How to Make a Data Access Request Under Swiss Law (Art. 25 nDSG)

Anyone in Switzerland, and in some cases anyone outside it, can ask an organization what personal data it holds about them and how that data is used. This is the Auskunftsrecht, the right of access set out in Art. 25 of the nDSG, the revised Federal Act on Data Protection. It works even against a company or authority that has never told the person anything about its data holdings, and it does not require a lawyer or a court to invoke.
This page explains what a controller, the Verantwortliche who decides why and how data is processed, actually has to hand over, how long it has to answer, what it may charge, and the narrow grounds on which it may refuse. It also gives worked examples and a short template you can adapt to send your own request.
It is part of our wider Swiss data privacy coverage, itself part of the broader guide to Swiss law.
Information last verified on 21 July 2026. This page provides general legal information about Swiss law and does not constitute legal advice in an individual case.
What Article 25 actually entitles you to receive
Under Art. 25 Abs. 1 nDSG, anyone can ask a controller whether it is processing personal data about them at all. If it is, Art. 25 Abs. 2 nDSG requires the controller to hand over what the person needs to actually exercise their rights, and it fixes a minimum that must be included in every case.
That minimum covers the identity and contact details of the controller, the personal data being processed as such, the purpose of the processing, and how long the data will be kept or the criteria used to decide that. It also covers what is known about where the data came from when it was not collected from the person directly, whether an automated individual decision was involved and the logic behind it where that applies, and the recipients or categories of recipients the data has been or will be disclosed to.
Health data gets one extra safeguard. Art. 25 Abs. 3 nDSG allows it to be communicated through a health professional the requester names, rather than directly, if the person prefers that route. Two further points matter for how the right actually works in practice.
Art. 25 Abs. 4 nDSG makes clear that using an outside processor, an Auftragsbearbeiter, does not let a controller pass the request along and wash its hands of it. The controller stays the one who must answer. Art. 25 Abs. 5 nDSG adds that nobody can waive this right in advance, so a clause buried in a contract or a set of terms of service cannot sign it away.
The realistic timeline: 30 days is the norm, not a hard wall
Art. 25 Abs. 7 nDSG states that the answer is given in der Regel, as a rule, within 30 days. That wording matters. It is a norm the system is built around, not an absolute statutory ceiling with no lawful way past it.
Art. 18 DSV fills in the mechanics. Abs. 1 sets the 30 day period running from the day the request arrives. Abs. 2 gives the controller a lawful way out if it genuinely cannot finish in time, requiring it to tell the requester that it cannot meet the 30 days and to give a new date by which the answer will come.
Abs. 3 adds that a refusal, a limitation or a deferral has to be communicated within that same original period, not left until later.
A short example shows how this runs in practice. Sara emails a company on 3 March asking for everything it holds about her under Art. 25 nDSG. Under Art. 18 Abs. 1 DSV, the response is due by 2 April. If the company's records sit across an old system it is still migrating and it genuinely cannot finish the review by then, it has to write to Sara before 2 April and name a new date, for example 30 April, rather than simply letting the 30 days pass in silence.
This is a real difference from the GDPR's structure of a fixed one month period extendable by up to two further months. The nDSG ties the extension to an actual notice obligation rather than a capped number of extra months, but the notice is not optional. A controller that misses 30 days and says nothing has not lawfully extended anything.
What it may cost you: free by default, capped if not
Art. 25 Abs. 6 nDSG states plainly that the controller must give the information free of charge. That is the rule, and most requests cost the requester nothing at all.
Art. 19 DSV carves out one narrow exception. Where answering would involve disproportionate effort, the controller can ask the person to contribute to the cost, and Abs. 2 caps that contribution at CHF 300 regardless of how large the effort actually was. Abs. 3 adds two protections. The controller must tell the person the amount before it provides the access, and if the person does not confirm the request within 10 days of that notice, the request is treated as withdrawn without any cost to them at all.
The timing detail worth remembering is where that 10 day window sits. It comes before the 30 day clock even starts. The Art. 18 Abs. 1 DSV period only begins once the 10 day confirmation window has closed, so a fee scenario can lawfully take longer overall than a straightforward one, without the controller having done anything wrong.
Marco's request illustrates it. He asks a call centre operator for five years of recorded interactions and associated notes. The company decides the manual review needed is disproportionate effort, and it tells Marco it will charge CHF 250 before doing the work.
Marco has 10 days to confirm he still wants to proceed. If he does, the 30 day period for the actual answer only starts running once that confirmation window has closed, not from the date of his original request.
When a controller can lawfully say no
Art. 26 Abs. 1 nDSG lets a controller refuse, limit or defer the answer where a formal statute requires it, in particular to protect a professional secrecy duty, where overriding interests of a third party make it necessary, or where the request is manifestly unfounded, including one pursuing a purpose contrary to data protection law, or manifestly querulous.
