6 min read
A data breach in a small business: what Swiss law provides
What a data security breach is, when the Swiss FADP provides for a report to the FDPIC, what goes into it and when affected people are informed.

At a fiduciary office in Solothurn, an employee sends a client’s payroll list on a Friday afternoon. The address in the field belongs to another client with a similar name. He notices five minutes later. The list contains the names, AHV numbers, salaries and bank details of twelve employees.
What now? Most small businesses rarely face a moment like this, and when they do, they are unprepared. The Swiss Federal Act on Data Protection (FADP, in German DSG) sets out what is provided for in this situation. Anyone who has read the rules once, calmly, can decide faster and more clearly when it matters.
What a data security breach is
The FADP defines it as a breach of security that leads to personal data being accidentally or unlawfully lost, deleted, destroyed or altered, or disclosed or made accessible to unauthorised persons (Art. 5 let. h FADP).
The definition is broader than the picture of a hacker attack. It also covers:
- the misaddressed email with a customer list;
- the lost USB stick or the stolen laptop;
- the spreadsheet accidentally shared publicly;
- data deleted by mistake that cannot be restored.
The Federal Data Protection and Information Commissioner (FDPIC) notes in its guide that incidents affecting trade or professional secrets, but no personal data, do not fall under this provision.
When a report to the FDPIC is provided for
The controller reports to the FDPIC, as soon as possible, a data security breach that is likely to result in a high risk to the privacy or fundamental rights of the person concerned (Art. 24 para. 1 FADP). So not every mishap has to be reported. What matters is the likely high risk.
The FDPIC’s guide describes how this risk is assessed. Some of its criteria:
| Criterion | What the guide says |
|---|---|
| Type of data | With sensitive data, a high risk can be assumed in many cases; copies of ID documents or credit card details can also mean one |
| How easily people can be identified | A customer number alone weighs less than email addresses containing people’s names |
| Encryption | Effectively encrypted data counts as anonymous for unauthorised persons; the duty to report does not apply |
| Disadvantages for those affected | Identity theft, credit card fraud and damage to reputation point to serious consequences |
| Vulnerable people | Data of minors or people with disabilities can indicate serious consequences |
| Numbers | Many affected people alone do not establish a high risk |
On timing, the guide states: anyone who recognises a likely high risk may not wait for lengthy investigations that would confirm or rule it out beyond doubt. Immediate measures that demonstrably ruled out the consequences before the report can be taken into account; measures that are merely planned cannot.
What goes into the report
The Data Protection Ordinance lists what a report to the FDPIC must contain (Art. 15 para. 1 DPO):
- the type of breach;
- where possible, the time and duration;
- where possible, the categories and approximate number of personal data affected;
- where possible, the categories and approximate number of persons affected;
- the consequences, including any risks, for the persons concerned;
- which measures have been taken or are planned to remedy the defect and mitigate the consequences;
- the name and contact details of a contact person.
If not everything is known at once, the missing information is supplied as soon as possible (Art. 15 para. 2 DPO). According to the guide, the FDPIC’s reporting portal walks through these details, issues a confirmation of the time of the report and allows follow-up reports.
When affected people are informed
Reporting to the FDPIC and informing the people affected are two different things. The controller informs the person concerned if this is necessary for their protection or if the FDPIC requests it (Art. 24 para. 4 FADP).
The guide explains when such a need for protection can be assumed: when the people affected can or must do something themselves to avert harm — change a password, block a credit card, check account statements, recognise phishing emails. According to the guide, this duty does not depend on the high risk that triggers the report to the FDPIC.
The information is given in simple, understandable language and states at least the type of breach, the consequences, the measures taken or planned, and a contact person (Art. 15 para. 3 DPO). The FADP also provides for cases in which the information can be restricted, postponed or replaced by a public announcement (Art. 24 para. 5 FADP).
When a service provider has the breach
Many small businesses work with service providers: a cloud payroll program, accounting software, an IT support company. The FADP obliges the processor to report a data security breach to the controller as soon as possible (Art. 24 para. 3 FADP). The guide stresses that this covers every breach, regardless of risk. Reporting to the FDPIC and informing those affected, however, remain the controller’s job — the business whose data it is.
Documenting
Whether or not a report is made, the controller must document breaches. The documentation contains the facts, the effects and the measures taken (Art. 15 para. 4 DPO). Under this provision it must be kept for at least two years from the time of the report.
The first hours
In an emergency, it helps to have an order you do not have to invent on the spot. One possible sequence, derived from what the FADP, the ordinance and the guide require:
- Contain. Do what can be done immediately: ask the recipient to delete, block an account, withdraw access. According to the guide, such immediate measures can be taken into account if they demonstrably rule out or reduce the consequences.
- Record. What happened, when, which data, how many people? These details are needed for the documentation and any report.
- Assess. Judge, using the guide’s criteria, whether a high risk is likely — without waiting for certainty where doubt remains.
- Report and inform. If needed, via the reporting portal to the FDPIC; inform those affected if they can do something to protect themselves.
- Follow up. What can change so it does not happen again? Complete the documentation.
Being prepared
For a small business, preparation need not be elaborate. A sheet of paper in the binder is often enough:
- Who in the business decides whether to report and inform?
- Which service providers process personal data for us, and how do we reach them?
- Where is the FDPIC’s reporting portal, and what does it ask for?
- Which of our data is encrypted, and which is not?
The last question sounds technical but is central to the assessment: the guide names effective encryption as a circumstance in which the duty to report does not apply. A lost, encrypted laptop is a different situation from an unencrypted one.
For the fiduciary office in Solothurn, this means: payroll lists with AHV numbers and bank details sent to the wrong recipient — here the question of a high risk will need serious consideration. How it is answered in the individual case depends on the circumstances; the FDPIC’s guide is the best basis for it, and where there is uncertainty, a professional can help.
Sources
- 1.Bundesgesetz über den Datenschutz (DSG, SR 235.1) (checked on 25 September 2026)
- 2.Datenschutzverordnung (DSV, SR 235.11), Fassung in Kraft seit 15. September 2024 (checked on 25 September 2026)
- 3.EDÖB: Leitfaden betreffend die Meldung von Datensicherheitsverletzungen und Information der Betroffenen nach Art. 24 DSG (Version 1.2 vom 23. April 2025) (checked on 25 September 2026)
- 4.EDÖB: DataBreach (Meldeportal) (checked on 25 September 2026)
Follow our ideas
Look at our ideas and ask to be told once when one of them becomes an app. Or write to us – about an idea, about a task that deserves an app, or just to say hello.