[codicts-css-switcher id=”346″]

Global Law Experts Logo
employee monitoring switzerland

Employee Monitoring and Workplace Privacy in Switzerland (2026): Employer Guide Under the Revised FADP

By Global Law Experts
– posted 2 hours ago

Employee monitoring Switzerland has become one of the most pressing compliance questions for HR managers, in-house counsel and data protection officers as the revised Federal Act on Data Protection (FADP), in force since 1 September 2023, settles into full enforcement across 2026. The growth of hybrid and remote work has multiplied the number of tools employers deploy, from CCTV and email review to keystroke logging and third-party productivity analytics, and each of these carries distinct legal exposure. The revised FADP raises the bar on documentation, proportionality and risk assessment, meaning that programs designed a few years ago may no longer stand up to scrutiny.

This guide gives employers a practical, actionable framework for lawful employee monitoring Switzerland: how to select a lawful basis, when to run a data protection impact assessment (DPIA), how to draft notices, and how to manage vendors and rights requests. Read it as a compliance playbook, not a theoretical survey, the goal is to take a clear position on what you should and should not do.

Quick summary and key takeaways

The revised FADP tightens expectations around transparency, necessity and record-keeping for any employer running a monitoring program. Before you deploy or renew any tool, work through the essentials below.

  • What changed. The revised FADP places greater emphasis on documented accountability, DPIAs for high-risk processing, tighter transparency duties and stricter treatment of sensitive data. Monitoring programs must now be demonstrably proportionate and recorded.
  • Immediate action items. Inventory every monitoring tool in use, confirm a lawful basis for each, issue clear notices, and document a DPIA where the processing is systematic, intrusive or large-scale.
  • High-risk monitoring types. Keystroke logging, constant screenshots, content scanning of email, biometric access and covert surveillance are the categories most likely to trigger enforcement and employee claims.
  • DPIA triggers. Large-scale, systematic monitoring; technologies that intrude on private life; profiling of productivity; and any processing of sensitive categories.

Three-point checklist to memorise: (1) notice, tell employees clearly; (2) lawful basis, usually a justification such as overriding private interest, contractual necessity or legal obligation, rarely consent; (3) DPIA, assess and document before you deploy anything intrusive.

Overview: what the revised FADP changes for employee monitoring Switzerland

The revised FADP modernised Swiss data protection law and aligned it more closely with European standards while retaining its own distinctive rules. For employers, the practical significance is not a wholesale reinvention of principles but a sharpening of enforcement expectations. Transparency, purpose limitation, data minimisation and proportionality were always central to Swiss law; the revised statute makes the documentation of these principles a live compliance obligation rather than an aspiration. Employers who cannot show, on paper, why a monitoring measure is necessary and how they limited its intrusiveness are now more exposed.

Scope and application to private-sector employers

The FADP applies to the processing of personal data of natural persons by private persons and federal bodies. Private-sector employers fall squarely within scope whenever they collect, store, analyse or disclose data about their staff, and monitoring is, by definition, data processing. The employment relationship in Switzerland is also governed by parallel labour-law protections that reinforce the FADP: under Article 328b of the Code of Obligations, an employer may only process data about an employee to the extent it concerns the employee’s suitability for the job or is necessary to perform the employment contract.

In addition, Article 26 of Ordinance 3 to the Labour Act prohibits the use of surveillance or control systems intended to monitor the behaviour of employees at the workplace; where such systems are necessary for other reasons, they must be designed and arranged so that they do not impair the health and freedom of movement of employees. In practice the FADP and employment law operate together, and a monitoring measure that is lawful under one but not the other is not lawful at all.

Extra-territorial reach and cross-border processing

The revised FADP can reach processing that takes place abroad where it produces effects in Switzerland, which matters for employers using cloud-hosted monitoring tools or offshore analytics providers. If your workforce data leaves Switzerland, for storage, support or productivity analysis, you must ensure the transfer rests on a destination the Federal Council recognises as providing adequate protection, or on appropriate safeguards such as the standard contractual clauses recognised by the FDPIC. Cross-border monitoring data flows are one of the most commonly overlooked risks in employee monitoring Switzerland, because the tool looks compliant on the surface while the underlying data quietly travels through jurisdictions without adequate protection.

