[codicts-css-switcher id=”346″]

Global Law Experts Logo
data protection impact assessment switzerland

How to Conduct a Data Protection Impact Assessment (DPIA) in Switzerland (2026)

By Global Law Experts
– posted 1 hour ago

A data protection impact assessment Switzerland requires under the revised Federal Act on Data Protection (revFADP) is now a core accountability document, and in 2026 the Federal Data Protection and Information Commissioner (FDPIC) expects organisations to produce it on demand. This practitioner guide sets out when a DPIA is legally required, an eleven-step process to run one, the documents you should retain, realistic timelines and costs, and the pitfalls that most often expose organisations during scrutiny. It is written for people who have to do the work, not just describe it. Wherever a legal claim is made, it is tied to the FADP text, FDPIC guidance, or an established international framework so that your assessment is defensible.

Who this guide is for: data protection officers/advisers, in-house counsel, privacy and compliance officers, IT and security leads, and SMEs operating in or into Switzerland.

What you will get: eligibility tests under the revised FADP, an 11-step DPIA process with roles and durations, a required-documents table, a phase-by-phase timeline, indicative costs, a checklist, and FDPIC consultation and defence guidance.

Overview: the current data privacy law in Switzerland

The current data privacy law in Switzerland is the totally revised Federal Act on Data Protection (FADP), which entered into force on 1 September 2023, together with the revised Ordinance on Data Protection (DPO). The revision modernised Swiss law and brought it closer to European standards while retaining distinct Swiss features. The revised FADP places accountability at the centre: controllers must be able to demonstrate that they have identified and mitigated risks to the people whose data they process. The instrument used to demonstrate this for higher-risk processing is the data protection impact assessment (in the FADP, “data protection impact assessment”, DPIA).

A DPIA is therefore not a bureaucratic formality, it is evidence that a controller considered privacy harms before processing began.

The regulator responsible for supervising compliance is the FDPIC, which issues guidance, receives consultations, and can conduct investigations and issue orders. In the current enforcement environment, the FDPIC has signalled a clear expectation that organisations engaged in high-risk processing, such as high-risk profiling, large-scale processing, or the use of sensitive data, can produce documented risk assessments. This guide follows the structure of the revised FADP and aligns methodology with international best practice from the European Data Protection Board (EDPB) and the UK Information Commissioner’s Office (ICO), both of which offer mature DPIA frameworks that transfer well to the Swiss context.

Eligibility: when a data protection impact assessment Switzerland requires is triggered

Under the revised FADP (Article 22), a DPIA must be carried out where planned processing is likely to result in a high risk to the personality or fundamental rights of the data subjects. The statutory basis is set out in the consolidated FADP text on Fedlex. A high risk arises in particular from the use of new technologies and is assessed by reference to the nature, scope, circumstances and purpose of the processing. In practice, the decisive factors are scale, scope, sensitivity and novelty. When two or more of these are present at a meaningful level, a DPIA is almost always the correct response.

The FADP expressly indicates that a high risk may result, in particular, from extensive processing of sensitive personal data or systematic large-scale monitoring of public areas.

Quick test: five questions to decide

  1. Does the processing involve sensitive personal data (for example, health, biometric data used to identify a person, genetic data, data on religious, philosophical, political or trade-union views or activities, data on legal proceedings or sanctions, or data on social assistance)?
  2. Does it involve large-scale processing of personal data, or systematic monitoring of a public or accessible area?
  3. Does it involve high-risk profiling or automated individual decisions that produce legal or similarly significant effects?
  4. Is the technology or purpose novel (for example, new AI models, tracking, or data-matching techniques)?
  5. Could the processing prevent data subjects from exercising a right or accessing a service?

If you answer “yes” to any single question, screen the processing formally and document the reasoning. If you answer “yes” to two or more, proceed to a full DPIA.

