Our Expert in Switzerland
No results available
Understanding how to respond to an EDÖB investigation in Switzerland is now a core competency for any business that processes personal data with effects in the country. The EDÖB, formally the Federal Data Protection and Information Commissioner (FDPIC), has significantly expanded its investigative activity since the revised Federal Act on Data Protection (FADP) entered into force on 1 September 2023, and the FDPIC enforcement process in 2026 reflects a sharper focus on evidence-driven inquiries, privacy-by-design obligations and systemic risks including artificial intelligence. This guide sets out the complete EDÖB investigation procedure: what triggers it, the documents needed, every procedural step with responsible roles and deadlines, a realistic costs breakdown, and the appeal options available if you disagree with the outcome.
It is written for General Counsel, Data Protection Officers, in-house compliance teams and external advisers who need to act quickly and correctly once a regulator notice arrives.
The EDÖB is Switzerland’s independent federal supervisory authority for data privacy. Under Art. 49 FADP, the Commissioner may open an investigation of its own accord or on the basis of a report from a third party whenever there are sufficient indications that a data processing operation may violate data protection provisions. The terms “EDÖB” and “FDPIC” are used interchangeably; both refer to the same authority.
An investigation can target any controller (the entity determining the purposes and means of processing), any processor acting on a controller’s behalf, or a third-party service provider involved in the processing chain. The FADP applies to all processing that has effects in Switzerland, even if the controller is established abroad.
Notification typically arrives as a formal written letter from the EDÖB, either by post or secure electronic communication. The letter will identify the data processing activities under review, cite the relevant FADP provisions, set out the information the Commissioner requires, and specify a response deadline. Engage qualified data-protection counsel immediately upon receipt, the deadlines are enforceable and the quality of your initial response can materially affect the investigation’s trajectory.
Before assembling your response, confirm that your organisation does fall within the EDÖB’s supervisory scope. The FADP governs the processing of personal data by private persons and federal bodies. Cantonal data protection authorities supervise cantonal and communal bodies separately. If your organisation is a private-sector entity or a federal body processing personal data with effects in Switzerland, the EDÖB has competence.
Foreign companies without a Swiss establishment may still be subject to the FADP, and therefore to an EDÖB data protection investigation in Switzerland, if their processing has effects in the country. Under Art. 14 FADP, such controllers must designate a representative in Switzerland in certain circumstances.
Ensure your organisation has an up-to-date incident response plan and that evidence-preservation protocols are activated before anyone begins preparing the substantive response. Failure to preserve evidence at this stage is one of the most common, and most damaging, procedural errors.
The following numbered procedure covers the full lifecycle of an EDÖB investigation from the moment you receive notice through to closure and remediation. Each step identifies the responsible role and the typical timeframe. The consolidated timeline table appears below.
Who: CISO / IT / Incident Response Lead
When: Immediately, first 24–72 hours
If the investigation relates to a data breach or security incident, take immediate containment steps: isolate affected systems, revoke compromised credentials, and implement interim access controls. Simultaneously, issue a litigation-hold notice across the organisation to prevent the deletion, modification or overwriting of any data, logs, emails or documents that could be relevant. Hash and timestamp all preserved data. Document every containment action with a responsible person and sign-off.
Who: DPO / Legal
When: Within 48 hours of receiving the EDÖB notice
Send a brief written acknowledgement to the EDÖB confirming receipt and identifying your designated contact person. Internally, break the EDÖB’s letter into discrete information requests and assign each to the team member best placed to gather the relevant material. Create a shared tracker (spreadsheet or project-management tool) with columns for each request item, responsible owner, deadline, status and sign-off.
Who: Legal / DPO + IT Forensic
When: 7–30 days (depending on the deadline stated in the EDÖB letter; request an extension in writing if needed)
This is the most substantive step. Your response should be structured, factual and complete. Address each item in the EDÖB’s request sequentially, cross-referencing the supporting documents in a numbered exhibit list. Use a formal cover letter addressed to the Commissioner, identifying the investigation reference number, summarising the key facts, and stating any legal positions or defences. Include a regulator response template that follows a clear structure: identification of the parties, chronological factual narrative, legal analysis referencing specific FADP provisions, list of remedial measures already taken or planned, and a signed declaration by an authorised representative.
Attach all supporting evidence as indexed exhibits (see the Required Documents section below). Where you assert legal privilege over any document, include a privilege log listing the withheld items, the privilege claimed and the legal basis, and seal any privileged material separately.