Lawful bases for employee monitoring under the FADP

Every act of employee monitoring Switzerland needs a defensible legal footing. Swiss data protection law does not follow the EU’s closed list of six legal bases; instead, processing of personal data by private persons is lawful in principle provided the data protection principles are respected, and a “justification” (such as an overriding private or public interest, a legal basis, or consent) is needed where processing would otherwise breach a data subject’s personality. In the employment context, the realistic justifications are performance of the employment contract, compliance with a legal obligation, an overriding private interest, or, in narrow cases, consent.

Our position is clear: for most workplace monitoring, an overriding legitimate interest supported by transparency and proportionality is the correct and defensible basis, and consent should be treated as the exception rather than the rule.

Consent versus legitimate interest, the practical test

Consent looks attractive because it feels like agreement, but in the employment context it is fragile. The imbalance of power between employer and employee undermines the “freely given” quality that valid consent requires, and consent can be withdrawn at any time, leaving your program without a basis overnight. An overriding legitimate interest, by contrast, is more durable if you can pass the balancing test. Work through these questions before you deploy anything:

  • Is there a genuine, specific purpose? Security, fraud prevention, fleet management or legal compliance are concrete; “general oversight” is not.
  • Is the measure necessary? Could a less intrusive method achieve the same result? If yes, you must choose it.
  • Is it proportionate? Does the intrusion into private life outweigh the business benefit? If the balance tips toward the employee, stop.
  • Have you been transparent? Covert monitoring is almost never defensible outside narrow, exceptional investigations.

If the measure clears all four gates, an overriding legitimate interest is your basis and you should document that reasoning. If it fails any gate, redesign the measure, do not fall back on consent to rescue a disproportionate program.

Special categories and stricter rules

Sensitive personal data, health information, biometric data uniquely identifying a person, genetic data, data on religious, ideological or political views or activities, trade-union membership, data on the private sphere, and data on administrative or criminal proceedings, attracts heightened protection. Monitoring that captures such data, for example biometric access control or health-related productivity inferences, faces a materially higher bar and will almost always require a DPIA. Where an employer cannot avoid processing sensitive categories, it must apply stronger safeguards, tighter access controls and shorter retention, and it should expect close supervisory attention.

Do employers need employee consent to monitor staff? Rarely, and you should not rely on it. Because of the employment power imbalance and the risk of withdrawal, an overriding legitimate interest, contractual necessity or legal obligation are the preferred and more robust bases, always paired with clear notice and proportionality.

Technology-by-technology compliance for employee monitoring Switzerland

Different tools carry very different risk profiles, and treating them uniformly is a mistake. The table below compares the most common monitoring technologies across the dimensions that determine lawfulness and enforcement exposure. Use it as a triage tool: identify your technology, read across the row, and confirm you have addressed every column before deployment.

Employer Conducting Lawful Employee Monitoring Switzerland In A Swiss Office, Dpia And Notice Checklist
Lawful employee monitoring Switzerland depends on the right lawful basis, clear notice and a documented DPIA for high-risk tools.
Monitoring type Lawful basis (typical) Consent required? DPIA likely? Notice required Minimisation & retention Employee rights Enforcement risk
CCTV (public/production areas) Overriding interest / safety / legal obligation Not usually (but inform) Often (if systematic or large-scale) Yes, visible signs + policy Limit coverage, blur private areas; short, justified retention Access on request; limited disclosure Medium-high, visible and sensitive
CCTV (private areas: changing rooms) Almost never lawful No, forbidden in most cases Very high Prohibited in most cases N/A N/A High, legal prohibition risk
Email & corporate IT monitoring Overriding interest / contract compliance Not usually, consent unreliable Sometimes (if content scanning) Yes, clear acceptable-use policy + reminders Prefer metadata over content; short retention Access rights apply; balancing test Medium, higher if content scanned
Keylogging / screen capture / constant screenshots Rarely proportionate; hard to justify No, consent unreliable High Yes, explicit notice & strict limits Avoid capturing personal activity; very short retention High access requests; claim risk High, intrusive and reputational
GPS / vehicle tracking Overriding interest (fleet management) Not usually Sometimes Yes, policy + in-vehicle notice Geofence sensitive times; avoid private journeys Access to trip data; blur private legs Medium, balancing required
Third-party SaaS / cloud monitoring Depends (contract / overriding interest) No, plus processor compliance Often Yes, combined notice + processor info Vendor minimisation; contractual safeguards Controller/processor duties; DSAR routing Medium, transfer & vendor risk