Swiss examples that typically require a DPIA

  • Employee monitoring. Systematic logging of email, browsing or location data.
  • Video surveillance. CCTV in publicly accessible areas or workplaces.
  • Health and insurance data platforms. Large-scale processing of medical records.
  • Credit and fraud scoring. Profiling that influences eligibility for services.
  • HR analytics. Performance or attrition prediction using automated tools.
  • Marketing profiling. Combining datasets to build behavioural profiles.
  • Biometric access control. Fingerprint or facial recognition systems.
  • Connected devices / IoT. Continuous data capture from users or premises.
  • Cross-border transfers to countries without adequate protection.
  • AI and machine-learning training on personal data at scale.

It helps to distinguish a DPIA from adjacent exercises that organisations sometimes confuse it with.

Purpose DPIA General data risk assessment Data mapping
Goal Assess high-risk processing to mitigate privacy harms and record legal basis Identify security and operational risks across the organisation Identify flows, actors and categories of data
When used Where processing is likely to result in high risk (FADP Art. 22 / FDPIC criteria) Routine risk management Early design or inventory stage
Required by law? Required for high-risk processing under Art. 22 FADP Not specifically Not specifically (but supports the record of processing under Art. 12 FADP)
Output Mitigation plan, residual risk, tracking Risk register Data flow diagrams, inventory

Step-by-step: how to conduct a data protection impact assessment Switzerland accepts as defensible

The following eleven-step process is designed to be reproducible. Each step names the primary owner, the output, and the acceptance criteria that let you move on. Treat the outputs as evidence, every step should leave a document trail. You can adapt the sequence to your project methodology, but do not skip the screening decision or the residual-risk sign-off, which are the two points most closely examined during an FDPIC investigation.

Step 1, Initiation and trigger

A DPIA is triggered by a project event: a new product, a new processing purpose, a vendor change, or a technology upgrade. The project owner typically raises the flag, but the privacy function owns the screening decision. Complete a short screening checklist against the five eligibility questions above and record the outcome, including a reasoned “no DPIA required” decision where that applies. Output: signed screening record. Acceptance criteria: documented decision with named approver.

Step 2, Scope and objectives

Define precisely what is being assessed. State the processing operations in scope, the purposes, the data subjects affected, the systems involved, and the intended legal bases. Identify stakeholders and confirm who has authority to accept residual risk. A vague scope is a common reason a DPIA fails under scrutiny, so pin down boundaries in writing. Output: scope statement. Acceptance criteria: agreed by project owner, privacy function and legal.

Step 3, Data inventory and flow mapping

Map the data end to end. For each processing activity, record the categories of personal data (flagging sensitive data), the sources, the internal and external recipients, any processors, the storage locations, retention periods, and every cross-border transfer with its transfer mechanism. Produce a data flow diagram that a non-specialist can follow. This artefact underpins the entire risk assessment: if the map is incomplete, the risk analysis will be too. Output: data inventory and flow map. Acceptance criteria: IT and data owner confirm accuracy; all transfers identified.

Step 4, Identify legal basis and justification

Under the FADP, lawful processing by private controllers does not always require a specific legal basis, but processing must comply with the principles of good faith, proportionality and purpose limitation, and certain processing (for example, breaching data-protection principles, processing against an express refusal, or disclosing sensitive data to third parties) requires a justification such as consent, an overriding private or public interest, or a legal basis. Document the justification for each relevant processing operation. Where you rely on an overriding interest, complete and record a balancing test that weighs your interest against the data subjects’ rights, and note any factors that tip the balance. Keep the reasoning, not just the conclusion. Output: legal basis/justification documentation and balancing test.

Acceptance criteria: legal counsel sign-off.

Step 5, Identify and categorise risks to rights and freedoms

Work systematically through a risk taxonomy rather than brainstorming loosely. Consider: loss of confidentiality (unauthorised access or disclosure); loss of integrity (unauthorised alteration); loss of availability (loss or destruction); discrimination from profiling or automated decisions; reputational harm; financial loss; and loss of control over data. For each risk, describe the scenario, the affected data subjects, and the potential consequence. Draw on EDPB and ICO methodology to ensure the taxonomy is complete. Output: privacy risk register. Acceptance criteria: security and business leads confirm no material risk is missing.

