Cybersecurity 2026

SWITZERLAND Law and Practice Contributed by: David Vasella, Jürg Schneider, Hugh Reeves and Yannick Caballero Cuevas, Walder Wyss Ltd

Further, sector-specific regulations address particular data protection issues. For example, the Swiss gov - ernment has also created a general frame of reference for the use of AI within the federal administration, and FINMA issued binding guidelines on outsourcing and data security for the financial and insurance sector, as well as Guidance 08/2024 on governance and risk management relating to the use of AI by banks and financial institutions, in which it sets out its supervi - sory expectations. The following FADP safeguards can be applied to AI systems. • Privacy by design/privacy by default – the data controller is obliged to implement technical and organisational measures to ensure that processing complies with data protection requirements right from the outset. • Obligation to carry out an impact assessment – where the planned processing is likely to pose a high risk to data subjects or their fundamental rights, the data controller must first carry out a data protection impact analysis. A high risk exists in particular in the case of large-scale processing of sensitive data or systematic surveillance of large parts of the public domain. • Transparency obligation for automated decisions – the data controller must inform the data subject of any decision taken exclusively on the basis of automated personal data processing that has legal effects on the data subject or significantly affects him or her. The data subject also has the right to express his or her point of view and to demand that the decision be reviewed by a natural person. These measures do not apply where the data sub - ject has expressly consented to the decision being taken by automated means, or where the decision is directly related to the conclusion or performance of a contract and the data subject’s request is met. If the automated decision is made by a federal body, such body must qualify it as such. The right of the data subject to express his or her point of view and to demand that the decision be reviewed by a natural person does not apply when the data subject does not have to be heard before the decision is made. When exercising his or her right of access, the data subject receives, in particular,

information concerning the existence of an auto - mated decision and the logic on which the decision is based. • Requirement for a formal legal basis – federal bod - ies are only entitled to process personal data if a legal basis is given. The legal basis must be laid down in a law in the formal sense in three cases, namely: (a) the processing of sensitive data (for example biometric and genetic data); (b) profiling (as defined by the FADP); and (c) when the purpose or method of processing is likely to cause serious harm to the fundamental rights of the data subject. The use of AI may therefore require a formal legal basis, even in the absence of sensitive data or profil - ing, if the processing method (eg, automated decision) is likely to seriously affect the fundamental rights of the data subject. Finally, on 12 February 2025, DETEC and the Fed - eral Department of Foreign Affairs (FDFA) presented an overview to the Swiss Federal Council of possi - ble regulatory approaches to AI. On the basis of this overview, the Swiss Federal Council has decided on a Swiss regulatory approach for AI based on three objectives: strengthening Switzerland’s location for innovation; safeguarding the protection of fundamen - tal rights, including economic freedom; and increas - ing public trust in AI. To achieve these objectives, the Swiss Federal Council has set the following key steps for the future: incorporation of the Council of Europe’s AI Convention (which Switzerland signed on 27 March 2025) into Swiss law; sector-specific legislation as far as required (cross-sector regulation, to be limited to central areas relevant to fundamental rights); and non- binding measures. 6.3 Cybersecurity in the Healthcare Sector Concerning cybersecurity in the healthcare sector, see 6.1 Cybersecurity and Data Protection .

384 CHAMBERS.COM

Powered by