Law / Switzerland

Switzerland

12 of 13 named instruments researched to a stage, across four of the six areas of law we track: 10 in force, 1 enacted but not yet in force and 1 proposed. As of 15 September 2026.

When they take effect10 of 12 carry a date, 2 do not. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 1 instrument (1 in force) 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 1 instrument (1 in force) ’20 2021: 0 instruments 2022: 0 instruments 2023: 6 instruments (6 in force) 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 1 in force, 1 proposed

Research summary (209 words)

Switzerland has no horizontal AI statute and no AI-transparency or output-labelling duty in force. On 12 February 2025 the Federal Council decided to pursue ratification of the Council of Europe Convention on Artificial Intelligence and to make the necessary amendments to Swiss law, while continuing separately to regulate AI in specific sectors such as healthcare and transport; this is a policy decision rather than enacted or proposed legislation.

Switzerland signed that Convention, the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, on 27 March 2025, an international treaty not yet ratified by Switzerland and not yet part of Swiss domestic law.

The Swiss Criminal Code's pornography provision, unchanged in this respect since the technology-neutral wording of its 2014 revision, criminalises producing, possessing or distributing pornographic depictions of non-genuine sexual acts with minors, reaching a computer-generated or otherwise synthetic depiction on the same terms as one involving a real minor.

A duty attaching to personal data, including the FDPIC's 8 May 2025 confirmation that the Federal Act on Data Protection reaches AI systems and its stated prohibition on comprehensive real-time facial recognition and social scoring, is described in the privacy topic's own document for this jurisdiction and is not repeated here.

AI governance

Council of Europe Framework Convention on Artificial Intelligence, Swiss Signature

Council of Europe Framework Convention on Artificial Intelligence and Human Rights Democracy and the Rule of Law (CETS No. 225), signed by Switzerland 27 March 2025Council of Europe, official Artificial Intelligence newsroom

Proposed: draft date not recorded. Signed, with consent not yet expressed, dated 27 March 2025, as of 12 September 2026.

What this law does

Switzerland signed the Council of Europe's Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law in Strasbourg on 27 March 2025, the first internationally binding treaty aimed at ensuring that AI systems remain consistent with human rights, democracy and the rule of law.

Switzerland has signed but has not yet ratified the Convention; on 12 February 2025 the Federal Council decided to pursue ratification and to make the amendments to Swiss law that would require.

What it requires

AI prohibited practices

Swiss Criminal Code, Pornographic Depictions of Non-Genuine Sexual Acts with Minors

Swiss Criminal Code (StGB/CP/CP), SR 311.0, Art. 197 para. 4-5Swiss Criminal Code, official English translation, Fedlex

In force since 1 July 2014. Binds public and private bodies.

What this law does

Article 197 paragraph 4 penalises, with a custodial sentence not exceeding three years or a monetary penalty, any person who produces, imports, stores, markets, advertises, exhibits, offers, shows, passes on or makes accessible to others, acquires, or procures or possesses via electronic media or otherwise, items or recordings that contain sexual acts involving animals or non-genuine sexual acts with minors; where the items or recordings instead contain genuine sexual acts with minors, the penalty rises to a custodial sentence not exceeding five years, in the wording in force since 1 July 2024.

Paragraph 5 separately penalises, with a custodial sentence not exceeding one year or a monetary penalty, consuming or producing for one's own consumption the same non-genuine content. Paragraph 9 excludes an item from being regarded as pornographic where it has a cultural or scientific value that justifies its protection by law.

What it requires

Privacy law6 instruments, 6 in force

Research summary (136 words)

Switzerland's comprehensive private-sector data protection law is the revised Federal Act on Data Protection (nFADP), SR 235.1, in force since 1 September 2023, its own statute aligned with but distinct from General Data Protection Regulation (GDPR) rather than an EU member state's implementation of it.

Biometric data has been a sensitive personal data category since the 2023 revision, with no dedicated biometric statute; the most consequential recent development is the FDPIC's 16 May 2025 order against PostFinance to obtain opt-in consent before creating a voiceprint, currently under appeal to the Federal Administrative Court.

