Skip to Content

The Swiss Data Protection Act in practice: lessons from the first interventions by the FDPIC

Access rights, opposition to marketing, deletion, cookies, and security breaches: what the first decisions of the FDPIC change for SMEs.
July 3, 2026 by
JBP
| No comments yet

Since September 1st 2023, the new Federal Act on Data Protection (FADP) has given the Federal Data Protection and Information Commissioner (FDPIC) more direct oversight powers. The first published decisions and the 2025/2026 activity report now show how this authority uses them.

The message for an SME is not that it needs to produce a 180-page compliance binder. It is more down to earth: an access right must lead to a real response, an unsubscribe must actually stop marketing, a promised deletion must be executed in all systems, and a security breach must be assessed without delay.

In other words, the FDPIC is less concerned with nice statements than with the actual functioning of processes. And, in this regard, a simple customer email left unanswered can become the starting point of a formal investigation.

In short

  • An investigation is no longer reserved for breaches affecting a large number of people: a significant violation concerning just one person may be sufficient.
  • A standardized response to a request for access does not replace the communication of personal data actually processed; the response generally occurs within 30 days.
  • An objection to marketing or a request for deletion must be applied in operational tools, not just confirmed by email.
  • The FDPIC often favors a quick and informal correction, but can make binding decisions, order the cessation of processing, or the deletion of data.
  • The FDPIC does not impose administrative fines comparable to those of the GDPR; the criminal offenses provided for by the FADP fall under the jurisdiction of the cantonal authorities.

What has changed in supervisory practice

Under the old law, the FDPIC's actions against private companies generally resulted in recommendations. The revised FADP allows it to open a formal administrative procedure when there are sufficient indications of a violation and, if confirmed, to order, in particular, the modification, suspension, or cessation of processing, as well as the deletion or destruction of data.

The threshold for intervention has also changed. It is no longer necessary for the processing to be likely to harm a significant number of people. According to the FDPIC's memo, a violation of sufficient intensity can justify an investigation even if it only affects one person or a small number of people.

The figures published on June 30, 2026, confirm the strengthening of the system. The FDPIC reports more than 2,000 reports of potential violations during the year under review, 156 low-threshold interventions, 22 preliminary investigations, and 9 formal investigations. It also received 484 reports of data security violations.

Useful clarification:  the FDPIC is responsible for processing carried out by private companies and federal bodies. The processing by cantonal or municipal authorities is generally under the jurisdiction of the cantonal data protection authorities.

Six concrete lessons for SMEs

1. A request for access requires the data, not a polite formula

In the case of Cembra Money Bank AG, the FDPIC examined 13 access requests processed between December 2023 and September 2024. Nine responses were sent after the legal deadline of 30 days had expired. Most importantly, all individuals received a standardized response that did not communicate the personal data actually processed about them.

The lesson extends far beyond the banking sector. An SME must be able to identify the person, search for the data in its applications, messaging, CRM, HR files, and, if applicable, with its subcontractors. It must then provide the information required by the FADP and the relevant data in an understandable form. A data protection statement or a phrase such as "we process your data in accordance with the law" is not an access response.

2. Objection and deletion must traverse all systems

The decision published on June 26, 2026, against Cream della Cream Switzerland GmbH and Philipp Plein International AG is particularly telling. Several people had continued to receive advertising messages after opposing them. In some cases, the companies had even confirmed the deletion of the data before continuing the sends.

The FDPIC initially intervened informally. Failing correction, it opened a formal investigation and ordered to cease advertising processing in case of opposition, to delete the data upon request unless justified, and to no longer use the data of individuals who had already exercised these rights. The decision, which came into force, also imposed a fee of CHF 5,500 on the companies. It was not a fine, but the nuance does not make the bill decorative.

In practice, an unsubscribe link must work, the opposition status must be propagated to the CRM, to the sending tool, and to the re-imported lists, and manual requests must be followed up until their execution. A legal obligation to retain may justify keeping certain data, such as accounting documents, but it does not allow for continued use for advertising purposes.