Art. 26 Abs. 2 nDSG adds two further grounds depending on who the controller is. A private controller can also refuse where its own overriding interests apply and the data will not be passed to third parties. A federal body can refuse where an overriding public interest exists, in particular internal or external state security, or where the request would endanger an investigation, an inquiry or a proceeding.
Art. 26 Abs. 3 nDSG closes an obvious loophole for corporate groups. Companies belonging to the same group are not treated as third parties for the private controller ground above, so a group cannot claim it withheld data to protect a sibling company's separate interests.
Whatever ground a controller relies on, Art. 26 Abs. 4 nDSG requires it to actually say why it refused, limited or delayed the answer. A blank refusal with no stated reason is not a lawful use of Art. 26, it is simply a request the controller has not properly answered.
Writing the request
The nDSG does not prescribe an official form, and a controller cannot lawfully demand you use one of its own before it will act. A few practical choices make the difference between a request that gets answered properly and one that drags.
Identify yourself clearly, with your name and the contact details the answer should go to, and enough information for the controller to actually find your records without guessing. State plainly that you are exercising your right of access under Art. 25 nDSG, so the request is not read as an ordinary customer service email. Say what you want confirmed, whether that is everything the controller holds about you or a specific system, department or time period, since a scoped request is often answered faster than an open ended one.
Send it through a channel that leaves a paper trail, such as email or a registered letter, and keep a copy with the date. Nothing in the law requires German, French or Italian, but writing in whichever official language the controller normally operates in can help the request reach the right desk sooner.
A short template you can adapt follows below. Replace the bracketed sections with your own details before sending it.
To the Data Protection or Legal Department of [company name]. I am exercising my right of access under Art. 25 nDSG and ask you to confirm whether you process personal data about me. If you do, please provide the categories of data you hold, the purpose of the processing, the retention period or the criteria used to set it, the source of the data where it was not collected from me directly, and the recipients or categories of recipients it has been disclosed to. My name is [your name], my address is [your address], and I can be reached at [your email or phone number]. I understand a response is normally due within 30 days under Art. 18 of the Datenschutzverordnung, and I ask to be told directly if more time is needed.
A worked example: requesting your file from a former employer
A common real case is a former employee who wants their personnel file after a dismissal or a dispute. Sent properly, the request should reach the personnel file itself, any appraisal or performance notes, records of disciplinary steps, and the outcome of any automated scoring the employer used, along with the purpose behind keeping each category.
An employer can still invoke Art. 26 in a genuine case. Notes tied to an active internal investigation into someone else, or material genuinely covered by a third party's overriding interest such as a colleague's own personal data mixed into the same file, can lawfully be withheld or redacted. What the employer cannot lawfully do is refuse the whole file with no explanation, or simply let the 30 days pass without a word.
What to do when the answer is inadequate or never comes
Two routes exist once a controller has answered badly, answered late with no notice, or not answered at all, and it helps to know honestly what each one can and cannot do.
The first is a complaint to the EDÖB. Art. 49 nDSG lets the authority open an investigation on a complaint where there are sufficient indications of a possible violation, and Art. 50 nDSG gives it power to demand documents and access if the controller does not cooperate voluntarily. Where it finds a violation, Art. 51 nDSG lets it order the controller to comply, for example by actually giving the access Art. 25 requires, or it may limit itself to a formal warning if the problem was already fixed during the investigation. What it cannot do is award you damages or impose a fine on the company itself.
If a controller intentionally gave false or incomplete information in response to your request, or intentionally failed to answer at all, that can amount to an offence under Art. 60 nDSG, punishable by a fine of up to CHF 250000. Art. 60 Abs. 1 nDSG punishes this only auf Antrag, so it is an Antragsdelikt: in the ordinary case the affected person has to lodge a criminal complaint, and reporting the matter to the EDÖB does not by itself set a prosecution in motion.
That liability falls on the individual responsible within the organization, not the company as an abstraction, and it is prosecuted by the cantonal authorities under Art. 65 nDSG. The EDÖB can file a complaint and take part as a private party, but it cannot impose the fine itself. The offence requires intent, so ordinary carelessness does not meet this bar. Our nDSG overview sets out the criminal provisions in full.
The second route is an ordinary civil claim. A person can ask a civil court to order a controller to comply with Art. 25, using the general procedure available for any civil claim in Switzerland. This route can compel compliance where the EDÖB's corrective powers are not enough, but it is slower and costs more than a complaint, and it will not by itself produce compensation for an unrelated dispute, only an order tied to the access request itself.
