Alessandro AleddaInsider Threat and Risk

ITER/CHSwitzerland

What the record establishes for Switzerland: the bodies an insider event is reported to, the channel each takes, and what binds there instead of the Union instruments.

Recipients
2 of 4
Reporting address
None recorded
NIS2
Equivalents read
Terms moved
Sources cited
2
Last read
5 SEPTEMBER 2026

Recipients

Reached underBodyChannelSource
Data protection authorityGDPR, article 33Federal Data Protection and Information Commissioner bindingch fadp
CSIRT or competent authorityNIS2, article 23Bundesamt für Cybersicherheit, the BACS binding

Electronically, under article 74f, through the means the Office provides. The Office's own page on the duty answered 404 when read, so no address is recorded

ch isg
Financial supervisorDORA, article 19No recipient recorded.
Market authorityMAR, article 17No recipient recorded.

Instead of the Union instruments

The Union instruments do not bind in Switzerland. What binds instead is read here, one row per instrument.

Instead ofActTermOwed toIn forceSource
GDPRFederal Act on Data Protection, article 24 bindingAs quickly as possible · from the breach of data security, where it is likely to lead to a high risk to the data subject's personality or fundamental rightsThe FDPIC, and the data subject where required for their protection or where the FDPIC so requests1 September 2023ch fadp
NIS2Informationssicherheitsgesetz, articles 74b to 74f binding24 hours · from the discovery of the cyberattackThe BACS1 April 2025ch isg
DORANone read. The Regulation does not bind in SwitzerlandDoes not apply
MARNone read. The Regulation does not bind in SwitzerlandDoes not apply

An event in Switzerland

The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.