Cybersecurity 2026

SWITZERLAND Law and Practice Contributed by: David Vasella, Jürg Schneider, Hugh Reeves and Yannick Caballero Cuevas, Walder Wyss Ltd

Walder Wyss Ltd Seefeldstrasse 123

8008 Zurich Switzerland

Tel: +41 586 585 858 Fax: +41 586 585 959 Email: reception@walderwyss.com Web: www.walderwyss.com

1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy Switzerland is a federation comprising 26 federated states (cantons) as well as a federal government. This leads to a layered body of laws as well as, at times, a decentralised official cybersecurity approach. Cyber - security in Switzerland remains closely tied to the area of data protection. Cybersecurity is frequently perceived as an off-shoot – or even a synonym – of data security, which, as the name suggests, targets the security and resilience of data processing and storage activities. A further manifestation of the government’s interest in cybersecurity is another governmental venture, the Digital Switzerland Strategy. The Digital Switzer - land Strategy sets guidelines for Switzerland’s digital transformation, and is updated annually by the Swiss Federal Council, each time with three focus topics. It is binding on the federal administration and provides guidance for other stakeholders involved in digitalisa - tion. The first Digital Switzerland Strategy was pub - lished in 2016, and updates arrived in 2018, 2020, 2023, 2024 and 2025. On 12 December 2025, the Swiss Federal Council adopted the updated Digital Switzerland Strategy for 2026. In 2023, the Swiss Federal Council approved the new Digital Administration Switzerland Strategy 2024–27, which defines the fields of action to be prioritised in order for the Confederation, the cantons, and cities and municipalities to jointly determine how the digi -

tal transformation of administrations is to be driven forward. A second strategy approved by the Swiss Federal Council is the Digital Federal Administration Strategy, which creates a framework for digital trans - formation projects in the federal administration. 1.2 Cybersecurity Laws On a federal level, the Swiss Constitution of 18 April 1999 protects the right to privacy, in particular the right to be protected against misuse of personal data (Article 13). The collection and use of personal data by private bodies are regulated at the federal level and are mainly governed by the Federal Data Protec - tion Act (FADP) and its ordinances, including the Data Protection Ordinance (DPO). Data processing by public bodies is governed by the FADP for federal bodies, which includes private organ - isations performing public tasks such as health insur - ance providers, pension funds and many others, and by cantonal (for example, the Information and Data Protection Act of the Canton of Zurich) and communal laws for cantonal and communal bodies. The FADP was revised in order to implement the revised Council of Europe’s Convention 108, and to more closely align with the EU General Data Protec - tion Regulation (GDPR). The revised FADP and DPO entered into force on 1 September 2023. While the FADP and the GDPR are similar in their approach and purpose, there are notable differenc - es. For example, there is a data breach notification obligation under the FADP, similar to that under the

376 CHAMBERS.COM

Powered by