CCTV specific requirements and sample notice language

Video surveillance in the workplace is permitted where it is proportionate, limited to a clear purpose and properly signposted, but it is subject to strict boundaries. Cameras aimed at production lines, entrances and public-facing areas can be justified by safety, theft prevention or legal obligations. Cameras in changing rooms, toilets, break rooms or any space where employees expect privacy are effectively prohibited, and continuous surveillance designed solely to monitor worker performance is not permitted. Signage must be visible, and the footage should be retained only as long as the stated purpose requires.

Sample notice language: “This area is monitored by CCTV for the purposes of premises security and theft prevention. Recordings are retained for [X days] and accessed only by authorised personnel. For information about your data protection rights, contact [DPO/responsible contact].” Post this at every entrance to a monitored zone and mirror it in your written employee privacy policy.

Email and computer-use monitoring best practices

Employers may review corporate email and IT usage where they have a clear, communicated purpose, but the intrusiveness matters enormously. Monitoring aggregate metadata (volume, timestamps, bandwidth) is far easier to justify than reading the content of individual messages. If you must inspect content, restrict it to defined, exceptional circumstances such as a security incident or a substantiated investigation, and never routinely trawl personal correspondence that has slipped into corporate systems. Publish a plain-language acceptable-use policy, remind staff of it periodically, and separate personal from work channels wherever you can.

Remote monitoring, keystroke logging and screen capture, proportionality first

Remote work monitoring is where employers most often overreach. Keystroke logging, continuous screenshots and always-on webcam checks are highly intrusive and rarely proportionate; they capture private life, generate large volumes of sensitive data and provoke both enforcement scrutiny and employee grievances. Our position is unambiguous: default to outcome-based measures, project deliverables, ticket completion, agreed availability windows, rather than behavioural surveillance. If you genuinely need activity data, choose the least intrusive option, apply strict scope and retention limits, run a DPIA, and give explicit notice. A monitoring measure that would be indefensible in the office does not become defensible simply because the employee is at home.

DPIAs for employee monitoring: when, how and what to document

The data protection impact assessment is a central compliance instrument of the revised FADP for high-risk processing, and employee monitoring frequently qualifies. Under the FADP, a DPIA is required where processing is likely to result in a high risk to the personality or fundamental rights of the data subject, in particular when new technologies are used, or when processing sensitive data on a large scale or systematically monitoring extensive public areas. A DPIA is not a bureaucratic formality, it is the document that proves you thought about necessity and proportionality before deploying a tool, and it is the first thing the supervisory authority will ask to see.

DPIA trigger examples and an inline checklist

Run a DPIA when any of these apply to your employee monitoring Switzerland program:

  • Large-scale or systematic monitoring of a workforce, such as continuous IT activity logging across all staff.
  • Intrusion into private life, for example screen capture, keystroke logging or GPS tracking that could reveal private movements.
  • Productivity profiling that scores or ranks employees using automated analytics.
  • Content scanning of communications, including email or messaging inspection beyond metadata.
  • Sensitive data processing, such as biometric access control or health-related inferences.

Your DPIA should move through a clear sequence: describe the processing and its context; state the purpose and legal basis; assess necessity and proportionality against less intrusive alternatives; identify risks to employees; set out mitigations; record the residual risk; and secure documented approval with a review date. If, despite the measures envisaged, high residual risk remains, the FADP requires consultation with the Federal Data Protection and Information Commissioner (FDPIC) before proceeding, a controller with a data protection adviser may instead consult that adviser.

