The FAC dis­missed an appeal against a ruling by the FDPIC and con­firm­ed the order to inform the data sub­jects (judgment A‑3790/2024 dated April 8, 2026). Howe­ver, it shar­ply cri­ti­ci­zes the FDPIC’s con­duct of pro­ce­e­dings by Serious vio­la­ti­ons of the right to be heard or vio­la­ti­on of the offi­ci­al duty to sta­te rea­sons recognizes.

The mat­ter con­cer­ned the Obli­ga­ti­on to inform the data sub­jects about a data breach (the Blick has repor­ted):

  • Sky­Sa­le Switz­er­land (repre­sen­ted here by att­or­ney Mar­tin Stei­ger) ope­ra­tes the online store apfelkiste.ch. Apfel­ki­ste uses cus­to­mer-spe­ci­fic URLs with an unguessa­ble hash value to pro­cess sup­port cases (appar­ent­ly becau­se Apfel­ki­ste allo­ws guest orders).
  • The­se URLs ended up in the index of search engi­nes, espe­ci­al­ly Bing. This expo­sed cont­act details, com­mu­ni­ca­ti­on con­tent, bank details (IBAN) and other data. At least 19,000 cases were affec­ted over a peri­od of around 8 months.
  • Fol­lo­wing a tip-off from a third par­ty, Apfel­ki­ste repor­ted the inci­dent to the FDPIC and took mea­su­res, inclu­ding blocking the Bing craw­ler and redi­rec­ting the affec­ted URLs to ano­ther landing page.

Apfel­ki­ste had refrai­ned from informing tho­se affec­ted. After an inve­sti­ga­ti­on, the FDPIC orders the infor­ma­ti­on of the per­sons con­cer­ned. Howe­ver, becau­se he had also com­men­ted on excep­ti­ons and the public announce­ment in the ruling, it remain­ed unclear what was spe­ci­fi­cal­ly requi­red of Apfel­ki­ste. Nevert­hel­ess, the FAC dis­missed Apfelkiste’s appeal, albeit with an obvious stomachache.

Order to inform the per­sons concerned

After cor­re­spon­ding cor­re­spon­dence with the FDPIC, Apfel­ki­ste did not inform the cus­to­mers con­cer­ned, whereu­pon the FDPIC orde­red such information:

[…] Sky­Sa­le Schweiz GmbH infor­med the FDPIC that it did not con­sider it neces­sa­ry to inform the per­sons con­cer­ned. The mea­su­res it had taken were effec­ti­ve. It was it is not clear what addi­tio­nal mea­su­res would be available to the per­sons con­cer­ned to redu­ce the risks […] over and abo­ve the mea­su­res it has taken its­elf. In addi­ti­on, informing the per­sons con­cer­ned is not pos­si­ble or can only be imple­men­ted with dis­pro­por­tio­na­te effort.

The FAC repro­du­ces the dis­po­si­ti­ve of the order as follows:

In a ruling dated May 28, 2024, the FDPIC obli­ged Sky­Sa­le Schweiz GmbH to inform the per­sons affec­ted by the […] data secu­ri­ty breach within 10 days of the ruling taking legal effect (point 1). The FDPIC poin­ted out that the type and con­tent of the infor­ma­ti­on must com­ply with the requi­re­ments of data pro­tec­tion legis­la­ti­on (para­graph 2). In addi­ti­on, the natu­ral per­sons […] respon­si­ble for com­ply­ing with the order were express­ly infor­med that the order was issued under penal­ty of a fine in accordance with the Data Pro­tec­tion Act (point 3). Final­ly, a fee tota­ling CHF 2,850 was impo­sed on Sky­Sa­le Schweiz GmbH (point 4).

