors the ISMS function via ISO 27001 and external CISO/ISB mandates. Workshops via privacy workshops for SMEs embed obligations organisation-wide.

Write to us via the contact form or request a quote, we respond within one business day with a proposal tailored to your size, sector and regulatory reach.

Need help putting this into practice? SIDD operates the matching service.
See service →

Swiss Federal Act on Data Protection (DSG), The Complete Guide

INSIGHT

Data Protection
24 May 2026
Dr. Dominic Staiger
The Swiss Federal Act on Data Protection at a glance: scope, principles, data subject rights, obligations, sanctions and the role of the FDPIC.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.