Skip to content

Swiss Chinese Law Association — Geneva

SCLA | Swiss Chinese Law Association

Legal Observatory / AI and Data

Explained Switzerland Rules in force

Swiss FDPIC Outlines Online Reporting Portals for Data Breaches, Registers, DPO Notifications, and Complaints

The Swiss FDPIC provides online portals for data breach reports, DPO notifications, registers of processing activities, and data protection complaints under the revised FADP.

What Changed

  • Data controllers can securely submit breach reports online and download confirmation documents containing submitted data.
  • Federal bodies remain obligated under Art. 12 FADP to report registers of processing activities, while private individuals have been exempt since 1 September 2023.
  • DPO notifications are submitted under Art. 10 para. 3 FADP for private persons and Art. 10 para. 4 FADP for federal bodies, with specific guidance not to send ID copies for complaints unless requested.

The Federal Data Protection and Information Commissioner (FDPIC) of Switzerland maintains dedicated digital reporting portals for data controllers, federal bodies, private persons, and members of the public. These online reporting mechanisms facilitate compliance with the Swiss Federal Act on Data Protection (FADP) across multiple administrative and regulatory categories, including data breach reporting, the registration of processing activities, data protection officer (DPO) notifications, and personal data violation complaints.

Following the entry into force of the revised Federal Act on Data Protection (FADP) on 1 September 2023, specific obligations regarding reporting and registration underwent explicit procedural definitions. The FDPIC digital portals serve as secure, standardized administrative channels allowing data controllers and federal entities to fulfill statutory duties under Swiss federal data protection legislation, while simultaneously providing members of the public a structured channel to report observed personal data violations.

Rules and Obligations by Reporting Portal

1. DataBreach Reporting Portal

Under the mechanisms established by the FDPIC, data controllers have access to an online reporting form designed to submit data breach notifications digitally and securely. Upon completing and submitting a data breach report through this secure electronic channel, the data controller is provided with the immediate option to download an official confirmation document containing the exact data submitted during the reporting process.

2. DataReg – Report of Processing Activities (Article 12 FADP)

The DataReg portal addresses the reporting requirements related to entries from the register of processing activities pursuant to Article 12 of the Federal Act on Data Protection (FADP). The operational scope of this requirement applies specifically to federal bodies:

- Federal bodies are statutory entities legally obliged under Article 12 FADP to report entries from their register of processing activities directly to the FDPIC.

- Private individuals are explicitly exempted from this reporting obligation. This exemption took effect when the revised Federal Act on Data Protection (FADP) officially came into force on 1 September 2023.

3. Notification of Data Protection Officers (Art. 10 FADP)

The FDPIC portal accommodates notifications regarding designated Data Protection Officers (DPOs) in accordance with the specific statutory provisions of the FADP:

- Notifications for private persons are conducted pursuant to Article 10 paragraph 3 FADP.

- Notifications for federal bodies are conducted pursuant to Article 10 paragraph 4 FADP.

4. Submitting Complaints and Reporting Data Protection Violations

For individuals or entities wishing to report a potential violation of personal data protection for which they themselves are not responsible, the FDPIC provides a dedicated complaints submission form. When utilizing this reporting channel:

- Complainants are instructed to evaluate and check their personal situation prior to submission to ascertain how the FDPIC can intervene within its statutory regulatory scope.

- Individuals submitting requests for information or complaints must not send a copy of their identification document (ID) with the initial submission. If formal identity verification is determined to be necessary, the FDPIC will contact the submitting party directly to request identity verification.

Practical Implications for Affected Parties

The statutory structure outlined across the FDPIC reporting portals dictates distinct actions for different classes of legal and natural persons operating under Swiss federal jurisdiction:

- Federal Bodies: Must systematically report entries from their register of processing activities to the FDPIC pursuant to Article 12 FADP. Additionally, federal bodies must formally notify the FDPIC of their designated Data Protection Officer pursuant to Article 10 paragraph 4 FADP.

- Private Persons and Individuals: Private individuals benefit from an explicit exemption from reporting entries from the register of processing activities to the FDPIC, which became effective with the entry into force of the revised FADP on 1 September 2023. However, private persons who appoint a Data Protection Officer must notify the FDPIC pursuant to Article 10 paragraph 3 FADP.

- Data Controllers: Any data controller experiencing a personal data breach can submit reports via the FDPIC's digital online form to ensure secure transmission and obtain downloadable confirmation records containing submitted details.

- Members of the Public: Individuals who observe data protection violations for which they are not responsible can lodge complaints via the online form, ensuring they do not enclose ID copies unless specifically requested by the authority.

Frequently Asked Questions

Q1: Are private individuals required to report their register of processing activities to the FDPIC?

A1: No. Private individuals were explicitly exempted from the obligation to report entries from the register of processing activities to the FDPIC when the revised Data Protection Act (FADP) came into force on 1 September 2023. This reporting duty under Article 12 FADP applies to federal bodies.

Q2: What statutory provisions govern the notification of Data Protection Officers (DPOs) to the FDPIC?

A2: Data Protection Officers must be notified to the FDPIC pursuant to Article 10 paragraph 3 FADP for private persons, and pursuant to Article 10 paragraph 4 FADP for federal bodies.

Q3: Should individuals enclose a copy of their identity document (ID) when filing a complaint or information request with the FDPIC?

A3: No. Individuals should not send a copy of their ID when submitting a request for information or a complaint. If identity verification is required, the FDPIC will contact the individual directly.

Q4: What confirmation is provided to a data controller after submitting a data breach report online?

A4: After submitting a report through the online form provided by the FDPIC, the data controller can download a confirmation containing the submitted data.

Who May Be Affected

Data controllers, federal bodies in Switzerland, private persons, Data Protection Officers, and individuals submitting data protection complaints or requests.

Cross-Border Context

Applies within Switzerland under federal law (FADP); relevant to foreign entities or controllers subject to Swiss federal data protection rules.

What to check next

  • Check specific procedures on FDPIC reporting forms before submitting breach reports or DPO notifications.
  • Verify applicable requirements under Art. 10 and Art. 12 FADP for organizational compliance.

This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.

Prepared automatically with AI assistance from the official sources linked on this page. Translations and explanations do not replace the official text.

Keep the issues that matter to you in view

Subscribe to SCLA updates and choose your interests.