Latest news
2025
Federal Administrative Court confirms practice of the FDPIC
In a ruling dated 6 October 2025, the Federal Administrative Court dismissed the appeal lodged by the Swiss citizens’ association ‘Bürgerforum Schweiz’ against a processing ban imposed by the FDPIC.
Schengen: Entry/Exit-System (EES) in operation
On 12 October 2025, the EU Entry/Exit System (EES) went into operation in the Schengen area. As an associated member of Schengen, Switzerland participates in this information system alongside 28 other European states. The FDPIC has created sample letters that data subjects can use to assert their rights.
Cookie Guidelines: updated version published
The FDPIC publishes an updated version of its cookie guidelines dated 22 January 2025, which contains specific clarifications and additions intended to improve the comprehensibility of the text and clarify practical issues.
Closure of preliminary investigation into Coop: Use of intelligent video surveillance cameras at automatic checkouts
The FDPIC is closing its preliminary investigation into the artificial intelligence surveillance cameras used by Coop Group. A formal investigation will not be opened. Examination of the case showed that data was processed in compliance with the Data Protection Act.
The FDPIC has published a factsheet on the forms that are given to patients to sign when they go to the doctor
Patients regularly have questions about the purpose and content of the forms they are given when they consult a doctor. The FDPIC has published a factsheet to remind the data protection framework and clarify its details.
FDPIC signs first MoU with foreign supervisory authority
The Federal Data Protection and Information Commissioner (FDPIC), Adrian Lobsiger, and his United Kingdom counterpart, John Edwards, have signed a Memorandum of Understanding (MoU). This is the first time that Switzerland’s data protection supervisory authority has entered into an agreement of this type.
FDPIC files criminal complaint against Add Conti GmbH for failure to cooperate in an investigation
Following several complaints from affected individuals, the FDPIC opened an investigation on 4 June 2025 into Add Conti GmbH, a company operating in the marketing sector.
FDPIC concludes investigation into voice recognition at PostFinance
The FDPIC has examined whether PostFinance AG is violating data protection regulations when using voice recognition as a means of authentication.
Ruling of the FDPIC against Cembra Money Bank AG
In its ruling of 29 January 2025, the FDPIC concluded its investigation against Cembra Money Bank AG (Cembra). In the proceedings, the FDPIC assessed the statutory time limits for processing requests for information and the information to be provided on the personal data processed.
FDPIC ruling against Inkasso-Team AG
In its decision of 28 April 2025, the FDPIC concluded its investigation into a debt collection agency that published personal data of alleged debtors on a website.
Update - Current data protection legislation is directly applicable to AI
Artificial intelligence (AI) is penetrating economic and social life in Switzerland as elsewhere. The FDPIC therefore wishes to point out that the Federal Data Protection Act, which has been in force since 1 September 2023, is directly applicable to AI-supported data processing.
Conclusion of preliminary investigation X formerly Twitter: use of personal data for training the AI Grok
The FDPIC concludes his preliminary investigation into the use of personal data for training the artificial intelligence (AI) Grok. Users of Platform X can object to their public posts being used to train AI.
The Federal Chancellery's CEBA project
The FDPIC accompanies the ‹Cloud Enabling Büroautomation› (CEBA) project from a supervisory perspective. The focus is currently on the data protection impact assessment carried out by the administration and the implementation of the measure to introduce confidentiality labels for federal administration documents (so-called labelling).
Guidelines on data breaches
The FDPIC has published guidelines on reporting data security breaches.
Guidelines published on data processing using cookies
The FDPIC has published guidelines on data processing using cookies and similar technologies. The guidelines, which are aimed at a specialist audience, describe the data protection requirements for the use of cookies and similar technologies by private controllers, with specific references to the special provisions applicable to federal bodies. The Commissioner derives these requirements from the Federal Data Protection Act (FADP SR 235.1), the Data Protection Ordinance (DPO SR 235.11), the data protection provisions of special federal legislation, as well as from the case law of the Federal Supreme Court, the relevant schools of thought and his previous supervisory practice.
Data Protection Day 2025: Data protection in the face of digital transformation
To mark International Data Protection Day, the University of Lausanne's Faculty of Law, Criminal Sciences and Public Administration organised a public conference on the theme of ‹Freedom of choice in the digital age›, in collaboration with the Federal Data Protection and Information Commissioner (FDPIC), the University of Geneva's Centre universitaire d'informatique and ThinkServices.
