EDÖB: The Swiss Data Protection Commissioner

The EDÖB (Eidgenössischer Datenschutzbeauftragter) is Switzerland's federal data protection commissioner, independent and appointed by Parliament. They investigate complaints from employees about how you handle personal data—especially during recruitment and employment—and issue binding decisions. You don't need to ask permission before processing data, but you must notify EDÖB immediately if a data breach exposes employee or candidate information.

Also available inDeutschFrançaisItaliano

The EDÖB exists because Swiss data protection law (revDSG—the revised Federal Data Protection Act) gives every worker the right to know how their data is used. As an employer, you collect sensitive information: home addresses, salary history, health declarations, social insurance numbers. The EDÖB ensures you do this lawfully and securely.

You will encounter the EDÖB when an employee or candidate complains that you've misused their data, or when you suffer a data breach. The office is small but has real authority. Ignoring a breach notification requirement or an EDÖB order can result in fines up to CHF 250,000.

When the EDÖB Becomes Your Concern

The EDÖB gets involved only after someone complains or you report a breach. There is no permit or approval you need before hiring. However, the revDSG requires you to report data breaches to EDÖB without unnecessary delay—usually within 72 hours—if the breach risks serious harm to rights or freedom of a natural person.

Employees and candidates can file complaints directly if they believe you've illegally stored their data, shared it without consent, or failed to let them access it. EDÖB then investigates and can order you to stop, correct records, or delete information.

  • Data breaches: report to EDÖB within 72 hours if risk of serious harm exists
  • Complaints: employees can appeal to EDÖB if they suspect illegal data handling
  • Right of access: candidates and workers can demand copies of their personal data you hold
  • No pre-approval needed: you don't ask EDÖB permission before collecting or processing data
  • Binding decisions: EDÖB rulings are enforceable; you cannot ignore them
  • Applies to all employers: no size exemption, even single-person companies are covered

Your Obligations Under Swiss Data Protection Law

Under revDSG, you must collect only data that is necessary for recruitment or employment. If you ask for health history before a conditional job offer, or retain CVs for longer than needed, you violate the law. You must also ensure data is stored securely—unencrypted files on shared drives or printed forms left in unlocked cabinets invite trouble.

You must tell candidates and employees what data you collect and why. A privacy notice in your job ad or employment contract—in plain language—satisfies this. If you use a recruitment software like zenRecruiting.ai, verify that the vendor has signed a data-processing agreement (Auftragsbearbeitervertrag) with you.

  • Purpose limitation: collect data only for legitimate hiring or employment purposes
  • Minimize data: do not ask for more than you need
  • Storage security: encrypt digital files, lock cabinets, control access
  • Transparency: inform candidates and employees how you use their data
  • Data-processing agreements: ensure your software vendors comply with revDSG
  • Retention limits: delete CVs and application data after hiring is complete or a reasonable period

The Most Common Mistake

Employers routinely keep candidate CVs and applications 'just in case' for years. Under revDSG, this is illegal storage without a lawful purpose. If a candidate later complains that you're holding their data unlawfully, EDÖB will side with them. You then face an order to delete and potential fines.

A second common error: failing to report a breach because you assume it 'wasn't serious.' EDÖB decides severity, not you. If an employee's salary data was exposed, report it. If you store passwords in plain text and they leak, report it. Silence makes the violation worse. Consult a lawyer if you're unsure whether your situation meets the 72-hour threshold.

  • Holding CVs indefinitely without a stated purpose violates revDSG
  • Failing to report breaches is both illegal and aggravates the original violation
  • Assuming 'it's not that bad' costs you more than swift disclosure
  • Never assume you alone judge breach severity—EDÖB does
  • Hiring software must have explicit data-processing clauses in your contract
  • Document your retention policy and stick to it, or EDÖB will find you non-compliant

Frequently asked questions

Do I need EDÖB approval before I start recruiting?
No. You do not seek permission from EDÖB before processing personal data. The revDSG is principles-based: you must follow lawful practices on your own. EDÖB investigates only after a complaint or breach report.
How long can I keep a candidate's CV after they are rejected?
Under revDSG, no longer than necessary for the recruitment purpose. Best practice: delete after 6–12 months unless the candidate has agreed you may keep it for future roles. Document your policy and apply it consistently.
What happens if I don't report a data breach to EDÖB?
You face fines up to CHF 250,000 and enforcement action. EDÖB can also issue public notices, damaging your reputation. If the breach harmed affected individuals, they may sue you separately for damages.

General information for Swiss employers, not legal advice. Have a lawyer confirm anything with legal consequences.

Related