The FDPIC has made its 33rd Acti­vi­ty Report for the Peri­od from April 1, 2025, to March 31, 2026, Pre­sen­ted. The focus is on the 20th anni­ver­sa­ry of the prin­ci­ple of public access. In terms of data pro­tec­tion law, two topics stand out: the con­so­li­da­ti­on of over­sight under the revi­sed Data Pro­tec­tion Act (DSG) and a remar­kab­ly high num­ber of pro­ce­e­dings against pri­va­te data con­trol­lers, par­ti­cu­lar­ly in the finan­cial sec­tor as well as in the debt coll­ec­tion and cre­dit report­ing indu­stries. You can listen to the dis­cus­sion about the report bet­ween att­or­ney Mar­tin Stei­ger and Andre­as von Gun­ten on the pod­cast „Daten­schutz-Plau­de­rei­en“ here Listen.

Here are some key figu­res for the report­ing period:

  • Con­sul­ta­ti­ons: 971
  • Con­sul­ta­ti­ons with Govern­ment Agen­ci­es: 306
  • Adver­ti­se­ments: 2,447 (pre­vious year: 1,053), of which 2,347 were against pri­va­te indi­vi­du­als and about 100 against the fede­ral government
  • Super­vi­so­ry actions: 156 low-thres­hold inter­ven­ti­ons, 22 preli­mi­na­ry inve­sti­ga­ti­ons, 9 for­mal investigations
  • Requests for Media­ti­on (BGÖ): 203
  • Repor­ted Data Brea­ches: 484, of which 141 were vol­un­t­a­ry (pre­vious year: 363, of which 26 were vol­un­t­a­ry). This pre­su­ma­b­ly means that the low num­ber reflects only tho­se reports expli­ci­t­ly desi­gna­ted as vol­un­t­a­ry. The­re is likely a high num­ber of unre­por­ted cases — also invol­ving vol­un­t­a­ry reports — that could not be clas­si­fi­ed as such due to the report­ing form.
  • Agen­ci­es that can be invol­ved in DSG mat­ters: 32 (pre­vious year: 33)

Key Points

Over­sight of the Revi­sed Data Pro­tec­tion Act Consolidated

The EDÖB descri­bes the regu­la­to­ry enforce­ment of the DSG, which has been in effect sin­ce Sep­tem­ber 1, 2023, as „con­so­li­da­ted“:

The regu­la­to­ry enforce­ment of the DSG, which took effect on Sep­tem­ber 1, 2023, can be con­side­red con­so­li­da­ted now that the EDÖB has sup­ple­men­ted its infor­ma­ti­on resour­ces on the appli­ca­ti­on of the newU. law during the report­ing year with addi­tio­nal prac­ti­cal gui­des, and the Fede­ral Admi­ni­stra­ti­ve Court con­firm­ed the authority’s new decis­i­on-making prac­ti­ce on Octo­ber 6, 2025, with a first judgment that has beco­me final.

This con­cerns the ruling of Octo­ber 6, 2025, in the case of “Pfar­rer­check,” in which the Fede­ral Admi­ni­stra­ti­ve Court upheld a ruling by the Fede­ral Data Pro­tec­tion Com­mis­sio­ner (EDÖB) — name­ly, the pro­hi­bi­ti­on on publi­shing cont­act infor­ma­ti­on for cler­gy wit­hout their con­sent and the order to dele­te such infor­ma­ti­on within 40 days. The court also upheld the fee based on the actu­al time spent and the anony­mizati­on of the records in the con­text of access to the case file.

Howe­ver, to say that super­vi­so­ry prac­ti­ce has thus been con­so­li­da­ted is a bold state­ment, given that the Fede­ral Admi­ni­stra­ti­ve Court ruled against the FDPIC with Judgment in the “Apfel­ki­ste” Case had found a serious vio­la­ti­on of pro­ce­du­ral rights. The con­so­li­da­ti­on is likely to take some time.

