When the revised Data Protection Act entered into force on 1 September 2023 without any transition period, concern was great and preparation very uneven. Three years on, an honest review is possible: the basic duties have arrived in most companies. Privacy notices were revised, records of processing activities created, responsibilities assigned.
The quality of implementation, however, often lags behind formal compliance. The typical pattern from our advisory practice: the processing record was created once in 2023 and never touched again. New tools, new processes and new providers are recorded nowhere. The overview the law demands is missing exactly where it matters.
Second perennial issue: processing by third parties. Anyone having personal data processed by service providers needs the contractual guarantees of Art. 9 FADP. In practice these contracts are missing surprisingly often, or they date from a time when the provider delivered entirely different services. It becomes critical with cloud and AI services processing data outside Switzerland: without a clean basis for cross-border disclosure under Art. 16 et seq. FADP, the whole chain stands on shaky ground.
Third: reporting data security breaches. The law requires notification to the FDPIC as quickly as possible where a breach is likely to lead to a high risk. We see both extremes: breaches that are never escalated internally, and reports that arrive weeks late because nobody knew who decides. A tested reporting process with clear responsibilities is not a luxury but basic equipment.
The practice topic of 2026 is the connection between data protection and artificial intelligence. Anyone feeding personal data into AI tools is processing it within the meaning of the FADP, with all consequences: transparency, purpose limitation, processor contracts, cross-border disclosure, possibly a data protection impact assessment. For companies with EU exposure, the EU AI Act duties applicable since August 2026 come on top. The good news: whoever puts the FADP foundation in order has already done half the AI work.
Our recommendation for autumn 2026: a compact data health check. Update the record, review provider contracts, run the incident process once. Three days of effort that can save weeks when it counts.