Pro­ce­du­ral issues

This order was issued after an appro­pria­te inve­sti­ga­ti­on (which should be the rule, but accor­ding to str. opi­ni­on is not always man­da­to­ry). Howe­ver, the infor­ma­ti­on of the per­sons con­cer­ned was not orde­red as a pre­cau­tio­na­ry mea­su­re, which would have been pos­si­ble in prin­ci­ple (Art. 55 para. 2 VwVG):

In a ruling dated May 28, 2024, the FDPIC obli­ged Sky­Sa­le Schweiz GmbH to noti­fy the […] Data secu­ri­ty breach affec­ted per­sons within 10 days of legal effect of the order […]. The FDPIC poin­ted out that the type and con­tent of the infor­ma­ti­on must com­ply with the requi­re­ments of data pro­tec­tion legis­la­ti­on (point 2). […]

The com­pa­ny was also cri­ti­ci­zed for ina­de­qua­te Estab­lish­ment of the facts. As far as can be seen, the ruling its­elf is not yet publicly available, which is not a mat­ter of cour­se: the FDPIC unfort­u­n­a­te­ly has an extre­me­ly gene­rous view of the public infor­ma­ti­on per­mit­ted under Art. 57 para. 2 FADP. Accor­din­gly, Apfelkiste’s com­plaints about the facts of the case can­not be veri­fi­ed – but the fact that the facts of the case are only dealt with incom­ple­te­ly or impre­cis­e­ly in rulings is in any case con­si­stent with a cer­tain amount of expe­ri­ence. In any case, the FAC can and must estab­lish the facts itself:

In prin­ci­ple, the Fede­ral Admi­ni­stra­ti­ve Court deci­des with unli­mi­t­ed juris­dic­tion; it reviews the con­te­sted decis­i­on for vio­la­ti­ons of the law – inclu­ding incor­rect and incom­ple­te deter­mi­na­ti­on of the legal­ly rele­vant facts and errors of law in the exer­cise of dis­creti­on – as well as for appro­pria­ten­ess (Art. 49 VwVG). The Fede­ral Admi­ni­stra­ti­ve Court then estab­lishes the legal­ly rele­vant facts ex offi­cio, sub­ject to the par­ties’ duty to cooperate […]

From the cla­im to right to be heard The par­ties are also entit­led to have their sub­mis­si­ons taken into account. Whe­ther this was the case here was dis­pu­ted befo­re the FAC becau­se a state­ment was not or at least not express­ly men­tio­ned in the ruling. Howe­ver, accor­ding to the FAC, the FDPIC does not have to do this eit­her – it is suf­fi­ci­ent if opi­ni­ons are inclu­ded in the files, at least if it can be seen in the cour­se of the pro­ce­e­dings that and how the opi­ni­on was taken into account (in this case by amen­ding the decision).

The FAC also sets the requi­re­ments for the depth of justi­fi­ca­ti­on of the order quite low here: The fact that the FDPIC had clas­si­fi­ed phis­hing as a risk for the per­sons con­cer­ned did not have to be justi­fi­ed in detail. On one point, howe­ver, the FAC rejects the rea­so­ning in the ruling – the FDPIC did not Apfelkiste’s cla­im to a com­pre­hen­si­ble justi­fi­ca­ti­on „serious­ly“ vio­la­ted.

This ruling must send a signal on this point. It can be sta­ted that ear­lier cla­ri­fi­ca­ti­ons of the facts and today’s inve­sti­ga­ti­ons some­ti­mes deal with the facts in a very libe­ral man­ner and that the rea­sons given by the FDPIC can be very con­cise, wood­cut-like, some­what airy-fairy or even contradictory.

So, „serious“, both in the rea­so­ning and in the dispositive:

In the con­te­sted ruling, the lower court sta­tes on the one hand that informing the data sub­jects is not impos­si­ble, but dis­pro­por­tio­na­te. At the same time, it points out that in the pre­sent con­stel­la­ti­on, Art. 24 para. 5 let. c FADP or public dis­clo­sure could be applied. The con­te­sted ruling does not con­tain any fur­ther expl­ana­ti­ons. The­re is no dis­cus­sion of the public announce­ment at all. On the other hand, it sta­tes that no rea­sons have been pro­ven that would justi­fy rest­ric­ting the infor­ma­ti­on pro­vi­ded to the data sub­jects. In the dis­po­si­ti­ve, the lower court then obli­ges the appel­lant to inform the per­sons con­cer­ned, wit­hout spe­ci­fy­ing this more pre­cis­e­ly. By qua­li­fy­ing the indi­vi­du­al infor­ma­ti­on as dis­pro­por­tio­na­te, but at the same time impo­sing the obli­ga­ti­on to inform the per­sons con­cer­ned wit­hout any clear dif­fe­ren­tia­ti­on or expl­ana­ti­on, the con­te­sted decis­i­on is dis­pro­por­tio­na­te. Order not com­pre­hen­si­ble and the­r­e­fo­re insuf­fi­ci­ent­ly sub­stan­tia­ted. Con­se­quent­ly, the lower court did not Complainant’s right to a com­pre­hen­si­ble and con­clu­si­ve justi­fi­ca­ti­on of the order serious­ly vio­la­ted.