Who: Head of Legal / DPO
When: At any point during the response period; meeting scheduling typically takes 2–8 weeks
If any aspect of the EDÖB’s request is ambiguous, request written clarification promptly, do not guess. You may also proactively propose an in-person or virtual meeting with the EDÖB to present complex technical evidence or to discuss interim measures. Meetings with the Commissioner’s team typically last 1–3 hours. Prepare a concise agenda in advance, designate a lead spokesperson (usually Head of Legal or external counsel), and bring a technical lead who can answer forensic questions directly. Take detailed minutes and circulate them to the EDÖB promptly for agreement.
Who: Controller implements / Legal monitors
When: Immediate to 30 days, depending on the measure ordered
Under Art. 51 FADP, the EDÖB may order interim administrative measures during an ongoing investigation, for example, ordering the suspension of a particular data processing activity, mandating specific technical safeguards, or requiring immediate notification of affected data subjects. Comply promptly with any binding order. If you believe an interim measure is disproportionate, you may submit reasoned objections in writing, but non-compliance with a binding order can escalate sanctions significantly. Document all remedial steps taken, including dates and responsible personnel.
Who: EDÖB issues decision; Controller implements remediation
When: Weeks to months (investigation duration varies); public rulings published per Art. 57 FADP for matters of public interest
At the conclusion of its investigation, the EDÖB will issue a formal ruling. Under Art. 57 FADP, the Commissioner may publish findings of general interest, meaning your organisation may be named publicly. The ruling may require specific remedial actions within a stated timeframe. Implement all ordered measures, document compliance and report back to the EDÖB as directed. If you disagree with the ruling, you may appeal to the Federal Administrative Court within 30 days of notification of the decision.
| Step | Who Does It | Typical Duration |
|---|---|---|
| Acknowledge receipt & initial categorisation | DPO / Legal | Within 48 hours of EDÖB notice |
| Preserve evidence & containment | CISO / IT / Incident Response | Immediate (first 24–72 hours) |
| Prepare formal written response & evidence bundle | Legal / DPO + IT Forensic | 7–30 days (per EDÖB deadline; request extension if needed) |
| Meeting / inspection with EDÖB (if requested) | Head of Legal / DPO + technical lead | 2–8 weeks scheduling; meeting typically 1–3 hours |
| EDÖB interim measures / remedial order | Controller implements / Legal monitors | Immediate to 30 days depending on measure |
| Closure / ruling and remediation | EDÖB decision; Controller implements | Weeks to months, public rulings per Art. 57 FADP |
The EDÖB’s information requests are typically broad and evidence-intensive. The table below lists the documents needed most frequently, together with practical notes on format, issuer and best-practice handling. Preparing these proactively, before an investigation begins, dramatically reduces response times and improves the quality of your submission.
| Document | Notes (Issuer, Format, Best Practice) |
|---|---|
| Initial EDÖB notice / correspondence | EDÖB letter or PDF, record original receipt date, reference number and contact person |
| Incident timeline & chronology | Prepared by Incident Response team, PDF or Word with precise timestamps; signed off by Head of Security |
| System logs (access, authentication, change logs) | Exported logs in CSV or JSON; include cryptographic hash/checksum for integrity; specify exact logging period covered |
| DPIA / risk assessment for relevant processing | Controller document, versioned PDF with approval dates and sign-off by DPO |
| Records of processing activities (ROPA) | Controller-produced register per Art. 12 FADP, export to PDF or CSV; ensure current as of response date |
| Contracts / Data Processing Agreements (DPAs) | Signed contracts with all processors, PDFs with signature pages; note any sub-processor chains |
| Data subject communications (notifications, emails) | Copies and archives, include delivery confirmations and read receipts where available |
| Retention & deletion policies | Policy document, current version plus any historical versions applicable to the period under investigation |
| Encryption / technical controls evidence | Technical design documents, configuration screenshots, TLS/SSL certificate details |
| Forensic analysis report | Vendor report in PDF, append chain-of-custody documentation for all examined media |
| Legal privilege log (if asserting privilege) | Privilege log listing each withheld document, the privilege claimed and the legal basis; seal privileged material separately |
Evidentiary best practice: For all digital evidence, particularly system logs and forensic images, maintain a documented chain of custody that records who extracted the data, when, from which system, and using what tools. Apply cryptographic hashes (SHA-256 or equivalent) at the point of extraction and verify them before submission. This protects the integrity and admissibility of evidence and demonstrates good faith to the EDÖB.