3. Publicly available data is still subject to rules

In the so-called "Pfarrer-Check" case, an association had published data concerning priests, pastors, and other individuals active in the ecclesiastical field. The FDPIC ordered the deletion of the registrations of individuals who had not consented to this publication. The Federal Administrative Court confirmed the decision on October 6, 2025.

Reasoning is important for directories, prospecting, recruitment, and profiling: the fact that a professional address, a position, or other information is accessible on the internet does not allow it to be reused for any purpose. Transparency, proportionality, purpose, and the rights of the individual remain applicable.

4. The choice must be real and technically simple

In the Digitec Galaxus case, examined still under the old law, the FDPIC criticized the coupling of the ordering process to the creation of a customer account and the resulting data processing. The company then introduced a global option to disable site personalization with one click; the corresponding cookies are then disabled, the registration form explicitly informs about personalization, and the privacy statement has been adapted.

This case does not mean that every cookie automatically requires consent according to the European model. It shows, however, that the interface, information, and effectiveness of the choice matter. A right to object hidden in five screens or a button that does not actually change the processing will not withstand scrutiny.

5. An incident at the service provider is also your problem

According to Art. 24 FADP, the data controller must notify the FDPIC, as soon as possible, of a data security breach that is likely to result in a high risk to the personality or fundamental rights of the affected individuals. The subcontractor must inform the controller as soon as possible.

The 2025/2026 report notes 484 announcements, including 141 spontaneous announcements, and an increase in provisional notifications. When the facts and the level of risk are not yet fully known, an initial notification can therefore be supplemented after analysis. On the other hand, the fact that a host, a payroll provider, or an IT service provider caused the incident does not automatically transfer the obligation of the responsible party to announce to the provider.

6. Ignoring authority often turns a correctable issue into a procedure

The FDPIC indicates that an informal intervention may be sufficient when a company responds, explains its practice, and quickly corrects the processing. In contrast, a formal investigation entails an obligation to cooperate and produce the necessary information and documents, subject to the rights of refusal provided by law.

The report thus relates an investigation still pending as of March 31, 2026, in which the FDPIC issued an interim decision ordering cooperation and filed a criminal complaint after several letters went unanswered. The substantive facts had not yet been resolved by the date of the report; the procedural lesson, however, is clear: silence is not a defense strategy, it is rather an expensive way to let the authority write the scenario alone.

Update of September 2, 2026

On August 20, 2026, the FDPIC announced that the Federal Administrative Court had fully rejected, by ruling of June 22, 2026, the appeal of Inkasso-Team AG. The online publication of data of presumed debtors in order to locate them and warn third parties was deemed contrary to personality rights and lacking sufficient justification. The ruling has come into effect and the concerned site has been removed. This development, made public after the editorial date of this article, confirms that the binding decisions of the FDPIC can withstand judicial review.

The reasonable action plan for an SME

Useful compliance does not start with a theoretical document, but with some operational tests. An SME can engage the following controls:

  1. Designate an internal responsible person and a single channel. Access requests, objections, corrections, and deletions should not get lost between the info@ address, sales, and IT.
  2. Create a request tracking register. Date of receipt, verified identity, systems consulted, responsible person, deadline, response, and proof of sending must be documented.
  3. Test a real end-to-end case. Simulate an access request and check if the data can be retrieved within 30 days, including in cloud tools and from subcontractors.
  4. Test unsubscriptions and deletions. A marketing opt-out address must not reappear during the next contact import. Requests confirmed as executed must be so in all relevant environments.
  5. Control the site and interfaces. Understandable information, non-deceptive choices, effective cookie settings, proportionate account creation, and accessible opposition must be technically verified.
  6. Prepare incident management. The contract with each critical subcontractor must provide for prompt information, contact persons, and the transmission of elements necessary for risk assessment.
  7. Keep useful evidence. Version of notices, consent or opposition logs, deletion tickets, risk analysis, and internal decisions are more convincing than a reconstruction afterward.

