Take-Aways (AI)
  • The gui­de­lines cla­ri­fy report­ing and infor­ma­ti­on obli­ga­ti­ons in accordance with Art. 24 FADP: report­ing is man­da­to­ry in the case of “high risk”, vol­un­t­a­ry reports are pos­si­ble, dead­line “as soon as possible”.
  • The FDPIC may exami­ne noti­fi­ca­ti­ons, issue infor­ma­ti­on orders and report publicly; this is sub­ject to the FADP and rai­ses data pro­tec­tion and publi­ci­ty issues.

On Febru­ary 7, 2025, the FDPIC published an eight-page “Gui­de­line on report­ing data secu­ri­ty brea­ches and informing data sub­jects in accordance with Art. 24 FADP” dated Febru­ary 6, 2025:

The gui­de­lines con­cern the obli­ga­ti­ons in the event of a breach of data secu­ri­ty within the mea­ning of Art. 5 lit. h FADP, i.e. only if per­so­nal data is affec­ted. Other report­ing obli­ga­ti­ons, e.g. accor­ding to Art. 29 para. 2 FINMASAafter the revi­sed ver­si­on of the ISG etc. are not cover­ed by the guidelines.

Infor­ma­ti­on for tho­se responsible

Sub­ject of the noti­fi­ca­ti­onThe gui­de­lines remain very brief here and refer to Art. 15 DSV.

Obli­ga­ti­on to regi­ster and right to regi­ster:

  • The FDPIC takes Vol­un­t­a­ry reports in the case of lower risks, espe­ci­al­ly if the­re may be media inte­rest (which, howe­ver, is gene­ral­ly not advi­sa­ble, except in cases whe­re the­re is a risk of media publi­ci­ty any­way, becau­se the FDPIC is sub­ject to the FSC [see below] and the media can, and regu­lar­ly do, demand fur­ther infor­ma­ti­on, and becau­se the FDPIC is not respon­si­ble for the publi­ca­ti­on of such infor­ma­ti­on. is very gene­rous). Unfort­u­n­a­te­ly, vol­un­t­a­ry reports can still not be sub­mit­ted via the FDPIC breach noti­fi­ca­ti­on form which is why at least such reports should be made in ano­ther form.
  • A Obli­ga­ti­on to report exists in the case of “high risks”. Becau­se the FADP does not defi­ne risk levels uni­form­ly, Art. 24 FADP must be inter­pre­ted auto­no­mously, so to speak. The gui­de­lines lea­ve it open as to when a risk is high in this sen­se; they only con­tain infor­ma­ti­on on how the risk is to be deter­mi­ned (but not when it beco­mes high): 
    • The fol­lo­wing should not be taken into account Mea­su­res that are only taken after the inju­ry beco­me effec­ti­ve. Howe­ver, “in pre­vious prac­ti­ce”, the FDPIC has also been able to take into account imme­dia­te mea­su­res that took effect befo­re the noti­fi­ca­ti­on. This still seems to app­ly, even if the gui­de­lines lack a clear state­ment in this regard. Howe­ver, the fact that such mea­su­res are rele­vant is not only due to the fact that the FDPIC refers to his “pre­vious” prac­ti­ce, but does not cle­ar­ly devia­te from it, but also due to the nor­ma­ti­ve pur­po­se of the noti­fi­ca­ti­on obli­ga­ti­on. It is the­r­e­fo­re pro­ba­b­ly cor­rect to rela­te the requi­re­ment of high risk to the time of noti­fi­ca­ti­on and not or not only to the occur­rence of the breach. “In case of doubt”, howe­ver, it is neces­sa­ry to report and not to wait.
    • Seve­ri­ty of the con­se­quen­ces: This is to be deter­mi­ned depen­ding on 
      • the pro­tec­ta­bi­li­ty of the data;
      • the natu­re and cir­cum­stances of the injury;
      • of the cir­cle and the moti­ves of unaut­ho­ri­zed third parties;
      • the effort invol­ved in deter­mi­ning the data sub­jects (dis­clo­sure of data that is anony­mous to reci­pi­en­ts – e.g. effec­tively encrypt­ed – does not fall under Art. 24 FADP, as the FDPIC right­ly points out);
      • the amount of data and the pro­ce­s­sing time (why the lat­ter is unclear and questionable);
      • the pos­si­ble non-mate­ri­al and eco­no­mic disadvantages;
      • the vul­nerabi­li­ty of tho­se affec­ted; and
      • the total amount of per­sons and data concerned.
    • Pro­ba­bi­li­ty of occur­rence: This is an assess­ment, which is why the per­son respon­si­ble must not wait until the­re is certainty.