Schengen evaluation of Switzerland
A group of experts visited the FDPIC on January 20 2025 as part of the Schengen evaluation of Switzerland in the area of data protection. The evaluation is being carried out on the basis of the Schengen Association Agreement (SAA) between the EU and Switzerland, which has been in force since 2008. This agreement facilitates travel between Switzerland and the EU and EEA member states and improves international legal and police cooperation.
2024
Completion of an informal preliminary enquiry due to indications of data protection violations
20.12.2024 – In November 2023, the software company Concevis was the victim of a hacker attack. Their clients included the Federal Statistical Office (FSO). Both the FSO and Concevis informed the FDPIC about the incident, as there were indications that FSO data may have fallen into the hands of unauthorised persons. The FDPIC subsequently opened an informal preliminary enquiry against the FSO and Concevis and informed the public with a short news report.
The new Data Protection Act in figures
On 1 September 2023, the new Data Protection Act of 25 September 2020 (FADP) came into force, with the aim of better protecting the privacy and fundamental rights of people living in Switzerland.
International Cooperation: 46th Global Privacy Assembly
The Federal Data Protection and Information Commissioner (FDPIC) attended the 46. Global Privacy Assembly, which took place from 28 October to 1 November in Jersey.
Concluding Statement on Data Scraping
Global data protection authorities issue follow-up joint statement on data scraping after industry engagement.
New Swiss-US Data Privacy Framework
15.08.2024 - The Federal Data Protection and Information Commissioner takes note of the new Data Privacy Framework between Switzerland and the USA.
Somali data protection authority pays visit to FDPIC in Bern
07.08.2024 - The Federal Data Protection and Information Commissioner, Adrian Lobsiger, welcomed his Somali counterpart for talks.
Explanations on data processing in clubs and associations supplemented and expanded
09.07.2024 - The existing explanations on data processing in clubs and associations have been comprehensively supplemented with frequently asked questions and important innovations under the new Data Protection Act.
Data Protection Commissioner welcomes public debate on the inter-cantonal agreement on the exchange of data between police corps and the planned involvement of the federal government
27.03.2024 - The Conference of Cantonal Justice and Police Directors (CCJPD) has conducted a consultation on an agreement on the exchange of police data. Following the criticism of the agreement expressed by the Commissioner both in the consultation and in the media, several police corps commanders and the CCJPD felt compelled to publicly reject the FDPIC's criticism.
Meta: No change to the terms of use for Switzerland for the time being
21.06.2024 - Meta will not use the data of Facebook and Instagram users in Switzerland to train its AI either. The US company had originally announced that the data of adult users could be used for AI training from 26 June 2024.
New factsheet on planning and justifying online access
18.6.2024 - Online access to personal data can cause serious prejudice to the fundamental rights of the data subjects concerned. Federal authorities must therefore plan such access in good time in accordance with the Federal Act on Data Protection and justify it to their political overseers. In a new factsheet, the FDPIC shows how this should be done.
Bilateral meeting with the head of the Austrian data protection authority in Bern
04.06.2024 - The Federal Data Protection and Information Commissioner, Adrian Lobsiger, met with his Austrian counterpart in Bern for an exchange of views. Dr. Matthias Schmidl has headed the Austrian data protection authority since january 2024. He was accompanied by his deputy, MMag Elisabeth Wagner. The topics of the exchange were the common challenges and bilateral cooperation in the field of digitalization and data protection as well as freedom of information and the principle of publicity.
Data Protection Day 2024: Digital transformation – Do we still have control over our data?
26.01.2024 - To mark International Data Protection Day, experts will be discussing the topic of ‹Data protection and vulnerability› at the University of Lausanne on 26 January. In his presentation entitled ‹Digital transformation – Do we still have control over our data?›, Florian Harms, head of the Data Protection Division at the Federal Data Protection and Information Commissioner FDPIC, reflects on the interplay between the ability and willingness to control personal data in light of the authority's recent experiences.
Guide to Technical and Organisational Data Protection Measures (TOM) available in English
23.01.2024 - The guidelines on technical and organisational data protection measures (TOM) have been extensively revised and are also available in English in the updated version.
