Forms10 min read
Health data in a Swiss practice: what makes intake forms different
Registration and intake forms in Swiss practices: what the FADP says about health data, what the ordinance requires of security, and where professional secrecy sits.

A physiotherapy practice in Olten puts its registration sheet online. The page that used to sit on a clipboard at reception becomes a form: name, date of birth, address, health insurer, referring doctor, reason for referral, current medication, previous operations, and a box for “anything else we should know”. At the bottom, a tick box acknowledging the information notice.
Technically this is the same form as a music school’s term registration. Legally it is not. The difference is not that something sensitive arrives here by accident — that can happen in any free-text box. It is that the sensitive answers are the whole point of the form. An intake sheet containing no health data has failed at its job.
The category is named in the act
Art. 5 lit. c of the Federal Act on Data Protection (FADP) sets out an exhaustive list of what counts as sensitive personal data. Item 2 names “data on health, the intimate sphere or racial or ethnic origin”. The content of an intake sheet is therefore not a matter of interpretation but a case the act itself names.
The more interesting question is how far the category reaches inside a practice. In its guidance note on patient forms, the Federal Data Protection and Information Commissioner (FDPIC) states that in a health context the mere existence of a relationship with a therapist allows conclusions to be drawn about a person’s state of health — most clearly with specialists. The example given is an appointment with an oncologist. From this the FDPIC concludes that purely administrative exchanges, such as arranging an appointment, are also to be classified as sensitive.
The line between “the medical part” and “the administrative part” of a form therefore carries less weight than it appears to at first glance.
Consent is not the hook most people expect
Because sensitive data is involved, the natural assumption is that every form needs a consent declaration. The FDPIC describes the position differently. Its guidance note states that under the FADP consent is not a precondition for doctors to process patient data: data processed in the course of a medical service falls under the treatment contract, and health professionals are additionally required by law to carry out certain processing — in particular by cantonal health acts, for instance the duty to keep a patient file.
On the same account, consent becomes important mainly where data is disclosed: to a colleague, to a billing company, to a laboratory. And there the form prescribed by Art. 6 para. 7 lit. a FADP applies: consent to the processing of sensitive personal data must be express. Art. 6 para. 6 FADP adds that it is valid only if given voluntarily for one or more specific processing operations and after appropriate information.
What that rules out, the FDPIC describes in unusual detail. Blanket declarations and open-ended consent are excluded. Clauses drafted too vaguely to cover a general, advance disclosure of the patient file to third parties — other doctors, pharmacies, laboratories — without reference to a specific processing operation are called invalid. The same goes for advance consent to handing a possible debt collection case to a third-party firm, and for a clause allowing partner companies to use patient data to develop their digital offerings. On disclosure to a specialist, the FDPIC writes that consent should be obtained only once the question actually arises.
Which fields the FDPIC names
Proportionality is set out in Art. 6 para. 2 FADP; Art. 6 para. 3 FADP adds that personal data may only be collected for a specific purpose that is evident to the data subject. In the doctor–patient relationship that purpose is, in the FDPIC’s words, essentially the therapeutic treatment.
The guidance note becomes concrete here and names fields whose systematic collection is in principle not necessary: maiden name, marital status, nationality, work telephone number, occupation and the employer’s name. The qualification that follows immediately is what makes the sentence usable: collecting them is not thereby ruled out. If a patient’s occupation could be relevant to the consultation because it relates to their state of health — the example in the note is back pain — it may be asked. What is problematic is systematic collection; the individual case determines what is necessary.
That yields a test needing no legal knowledge: every field comes with a sentence explaining its connection to the treatment. The FDPIC puts it as a requirement on the practice itself — it must always be able to justify a given processing operation, and to explain the reason when it announces, as part of the duty to inform, that it collects particular data.
In this logic the free-text box is not the exception but the norm: for “anything else we should know”, open text is the professionally correct format. What distinguishes it from the comments box on a club registration is that nobody here is surprised by what turns up in it. The question therefore moves from the form to the filing — who sees the answer later, how long it stays, and whether it can be kept apart from the appointment calendar.
What the ordinance requires of security
Art. 8 FADP requires the controller and the processor to ensure data security appropriate to the risk through suitable technical and organisational measures, and leaves the minimum requirements to the Federal Council. They sit in the Data Protection Ordinance, and they are more concrete than the cross-reference suggests.
