- The guidelines clarify reporting and information obligations in accordance with Art. 24 FADP: reporting is mandatory in the case of “high risk”, voluntary reports are possible, deadline “as soon as possible”.
- The FDPIC may examine notifications, issue information orders and report publicly; this is subject to the FADP and raises data protection and publicity issues.
On February 7, 2025, the FDPIC published an eight-page “Guideline on reporting data security breaches and informing data subjects in accordance with Art. 24 FADP” dated February 6, 2025:
The guidelines concern the obligations in the event of a breach of data security within the meaning of Art. 5 lit. h FADP, i.e. only if personal data is affected. Other reporting obligations, e.g. according to Art. 29 para. 2 FINMASAafter the revised version of the ISG etc. are not covered by the guidelines.
Information for those responsible
Subject of the notificationThe guidelines remain very brief here and refer to Art. 15 DSV.
Obligation to register and right to register:
- The FDPIC takes Voluntary reports in the case of lower risks, especially if there may be media interest (which, however, is generally not advisable, except in cases where there is a risk of media publicity anyway, because the FDPIC is subject to the FSC [see below] and the media can, and regularly do, demand further information, and because the FDPIC is not responsible for the publication of such information. is very generous). Unfortunately, voluntary reports can still not be submitted via the FDPIC breach notification form which is why at least such reports should be made in another form.
- A Obligation to report exists in the case of “high risks”. Because the FADP does not define risk levels uniformly, Art. 24 FADP must be interpreted autonomously, so to speak. The guidelines leave it open as to when a risk is high in this sense; they only contain information on how the risk is to be determined (but not when it becomes high):
- The following should not be taken into account Measures that are only taken after the injury become effective. However, “in previous practice”, the FDPIC has also been able to take into account immediate measures that took effect before the notification. This still seems to apply, even if the guidelines lack a clear statement in this regard. However, the fact that such measures are relevant is not only due to the fact that the FDPIC refers to his “previous” practice, but does not clearly deviate from it, but also due to the normative purpose of the notification obligation. It is therefore probably correct to relate the requirement of high risk to the time of notification and not or not only to the occurrence of the breach. “In case of doubt”, however, it is necessary to report and not to wait.
- Severity of the consequences: This is to be determined depending on
- the protectability of the data;
- the nature and circumstances of the injury;
- of the circle and the motives of unauthorized third parties;
- the effort involved in determining the data subjects (disclosure of data that is anonymous to recipients – e.g. effectively encrypted – does not fall under Art. 24 FADP, as the FDPIC rightly points out);
- the amount of data and the processing time (why the latter is unclear and questionable);
- the possible non-material and economic disadvantages;
- the vulnerability of those affected; and
- the total amount of persons and data concerned.
- Probability of occurrence: This is an assessment, which is why the person responsible must not wait until there is certainty.
Reporting deadlineReportable injuries must be reported as quickly as possible, in stages if necessary. The reporting portal can be used, but this is not mandatory, and the form also asks for non-reportable information, which can then become public.
Procedure for a notificationIf a report of an injury is received,
- the FDPIC shall summarily review whether the measures taken or planned appear appropriate to protect the data subjects. If necessary, the FDPIC requests that the information be clarified or other measures be taken, and the FDPIC may contact the controller so that the incident is documented (e.g. by backing up log data);
- he checks whether the persons concerned are adequately informed, and the FDPIC can inform the public about his findings and orders (a problem because it means that even sensible reports tend to be omitted, and because the FDPIC’s publication practice goes enormously far).
The publicThe FDPIC expressly points out that the content of reports is subject to the FADP.
SanctionsViolation of the obligation to notify the FDPIC is not sanctioned (and does not constitute a violation of personality rights). Only a violation of an order of the FDPIC would be punishable.
Information for those affected
According to Art. 24 para. 4 FADP, the controller must inform data subjects about a data breach if the information is necessary to protect the data subjects (or if the FDPIC so orders):
TriggerNotification is necessary to protect the data subjects (contrary to some of the literature, but in line with the BSK: even if there is no obligation to notify the FDPIC, i.e. the risk is not high in this sense),
- if these Measures for self-protection (e.g. changing passwords, blocking credit cards, increased vigilance due to the risk of phishing) or if those affected “in ignorance of the situation […] expect the worst”, even if the risk may be low. However, the FDPIC does not provide any further justification for the fact that information may be legally mandatory in such a situation; the message says nothing to this effect. It is likely to be a rare case; however, the FDPIC may order a notification in this case;
- when the FDPIC orders a communication. According to the guidelines, he can do this not only when it is necessary to protect those affected, but also because the media are interested in it:
However, it can also demand it because, in its opinion, due to the large number of people affected or media coverage, a there is a public interest inthat those responsible are aware of the high number of people affected and therefore indirectly also a broad public in a suitable manner with more detailed information on the consequences of a data breach.
This must be rejected. The FDPIC’s order is intended as a measure to encourage the controller to comply with the duty of notification; this is clear both from the structure of the law and the purpose of the law as well as the message. It also follows from Art. 57 para. 2 FADP: The FDPIC can – if there is actually sufficient public interest – inform the public about his “findings and decisions”. However, the FDPIC can certainly not decree a measure only to subsequently report on it, which is what his position amounts to. The FDPIC’s task is to supervise the application of the FADP, which must be interpreted in a reasonable manner (Art. 4 para. 1 FADP), and not to assist the media or act as a medium himself. An order to notify data subjects for this reason would therefore be unlawful.
MannerAccording to Art. 15 para. 3 GDPR, data subjects must be informed in “plain and intelligible language” and with certain minimum details, but there are no formal requirements. By way of exception, a public announcement may suffice, provided that this ensures that the individual data subjects are informed.