EU adequacy decision regarding Switzerland
15.01.2024 - In its report of 15th January, the European Commission confirmed the adequacy of the Swiss level of data protection. The EU thereby recognises that Switzerland's legislation continues to provide an adequate level of protection for the processing of personal data.
2023
Phishing attack on hotels
12.12.2023 - Cybercriminals have stolen hotels’ access data to booking platforms such as booking.com and are trying to defraud hotel guests.
Freedom of Information Act: The FDPIC publishes his recommendations on takeover of Credit Suisse by UBS
29.11.2023 - Following the takeover of Credit Suisse by UBS, several applications for access to information were submitted to the General Secretariat of the Federal Department of Finance (GS-FDF) and the State Secretariat for International Financial Matters (SIF). Following the refusal of access, the FDPIC received requests for mediation of varying content. Insofar as the documents fall within the scope of the Freedom of Information Act, the FDPIC recommends the deferral of access until the Parliamentary Investigation Commission PInC has completed its work if their disclosure could significantly harm the free opinion-forming and decision-making process of the PInC.
Freedom of Information Act: FDPIC publishes six recommendations on contracts for COVID vaccines
24.11.2023 - During the coronavirus pandemic, several applications for access to contracts for COVID-19 vaccines were submitted to the Federal Office of Public Health (FOPH). After the FOPH had published partly redacted contracts, the FDPIC received ten requests for mediation. In his six recommendations, the FDPIC concludes that access should be granted to a large extend. This concludes the proceedings involving the FDPIC.
European Case Handling Workshop in Bern
22.11.2023 – The Federal Data Protection and Information Commissioner hosted the European Case Handling Workshop in Bern from 8 to 9 November 2023. Under the aegis of the Conference of European Data Protection Authorities, representatives from almost 40 data protection authorities exchanged views on current challenges in dealing with the latest technologies.
Preliminary enquiry due to indications of violations of data protection regulations
14.11.2023 - On 13 November, the FDPIC opened a preliminary enquiry against the company Concevis AG and the Federal Statistical Office FSO due to indications of possible violations of data protection regulations.
Current data protection legislation is directly applicable to AI
09.11.2023 – Artificial intelligence (AI) is penetrating economic and social life in Switzerland as elsewhere. The FDPIC therefore wishes to point out that the Federal Data Protection Act, which has been in force since 1 September 2023, is directly applicable to AI-supported data processing.
Oracle: No concerns for people living in Switzerland
06.10.2023 - The operations which are the focus of unlawful data processing allegations against Oracle America, Inc. in the USA do not affect the Swiss population. The FDPIC has terminated its investigations and decided not to bring formal proceedings.
Switzerland ratifies the Convention 108+
08.09.2023 - At the meeting in Bern, President Berset presented the Council of Europe's secretary general with the instrument of ratification confirming Switzerland's adoption of the modernised Convention on Data Protection of 1981 (Convention 108). The amending protocol (Convention 108+) is intended to respond to the challenges resulting from the use of new information and communication technologies.
Factsheet on data protection impact assessment
31.08.2023 – With the entry into force of the revised Data Protection Act, there is now an obligation for federal bodies and private individuals to prepare a data protection impact assessment if the planned data processing entails a high risk for the personality or fundamental rights of the data subjects.
Joint statement on data scraping and data protection
24.08.2023 - The Federal Data Protection and Information Commissioner (FDPIC), acting with nine other national data protection authorities, has published a joint statement to social media platform operators on the protection of personal data against data scraping. This is generally understood as the automated extraction of data from the internet.
Factsheet on FDPIC investigations of violations of data protection regulations
18.07.2023 - The factsheet is designed to provide a brief overview of the investigation. It summarises the in-depth interpretations of the FDPIC on Articles 49-53 FADP (see "Untersuchung von Verstössen gegen Datenschutzvorschriften durch den EDÖB").
Third reporting portal online
13.07.2023 - In view of the entry into force of the revised Data Protection Act on 1 September 2023, the FDPIC is completing its reporting portals with the online registration of contact details of Data Protection Officers.