Step 6, Assess likelihood and impact; estimate residual risk

Score each risk on two axes: likelihood and impact on the data subject. A simple five-by-five matrix works well. Use consistent definitions, for example, treat “high impact” as significant harm that is difficult for the individual to remedy, and “high likelihood” as an event expected to occur under normal operating conditions. Record the inherent risk before mitigation and the residual risk after mitigation. Set a threshold above which residual risk cannot be accepted at operational level and must be escalated. Output: scored risk matrix. Acceptance criteria: privacy function and risk team agree the scoring.

Step 7, Identify mitigations and risk-treatment plan

For each significant risk, specify technical and organisational measures: encryption, pseudonymisation, access controls, minimisation, retention limits, contractual safeguards, staff training, and logging. Assign an owner and a deadline to every measure, and define the acceptance criterion that confirms the mitigation is effective. Sample acceptance language: “Residual risk is accepted where the measure reduces likelihood to ‘low’ and impact to ‘moderate’ or below, verified by the control owner.” Output: mitigation and risk-treatment plan. Acceptance criteria: each measure has an owner, deadline and test.

Step 8, Consultation and stakeholder review

Circulate the draft to security, business owners, legal, and where relevant an external adviser or data protection officer. Note that organisations that have appointed a data protection adviser (Datenschutzberater) meeting the FADP conditions may, in certain cases, consult that adviser instead of the FDPIC. Record who was consulted, what they said, and how their input changed the assessment. Output: consultation minutes. Acceptance criteria: all required stakeholders have reviewed; FDPIC/adviser consultation trigger considered and documented.

Step 9, Document outcomes and decision

Compile the DPIA report: executive summary, scope, data flows, legal basis/justification, risk assessment, mitigations, residual risk, and the accept/reject decision. Record who signed off and when, and apply version control. Output: final DPIA report. Acceptance criteria: signed by the person authorised to accept residual risk.

Step 10, Implementation and tracking

Fold the mitigation plan into the project schedule. Track each measure to completion, assign a KPI for risk reduction, and confirm that controls are actually deployed, not merely planned. Output: tracked implementation log. Acceptance criteria: all high-priority measures live before processing begins.

Step 11, Review and update

A DPIA is a living document. Review it when the processing changes materially, after any incident, and on a periodic basis, for example, at least annually for ongoing high-risk processing. Output: review record. Acceptance criteria: review date logged and next review scheduled.

Image alt: DPIA checklist and risk matrix for Switzerland (FADP 2026).

You can download our DPIA template and checklist Switzerland to apply this process directly (for guidance, review with legal counsel before relying on it).

Step Who (primary) Typical duration
1. Initiation & screening Project owner + privacy function 1–3 days
2. Scope & objectives Project owner, privacy function, legal 1–2 weeks
3. Data inventory & flow mapping IT, data owner, privacy function 1–3 weeks
4. Legal basis & justification Legal counsel, privacy function 3–7 days
5. Risk identification Privacy function, security, business leads 1 week
6. Likelihood & impact assessment Privacy function, risk team 3–5 days
7. Mitigation design IT/security, legal, privacy function 1–3 weeks
8. Consultation & review Stakeholders ± external adviser 1–2 weeks
9. Document & sign-off Privacy function, senior management/Board 3–7 days
10. Implementation & tracking Project manager, IT, privacy function Weeks–months (depends on measures)
11. Review & update Privacy function, business owner Periodic or on change

Required documents for a defensible DPIA

The documentation is the DPIA’s defence. When the FDPIC asks how you assessed a high-risk processing operation, your file should answer the question without further explanation. Keep the records below, and retain the optional supporting artefacts where the processing is sensitive or novel.