In addi­ti­on, the FDPIC has recei­ved fur­ther comm­ents from Apfel­ki­ste on the Facts „not or only par­ti­al­ly taken into account“ – This invol­ved tech­ni­cal details of the URLs con­cer­ned and their index­ing, which were of cour­se not details, but essen­ti­al in asses­sing the risks for tho­se affected:

In sum­ma­ry, it can be sta­ted that the lower court did not or only par­ti­al­ly took into account the appellant’s state­ments on the facts in the con­te­sted decision.

The FDPIC was also accu­sed of making seve­ral impre­cise state­ments. – The fede­ral admi­ni­stra­ti­ve jud­ges must have scrat­ched their heads when rea­ding the ruling. Nevert­hel­ess, the FAC deci­ded not to annul the ruling. It is true that the right to be heard is of a for­mal natu­re. Becau­se the FAC deci­des with full cogni­ti­on and a rejec­tion would be an idle exer­cise, it deci­des its­elf. But at least it impo­ses the FDPIC, despi­te his vic­to­ry, a par­ty fee of CHF 500 and redu­ces the court costs becau­se the FDPIC vio­la­ted the right to a fair hea­ring and the offi­ci­al duty to sta­te reasons.

Data secu­ri­ty breach

The FAC first con­firms that the­re was a breach of data secu­ri­ty within the mea­ning of Art. 5 let. h FADP. It defi­nes the term data secu­ri­ty breach as follows:

A data secu­ri­ty breach can also be descri­bed as an «unin­ten­tio­nal inci­dent with secu­ri­ty rele­van­ce» that leads to the impair­ment of one or more data secu­ri­ty pro­tec­tion objec­ti­ves. Three pro­tec­tion goals are rele­vant here: Con­fi­den­tia­li­ty (the data is only acce­s­si­ble to aut­ho­ri­zed per­sons), Avai­la­bi­li­ty (the data is available when it is nee­ded) and Inte­gri­ty (the data is not chan­ged wit­hout aut­ho­rizati­on or unin­ten­tio­nal­ly). In other words, a breach of data secu­ri­ty occurs when at least one of the­se three aspects is unin­ten­tio­nal­ly or unlawful­ly impai­red beco­mes. In prin­ci­ple, it must effec­tively lead to such an impair­ment come or have come. Con­fi­den­tia­li­ty is alre­a­dy dee­med to have been com­pro­mi­sed as soon as the mere Pos­si­bi­li­ty that per­so­nal data is acce­s­si­ble to unaut­ho­ri­zed per­sons; whe­ther such access actual­ly takes place or has taken place is irrele­vant. A breach of data secu­ri­ty can be accom­pa­nied by a per­ma­nent impair­ment as well as an actu­al vio­la­ti­on of pri­va­cy, for exam­p­le if the data sub­ject loses con­trol over their data or if the data is misu­s­ed or dis­c­lo­sed to unaut­ho­ri­zed per­sons. Whe­ther a breach of data secu­ri­ty has occur­red must be asses­sed regard­less of whe­ther it was cau­sed cul­pa­b­ly or unlawful­ly. The risks asso­cia­ted with the inju­ry are also irrele­vant in this con­text. The breach of data secu­ri­ty can be cau­sed by third par­ties as well as by the con­trol­ler or pro­ces­sor itself […].

That is cer­tain­ly an accu­ra­te defi­ni­ti­on. Whe­ther access has taken place is not decisi­ve for the con­cept of a secu­ri­ty breach, but it is very important for the risk assessment.

