Switzerland Switzerland FDPIC nFADP data protection

Switzerland's Debtor-Shaming Website Case Shows the nFADP's Proportionality Principle Working as Designed

The FDPIC closed a probe into a site that posted debtors' ID scans with only a warning, rewarding fast remediation over punitive action.

Two Paths Through Swiss Data Protection Enforcement People of Internet Research · Switzerland ~5 months Investigation to warning FDPIC opened its probe in February… CHF 250,000 Max individual criminal fine nFADP Art. 60-63 penalize intentio… Apr 28, 2025 Comparable formal ruling date Inkasso-Team AG was formally order… peopleofinternet.com
Two Paths Through Swiss Data Protectio… People of Internet Research · Switzerland ~5 months Investigation to warning CHF 250,000 Max individual criminal fine Apr 28, 2025 Comparable formal ruling date peopleofinternet.com

Key Takeaways

What happened

The Federal Data Protection and Information Commissioner (FDPIC) disclosed on June 25, 2026 that it had formally warned an unnamed website operator after finding that the site had made identification card copies, photographs, and other personal documents of alleged debtors publicly accessible without any legal basis. The FDPIC says it learned of the unlawful publication through a complaint in January 2026 and opened a formal investigation the following month under Article 49 of the revised Federal Act on Data Protection (nFADP). During the proceedings, the operator deleted the published material — which let the regulator close the file under Article 51(5) nFADP with a warning and procedural fees rather than a binding order.

The steelman for the regulator

Before litigating the proportionality question, it's worth being honest about why this kind of publication is genuinely dangerous. A scanned government ID is not an ordinary piece of personal data — it's a master key to identity theft, account takeover, and targeted harassment, especially when paired with a photo and an accusation of debt. Unlike a name on a court docket, an ID scan serves no informational purpose that a debtor-locating website actually needs; it adds risk without adding truth-value to the claim being made. And because the people named have no say in whether they end up on such a site — no notice, no opportunity to contest before publication — the harm lands before due process even starts. A regulator moving quickly to stop that kind of exposure, even informally, is doing exactly what a data protection authority exists to do.

Why the outcome is still the right one

The FDPIC's response nonetheless illustrates something the nFADP got right when it entered into force on September 1, 2023: enforcement calibrated to conduct, not to headlines. The statute lets the Commissioner close a case with nothing more than a warning when the controller fixes the problem during the investigation (Art. 51(5) nFADP) — as opposed to issuing a binding order that can be appealed, litigated, and dragged out for years. That's the more efficient outcome for everyone: the exposed individuals get their documents removed fast, the regulator doesn't have to spend scarce investigative capacity fighting a court battle over a case the operator already resolved, and the incentive structure rewards operators who cooperate rather than stonewall.

The contrast is instructive. In a separate, formally published decision dated April 28, 2025, the FDPIC ordered Inkasso-Team AG, a debt-collection firm, to stop publishing alleged debtors' personal data online, finding the practice violated the proportionality principle and lacked the justification required for such disclosure. Inkasso-Team contested the finding and appealed to the Federal Administrative Court, where the matter remains pending — meaning the company is now absorbing the cost, delay, and reputational exposure of a named, public ruling that it chose to fight rather than a quiet warning it could have avoided by simply taking the material down. Two operators, functionally similar conduct, two very different enforcement paths — and the difference tracked behavior, not regulatory whim.

The gap worth watching

There is a legitimate critique buried in this comparison, and it cuts against easy praise for either side. Because the warned operator was never named, the public gets no signal about which website was hosting sensitive debtor documents, no deterrent effect for copycat sites, and no way to confirm the FDPIC's own account of what was removed. Inkasso-Team, by contrast, is now permanently associated with a published enforcement decision precisely because it exercised its right to appeal. A system that anonymizes cooperative violators while publicly naming those who litigate risks quietly discouraging operators from testing genuinely contestable enforcement theories in court — which is a due-process cost, not a feature. Regulators serious about proportionate enforcement should also be transparent about it; anonymized warnings are defensible for privacy reasons on the complainant's side, but they shouldn't become a shield for repeat offenders simply because deletion is cheap.

The bigger enforcement backdrop

It's also worth remembering how much sharper the nFADP's teeth can get from here. Articles 60–63 of the Act create criminal fines of up to CHF 250,000 for intentional violations — but, unusually among major privacy regimes, those fines target the individual who committed or tolerated the violation (an employee or executive), not the company itself, and only for willful conduct prosecuted by cantonal authorities on complaint. That structure gives Swiss enforcement a personal-accountability edge the GDPR's company-fine model lacks, while reserving it for genuinely intentional misconduct rather than sloppy web development. A first-time operator who deletes offending content the moment a regulator calls is precisely the case that structure should treat leniently. This one did.

Sources & Citations

  1. FDPIC: warning to website operator
  2. FDPIC: ruling against Inkasso-Team AG
  3. Pestalozzi: revFADP sanctions explainer
  4. Steiger Legal: EDÖB warning analysis