Law note · Switzerland

FADP Article 24, Breach Notification in Switzerland

cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 24 stage In effect since 2023-09-01 reviewed 2026-08-24

A controller must notify the FDPIC as soon as possible once aware of a data security breach likely to result in a high risk to the data subject's personality or fundamental rights. Unlike General Data Protection Regulation (GDPR) there is no fixed statutory clock: commentary treats 72 hours as a practical benchmark drawn from the Federal Council's explanatory message, not a binding deadline.

Notification to the data subject is required only where necessary to protect them, or if the FDPIC orders it; the controller may limit, defer, or omit subject notification if it is impossible, disproportionate, or superseded by a public communication of comparable effect.

What it asks of an app

  • Notify the FDPIC as soon as possible once you become aware of a data security breach likely to result in a high risk to a Swiss data subject's personality or fundamental rights.
  • Notify the affected individual only where necessary to protect them or where the FDPIC orders it; there is no fixed statutory hour count as there is under General Data Protection Regulation (GDPR).

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: Fedlex, the Swiss Federal Council's official legislation portal

← Back to the example  ·  Lint your app →