To date, it has not been cla­ri­fi­ed in court whe­ther the EDÖB’s publi­ca­ti­on prac­ti­ce — name­ly, the stan­dard pro­ce­du­re of publi­shing decis­i­ons while iden­ti­fy­ing the addres­see by name — is con­si­stent with the prin­ci­ples of the rule of law. Both the legal basis pro­vi­ded by Art. 57(2) of the Data Pro­tec­tion Act (DSG) and the prin­ci­ple of pro­por­tio­na­li­ty requi­re, in any case, a balan­cing of the public’s inte­rest in infor­ma­ti­on regar­ding the dis­clo­sure of the recipient’s name against the recipient’s inte­rest in con­fi­den­tia­li­ty — a balan­cing that is not reflec­ted in the EDÖB’s publi­ca­ti­on decis­i­ons. It is also striking that in cases of „vol­un­t­a­ry“ com­pli­ance with low-thres­hold inter­ven­ti­ons (e.g.,. here) no names are men­tio­ned, whe­re­as they are in offi­ci­al orders. This effec­tively turns the­se low-thres­hold inter­ven­ti­ons into coer­ci­ve mea­su­res wit­hout a legal basis. In any case, the high „suc­cess rate“ of the­se inter­ven­ti­ons can likely be explai­ned in part not by spon­ta­neous com­pli­ance, but by the fear of repu­ta­tio­nal dama­ge resul­ting from an inve­sti­ga­ti­on and an order.

Many com­plaints, few for­mal super­vi­so­ry actions

The num­ber of com­plaints recei­ved more than dou­bled to 2,447. Of the­se, 2,347 were direc­ted against pri­va­te indi­vi­du­als and only about 100 against fede­ral aut­ho­ri­ties. 2,210 of the­se were pro­ce­s­sed, while 237 remain­ed pen­ding. This volu­me resul­ted in 156 low-thres­hold inter­ven­ti­ons, 22 preli­mi­na­ry inve­sti­ga­ti­ons, and 9 for­mal inve­sti­ga­ti­ons, 6 of which were initia­ted during the report­ing year.

The ad view­er­ship ratings are the­r­e­fo­re rough­ly as follows:

  • Low-thres­hold inter­ven­ti­ons: 6%
  • Preli­mi­na­ry Inve­sti­ga­ti­ons: 1%
  • for­mal inve­sti­ga­ti­ons: 0.36%

This speaks to the EDÖB’s sound judgment and makes it clear what also applies to requests for infor­ma­ti­on: As a rule, the­se cases do not invol­ve data pro­tec­tion con­cerns (at least unless mul­ti­ple com­plaints are filed against the same company).

For DSG mat­ters, 32 full-time posi­ti­ons will be available in 2026, one fewer than in 2025. The workload is dis­tri­bu­ted among

  • Con­sul­ting (49.7 %)
  • Super­vi­si­on (21.5 %)
  • Infor­ma­ti­on (17 %) and
  • Legis­la­ti­on (11.8 %).

The super­vi­so­ry share has risen slight­ly com­pared to the pre­vious year (20.3 %).

Legal Pro­ce­e­dings Against Pri­va­te Indi­vi­du­als: Banks, Debt Coll­ec­tion Agen­ci­es, Cre­dit Bureaus

Super­vi­si­on focu­ses on pri­va­te enti­ties, with a par­ti­cu­lar empha­sis on finan­cial ser­vice pro­vi­ders and the right to access information:

  • Against Post­Fi­nan­ce The FDPIC ruled that expli­cit con­sent must be obtai­ned when crea­ting voice­prints for authen­ti­ca­ti­on via voice reco­gni­ti­on, and that voice­prints must be dele­ted if such con­sent is not obtai­ned (see here). Post­Fi­nan­ce filed an appeal against the ruling and the plan­ned publi­ca­ti­on. As of the report’s publi­ca­ti­on dead­line, both pro­ce­e­dings were appar­ent­ly still pending.
  • Against Cem­bra Money Bank In Janu­ary 2025, the EDÖB con­clu­ded an inve­sti­ga­ti­on into the hand­ling of requests for infor­ma­ti­on. Cem­bra had not filed an appeal against the decision.
  • Against Debt Coll­ec­tion Team The FDPIC orde­red that the publi­ca­ti­on of per­so­nal data of alle­ged debtors on the Inter­net be dis­con­tin­ued and that any data alre­a­dy published be deleted.
  • The EDÖB laun­ched an inve­sti­ga­ti­on into an unna­med cre­dit report­ing agen­cy to deter­mi­ne whe­ther data deri­ved from cre­dit reports may be dis­c­lo­sed to third par­ties for mar­ke­ting pur­po­ses and whe­ther the agency’s hand­ling of requests for infor­ma­ti­on and dele­ti­on is lawful.
  • In one case, in which Add Con­ti GmbH, the FDPIC filed a cri­mi­nal com­plaint with the St. Gal­len Public Prosecutor’s Office for vio­la­ti­on of the duty to cooperate.

AI and Biometrics

On March 3, 2026, fol­lo­wing an infor­mal preli­mi­na­ry assess­ment, the FDPIC laun­ched an inve­sti­ga­ti­on into a Swiss com­pa­ny that offers digi­tal iden­ti­ty veri­fi­ca­ti­on and AI-based age iden­ti­fi­ca­ti­on ser­vices and uses the bio­me­tric data coll­ec­ted for iden­ti­ty veri­fi­ca­ti­on to train its AI. The inve­sti­ga­ti­on is exami­ning whe­ther the AI-based pro­ce­s­sing ope­ra­ti­ons com­ply with data pro­ce­s­sing prin­ci­ples and whe­ther the rights of data sub­jects are being upheld. The inve­sti­ga­ti­on was appar­ent­ly trig­ge­red by insuf­fi­ci­ent respon­ses regar­ding the hand­ling of data sub­ject requests.

Right to Infor­ma­ti­on for the Pur­po­se of Obtai­ning Evidence

The EDÖB once again recei­ved num­e­rous com­plaints from indi­vi­du­als who were unable to access their accounts with social media pro­vi­ders, but found no vio­la­ti­on of the right to infor­ma­ti­on. Whe­ther ope­ra­tors and users com­plied with the terms of ser­vice is a mat­ter of civil law. The right of access ser­ves exclu­si­ve­ly the pur­po­se of infor­ma­tio­nal self-deter­mi­na­ti­on and is not a tool for gathe­ring evi­dence in civil or cri­mi­nal mat­ters; nor does it cover data belon­ging to third par­ties, such as alle­ged hackers. At the same time, the EDÖB notes that pro­vi­ders must veri­fy users’ iden­ti­ties and refu­se to dis­c­lo­se infor­ma­ti­on if account owner­ship can­not be proven.

Data secu­ri­ty breaches

The num­ber of repor­ted data brea­ches rose to 484 (pre­vious year: 363). The increa­se is almost enti­re­ly due to vol­un­t­a­ry reports, which rose from 26 to 141, while man­da­to­ry reports remain­ed con­stant. The rea­son is said to be an adjust­ment to the FDPIC Gui­de­lines on the Report­ing of Data Brea­ches in which the FDPIC expli­ci­t­ly points out the pos­si­bi­li­ty of vol­un­t­a­ry reports. In addi­ti­on, the num­ber of preli­mi­na­ry reports is also increasing.

Prin­ci­ple of publicity

To mark the anni­ver­sa­ry of the BGÖ, the report records 203 requests for media­ti­on in 2025 — one more than the pre­vious year. The actu­al increa­se in casel­oad is attri­bu­ta­ble to the num­ber of requests for access to infor­ma­ti­on sub­mit­ted to the fede­ral admi­ni­stra­ti­on, which has more than tri­pled over the past ten years. Most requests for media­ti­on came from media out­lets (84) and pri­va­te indi­vi­du­als (53). In 1,030 cases of com­ple­te or par­ti­al deni­al of access, a request for media­ti­on was filed in 20%; 207 cases were resol­ved, and an agree­ment was rea­ched in 98 of them.

