Switzerland Switzerland FDPIC nFADP data protection

Switzerland's Data Protection Watchdog Blames Bureaucratic Culture, Not Law, for E-ID and Police-Database Risk

The FDPIC's 2025/2026 report says federal leadership downplays surveillance risk in digital mega-projects, not that Switzerland's data law is too weak.

Switzerland's Data Protection Enforcement, 2025/2026 People of Internet Research · Switzerland 2,000+ Breach notifications received Possible data protection violation… 156 Formal interventions made Times the FDPIC intervened against… 9 Formal investigations opened Out of 22 preliminary clarificatio… 13 BGÖ exemption gaps flagged Freedom of Information Act carve-o… peopleofinternet.com
Switzerland's Data Protection Enforcem… People of Internet Research · Switzerland 2,000+ Breach notifications re… 156 Formal interventions ma… 9 Formal investigations o… 13 BGÖ exemption gaps flagged peopleofinternet.com

Key Takeaways

Switzerland's data protection regulator has delivered an unusually pointed diagnosis of what ails its government's digital transformation — and it isn't a gap in the law. In its 33rd activity report, published 30 June 2026 and submitted to the Federal Assembly, the Federal Data Protection and Information Commissioner (FDPIC) states plainly that federal offices are competent at spotting conventional information-security threats — hacks, breaches, unauthorized access — but struggle institutionally to reckon with the "surveillance and control potential" that emerges once citizen data from separate systems becomes interconnected at scale (FDPIC, Annual Report of the FDPIC).

The report names the projects it's worried about: the national e-ID rollout, the AGOV federal authentication service, e-justice (electronic case management moving into courts and social insurance), electronic postal services, and the police query platform, POLAP (Steiger Legal analysis). None of these is inherently objectionable — digitizing court filings and letting police query databases through one interface instead of ad hoc mutual assistance requests are exactly the kind of efficiency gains a modern state should pursue. The FDPIC isn't arguing otherwise. Its complaint is narrower and, frankly, harder to dismiss: that whether a given system carries systemic surveillance risk depends heavily on the "leadership culture" of the federal office running it, and that some offices resist even acknowledging the risk exists, let alone disclosing how they're managing it.

The Numbers Behind the Warning

The report isn't just qualitative hand-wringing. In the reporting year (roughly April 2025 to March 2026), the FDPIC logged more than 2,000 notifications of possible data protection violations, intervened 156 times against responsible parties, and opened 22 preliminary clarifications that produced 9 formal investigations (itmagazine.ch). That's a regulator that is clearly active, not toothless — and its enforcement authority under the revised Federal Act on Data Protection (nFADP, in force since September 2023) was itself tested and upheld: on 6 October 2025, the Federal Administrative Court dismissed an appeal by the citizens' group Bürgerforum Schweiz against an FDPIC processing ban, confirming the office's power to order compliance rather than merely recommend it.

The Police Platform Test Case

The report's timing lines up with a live legislative fight that illustrates its concern precisely. POLAP, the federal police query platform, has operated since August 2024 but so far only connects federal systems (RIPOL) and EU/Schengen databases — cantonal police databases can't yet plug in because there's no constitutional basis for it. On 18 February 2026 the Federal Council opened a consultation on exactly that: a partial revision of the Federal Act on Police Information Systems plus an amendment to Article 57 of the Federal Constitution, running through 26 May 2026 (EJPD, Verbesserung der polizeilichen Datenabfrage). The stated rationale is mundane and legitimate: today's mutual-assistance workflow for cross-cantonal police queries is slow, duplicative, and a poor fit for urgent cases. But a unified national query layer spanning every canton's police data is also precisely the kind of "complexly interlinked" citizen-data system the FDPIC's report flags as systemically risky regardless of how well any single agency secures its own database.

Where the Steelman Holds — and Where It Doesn't

There's a real case for treating this as overcaution. Fragmented cantonal police data has genuine costs: investigative delay, duplicated casework, and — in a federal system with 26 separate cantonal forces — real public-safety externalities from slow information-sharing. A regulator that treats every consolidation project as inherently suspect risks freezing government IT in its current, more fragmented and arguably less secure state, since scattered legacy systems are themselves a security liability. The FDPIC's report does not argue for blocking these projects; it explicitly credits federal offices for taking conventional cybersecurity seriously.

What the report gets right is that data protection risk and information security risk are not the same thing, and Swiss federal offices are conflating them. A system can be perfectly hardened against external hackers and still create surveillance capacity that didn't exist when the same data sat in disconnected silos — that's a design-and-governance question, not a patching question, and it's the one federal leadership is reportedly reluctant to engage with in public. The appropriate regulatory response to that gap is not to slow-walk e-ID or POLAP, but to require the kind of proactive, public risk disclosure the FDPIC says some offices resist — data protection impact assessments made available for scrutiny before systems go live, not after a breach.

The report's parallel complaint — that federal offices are increasingly using their own legislative drafting power to carve their working documents out of the Freedom of Information Act (BGÖ), leaving 13 exemptions on the books and 11 more proposed after 20 years of the law's operation — reinforces the same underlying point. A government that wants public trust in digital mega-projects that consolidate citizen data needs to be more transparent about them over time, not less. Switzerland's data protection law itself isn't the bottleneck here; institutional willingness to be examined is.

Sources & Citations

  1. FDPIC — Annual Report of the FDPIC (33rd report, 2025/2026)
  2. EJPD — Verbesserung der polizeilichen Datenabfrage (consultation, 18 Feb 2026)
  3. Steiger Legal — EDÖB-Tätigkeitsbericht 2025/2026: KI, systemische Risiken und Transparenz
  4. IT Magazine — Tätigkeitsbericht des EDÖB: Grosses Lob und harsche Kritik an Verwaltung