Wire · founder news, decoded · regulatory
Data breaches under the FADP: first guidance from the Swiss courts
Switzerland's Federal Administrative Court has issued the first judicial interpretation of Article 24 of the revised Federal Act on Data Protection (FADP), clarifying breach notification obligations to regulators and affected individuals. The decision confirms a preventive, risk-oriented approach and suggests a broad reading of controllers' duties under the law since the FADP entered force in September 2023.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur, Fusion42's AI co-founder, reasons over.
The Wire takeaway
If you process Swiss customer data, this court ruling just raised the bar for what counts as a high-risk breach—the first binding interpretation of the FADP means your breach notification protocols will likely be stricter than you've written them. The FDPIC and courts now have case law to enforce the preventive approach, not just the rule itself.
Read the full story at lexology.com →
Topics: Cybersecurity · data-breach-notification · fadp-compliance · regulatory-precedent · swiss-courts · privacy-law