Published on 30 June 2026, the 33rd Annual Report 2025/2026 of the Federal Data Protection and Information Commissioner (FDPIC) provides an insightful overview of the state of data protection in Switzerland. More than individual decisions, the figures illustrate how the system is evolving: notifications of data security breaches are increasing, supervisory activities are expanding, and the importance of effective data protection governance is once again emphasised.
Key figures
During the reporting period, 484 notifications of data security breaches were submitted, compared with 363 in the previous year.
Particularly significant is the increase in voluntary reports, which rose from 26 to 141, partly because of the updated FDPIC guidance on notifying data security breaches, which expressly highlights the possibility of voluntary reporting.
The Authority’s supervisory activities confirm an intensification of its controls:
- 2,447 complaints, of which 2,347 concerned private entities and 100 concerned the Federal Administration;
- 156 low-threshold interventions;
- 22 preliminary investigations;
- 9 formal investigations.
The Report also highlights an increase in provisional notifications, which are submitted when an incident is still under analysis and its effects on the individuals concerned cannot yet be assessed.
In the event of a data security breach, it is also reiterated that the notification obligation under Article 24 of the Federal Act on Data Protection (FADP) remains the responsibility of the data controller. At the same time, the usefulness of voluntary reports submitted by data processors is acknowledged, particularly in facilitating the coordination of complex incidents.
The role of the Data Protection Officer (DPO)
The Report includes a specific analysis of the Data Protection Officer (DPO), describing the role as essential to the Swiss data protection system in both the public and private sectors. The DPO’s responsibilities include training and raising staff awareness, supporting the implementation of the FADP, and acting as a point of contact for the FDPIC and the individuals concerned.
The most significant aspect, however, concerns an issue expressly highlighted by the Authority: data controllers do not always involve the DPO sufficiently in their processes. The FDPIC notes that, even within the Federal Administration, it is frequently asked to provide an opinion on data protection matters without any indication as to whether the organisation’s DPO has previously been consulted.
For this reason, the Report reiterates a very clear governance principle: the Data Protection Officer must be involved sufficiently early in organisational processes so that projects are properly structured from the outset. The Authority also specifies that federal bodies should first consult their own DPO and approach the FDPIC only subsequently, where necessary.
Governance is becoming increasingly important
The increase in data security breach notifications confirms that organisations operate in an increasingly complex digital environment. At the same time, the Report emphasises the need to strengthen data processing governance by involving the Data Protection Officer promptly in projects and decisions affecting the processing of personal data.
Compliance with the FADP does not depend solely on technical and organisational measures, but also on an organisation’s ability to integrate data protection into its decision-making processes from the design stage onwards.



