The FDPIC has made its 33rd Activity Report for the Period from April 1, 2025, to March 31, 2026, Presented. The focus is on the 20th anniversary of the principle of public access. In terms of data protection law, two topics stand out: the consolidation of oversight under the revised Data Protection Act (DSG) and a remarkably high number of proceedings against private data controllers, particularly in the financial sector as well as in the debt collection and credit reporting industries. You can listen to the discussion about the report between attorney Martin Steiger and Andreas von Gunten on the podcast „Datenschutz-Plaudereien“ here Listen.
Here are some key figures for the reporting period:
- Consultations: 971
- Consultations with Government Agencies: 306
- Advertisements: 2,447 (previous year: 1,053), of which 2,347 were against private individuals and about 100 against the federal government
- Supervisory actions: 156 low-threshold interventions, 22 preliminary investigations, 9 formal investigations
- Requests for Mediation (BGÖ): 203
- Reported Data Breaches: 484, of which 141 were voluntary (previous year: 363, of which 26 were voluntary). This presumably means that the low number reflects only those reports explicitly designated as voluntary. There is likely a high number of unreported cases — also involving voluntary reports — that could not be classified as such due to the reporting form.
- Agencies that can be involved in DSG matters: 32 (previous year: 33)
Key Points
Oversight of the Revised Data Protection Act Consolidated
The EDÖB describes the regulatory enforcement of the DSG, which has been in effect since September 1, 2023, as „consolidated“:
The regulatory enforcement of the DSG, which took effect on September 1, 2023, can be considered consolidated now that the EDÖB has supplemented its information resources on the application of the newU. law during the reporting year with additional practical guides, and the Federal Administrative Court confirmed the authority’s new decision-making practice on October 6, 2025, with a first judgment that has become final.
This concerns the ruling of October 6, 2025, in the case of “Pfarrercheck,” in which the Federal Administrative Court upheld a ruling by the Federal Data Protection Commissioner (EDÖB) — namely, the prohibition on publishing contact information for clergy without their consent and the order to delete such information within 40 days. The court also upheld the fee based on the actual time spent and the anonymization of the records in the context of access to the case file.
However, to say that supervisory practice has thus been consolidated is a bold statement, given that the Federal Administrative Court ruled against the FDPIC with Judgment in the “Apfelkiste” Case had found a serious violation of procedural rights. The consolidation is likely to take some time.
To date, it has not been clarified in court whether the EDÖB’s publication practice — namely, the standard procedure of publishing decisions while identifying the addressee by name — is consistent with the principles of the rule of law. Both the legal basis provided by Art. 57(2) of the Data Protection Act (DSG) and the principle of proportionality require, in any case, a balancing of the public’s interest in information regarding the disclosure of the recipient’s name against the recipient’s interest in confidentiality — a balancing that is not reflected in the EDÖB’s publication decisions. It is also striking that in cases of „voluntary“ compliance with low-threshold interventions (e.g.,. here) no names are mentioned, whereas they are in official orders. This effectively turns these low-threshold interventions into coercive measures without a legal basis. In any case, the high „success rate“ of these interventions can likely be explained in part not by spontaneous compliance, but by the fear of reputational damage resulting from an investigation and an order.
Many complaints, few formal supervisory actions
The number of complaints received more than doubled to 2,447. Of these, 2,347 were directed against private individuals and only about 100 against federal authorities. 2,210 of these were processed, while 237 remained pending. This volume resulted in 156 low-threshold interventions, 22 preliminary investigations, and 9 formal investigations, 6 of which were initiated during the reporting year.
The ad viewership ratings are therefore roughly as follows:
- Low-threshold interventions: 6%
- Preliminary Investigations: 1%
- formal investigations: 0.36%
This speaks to the EDÖB’s sound judgment and makes it clear what also applies to requests for information: As a rule, these cases do not involve data protection concerns (at least unless multiple complaints are filed against the same company).
For DSG matters, 32 full-time positions will be available in 2026, one fewer than in 2025. The workload is distributed among
- Consulting (49.7 %)
- Supervision (21.5 %)
- Information (17 %) and
- Legislation (11.8 %).
The supervisory share has risen slightly compared to the previous year (20.3 %).
Legal Proceedings Against Private Individuals: Banks, Debt Collection Agencies, Credit Bureaus
Supervision focuses on private entities, with a particular emphasis on financial service providers and the right to access information:
- Against PostFinance The FDPIC ruled that explicit consent must be obtained when creating voiceprints for authentication via voice recognition, and that voiceprints must be deleted if such consent is not obtained (see here). PostFinance filed an appeal against the ruling and the planned publication. As of the report’s publication deadline, both proceedings were apparently still pending.