Switzerland's own primary legislative text (fedlex.admin.ch) is served as a JavaScript single-page application that returns only its unrendered application shell, not parseable text, so several findings below rest on consistent secondary corroboration rather than an independently read primary quote; this is recorded per finding, not smoothed over.

Breach notification

FADP Article 24, Breach Notification in Switzerland

Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 24Fedlex, the Swiss Federal Council's official legislation portal

In force since 1 September 2023. Binds public and private bodies.

What this law does

A controller must notify the FDPIC as soon as possible once aware of a data security breach likely to result in a high risk to the data subject's personality or fundamental rights. Unlike General Data Protection Regulation (GDPR) there is no fixed statutory clock: commentary treats 72 hours as a practical benchmark drawn from the Federal Council's explanatory message, not a binding deadline.

Notification to the data subject is required only where necessary to protect them, or if the FDPIC orders it; the controller may limit, defer, or omit subject notification if it is impossible, disproportionate, or superseded by a public communication of comparable effect.

What it requires

Comprehensive regime

Federal Act on Data Protection (nFADP), General Processing Principles

Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 1-4, 6, 30-31Fedlex, the Swiss Federal Council's official legislation portal

In force since 1 September 2023. Binds public and private bodies.

What this law does

Switzerland's comprehensive private-sector data protection law is the revised Federal Act on Data Protection (nFADP in English, revDSG in German, nLPD in French), SR 235.1, in force since 1 September 2023. It replaces the 1992 FADP and is Switzerland's own statute, aligned with but distinct from General Data Protection Regulation (GDPR).

Processing personal data is not consent-gated by default the way GDPR is opt-in for many bases; the FADP instead prohibits processing that violates a data subject's personality rights unless justified, by consent, an overriding private or public interest, or law.

Controllers ("responsible persons") and processors are distinguished in Article 5 lit. j-k, with duty allocation similar in shape to GDPR's controller and processor split but not identical in mechanics; the Ordinance on Data Protection (ODP) adds implementing detail rather than a separate top-level instrument.

What it requires

Cross border transfer

FADP Articles 16-17, Cross-Border Transfer of Personal Data from Switzerland

Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 16-17Fedlex, the Swiss Federal Council's official legislation portal

In force since 1 September 2023. Binds public and private bodies.

What this law does

Transfer abroad is permitted without extra safeguards to a state or international body the Federal Council has found provides an adequate level of protection, a maintained list that includes the EU and EEA states.

Absent adequacy, a transfer needs a safeguard: standard contractual clauses, the EU SCCs work with a Swiss-law addendum, binding corporate rules, or one of the narrower Article 17 derogations, explicit consent, contract necessity, overriding public interest, life or safety, or transfer of data from a public register. This is structurally the General Data Protection Regulation (GDPR) Chapter V mechanism, adequacy or safeguards or a derogation, not a hard localization duty.

The European Commission's own adequacy decision for Switzerland was reconfirmed 15 January 2024, covering the post-revision regime, and Switzerland's own Federal Council lists the EU and EEA as adequate for outbound transfers, so the relationship is adequate in both directions.

What it requires

Data subject rights

FADP Articles 25-32, Data Subject Rights in Switzerland

Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 25-32Fedlex, the Swiss Federal Council's official legislation portal

In force since 1 September 2023. Binds public and private bodies.

What this law does

Articles 25 to 32 FADP give a person in Switzerland rights of access, rectification, deletion or destruction, objection to ongoing processing at any time, and a narrower portability right under Article 28 limited to data the subject provided and that is processed by automated means, in a standard electronic format, on request. Article 32 additionally lets a person go straight to a civil court to compel correction or have disputed data flagged, independent of the FDPIC complaint route.

What it requires

Enforcement supervision

FADP Articles 43, 60-65, FDPIC Supervision and Criminal Sanctions in Switzerland

Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 43, 60-65Fedlex, the Swiss Federal Council's official legislation portal

In force since 1 September 2023. Binds public and private bodies.

