Why can a careless press release lead to personal liability in a crisis? Why do board members risk fines of up to CHF 250,000 for incorrect crisis communication? How do successful Swiss companies navigate between DSG requirements, ad hoc publicity, and compliance requirements?
In the Swiss business world, where reputation and trust are traditionally highly valued, a crisis can destroy decades of credibility within hours. But while communications managers are under enormous time pressure, there are legal pitfalls that can quickly turn a corporate crisis into a personal liability issue for board members and senior management.
The revised Data Protection Act (DSG), which has been in force since September 2023, has fundamentally changed the rules of the game. According to the current activity report of the Federal Data Protection and Information Commissioner (FDPIC), the authority recorded a 53 percent increase in conciliation requests – a clear sign of increased sensitivity to data protection issues. At the same time, listed companies must comply with the strict ad hoc disclosure requirements of the SIX Swiss Exchange, while the personal liability of the executive bodies under Art. 754 of the Swiss Code of Obligations hangs like a sword of Damocles over every decision.
A data breach or cyberattack – and suddenly the clock is ticking. The revised DSG requires Swiss companies to report data security breaches to the FDPIC "as soon as possible" if there is a high risk to the privacy of the individuals concerned. Unlike the European GDPR with its 72-hour deadline, Swiss law allows more room for interpretation, but this apparent advantage can become a trap.
The crux lies in the details: While the GDPR stipulates a reporting obligation even in the event of a potential risk, the DSG only applies in the event of a "high risk." However, this higher threshold does not mean that companies can sit back and relax. On the contrary, the assessment of whether a high risk exists must be documented and justified internally. A misjudgment can not only lead to fines, but also result in civil liability claims.
In February 2025, the EDÖB published detailed guidelines on reporting data breaches , which assist companies in making this critical decision. Particularly controversial: informing the individuals affected must also be carefully considered. Premature communication can cause panic and damage reputation, while delayed information can have legal consequences.
This poses a particular challenge for Swiss SMEs, which often operate without a specialized legal department. Our consulting experience shows that crucial mistakes are often made in the first few hours of a data breach. A structured crisis communication plan that takes GDPR requirements into account is therefore not a luxury, but a necessity.
Additional rules apply to companies listed on the SIX Swiss Exchange. The ad hoc disclosure requirement stipulates the immediate publication of price-sensitive information – and a crisis is almost always price-sensitive.
The revised SIX Exchange Regulation guideline, which has been in force since July 2021, has further tightened the requirements. Ad hoc announcements must be explicitly identified as such ("Ad hoc announcement pursuant to Art. 53 KR"), and there are no longer any "per se" price-sensitive facts. Each individual case must be assessed on its own merits.
Paradoxically, this apparent flexibility increases the pressure on those responsible. The decision as to whether information is subject to ad hoc disclosure must be made under enormous time pressure—ideally outside trading hours, i.e., before 7:30 a.m. or after 5:40 p.m. If a notification falls within the trading-critical period, the SER must be informed at least 90 minutes in advance.
Violating ad hoc disclosure requirements can be costly. The SIX Sanctions Commission regularly imposes fines in the six-figure range. But that is often just the tip of the iceberg: shareholders can claim damages for losses incurred due to delayed information.
What many board members and executives underestimate is that in a crisis, they are personally and jointly liable for breaches of duty. Art. 754 of the Swiss Code of Obligations makes no exceptions for stressful situations.
The conditions for liability are quickly met: a breach of duty, damage, causality, and fault—whereby even slight negligence is sufficient. There are numerous pitfalls in crisis communication: a hasty statement that later turns out to be false can be considered a breach of duty of care. The same applies to the concealment of essential information.
The situation becomes particularly delicate when data protection violations are involved. According to current case law , GDPR fines imposed on a Swiss company can lead to personal liability claims against board members if they have violated their supervisory duties. With fines of up to 4% of global annual turnover, this is not a theoretical risk.
Although the business judgment rule offers a certain degree of protection, its requirements are strict: the decision must have been made on the basis of adequate information, be in the company's best interests, and be free of conflicts of interest. In the hectic atmosphere of a crisis, these requirements are often difficult to meet.
A well-designed compliance system can make all the difference in a crisis. It's not just about complying with legal requirements, but about structured processes that work even under pressure.
Clear responsibilities and escalation levels are key components of a crisis-proof compliance system. Who decides on the publication of an ad hoc announcement? Who communicates with the EDÖB? These questions must be clarified in advance, not only when a crisis arises.