Minimum documentation to keep

Optional supporting artefacts for FDPIC defence

Document Purpose Who prepares
DPIA report (final) Records assessment, mitigations, residual risk Privacy function / project owner
DPIA record / screening checklist Evidence of the initial screening decision Project owner / privacy function
Data inventory / data flow map Shows categories, transfers, processors IT / data owner
Legal basis / justification documentation Evidence of justification and balancing test Legal counsel / privacy function
Risk register (privacy risks) Tracks identified risks and status Risk team / privacy function
Mitigation plan with owners & deadlines Implementation evidence Project manager / IT
Minutes of stakeholder consultations Evidence of consultation (incl. FDPIC/adviser consults) Privacy function / meeting owner
Technical evidence (logs, encryption configs) Evidence of implemented measures IT / security
Vendor / processor contracts & DPAs Shows contractual safeguards Procurement / Legal
Version control & sign-off record Audit trail and accountability Privacy function / compliance

Timeline and deadlines, including regulatory triggers

A straightforward DPIA for a small project usually completes in one to three weeks. A medium-complexity assessment runs three to eight weeks. Large or cross-border processing with significant mitigation work can take several months, largely because implementation (Step 10) depends on engineering timelines rather than the assessment itself. Build the DPIA into the project plan early, attempting it just before launch compresses the analysis and produces exactly the superficial screening the FDPIC looks for.

FDPIC consultation triggers

There is no general pre-approval requirement in Switzerland: you do not file every DPIA with the FDPIC. Under Article 23 FADP, where the DPIA shows that the planned processing would still result in a high risk to the personality or fundamental rights of data subjects despite the measures envisaged, the controller must consult the FDPIC in advance. A controller that has appointed a data protection adviser meeting the statutory conditions may instead consult that adviser. Treat the consultation trigger as the point at which your risk matrix still shows an unacceptable residual score despite reasonable measures. Prepare the full DPIA report before any consultation, so the FDPIC can see your reasoning and proposed safeguards.

Internal escalation milestones

Set two internal milestones: escalation to the accountable owner when residual risk exceeds the acceptance threshold at Step 6, and escalation to senior management or the board at Step 9 where sign-off requires risk acceptance above operational authority. In the event of a data-security breach affecting the assessed processing, revisit the DPIA immediately as part of the incident response, bearing in mind the separate obligation under Article 24 FADP to notify the FDPIC of a breach likely to result in a high risk to data subjects as soon as possible.

Costs and fees

DPIA cost varies with organisation size, processing complexity, and whether you rely on internal resources or external support. Cross-border transfers, large-scale processing, and AI use cases push costs toward the upper end because they demand more legal analysis and mitigation engineering. Indicative ranges are set out below; these are illustrative market estimates, not fixed prices, and you should obtain quotes for your specific project.

Item Typical cost (CHF) Notes
Internal staff time (total) Varies widely Depends on hours and seniority (SME vs enterprise)
External privacy consultant / DPO support Hourly, by provider Scope-dependent hours; obtain a quote
Legal review (external counsel) Hourly, by firm Complex legal issues or cross-border transfers increase cost
Outsourced ongoing privacy oversight (monthly) By provider If ongoing external oversight is needed
DPIA software / tool subscription By vendor Workflow and record-keeping tools
FDPIC consultation Confirm current position with the FDPIC Fees, if any, are set by the FDPIC’s applicable fee rules

What changes for 2026, revised FADP and FDPIC focus

The current compliance environment is defined by demonstrable accountability. The FDPIC’s attention has sharpened on profiling, automated individual decision-making, AI-driven processing, and cross-border transfers, precisely the areas where a data protection impact assessment Switzerland treats as evidence becomes indispensable. Organisations should expect that, in an investigation, the regulator will ask to see the DPIA, the screening record, and the residual-risk sign-off, and will test whether stated mitigations were actually implemented. Switzerland is frequently cited among jurisdictions with strong data protection standards, and the revised FADP reinforces that reputation by aligning key principles with European expectations while keeping Swiss-specific rules; Switzerland is also recognised by the European Commission as providing an adequate level of protection.

The practical effect is that undocumented risk decisions are increasingly likely to be treated as compliance failures in their own right. Consult the FADP text on Fedlex and current FDPIC commentary as your primary references.