It was clear that the secu­ri­ty of per­so­nal data had been brea­ched here and, as far as could be seen, this was not dis­pu­ted in principle:

The file shows that RMA URLs of sup­port cases of the respon­dent in the Index of the Bing search engi­ne from Micro­soft and thus, sin­ce around June 2023, cus­to­mer data or per­so­nal data in accordance with Art. 5 let. a FADP, name­ly cont­act data (names, e‑mail addres­ses, postal addres­ses), com­mu­ni­ca­ti­on con­tent (of the exch­an­ge bet­ween the cus­to­mer and «apfelkiste.ch» regar­ding the sup­port case), bank data (IBAN) as well as image data (pho­tos of the purcha­sed pro­ducts) and vou­ch­er codes have been disclosed/accessed by unaut­ho­ri­zed per­sons or the pos­si­bi­li­ty exi­sted that per­so­nal data could be acce­s­sed by unaut­ho­ri­zed per­sons. This com­pro­mi­sed the pro­tec­tion objec­ti­ve of con­fi­den­tia­li­ty, regard­less of whe­ther such access actual­ly took place.

Risk assess­ment

It is note­wor­t­hy and cor­rect that the FAC found that the The num­ber of per­sons affec­ted is gene­ral­ly irrele­vant for the que­sti­on of whe­ther a secu­ri­ty breach trig­gers a „need for pro­tec­tion“ for tho­se affec­ted, i.e. the need for risk-redu­cing measures:

The fact that only a small pro­por­ti­on of the RMA URLs are affec­ted and that at most and not at least 19,000 URLs or cus­to­mers are affec­ted does not chan­ge the assess­ment of whe­ther the­re is a need for pro­tec­tion. The Pro­tec­tion requi­re­ments rela­te to the indi­vi­du­al cus­to­mers affec­ted by the data breach and con­sists of being able to take mea­su­res to redu­ce the risks to their pri­va­cy or fun­da­men­tal rights. The mea­su­res to be taken the­r­e­fo­re do not depend on the num­ber of RMA URLs or cus­to­mers affected.

This is cor­rect becau­se the right to pro­tec­tion of per­so­na­li­ty or fun­da­men­tal rights is an indi­vi­du­al right and indi­vi­du­als can­not be less well pro­tec­ted just becau­se the num­ber of others affec­ted is low. Howe­ver, the num­ber of peo­p­le affec­ted can Pro­ba­bi­li­ty of occur­rence harmful events, which may or must be taken into account in a risk assess­ment. This also fol­lows from the ruling of the FAC:

Even if the risk of misu­se gene­ral­ly increa­ses as the num­ber of peo­p­le who have (unaut­ho­ri­zed) access to per­so­nal data increa­ses, the group of cus­to­mers in this case is not insi­gni­fi­cant (around 19,000 peo­p­le). Data misu­se can­not be ruled out; rather, the­re is a rele­vant risk to the per­so­na­li­ty and fun­da­men­tal rights of the per­sons concerned.

After beco­ming awa­re of the breach, Apfel­ki­ste had Mea­su­res were taken to make access by unaut­ho­ri­zed per­sons dif­fi­cult or impos­si­ble. Howe­ver, this was not suf­fi­ci­ent becau­se it was too late:

Fur­ther­mo­re, it can­not be ruled out that the pre­vious­ly dis­c­lo­sed data has alre­a­dy been acce­s­sed, stored or fur­ther pro­ce­s­sed. Accor­din­gly, even after the sub­se­quent access rest­ric­tion, the­re is still a rele­vant risk of data misu­se, which is why the data sub­jects’ need for pro­tec­tion con­ti­nues to exist.

