Chapter 3
Swiss FADP Article 24: Notifications of data security breaches
1 The controller shall notify the FDPIC of any breach of data security that is likely to lead to a high risk to the data subject's personality or fundamental rights as quickly as possible.
2 In the notification, it shall as a minimum specify the nature of the breach of data security, its consequences and the measures taken or planned.
3 The processor shall notify the controller of any breach of data security as quickly as possible.
4 The controller shall inform the data subject if this is required for their protection or if the FDPIC so requests.
5 It may limit, delay or dispense with the provision of information to the data subject if: (a) there is a reason for doing so pursuant to Article 26 paragraph 1 letter b or paragraph 2 letter b or the provision of information is prohibited by a statutory duty of confidentiality; (b) the provision of information is impossible or requires disproportionate effort; or (c) the provision of information to the data subject is equally guaranteed by making a public announcement.
6 A notification made pursuant to this Article may only be used against the person required to notify in criminal proceedings with that person's consent.
Switzerland enacts in German, French and Italian. This is Fedlex's English translation, which Fedlex itself publishes without legal force. Where a word matters, the German, French or Italian text governs and this page does not. Every other instrument in this library is reproduced from its own authentic language text; this one is the exception and says so on every page.
Source text reproduced from Fedlex, Classified Compilation SR 235.1, English translation, version in force from 1 September 2023 and marked for verification against the official source. Cross-checked against a second reproduction.