Law note · Switzerland
FADP Article 24, Breach Notification in Switzerland
A controller must notify the FDPIC as soon as possible once aware of a data security breach likely to result in a high risk to the data subject's personality or fundamental rights. Unlike General Data Protection Regulation (GDPR) there is no fixed statutory clock: commentary treats 72 hours as a practical benchmark drawn from the Federal Council's explanatory message, not a binding deadline.
Notification to the data subject is required only where necessary to protect them, or if the FDPIC orders it; the controller may limit, defer, or omit subject notification if it is impossible, disproportionate, or superseded by a public communication of comparable effect.
What it asks of an app
- Notify the FDPIC as soon as possible once you become aware of a data security breach likely to result in a high risk to a Swiss data subject's personality or fundamental rights.
- Notify the affected individual only where necessary to protect them or where the FDPIC orders it; there is no fixed statutory hour count as there is under General Data Protection Regulation (GDPR).
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics
Primary source: Fedlex, the Swiss Federal Council's official legislation portal