Documentation is essential. Every decision and every communication must be recorded in a comprehensible manner. This not only serves as justification later on, but also creates clarity during the crisis and prevents contradictory statements.
The integration of "privacy by design" and "privacy by default," as required by the revised GDPR, pays off in times of crisis. Companies that have integrated data protection into their processes from the outset can respond more quickly and securely when it matters.
The Swiss legal landscape, with its mix of federal peculiarities and international obligations, requires a tailored approach. SMEs in Zurich, Basel, or Geneva face similar challenges, but local conditions and industry specifics must be taken into account.
A financial services provider in Zurich is subject to different regulatory requirements than a technology start-up in Lausanne. FINMA has its own guidelines for crisis communication by banks and insurance companies, while pharmaceutical companies in Basel must also comply with international standards.
Experience shows that Swiss companies that invest in legally compliant crisis communication during calm times are much better equipped to cope with turbulent phases. A crisis management team that is familiar with the legal framework and trains regularly can make the difference between an incident that is overcome and a scandal that threatens the company's existence.
Successful crisis communication begins long before the actual crisis. A legally compliant crisis plan should contain at least the following elements:
A decision tree for assessing reporting obligations under the DSG is essential. Define clear criteria for assessing "high risk" and document them. Contact with the EDÖB should be prepared in advance, including the technical requirements for the secure transmission of sensitive information.
For listed companies, the ad hoc disclosure process must be watertight. Appoint deputies for all key positions and ensure that swift action can be taken even outside office hours. All parties involved should be familiar with the Connexor Reporting Platform from SIX.
The interface between communications and legal must be clearly defined. In practice, a mixed crisis management team model with representatives from both areas has proven effective. Regular simulations help to identify weaknesses and optimize cooperation.
Particularly important: Create template documents for various crisis scenarios. A data breach requires different wording than a product recall or a compliance violation. These templates should be reviewed regularly for current legal changes.
For Swiss SMEs in particular, bringing in specialist consultants can be crucial in a crisis. External experts not only contribute their expertise, but also the necessary emotional distance to make rational decisions.
When selecting crisis consultants, Swiss specifics should be taken into account. Knowledge of the DSG and the Swiss media landscape is just as important as experience with the requirements of SIX. A consultant who only has GDPR expertise may quickly reach their limits in Swiss practice.
Cooperation with external consultants must also be legally secure. Confidentiality agreements and clear mandates are essential. Particularly in cross-border crises, data protection aspects must be taken into account when passing on information.
The Swiss corporate landscape has experienced several sensational crises in recent years, which offer valuable lessons for the future. Without naming individual companies, clear patterns can be identified.
Companies that communicated transparently and proactively were often able to restore their reputation more quickly. It became clear that the initial communication did not have to be perfect, but it did have to be timely and meet the essential legal requirements.
Delaying tactics and attempts at concealment, on the other hand, almost always lead to tougher sanctions and lasting damage to reputation. The Swiss public and authorities reward honesty and accountability – provided they are in compliance with the law.
Digitalization and the use of artificial intelligence create new challenges for crisis communication. In 2025, the EDÖB clarified that the current data protection law is directly applicable to AI-supported data processing . This means that AI-related incidents may also be reportable.
Algorithm-based decisions that turn out to be flawed or discriminatory can quickly escalate into a crisis. The legal requirements for communicating such incidents are complex and require both technical and legal understanding.
At the same time, technology also offers opportunities. Automated monitoring systems can provide earlier warning of potential crises. AI-supported analysis tools help to assess the scope of an incident more quickly. But here too, the final decision and responsibility lies with humans—and thus with the board of directors and senior management.
Swiss companies that set up their crisis communication in a legally compliant manner gain a real competitive advantage. In a market that thrives on trust and reputation, professional crisis management can mean the difference between a temporary setback and lasting damage.
Investing in legally compliant crisis communication pays off in many ways: it minimizes liability risks, protects your reputation, and strengthens the trust of customers, partners, and investors. This is invaluable, especially in Switzerland, where personal relationships and long-term business partnerships are important.
Would you like to put your crisis communication on a legally secure footing and confidently master DSG requirements, ad hoc publicity, and compliance requirements? Brand Affairs supports you in developing a tailor-made crisis communication plan that takes the Swiss legal landscape into account. With over 15 years of experience in the Swiss market and our network of communications and legal experts, we ensure that you communicate in a legally compliant manner, even in turbulent times.
Contact us for a no-obligation consultation. Together, we will develop a crisis communication strategy that suits your company and protects you from legal pitfalls – in Zurich, Basel, Bern, Geneva, and throughout Switzerland.
You are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information