Switzerland's revised FADP introduced a mandatory breach notification obligation for the first time. Before the revised Act came into force in September 2023, there was no legal requirement to report data breaches in Switzerland. Now there is — and the mechanism differs meaningfully from GDPR's 72-hour rule.
The Legal Requirement
Under FADP Article 24, a controller must notify the Federal Data Protection and Information Commissioner (FDPIC) "as soon as possible" when a data security breach:
- Is likely to lead to a high risk to the personality or fundamental rights of the data subjects
This is a risk-based trigger — not all breaches require notification. The assessment must consider the likelihood that the breach will result in real harm to affected individuals.
FADP vs GDPR: The Key Difference
| Aspect | Swiss FADP | GDPR |
|---|---|---|
| Notification deadline | "As soon as possible" — no fixed hours | 72 hours from awareness (Article 33) |
| Who to notify | FDPIC (supervisory authority) | Lead DPA (supervisory authority) |
| Individual notification | Required where high risk to individuals | Required where high risk (Article 34) |
| Threshold | Likely high risk to personality / fundamental rights | Likely to result in risk to rights and freedoms |
| Documentation | All breaches must be documented | All breaches must be documented (Article 33(5)) |
The absence of a fixed 72-hour deadline under FADP is less permissive than it sounds. "As soon as possible" means prompt action from the point of awareness — not weeks later. The practical expectation of Swiss authorities is notification within a few days for significant breaches.
When Notification Is Required: Assessing "High Risk"
Not every security incident is a notifiable breach. The key question is whether the breach is likely to result in a high risk to the personality or fundamental rights of affected individuals.
Factors that increase the risk level:
| Factor | Why it matters |
|---|---|
| Sensitivity of data | Health, financial, biometric, or sensitive FADP categories → higher risk |
| Number of individuals affected | More people affected → more likely high risk |
| Vulnerability of affected persons | Minors, patients, employees in power-imbalanced relationships |
| Nature of the breach | Intentional attack vs accidental exposure — both matter |
| Ease of identification | Can individuals be directly identified from the breached data? |
| Irreversibility | Permanent disclosure (e.g., published online) vs temporary access |
| Ability to mitigate | Can affected individuals take protective action? |
Factors that reduce the risk level:
- Data was encrypted and key was not compromised
- Data was pseudonymised and re-identification is not feasible
- Access was very limited and contained quickly
- No evidence of actual access to the data
Step-by-Step: What to Do After a Breach
Immediate (Day 0–1)
Contain the incident:
- Revoke compromised credentials or access
- Isolate affected systems if necessary
- Preserve evidence — do not delete logs or overwrite data
- Notify your security team and escalate to the responsible person for FADP compliance
Begin assessment:
- What data was affected? (categories, volume, sensitivity)
- Who may have had access to it?
- Is the breach contained?
- Is this a likely high-risk breach under FADP?
Short-term (Day 1–3)
Conduct the risk assessment: Using the factors above, make a documented risk determination: is this a high-risk breach requiring FDPIC notification?
If yes → notify FDPIC promptly. Document the time of awareness and the time of notification.
If no → document the reasoning. Your documentation must show you assessed the risk and determined notification was not required.
Assess individual notification: If the breach creates high risk to specific individuals, notify them "without delay" so they can take protective measures (change passwords, freeze credit, take other action).
FDPIC Notification
Contact the FDPIC at: edoeb.admin.ch
Provide:
- Description of the nature of the breach (what happened)
- Categories and approximate number of data subjects affected
- Categories and approximate volume of personal data affected
- Contact details of the data protection advisor (if appointed)
- Likely consequences of the breach
- Measures taken or proposed to address the breach
If all information is not available immediately, an initial notification can be submitted and supplemented — a common approach when investigation is still ongoing.
Documentation (Always)
Regardless of whether FDPIC notification is required, document every breach. Your records should include:
- Date and time the breach was detected
- Date and time awareness was established
- Description of the incident
- Data affected (categories, volume, sensitivity)
- Risk assessment with reasoning
- Decision on notification (notify or not) with justification
- Measures taken to contain and remediate
- Date of FDPIC notification (if applicable)
- Date of individual notification (if applicable)
Retain breach records for at least 2 years.
If You Also Have EU Customers: Running FADP and GDPR Notifications in Parallel
If a breach affects both Swiss residents and EU residents, you may need to notify both the FDPIC and the relevant EU DPA(s). The timelines differ:
- GDPR: 72 hours from awareness to DPA notification
- FADP: As soon as possible — but in practice, if you are running GDPR notification you should run FADP notification simultaneously
Practical approach: when a breach is assessed as high-risk under either framework, run both notification tracks simultaneously. The GDPR 72-hour deadline is your constraining timeline.
Identify your lead EU DPA: If you are EU-established, notify your lead DPA. If you are not EU-established, notify DPAs in each affected EU member state.
Identify the responsible person under FADP: Given personal liability under FADP, the responsible person should be directly involved in the breach response and notification decision.
What the FDPIC Can Do After Notification
The FDPIC may:
- Request additional information about the breach
- Open an investigation into the controller's security practices
- Issue recommendations or require corrective action
- Refer cases for criminal prosecution where violations are identified
Unlike EU DPAs, the FDPIC does not directly impose fines — enforcement goes through criminal authorities under FADP's personal liability model. But the FDPIC's investigation can establish the factual basis for those proceedings.
Building a Breach Response Procedure
A documented breach response procedure reduces notification delays and the risk of missing obligations. It should cover:
- How breaches are detected and reported internally (helpdesk tickets, monitoring alerts, employee reports)
- Who is notified immediately (security team, CTO, responsible person)
- How the risk assessment is conducted and documented
- Who has authority to decide on FDPIC notification
- Who drafts and sends the FDPIC notification
- Parallel GDPR notification process if applicable
- Individual notification process
- Post-incident review and remediation steps