Data Protection Impact Assessment in Switzerland: When it is mandatory, how a threshold analysis assesses risks, and when the FADP is required.
A Data Protection Impact Assessment (DPIA) must be carried out in advance under Art. 22 DPA if a planned processing operation may pose a high risk to the personality or fundamental rights of affected individuals. If a high residual risk remains after the intended measures, the FADP must be consulted. Those who are uncertain should not wait but immediately conduct a brief threshold analysis to classify their own processing.
In short: - For extensive processing of particularly sensitive personal data or systematic monitoring, the obligation to conduct a DPIA arises under Art. 22 DPA. - A brief threshold analysis helps determine the effort required and whether a detailed DPIA is necessary. - The complete DPIA includes a project description, risk analysis, catalogue of measures, and legal bases, as well as an implementation plan. - If a high residual risk remains, the FADP must be consulted or external data protection advice must be engaged. - DPIA records must be documented in a traceable manner, stored separately, and reviewed regularly.
Table of Contents
- What a Data Protection Impact Assessment achieves
- When a DPIA becomes mandatory under Art. 22 DPA
- Who is responsible for the data protection risk analysis in Switzerland
- The threshold analysis as the first step
- Structure of a complete DPIA
- Consultation of the FADP and the role of data protection advice
- Record-keeping and storage under the DPO
- Checklist: Implementing the DPIA step by step
- Perspective: A good DPIA is precaution, not a mandatory exercise
- Support with the Data Protection Impact Assessment by Sobiera-legal
- Sources
- FAQ
What a Data Protection Impact Assessment achieves
A DPIA is not a form to be ticked off but a tool to identify, assess, and treat risks to the personality and fundamental rights of affected individuals early on. The FADP describes it precisely in this sense: as a structured process, not a bureaucratic mandatory exercise.
Three points summarise the purpose:
- It reveals where data processing could actually harm individuals before the harm occurs.
- It protects not only data but the underlying fundamental rights, such as privacy and informational self-determination.
- It belongs in an organisation's risk management, not in a separate compliance drawer.
When a DPIA becomes mandatory under Art. 22 DPA
The Swiss Data Protection Impact Assessment is mandatory under Art. 22 DPA whenever the planned processing is likely to create a high risk to the personality or fundamental rights of the data subject. This obligation applies to both private and public controllers; there is no exception for small businesses.
Typical triggers for a high risk:
- Extensive processing of particularly sensitive personal data, such as health, biometric, or criminal register data.
- Systematic and extensive monitoring of publicly accessible areas, for example through video analysis.
- Pro tip: Profiling with high risk or automated decisions using artificial intelligence that produce legal effects for individuals.
- Disclosure of personal data to processors or group companies in states without an adequate level of data protection.
Those who recognise any of these criteria should not postpone the preliminary review. The earlier the assessment is made, the easier it is to adjust a project before systems go live.
Who is responsible for the data protection risk analysis in Switzerland
The obligation to conduct a DPIA always falls on the controller, i.e., the entity that decides on the purposes and means of the processing. A processor can support, for example with technical details on infrastructure, but bears separate, distinct obligations.
In practice, a clean data protection assessment in Switzerland requires multiple perspectives:
- IT managers provide details on system architecture, interfaces, and security measures.
- Business departments explain the purpose and actual scope of data processing.
- A data protection officer reviews the legal classification and, under certain conditions, can even replace the consultation of the FADP, but must be properly registered for this.
Those who do not have internal resources for this assessment often engage external data protection experts in Switzerland, especially for cross-border data flows with increased legal complexity.
The threshold analysis as the first step
Before a complete DPIA is created, a brief preliminary review, the threshold analysis, is worthwhile. It answers in a few questions whether a high risk exists at all and saves unnecessary effort for non-critical projects.
A useful threshold analysis asks at least:
- Which categories of personal data are processed, and do they include particularly sensitive data?
- How many individuals are affected, and how extensive is the processing in terms of time and space?
- For what purpose is the processing carried out, and is this purpose recognisable to those affected?
- Are new technologies being used, such as AI-based evaluation or biometric recognition?
Pro tip: Document the threshold analysis in writing, even if the result is “no DPIA required.” This short note is often the only proof in a dispute that a review was conducted at all.
The FADP provides templates for this purpose; additionally, many controllers orient themselves to international guidelines from CNIL, ISO, or EDPB, which the FADP itself cites as a reference.
Structure of a complete DPIA
If the threshold analysis is positive, the actual Data Protection Impact Assessment follows. It consists of four building blocks that have proven effective in this order.
- Project description: Nature, scope, and purpose of the processing, affected groups of individuals, data categories used, and systems involved.
- Risk analysis: Assessment of each identified risk based on likelihood and impact, often visualised in a 6x6 matrix.
- Catalogue of measures: Technical and organisational measures to reduce the risk, in accordance with the FADP guide on TOM.
- Residual risk assessment and legal bases: How high is the risk after implementing the measures, and on which legal basis is the processing supported?