What this law does

The FDPIC (Federal Data Protection and Information Commissioner) is the supervisory authority: it investigates on complaint or ex officio and can order a controller to start, change, suspend, or stop processing, or to delete or destroy data, and can compel appointment of a Swiss representative. It does not hold General Data Protection Regulation (GDPR)-style direct administrative fining power.

Criminal sanctions sit in Articles 60 to 65 FADP instead: up to CHF 250,000 against the individual responsible for a willful violation, prosecuted as an offense, with a CHF 50,000 fallback fine on the company itself only when the responsible individual cannot reasonably be identified within the business.

Private civil actions run in parallel and separately, through Article 32 FADP's direct civil-court route and the general Swiss Code of Obligations and Civil Code personality-rights provisions; a claimant must plead and prove quantifiable loss, there is no Biometric Information Privacy Act (BIPA)-style statutory per-violation damages figure.

What it requires

Sensitive categories

FADP Article 5 lit. c, Sensitive Personal Data Including Biometric Data

Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 5 lit. c, Art. 6 para. 7, Art. 22Fedlex, the Swiss Federal Council's official legislation portal

In force since 1 September 2023. Binds public and private bodies.

What this law does

Article 5 lit. c FADP defines sensitive personal data as a closed list: data on religious, philosophical, political or trade union views and activities; health data; data on the intimate sphere or racial or ethnic origin; genetic data; biometric data that uniquely identifies a natural person; and data on administrative or criminal proceedings and sanctions. Genetic and biometric data are the two categories the 2023 revision added.

A controller relying on consent for sensitive personal data needs express consent under Article 6 para. 7, and large-scale processing of sensitive personal data or systematic large-scale public-space monitoring triggers a mandatory Data Protection Impact Assessment under Article 22.

There is no dedicated Swiss biometric statute and no statutory biometric-specific retention or destruction schedule; retention is governed by the FADP's general proportionality and storage-limitation principle, Article 6 para. 3-4: keep only as long as the purpose requires, then delete or anonymize.

The controlling recent authority is a live FDPIC enforcement action rather than a statute amendment: on 16 May 2025 the FDPIC concluded its investigation into PostFinance's voice-recognition system and found the processing violated the proportionality principle because voiceprints were being created on an opt-out basis rather than opt-in.

The FDPIC ordered PostFinance to obtain explicit, affirmative consent before creating a voiceprint and to delete every voiceprint created without it, with a compliance deadline of 1 October 2025. PostFinance has appealed to the Federal Administrative Court, and the outcome of that appeal is not established; the FDPIC's order is treated as its currently stated position, not as final.

What it requires

Scraping law3 instruments, 3 in force

Research summary (237 words)

Switzerland has no scraping-specific statute, so general law governs each dimension separately. The Swiss Criminal Code's unauthorised access and data interference provisions (Art. 143, 143bis, 144bis) turn on defeating a security measure, so reading a public, unauthenticated page does not fit their plain terms.

No Swiss court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper; the Code of Obligations sets the general contract-formation framework but contains no scraping-specific rule.

The Copyright Act (URG/LDA) permits reproduction for scientific research where the copying uses a technical process and the source is lawfully accessible (Art. 24d), a narrower ground than a general text-and-data-mining exception, and it confers no sui generis database right; its related-rights title reaches only performers, phonogram and audio-visual producers, and broadcasting organisations.

Personal data scraped from a public Swiss source stays subject to the Federal Act on Data Protection regardless of public availability, which does not carve out publicly accessible personal data (see the privacy topic's document for that Act's own findings, not restated here).

The Federal Act against Unfair Competition (UWG/LCD) prohibits, as unfair, taking over and exploiting another's market-ready work product through technical reproduction without a reasonable own effort (Art. 5 lit. c), a general misappropriation-style doctrine that is not scraping-specific but is capable of reaching systematic copying of another's compiled output. No Swiss statute or reported case assigns a robots.txt directive legal weight or imposes an AI-training-specific rule.

Computer misuse

Swiss Criminal Code, Unauthorised Access to and Interference with Data Processing Systems

Swiss Criminal Code (StGB/CP/CP), SR 311.0, Art. 143, 143bis, 144bisSwiss Criminal Code, official English translation, Fedlex

In force since 1 January 2012. Binds public and private bodies.

