Skip to content
Swiss FADP

FDPIC Breach Notification Under Swiss FADP: Timeline and Requirements

7 min readUpdated 15 July 2026

Switzerland's revised FADP introduced a mandatory breach notification obligation for the first time. Before the revised Act came into force in September 2023, there was no legal requirement to report data breaches in Switzerland. Now there is — and the mechanism differs meaningfully from GDPR's 72-hour rule.


The Legal Requirement

Under FADP Article 24, a controller must notify the Federal Data Protection and Information Commissioner (FDPIC) "as soon as possible" when a data security breach:

  • Is likely to lead to a high risk to the personality or fundamental rights of the data subjects

This is a risk-based trigger — not all breaches require notification. The assessment must consider the likelihood that the breach will result in real harm to affected individuals.


FADP vs GDPR: The Key Difference

AspectSwiss FADPGDPR
Notification deadline"As soon as possible" — no fixed hours72 hours from awareness (Article 33)
Who to notifyFDPIC (supervisory authority)Lead DPA (supervisory authority)
Individual notificationRequired where high risk to individualsRequired where high risk (Article 34)
ThresholdLikely high risk to personality / fundamental rightsLikely to result in risk to rights and freedoms
DocumentationAll breaches must be documentedAll breaches must be documented (Article 33(5))

The absence of a fixed 72-hour deadline under FADP is less permissive than it sounds. "As soon as possible" means prompt action from the point of awareness — not weeks later. The practical expectation of Swiss authorities is notification within a few days for significant breaches.


When Notification Is Required: Assessing "High Risk"

Not every security incident is a notifiable breach. The key question is whether the breach is likely to result in a high risk to the personality or fundamental rights of affected individuals.

Factors that increase the risk level:

FactorWhy it matters
Sensitivity of dataHealth, financial, biometric, or sensitive FADP categories → higher risk
Number of individuals affectedMore people affected → more likely high risk
Vulnerability of affected personsMinors, patients, employees in power-imbalanced relationships
Nature of the breachIntentional attack vs accidental exposure — both matter
Ease of identificationCan individuals be directly identified from the breached data?
IrreversibilityPermanent disclosure (e.g., published online) vs temporary access
Ability to mitigateCan affected individuals take protective action?

Factors that reduce the risk level:

  • Data was encrypted and key was not compromised
  • Data was pseudonymised and re-identification is not feasible
  • Access was very limited and contained quickly
  • No evidence of actual access to the data

Step-by-Step: What to Do After a Breach

Immediate (Day 0–1)

Contain the incident:

  • Revoke compromised credentials or access
  • Isolate affected systems if necessary
  • Preserve evidence — do not delete logs or overwrite data
  • Notify your security team and escalate to the responsible person for FADP compliance

Begin assessment:

  • What data was affected? (categories, volume, sensitivity)
  • Who may have had access to it?
  • Is the breach contained?
  • Is this a likely high-risk breach under FADP?

Short-term (Day 1–3)

Conduct the risk assessment: Using the factors above, make a documented risk determination: is this a high-risk breach requiring FDPIC notification?

If yes → notify FDPIC promptly. Document the time of awareness and the time of notification.

If no → document the reasoning. Your documentation must show you assessed the risk and determined notification was not required.

Assess individual notification: If the breach creates high risk to specific individuals, notify them "without delay" so they can take protective measures (change passwords, freeze credit, take other action).

FDPIC Notification

Contact the FDPIC at: edoeb.admin.ch

Provide:

  • Description of the nature of the breach (what happened)
  • Categories and approximate number of data subjects affected
  • Categories and approximate volume of personal data affected
  • Contact details of the data protection advisor (if appointed)
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

If all information is not available immediately, an initial notification can be submitted and supplemented — a common approach when investigation is still ongoing.

Documentation (Always)

Regardless of whether FDPIC notification is required, document every breach. Your records should include:

  • Date and time the breach was detected
  • Date and time awareness was established
  • Description of the incident
  • Data affected (categories, volume, sensitivity)
  • Risk assessment with reasoning
  • Decision on notification (notify or not) with justification
  • Measures taken to contain and remediate
  • Date of FDPIC notification (if applicable)
  • Date of individual notification (if applicable)

Retain breach records for at least 2 years.


If You Also Have EU Customers: Running FADP and GDPR Notifications in Parallel

If a breach affects both Swiss residents and EU residents, you may need to notify both the FDPIC and the relevant EU DPA(s). The timelines differ:

  • GDPR: 72 hours from awareness to DPA notification
  • FADP: As soon as possible — but in practice, if you are running GDPR notification you should run FADP notification simultaneously

Practical approach: when a breach is assessed as high-risk under either framework, run both notification tracks simultaneously. The GDPR 72-hour deadline is your constraining timeline.

Identify your lead EU DPA: If you are EU-established, notify your lead DPA. If you are not EU-established, notify DPAs in each affected EU member state.

Identify the responsible person under FADP: Given personal liability under FADP, the responsible person should be directly involved in the breach response and notification decision.


What the FDPIC Can Do After Notification

The FDPIC may:

  • Request additional information about the breach
  • Open an investigation into the controller's security practices
  • Issue recommendations or require corrective action
  • Refer cases for criminal prosecution where violations are identified

Unlike EU DPAs, the FDPIC does not directly impose fines — enforcement goes through criminal authorities under FADP's personal liability model. But the FDPIC's investigation can establish the factual basis for those proceedings.


Building a Breach Response Procedure

A documented breach response procedure reduces notification delays and the risk of missing obligations. It should cover:

  1. How breaches are detected and reported internally (helpdesk tickets, monitoring alerts, employee reports)
  2. Who is notified immediately (security team, CTO, responsible person)
  3. How the risk assessment is conducted and documented
  4. Who has authority to decide on FDPIC notification
  5. Who drafts and sends the FDPIC notification
  6. Parallel GDPR notification process if applicable
  7. Individual notification process
  8. Post-incident review and remediation steps

ComplyOne assesses your FADP compliance alongside GDPR and identifies the gaps specific to Swiss law.

Check your Swiss FADP obligations →