FADP Article 5 lit. c, Sensitive Personal Data Including Biometric Data
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 September 2023.
A sensitive categories rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Obtain express, affirmative consent, opt-in rather than opt-out, before creating a voiceprint or other biometric identifier from a person in Switzerland, or establish another Article 6 basis for the processing.
- Perform a Data Protection Impact Assessment before large-scale processing of biometric or other sensitive personal data, or before systematic large-scale public-space monitoring, under FADP Article 22.
What it reaches
Excludes recording-derived identifiersNo
Who checks it
Audit expectation
none
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 5 lit. c FADP defines sensitive personal data as a closed list: data on religious, philosophical, political or trade union views and activities; health data; data on the intimate sphere or racial or ethnic origin; genetic data; biometric data that uniquely identifies a natural person; and data on administrative or criminal proceedings and sanctions. Genetic and biometric data are the two categories the 2023 revision added.
A controller relying on consent for sensitive personal data needs express consent under Article 6 para. 7, and large-scale processing of sensitive personal data or systematic large-scale public-space monitoring triggers a mandatory Data Protection Impact Assessment under Article 22.
There is no dedicated Swiss biometric statute and no statutory biometric-specific retention or destruction schedule; retention is governed by the FADP's general proportionality and storage-limitation principle, Article 6 para. 3-4: keep only as long as the purpose requires, then delete or anonymize.
The controlling recent authority is a live FDPIC enforcement action rather than a statute amendment: on 16 May 2025 the FDPIC concluded its investigation into PostFinance's voice-recognition system and found the processing violated the proportionality principle because voiceprints were being created on an opt-out basis rather than opt-in.
The FDPIC ordered PostFinance to obtain explicit, affirmative consent before creating a voiceprint and to delete every voiceprint created without it, with a compliance deadline of 1 October 2025. PostFinance has appealed to the Federal Administrative Court, and the outcome of that appeal is not established; the FDPIC's order is treated as its currently stated position, not as final.
When LexLint raises it
processes_biometricsprocesses_voicehigh_risk_decisions
Read the law
Fedlex, the Swiss Federal Council's official legislation portal
FDPIC, official conclusion of the PostFinance investigation (16 May 2025)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.