- Against Cembra Money Bank In January 2025, the EDÖB concluded an investigation into the handling of requests for information. Cembra had not filed an appeal against the decision.
- Against Debt Collection Team The FDPIC ordered that the publication of personal data of alleged debtors on the Internet be discontinued and that any data already published be deleted.
- The EDÖB launched an investigation into an unnamed credit reporting agency to determine whether data derived from credit reports may be disclosed to third parties for marketing purposes and whether the agency’s handling of requests for information and deletion is lawful.
- In one case, in which Add Conti GmbH, the FDPIC filed a criminal complaint with the St. Gallen Public Prosecutor’s Office for violation of the duty to cooperate.
AI and Biometrics
On March 3, 2026, following an informal preliminary assessment, the FDPIC launched an investigation into a Swiss company that offers digital identity verification and AI-based age identification services and uses the biometric data collected for identity verification to train its AI. The investigation is examining whether the AI-based processing operations comply with data processing principles and whether the rights of data subjects are being upheld. The investigation was apparently triggered by insufficient responses regarding the handling of data subject requests.
Right to Information for the Purpose of Obtaining Evidence
The EDÖB once again received numerous complaints from individuals who were unable to access their accounts with social media providers, but found no violation of the right to information. Whether operators and users complied with the terms of service is a matter of civil law. The right of access serves exclusively the purpose of informational self-determination and is not a tool for gathering evidence in civil or criminal matters; nor does it cover data belonging to third parties, such as alleged hackers. At the same time, the EDÖB notes that providers must verify users’ identities and refuse to disclose information if account ownership cannot be proven.
Data security breaches
The number of reported data breaches rose to 484 (previous year: 363). The increase is almost entirely due to voluntary reports, which rose from 26 to 141, while mandatory reports remained constant. The reason is said to be an adjustment to the FDPIC Guidelines on the Reporting of Data Breaches in which the FDPIC explicitly points out the possibility of voluntary reports. In addition, the number of preliminary reports is also increasing.
Principle of publicity
To mark the anniversary of the BGÖ, the report records 203 requests for mediation in 2025 — one more than the previous year. The actual increase in caseload is attributable to the number of requests for access to information submitted to the federal administration, which has more than tripled over the past ten years. Most requests for mediation came from media outlets (84) and private individuals (53). In 1,030 cases of complete or partial denial of access, a request for mediation was filed in 20%; 207 cases were resolved, and an agreement was reached in 98 of them.
More points
The activity report contains additional notes and observations, some of which are briefly highlighted below (more or less following the report’s structure):
Digitization
- Dashcams: According to the EDÖB, continuous dashcam recordings violate the principles of the DSG because their purpose and legal basis are not sufficiently defined. Event-triggered systems — which, for example, record only during emergency braking, sudden movement, or jolts, and quickly delete unnecessary recordings — can be operated in compliance with the DSG.
- M365 and the Cloud in the Federal Administration: During the Federal Administration’s migration to Microsoft 365 as part of the CEBA project, the FDPIC helped ensure that GEVER files, the contents of Outlook mailboxes, and particularly sensitive personal data and personality profiles continue to be processed in the Federal Administration’s data centers, on-premises rather than in the cloud. It also requires a precise description of high risks and risk-mitigation measures in the Data Protection Impact Assessment (DPIA). Furthermore, the Office welcomes the fact that the Federal Chancellery is examining open-source alternatives to M365 that can be deployed in the medium term as part of the BOSS project.
- Secondary Use of Personal Data. To the Motion 22.3890 (Framework Act on the Secondary Use of Data) The FDPIC sees no need for new regulations under data protection law. The DSG already permits secondary use, provided that the requirements of Art. 31 and Art. 39 of the DSG are met. In particular, a change in purpose may be justified for non-personal purposes such as research, planning, or statistics.
Artificial intelligence
- Technology-neutral DSG: The EDÖB emphasizes that the DSG is worded in a technology-neutral manner and applies to AI-supported data processing.
- Go to AI Convention of the Council of Europe The FDPIC supports the Federal Council’s approach of regulating areas relevant to fundamental rights (including data protection) in a general manner and supplementing them with sector-specific provisions as needed (if this remains the case).
- Federal Government-Owned AI Systems: The FDPIC considers federally owned AI systems to be necessary for the federal administration to comply with data protection and information security requirements. It is crucial that prompts and the data they contain be processed locally and made accessible only to authorized organizational units. Commercial LLMs such as Copilot or ChatGPT, on the other hand, pose a data security risk due to the fact that data is stored — at least temporarily — in the provider’s cloud.
- Smart Glasses: “Smart” glasses raise questions about transparency. Automatic light signals are not necessarily sufficient for this purpose. In addition, the FDPIC reminds users that the covert use of recording devices to observe or record private activities may be a criminal offense. Private users must fulfill their obligations to provide information and, depending on the intended use, obtain the consent of affected third parties.