Report­ing dead­lineRepor­ta­ble inju­ries must be repor­ted as quick­ly as pos­si­ble, in stages if neces­sa­ry. The report­ing por­tal can be used, but this is not man­da­to­ry, and the form also asks for non-repor­ta­ble infor­ma­ti­on, which can then beco­me public.

Pro­ce­du­re for a noti­fi­ca­ti­onIf a report of an inju­ry is received,

  • the FDPIC shall sum­ma­ri­ly review whe­ther the mea­su­res taken or plan­ned appear appro­pria­te to pro­tect the data sub­jects. If neces­sa­ry, the FDPIC requests that the infor­ma­ti­on be cla­ri­fi­ed or other mea­su­res be taken, and the FDPIC may cont­act the con­trol­ler so that the inci­dent is docu­men­ted (e.g. by back­ing up log data);
  • he checks whe­ther the per­sons con­cer­ned are ade­qua­te­ly infor­med, and the FDPIC can inform the public about his fin­dings and orders (a pro­blem becau­se it means that even sen­si­ble reports tend to be omit­ted, and becau­se the FDPIC’s publi­ca­ti­on prac­ti­ce goes enorm­ously far).

The publicThe FDPIC express­ly points out that the con­tent of reports is sub­ject to the FADP.

Sanc­tionsVio­la­ti­on of the obli­ga­ti­on to noti­fy the FDPIC is not sanc­tion­ed (and does not con­sti­tu­te a vio­la­ti­on of per­so­na­li­ty rights). Only a vio­la­ti­on of an order of the FDPIC would be punishable.

Infor­ma­ti­on for tho­se affected

Accor­ding to Art. 24 para. 4 FADP, the con­trol­ler must inform data sub­jects about a data breach if the infor­ma­ti­on is neces­sa­ry to pro­tect the data sub­jects (or if the FDPIC so orders):

Trig­gerNoti­fi­ca­ti­on is neces­sa­ry to pro­tect the data sub­jects (con­tra­ry to some of the lite­ra­tu­re, but in line with the BSK: even if the­re is no obli­ga­ti­on to noti­fy the FDPIC, i.e. the risk is not high in this sense),

  • if the­se Mea­su­res for self-pro­tec­tion (e.g. chan­ging pass­words, blocking cre­dit cards, increa­sed vigi­lan­ce due to the risk of phis­hing) or if tho­se affec­ted “in igno­rance of the situa­ti­on […] expect the worst”, even if the risk may be low. Howe­ver, the FDPIC does not pro­vi­de any fur­ther justi­fi­ca­ti­on for the fact that infor­ma­ti­on may be legal­ly man­da­to­ry in such a situa­ti­on; the mes­sa­ge says not­hing to this effect. It is likely to be a rare case; howe­ver, the FDPIC may order a noti­fi­ca­ti­on in this case;
  • when the FDPIC orders a com­mu­ni­ca­ti­on. Accor­ding to the gui­de­lines, he can do this not only when it is neces­sa­ry to pro­tect tho­se affec­ted, but also becau­se the media are inte­re­sted in it:

    Howe­ver, it can also demand it becau­se, in its opi­ni­on, due to the lar­ge num­ber of peo­p­le affec­ted or media covera­ge, a the­re is a public inte­rest inthat tho­se respon­si­ble are awa­re of the high num­ber of peo­p­le affec­ted and the­r­e­fo­re indi­rect­ly also a broad public in a sui­ta­ble man­ner with more detail­ed infor­ma­ti­on on the con­se­quen­ces of a data breach.

    This must be rejec­ted. The FDPIC’s order is inten­ded as a mea­su­re to encou­ra­ge the con­trol­ler to com­ply with the duty of noti­fi­ca­ti­on; this is clear both from the struc­tu­re of the law and the pur­po­se of the law as well as the mes­sa­ge. It also fol­lows from Art. 57 para. 2 FADP: The FDPIC can – if the­re is actual­ly suf­fi­ci­ent public inte­rest – inform the public about his “fin­dings and decis­i­ons”. Howe­ver, the FDPIC can cer­tain­ly not decree a mea­su­re only to sub­se­quent­ly report on it, which is what his posi­ti­on amounts to. The FDPIC’s task is to super­vi­se the appli­ca­ti­on of the FADP, which must be inter­pre­ted in a rea­sonable man­ner (Art. 4 para. 1 FADP), and not to assist the media or act as a medi­um hims­elf. An order to noti­fy data sub­jects for this rea­son would the­r­e­fo­re be unlawful.

Man­nerAccor­ding to Art. 15 para. 3 GDPR, data sub­jects must be infor­med in “plain and intel­li­gi­ble lan­guage” and with cer­tain mini­mum details, but the­re are no for­mal requi­re­ments. By way of excep­ti­on, a public announce­ment may suf­fice, pro­vi­ded that this ensu­res that the indi­vi­du­al data sub­jects are informed.