There is no single statutory timeframe that governs the entire duration of an EDÖB investigation. The timeline depends on the complexity of the matter, the volume of data involved and the level of cooperation from the organisation under investigation. However, several milestone deadlines are either prescribed by the EDÖB in its correspondence or implied by statutory provisions.
| Milestone | Typical Timeframe | Notes |
|---|---|---|
| Initial response deadline (set in EDÖB letter) | 14–30 days from receipt | Verify exact date on your letter; request an extension in writing before expiry if needed |
| Evidence preservation | Immediately upon notice | Litigation hold must be issued within hours, do not wait for the formal response deadline |
| EDÖB follow-up requests | Ongoing throughout investigation | Respond within any stated deadline; propose reasonable timelines where none is specified |
| Investigation duration (total) | 3–18 months (varies significantly) | Complex cross-border or AI-related matters may take longer |
| EDÖB ruling issued | At conclusion of investigation | May be published under Art. 57 FADP if of public interest |
| Appeal to Federal Administrative Court | Within 30 days of notification of decision | Strict deadline, late filing is generally not accepted |
Extension requests: If you cannot meet an EDÖB deadline, submit a written extension request before the deadline expires. Explain why additional time is needed (e.g., volume of records, cross-border coordination) and propose a specific new date. The EDÖB will generally grant reasonable extensions where good cause is shown, but silent non-compliance will be treated as obstruction and may lead to escalated measures.
Missed deadlines: Failure to respond within the prescribed timeframe can result in the EDÖB drawing adverse inferences, ordering compulsory production of documents, or escalating to administrative sanctions. In serious cases, the EDÖB may refer matters for criminal prosecution under Art. 63 FADP.
Responding to a data protection investigation in Switzerland carries significant direct and indirect costs. The table below provides a realistic breakdown. All monetary figures are estimates unless otherwise stated and should be validated against current market rates.
| Item | Amount | Notes |
|---|---|---|
| EDÖB administrative / filing fee | Typically none | The EDÖB does not generally charge an investigation fee to the subject of an inquiry |
| External counsel (initial response, first 30 days) | Estimate: CHF 5,000–30,000 | Depends on complexity, volume and whether cross-border issues are involved |
| Forensic investigation vendor | Estimate: CHF 3,000–50,000+ | Driven by data volumes, number of systems and cross-border scope |
| Remediation costs (technical fixes, process redesign) | Varies widely | Project-dependent; classify as OPEX or CapEx depending on nature of remediation |
| Potential fines (individuals) | Up to CHF 250,000 | Under Art. 60–63 FADP, fines are imposed on responsible natural persons, not the organisation itself |
| PR & communications support | Estimate: CHF 2,000–20,000 | Required if the EDÖB publishes findings or media attention is anticipated |
Note that under the revised FADP, criminal penalties (fines up to CHF 250,000) are directed at the responsible natural person, typically a senior executive or the person who caused the violation through wilful or negligent conduct, rather than at the legal entity. This is a distinctive feature of Swiss data protection enforcement compared to the GDPR’s corporate-fine model. Administrative measures ordered by the EDÖB (e.g., orders to cease processing or to delete data) are directed at the controller and are separately enforceable.
The revised FADP has been in force since 1 September 2023, and by 2026 the EDÖB’s enforcement practice has matured considerably. Early indications suggest several clear priorities shaping how to respond to an EDÖB investigation in Switzerland this year:
Knowing how to respond to an EDÖB investigation in Switzerland is no longer optional for organisations processing personal data with Swiss effects. The FDPIC enforcement process in 2026 demands structured, evidence-based responses delivered within tight deadlines, supported by complete documentation and a clear legal strategy. The consequences of getting it wrong, from adverse EDÖB rulings and public findings to personal criminal fines of up to CHF 250,000, are substantial.
The procedural steps set out in this guide, from immediate evidence preservation through formal response preparation, regulator meetings, interim measures and eventual ruling, provide a practical framework that General Counsel, DPOs and compliance teams can follow systematically. Prepare your documents proactively, maintain current records of processing activities and DPIAs, and ensure your incident response team can mobilise within hours of a regulator notice.
For organisations seeking specialist guidance on the EDÖB investigation procedure, early engagement with experienced data privacy counsel is the single most effective step you can take to protect your organisation’s position and minimise enforcement risk.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Alexandros Manousakis at Privintelligent Solutions, a member of the Global Law Experts network.
posted 1 hour ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
posted 6 hours ago
posted 6 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message