EU-US Data Protection Framework: Adequacy decision of the EU
10.07.2023 - The FDPIC has taken note of the EU-US Data Privacy Framework and the corresponding EU adequacy decision. Switzerland is also engaged in discussions on a parallel framework with the U.S. (Swiss-U.S. Data Privacy Framework), these discussions are well advanced. As of September 1, 2023, it will be the responsibility of the Federal Council to decide on the adequacy of states under the new Swiss data protection legislation. It will be up to the Federal Council to determine whether the U.S. can be added to the list in due course. Until such a framework is finalized, Switzerland's adequacy list will remain unchanged.
FDPIC launches new website
11.05.2023 - The FDPIC has updated the content of its website ahead of the new Data Protection Act coming into force on 1 September 2023. At the same time, it is launching the ‹DataBreach Portal› for reporting security vulnerabilities.
Using emergency legislation to exclude the Freedom of Information Act
06.04.2023 - In the Emergency Ordinance of 16 March 2023 on Additional Liquidity Assistance Loans and the Granting of Federal Default Guarantees for Liquidity Assistance Loans made by the Swiss National Bank to Systemically Important Banks, the Federal Council stipulated, inter alia, that no access to official documents will be granted under the Freedom of Information Act. The exclusion of citizens' rights of access guaranteed by the Freedom of Information Act by way of an emergency ordinance raises fundamental legal issues.
04.04.2023 - Einsatz von ChatGPT und vergleichbaren KI-gestützten Anwendungen
Nach dem Verbot von ChatGPT in Italien rät der EDÖB Nutzerinnen und Nutzern zu einem bewussten Umgang mit KI-gestützten Anwendungen und erinnert Unternehmen an ihre Pflichten.
Federal Administration introduces public cloud-based application Microsoft 365
07.03.2023 - The Microsoft Office 2021 applications that are currently still run locally throughout the Federal Administration are to be replaced by the public cloud-based Microsoft 365 application. The FDPIC will provide supervisory support for the outsourcing project.
Bahnhöfe SBB
15.02.2023 - Die heutigen Medien berichteten über ein Projekt der SBB betreffend Erhebung von Daten in Bahnhöfen, mit denen Personenflüsse optimiert werden sollen.
Data Protection Day 2023 - topics: elections and new data protection legislation in the Confederation and cantons
27.01.2023 - Elections and votes at all federal levels in Switzerland now take place in a digitalised world. Those involved in forming political opinion use the potential of digitalisation to specifically target their campaigns at voters. In this, voters’ rights to privacy and self-determination may come under considerable threat.
2022
Cyber attack on Infopro AG
14.12.2022 - Status of the FDPIC's ongoing preliminary investigation and list of questions for Winbiz
Nutzerdaten von WhatsApp abgegriffen
25.11.2022 - Gemäss News-Meldungen werden rund 550 Mio. Nutzerdaten des Messengerdienstes WhatsApp im Darknet zum Kauf angeboten, davon betroffen seien 1.5 Mio. Schweizer Nutzerinnen und Nutzer.
Zur Fussball-WM nach Katar - EDÖB empfiehlt Reisenden Zweit-Smartphone
18.11.2022 - Katar verlangt von den Gästen der Fussball-WM für die Einreise die Installation der beiden Apps «Ehteraz» und «Hayya to Qatar 2022». Nach Einschätzung des EDÖB weisen beide Applikationen erhebliche datenschutzrechtliche Risiken auf.
Registering a data file - reporting inventories (DataReg)
17.11.2022 - When the new Data Protection Act (FADP) comes into force on 1 September 2023, the procedure for registering data files with the FDPIC will undergo a change. From this date onwards, only federal bodies will have to report their data processing activities to the FDPIC.
European-U.S. Data Privacy Framework (EU-U.S. DPF)
07.10.2022 - The FDPIC has taken note of the factsheet released by the US regarding the «Data Privacy Framework (DPF)» and is analysing it.
Oracle: Tracking technologies encroach on internet users' privacy rights
27.09.2022 - In a lawsuit filed in the US on 19 August 2022 against Oracle America Inc., plaintiffs raise serious allegations of unlawful tracking of internet users.
Credential stuffing: report and guidelines
08.07.2022 - In its latest report, the Global Privacy Assembly identifies credential stuffing as a growing threat to personal data. The related guidelines provide users with information on security measures that can be taken to protect against this threat.