That may be, but the FAC is making things too easy for its­elf here. For the risk assess­ment It does not mat­ter whe­ther tho­se affec­ted have come for­ward or whe­ther nega­ti­ve con­se­quen­ces are known. are:

The complainant’s argu­ment that the­re were no indi­ca­ti­ons that pos­si­ble con­se­quen­ces for the affec­ted cus­to­mers would actual­ly have mani­fe­sted them­sel­ves is not con­vin­cing. The same applies to the objec­tion that the­re was neither a rele­vant pro­ba­bi­li­ty of occur­rence nor did such a pro­ba­bi­li­ty – con­tra­ry to initi­al expec­ta­ti­ons – pro­ve to be low, […] […] 

The fact that – as far as is known – no spe­ci­fic con­se­quen­ces have occur­red to date does not allow the con­clu­si­on to be drawn that the risk should be clas­si­fi­ed as low. Like­wi­se, the com­plainant can­not be fol­lo­wed when it makes the pro­ba­bi­li­ty of dama­ge occur­ring depen­dent on whe­ther the affec­ted cus­to­mers have cont­ac­ted it or not.

This is wrong inso­far as it denies any rele­van­ce to the known con­se­quen­ces. With a lar­ge num­ber of peo­p­le affec­ted and a lon­ger dura­ti­on, the fact that no one has come for­ward and appar­ent­ly no nega­ti­ve con­se­quen­ces have occur­red cer­tain­ly allo­ws the con­clu­si­on that the pro­ba­bi­li­ty of nega­ti­ve con­se­quen­ces occur­ring is some­what lower than would other­wi­se be assu­med. It appears that the data in que­sti­on was not syste­ma­ti­cal­ly acce­s­sed, sold on the dark­net and used in a phis­hing cam­paign – this is not irrele­vant, even if it does not pro­ve zero risk.

Obli­ga­ti­on to noti­fy the per­sons concerned

The FDPIC had appar­ent­ly justi­fi­ed the obli­ga­ti­on to noti­fy the data sub­jects of the breach in gene­ral terms by sta­ting that phis­hing could occur:

The infor­ma­ti­on [accor­ding to the FDPIC] enables the data sub­jects to exer­cise con­trol over the use of their data. It sta­tes that in its noti­fi­ca­ti­on of Febru­ary 16, 2024, the com­plainant listed iden­ti­ty theft and finan­cial dama­ge as a pos­si­ble con­se­quence for the per­sons con­cer­ned. Data records from data secu­ri­ty brea­ches are often used for the phis­hing attacks descri­bed in the con­te­sted order. The lower court also cri­ti­ci­zed the fact that the appel­lant clai­med that a risk-redu­cing effect could no lon­ger be expec­ted due to the pas­sa­ge of time, even though it had cau­sed a delay in the infor­ma­ti­on its­elf. This argu­ment under­mi­nes the duty to inform.

The que­sti­on befo­re the FAC was whe­ther risks could be pre­ven­ted or redu­ced by informing the per­sons con­cer­ned, which is par­ti­cu­lar­ly the case if the per­son con­cer­ned is able to take cer­tain mea­su­res to pro­tect them­sel­ves. The FAC casual­ly says some­thing wel­co­me here:

The FDPIC may also only request the infor­ma­ti­on if it is neces­sa­ry to pro­tect the data subject

The FDPIC hims­elf had in his Gui­de to secu­ri­ty brea­ches claims that he can also order infor­ma­ti­on to be pro­vi­ded to tho­se affec­ted becau­se peo­p­le like to read it:

[…] becau­se, in its opi­ni­on, due to the lar­ge num­ber of affec­ted per­sons or media covera­ge, the­re is a public inte­rest in tho­se respon­si­ble pro­vi­ding the lar­ge num­ber of affec­ted per­sons and thus indi­rect­ly also a broad public with more detail­ed infor­ma­ti­on on the con­se­quen­ces of a data secu­ri­ty breach in an appro­pria­te manner.

That should now be off the table.