What this law does

Article 143bis penalises, on complaint, any person who obtains unauthorised access by means of data transmission equipment to a data processing system that has been specially secured to prevent access, by a custodial sentence not exceeding three years or a monetary penalty; its current wording dates from the Federal Decree of 18 March 2011 implementing the Council of Europe Convention on Cybercrime, in force since 1 January 2012.

Article 143 punishes, with a custodial sentence not exceeding five years or a monetary penalty, obtaining specially secured data not intended for the offender for the offender's own or another's unlawful gain, a narrower, gain-motivated offence whose current terminology dates from 1 January 2007.

Article 144bis punishes, on complaint, altering, deleting or rendering unusable data stored or transmitted electronically without authority, escalating to a custodial sentence not exceeding five years and prosecution ex officio where major damage results; its current wording dates from the sentencing-policy harmonisation act in force since 1 July 2023.

What it requires

Unfair competition

Unfair Competition Act, Exploitation of Another Person's Market-Ready Work Product

Federal Act against Unfair Competition (UWG/LCD), SR 241, Art. 2, 5 lit. c, 23Federal Act against Unfair Competition, Fedlex

In force since 1 March 1988. Binds private bodies.

What this law does

Article 2's general clause treats as unfair and unlawful any deceptive conduct, or conduct otherwise contrary to good faith, that affects the relationship between competitors or between suppliers and customers.

Article 5 lit. c specifically treats as unfair taking over and exploiting, as such, another's market-ready work product through a technical reproduction process without a reasonable own effort, a misappropriation-style doctrine capable of reaching the wholesale technical copying of a competitor's compiled output, including scraped data, though no reported Swiss case applies it specifically to web scraping.

Intentional unfair competition under Articles 3 to 6 is a criminal offence on complaint, carrying a custodial sentence not exceeding three years or a monetary penalty (Art. 23 para. 1), in its current form since 1 July 2016.

What it requires

Age gating law1 instrument, 1 enacted but not yet in force

Research summary (124 words)

Switzerland's age-classification and age-verification statute for film and video game content is the Federal Act on the Protection of Minors in Film and Video Games (JSFVG), SR 446.2, passed 30 September 2022.

Only part of the Act has been brought into force: the definitions, scope, and the mechanism for declaring an industry branch's own age-classification code binding on non-member actors entered into force on 1 January 2025, but the direct provisions setting the age-labelling, content-descriptor and age-verification requirements themselves (Art. 6-8) are among those the Federal Council has not yet brought into force, and no commencement date for them has been set.

Switzerland has no adult-content-specific age-verification statute distinct from the JSFVG, no dedicated social-media minor-access restriction, and no app-store or device-level age-verification requirement.

Age-appropriate design code

Federal Act on the Protection of Minors in Film and Video Games, Age Classification and Verification Regime

Federal Act on the Protection of Minors in Film and Video Games (JSFVG), SR 446.2, Art. 1-19Federal Act on the Protection of Minors in Film and Video Games, Fedlex

Commencement not set. Binds private bodies.

What this law does

The JSFVG applies to film and video game industry actors and to providers of platform services, in each case within their economic activity, and covers the requirements for age labelling, content descriptors and age verification (Art. 4 lit. a), measures applying to platform services on which users upload and retrieve films or video games (Art. 4 lit. b), and the process for declaring an industry branch's own age-classification code binding on actors who are not members of the branch organisation that wrote it (Art. 4 lit. c, 9-19).

A binding code must set at least five age tiers, with the highest reserved for adults, and must cover age-labelling and age-verification rules. The Federal Assembly passed the Act on 30 September 2022.

Only Articles 1-5, 9-13, 15-19, 29, 32, 37-39 and 41, covering the definitions, scope, and the branch-code binding-declaration mechanism, entered into force on 1 January 2025; the Federal Council has not brought the remaining provisions into force, including Articles 6-8, which set out the age-labelling, content-descriptor and age-verification requirements directly, and no commencement date for them has been announced.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.