Reach beyond Switzerland's borders
Art. 3 nDSG applies the law wherever a situation has its effect in Switzerland, even if it was set in motion abroad. The test is where the effect lands, not where the company keeps its servers or its head office.
In practice, a foreign business serving customers located in Switzerland, an online retailer or a subscription service based outside the country, for instance, can be within scope of Art. 25 even though it has no Swiss office at all, if its processing affects people here. Distance from Switzerland is not by itself a defence to an access request.
Switzerland is not the EU, and this is not a GDPR request
Switzerland is not a member of the European Union, and the GDPR is not Swiss law. The right described on this page comes from the nDSG, a Swiss statute, and it is answered under Swiss deadlines and Swiss fee rules, not the GDPR's one month and two month structure.
The two systems do connect at one point. The European Commission reaffirmed, on 15 January 2024, that Switzerland's data protection framework is adequate under the GDPR, a decision that lets personal data flow from the EU to Switzerland without extra safeguards. That is a recognition running from the EU toward Switzerland, not Switzerland adopting or being bound by the GDPR itself, and it does not change what an Art. 25 nDSG request is or how it is answered.
What this right can and cannot do for you
An access request tells you what a controller holds about you, where it says that data came from, and why it says it is processing it. That is genuinely useful information, and it can support a later step, whether that is correcting a record, understanding a decision, or building a case.
It is not, by itself, a fast route to winning a dispute with an employer, an insurer or a bank. It does not produce an admission of fault, a settlement or a payout, and a controller answering it correctly is not conceding anything about the underlying disagreement. If you are in the middle of such a dispute, it is worth sending the request calmly and factually, and treating whatever comes back as one piece of information among others rather than a resolution in itself.
Frequently Asked Questions
What is the Swiss right to access personal data?
It is the Auskunftsrecht under Art. 25 nDSG. Anyone can ask a controller whether it processes personal data about them, and if so, the controller must provide the data itself, its purpose, retention period, source and recipients.
How long does a company have to respond to a Swiss data access request?
Art. 25 Abs. 7 nDSG and Art. 18 DSV set 30 days from receipt as the operational norm. If the controller cannot meet it, it must tell the requester a new date before the 30 days run out, rather than simply going quiet.
Can a company charge for a Swiss data access request?
Normally no. Art. 25 Abs. 6 nDSG makes access free by default. A fee is only allowed under Art. 19 DSV where the effort is disproportionate, and it is capped at CHF 300, with the amount disclosed to the requester in advance.
Can a company refuse my Swiss data access request?
Only on the grounds listed in Art. 26 nDSG, including a formal statutory secrecy duty, overriding interests of a third party, or a request that is manifestly unfounded or querulous. The controller must state which ground it is relying on.
What happens if a company ignores my Swiss access request?
You can file a complaint with the EDÖB, which can investigate and order the controller to comply, or bring an ordinary civil claim. Neither route is fast, and the EDÖB itself cannot award damages or impose a fine.
Can the Swiss data protection authority fine a company that ignores my request?
No. The EDÖB's own powers under Art. 49 to 51 nDSG are investigative and corrective only. A criminal fine for intentionally giving false or incomplete information runs through Art. 60 nDSG against the individual responsible, prosecuted by a cantonal authority, not the EDÖB.
Does a foreign company have to answer a Swiss access request?
Yes, if the processing affects a person in Switzerland. Art. 3 nDSG applies based on where the effect falls, not on where the company is domiciled or where its servers sit.
Will a data access request resolve my dispute with my employer or bank?
Usually not by itself. It tells you what data is held and why, which can support a later claim, but it is not a fast route to a settlement, a payout or an admission, and it should not be used mainly as pressure.
Sources and References
- Art. 25 nDSG, Auskunftsrecht(fedlex.admin.ch).gov
- Art. 26 nDSG, Einschränkungen des Auskunftsrechts(fedlex.admin.ch).gov
- Art. 18 DSV, Frist(fedlex.admin.ch).gov
- Art. 19 DSV, Ausnahme von der Kostenlosigkeit(fedlex.admin.ch).gov
- Art. 3 nDSG, Räumlicher Geltungsbereich(fedlex.admin.ch).gov
- Art. 49 nDSG, Untersuchung(fedlex.admin.ch).gov
- Art. 50 nDSG, Befugnisse(fedlex.admin.ch).gov
- Art. 51 nDSG, Verwaltungsmassnahmen(fedlex.admin.ch).gov
- Art. 60 nDSG, Verletzung von Informations-, Auskunfts- und Mitwirkungspflichten(fedlex.admin.ch).gov
- Art. 65 nDSG, Zuständigkeit(fedlex.admin.ch).gov
- EDÖB, EU Adequacy Decision Regarding Switzerland(edoeb.admin.ch).gov