An implementation plan is also part of it: Who implements which measure by when, and who checks the effectiveness? Without this plan, the DPIA remains an analysis without consequence, and this is what the FADP most frequently criticises in practice.
Consultation of the FADP and the role of data protection advice
If a high residual risk remains after implementing all measures, Art. 23 DPA prescribes the consultation of the FADP. This prior consultation is not a formal self-purpose but a genuine control by the supervisory authority.
- The FADP generally responds within two months; this deadline can be extended for complex cases.
- Private controllers can bypass the consultation if a properly registered data protection officer conducts the risk assessment internally.
- Certified systems or a code of conduct approved by the FADP can also reduce the DPIA obligation, as provided for in Art. 22 DPA.
Those who regularly carry out processing with high risk, for example in the area of profiling or international data transfers, should institutionalise this exception with a fixed data protection advisory service rather than deciding anew each time.
Record-keeping and storage under the DPO
The technical side of the Data Protection Impact Assessment in Switzerland does not end with the report. The Ordinance on the Data Protection Act requires traceable record-keeping of the processing, and these records must be stored.
- At minimum, storing, reading, modifying, disclosing, deleting, and destroying of personal data must be recorded, as stipulated in the FADP recommendation on record-keeping under the DPO.
- Records should be stored for an appropriate period, and the DPIA documentation must be stored for a legally prescribed time after the end of the processing.
Pro tip: Store DPIA reports and records separately from the operational system, with restricted access. In the event of an investigation by the FADP, it counts how quickly you can submit a complete, unaltered proof.
Checklist: Implementing the DPIA step by step
Those who must undertake a Data Protection Impact Assessment in Switzerland from scratch can orient themselves to the following roadmap.
- Conduct a threshold analysis and record it in writing, even if the result is negative.
- If positive: Describe the project, data categories, purpose, and systems involved in detail.
- Assess risks systematically, for example with a matrix of likelihood and impact.
- Define technical and organisational measures and reassess the remaining residual risk.
- If a high residual risk remains, consult the FADP or engage a registered data protection advisory service.
- Store the report, catalogue of measures, and records securely and separately.
- Review the DPIA periodically, especially when there are changes to systems, purposes, or data categories.
| Step | Core question | Result |
|---|
| Threshold analysis | Is there a high risk? | Yes/No decision with justification |
| Risk analysis | How likely and how severe is the harm? | Risk matrix with classification |
| Measures | How can the risk be reduced? | Catalogue of measures with implementation plan |
| Consultation | Does a high residual risk remain? | FADP statement or internal approval |
This sequence prevents the most common problem in practice: a DPIA that exists but never leads to concrete measures.
Perspective: A good DPIA is precaution, not a mandatory exercise
A carefully prepared DPIA saves organisations a lot of explanatory effort later, especially towards the FADP. Those who embed it in existing processes, such as an information security management system, rather than treating it as a standalone project, gain a robust defensive position. In cross-border cases involving multiple legal systems, Sobiera Legal Consulting supports clients precisely at this point.
— Bitblade
Support with the Data Protection Impact Assessment by Sobiera-legal
Those who do not want to conduct their own data protection risk analysis in Switzerland alone do not have to start from zero. A data protection check under the revised DPA can start exactly where the threshold analysis ends: with the legal classification of the specific case, not with a generic template.
Direct access to lawyers in multiple languages pays off particularly for international data flows, for example when personal data is transferred to group companies in third countries and the question of the adequacy of the level of data protection must be clarified. Legal support can accompany controllers from the initial assessment to the possible prior consultation with the FADP. An initial assessment of your own project can be requested via the package offers of Sobiera-legal, where the terms for an initial consultation can also be found.
This article contains general information and does not replace advice from a qualified lawyer. Please consult a qualified legal professional regarding your personal situation before acting on the basis of this content.
Sources
FAQ
When is a Data Protection Impact Assessment required?
A DPIA is necessary if a planned processing operation is likely to create a high risk to the personality or fundamental rights of affected individuals, for example in the case of extensive processing of particularly sensitive data or systematic monitoring. The exact criteria are set out in Art. 22 DPA.
Is the GDPR also valid in Switzerland?
The European GDPR does not apply directly in Switzerland; the revised Swiss Data Protection Act (DPA) is decisive. Swiss companies may nevertheless be subject to the GDPR if they process personal data of individuals in the EU and the applicable criteria there are met.
Who must carry out a Data Protection Impact Assessment?
The obligation falls on the controller, i.e., the entity that determines the purpose and means of data processing, regardless of whether it is a private company or an authority. Those who do not have their own data protection expertise often engage external data protection advice for this, as offered by Sobiera-legal through the data protection check.
Is it a criminal offence in Switzerland to pass on data to third parties?
The transfer of personal data to third parties is not per se a criminal offence, but it must be based on a valid legal basis and comply with the principles of the DPA. If this basis is missing or central information obligations are violated, supervisory measures and, in certain cases, criminal sanctions against responsible persons may apply.
Recommendations