The FAC dismissed an appeal against a ruling by the FDPIC and confirmed the order to inform the data subjects (judgment A‑3790/2024 dated April 8, 2026). However, it sharply criticizes the FDPIC’s conduct of proceedings by Serious violations of the right to be heard or violation of the official duty to state reasons recognizes.
The matter concerned the Obligation to inform the data subjects about a data breach (the Blick has reported):
- SkySale Switzerland (represented here by attorney Martin Steiger) operates the online store apfelkiste.ch. Apfelkiste uses customer-specific URLs with an unguessable hash value to process support cases (apparently because Apfelkiste allows guest orders).
- These URLs ended up in the index of search engines, especially Bing. This exposed contact details, communication content, bank details (IBAN) and other data. At least 19,000 cases were affected over a period of around 8 months.
- Following a tip-off from a third party, Apfelkiste reported the incident to the FDPIC and took measures, including blocking the Bing crawler and redirecting the affected URLs to another landing page.
Apfelkiste had refrained from informing those affected. After an investigation, the FDPIC orders the information of the persons concerned. However, because he had also commented on exceptions and the public announcement in the ruling, it remained unclear what was specifically required of Apfelkiste. Nevertheless, the FAC dismissed Apfelkiste’s appeal, albeit with an obvious stomachache.
Order to inform the persons concerned
After corresponding correspondence with the FDPIC, Apfelkiste did not inform the customers concerned, whereupon the FDPIC ordered such information:
[…] SkySale Schweiz GmbH informed the FDPIC that it did not consider it necessary to inform the persons concerned. The measures it had taken were effective. It was it is not clear what additional measures would be available to the persons concerned to reduce the risks […] over and above the measures it has taken itself. In addition, informing the persons concerned is not possible or can only be implemented with disproportionate effort.
The FAC reproduces the dispositive of the order as follows:
In a ruling dated May 28, 2024, the FDPIC obliged SkySale Schweiz GmbH to inform the persons affected by the […] data security breach within 10 days of the ruling taking legal effect (point 1). The FDPIC pointed out that the type and content of the information must comply with the requirements of data protection legislation (paragraph 2). In addition, the natural persons […] responsible for complying with the order were expressly informed that the order was issued under penalty of a fine in accordance with the Data Protection Act (point 3). Finally, a fee totaling CHF 2,850 was imposed on SkySale Schweiz GmbH (point 4).
Procedural issues
This order was issued after an appropriate investigation (which should be the rule, but according to str. opinion is not always mandatory). However, the information of the persons concerned was not ordered as a precautionary measure, which would have been possible in principle (Art. 55 para. 2 VwVG):
In a ruling dated May 28, 2024, the FDPIC obliged SkySale Schweiz GmbH to notify the […] Data security breach affected persons within 10 days of legal effect of the order […]. The FDPIC pointed out that the type and content of the information must comply with the requirements of data protection legislation (point 2). […]
The company was also criticized for inadequate Establishment of the facts. As far as can be seen, the ruling itself is not yet publicly available, which is not a matter of course: the FDPIC unfortunately has an extremely generous view of the public information permitted under Art. 57 para. 2 FADP. Accordingly, Apfelkiste’s complaints about the facts of the case cannot be verified – but the fact that the facts of the case are only dealt with incompletely or imprecisely in rulings is in any case consistent with a certain amount of experience. In any case, the FAC can and must establish the facts itself:
In principle, the Federal Administrative Court decides with unlimited jurisdiction; it reviews the contested decision for violations of the law – including incorrect and incomplete determination of the legally relevant facts and errors of law in the exercise of discretion – as well as for appropriateness (Art. 49 VwVG). The Federal Administrative Court then establishes the legally relevant facts ex officio, subject to the parties’ duty to cooperate […]
From the claim to right to be heard The parties are also entitled to have their submissions taken into account. Whether this was the case here was disputed before the FAC because a statement was not or at least not expressly mentioned in the ruling. However, according to the FAC, the FDPIC does not have to do this either – it is sufficient if opinions are included in the files, at least if it can be seen in the course of the proceedings that and how the opinion was taken into account (in this case by amending the decision).
The FAC also sets the requirements for the depth of justification of the order quite low here: The fact that the FDPIC had classified phishing as a risk for the persons concerned did not have to be justified in detail. On one point, however, the FAC rejects the reasoning in the ruling – the FDPIC did not Apfelkiste’s claim to a comprehensible justification „seriously“ violated.
This ruling must send a signal on this point. It can be stated that earlier clarifications of the facts and today’s investigations sometimes deal with the facts in a very liberal manner and that the reasons given by the FDPIC can be very concise, woodcut-like, somewhat airy-fairy or even contradictory.