- AI Training Using Biometric Data: On March 3, 2026, the EDÖB launched an investigation into a Swiss company that offers digital identity verification and AI-based age identification and uses biometric data from the identity verification process to train its AI. The investigation focuses on compliance with the principles of transparency, proportionality, good faith, and purpose limitation, as well as the implementation of data subjects’ rights.
Health
- Electronic Health Record: The electronic patient record is to be replaced by the electronic health record. The Federal Council submitted the related message to Parliament in November 2025; the law is expected to take effect in 2030. The E‑GD is to be automatically and free of charge created for individuals residing in Switzerland, with an opt-out option available. The FDPIC demands a genuine, uniform, and informal right to object — including analog solutions — as well as independent management of access rights, access to logs, and high standards for data protection and data security. Access by health apps has been restricted at the FDPIC’s request. He welcomes the retention of a sector-specific identification number instead of the AHV number, as it reduces the risk of linking to other databases.
- TARDOC and outpatient flat rates: The new fee schedule for outpatient medical treatments has been in effect since January 1, 2026, and replaces TARMED. It consists of TARDOC, a fee-for-service schedule, and outpatient flat rates. The EDÖB points out that there are still unresolved technical and legal issues, particularly regarding the transmission of diagnostic data. Such data must not exceed what is necessary for invoice verification.
- SpiGes: SpiGes stands for «Inpatient Hospital Care» and is a DigiSanté project aimed at implementing the “once-only” principle in the inpatient hospital sector. Hospital data should be collected once and then made available for various legal purposes, including by federal agencies, cantons, insurers, SwissDRG AG, and ANQ. The FDPIC requires that each recipient have access only to the data necessary for its legal duties. Personal data must be anonymized before transmission and limited to the necessary minimum.
Traffic
- SBB Body Cams: Regarding the planned use of body cameras by train attendants, the EDÖB emphasizes the principle of legality. Video surveillance constitutes a serious infringement of fundamental rights; its essential elements must therefore be regulated by statutory law and, as far as possible, in a technology-neutral manner. In the EDÖB’s view, the current legal framework is insufficient. SBB has apparently agreed to postpone implementation. On February 24, 2026, the EDÖB launched an investigation into BLT Baselland Transport regarding body cameras that were already in use.
- Facial Recognition at Zurich Airport: Flughafen Zürich AG is considered a federal agency by virtue of its operating license. In the opinion of the EDÖB, there is no formal legal basis for a pilot project on facial recognition during boarding pass checks. Flughafen Zürich AG will not proceed with the project until the necessary legal basis comes into effect.
Principle of publicity
- Oral Mediation: In 2025, 97 mediation proceedings were conducted; agreements were reached in 71 cases, representing a success rate of 73 percent. A total of 203 mediation requests were filed, and 49 recommendations were issued. The high settlement rate speaks in favor of this mechanism, even though the standard time limits remain a problem.
- Misuse of the BGÖ: Of particular interest is the FDPIC’s very valid criticism of the increasing use of the BGÖ for purposes unrelated to its intended scope. It has observed an increase in attempts to use the BGÖ to resolve legal issues or to obtain administrative decisions in cases where the main issue is no longer access to official documents. It cites the low barriers to entry and the fact that the conciliation procedure is free of charge as reasons for this.
- Formalism and Participation: The EDÖB criticizes the growing tendency toward formalism. In some cases, authorities did not clarify key preliminary issues — such as power of attorney, standing to sue, or eligibility to file a petition — until the conciliation proceedings. On the other hand, the EDÖB is increasingly confronted with procedural motions based on formalistic grounds.
- Gaps in the Scope of Special Laws: The EDÖB defines “gaps in applicability” as exceptions under special laws pursuant to Art. 4 of the Federal Act on Access to Government Information (BGÖ), i.e., provisions in other federal laws that classify certain information as confidential or establish conditions for access that differ from those of the BGÖ. The EDÖB lists 13 existing and 11 planned such gaps in applicability. According to the EDÖB, the existing exceptions under the BGÖ — in particular Articles 7 and 9 of the BGÖ concerning the protection of trade secrets, privacy, and data of legal entities — should, in principle, be sufficient. However, this view must be contested to the extent that trade secrets are effectively rendered meaningless by the very strict enforcement practices.
- Erosion of the Principle of Public Access. The FDPIC considers exceptions for supervisory, control, audit, and inspection authorities to be problematic. It is precisely in these areas that there is a heightened public interest in transparency. If supervisory activities are excluded from the scope of the Federal Act on Access to Government Information (BGÖ), the principle of public access will be eroded. The EDÖB therefore intends to continue opposing new special provisions in consultations with government agencies.