What to record in the monitoring register and audit trail

Maintain a monitoring register that records, for each tool: the purpose, the legal basis, the categories of data collected, who has access, the retention period, any processors involved, the DPIA reference and the date of last review. This register complements the statutory record of processing activities and is your accountability backbone. Keep an audit trail of who accessed monitoring data, when and why, access logs turn an abstract policy into demonstrable governance and protect the employer if a decision is later challenged.

How should employers document monitoring and perform DPIAs? Use a standard DPIA template for every new or materially changed tool, record the outcome in the monitoring register, retain access logs, and schedule periodic reviews. Documentation is the difference between a defensible program and an indefensible one.

Operational requirements: notices, policies and HR processes

Even a lawful monitoring measure fails compliance if employees were never properly informed. Transparency is the operational heart of the FADP, and it is delivered through clear notices, a coherent policy and trained managers.

Draft notice and short policy checklist

Every monitoring notice and employee privacy policy should contain the following elements:

  • Purpose, the specific reason for monitoring, stated concretely.
  • Lawful basis / justification, typically an overriding legitimate interest or contractual/legal necessity.
  • Scope, what is monitored, where and when.
  • Categories of data, the types of personal data collected.
  • Retention period, how long data is kept and why.
  • Recipients, internal roles and any processors or third parties, including any recipients abroad.
  • Employee rights, access, correction, objection and deletion, with the process to exercise them.
  • Contact point, the DPO/data protection adviser or responsible function.

Deliver the policy at onboarding, reference it in the contract, and reinforce it with periodic reminders. Train line managers so they understand what the tools do and, equally important, what they are not allowed to do with the data.

Handling investigations and disciplinary evidence

Monitoring data is frequently used as evidence in disciplinary proceedings, and this is where employers most often stumble. Only data collected for a compatible, notified purpose should be used against an employee; evidence gathered covertly or beyond the stated scope is vulnerable to challenge. Maintain a clear chain of custody, limit disclosure to those who genuinely need it, and where employee representatives are involved, consult them on the introduction of behavioural surveillance systems as required by labour law. Discipline based on unlawfully obtained monitoring data can unravel the whole action and expose the employer to further claims.

Cross-border transfers, processors and vendor selection

Much modern monitoring runs on cloud platforms hosted outside Switzerland, which brings the transfer rules into play. When employee monitoring data is processed abroad, ensure the destination is recognised by the Federal Council as providing adequate protection or that appropriate safeguards, such as the FDPIC-recognised standard contractual clauses or binding corporate rules, are in place, and confirm that your processor agreements bind vendors to FADP-consistent obligations.

Vendor due diligence checklist

  • Data location. Where is monitoring data stored and processed, and does that trigger transfer safeguards?
  • Processor agreement. Is there a written contract imposing confidentiality, security, sub-processor control and deletion duties?
  • Data minimisation. Can the tool be configured to collect only what is necessary, and is that the default?
  • Security measures. What technical and organisational controls does the vendor apply, and can they be audited?
  • DSAR support. Can the vendor help you locate and extract data to answer an employee access request?
  • Exit and deletion. How is data returned or destroyed when the contract ends?

Responding to rights requests, complaints and enforcement

Employees have the right to know what data an employer holds about them, and monitoring records fall within that right. When a request arrives, act promptly and methodically rather than defensively.

Example workflow: from DSAR to preservation to deletion

On receiving an access request, first confirm the requester’s identity and the scope of what they seek. Locate the relevant monitoring records across CCTV, IT logs and any SaaS platforms. Redact information about third parties or that would compromise a legitimate exception, then respond within the statutory timeframe, generally 30 days under the FADP, extendable where justified. If the request coincides with a live investigation, preserve the evidence and document why. Once the retention period expires and no legal hold applies, delete the data and log the deletion. Where an employee complains to the FDPIC, cooperate transparently, a well-documented monitoring register and DPIA are your strongest defence, and they materially reduce the likelihood of adverse findings or administrative measures.