More points

The acti­vi­ty report con­ta­ins addi­tio­nal notes and obser­va­tions, some of which are brief­ly high­ligh­ted below (more or less fol­lo­wing the report’s structure):

Digi­tizati­on

  • Dash­cams: Accor­ding to the EDÖB, con­ti­nuous dash­cam recor­dings vio­la­te the prin­ci­ples of the DSG becau­se their pur­po­se and legal basis are not suf­fi­ci­ent­ly defi­ned. Event-trig­ge­red systems — which, for exam­p­le, record only during emer­gen­cy bra­king, sud­den move­ment, or jolts, and quick­ly dele­te unneces­sa­ry recor­dings — can be ope­ra­ted in com­pli­ance with the DSG.
  • M365 and the Cloud in the Fede­ral Admi­ni­stra­ti­on: During the Fede­ral Administration’s migra­ti­on to Micro­soft 365 as part of the CEBA pro­ject, the FDPIC hel­ped ensu­re that GEVER files, the con­tents of Out­look mail­bo­xes, and par­ti­cu­lar­ly sen­si­ti­ve per­so­nal data and per­so­na­li­ty pro­files con­ti­n­ue to be pro­ce­s­sed in the Fede­ral Administration’s data cen­ters, on-pre­mi­ses rather than in the cloud. It also requi­res a pre­cise descrip­ti­on of high risks and risk-miti­ga­ti­on mea­su­res in the Data Pro­tec­tion Impact Assess­ment (DPIA). Fur­ther­mo­re, the Office wel­co­mes the fact that the Fede­ral Chan­cel­lery is exami­ning open-source alter­na­ti­ves to M365 that can be deployed in the medi­um term as part of the BOSS project.
  • Secon­da­ry Use of Per­so­nal Data. To the Moti­on 22.3890 (Frame­work Act on the Secon­da­ry Use of Data) The FDPIC sees no need for new regu­la­ti­ons under data pro­tec­tion law. The DSG alre­a­dy per­mits secon­da­ry use, pro­vi­ded that the requi­re­ments of Art. 31 and Art. 39 of the DSG are met. In par­ti­cu­lar, a chan­ge in pur­po­se may be justi­fi­ed for non-per­so­nal pur­po­ses such as rese­arch, plan­ning, or statistics.

Arti­fi­ci­al intelligence

  • Tech­no­lo­gy-neu­tral DSG: The EDÖB empha­si­zes that the DSG is worded in a tech­no­lo­gy-neu­tral man­ner and applies to AI-sup­port­ed data processing.
  • Go to AI Con­ven­ti­on of the Coun­cil of Euro­pe The FDPIC sup­ports the Fede­ral Council’s approach of regu­la­ting are­as rele­vant to fun­da­men­tal rights (inclu­ding data pro­tec­tion) in a gene­ral man­ner and sup­ple­men­ting them with sec­tor-spe­ci­fic pro­vi­si­ons as nee­ded (if this remains the case).
  • Fede­ral Govern­ment-Owned AI Systems: The FDPIC con­siders fede­ral­ly owned AI systems to be neces­sa­ry for the fede­ral admi­ni­stra­ti­on to com­ply with data pro­tec­tion and infor­ma­ti­on secu­ri­ty requi­re­ments. It is cru­cial that prompts and the data they con­tain be pro­ce­s­sed local­ly and made acce­s­si­ble only to aut­ho­ri­zed orga­nizatio­nal units. Com­mer­cial LLMs such as Copi­lot or ChatGPT, on the other hand, pose a data secu­ri­ty risk due to the fact that data is stored — at least tem­po­r­a­ri­ly — in the provider’s cloud.
  • Smart Glas­ses: “Smart” glas­ses rai­se que­sti­ons about trans­pa­ren­cy. Auto­ma­tic light signals are not neces­s­a­ri­ly suf­fi­ci­ent for this pur­po­se. In addi­ti­on, the FDPIC reminds users that the covert use of recor­ding devices to obser­ve or record pri­va­te acti­vi­ties may be a cri­mi­nal offen­se. Pri­va­te users must ful­fill their obli­ga­ti­ons to pro­vi­de infor­ma­ti­on and, depen­ding on the inten­ded use, obtain the con­sent of affec­ted third parties.
  • AI Trai­ning Using Bio­me­tric Data: On March 3, 2026, the EDÖB laun­ched an inve­sti­ga­ti­on into a Swiss com­pa­ny that offers digi­tal iden­ti­ty veri­fi­ca­ti­on and AI-based age iden­ti­fi­ca­ti­on and uses bio­me­tric data from the iden­ti­ty veri­fi­ca­ti­on pro­cess to train its AI. The inve­sti­ga­ti­on focu­ses on com­pli­ance with the prin­ci­ples of trans­pa­ren­cy, pro­por­tio­na­li­ty, good faith, and pur­po­se limi­ta­ti­on, as well as the imple­men­ta­ti­on of data sub­jects’ rights.