Outsourcing of personal data processing by Suva to a Microsoft cloud service
13.06.2022 - In view of certain differences of legal opinion, the FDPIC is advising Suva to reconsider the decision to outsource its personal data processing to a cloud service operated by the US company Microsoft.
FDPIC meets Tunisian delegation in Bern
12.05.2022 - Der Eidgenössische Datenschutz- und Öffentlichkeitsbeauftragte Adrian Lobsiger traf gestern in Bern seine tunesischen Amtskollegen zu einem Gespräch.
Hackerangriffe auf Arztpraxen in der Romandie
31.03.2022 - Gestern wurde bekannt, dass Hacker mehreren Arztpraxen in der Romandie Patientendossiers entwendet und eine grosse Menge medizinischer Daten im Darknet publiziert haben. Der EDÖB steht mit den fraglichen Praxen in Kontakt und erwartet, dass die betroffenen Patientinnen und Patienten umfassend informiert werden. Der Vorfall ist ein erneuter Hinweis darauf, dass die besonders schützenswerten Gesundheitsdaten in der Schweiz ungenügend geschützt sind.
2021
Update Mitto AG
23.12.2021 - In the preliminary investigation now opened, the FDPIC has contacted Mitto AG and the mobile phone operators in Switzerland.
Mitgliederdaten der Schützenvereine an Kreditkartenanbieter
15.11.2021 - Anfang Mai hat der Schweizer Schiesssportverband (SSV) über 50'000 lizenzierten Schützinnen und Schützen einen neuen Mitgliederausweis mit Kreditkartenfunktion verschickt. In der Folge haben sich zahlreiche Schützinnen und Schützen beim EDÖB mit der Frage gemeldet, ob diese Bekanntgabe zulässig war.
Versand von Impfdaten durch die Stiftung «meineimpfungen»
08.11.2021 - Die Stiftung meineimpfungen hat am Freitag, 04.11.2021 damit begonnen, den Nutzerinnen und Nutzern der Plattform deren Impfdaten als Anhang einer unverschlüsselten E-Mail zukommen zu lassen.
Der EDÖB empfiehlt die Verwendung des Covid-Zertifikats Light
08.09.2021 - Der EDÖB hat die Entwicklung des Covid-Zertifikats begleitet und darauf hingewirkt, dass dieses Zertifikat datenschutzkonform ausgestaltet wurde. Er begrüsst, dass der Nachweis jetzt ausschliesslich durch das Covid-Zertifikat erbracht werden muss und nicht auf beliebig andere Nachweise abgestellt wird.
Schlussbericht des EDÖB in der Sachverhaltsabklärung zu meineimpfungen.ch
07.09.2021 - In der Sachverhaltsabklärung betreffend die Plattform meineimpfungen.ch hat der EDÖB der Stiftung meineimpfungen Ende Juli 2021 seinen Schlussbericht zugestellt. Darin hat er drei Empfehlungen formuliert, die sich insbesondere auf die Datenintegrität und das Schicksal der Daten im Fall einer Einstellung der Plattform beziehen. Die Stiftung hat die Empfehlungen innert der 30-tägigen Frist akzeptiert. Der Schlussbericht wird heute publiziert.
The transfer of personal data to a country with an inadequate level of data protection based on recognised standard contractual clauses and model contracts
27.08.2021 - In its statement of 27 August 2021, the FDPIC recognises the standard contractual clauses for the transfer of personal data to third countries in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (pursuant to Implementing Decision 2021/914/EU) as the basis for personal data transfers to a country without an adequate level of data protection, provided that the necessary adaptations and amendments are made for use under Swiss data protection law.
FDPIC comments on the transfer of data to the United States Securities and Exchange Commission
04.08.2021 –The FDPIC has issued the following memorandum to the US Securities and Exchange Commission (SEC) on the question of the lawfulness of the transfer of data from Swiss asset managers to the US supervisory authority:
EDÖB empfiehlt Verwendung des datenschutzfreundlichen Covid-Zertifikats Light für Veranstaltungen in der Schweiz
19.07.2021 - Mit der neusten Version der «COVID Certificate»-App, kann auf einfache Weise ein datenschutzfreundliches Zertifikat Light generiert werden. Letzteres enthält keine Gesundheitsdaten. Der EDÖB empfiehlt der Bevölkerung, vom Zertifikat Light für Veranstaltungen in der Schweiz Gebrauch zu machen.