Practical roadmap: a 12-step employer checklist for employee monitoring Switzerland

Use this roadmap to bring your employee monitoring Switzerland program into compliance within the first 90 days.

  1. Inventory every monitoring tool currently in use, including shadow IT and departmental tools.
  2. Map the purpose of each tool and discard any without a genuine business need.
  3. Assign a lawful basis / justification to each remaining tool, usually an overriding legitimate interest.
  4. Run the balancing test and document the reasoning for each measure.
  5. Identify DPIA triggers and complete a DPIA for every high-risk tool.
  6. Build the monitoring register capturing purpose, basis, data, access, retention and DPIA reference.
  7. Draft or update notices and the employee privacy policy with all required elements.
  8. Set retention periods and configure automatic deletion where possible.
  9. Review vendors against the due-diligence checklist and fix processor agreements.
  10. Confirm transfer safeguards for any data processed abroad.
  11. Train managers on lawful use, access limits and disciplinary boundaries.
  12. Schedule audits and set review dates so the program stays current.

For deeper support, our Data Privacy lawyers, Switzerland can help you scope DPIAs, draft notices and structure a defensible program. You can also review the author’s profile via the GLE listing.

Conclusion

Getting employee monitoring Switzerland right under the revised FADP is less about avoiding technology than about deploying it deliberately, proportionately and transparently. The employers who succeed in 2026 will be those who inventory their tools, choose an overriding legitimate interest over fragile consent, run and document DPIAs for high-risk measures, issue clear notices, and control their vendors and cross-border flows. Behavioural surveillance that captures private life, keystroke logging, constant screenshots, covert cameras, should be the exception you can justify in writing, not the default you reach for. Treat the monitoring register and DPIA as living accountability documents, review them on a schedule, and you will have a program that withstands both employee challenge and supervisory scrutiny.

Approached this way, employee monitoring Switzerland becomes a governed, defensible capability rather than a latent liability.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Alexandros Manousakis at Privintelligent Solutions, a member of the Global Law Experts network.

Sources

  1. Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
  2. Federal Act on Data Protection (FADP), SR 235.1, consolidated text
  3. Ordinance on Data Protection (DPO), SR 235.11
  4. Fedlex, Official Swiss legislative repository
  5. University of St. Gallen, Data Protection in Swiss Law Firms (research report)

FAQs

Can I monitor employees' emails under the revised FADP?
Yes, but only where it is proportionate, documented and covered by clear notice. Monitoring metadata is far easier to justify than reading message content; content scanning requires stronger justification and may trigger a DPIA. Publish an acceptable-use policy and restrict content review to defined, exceptional circumstances.
Consent is rarely a reliable basis for employee monitoring Switzerland because of the power imbalance in the employment relationship and the risk of withdrawal. An overriding legitimate interest, contractual necessity or a legal obligation is usually preferable, always paired with strong safeguards, proportionality and transparent notice.
A DPIA is required when processing is likely to result in a high risk to the personality or fundamental rights of employees, for example large-scale or systematic monitoring, intrusion on private life, productivity profiling through automated analytics, content scanning of communications, or processing of sensitive data such as biometrics. High-risk technologies like keystroke logging and constant screenshots should always be preceded by a DPIA.
The notice should state the purpose, lawful basis/justification, scope of monitoring, categories of data collected, retention period, recipients (including any abroad), employee rights and a contact point such as the DPO or responsible function. Deliver it at onboarding and reinforce it periodically so employees remain genuinely informed.
Yes, provided you carry out vendor due diligence, put a processor agreement in place, check cross-border transfer rules, and consider a DPIA where the tool profiles employees. Configure the platform for data minimisation and confirm you can answer access requests using the vendor’s tooling.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Employee Monitoring and Workplace Privacy in Switzerland (2026): Employer Guide Under the Revised FADP

Send welcome message

Custom Message