Health

  • Elec­tro­nic Health Record: The elec­tro­nic pati­ent record is to be repla­ced by the elec­tro­nic health record. The Fede­ral Coun­cil sub­mit­ted the rela­ted mes­sa­ge to Par­lia­ment in Novem­ber 2025; the law is expec­ted to take effect in 2030. The E‑GD is to be auto­ma­ti­cal­ly and free of char­ge crea­ted for indi­vi­du­als resi­ding in Switz­er­land, with an opt-out opti­on available. The FDPIC demands a genui­ne, uni­form, and infor­mal right to object — inclu­ding ana­log solu­ti­ons — as well as inde­pen­dent manage­ment of access rights, access to logs, and high stan­dards for data pro­tec­tion and data secu­ri­ty. Access by health apps has been rest­ric­ted at the FDPIC’s request. He wel­co­mes the reten­ti­on of a sec­tor-spe­ci­fic iden­ti­fi­ca­ti­on num­ber instead of the AHV num­ber, as it redu­ces the risk of lin­king to other data­ba­ses.  
  • TARDOC and out­pa­ti­ent flat rates: The new fee sche­du­le for out­pa­ti­ent medi­cal tre­at­ments has been in effect sin­ce Janu­ary 1, 2026, and replaces TARMED. It con­sists of TARDOC, a fee-for-ser­vice sche­du­le, and out­pa­ti­ent flat rates. The EDÖB points out that the­re are still unre­sol­ved tech­ni­cal and legal issues, par­ti­cu­lar­ly regar­ding the trans­mis­si­on of dia­gno­stic data. Such data must not exce­ed what is neces­sa­ry for invoice verification.
  • Spi­Ges: Spi­Ges stands for «Inpa­ti­ent Hos­pi­tal Care» and is a Digi­S­an­té pro­ject aimed at imple­men­ting the “once-only” prin­ci­ple in the inpa­ti­ent hos­pi­tal sec­tor. Hos­pi­tal data should be coll­ec­ted once and then made available for various legal pur­po­ses, inclu­ding by fede­ral agen­ci­es, can­tons, insu­r­ers, Swiss­DRG AG, and ANQ. The FDPIC requi­res that each reci­pi­ent have access only to the data neces­sa­ry for its legal duties. Per­so­nal data must be anony­mi­zed befo­re trans­mis­si­on and limi­t­ed to the neces­sa­ry minimum.

Traf­fic

  • SBB Body Cams: Regar­ding the plan­ned use of body came­ras by train atten­dants, the EDÖB empha­si­zes the prin­ci­ple of lega­li­ty. Video sur­veil­lan­ce con­sti­tu­tes a serious inf­rin­ge­ment of fun­da­men­tal rights; its essen­ti­al ele­ments must the­r­e­fo­re be regu­la­ted by sta­tu­to­ry law and, as far as pos­si­ble, in a tech­no­lo­gy-neu­tral man­ner. In the EDÖB’s view, the cur­rent legal frame­work is insuf­fi­ci­ent. SBB has appar­ent­ly agreed to post­po­ne imple­men­ta­ti­on. On Febru­ary 24, 2026, the EDÖB laun­ched an inve­sti­ga­ti­on into BLT Basel­land Trans­port regar­ding body came­ras that were alre­a­dy in use.
  • Facial Reco­gni­ti­on at Zurich Air­port: Flug­ha­fen Zürich AG is con­side­red a fede­ral agen­cy by vir­tue of its ope­ra­ting licen­se. In the opi­ni­on of the EDÖB, the­re is no for­mal legal basis for a pilot pro­ject on facial reco­gni­ti­on during boar­ding pass checks. Flug­ha­fen Zürich AG will not pro­ce­ed with the pro­ject until the neces­sa­ry legal basis comes into effect.

