ITER/CHSwitzerland
What the record establishes for Switzerland: the bodies an insider event is reported to, the channel each takes, and what binds there instead of the Union instruments.
Recipients
| Reached under | Body | Channel | Source |
|---|---|---|---|
| Data protection authorityGDPR, article 33 | Federal Data Protection and Information Commissioner binding | — | ch fadp |
| CSIRT or competent authorityNIS2, article 23 | Bundesamt für Cybersicherheit, the BACS binding | Electronically, under article 74f, through the means the Office provides. The Office's own page on the duty answered 404 when read, so no address is recorded | ch isg |
| Financial supervisorDORA, article 19 | No recipient recorded. | ||
| Market authorityMAR, article 17 | No recipient recorded. | ||
Instead of the Union instruments
The Union instruments do not bind in Switzerland. What binds instead is read here, one row per instrument.
| Instead of | Act | Term | Owed to | In force | Source |
|---|---|---|---|---|---|
| GDPR | Federal Act on Data Protection, article 24 binding | As quickly as possible · from the breach of data security, where it is likely to lead to a high risk to the data subject's personality or fundamental rights | The FDPIC, and the data subject where required for their protection or where the FDPIC so requests | 1 September 2023 | ch fadp |
| NIS2 | Informationssicherheitsgesetz, articles 74b to 74f binding | 24 hours · from the discovery of the cyberattack | The BACS | 1 April 2025 | ch isg |
| DORA | None read. The Regulation does not bind in Switzerland | — | — | Does not apply | — |
| MAR | None read. The Regulation does not bind in Switzerland | — | — | Does not apply | — |
An event in Switzerland
The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.