So, „serious“, both in the reasoning and in the dispositive:
In the contested ruling, the lower court states on the one hand that informing the data subjects is not impossible, but disproportionate. At the same time, it points out that in the present constellation, Art. 24 para. 5 let. c FADP or public disclosure could be applied. The contested ruling does not contain any further explanations. There is no discussion of the public announcement at all. On the other hand, it states that no reasons have been proven that would justify restricting the information provided to the data subjects. In the dispositive, the lower court then obliges the appellant to inform the persons concerned, without specifying this more precisely. By qualifying the individual information as disproportionate, but at the same time imposing the obligation to inform the persons concerned without any clear differentiation or explanation, the contested decision is disproportionate. Order not comprehensible and therefore insufficiently substantiated. Consequently, the lower court did not Complainant’s right to a comprehensible and conclusive justification of the order seriously violated.
In addition, the FDPIC has received further comments from Apfelkiste on the Facts „not or only partially taken into account“ – This involved technical details of the URLs concerned and their indexing, which were of course not details, but essential in assessing the risks for those affected:
In summary, it can be stated that the lower court did not or only partially took into account the appellant’s statements on the facts in the contested decision.
The FDPIC was also accused of making several imprecise statements. – The federal administrative judges must have scratched their heads when reading the ruling. Nevertheless, the FAC decided not to annul the ruling. It is true that the right to be heard is of a formal nature. Because the FAC decides with full cognition and a rejection would be an idle exercise, it decides itself. But at least it imposes the FDPIC, despite his victory, a party fee of CHF 500 and reduces the court costs because the FDPIC violated the right to a fair hearing and the official duty to state reasons.
Data security breach
The FAC first confirms that there was a breach of data security within the meaning of Art. 5 let. h FADP. It defines the term data security breach as follows:
A data security breach can also be described as an «unintentional incident with security relevance» that leads to the impairment of one or more data security protection objectives. Three protection goals are relevant here: Confidentiality (the data is only accessible to authorized persons), Availability (the data is available when it is needed) and Integrity (the data is not changed without authorization or unintentionally). In other words, a breach of data security occurs when at least one of these three aspects is unintentionally or unlawfully impaired becomes. In principle, it must effectively lead to such an impairment come or have come. Confidentiality is already deemed to have been compromised as soon as the mere Possibility that personal data is accessible to unauthorized persons; whether such access actually takes place or has taken place is irrelevant. A breach of data security can be accompanied by a permanent impairment as well as an actual violation of privacy, for example if the data subject loses control over their data or if the data is misused or disclosed to unauthorized persons. Whether a breach of data security has occurred must be assessed regardless of whether it was caused culpably or unlawfully. The risks associated with the injury are also irrelevant in this context. The breach of data security can be caused by third parties as well as by the controller or processor itself […].
That is certainly an accurate definition. Whether access has taken place is not decisive for the concept of a security breach, but it is very important for the risk assessment.
It was clear that the security of personal data had been breached here and, as far as could be seen, this was not disputed in principle:
The file shows that RMA URLs of support cases of the respondent in the Index of the Bing search engine from Microsoft and thus, since around June 2023, customer data or personal data in accordance with Art. 5 let. a FADP, namely contact data (names, e‑mail addresses, postal addresses), communication content (of the exchange between the customer and «apfelkiste.ch» regarding the support case), bank data (IBAN) as well as image data (photos of the purchased products) and voucher codes have been disclosed/accessed by unauthorized persons or the possibility existed that personal data could be accessed by unauthorized persons. This compromised the protection objective of confidentiality, regardless of whether such access actually took place.
Risk assessment
It is noteworthy and correct that the FAC found that the The number of persons affected is generally irrelevant for the question of whether a security breach triggers a „need for protection“ for those affected, i.e. the need for risk-reducing measures:
The fact that only a small proportion of the RMA URLs are affected and that at most and not at least 19,000 URLs or customers are affected does not change the assessment of whether there is a need for protection. The Protection requirements relate to the individual customers affected by the data breach and consists of being able to take measures to reduce the risks to their privacy or fundamental rights. The measures to be taken therefore do not depend on the number of RMA URLs or customers affected.
This is correct because the right to protection of personality or fundamental rights is an individual right and individuals cannot be less well protected just because the number of others affected is low. However, the number of people affected can Probability of occurrence harmful events, which may or must be taken into account in a risk assessment. This also follows from the ruling of the FAC:
Even if the risk of misuse generally increases as the number of people who have (unauthorized) access to personal data increases, the group of customers in this case is not insignificant (around 19,000 people). Data misuse cannot be ruled out; rather, there is a relevant risk to the personality and fundamental rights of the persons concerned.
After becoming aware of the breach, Apfelkiste had Measures were taken to make access by unauthorized persons difficult or impossible. However, this was not sufficient because it was too late:
Furthermore, it cannot be ruled out that the previously disclosed data has already been accessed, stored or further processed. Accordingly, even after the subsequent access restriction, there is still a relevant risk of data misuse, which is why the data subjects’ need for protection continues to exist.