Common pitfalls and how to avoid them

  • Superficial screening. Record a reasoned screening decision every time, including “no DPIA” outcomes, rather than skipping the step.
  • Poor scoping. Define processing boundaries in writing before assessing risk; vague scope undermines everything downstream.
  • Missing legal-basis/justification documentation. Capture the reasoning and the balancing test, not just the conclusion.
  • Weak vendor DPAs. Verify that processor contracts actually contain the safeguards your DPIA relies on.
  • No traceable sign-off. Ensure the person accepting residual risk has the authority to do so and that the acceptance is dated and versioned.
  • Failure to update. Trigger a review on material change, after incidents, and periodically.
  • Security implementation gaps. Confirm controls are deployed and tested, not merely planned in the mitigation table.
  • Underestimating cross-border transfers. Identify every transfer and its mechanism; these are a frequent FDPIC focus.
  • Poor stakeholder engagement. Involve security, business and legal early, and record their input.
  • Treating the DPIA as a one-off. Maintain version control and schedule the next review before closing the file.

Conclusion

Running a data protection impact assessment Switzerland recognises as defensible is a matter of discipline: screen every high-risk trigger, scope tightly, map the data honestly, document the legal basis/justification, score residual risk against a clear threshold, and keep an auditable trail through to implementation and review. Under the revised FADP and the current enforcement climate, the organisations that fare best in FDPIC scrutiny are those whose files answer the regulator’s questions before they are asked. Use the eleven-step process, retain the required documents, and treat the DPIA as living evidence of accountability rather than a box to tick.

For tailored support, connect with data privacy lawyers, Switzerland, and download our DPIA template & checklist Switzerland to put this process into practice under legal review.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Alexandros Manousakis at Privintelligent Solutions, a member of the Global Law Experts network.

Sources

  1. Federal Act on Data Protection (FADP), consolidated text, Fedlex
  2. Federal Data Protection and Information Commissioner (FDPIC)
  3. EUR-Lex, Regulation (EU) 2016/679 (GDPR)
  4. European Data Protection Board (EDPB), Guidelines & recommendations
  5. Information Commissioner’s Office (ICO), DPIA guidance

FAQs

What is the current data privacy law in Switzerland?
The revised Federal Act on Data Protection (FADP), in force since 1 September 2023 and available in consolidated form on Fedlex, governs the processing of personal data in Switzerland, together with the revised Ordinance on Data Protection. It sets out accountability duties, including the requirement in Article 22 to carry out a DPIA for processing likely to result in a high risk to the personality or fundamental rights of data subjects.
A DPIA is required when planned processing is likely to result in a high risk to the personality or fundamental rights of data subjects (Article 22 FADP). Assess this by reference to the nature, scope, circumstances and purpose of the processing, a high risk arises in particular from the use of new technologies, extensive processing of sensitive personal data, or systematic large-scale monitoring of public areas. Where the risk is present, a DPIA must be documented.
The GDPR does not apply directly inside Switzerland; the FADP is the governing law. However, the GDPR can apply to Swiss organisations that process the personal data of individuals in the EU/EEA in connection with offering goods and services to them or monitoring their behaviour. Many Swiss organisations therefore align their DPIA methodology with EDPB standards to satisfy both regimes.
There is no general filing requirement; you do not submit every DPIA to the FDPIC. Under Article 23 FADP, where high residual risk remains despite the measures envisaged, the controller must consult the FDPIC in advance (or, where the conditions are met, its own data protection adviser). Prepare the complete DPIA report before any consultation.
Small projects typically take one to three weeks, medium-complexity projects three to eight weeks, and large or cross-border projects several months, driven largely by mitigation implementation timelines rather than the assessment itself.
An executive summary, the scope and objectives, data flows, the legal basis/justification and any balancing test, the risk assessment (likelihood and impact), mitigation measures, residual risk, sign-offs, and the implementation plan with owners and deadlines.
Costs vary from a modest internal exercise to a substantial spend for complex, cross-border or AI-related processing that needs external consultants and legal review. Obtain quotes for your specific project; cross-border transfers and large-scale processing are the main cost drivers.
Review it periodically for ongoing high-risk processing, for example at least annually, and immediately whenever the processing changes materially or an incident occurs. A DPIA is a living record, not a one-time document.
file divorce ukraine
By Global Law Experts

posted 3 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Conduct a Data Protection Impact Assessment (DPIA) in Switzerland (2026)

Send welcome message

Custom Message