← Back

Wire · regulatory

Data breaches under the FADP: first guidance from the Swiss courts

Published

17 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

Switzerland

Source

Read at lexology.com

Verified

Fusion42 · 17 July 2026 · Fusion42 review

Switzerland's Federal Administrative Court has issued the first judicial interpretation of Article 24 of the revised Federal Act on Data Protection (FADP), clarifying breach notification obligations to regulators and affected individuals. The decision confirms a preventive, risk-oriented approach and suggests a broad reading of controllers' duties under the law since the FADP entered force in September 2023.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If you process Swiss customer data, this court ruling just raised the bar for what counts as a high-risk breach—the first binding interpretation of the FADP means your breach notification protocols will likely be stricter than you've written them. The FDPIC and courts now have case law to enforce the preventive approach, not just the rule itself.

Coverage

1 source · 17 Jul 2026

Related on Wire

Topics

Cybersecuritydata-breach-notificationfadp-complianceregulatory-precedentswiss-courtsprivacy-law