That may be, but the FAC is making things too easy for itself here. For the risk assessment It does not matter whether those affected have come forward or whether negative consequences are known. are:
The complainant’s argument that there were no indications that possible consequences for the affected customers would actually have manifested themselves is not convincing. The same applies to the objection that there was neither a relevant probability of occurrence nor did such a probability – contrary to initial expectations – prove to be low, […] […]
The fact that – as far as is known – no specific consequences have occurred to date does not allow the conclusion to be drawn that the risk should be classified as low. Likewise, the complainant cannot be followed when it makes the probability of damage occurring dependent on whether the affected customers have contacted it or not.
This is wrong insofar as it denies any relevance to the known consequences. With a large number of people affected and a longer duration, the fact that no one has come forward and apparently no negative consequences have occurred certainly allows the conclusion that the probability of negative consequences occurring is somewhat lower than would otherwise be assumed. It appears that the data in question was not systematically accessed, sold on the darknet and used in a phishing campaign – this is not irrelevant, even if it does not prove zero risk.
Obligation to notify the persons concerned
The FDPIC had apparently justified the obligation to notify the data subjects of the breach in general terms by stating that phishing could occur:
The information [according to the FDPIC] enables the data subjects to exercise control over the use of their data. It states that in its notification of February 16, 2024, the complainant listed identity theft and financial damage as a possible consequence for the persons concerned. Data records from data security breaches are often used for the phishing attacks described in the contested order. The lower court also criticized the fact that the appellant claimed that a risk-reducing effect could no longer be expected due to the passage of time, even though it had caused a delay in the information itself. This argument undermines the duty to inform.
The question before the FAC was whether risks could be prevented or reduced by informing the persons concerned, which is particularly the case if the person concerned is able to take certain measures to protect themselves. The FAC casually says something welcome here:
The FDPIC may also only request the information if it is necessary to protect the data subject
The FDPIC himself had in his Guide to security breaches claims that he can also order information to be provided to those affected because people like to read it:
[…] because, in its opinion, due to the large number of affected persons or media coverage, there is a public interest in those responsible providing the large number of affected persons and thus indirectly also a broad public with more detailed information on the consequences of a data security breach in an appropriate manner.
That should now be off the table.
However, the FAC affirms that there is a duty to inform those affected about the incident because the risk of phishing, social engineering, identity theft or money theft exists and can be reduced by those affected. can:
Various personal data are affected by the data security breach. In combination with the IBAN, the name and the address of a person, in particular Identity or social engineering fraud be committed. This could also be done, for example, by means of a Direct debit money withdrawn be taken. Measures that the data subject can take themselves include, for example, changing access data or passwords to user accounts, checking account statements, critically examining messages and requests that may have been fabricated with unlawfully obtained (particularly confidential) personal data and could be used for phishing purposes […] The data subject could, for example, take these measures or Information from your own bank and the Restricting or blocking the direct debit procedure carry out. There is a corresponding need to protect the data subjects, which is why it is necessary to inform the data subjects
The fact that since the injury some time has passed did not change this – in general, the passage of time does not seem to play a role in injuries such as this one:
The argument put forward by the complainant, according to which no longer expected to have a risk-mitigating effect due to the passage of time is not valid. The time that has elapsed since the data breach does not rule out misuse of the data concerned. Personal data can be misused after an unauthorized disclosure saved, copied and used or passed on at a later date at any time. become. Misuse can therefore occur long after the unauthorized disclosure or data breach. The passage of time therefore does not allow any reliable conclusion to be drawn that the data concerned is no longer being misused and that a risk-reducing effect can no longer be expected. Accordingly, the risk of data misuse – and thus the need for protection of the data subjects – remains regardless of the time that has passed since the data breach.
Exceptions to the obligation to provide information
According to Art. 24 para. 5 FADP, the controller may, among other things, restrict, postpone or waive the provision of information to the data subject if the information is impossible or requires a disproportionate effort.
„Impossible“ does not mean „difficult“ or „I don’t know which part of my customers is affected“:
Furthermore, a restriction of the notification to the data subject pursuant to Art. 24 para. 5 let. b FADP may initially be considered if it is impossible to provide information. This applies in particular to cases in which the controller does not even know which persons are affected by the data security breach, which may be due, for example, to the fact that the log files from which this would be evident are no longer available. It is then impossible to provide information if the data subjects can be identified but their contact details are not known. However, the data controller cannot evade the reporting obligation by arguing that they do not know exactly from which persons their customers« data was stolen. In such constellations, an »excessive” report is required, by the controller also informing persons (and asking them to change passwords, for example) who may not even be affected by the data breach. […]
In this case, however, information was apparently effectively impossible because Apfelkiste had all potentially affected URLs blocked on Bing as a protective measure. This made it technically impossible to inform the affected customers. Whether this is effectively the case is not entirely clear from the judgment, nor apparently was it clear to the FAC, but it did not matter:
A restriction in accordance with Art. 24 para. 5 let. b FADP is also possible if the information contains a disproportionate effort is required. This would be the case, for example, if a large number of data subjects had to be informed individually, whereby the resulting costs would be disproportionate in relation to the information gained for the individual persons. Another example is where the contact details of a large number of data subjects are difficult to obtain or would require lengthy investigations, so that the notification could only be made at a time when it is already too late for the data subjects to take countermeasures, in particular because the risk has materialized in the meantime […].
