Switzerland Switzerland FDPIC nFADP data protection

Swiss Court Confirms Debt Collectors Cannot Publish Alleged Debtors' Names Online to Force Payment

Federal Administrative Court upholds FDPIC order against Inkasso-Team AG, ruling that public 'debtor shaming' violates personality rights under the nFADP with no valid justification.

Switzerland's Debtor-Shaming Ruling, By the Numbers People of Internet Research · Switzerland 14 months Order to final ruling From the FDPIC's 28 April 2025 ord… CHF 250,000 Max individual fine Maximum criminal fine for executiv… CHF 50,000 Max organizational fine Fallback fine against the company … 2 actions Debtor-site cases in 14 months Inkasso-Team AG plus a separate op… peopleofinternet.com
Switzerland's Debtor-Shaming Ruling, B… People of Internet Research · Switzerland 14 months Order to final ruling CHF 250,000 Max individual fine CHF 50,000 Max organizational f… 2 actions Debtor-site cases in 14 months peopleofinternet.com

Key Takeaways

Switzerland's Federal Administrative Court has closed the door on a debt-collection tactic that has quietly persisted for years: publishing the names and details of alleged debtors online in the hope that public shame, or a tip from a stranger, will do what a court judgment couldn't.

In a judgment dated 22 June 2026 and published by the Federal Data Protection and Information Commissioner (FDPIC) on 20 August 2026, the court dismissed an appeal by Inkasso-Team AG, a Swiss debt-collection firm that operated a website listing alleged debtors by name to help locate them and to "warn third parties" about them (FDPIC ruling summary). The ruling, case A-3891/2025, upholds the FDPIC's original order of 28 April 2025, which found the practice violated the transparency and proportionality principles in Article 6 of the revised Federal Act on Data Protection (nFADP) and directed the company to stop publishing the data and delete what was already online (FDPIC latest news).

The case for public debtor lists

Before dismissing the practice, it's worth taking seriously why a debt collector would build such a site in the first place. Chasing an absconding debtor is genuinely hard: Swiss civil procedure gives creditors formal tools — the Betreibungsregister (debt enforcement registry), garnishment, seizure — but these require a known address and can take months. A tradesperson, landlord, or small creditor who has already been stiffed once has a real interest in warning others and in crowdsourcing a debtor's whereabouts. Notably, the nFADP itself recognizes this logic in a narrow form: Article 31 lists assessing a person's creditworthiness as a legitimate justification for processing their data, which is exactly why licensed credit bureaus are allowed to operate. Inkasso-Team AG's defense was, in effect, that its website was doing informally what credit-reporting law already permits formally.

The court rejected that framing, and rightly so. The judgment confirmed that publishing personal data "for the purpose of locating alleged debtors and warning third parties" constitutes a violation of personality rights under Article 30 nFADP, and that no justification under Article 31 — consent, an overriding private or public interest, or a legal basis — applies (FDPIC ruling summary). The distinction is precise, not sweeping: a regulated credit bureau assessing risk for a specific contracting decision is a bounded, accountable use of data. An open, indefinite public list of names, published before any court has determined the underlying debt is even valid, and aimed at crowdsourcing enforcement, is something else — closer to extra-judicial punishment than credit assessment. The court didn't need to invent new law to reach that conclusion; it applied personality-rights principles that have existed in Swiss data protection law for decades, just now under the nFADP framework that took effect 1 September 2023.

Proportionate enforcement, not overreach

What makes this ruling a useful data point — rather than a cautionary tale — is its restraint. The FDPIC did not seek to ban debt collection, credit reporting, or the Betreibungsregister itself. It targeted one specific, disproportionate practice and left the legitimate machinery of debt enforcement untouched. That's the proportionality this publication generally argues regulators should aim for: narrow findings tied to concrete harm, not blanket restrictions on an industry. It also took over 14 months from the original FDPIC order to a final, binding court confirmation — the company got a full appeal on the merits before the state's coercive power was applied, which is exactly how due process should work even in fast-moving data cases.

The case is not isolated. In a separate matter, the FDPIC opened an investigation in February 2026, after a January 2026 report, into another operator that had made debtors' ID documents and photos public; the operator deleted the data and received a warning rather than a formal order (FDPIC latest news). Two enforcement actions against debtor-shaming sites within roughly fourteen months suggest a real, if small, corner of the debt-collection market has been testing how far "transparency" can be stretched — and the regulator is now answering consistently.

The sharper edge worth watching

Where Swiss law diverges from the GDPR model most other European readers are used to is enforcement mechanics: the nFADP is built on criminal, not administrative, liability. Fines of up to CHF 250,000 attach to the individual executives or data protection officers found responsible for intentional violations, with a fallback of up to CHF 50,000 against the organization only if no responsible individual can be identified (IAPP analysis). That's a genuinely different incentive structure — it concentrates deterrence on named decision-makers rather than spreading it across shareholders as a cost of doing business, which in principle should make compliance a personal priority for the people who actually design a data practice. The Inkasso-Team ruling itself was a cease-and-delete order, not a criminal fine, but it establishes the factual and legal predicate — an unjustified personality-rights violation — on which future criminal exposure could be built if a company repeats the conduct after being told to stop. Regulators and courts applying this framework should keep the line this ruling draws crisp: legitimate, regulated creditworthiness assessment stays protected; unbounded public shaming does not. Blur that line and the same statute that just delivered a proportionate, narrow result could start chilling ordinary credit-risk data sharing that the law was never meant to touch.

Sources & Citations

  1. FDPIC: Ruling against Inkasso-Team AG
  2. FDPIC: Latest news (court confirms FDPIC practice)
  3. Fedlex: Federal Act on Data Protection (DSG/nFADP) text
  4. IAPP: Revised Swiss data protection law implications