Prin­ci­ple of publicity

  • Oral Media­ti­on: In 2025, 97 media­ti­on pro­ce­e­dings were con­duc­ted; agree­ments were rea­ched in 71 cases, repre­sen­ting a suc­cess rate of 73 per­cent. A total of 203 media­ti­on requests were filed, and 49 recom­men­da­ti­ons were issued. The high sett­le­ment rate speaks in favor of this mecha­nism, even though the stan­dard time limits remain a problem.
  • Misu­se of the BGÖ: Of par­ti­cu­lar inte­rest is the FDPIC’s very valid cri­ti­cism of the incre­a­sing use of the BGÖ for pur­po­ses unre­la­ted to its inten­ded scope. It has obser­ved an increa­se in attempts to use the BGÖ to resol­ve legal issues or to obtain admi­ni­stra­ti­ve decis­i­ons in cases whe­re the main issue is no lon­ger access to offi­ci­al docu­ments. It cites the low bar­riers to ent­ry and the fact that the con­ci­lia­ti­on pro­ce­du­re is free of char­ge as rea­sons for this.
  • For­ma­lism and Par­ti­ci­pa­ti­on: The EDÖB cri­ti­ci­zes the gro­wing ten­den­cy toward for­ma­lism. In some cases, aut­ho­ri­ties did not cla­ri­fy key preli­mi­na­ry issues — such as power of att­or­ney, stan­ding to sue, or eli­gi­bi­li­ty to file a peti­ti­on — until the con­ci­lia­ti­on pro­ce­e­dings. On the other hand, the EDÖB is incre­a­sing­ly con­fron­ted with pro­ce­du­ral moti­ons based on for­ma­li­stic grounds.
  • Gaps in the Scope of Spe­cial Laws: The EDÖB defi­nes “gaps in appli­ca­bi­li­ty” as excep­ti­ons under spe­cial laws pur­su­ant to Art. 4 of the Fede­ral Act on Access to Govern­ment Infor­ma­ti­on (BGÖ), i.e., pro­vi­si­ons in other fede­ral laws that clas­si­fy cer­tain infor­ma­ti­on as con­fi­den­ti­al or estab­lish con­di­ti­ons for access that dif­fer from tho­se of the BGÖ. The EDÖB lists 13 exi­sting and 11 plan­ned such gaps in appli­ca­bi­li­ty. Accor­ding to the EDÖB, the exi­sting excep­ti­ons under the BGÖ — in par­ti­cu­lar Artic­les 7 and 9 of the BGÖ con­cer­ning the pro­tec­tion of trade secrets, pri­va­cy, and data of legal enti­ties — should, in prin­ci­ple, be suf­fi­ci­ent. Howe­ver, this view must be con­te­sted to the ext­ent that trade secrets are effec­tively ren­de­red meanin­g­less by the very strict enforce­ment practices.
  • Ero­si­on of the Prin­ci­ple of Public Access. The FDPIC con­siders excep­ti­ons for super­vi­so­ry, con­trol, audit, and inspec­tion aut­ho­ri­ties to be pro­ble­ma­tic. It is pre­cis­e­ly in the­se are­as that the­re is a heigh­ten­ed public inte­rest in trans­pa­ren­cy. If super­vi­so­ry acti­vi­ties are exclu­ded from the scope of the Fede­ral Act on Access to Govern­ment Infor­ma­ti­on (BGÖ), the prin­ci­ple of public access will be ero­ded. The EDÖB the­r­e­fo­re intends to con­ti­n­ue oppo­sing new spe­cial pro­vi­si­ons in con­sul­ta­ti­ons with govern­ment agencies.