The Ruling
On 22 June 2026, Switzerland's Federal Administrative Court dismissed an appeal by Inkasso-Team AG and confirmed a prior order from the Federal Data Protection and Information Commissioner (FDPIC), ordering the debt-collection company to stop publishing personal data about alleged debtors online and to delete what it had already posted. The court also ordered Inkasso-Team to pay CHF 5,000 in procedural costs. It is a modest sum, but a significant precedent for how far a private company can go in the name of debt recovery.
What the Company Was Doing
Inkasso-Team AG ran a website, Schuldner-finden.com, that published names and identifying details of people it described as debtors, alongside information about associates, voice recordings, and — in some cases — unproven allegations involving fraud, loan defaults, or criminal proceedings. The company's stated rationale was twofold: crowdsourcing the whereabouts of people who had allegedly skipped out on debts, and warning third parties away from dealing with them.
The FDPIC opened a formal investigation and, in a decision dated 28 April 2025, found that the practice violated the processing principles in Article 6 of Switzerland's revised Federal Act on Data Protection (nFADP) — specifically transparency and proportionality — and that Inkasso-Team could not invoke any of the justification grounds in Article 31, since it had neither the consent of the people named nor an overriding public or private interest strong enough to justify the disclosure. The FDPIC ordered the publication stopped and the data deleted. Inkasso-Team appealed; the Federal Administrative Court's June 2026 ruling closes that appeal and leaves the order intact.
Steelmanning the Debt Collector's Case
Before dismissing the practice, it's worth taking seriously why a company would build this. Chronic non-payment is a real cost to small creditors, landlords, and tradespeople, and Switzerland's official debt enforcement register (the Betreibungsregister) is narrow: it records enforcement proceedings, is accessed through cantonal debt collection offices, and doesn't function as a searchable, public warning system that ordinary businesses can consult before extending credit. A company arguing that there's a genuine information gap here — and that surfacing it deters serial defaulters — isn't inventing a problem out of thin air. Proportionate data protection law should leave room for legitimate credit-risk tools, not treat every use of debtor data as presumptively suspect.
Why the Line Still Holds
But Inkasso-Team's model differs from a legitimate credit registry in ways that matter under Article 31. The official enforcement register only lists debts that have actually entered a judicial enforcement process, is accessed on a need-to-know basis, and expires the entries after a fixed period. Schuldner-finden.com published alleged debtors — no judicial finding required — attached unrelated and unproven claims about fraud or criminal conduct, included third parties who weren't debtors at all, and left everything indefinitely and publicly searchable with no independent adjudication of accuracy or relevance. That combination is precisely what the proportionality principle exists to catch: a measure whose intrusiveness on personality rights is out of proportion to what a legitimate registry would actually need to achieve deterrence.
The court didn't need to invent new law to reach that conclusion — the FDPIC had already flagged the site as unlawful in September 2021, four and a half years before the final order, meaning Inkasso-Team continued operating the practice through a formal warning, a nFADP-based investigation, a prohibition order, and an appeal before finally taking the site down.
A Business-Friendly Regime, Working as Designed
Switzerland's nFADP, in force since September 2023, was deliberately built lighter than the GDPR — no blanket DPO mandate for private firms, no EU-style turnover-based administrative fines against companies (personal criminal liability attaches to individuals, not the corporate fine schedule that dominates EU headlines). That design choice reflects a bet that Swiss enforcement can be proportionate and still effective without the compliance overhead that smaller EU-market entrants complain about. This case is a fair test of that bet, and it holds up: the FDPIC didn't reach for maximal punishment — CHF 5,000 is a rounding error for a debt-collection firm — but it did secure the substantive remedy that mattered, a dead website and a confirmed prohibition, through ordinary administrative and judicial process.
The Compliance Signal
For Swiss fintechs, credit-scoring startups, and marketplaces that handle reputational or payment-history data, the takeaway isn't that publishing debtor information is categorically off-limits — Article 31 still leaves room for tools built around consent or a genuine, demonstrable overriding interest. The takeaway is narrower and more useful: "it works as a deterrent" is not, by itself, an overriding interest under Swiss law. A product that skips consent, skips proportional limits on scope and duration, and folds in unadjudicated allegations to make the deterrent sharper is building on ground the FDPIC and now the Federal Administrative Court have already ruled unstable.