For the use of artificial intelligence tools, the same reflexes apply: limit data, choose an appropriate contractual environment, and maintain documented control over flows. Our article on generative AI and data protection in Swiss SMEs details this point.

The opposing viewpoint: "the FDPIC is not the CNIL"

That is correct: the Swiss system does not replicate the administrative fines of the GDPR. The FDPIC can investigate and order administrative measures, but it does not itself impose the criminal sanctions of the FADP. The prosecution and judgment of these offenses belong to the cantonal authorities, and criminal responsibility primarily targets individuals who acted intentionally.

However, it would be unwise to conclude that the exposure is negligible. A decision may impose the cessation of a treatment, the deletion of a database, or the modification of a central process. It may be published if the public interest justifies it, generate fees and consulting costs, and then be contested in court. The operational and reputational risk may therefore far exceed the amount of any potential sanction.

What to do if you receive a letter from the FDPIC?

  1. Verify the authenticity of the message through an official channel. The FDPIC reported in April 2026 fraudulent emails sent in its name to website operators.
  2. Keep relevant data, logs, and document versions; do not hastily delete elements necessary for establishing the facts.
  3. Determine whether it is an informal intervention, a preliminary investigation, or a formal investigation: the procedural obligations are not the same.
  4. Respond factually, within the indicated timeframe, distinguishing established facts, points to verify, and corrective measures already taken.
  5. Have the legal and technical issues examined when the treatment is sensitive, massive, contested, or likely to have a lasting impact on the activity.

Caution: cooperating does not mean waiving your rights. In a formal investigation, the company has the right to be heard, to consult the file, and to provide evidence. It can also contest a decision before the Federal Administrative Court. However, a defensible position must be based on documented facts and a specific justification, not on the general idea that "everyone does the same."

How Delta Conseil SA can assist you

Delta Conseil SA can help a small business map its main processes, organize the reception of requests, test access and deletion processes, review marketing circuits, and formalize an incident management procedure. When the case requires specialized legal analysis, cybersecurity expertise, or the conduct of contentious proceedings, we coordinate the intervention of the appropriate specialist.

Do you want to check if your processes are really working before a client — or the FDPIC — tests them for you?

Talk to an advisor

Frequently asked questions

Does the FDPIC investigate after every complaint?

No. It checks if there is sufficient evidence of a violation. It may refrain when it is of little importance and often favors informal intervention. In contrast, a significant violation may justify an investigation even if it only affects one person.

Does a small business have to respond to a request for access within 30 days?

In principle, yes. If the information cannot be provided within this timeframe, the person must be informed and given an indication of the timeframe in which the response will occur. Internal complexity or data dispersion does not allow leaving the request without follow-up.

Does a request for deletion require deleting all traces of the client?

Not necessarily. Some data must be retained due to a legal obligation or a justifiable reason, such as accounting documents. However, they must no longer be used for an incompatible purpose, such as marketing after opposition.

Does consent solve all problems?

No. It must be free, informed, and linked to a sufficiently determined processing when invoked. It does not correct either disproportionate collection, misleading devices, or insufficient security. Depending on the processing, another justifying reason may be relevant, but it must be identified and documented.

Can the FDPIC impose a fine of CHF 250,000 on the company?

The FDPIC does not itself impose administrative fines. The FADP provides for criminal offenses pursued by the cantonal authorities and aimed primarily at the responsible natural persons in cases of intentional behavior. The maximum amount does not automatically apply to every non-compliance.

Official sources

Last legal check: September 2, 2026.

Warning

This publication is provided for informational purposes only and does not constitute individualized legal, tax, accounting, or financial advice. The situation must be assessed in light of the specific circumstances and the applicable law at the time of the decision.

For more information, please see our Legal notices and disclaimer.

Sign in to leave a comment