Howe­ver, the FAC affirms that the­re is a duty to inform tho­se affec­ted about the inci­dent becau­se the risk of phis­hing, social engi­nee­ring, iden­ti­ty theft or money theft exists and can be redu­ced by tho­se affec­ted. can:

Various per­so­nal data are affec­ted by the data secu­ri­ty breach. In com­bi­na­ti­on with the IBAN, the name and the address of a per­son, in par­ti­cu­lar Iden­ti­ty or social engi­nee­ring fraud be com­mit­ted. This could also be done, for exam­p­le, by means of a Direct debit money with­drawn be taken. Mea­su­res that the data sub­ject can take them­sel­ves include, for exam­p­le, chan­ging access data or pass­words to user accounts, checking account state­ments, cri­ti­cal­ly exami­ning mes­sa­ges and requests that may have been fab­ri­ca­ted with unlawful­ly obtai­ned (par­ti­cu­lar­ly con­fi­den­ti­al) per­so­nal data and could be used for phis­hing pur­po­ses […] The data sub­ject could, for exam­p­le, take the­se mea­su­res or Infor­ma­ti­on from your own bank and the Rest­ric­ting or blocking the direct debit pro­ce­du­re car­ry out. The­re is a cor­re­spon­ding need to pro­tect the data sub­jects, which is why it is neces­sa­ry to inform the data subjects

The fact that sin­ce the inju­ry some time has pas­sed did not chan­ge this – in gene­ral, the pas­sa­ge of time does not seem to play a role in inju­ries such as this one:

The argu­ment put for­ward by the com­plainant, accor­ding to which no lon­ger expec­ted to have a risk-miti­ga­ting effect due to the pas­sa­ge of time is not valid. The time that has elap­sed sin­ce the data breach does not rule out misu­se of the data con­cer­ned. Per­so­nal data can be misu­s­ed after an unaut­ho­ri­zed dis­clo­sure saved, copied and used or pas­sed on at a later date at any time. beco­me. Misu­se can the­r­e­fo­re occur long after the unaut­ho­ri­zed dis­clo­sure or data breach. The pas­sa­ge of time the­r­e­fo­re does not allow any relia­ble con­clu­si­on to be drawn that the data con­cer­ned is no lon­ger being misu­s­ed and that a risk-redu­cing effect can no lon­ger be expec­ted. Accor­din­gly, the risk of data misu­se – and thus the need for pro­tec­tion of the data sub­jects – remains regard­less of the time that has pas­sed sin­ce the data breach.

Excep­ti­ons to the obli­ga­ti­on to pro­vi­de information

Accor­ding to Art. 24 para. 5 FADP, the con­trol­ler may, among other things, rest­rict, post­po­ne or wai­ve the pro­vi­si­on of infor­ma­ti­on to the data sub­ject if the infor­ma­ti­on is impos­si­ble or requi­res a dis­pro­por­tio­na­te effort.

Impos­si­ble“ does not mean „dif­fi­cult“ or „I don’t know which part of my cus­to­mers is affected“:

Fur­ther­mo­re, a rest­ric­tion of the noti­fi­ca­ti­on to the data sub­ject pur­su­ant to Art. 24 para. 5 let. b FADP may initi­al­ly be con­side­red if it is impos­si­ble to pro­vi­de infor­ma­ti­on. This applies in par­ti­cu­lar to cases in which the con­trol­ler does not even know which per­sons are affec­ted by the data secu­ri­ty breach, which may be due, for exam­p­le, to the fact that the log files from which this would be evi­dent are no lon­ger available. It is then impos­si­ble to pro­vi­de infor­ma­ti­on if the data sub­jects can be iden­ti­fi­ed but their cont­act details are not known. Howe­ver, the data con­trol­ler can­not eva­de the report­ing obli­ga­ti­on by arguing that they do not know exact­ly from which per­sons their cus­to­mers« data was sto­len. In such con­stel­la­ti­ons, an »exce­s­si­ve” report is requi­red, by the con­trol­ler also informing per­sons (and asking them to chan­ge pass­words, for exam­p­le) who may not even be affec­ted by the data breach. […]

In this case, howe­ver, infor­ma­ti­on was appar­ent­ly effec­tively impos­si­ble becau­se Apfel­ki­ste had all poten­ti­al­ly affec­ted URLs blocked on Bing as a pro­tec­ti­ve mea­su­re. This made it tech­ni­cal­ly impos­si­ble to inform the affec­ted cus­to­mers. Whe­ther this is effec­tively the case is not enti­re­ly clear from the judgment, nor appar­ent­ly was it clear to the FAC, but it did not matter:

A rest­ric­tion in accordance with Art. 24 para. 5 let. b FADP is also pos­si­ble if the infor­ma­ti­on con­ta­ins a dis­pro­por­tio­na­te effort is requi­red. This would be the case, for exam­p­le, if a lar­ge num­ber of data sub­jects had to be infor­med indi­vi­du­al­ly, wher­eby the resul­ting costs would be dis­pro­por­tio­na­te in rela­ti­on to the infor­ma­ti­on gai­ned for the indi­vi­du­al per­sons. Ano­ther exam­p­le is whe­re the cont­act details of a lar­ge num­ber of data sub­jects are dif­fi­cult to obtain or would requi­re leng­thy inve­sti­ga­ti­ons, so that the noti­fi­ca­ti­on could only be made at a time when it is alre­a­dy too late for the data sub­jects to take coun­ter­me­a­su­res, in par­ti­cu­lar becau­se the risk has mate­ria­li­zed in the meantime […].

In the pre­sent case, it is no lon­ger pos­si­ble to iden­ti­fy the data sub­jects due to the mea­su­res taken by the com­plainant. Howe­ver, even if such iden­ti­fi­ca­ti­on were pos­si­ble, the rest­ric­tion pur­su­ant to Art. 24 para. 5 let. b FADP would app­ly, as informing the 19,000 cus­to­mers affec­ted would invol­ve a dis­pro­por­tio­na­te effort.

Infor­ma­ti­on by public announcement

Inte­re­st­ingly enough Art. 24 FADP does not express­ly pro­vi­de for dis­clo­sure, but only makes the exemp­ti­on from the obli­ga­ti­on to inform the data sub­jects depen­dent on such a pos­si­bi­li­ty, which is why the FDPIC can­not order such a dis­clo­sure – but he does have a means of exer­ting pres­su­re through the instru­ment of informing the public himself:

[…] Howe­ver, the DPA does not sti­pu­la­te an (expli­cit) obli­ga­ti­on to make a public announce­ment in such cases. This appears justi­fia­ble inso­far as in con­stel­la­ti­ons in which only a few data sub­jects can­not be infor­med indi­vi­du­al­ly, e.g. becau­se their email addres­ses are unknown, a public announce­ment is not neces­sa­ry. public announce­ment would appear dis­pro­por­tio­na­te. Howe­ver, in indi­vi­du­al cases, dis­rup­ti­ve results are also conceiva­ble: If, for exam­p­le, num­e­rous per­sons are affec­ted by a data secu­ri­ty breach and their indi­vi­du­al infor­ma­ti­on would requi­re a dis­pro­por­tio­na­te effort, public dis­clo­sure is in prin­ci­ple not requi­red accor­ding to the wor­ding of the law even if this could effec­tively coun­ter the risks ari­sing from the breach. In such cases, the FDPIC also lacks the aut­ho­ri­ty to (for­mal­ly) requi­re the con­trol­ler to make a public announce­ment, becau­se, in the con­text of an admi­ni­stra­ti­ve mea­su­re, the FDPIC can in prin­ci­ple only demand con­duct to which the con­trol­ler is alre­a­dy legal­ly obli­ged. Nevert­hel­ess, the FDPIC could, under cer­tain cir­cum­stances, inform the public of his own accord «about his fin­dings and decis­i­ons» (Art. 57 para. 2 FADP). In order to anti­ci­pa­te such a mea­su­re, the con­trol­ler should in fact be advi­sed to make a public announce­ment on its own initia­ti­ve, despi­te the lack of an (expli­cit) obli­ga­ti­on, inso­far as this appears rea­sonable for the pro­tec­tion of the data sub­jects and pro­por­tio­na­te in terms of an over­all assessment […].

