Data Protection Ordinance (DPO)
English is not an official language of the Swiss Confederation. This translation is provided for information purposes only and has no legal force.
Section 1 Data Security
Art. 1 Principles
1 In order to guarantee an adequate level of data security, the controller and the processor must determine the extent to which personal data requires to be protected and adopt the technical and organisational measures that are appropriate to the risk. 2 The extent to which personal data requires to be protected shall be assessed according to the following criteria: a. the type of the data being processed; b. the purpose, nature, extent and circumstances of the processing. 3 The risk for the personality or fundamental rights of the data subject shall be assessed according to the following criteria: a. the causes of the risk; b. the main threats; c. measures taken or planned to reduce the risk; d. the probability and seriousness of a breach of data security despite the measures taken or planned. 4 When determining the technical and organisational measures, the following criteria shall also be considered: a. the state of the art; b. the implementation costs. 5 The extent to which persona
Art. 2 Goals
The controller and the processor must take technical and organisational measures in order to ensure, depending on the level of protection required, that the data being processed: a. are only accessible to authorised persons (confidentiality); b. are available when they are required (availability); c. are not altered without authorisation or unintentionally (integrity); d. are processed in a traceable manner (traceability).
Art. 3 Technical and organisational measures
1 In order to guarantee confidentiality, the controller and the processor must take appropriate measures to ensure that: a. authorised persons only have access to those personal data that they require to fulfil their tasks (data access control); b. only authorised persons have access to the premises and facilities in which personal data are processed (premises and facilities access control); c. unauthorised persons are unable to use automated data processing systems by means of data transmission devices (user control). 2 In order to guarantee availability and integrity, the controller and the processor must take appropriate measures to ensure that: a. unauthorised persons are unable to read, copy, alter, move, delete or destroy data carriers (data carrier control); b. unauthorised persons are unable to save, read, alter, delete or destroy stored personal data (storage control); c. unauthorised persons are unable to read, copy, alter, delete or destroy personal data in the event of the
Art. 4 Logging
1 If a large volume of sensitive personal data is processed by automated means or if high-risk profiling is carried out and if preventive measures are unable to guarantee data protection, the private controller and its private processor must as a minimum / log the storage, alteration, disclosure, deletion and destruction of the data and any access to the data. A log file must in particular be kept if otherwise it would not be possible to establish whether the data has been processed for the purposes for which it was collected or disclosed. 2 The responsible federal body and its processor shall when carrying out automated processing of sensitive personal data, profiling and automated processing that falls within the scope of Directive (EU) 2016/680, log as a minimum the storage, alteration, disclosure, deletion and destruction of the data, as well as any access to the data. For other forms of automated data processing, they shall assess in advance the risk to the fundamental rights of t
Para. 1 — Amended by No I of the O of 29 Oct. 2025, in force since 1 Dec. 2025 (AS 2025 694). Para. 2 — Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Fr
Art. 5 Processing regulations for private persons
1 The private controller and its private processor must issue regulations on automated processing if they: a. process a large volume of sensitive personal data; or b. carry out high-risk profiling. 2 The regulations must in particular include details of the internal organisational structure, data processing and control procedures and the measures that guarantee data security. 3 The private controller and its private processor must update the regulations regularly. If a data protection officer has been appointed, the regulations must be made available to the officer.
Art. 6 Processing regulations for federal bodies
1 The responsible federal body and its processor must issue processing regulations for automated processing if they: a. process sensitive personal data; b. carry out profiling; c. process personal data in accordance with Article 34 paragraph 2 letter c FADP; d. allow cantons, foreign authorities, international organisations or private persons access to personal data; e. link data collections with each other; or f. operate an information system or manage data collections with other federal authorities. 2 The regulations must in particular include details of the internal organisational structure, data processing and control procedures, and the measures that guarantee data security. 3 The responsible federal body and its processor must update the regulations regularly and make them available to the data protection officer.
Section 2 Processing by Processors
Art. 7
1 The prior approval from the controller that allows the processor to assign the data processing to a third party may be specific or general in its scope. 2 In the case of general approval, the processor shall inform the controller of any plan to engage additional or replace existing third parties. The controller may object to such changes.
Section 3 Disclosure of Personal Data Abroad
Art. 8 Assessing the adequacy of the data protection offered by a State, territory, specified sector in a State, or international body
1 The States, territories, specified sectors in a State and international bodies that guarantee an adequate level of data protection are listed in Annex 1. 2 When assessing whether a State, a territory, a specified sector in a State or an international body guarantees an adequate level of data protection, the following criteria in particular shall be considered: a. the international obligations of the State or international body, in particular in relation to data protection; b. whether it respects the rule of law and human rights; c. the legislation applicable, in particular to data protection, its implementation and the relevant case law; d. that data subjects’ rights and redress are effectively guaranteed; e. the effective functioning of one or more independent authorities in the State concerned that are responsible for data protection or to which an international body is accountable and that have sufficient powers and responsibilities. 3 The FDPIC shall be consulted in the course of
Para. 3 — Amended by No I of the O of 29 Oct. 2025, in force since 1 Dec. 2025 (AS 2025 694).
Art. 9 Data protection clauses and specific guarantees
1 The data protection clauses in an agreement under Article 16 paragraph 2 letter b FADP and the specific guarantees under Article 16 paragraph 2 letter c FADP must include at least the following points: a. the requirement to apply the principles of legality, good faith, proportionality, transparency, purpose limitation and accuracy; b. the categories of personal data disclosed and of data subjects; c. the manner and purpose of the disclosure of personal data; d. if applicable, the names of the countries or international organisations, in which personal data is to be disclosed and the requirements for disclosure; e. the requirements for safeguarding, deleting and destroying personal data; f. the recipients or the categories of recipients; g. the measures to guarantee data security; h. the requirement to report breaches of data security; i. if the recipients are controllers: the requirement to inform the data subjects about the processing; j. the rights of data subjects, and in particul
Art. 10 Standard data protection clauses
1 If the controller or the processor discloses personal data abroad based on standard data protection clauses in accordance with Article 16 paragraph 2 letter d FADP, it shall take appropriate measures to ensure that the recipient complies therewith. 2 The FDPIC shall publish a list of standard data protection clauses that it has approved, issued or recognised. It shall give notice of the result of its assessment of standard data protection clauses that it has been submitted within 90 days.
Art. 11 Binding corporate rules
1 Binding corporate rules in accordance with Article 16 paragraph 2 letter e FADP apply to all undertakings that belong to the same group of undertakings. 2 They shall include as a minimum the points mentioned in Article 9 paragraph 1 as well as the following information: a. details of the organisational structure and the contact details for the group of undertakings and its members; b. details of the measures taken within the group of undertakings to comply with the binding corporate rules. 3 The FDPIC shall give notice of the result of its assessment of the binding corporate rules that it has been submitted within 90 days.
Art. 12 Code of conduct and certification
1 Personal data may be disclosed abroad if a code of conduct or certification guarantees an appropriate level of data protection. 2 The code of conduct must be submitted beforehand to the FDPIC for approval. 3 The code of conduct or certification must be combined with a binding and enforceable obligation for the controller or the processor in the third State to apply the measures contained therein.
