Data Protection Act (FADP)
English is not an official language of the Swiss Confederation. This translation is provided for information purposes only and has no legal force.
Art. 19 Duty to provide information when collecting personal data
1 The controller shall inform the data subject in an appropriate manner when collecting personal data; this duty to provide information also applies if the data is not collected from the data subject. 2 It shall provide the data subject on collecting the data with the information required for the data subject to exercise their rights under this Act and to guarantee transparent data processing; it shall provide the following information as a minimum: a. the controller's identity and contact details; b. the purpose of processing; c. if applicable, the recipients or the categories of recipients to which personal data is disclosed. 3 If the data is not collected from the data subject, the controller shall also inform the data subject of the categories of processed personal data. 4 If the personal data are disclosed abroad, the controller shall also inform the data subject of the State or the international body to which such data are disclosed and if applicable of the guarantees under Artic
Art. 20 Exceptions from the duty to provide information and restrictions
1 The duty to provide information under Article 19 ceases to apply if one of the following requirements is satisfied: a. The data subject already has the information concerned. b. The processing is required by law. c. The controller is a private person who is required by law to preserve confidentiality. d. The requirements of Article 27 are satisfied. 2 If the personal data is not collected from the data subject, the duty to provide information also ceases to apply if any one of the following requirements is satisfied: a. It is not possible to provide the information. b. Providing the information requires disproportionate effort. 3 The controller may restrict, delay or dispense with the communication of the information in the following cases: a. It is required to do so because of overriding third party interests. b. Providing the information defeats the purpose of the processing. c. The controller is a private person and the following requirements are satisfied: 1. The controller is re
Art. 21 Duty to provide information in the case of an automated individual decision
1 The controller shall inform the data subject about any decision that is based exclusively on automated processing and that has a legal consequence for or a considerable adverse effect on the data subject (automated individual decision). 2 It shall on request allow the data subject to express their point of view. The data subject may request that the automated individual decision be reviewed by a natural person. 3 Paragraphs 1 and 2 do not apply if: a. the automated individual decision is directly connected with the conclusion or the processing of a contract between the controller and the data subject and the data subject's request is granted; or b. the data subject has explicitly consented to the decision being automated. 4 If the automated individual decision is issued by a federal body, it must designate the decision accordingly. Paragraph 2 does not apply if, in accordance with Article 30 paragraph 2 of the Administrative Procedure Act of 20 December 1968 (APA) or another federal
Para. 4 — SR 172.021
Art. 22 Data protection impact assessment
1 If processing is likely to result in a high risk to the data subject's personality or fundamental rights, the controller shall carry out a data protection impact assessment beforehand. If several similar processing procedures are planned, a joint assessment may be carried out. 2 The existence of a high risk, in particular when using new technologies, depends on the nature, extent, circumstances and purpose of the processing. A high risk arises in particular: a. in the case of the large-scale processing of sensitive personal data; b. if public areas are systematically monitored on a large scale. 3 The data protection impact assessment shall include a description of the planned processing, an evaluation of the risks to the data subject's personality or fundamental rights and a description of the measures to protect personality and fundamental rights. 4 Private controllers are exempt from having to carry out a data protection impact assessment if they are required by law to process the
Art. 23 Consultation of the FDPIC
1 If the data protection impact assessment indicates that the planned processing despite the measures planned by the controller will still pose a high risk to the personality or the data subject's fundamental rights, the controller shall seek the FDPIC's opinion beforehand. 2 The FDPIC shall inform the controller within two months of any objections to the planned processing. This deadline may be extended by one month if the data processing is complex. 3 If the FDPIC objects to the planned processing, he or she shall propose suitable measures to the controller. 4 A private controller may dispense with consulting the FDPIC if it has consulted the data protection officer under Article 10.
Art. 24 Notifications of data security breaches
1 The controller shall notify the FDPIC of any breach of data security that is likely to lead to a high risk to the data subject's personality or fundamental rights as quickly as possible. 2 In the notification, it shall as a minimum specify the nature of the breach of data security, its consequences and the measures taken or planned. 3 The processor shall notify the controller of any breach of data security as quickly as possible. 4 The controller shall inform the data subject if this is required for their protection or if the FDPIC so requests. 5 It may limit, delay or dispense with the provision of information to the data subject if: a. there is a reason for doing so pursuant to Article 26 paragraph 1 letter b or paragraph 2 letter b or the provision of information is prohibited by a statutory duty of confidentiality; b. the provision of information is impossible or requires disproportionate effort; or c. the provision of information to the data subject is equally guaranteed by maki
Para. 5bis — Inserted by No II 2 of the FA of 29 Sept. 2023 (Introduction of a Reporting Obligation for Cyberattacks on Critical Infrastructure), in force since 1 April 2025 (AS 2024 257; 2025 168, 173; BBl 2023 84).