13.07.2021 - Neues DSG: Rekrutierung von 5 weiteren Stellen ab Juli 2022
13.07.2021 - Nach dem der Bundesrat dem EDÖB mit Blick auf das im 2. Semester 2022 vorgesehene Inkrafttreten des neuen Bundesgesetzes über den Datenschutz (DSG) im Jahr 2019 die Schaffung von drei, vom EDÖB inzwischen rekrutierten Stellen genehmigte, hat er nun fünf weitere Stellen bewilligt.
Entwicklungen im Verfahren «SocialPass»
22.06.2021 - Nachdem die gemeinsame Rechtsvertretung der Betreiber von SocialPass das Mandat beendet hat, droht sich das hängige Aufsichtsverfahren zeitlich erneut zu verzögern.
Covid certificate dispels major data protection concerns
04.06.2021 - At its press conference today, the Federal Council explained the creation and introduction of the COVID-19 certificate. By offering the option of providing certificates in paper form, and creating an additional minimal data QR code for use in Switzerland, the Federal Council has dispelled key concerns raised by the Federal Data Protection and Information Commissioner (FDPIC).
Datenabflüsse bei Sozialen Netzwerken
13.04.2021 - Nach Facebook ist nun auch LinkedIn Opfer eines massiven Abflusses von Personendaten geworden. Wie die Website Cybernews berichtet, stehen die Daten von 500 Millionen Nutzern des professionellen sozialen Netzwerks auf einem spezialisierten Forum zum Verkauf. Die Daten umfassen Benutzer-IDs, vollständige Namen, E-Mail-Adressen, Telefonnummern, Links zu anderen LinkedIn-Profilen und anderen Profilen in sozialen Medien.
Begleitung des BAG-Projekts für ein datenschutzkonformes Covid-19-Impfzertifikat
13.04.2021 - Der EDÖB wirkt in einer vom BAG eingesetzte Projektgruppe im Hinblick auf die Umsetzung eines Covid-19-Zertifikats auf datenschutzkonforme Ausgestaltung des Nachweises hin. Die Forderungen des EDÖB decken sich im Wesentlichen auch mit der Stellungnahme des Europäischen Datenschutzausschusses und des Europäischen Datenschutzbeauftragten zum Verordnungsentwurf zum «Grünen Pass» der EU.
05.03.2021 - Das neue Datenschutzgesetz aus Sicht des EDÖB
05.03.2021 / aktualisiert am 27.10.2022 - Bis zum Inkrafttreten des neuen DSG werden Privatwirtschaft und Bundesbehörden ihre Bearbeitung von Personendaten an die neuen Bestimmungen anpassen müssen. Der Beauftragte hat hierzu die aus seiner Sicht wesentlichsten Neuerungen festgehalten und publiziert.
Datenschutzrechtliche Anforderungen für die Erhebung von Gesundheitsdaten durch Private im Zusammenhang mit der Pandemiebekämpfung
22.01.2021 - Bei der Bekämpfung der Covid-Pandemie kommen zunehmend digitale Applikationen zum Einsatz, die auf Smartphones installiert werden, auf denen sich meist umfangreiche Spuren der digitalen Lebensführung ihrer Besitzer befinden. So die vom Bund lancierte SwissCovid App oder sogenannte «Tracing Apps», welche von Privaten angeboten werden und das Contact Tracing in den Kantonen erleichtern sollen.
2020
Gästelisten: Betreiber müssen bei der Erfassung der Kontaktdaten Datenschutz sicherstellen
29.10.2020 - Für die Erfassung von Kontaktdaten für das Contact Tracing besteht eine gesetzliche Grundlage. Die Covid-19-Verordnung besondere Lage sieht vor, welche Daten zu welchem Zweck gesammelt werden dürfen. Wie die Erfassung erfolgt, steht den verantwortlichen Betreibern und Organisatoren indes frei. Der Einsatz von Apps ist zulässig, sofern dabei der datenschutzrechtliche Rahmen eingehalten wird.
