Data Security & Breach Notification
Federal Act on Data Protection — notification of data security breaches
Switzerland · September 1, 2023
Switzerland's trigger is deliberately narrower than the GDPR's and its clock is deliberately looser. Art. 24(1) requires notifying the FDPIC only where the breach is likely to result in a HIGH risk to the personality or fundamental rights of the data subject — so the many breaches that would be reportable in the EU under the 'any risk' test are not reportable here — and it sets no fixed hour count, requiring notification 'as soon as possible' instead of within 72 hours. Art. 24(4) requires informing affected individuals where that is necessary for their protection or where the FDPIC demands it. A business already running a GDPR breach process should not assume it can simply reuse the EU deadline as a Swiss one, in either direction: the Swiss threshold is higher but the Swiss timing standard is open-ended and the FDPIC's February 2025 guide sets out expectations on content that the statute does not.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.