In the present case, it is no longer possible to identify the data subjects due to the measures taken by the complainant. However, even if such identification were possible, the restriction pursuant to Art. 24 para. 5 let. b FADP would apply, as informing the 19,000 customers affected would involve a disproportionate effort.
Information by public announcement
Interestingly enough Art. 24 FADP does not expressly provide for disclosure, but only makes the exemption from the obligation to inform the data subjects dependent on such a possibility, which is why the FDPIC cannot order such a disclosure – but he does have a means of exerting pressure through the instrument of informing the public himself:
[…] However, the DPA does not stipulate an (explicit) obligation to make a public announcement in such cases. This appears justifiable insofar as in constellations in which only a few data subjects cannot be informed individually, e.g. because their email addresses are unknown, a public announcement is not necessary. public announcement would appear disproportionate. However, in individual cases, disruptive results are also conceivable: If, for example, numerous persons are affected by a data security breach and their individual information would require a disproportionate effort, public disclosure is in principle not required according to the wording of the law even if this could effectively counter the risks arising from the breach. In such cases, the FDPIC also lacks the authority to (formally) require the controller to make a public announcement, because, in the context of an administrative measure, the FDPIC can in principle only demand conduct to which the controller is already legally obliged. Nevertheless, the FDPIC could, under certain circumstances, inform the public of his own accord «about his findings and decisions» (Art. 57 para. 2 FADP). In order to anticipate such a measure, the controller should in fact be advised to make a public announcement on its own initiative, despite the lack of an (explicit) obligation, insofar as this appears reasonable for the protection of the data subjects and proportionate in terms of an overall assessment […].
However, public information is only an alternative if it is individual information equivalent („the information of the person concerned is ensured by a public announcement in a comparable manner“). That was questionable here. Nevertheless, the information would not be completely ineffective:
With a public announcement, for example on the complainant’s website, an information channel would be chosen which can be expected to be reached by at least some of the affected customers and this information would be passed on via various channels (oral communication, information via the media, etc.), so that ultimately those affected customers who do not learn first-hand about the information in the context of the public announcement would also become aware of it. In terms of content, the same information content would have to be communicated as in the context of individual information. Based on the above, a public announcement proves to be possible in principle.
An announcement would also be suitable, affected persons (regardless of whether other persons are also informed). As individual information would not be possible or would be disproportionate, publication is also the mildest means and therefore also the most appropriate. required. After all, it is also reasonable and thus Relative, because Apfelkiste itself is to blame for any damage to its reputation:
In view of the existing need for protection, this interest carries considerable weight. On the other hand, the complainant has an interest in not providing public information in order to avoid reputational damage and to avoid unnecessarily unsettling unaffected or potential customers. The interest in protecting the business reputation must be recognized in principle. However, it must be taken into account that the possible reputational damage has its cause in a data protection violation for which the complainant itself is responsible. It would be contrary to the protective purpose of data protection law if a (legal) person could evade informing those affected by referring to possible reputational damage. The fact that non-affected or potential customers also become aware of a data protection breach does not constitute a disproportionate additional burden, especially as the notification can be factual and limited to what is necessary. Overall, the interest of the person concerned in the protection of their personality outweighs the interest of the complainant in avoiding public information; the measure therefore also proves to be reasonable.
As I said, the FDPIC may not order public disclosure because the FADP – as interpreted by the FAC – does not expressly require it. This can certainly be disputed; the wording does not provide for such an obligation, but the purpose of the law is crystal clear. However, the FDPIC had not ordered such a notice at all – he had only ordered that the data subjects be informed.
The FAC protects this dispositive and considers the public announcement to be proportionate. So far so good – but at the same time it states that the information is impossible or at least disproportionate and that the FADP does not actually require public disclosure. So quid? In the end, the FAC can probably only be accused of the same violation of the duty to state reasons that it attests to the FDPIC. In any case, proportionality is not a basis under data protection law for a duty of public disclosure. It remains unclear why the FAC did not simply read such an obligation into Art. 24 para. 5. In any case, non-compliance with the order cannot possibly lead to disobedience under these circumstances.