Breakthrough for up-to-date data protection
25.09.2020 - In its final vote, the Parliament adopted today the total revision of the Federal Act on Data Protection (FADP). It was able to resolve the remaining differences standing in the way of more up-to-date protection of privacy.
Ungenügende Regelung der Datenbearbeitung in neuem Zollpolizeigesetz
11.09.2020 - Unter der Kurzbezeichnung «BAZG-Vollzugsaufgabengesetz» hat der Bundesrat heute die Vernehmlassung über ein Gesetzespaket eröffnet, mit dem er die rechtliche Grundlage für das Digitalisierungs- und Transformationsprogramm (DaziT) der Eidgenössischen Zollverwaltung schaffen will. Dabei handelt es sich um ein finanziell bedeutsames und datenschutzsensibles Grossvorhaben. Die Zollverwaltung und das dort integrierte Grenzwachtkorps sollen in ein neu zu schaffendes Zollpolizeiamt, das «Bundesamt für Zoll und Grenzsicherheit (BAZG)», überführt werden. Dessen gesamte Belegschaft soll mit Polizeibefugnissen und damit zwangsbewehrten Datenbeschaffungskompetenzen ausgestattet werden.
Court of Justice of the European Union (CJEU) ruling on European standard contractual clauses and the EU-US Privacy Shield
16.07.2020 - In its judgment of 16 July 2020 in Case C-311/18 Data Protection Commissioner v. Facebook Ireland Ltd and Maximilian Schrems, the Court of Justice annulled Decision 2016/1250 on the adequacy of the protection provided by the EU-US Privacy Shield. However, the EU Commission Decision 2010/87 on standard contractual clauses for the transfer of personal data to processors established in third countries remains valid.
Update Proximity Tracing App: technical security of the SwissCovid app confirmed
12.06.2020 - After reviewing the NCSC report on Risk Estimation Proximity Tracing published today, the FDPIC has confirmed his assessment that the Swiss proximity tracing system operated by the Federal Office of Public Health and the SwissCovid app are data protection compliant.
Coronavirus protection plans
19.05.2020 - The FDPIC supervises the implementation of the protection plans by private companies. He attaches importance to the fact that the procurement and transfer of personal data within the framework of these plans is voluntary.
Measures for the safe use of audio and video conferencing systems
01.05.2020 - The coronavirus pandemic is showing people all over Switzerland and, indeed, the world how a single event can completely change our surroundings and the way we do things. From one day to the next, it was no longer possible for us to meet friends and family in person, or exchange information with colleagues and hold meetings at our offices. In our work and in our private lives, we have abruptly switched to digital solutions such as audio or video conferencing systems. Despite the rush with which business meetings, children’s ‹visits› with their grandparents, or even parties have been moved online, we must not forget how important information security and data protection continue to be.
Update Proximity Tracing App
30.04.2020 - Data processing in the back end of the «Proximity Tracing-Application (PTAPP)» is proportionate from the perspective of the FDPIC.
Update «Proximity Tracing App»
23.04.2020 - FDPIC examines system architecture and demands proof of sufficient legal basis.
Update Proximity Tracing App
23.04.2020 - FDPIC examines system architecture and demands proof of sufficient legal basis.
Update Libra
20.04.2020 - Libra informs on FINMA's application and intensifies work on the data protection concept.
Évaluation sommaire du projet de « Covid Proximity Tracing App » de l’EPFL
02.04.2020 - L’École polytechnique fédérale de Lausanne (EPFL) a demandé le 21 mars 2020 au PFPDT de soumettre à une évaluation sommaire le projet d’une « Covid Proximity Tracing App » auquel elle participe.
Legal data protection framework for coronavirus containment
17.03.2020 - The authorities, in cooperation with health institutions, are doing everything possible to stem the rapid spread of the coronavirus. Insofar as private individuals (in particular employers) process personal data to combat the pandemic, the principles set out in Article 4 of the Federal Act on Data Protection must be respected.
What impact does Brexit have on cross-border data flows?
31.01.2020 - Following the referendum held in the United Kingdom in June 2016, the British government announced its decision to withdraw from the European Union (Brexit). The United Kingdom will leave the EU on 31 January 2020.