Art. 1 DPO requires the protection needs of the data to be determined, assessed among other things by the type of data processed. With health data that first step is already settled. Art. 2 DPO names four objectives: confidentiality (“accessible only to authorised persons”), availability, integrity and traceability. Art. 3 DPO fills them with controls, several of which touch a practice’s daily work directly:
| Control under Art. 3 DPO | What it touches in a practice |
|---|---|
| Access control | Authorised people see only the data they need for their tasks — reception, treatment, billing |
| Entry control | Who may enter the rooms and installations where data is processed |
| Transport control | Disclosure to the outside and the transport of data carriers |
| Restoration | That data becomes available again quickly after an incident |
| System security | Operating systems and applications kept at the current security level |
| Input control | Checking which data was entered or changed, when, and by whom |
On transmission the FDPIC is plain: where sensitive personal data is disclosed, the disclosure has to be secure — in its text on the disclosure of patient data it names encryption explicitly as a measure where data is to be sent by email. On clauses under which patients consent to unsecured electronic disclosure, it writes that this can be problematic; it is possible only after prior information about the risks and with a genuine choice, such as a box to tick.
Two further provisions attach to scale. Art. 4 DPO requires the logging of storage, modification, reading, disclosure, deletion and destruction where sensitive personal data is processed automatically on a large scale and preventive measures cannot ensure data protection. Art. 5 DPO requires processing regulations where sensitive personal data is processed on a large scale. What “on a large scale” means, the ordinance does not quantify.
A small business is exempt from one duty — and even that conditionally
Art. 12 para. 5 FADP instructs the Federal Council to provide exemptions for undertakings with fewer than 250 employees whose processing carries a low risk of personality violations. Art. 24 DPO implements it: undertakings and other private law organisations employing fewer than 250 people on 1 January of a given year, as well as natural persons, are exempt from keeping a register of processing activities — unless sensitive personal data is processed on a large scale or high-risk profiling is carried out.
Three things about that are precise. First, the exemption concerns the register only. The duty to inform, proportionality, data security, the form of consent and the rules on disclosure are untouched by it. Second, it is conditional: it falls away where sensitive data is processed on a large scale. Third, it arrives with the same unquantified wording as Art. 4 and 5 DPO, so a four-person practice cannot tell from its size alone which side of the line it is on.
Retention is similarly open. The FDPIC writes that, on the basis of the civil law limitation period for personal injury, a retention period of 20 years can generally be assumed, and points at the same time to the documentation duties in cantonal health acts. Art. 6 para. 4 FADP requires the opposite direction: personal data is destroyed or anonymised as soon as it is no longer necessary for the purpose of processing. Between those two poles lies a question each practice answers for its own records.
Professional secrecy is a second, separate order
Data protection and professional secrecy are often named in one breath, but they sit in different acts and work differently. Art. 321 of the Swiss Criminal Code makes it an offence for members of certain professions to reveal a secret confided to them in their professional capacity or which they became aware of in its exercise. The list in the statutory text names, among others, doctors, dentists, chiropractors, pharmacists, midwives, psychologists, nursing staff, physiotherapists, occupational therapists, dietitians, optometrists and osteopaths — “and their auxiliaries”.
In daily practice that last addition is the most important part of the sentence. It draws the person at reception, the practice assistant and the Saturday stand-in into the same circle as the treating professional. The act also states that the offence remains punishable after the person has stopped practising, and that anyone who reveals the secret with the consent of the person entitled, or with written authorisation from a superior or supervisory authority, is not liable; rights and duties to report, to testify and to inform an authority are reserved.
Two questions therefore stand side by side without being the same one: the data protection question of who may process which data, and the criminal law question of who may reveal a secret that was confided. An answer to one is not an answer to the other.
What of this hangs on the form
Seen this way, a practice form is a sequence of decisions that can be described: which fields exist and why, what is informed and what is consented to, who sees the answers at reception and in the treatment room, by which route something leaves the practice, and how long it stays. According to the guidance note the FDPIC expects forms to be cleaned up where they go beyond what the therapeutic relationship requires — and its list is a starting point that can be worked through on a printed registration sheet with a pencil.
The online forms app we are building starts where the ordinance speaks of confidentiality and transport control: answers are encrypted in the browser of the person filling them in, and operation and storage will be in Switzerland. Which fields an intake sheet carries, and who in the practice may read it, remains the practice’s decision — software changes nothing about that.
Sources
- 1.Bundesgesetz über den Datenschutz (DSG, SR 235.1) (checked on 23 September 2026)
- 2.Datenschutzverordnung (DSV, SR 235.11), Fassung in Kraft seit 15. September 2024 (checked on 23 September 2026)
- 3.Schweizerisches Strafgesetzbuch (StGB, SR 311.0), Art. 321 Verletzung des Berufsgeheimnisses (checked on 23 September 2026)
- 4.EDÖB: Merkblatt «Erläuterungen zu Patientenformularen für ärztliche und therapeutische Konsultationen» (checked on 23 September 2026)
- 5.EDÖB: Bekanntgabe von Patientendaten (checked on 23 September 2026)
- 6.EDÖB: Einsicht, Aufbewahrung und Löschung von Patientendaten (checked on 23 September 2026)
SchweizerformThis idea became Schweizerform.
Online forms with end-to-end encryption, made and hosted in Switzerland.