Howe­ver, public infor­ma­ti­on is only an alter­na­ti­ve if it is indi­vi­du­al infor­ma­ti­on equi­va­lent („the infor­ma­ti­on of the per­son con­cer­ned is ensu­red by a public announce­ment in a com­pa­ra­ble man­ner“). That was que­stionable here. Nevert­hel­ess, the infor­ma­ti­on would not be com­ple­te­ly ineffective:

With a public announce­ment, for exam­p­le on the complainant’s web­site, an infor­ma­ti­on chan­nel would be cho­sen which can be expec­ted to be rea­ched by at least some of the affec­ted cus­to­mers and this infor­ma­ti­on would be pas­sed on via various chan­nels (oral com­mu­ni­ca­ti­on, infor­ma­ti­on via the media, etc.), so that ulti­m­ate­ly tho­se affec­ted cus­to­mers who do not learn first-hand about the infor­ma­ti­on in the con­text of the public announce­ment would also beco­me awa­re of it. In terms of con­tent, the same infor­ma­ti­on con­tent would have to be com­mu­ni­ca­ted as in the con­text of indi­vi­du­al infor­ma­ti­on. Based on the abo­ve, a public announce­ment pro­ves to be pos­si­ble in principle.

An announce­ment would also be sui­ta­ble, affec­ted per­sons (regard­less of whe­ther other per­sons are also infor­med). As indi­vi­du­al infor­ma­ti­on would not be pos­si­ble or would be dis­pro­por­tio­na­te, publi­ca­ti­on is also the mil­dest means and the­r­e­fo­re also the most appro­pria­te. requi­red. After all, it is also rea­sonable and thus Rela­ti­ve, becau­se Apfel­ki­ste its­elf is to bla­me for any dama­ge to its reputation:

In view of the exi­sting need for pro­tec­tion, this inte­rest car­ri­es con­sidera­ble weight. On the other hand, the com­plainant has an inte­rest in not pro­vi­ding public infor­ma­ti­on in order to avo­id repu­ta­tio­nal dama­ge and to avo­id unneces­s­a­ri­ly unsett­ling unaf­fec­ted or poten­ti­al cus­to­mers. The inte­rest in pro­tec­ting the busi­ness repu­ta­ti­on must be reco­gnized in prin­ci­ple. Howe­ver, it must be taken into account that the pos­si­ble repu­ta­tio­nal dama­ge has its cau­se in a data pro­tec­tion vio­la­ti­on for which the com­plainant its­elf is respon­si­ble. It would be con­tra­ry to the pro­tec­ti­ve pur­po­se of data pro­tec­tion law if a (legal) per­son could eva­de informing tho­se affec­ted by refer­ring to pos­si­ble repu­ta­tio­nal dama­ge. The fact that non-affec­ted or poten­ti­al cus­to­mers also beco­me awa­re of a data pro­tec­tion breach does not con­sti­tu­te a dis­pro­por­tio­na­te addi­tio­nal bur­den, espe­ci­al­ly as the noti­fi­ca­ti­on can be fac­tu­al and limi­t­ed to what is neces­sa­ry. Over­all, the inte­rest of the per­son con­cer­ned in the pro­tec­tion of their per­so­na­li­ty out­weighs the inte­rest of the com­plainant in avo­i­ding public infor­ma­ti­on; the mea­su­re the­r­e­fo­re also pro­ves to be reasonable.

As I said, the FDPIC may not order public dis­clo­sure becau­se the FADP – as inter­pre­ted by the FAC – does not express­ly requi­re it. This can cer­tain­ly be dis­pu­ted; the wor­ding does not pro­vi­de for such an obli­ga­ti­on, but the pur­po­se of the law is cry­stal clear. Howe­ver, the FDPIC had not orde­red such a noti­ce at all – he had only orde­red that the data sub­jects be informed.

The FAC pro­tects this dis­po­si­ti­ve and con­siders the public announce­ment to be pro­por­tio­na­te. So far so good – but at the same time it sta­tes that the infor­ma­ti­on is impos­si­ble or at least dis­pro­por­tio­na­te and that the FADP does not actual­ly requi­re public dis­clo­sure. So quid? In the end, the FAC can pro­ba­b­ly only be accu­sed of the same vio­la­ti­on of the duty to sta­te rea­sons that it attests to the FDPIC. In any case, pro­por­tio­na­li­ty is not a basis under data pro­tec­tion law for a duty of public dis­clo­sure. It remains unclear why the FAC did not sim­ply read such an obli­ga­ti­on into Art. 24 para. 5. In any case, non-com­pli­ance with the order can­not pos­si­bly lead to dis­o­be­dience under the­se circumstances.