2019
Facebook to introduce special features in Switzerland for the elections
17.10.2019 – On the eve of the federal parliamentary elections on 20 October, Facebook is set to introduce features aimed to appeal to Swiss users of its social media platform. The company confirmed the plans following an enquiry made by the Federal Data Protection and Information Commissioner. The FDPIC welcomes the company’s transparency.
Second chamber concludes consultation on Federal Act on Data Protection Act (FADP)
18.12.2019 - The FDPIC welcomes the fact that the Council of States has debatted the totally revised FADP and has adopted most of the improvements proposed by its Commission in comparison to the National Council version.
The Data Protection Act goes to the Council of States in the winter session
20.11.2019 - The FDPIC welcomes the fact that, within the short time available up to the end of the session, the Political Institutions Committees of the Council of States (PIC-S) has succeeded in adopting a legislative text for the attention of the Plenum of the Council of States that is ready for consultation and significantly improved on the version of the National Council.
Complete Revision of the Federal Act on Data Protection (FADP) goes to the Commission of the Council of States
25.09.2019 – Now that the National Council has treated the complete revision of the Federal Act on Data Protection (FADP) as first chamber of parliament, the FDPIC hopes that the second chamber will be able to schedule the debate in its winter session and improve the protection of the Swiss population by aligning it with European standards.
4th Update concerning the Libra project
19.09.2019 - At a meeting with the FDPIC in Berne, Libra Association reiterates its commitment to develop a consistent data protection standard for the system. The association will involve the FDPIC in its ongoing development work at an early stage in order to comply with data protection requirements from the outset.
Postfinance: no equal treatment for customers under the current law
30.08.2019 - In a letter dated 13 June 2019 in response to an enquiry from the FDPIC, Postfinance AG confirmed that their Swiss customers will still require to register an express objection if they do not wish their identity to be authenticated by voiceprint. In contrast, Postfinance makes authentication by voiceprint for foreign customers subject to their express consent. This unequal treatment, which the FDPIC has publicly criticised, (see the report on SRF’s 10vor10 programme on 20.5.2019) is set to continue.
Draft of new Data Protection Act to be debated in the National Council
30.08.2019 - Following its discussion of the Federal Council dispatch of 15 September 2017, the National Council’s political institutions committee decided on 16 August 2019 based on the casting vote of its president to remit the draft of the totally revised Data Protection Act to the plenary session of the National Council for debate.
3rd Update concerning the Libra project
23.08.2019 -The Libra Association sent the first part of the requested documents to the FDPIC on time. Further documents and explanatory information will follow in the coming weeks.
2nd Update concerning the Libra project
06./08.08.2019 - The British and other data protection authorities have published a joint statement demanding more openness from Libra promoters about the project. The FDPIC stays in contact with the European Data Protection Board (EDPB) and the International Conference of Data Protection and Privacy Commissioners (ICDPPC).
1st Update concerning the Libra project
29.07.2019 - Die Libra Association hat auf das Schreiben des EDÖB vom 17. Juli 2019 reagiert und eine zeitnahe Antwort in Aussicht gestellt. Sie wird sich in den kommenden Wochen mit dem EDÖB zu Gesprächen treffen. Der EDÖB wird die Öffentlichkeit über das weitere Vorgehen informieren, sobald er die in Aussicht gestellten Informationen analysiert und sich zum aktuellen Stand des Projekts einen Überblick verschafft haben wird.
26th Annual Report: Switzerland must maintain its level of data protection
18.06.2019 - The FDPIC expects that the Federal Council and Parliament will continue to guarantee the Swiss population a level of data protection that is in line with its European neighbours by signing the Council of Europe Convention 108 in the near future and swiftly bringing to a close the complete revision of the Data Protection Act.
26th Annual Report: Switzerland must maintain its level of data protection
15.05.2019 - Nach ungenutztem Ablauf der Rechtsfrist kann der Bundesverwaltungsgerichtsentscheid vom 19. März 2019 in Sachen Helsana+ in Kraft treten. Das Bundesverwaltungsgericht hat wichtige Rechtsfragen geklärt, deren Umsetzung der EDÖB bei der Helsana überprüfen wird.
Data Protection Day 2019 - 3 priorities for the Confederation and cantons: elections, police, OASI number
28.01.2019 - Federal and cantonal data protection authorities' press release:

