-
- Art. 3 FC
- Art. 5a FC
- Art. 6 FC
- Art. 10 FC
- Art. 13 FC
- Art. 16 FC
- Art. 17 FC
- Art. 20 FC
- Art. 22 FC
- Art. 26 FC
- Art. 29a FC
- Art. 30 FC
- Art. 31 FC
- Art. 32 FC
- Art. 42 FC
- Art. 43 FC
- Art. 43a FC
- Art. 45 FC
- Art. 51 FC
- Art. 52 FC
- Art. 55 FC
- Art. 56 FC
- Art. 60 FC
- Art. 68 FC
- Art. 69 FC
- Art. 74 FC
- Art. 75b FC
- Art. 77 FC
- Art. 81 FC
- Art. 96 para. 1 FC
- Art. 96 para. 2 lit. a FC
- Art. 110 FC
- Art. 117a FC
- Art. 118 FC
- Art. 119a FC
- Art. 122 FC
- Art. 123a FC
- Art. 123b FC
- Art. 130 FC
- Art. 136 FC
- Art. 164 FC
- Art. 166 FC
- Art. 170 FC
- Art. 176 FC
- Art. 178 FC
- Art. 189 FC
- Art. 191 FC
-
- Art. 11 CO
- Art. 12 CO
- Art. 50 CO
- Art. 51 CO
- Art. 84 CO
- Art. 97 CO
- Art. 98 CO
- Art. 99 CO
- Art. 100 CO
- Art. 143 CO
- Art. 144 CO
- Art. 145 CO
- Art. 146 CO
- Art. 147 CO
- Art. 148 CO
- Art. 149 CO
- Art. 150 CO
- Art. 633 CO
- Art. 701 CO
- Art. 713 CO
- Art. 715 CO
- Art. 715a CO
- Art. 734f CO
- Art. 785 CO
- Art. 786 CO
- Art. 787 CO
- Art. 788 CO
- Art. 808c CO
- Transitional provisions to the revision of the Stock Corporation Act of June 19, 2020
-
- Art. 2 PRA
- Art. 3 PRA
- Art. 4 PRA
- Art. 6 PRA
- Art. 10 PRA
- Art. 10a PRA
- Art. 11 PRA
- Art. 12 PRA
- Art. 13 PRA
- Art. 14 PRA
- Art. 15 PRA
- Art. 16 PRA
- Art. 17 PRA
- Art. 19 PRA
- Art. 20 PRA
- Art. 21 PRA
- Art. 22 PRA
- Art. 23 PRA
- Art. 24 PRA
- Art. 25 PRA
- Art. 26 PRA
- Art. 27 PRA
- Art. 29 PRA
- Art. 30 PRA
- Art. 31 PRA
- Art. 32 PRA
- Art. 32a PRA
- Art. 33 PRA
- Art. 34 PRA
- Art. 35 PRA
- Art. 36 PRA
- Art. 37 PRA
- Art. 38 PRA
- Art. 39 PRA
- Art. 40 PRA
- Art. 41 PRA
- Art. 42 PRA
- Art. 43 PRA
- Art. 44 PRA
- Art. 45 PRA
- Art. 46 PRA
- Art. 47 PRA
- Art. 48 PRA
- Art. 49 PRA
- Art. 50 PRA
- Art. 51 PRA
- Art. 52 PRA
- Art. 53 PRA
- Art. 54 PRA
- Art. 55 PRA
- Art. 56 PRA
- Art. 57 PRA
- Art. 58 PRA
- Art. 59a PRA
- Art. 59b PRA
- Art. 59c PRA
- Art. 60 PRA
- Art. 60a PRA
- Art. 62 PRA
- Art. 63 PRA
- Art. 64 PRA
- Art. 67 PRA
- Art. 67a PRA
- Art. 67b PRA
- Art. 73 PRA
- Art. 73a PRA
- Art. 75 PRA
- Art. 75a PRA
- Art. 76 PRA
- Art. 76a PRA
- Art. 90 PRA
-
- Art. 1 IMAC
- Art. 1a IMAC
- Art. 3 para. 1 and 2 IMAC
- Art. 8 IMAC
- Art. 8a IMAC
- Art. 11b IMAC
- Art. 16 IMAC
- Art. 17 IMAC
- Art. 17a IMAC
- Art. 32 IMAC
- Art. 35 IMAC
- Art. 47 IMAC
- Art. 48 IMAC
- Art. 54 IMAC
- Art. 56 IMAC
- Art. 55a IMAC
- Art. 63 IMAC
- Art. 67 IMAC
- Art. 67a IMAC
- Art. 74 IMAC
- Art. 74a IMAC
- Art. 80 IMAC
- Art. 80a IMAC
- Art. 80b IMAC
- Art. 80c IMAC
- Art. 80d IMAC
- Art. 80h IMAC
- Art. 80k IMAC
-
- Vorb. zu Art. 1 FADP
- Art. 1 FADP
- Art. 2 FADP
- Art. 3 FADP
- Art. 4 FADP
- Art. 5 lit. c FADP
- Art. 5 lit. d FADP
- Art. 5 lit. f und g FADP
- Art. 6 para. 3-5 FADP
- Art. 6 Abs. 6 and 7 FADP
- Art. 7 FADP
- Art. 10 FADP
- Art. 11 FADP
- Art. 12 FADP
- Art. 14 FADP
- Art. 15 FADP
- Art. 18 FADP
- Art. 19 FADP
- Art. 20 FADP
- Art. 21 FADP
- Art. 22 FADP
- Art. 23 FADP
- Art. 25 FADP
- Art. 26 FADP
- Art. 27 FADP
- Art. 28 FADP
- Art. 29 FADP
- Art. 31 para. 2 lit. e FADP
- Art. 33 FADP
- Art. 34 FADP
- Art. 35 FADP
- Art. 38 FADP
- Art. 39 FADP
- Art. 40 FADP
- Art. 41 FADP
- Art. 42 FADP
- Art. 43 FADP
- Art. 44 FADP
- Art. 44a FADP
- Art. 45 FADP
- Art. 46 FADP
- Art. 47 FADP
- Art. 47a FADP
- Art. 48 FADP
- Art. 49 FADP
- Art. 50 FADP
- Art. 51 FADP
- Art. 52 FADP
- Art. 54 FADP
- Art. 55 FADP
- Art. 57 FADP
- Art. 58 FADP
- Art. 60 FADP
- Art. 61 FADP
- Art. 62 FADP
- Art. 63 FADP
- Art. 64 FADP
- Art. 65 FADP
- Art. 66 FADP
- Art. 67 FADP
- Art. 69 FADP
- Art. 72 FADP
- Art. 72a FADP
-
- Art. 1 CCC (Convention on Cybercrime)
- Art. 2 CCC (Convention on Cybercrime)
- Art. 3 CCC (Convention on Cybercrime)
- Art. 4 CCC (Convention on Cybercrime)
- Art. 5 CCC (Convention on Cybercrime)
- Art. 6 CCC (Convention on Cybercrime)
- Art. 7 CCC (Convention on Cybercrime)
- Art. 8 CCC (Convention on Cybercrime)
- Art. 9 CCC (Convention on Cybercrime)
- Art. 11 CCC (Convention on Cybercrime)
- Art. 12 CCC (Convention on Cybercrime)
- Art. 16 CCC (Convention on Cybercrime)
- Art. 18 CCC (Convention on Cybercrime)
- Art. 25 CCC (Convention on Cybercrime)
- Art. 27 CCC (Convention on Cybercrime)
- Art. 28 CCC (Convention on Cybercrime)
- Art. 29 CCC (Convention on Cybercrime)
- Art. 32 CCC (Convention on Cybercrime)
- Art. 33 CCC (Convention on Cybercrime)
- Art. 34 CCC (Convention on Cybercrime)
-
- Art. 2 para. 1 AMLA
- Art. 2a para. 1-2 and 4-5 AMLA
- Art. 2 para. 2 AMLA
- Art. 2 para. 3 AMLA
- Art. 3 AMLA
- Art. 7 AMLA
- Art. 7a AMLA
- Art. 8 AMLA
- Art. 8a AMLA
- Art. 9 AMLA
- Art. 11 AMLA
- Art. 14 AMLA
- Art. 15 AMLA
- Art. 20 AMLA
- Art. 23 AMLA
- Art. 24 AMLA
- Art. 24a AMLA
- Art. 25 AMLA
- Art. 26 AMLA
- Art. 26a AMLA
- Art. 27 AMLA
- Art. 28 AMLA
- Art. 29 AMLA
- Art. 29a AMLA
- Art. 29b AMLA
- Art. 30 AMLA
- Art. 31 AMLA
- Art. 31a AMLA
- Art. 32 AMLA
- Art. 33 AMLA
- Art. 34 AMLA
- Art. 38 AMLA
FEDERAL CONSTITUTION
FEDERAL ACT ON DIRECT FEDERAL TAX
MEDICAL DEVICES ORDINANCE
CODE OF OBLIGATIONS
FEDERAL LAW ON PRIVATE INTERNATIONAL LAW
LUGANO CONVENTION
CODE OF CRIMINAL PROCEDURE
CIVIL PROCEDURE CODE
FEDERAL ACT ON POLITICAL RIGHTS
CIVIL CODE
FEDERAL ACT ON CARTELS AND OTHER RESTRAINTS OF COMPETITION
FEDERAL ACT ON INTERNATIONAL MUTUAL ASSISTANCE IN CRIMINAL MATTERS
DEBT ENFORCEMENT AND BANKRUPTCY ACT
FEDERAL ACT ON DATA PROTECTION
CRIMINAL CODE
CYBERCRIME CONVENTION
COMMERCIAL REGISTER ORDINANCE
FEDERAL ACT ON COMBATING MONEY LAUNDERING AND TERRORIST FINANCING
FREEDOM OF INFORMATION ACT
FEDERAL ACT ON THE INTERNATIONAL TRANSFER OF CULTURAL PROPERTY
FEDERAL ACT ON MEDICINAL PRODUCTS AND MEDICAL DEVICES
TAX HARMONISATION ACT
- In a nutshell
- I. General
- II. Duty to Provide Information in the Case of Automated Individual Decision-Making (para. 1)
- III. Rights of the Data Subject (para. 2)
- IV. Exceptions (para. 3)
- V. Automated Individual Decision-Making by a Federal Body (para. 4)
- VI. Enforcement
- VII. Comparative Legal Notes
- VIII. Outlook
- Bibliography
- Materials
In a nutshell
Article 21 of the FADP establishes an obligation to provide information in cases of fully automated individual decisions that significantly affect a data subject or result in legal consequences for them. Furthermore, the provision grants the data subject various rights of protection: the right to present their point of view and the right to have the decision reviewed by a human. In addition, the provision requires federal agencies to explicitly label fully automated individual decisions as such. A significant shortcoming of the provision is that it does not include semi-automated decisions within its scope of application.
I. General
A. Overview and Structure
1 With the revision of the Data Protection Act in September 2023, the term “automated individual decision” was introduced into Swiss law. Art. 21 of the FADP governs the obligations of the controller within the meaning of Art. 5(j) FADP and the rights of the data subject in the case of an automated individual decision. Para. 1 defines the automated individual decision and establishes an obligation to provide information regarding it. Para. 2 sets forth the rights of the data subject, which include the right to be heard and the right to have the decision reviewed by a natural person. Para. 3 provides for exceptions to para. 1 and para. 2. Para. 4 establishes a special provision for federal bodies.
2 The FADP is implemented by the Data Protection Ordinance (DSV). To date, the Ordinance has not contained any further provisions regarding automated individual decision-making.
B. Purpose of the Provision
3 According to the Federal Council’s explanatory memorandum, Art. 21 of the FADP is intended to comply with existing provisions under international law. In terms of substance, the Federal Council justifies the new provision by noting that automated individual decisions are steadily increasing as a result of technological developments. However, there is no detailed examination of the risks associated with automated individual decision-making or the resulting need for regulation.
4 The explanatory memorandum does, however, cite examples of how erroneous decisions can be made based on incorrect or incomplete data sets. This suggests that one reason for introducing the new Art. 21 of the FADP was also the fear of precisely such decisions. The protection of human dignity can therefore be seen as a potential regulatory objective, the aim of which is, among other things, to protect people from being reduced to mere objects of machine-driven decisions. Another possible regulatory objective can be seen in protection against discrimination by the state: If an automated individual decision is based on machine learning algorithms, it does not follow rules created by humans but rather learns from large amounts of data (so-called “training data”), which may reflect societal disadvantages, patterns, or outdated role models (so-called data bias). In this way, an automated individual decision can reproduce disadvantages and have a discriminatory effect. The new provision grants affected individuals the opportunity to exert influence if they are the subject of an automated individual decision (“right to a human hearing”). According to the explanatory memorandum, this is intended to counteract erroneous decisions and their consequences. Furthermore, the legislature thereby implicitly regards human decisions as superior, since, in its view, erroneous automated decisions can be prevented through human intervention. This basic assumption also underlies the provision on automated individual decisions under the DSGVO (see N. 69 ff.), which the Explanatory Memorandum cites as further justification for Art. 21 of the FADP.
C. Historical Background
5 Although the legal discourse surrounding automated individual decisions only gained momentum with the explicit introduction of Art. 21 of the FADP, as will be shown below, the concept dates back several decades. Art. 21 of the FADP is therefore the result of a gradual development built upon earlier reform efforts and international standards.
6 1981: The materials accompanying the Directive on the Processing of Personal Data in the Federal Administration of March 16, 1981, highlighted the risks that could arise from the creation of personality profiles and the automated decision-making based on them. However, Swiss law did not at that time provide for explicit regulation of automated individual decision-making.
7 2003: As part of the partial revision of the FADP in 2003, the Federal Council sought to introduce an explicit duty to inform in cases of automated individual decision-making. Parliament, however, rejected this proposal.
8 2017–2020: The version of Art. 21 of the FADP proposed by the Federal Council in its 2017 message on the total revision was essentially adopted by Parliament. While the consultation process was still controversial, this provision was largely uncontested during the parliamentary proceedings. As the concordance table below shows, the changes made were limited to editorial clarifications:

Table 1: Concordance table on the development of Art. 21 FADP (own presentation)
9 2018: A renewed impetus to legally address automated individual decisions arose in the course of implementing Directive (EU) 2016/680—which is binding on Switzerland—on the protection of natural persons with regard to the processing of personal data in the context of judicial and police cooperation. To this end, a provision on automated individual decisions was created within the framework of the Schengen Data Protection Act (SDSG; in force until August 31, 2023) (Art. 11 FADP). This provision required federal agencies in the covered areas to inform data subjects about automated individual decisions and granted them corresponding rights to participate in the process. With the entry into force of the revised Data Protection Act, the FADP was repealed (Art. 68 in conjunction with Annex 1 FADP). Art. 21 FADP succeeded Art. 11 SDSG in substance.
10 2019–2023: Furthermore, the introduction of Art. 21 FADP serves to implement Switzerland’s obligations under international law. The modernized Data Protection Convention of the Council of Europe (Convention 108+, ER-Conv-108+), which Switzerland signed on November 21, 2019, and ratified on September 7, 2023, expressly obligates the contracting states to ensure a right to information and a right to be heard in the case of automated individual decision-making (Art. 8(1)(e) and Art. 9(1)(a) of the Council of Europe Convention 108+). Furthermore, by introducing Art. 21 of the FADP, the legislature sought to establish a level of data protection that continues to be considered “adequate” in relation to the European Union within the meaning of Art. 45 of the DSGVO.
II. Duty to Provide Information in the Case of Automated Individual Decision-Making (para. 1)
11 Automated individual decision-making is legally defined in Art. 21(1) of the FADP. In order to contextualize the term (B.), a few preliminary remarks on automation and its technical development must first be made (A.). The key legal requirements will then be clarified (C.).
A. Technical Background
1. Levels of Automation
12 The term “automation” refers to the transfer of tasks from humans to machines. An automated individual decision may involve different levels of automation. Broadly speaking, a distinction can be made between partial and full automation.
13 The term “partial automation” has several meanings. On the one hand, it may involve decision support. In this case, the automated system prepares the decision (identifying, compiling, or evaluating information; creating overviews). However, the actual decision is made by a responsible natural person.
For example, partially automated systems can be used to make medical diagnoses by analyzing X-rays, CT scans, or MRI scans.
Semi-automated systems can be used to draft contract terms.
Semi-automation can also be useful for extracting relevant data from large volumes of text. For example, a decision-support system in tax administration can provide the authorities with additional data not directly derived from the taxpayer’s tax return, or highlight relevant clauses in lengthy contracts.
In criminal proceedings, particularly in the United States, semi-automated systems are used to calculate the likelihood of recidivism among offenders.
14 On the other hand, the semi-automated system can function as a decision review by being used to verify a decision made by a natural person.
15 Full automation, on the other hand, means that a system carries out every single step of the decision-making process on its own. Strictly interpreted, even the programming and the initiation of the decision-making process must be carried out by the system.
For example, in the private sector, decisions on loan applications can be made fully automated by automatically assessing the applicant’s ability and willingness to pay. Contracts are then concluded automatically.
Furthermore, the automation of the recruitment process is conceivable. One example is the fully automated pre-selection of applications from potential employees. In this process, the system decides whether to invite an applicant to an interview with a human recruiter.
Fully automated systems can assign prospective students to a program of study and, thereby, to a college or university.
16 In the public sector, full automation is particularly well-suited for mass administration processes due to standardized procedures and the availability of large amounts of data. These are the areas of public administration in which a large number of decisions are made regarding virtually identical sets of facts.
For example, due to the availability of large amounts of data, the tax assessment process lends itself to be carried out either partially or fully automated.
In the social insurance sector, the decision regarding eligibility for premium reductions is well-suited for full automation.
In building permit procedures as well, the introduction of fully automated individual decisions is being considered as a possibility.
17 The potential of automated systems is considered particularly high in the near future for partially automated systems in public administration. This is intended to ensure that existing tasks are carried out more efficiently, more accurately, and thus with greater legal certainty.
2. Development
18 The origins of automated individual decision-making can be traced back to so-called expert systems. These are based on structured “if-then” schemas (so-called rule-based systems) and, in this sense, do not go beyond the cognitive decision-making processes of natural persons.
19 In particular, the emergence of Big Data Analytics—the ability to analyze very large, unstructured datasets—and the associated technical developments have enabled machine learning methods (often referred to somewhat broadly as “Artificial Intelligence” [AI]) to become established. This has, in a sense, brought about a shift in perspective: Instead of causal relationships—for example, when using artificial neural networks—correlations or probabilities come into play. The datasets are no longer processed using “if-then” schemes; rather, the systems establish their own rules to arrive at a result. In doing so, it often remains unclear how the systems arrive at such a result. The literature does not always clearly distinguish between “simple” automation or a “simple” automated system and situations where machine learning methods are used.
B. Automated Individual Decision
1. Full Automation
20 An automated individual decision within the meaning of Art. 21 FADP exists when a decision is based exclusively on automated processing and has legal consequences for the data subject or significantly affects them (para. 21 FADP) . It is required that a decision be made regarding a specific individual (individual decision) based on the processing of personal data. From a public law perspective, an automated individual decision may also be referred to as an “automated administrative decision.”
21 The decisive factor is that the processing takes place “without any human intervention.” It therefore involves an assessment of the facts and decision-making separate from any natural person, and thus constitutes full automation within the meaning of the distinction made in this commentary (see N. 15). However, according to the Explanatory Memorandum, full automation is not precluded by the fact that the decision is communicated to the data subject by a natural person, provided the decision can no longer be modified. Various authors, however, take the view that an automated individual decision still exists even if a natural person is involved in the programming process. If this view is followed, an automated individual decision within the meaning of Art. 21 para. 1 of the FADP need not be made entirely independently of human intervention.
2. Legal Consequence or Significant Adverse Effect
22 An automated individual decision further requires that it be associated with a legal consequence or that it have a significant adverse effect on the data subject. According to the Federal Council’s explanatory memorandum, the decision is associated with a legal consequence if it entails direct, legally prescribed consequences for the data subject. The decision always has a legal consequence when it affects the legal status of the data subject—that is, when it establishes, modifies, or revokes a right for the data subject. Unlike in the case of adverse effects (see N. 24), the legal consequence does not need to be particularly significant. As an example, the Federal Council cites the conclusion and termination of contracts, each of which entails a legal consequence for the data subject as a contracting party. Specifically, the automated conclusion of an insurance contract is mentioned. In this context, insurance coverage and the obligation to pay premiums are likely to be considered legal consequences. According to the explanatory memorandum, however, premium invoices sent periodically and automatically based on the insurance contract do not constitute an automated individual decision, particularly since the issuance of invoices is already a legal consequence resulting from the conclusion of the contract. Nor does the following constitute a legal consequence in the sense described above: if no contract is concluded with a person. In this example, however, the failure to conclude the contract may nonetheless be understood as an automated individual decision and trigger a duty to provide information if the data subject is significantly adversely affected as a result (see N. 24).
23 In the context of public law, a legal consequence essentially arises when administrative decisions are issued pursuant to Art. 5 APA, as well as in the case of real acts pursuant to Art. 25a APA. The Explanatory Memorandum cites automated tax assessments as an example.
24 An automated individual decision further gives rise to a duty to inform if the data subject is significantly adversely affected by it. This is presumed to be the case if the decision has a negative impact on the data subject’s economic or personal interests. The situation must reach a certain level of severity; mere annoyance is not sufficient. Factors such as the importance of the affected interest to the data subject, the duration of the decision’s impact, or the possibility of resorting to alternatives. Whether the data subject is significantly affected must therefore be determined by assessing the overall circumstances on a case-by-case basis. As a possible example, the explanatory memorandum cites the allocation of medical services or the failure to conclude a contract based on an automated individual decision.
25 The following are further examples of automated individual decisions that result in a legal consequence or significant adverse effect for the data subject:
the conclusion or non-conclusion of a lease agreement, including its terms (e.g., interest rate, payment terms), provided that these elements depend on an automated assessment of the data subject’s financial situation (legal consequence or significant adverse effect in the event of non-conclusion);
a health insurance company’s refusal to enter into a contract with the data subject based on the automated evaluation of their health data (significant disadvantage);
the automated issuance of traffic citations based on photographic evidence of the respective vehicle owner (legal consequence);
the automated rejection of an online loan application or an online job application without human intervention (significant adverse effect);
the determination of contractual terms, e.g., for personalized pricing (legal consequence);
26 The following, however, do not constitute automated individual decisions:
the delivery of personalized advertising, as there is no legal consequence or the required degree of adverse effect.
3. Additional Requirements
27 According to the Federal Council’s explanatory memorandum, the assessment should not be based solely on the criterion of “natural person,” but must also take into account the complexity of the system and the particular impact on the data subject. An automated individual decision exists when the automation exhibits a certain level of complexity and results in a legal consequence that is particularly detrimental to the data subject. Simple “if-then” decisions are not to be classified as automated individual decisions.
As an example, the Federal Council cites withdrawing money from an ATM. If the account balance is high enough, the withdrawal is authorized.
28 Apart from this example, the required level of complexity for such decisions remains open in the message and is thus, for the time being, unresolved. However, if necessary, the Federal Council will specify in an ordinance when a decision is based exclusively on automated processing.
29 In the government context, some authors focus on the discretionary leeway in decision-making. Other voices, however, explicitly state that an automated individual decision may not be made if the authority is granted discretion. Building on the criterion of complexity, Braun Binder notes that the required level of complexity can be determined by a reverse inference: automated individual decisions are those that do not require any fact-finding.
4. Assessment
30 Neither the text of the law nor the explanatory memorandum specifies exactly when an automated individual decision exists. The reference to the “complexity” of the system is of little help. This could give the impression that the provision applies only to fully automated decision-making processes based on machine learning (or “AI”) , while any process based on if-then schemes would not be covered. This can hardly be true, particularly for public administration, since most of the algorithms it uses are based on if-then schemes. The data protection provision would consequently have no substantive effect. To prevent Art. 21 of the FADP from being rendered ineffective, rule-based “if-then” schemes must also be covered. The hurdle regarding the requirement of complexity is therefore unlikely to be too high in practice.
31 It is also regrettable that decisions based on partial automation—in the form of decision support or review (see N. 13 et seq.) —are not subsumed under the concept of an automated individual decision pursuant to Art. 21 para. 1 of the FADP. In many cases, the applicability of this provision will be blocked in practice. This is all the more troubling given that partial automation, just like full automation, raises issues relevant to personal rights and fundamental rights (such as those concerning discrimination; see N. 4). This is all the more true when partial automation is based on complex machine learning methods.
C. Duty to Inform
32 Art. 21 para. 1 of the FADP stipulates that the controller must inform the data subject of an automated individual decision. In light of the definition of an automated individual decision (see N. 20 et seq.), the duty to inform therefore applies only if the decision results in a legal consequence or a significant adverse effect on the data subject (see N. 22 et seq.) .
1. Timing, Content, and Form
33 Neither the Act nor the Explanatory Memorandum provides detailed information regarding the timing, form, and content of the duty to inform in the case of an automated individual decision.
34 With regard to the timing, the controller is free to choose whether to inform the data subject before (ex ante) or after (ex post) the automated individual decision has been made. Even if there were good reasons for providing information in advance—such as the possibility of opting out of an automated individual decision without having to resort to legal action— and although a corresponding statutory clarification would be warranted, this is not provided for under the wording of the provision. In this sense, the exercise of data subjects’ rights under Art. 21(2) of the FADP (statement of position and subsequent human review of the decision; see N. 49 ff.) is currently also sufficiently addressed as one of the regulatory objectives of the duty to inform through ex post notification.
35 With regard to the form, reference can be made to Art. 13 of the General Data Protection Regulation (GDPR), which requires notification to be provided in a precise, transparent, understandable, and easily accessible form. This provision generally refers to the duty to inform when collecting personal data. An analogous application to Art. 21(1) of the FADP is justified due to the identical wording (“informs”) justify an analogous application to the provision of information regarding an automated individual decision. The controller may fulfill the duty to provide information, for example, by publishing the details in an easily accessible privacy policy on its website or by including a link to it in a contract. The identification of the automated individual decision (see N. 57 ff.) is mandatory only for federal agencies and, a contrario, voluntary for private entities.
36 The duty to provide information serves the purpose of transparency and the goal of making all information available to a data subject so that they may exercise their rights under Art. 21 para. 2 of the FADP. To ensure this, the controller must provide information on the following:
Information that an automated individual decision will be made or has been made (depending on when the information is provided);
a clear specification of which decisions or categories of decisions are made automatically (whereby only those falling under Art. 21 para. 1 of the FADP are covered);
the possibility of exercising the right to present one’s point of view and to have the automated individual decision reviewed, along with details on how to exercise these rights (e.g., the controller’s contact information).
37 In our view, based on the logic of automated individual decision-making, there is no obligation to provide this information. Rather, to obtain such information, the data subject may exercise the right of access. As a result, the controller must explicitly inform the data subject of the existence of the automated individual decision and the decision-making logic (see para. 2(f) of FADP).
38 The duty to provide information under Art. 21 para. 1 FADP must always be fulfilled by the controller in addition to the general duty to provide information upon data collection under Art. 19 FADP. However, it is possible for the information to be provided in the same place or in the same document (see N. 35 regarding the requirements for form).
2. Assessment
39 The duty to provide information also implicitly requires that the decision be a fully automated individual decision. For the authors’ assessment of this circumstance, see N. 31.
III. Rights of the Data Subject (para. 2)
40 Art. 21(2) FADP grants various rights to the data subject affected by an automated individual decision. The data subject may present their point of view (A.) and have the decision reviewed by a natural person (B.). This suggests that the information provided under para. 1 must enable the data subject to exercise the rights set forth in para. 2.
A. Right to Present One’s Point of View
41 The data subject affected by an automated individual decision must have the opportunity to present their point of view. Upon request, the data subject should, on the one hand, be able to express their views on the outcome of the automated individual decision. On the other hand, they should be able to receive information about how the automated individual decision was reached. The information regarding the process by which the automated individual decision was reached is intended, in particular, to prevent data processing from being based on incomplete, inaccurate, or outdated data.
1. Individuals
42 Private individuals will have an interest in the right to present their point of view, in particular, if the automated individual decision turns out to be erroneously negative for the data subject. If, for example, the creditworthiness of the affected private individual is rejected, this can also have negative consequences for the private controller if, as a result of the decision, no contractual relationship is established between the parties.
43 The law does not specify the timing for presenting the point of view. Accordingly, this may take place either before or after the decision is made. From the perspective of the private controller, this does not pose any difficulties as long as this opportunity exists at any point in time.
44 The private controller may charge fees for granting the right to be heard. However, it may be in the controller’s interest to keep these fees low so as not to prevent the potential conclusion of a contract.
2. State
45 In the state context, the right to present one’s position under data protection law is to be understood as a consequence of the right to a fair hearing pursuant to para. 2 of Art. 29 of the FC. As a fundamental constitutional procedural guarantee, the right to a fair hearing must be granted in every state proceeding.
46 According to Federal Supreme Court case law, a person affected by a government decision must be able to comment (in writing) on the relevant elements of the facts before a decision is made that affects their legal status. However, according to the explanatory memorandum to the FADP, the presentation of one’s position may also take place after the decision has been rendered, e.g., by filing an appeal. Since the right to be heard confers the right to be heard before the deciding authority, only a non-devolutive appeal—such as an objection with appellate effect—is admissible. The goal is to obtain a decision in the form of an objection ruling from the authority that issued the initial decision.
47 The objection period is determined by the relevant procedural laws. It is generally 30 days. The legal basis must be adapted accordingly if automated individual decisions are to be introduced.
48 Presenting one’s position in administrative proceedings must not entail such high (procedural) costs that the data subject is deterred from doing so. In principle, therefore, fees may be charged for filing an application. However, in light of the principle of legality, this is permitted only if provided for by law.
B. Right to Review by a Natural Person
49 Para. 2 of Art. 21 of the FADP further provides for the data subject’s right to a human review of the automated individual decision. This may be particularly important if the data subject suspects that they have been disadvantaged by the automated individual decision.
50 The review must be conducted by a natural person with decision-making authority so that they can overturn the decision if necessary. However, they are free to make their own determinations and are not obligated to overturn the decision. The only requirement, in our view, is that the person review the decision in good faith.
51 In practice, this right to subsequent review is considered insufficient, particularly with regard to the potential for discrimination. A preventive review should be conducted to determine whether automated decision-making systems are unintentionally making discriminatory decisions.
52 Neither the law nor the explanatory memorandum to the FADP specifies a particular time limit within which the right to review by a natural person must be asserted. For private individuals, a time limit cannot be established as a general rule but will depend on the circumstances of the individual case. Federal agencies may refer to the time limits for reconsideration, as these confer a similar right. In principle, the request for reconsideration is not subject to any time limits, subject to provisions in special laws. However, in light of the principle of legality and to prevent arbitrariness, it seems reasonable that a time limit be explicitly specified, at least at the ordinance level.
IV. Exceptions (para. 3)
53 Art. 21(3) of the FADP provides for two exceptions to automated individual decisions in which neither the duty to inform nor the additional rights of the data subject apply. As Vasella and Henseler aptly note, given the clear statutory provision and the systematic position of the provision, it must be assumed that the exceptions to the duty to inform provided for in Art. 20 of the FADP regarding the collection of personal data are not transferable to the duty to inform in the case of automated individual decisions pursuant to Art. 21(1) of the FADP. This distinction is also confirmed by the wording of Art. 20(1) of the FADP. Even if an automated individual decision is based on a legal basis (see Art. 20 para. 1 lit. b FADP), the controller cannot invoke an exception to the duty to provide information under Art. 21 para. 1 FADP.
54 The first exception under Art. 21 para. 3(a) of the FADP applies if the automated individual decision is directly related to the conclusion or performance of a contract between the controller and the data subject and fully complies with the data subject’s request. In such a scenario, the legislature assumed that the data subject has no interest worthy of protection in receiving additional information or in exercising further rights.
55 As the second exception, Art. 21 para. 3(b) FADP cites the data subject’s explicit consent to the automated individual decision. The legislative materials do not contain detailed information regarding the requirements for such consent. According to the legislature’s understanding, valid consent requires, at a minimum, prior and sufficient information. Various authors in the literature, however, assume that the general requirements for consent to data processing are also appropriate in the context of automated individual decision-making.
V. Automated Individual Decision-Making by a Federal Body (para. 4)
56 Finally, para. 21(4) of the FADP contains a special provision for federal bodies within the meaning of Art. 5(i) FADP. This provision imposes on them the obligation to label automated individual decisions (A.). Furthermore, in certain cases, para. 21(2) FADP is not applicable (B.). However, due to the lack of detailed regulations, the provision does not permit federal bodies to make automated individual decisions (C.).
A. Identification Requirement
57 The purpose of the identification requirement for automated decisions is to make it clear to the data subject that the decision was not made by a natural person. In principle, the data subject has the right to appeal against such decisions. The identification allows the data subject to exercise their right to a fair hearing (Art. 29 para. 2 of the FC) in the appeal proceedings by presenting their position and having the decision reviewed by a natural person.
58 It is questionable how the labeling requirement relates to the duty to inform under Art. 21(1) of the FADP. Unlike the duty to inform regarding the collection of personal data under Art. 19(1) FADP, the latter does not lapse if the processing is provided for by law (para. 20(1)(b) FADP). Given that automated individual decisions in public administration are to be introduced in the future, particularly in mass-processing procedures (see N. 16), it is questionable how the government controller is to comply with the duty to inform (in individual cases). Labeling, on the other hand, appears more targeted in light of procedural efficiency.
59 The label must be clearly and easily recognizable on the automated decision. In our view, it makes sense to place the notice after the actual content of the decision, but before the information on legal remedies. In this way, the data subject first learns that the decision was made by automated means before being informed of their options for legal protection. This corresponds to a natural reading sequence. If the label were placed after the information on legal remedies, there would be a risk that the data subject would notice this information too late or not at all, and thus make an uninformed decision regarding legal protection.
B. Non-Applicability of Art. 21(2) FADP
60 The rights of the data subject under Art. 21(2) FADP to present their point of view and to have the automated individual decision reviewed by a natural person generally apply to automated individual decisions made by federal agencies as well. However, pursuant to Art. 21(4) of the FADP, however, these rights do not apply if the data subject is not required to be heard under Art. 30(2) of the APA or another federal law.
61 Art. 30 of the APA specifies the right to a fair hearing under Art. 29(2) of the APA. Pursuant to para. 1, the parties must generally be heard before a decision is issued. This right is restricted in para. 2. Exceptions to the right to a hearing exist, for example, when a decision is subject to appeal (Art. 30, para. 2, lit. b APA) or when the authorities fully grant the parties’ requests (Art. 30, para. 2, lit. c APA) . This is intended to avoid duplication in the decision-making process and to ensure that the substance of the right to a hearing is not undermined. In an objection proceeding, the right to a hearing can be exercised retroactively. If, however, the parties’ requests are granted in full, this interest no longer applies.
62 Ultimately, the exception under data protection law means that the FADP does not grant individuals affected by an automated individual decision by a government agency any rights beyond those already provided for by the APA: If the parties are required to be heard under para. 30(1) APA anyway, they are also entitled to the—no more extensive— – rights under Art. 21(2) FADP. If an exception under Art. 30(2) APA applies and the party does not have to be heard, that party cannot rely on the right to be heard under data protection law pursuant to Art. 21(2) FADP. The rights under Art. 21(2) FADP are, with regard to automated decisions under federal law, of a declaratory nature and may even have created legal uncertainty for the data subject.
C. Lack of a General Intention to Grant Admissibility
63 Legal scholarship raises the question of whether, by enacting Art. 21(1) of the FADP, the legislature intended to introduce a general admissibility standard for automated individual decisions in Switzerland. According to the Federal Council, state-administered automated individual decisions constitute “ordinary administrative decisions” within the meaning of Art. 5 APA that are issued without human intervention. In contrast to the European regulation, which establishes a general prohibition on automation subject to authorization under Art. 22 para. 1 DSGVO and thus provides for a general inadmissibility (see N. 69 et seq.), Swiss law appears to assume the admissibility of such decisions largely without preconditions. The blanket reference to Art. 21 of the FADP gives the impression that the FADP serves as a general rule of admissibility for the issuance of automated individual decisions in Swiss administrative proceedings. However, such an intent cannot be inferred from the explanatory memorandum to the FADP, nor is it compatible with the principle of legality (Art. 5, para. 1 of the FC). The latter requires not only a formal statutory basis (Art. 164, para. 1 of the FC) but also sufficient specificity of the provision. Although the FADP is a formal law, its specificity appears insufficient with regard to fully automated decisions. It is also problematic that the provision does not specify concrete areas of application but simply implies the existence of automated individual decisions.
64 In addition, as part of the comprehensive revision of the FADP in 2020, other laws were amended to include the term “automated individual decision.” The FADP thus serves as the starting point for these cross-references in the relevant (procedural) laws.
VI. Enforcement
65 The Act primarily provides for criminal sanctions. Private individuals are subject to fines of up to CHF 250,000 if they provide false, incomplete, or no information whatsoever via an automated individual decision (see para. 60(1)(a) FADP). A prerequisite for imposing a sanction is the timely filing of a criminal complaint as well as intentional conduct. The fine provision does not apply to federal agencies.
66 Furthermore, the FADP provides for supervisory measures. Thus, violations of the obligations under Art. 21 FADP may be reported to the FDPIC. In such cases, the FDPIC may require the controller to provide the information to the data subject and to grant the data subject the opportunity to present their point of view or to have the automated individual decision reviewed by a natural person (see para. 51(3)(c) of the FADP). This applies equally to controllers in both the private and public sectors.
67 The FADP contains no provision regarding whether and how the controller must correct an erroneous automated individual decision. Consequently, there are occasional criticisms that it does not provide sufficient and effective protection against the consequences of automated individual decisions. In the specific case where a violation of the duty to inform and the right to be heard breaches the processing principles under Art. 6 of the FADP, this may constitute unlawful data processing by a federal agency (para. 41(1) of the FADP) or an infringement of personal rights by a private controller (Art. 30 of the FADP). In the context of automated individual decisions, a violation of the principle of purpose limitation (Art. 6 para. 3 FADP) is a likely outcome. As a result, the data subject is entitled to demand the elimination of the negative consequences of the unlawful data processing (see para. 41(1)(b) of the FADP for federal agencies and para. 32(2) of the FADP for private entities).
68 In the context of law enforcement under public law, it is unclear how the aforementioned right to remedy relates to the administrative procedural remedies available in the event of a violation of the right to be heard. This legal uncertainty stems from the fact that the right to a hearing or review under para. 21 2 FADP does not confer any rights beyond the existing right to a fair hearing under Art. 30 para. 1 APA. The problem is exacerbated if official action in connection with the issuance of a decision that violates the obligations under Art. 21 FADP were to be classified as unlawful data processing (see Art. 41 para. 1 FADP) . Under the FADP, the data subject has the option in this scenario to demand the elimination of the consequences of unlawful processing (Art. 41 para. 1(b) FADP). This suggests that a decision issued in violation of the right to a fair hearing would have to be revoked as a consequence of unlawful data processing. This would call into question the finality of decisions, particularly after the expiration of appeal periods.
VII. Comparative Legal Notes
A. European Regulation (Art. 22 DSGVO)
69 The DSGVO contains a provision comparable to Art. 21 of the FADP. Under the heading “Automated individual decision-making in specific cases, including profiling,” Art. 22 para. 1 of the DSGVO grants a data subject the right not to be subject to a decision based solely on automated processing —including profiling—that produces legal effects concerning the data subject or similarly significantly affects the data subject.
70 The difference from Art. 21 of the FADP lies in particular in the regulatory approach. Legal scholars commenting on Art. 22 of the DSGVO are divided on whether the European provision generally prohibits automated individual decision-making or whether data subjects are granted a right to object. The European Court of Justice (ECJ) in The Hague assumes—without providing much justification — that there is a general prohibition on automated individual decision-making. In contrast, the wording of Art. 21 para. 1 of the FADP generally permits automated decisions.
71 Article 22 para. 2 of the DSGVO, however, permits automated individual decision-making in exceptional—and exhaustive—cases if the decision is necessary for the conclusion or performance of a contract between the data subject and the controller (subparagraph a), if it is permitted under Union or Member State law to which the controller is subject and such law provides for appropriate measures to safeguard the rights and freedoms as well as the legitimate interests of the data subject (subparagraph b), or if it is based on the data subject’s explicit consent (subparagraph c). Overall, the Swiss regulation is thus less restrictive than the DSGVO.
72 Pursuant to Art. 22 para. 3 DSGVO, in the cases specified in Art. 22 para. 2(a) and (c) DSGVO, the controller shall take appropriate measures to safeguard the rights and freedoms as well as the legitimate interests of the data subject, which includes, at a minimum, the right to have a person intervene on the part of the controller, to state one’s own point of view, and to contest the decision. Further requirements for automated individual decision-making arise from a variety of other provisions in the DSGVO, such as the obligations to provide information and the right of access. In this regard, European law goes beyond the scope of Art. 21 of the FADP.
73 Finally, Art. 22 para. 4 DSGVO, unlike the provisions of the FADP, provides for specific restrictions regarding (in Swiss terminology) personal data requiring special protection.
B. Case Studies
74 The FADP introduces the concept of automated individual decision-making into Swiss law. To date, there is no case law on this subject in Switzerland. Even though the (Swiss) FADP and the (European) DSGVO establish different principles regarding the use of automated individual decision-making—the FADP assumes the general permissibility of such decisions, while the DSGVO establishes a prohibition with exceptions (see N. 69 ff.) —and EU practice cannot therefore be adopted unconditionally—it nevertheless provides guidance for Switzerland.
1. Distinguishing Between Partially and Fully Automated Decisions
75 Art. 21 of the FADP contains provisions exclusively regarding fully automated individual decisions (see N. 20 et seq.). Initial examples from the European context show that distinguishing these from partially automated decisions can be difficult. The following section presents two selected examples on this issue that have been reviewed by the European Court of Justice (ECJ).
a. Austria: AMAS Algorithm
76 In a first example, the trial implementation of the automated “Labor Market Opportunities Assistance System” (AMAS) by the Austrian Public Employment Service (AMS) led to the systematic discrimination against women and people with disabilities. The system (automatically) sorted job applications for a specific job description based on data from application documents spanning the past twenty years. Since men had been hired more frequently than women in the past, women (as well as people with disabilities) were not even invited to interviews in the first place. The Austrian Data Protection Authority took action against this. In December 2020, the Austrian Federal Administrative Court issued a ruling regarding AMAS. The primary issue was not the prohibition of discrimination, but rather the question of the legal basis for the use of AMAS. The answer to this question ultimately depended on whether the procedure in question was a fully or partially automated process, as these are subject to different requirements.
77 The parties presented the following differing arguments:

78 The Austrian court agreed with the argument put forward by the Public Employment Service. The court held that the directive is specific regarding the procedure and stipulates that the automatically calculated value must be discussed with the job seeker during a counseling session. The court therefore classified the procedure as partially automated.
79 For Swiss case law, this may indicate that, when distinguishing between partial and full automation, the involvement of a natural person in the process need not be the sole determining factor. Rather, the overall circumstances of the individual case must be considered.
b. Germany: The Schufa Example
80 Schufa is an organization established by German credit institutions and other companies through which contracting parties can obtain information about potential borrowers. Upon request, it provides a score or rating intended to indicate how reliably the person in question fulfills their payment obligations.
81 After several individuals in Germany filed lawsuits against Schufa—alleging, among other things, that their records had not been deleted and that they had not been granted access to their data—the Wiesbaden Administrative Court referred the case to the CJEU to determine whether Schufa’s scoring constitutes a decision based on automated processing—including profiling—within the meaning of Article 22 of the DSGVO.
82 On December 7, 2023, the CJEU ruled that Schufa’s scoring system falls under Article 22 of the DSGVO regarding automated decisions. It found that the following three conditions, which must be cumulatively met under Article 22(1) of the DSGVO, were satisfied:
Decision: The CJEU considered credit scoring—as the basis for the subsequent denial of credit—to be (also) a decision, particularly since decisions can also include measures, and the term must therefore be interpreted broadly. According to the CJEU, a narrower interpretation carries the risk of circumventing Article 22 of the DSGVO, for example, by allowing the calculation of the credit score to be exempt from the requirements governing the processing of special categories of personal data (Article 22 para. 4 of the DSGVO).
Exclusively automated data processing: This requirement is met, particularly since Schufa’s data processing constitutes profiling within the meaning of Article 4 no. 4 4 of the DSGVO, and the probability score was, moreover, determined entirely by automated means.
Legal effect or significant adverse effect: Since Schufa based its decision—and thus the denial of the loan—largely on the probability score derived from the credit scoring, there is a significant adverse effect on the data subject.
83 The ruling extends the applicability of Article 22 of the DSGVO to the credit scoring performed by Schufa, which takes place prior to the actual decision to deny the loan. However, the CJEU stipulates that the automated decision to deny the loan must be based primarily on the credit scoring as a kind of preliminary decision. The consequences of this ruling are far-reaching in that automated decisions within the meaning of Article 22 para. 1 of the DSGVO are, in principle, prohibited. An exception applies only if the decision, pursuant to para. 2, alternatively:
is necessary for the conclusion or performance of a contract between the data subject and the controller (subparagraph a);
is authorized by Union or Member State law (subparagraph b);
is based on the data subject’s explicit consent (subparagraph c).
2. On Significant Adverse Effects under Article 21(2) of the FADP
84 The question of whether the automated individual decision has a significant adverse effect on the data subject can only be assessed based on the circumstances of the individual case. Three cases from the Netherlands will illustrate when an adverse effect is significant and when it is not.
a. Netherlands: SyRI System
85 In 2014, a law was passed in the Netherlands to introduce the SyRI (Systeem Risico Indicatie) anti-fraud system. SyRI was an algorithmic tool for fraud detection that was limited to neighborhoods in the Netherlands with populations affected by poverty or minorities and created risk profiles of individuals to detect various forms of fraud —such as in the areas of taxation and social benefits—to be detected. In 2020, a Dutch court ordered the immediate suspension of the program, as it violated the ECHR.
86 Although the system did not make any automated individual decisions, the case clearly illustrates when a significant interference is evident. According to the court’s reasoning, even such a risk alert has a significant impact on the private life of the person to whom the alert relates.
b. Amsterdam District Court: Uber Taxi Service
87 A lawsuit was filed against the Uber taxi service for violating Article 22 of the DSGVO after Uber automatically suspended drivers’ accounts upon suspicion of fraudulent activity. Since the drivers were able to have their accounts reactivated following a review, the District Court ruled that there was no violation of Article 22 of the DSGVO. The temporary suspension of the accounts was not associated with significant, long-term, or permanent effects, which would be required under Article 22 of the DSGVO. Furthermore, the data collected consisted of factual data such as location and traffic, which is recorded independently of the driver’s behavior.
c. Amsterdam District Court: Ola App
88 The “Ola” app had imposed fare deductions or fines on its users based on data collected by the system. The District Court affirmed the existence of significant effects under Article 22 of the DSGVO. By imposing fines, the consequences for the data subjects were direct and definitive. Furthermore, comprehensive “performance data” relating to a person’s general and continuous behavior had been collected.
3. Implications for the Swiss Legal Situation
89 Drawing the line between fully automated individual decision-making within the meaning of Art. 21 para. 1 of the FADP and semi-automated decision-making could prove difficult in practice. The degree of human discretion in individual cases may serve as a point of reference. If this discretion is significant, the decision should be considered semi-automated. Similarly, internal administrative guidelines, employee training, and the opportunity for data subjects to present their arguments may serve as indicators of a semi-automated individual decision. In both cases, Art. 21 of the FADP does not apply. If, on the other hand, a decision is made by a third party, it may still constitute an automated individual decision within the meaning of Art. 21 FADP.
90 Likewise, drawing a line between decisions that result in a significant adverse effect and those that do not may prove difficult. The following aspects may aid in classification:
The directness of the decision’s impact on the data subject;
the temporary or permanent effect of the decision;
the potential influence of the decision on the data subject’s behavior or decision-making;
the question of whether the decision restricts potential income opportunities or results in a potential financial loss for the data subject.
VIII. Outlook
91 The automation of processes and decision-making procedures is advancing rapidly in both the private and public sectors. The Federal Council also anticipates that automated decisions will become more common in the future. Under Article 21 of the FADP, data controllers are required to inform data subjects about automated individual decisions and to grant them certain rights. However, it appears problematic that these obligations apply exclusively to fully automated decisions. Partially automated decisions (decision support or review) are not covered by the scope of the provision. This is problematic because such systems are more widespread in practice and—depending on the complexity of the algorithm used—can have a significant influence on the outcome of the decision. This creates gaps in protection, particularly with regard to transparency and the protection of fundamental rights. Against this backdrop, it is necessary to extend the scope of Article 21 of the FADP to include partially automated decisions. This concern has been addressed in legal scholarship on the use of automated systems. Furthermore, the need for action was also taken into account in the legislative process.
Bibliography
Alon Barkat Saar/Busuioc Madalina, Human-AI Interactions in Public Sector Decision Making : « Automation Bias » and « Selective Adherence » to Algorithmic Advice, JPART 33 (2023), S. 153 ff.
Alpaydin Ethem, Machine Learning, Cambridge 2016.
Bieri Adrian/Powell Julian, Kommentierung zu Art. 21 DSG, in: Bieri Adrian/Powell Julian (Hrsg.), Orell Füssli Kommentar, Datenschutzgesetz, Zürich 2023.
Bieri Adrian/Powell Julian, Informationspflicht nach dem totalrevidierten Datenschutzgesetz, AJP 12 (2020), S. 1533–1542.
Braun Binder Nadja, Künstliche Intelligenz und automatisierte Entscheidungen in der öffentlichen Verwaltung, SJZ 115 (2019), S. 467–476 (zit. Künstliche Intelligenz).
Braun Binder Nadja, Als Verfügungen gelten Anordnungen der Maschinen im Einzelfall…–Dystopie oder künftiger Verwaltungsalltag?, ZSR 139 (2020), S. 253–278 (zit. Dystopie).
Braun Binder Nadja, Automatisierte Entscheidungen: Perspektive Datenschutzrecht und öffentliche Verwaltung, SZW 2020, S. 27–34 (zit. Automatisierte Entscheidungen).
Braun Binder Nadja, Staat, Mensch, Algorithmus, BJM 2023, S. 2–19 (zit. Staat).
Braun Binder Nadja, Der Untersuchungsgrundsatz als Herausforderung automatisierter Verfahren, zsis) 2020, abrufbar unter https://www.zsis.ch/artikel/der-untersuchungsgrundsatz-als-herausforderung-vollautomatisierter-verfahren, besucht am 19.3.2026 (zit. Untersuchungsgrundsatz).
Braun Binder Nadja, Algorithmic Regulation – Der Einsatz algorithmischer Verfahren im staatlichen Steuerungskontext, in: Hermann Hill/Joachim Wieland (Hrsg.), Zukunft der Parlamente: Speyer Konvent in Berlin, Berlin 2018, S. 107–120 (zit. Algorithmic Regulation).
Braun Binder et al., Künstliche Intelligenz: Handlungsbedarf im Schweizer Recht, Jusletter vom 28.6.2021 (zit. Handlungsbedarf).
Braun Binder Nadja et al., Einsatz Künstlicher Intelligenz in der Verwaltung: rechtliche und ethische Fragen, Schlussbericht vom 28. Februar 2021 zum Vorprojekt IP6.4, abrufbar unter https://www.zh.ch/content/dam/zhweb/bilder-dokumente/themen/politik-staat/kanton/digitale-verwaltung-und-e-government/projekte_digitale_transformation/ki_einsatz_in_der_verwaltung_2021.pdf, besucht am 19.3.2026 (zit. Studie 2021).
Braun Binder Nadja/Obrecht Liliane, Algorithmisch überprüfte Steuererklärung im ordentlichen gemischten Veranlagungsverfahren, zsis 2023, abrufbar unter https://www.zsis.ch/artikel/algorithmisch-ueberpruefte-steuererklaerung-im-ordentlichen-verfahren, besucht am 19.3.2026.
Braun Binder Nadja/Thouvenin Florent/Volz Stephanie/Obrecht Liliane, Schutz vor algorithmischer Diskriminierung, Rechtsgutachten, November 2025, abrufbar unter https://www.ekr.admin.ch/pdf/D_Gutachten_Schutz_vor_algorithmischer_Diskriminierung.pdf, besucht am 19.3.2026.
Braun Binder Nadja/Ulbrich Christian, Die grosse Verwirrung – KI und Automatisierung in Staat und Wirtschaft, NZZ 27.4.2023, abrufbar unter https://www.nzz.ch/meinung/die-grosse-verwirrung-ki-und-automatisierung-in-staat-und-wirtschaft-ld.1729694, besucht am 19.3.2026.
Büyüksagis Erdem, Décisions algorithmiques: mieux vaut responsabiliser qu’informer, REAS 2020, S. 225–242 (zit. Décisions algorithmiques).
Büyüksagis Erdem, Responsabilité pour les systèmes d’intelligence artificielle, REAS 2021, S. 12–24 (zit. Responsabilité).
Bull Hans Peter, Verwaltung durch Maschinen, Köln/Berlin 1964.
Christen Markus et al., Wenn Algorithmen für uns entscheiden: Chancen und Risiken der künstlichen Intelligenz, TA-SWISS Studie, April 2020.
Daedelow Romy, Wenn Algorithmen (unfair) über Menschen entscheiden…, Jusletter 26.11.2018.
Dentand Claire, Wer soll entscheiden: Maschine oder Mensch?, Jusletter IT 30.9.2021.
Epiney Astrid, Kommentierung zu Art. 5 BV, in: Waldmann Bernhard/Belser Eva Maria/Epiney Astrid (Hrsg.), Basler Kommentar, Bundesverfassung, 2. Aufl., Basel 2025.
Ernst Christian, Algorithmische Entscheidungsfindung und personenbezogene Daten, JuristenZeitung 21 (2017), S. 1026–1036.
Ernst Hartmut/Schmidt Jochen/Beneken Gerd, Grundkurs Informatik, 8. Aufl., Wiesbaden 2023.
Flueckiger Christian, Kommentierung zu Art. 21 DSG, in: Meier Philippe/Métille Sylvain (Hrsg.), Loi sur la protection des données, Commentaire Romand, Basel 2023.
Glaser Andreas, Einflüsse der Digitalisierung auf das schweizerische Verwaltungsrecht, SJZ 114 (2018), S. 181–190.
Glatthaar Matthias, Robot Recruiting, SZW 2020, S. 43–52.
Gordon Clara-Ann/Lutz Tanja, Haftung für automatisierte Entscheidungen – Herausforderungen in der Praxis, SZW 2020, S. 53–61.
Häfelin Ulrich/Müller Georg/Uhlmann Felix, Allgemeines Verwaltungsrecht, 8. Aufl., Zürich 2020.
Henseler Simon, EuGH C-634/21 – Anträge GA: Kreditscore (der SCHUFA) als automatisierte Entscheidung, https://datenrecht.ch/eugh-c-634-21-antraege-ga-kreditscore-der-schufa-als-automatisierte-entscheidung/, besucht am 12.5.2023 (zit. EuGH).
Henseler Simon, Datenschutz beim Kreditscoring von Auskunfteien: Eine Untersuchung zum Profiling (mit hohem Risiko) und zur automatisierten Entscheidung, Zürich 2025, abrufbar unter https://eizpublishing.ch/wp-content/uploads/2025/09/Datenschutz-beim-Kreditscoring-von-Auskunfteien-Digital-V1_02-20250814.pdf, besucht am 19.3.2026 (zit. Kreditscoring ).
Kiener Regina/Rütsche Bernhard/Kuhn Matthias, Öffentliches Verfahrensrecht, 3. Aufl., Zürich 2021.
Konrad Lischka/Anita Klingel, Wenn Maschinen Menschen bewerten, Internationale Fallbeispiele für Prozesse algorithmischer Entscheidungsfindung, Arbeitspapier, Gütersloh 2017, abrufbar unter https://www.bertelsmann-stiftung.de/doi/10.11586/201702, besucht am 19.3.2026.
Lötscher Cordula, Wenn das Auto den Laster nicht sieht, Jusletter IT 24.11.2016.
Martini Mario, Blackbox Algorithmus: Grundfragen einer Regulierung Künstlicher Intelligenz, Berlin 2019.
Mathys Roland/Reinhart Helen, Bestimmung von Vertragskonditionen im Rahmen automatisierter Entscheidungen, SZW 2020, S. 35–42.
Mehmedovic Senida, Le droit d’accès à une décision individuelle automatisée, Jusletter 19.9.2022.
Meyer Christian, Digitale Formulare als Angelpunkt automatisierter Verwaltungsverfahren, ZSR I 2022, S. 365–383.
Morand Anne-Sophie, Warum das europäische KI-Gesetz auch die Schweiz betrifft, Interview in der Netzwoche mit René Jaun, 10. Mai 2023, abrufbar unter https://www.netzwoche.ch/interviews/2023-05-10/warum-das-europaeische-ki-gesetz-auch-die-schweiz-betrifft, besucht am 19.3.2026 (zit. Interview).
Obrecht Liliane, Verfügung und automatisierte Einzelentscheidung – same same but different?, ex/ante, 2022 Nr. 2, S. 38–45.
Pärli Kurt/Flück Nathalie, Kommentierung zu Art. 21 DSG, in Baeriswyl Bruno/Pärli Kurt/Blonski Dominika (Hrsg.), Stämpflis Handkommentar, Datenschutzgesetz (DSG), 2. Aufl., Bern 2023.
Pesapane Filippo/Codari Marina/Sardanelli Francesco, Artificial intelligence in medical imaging: threat or opportunity? – Radiologists again at the forefront of innovation in medicine, EurRadiol Exp 2018, abrufbar unter https://doi.org/10.1186/s41747-018-0061-6, besucht am 19.3.2026.
Plattner Roger, Digitales Verwaltungshandeln, Zürich 2021, abrufbar unter https://suigeneris-verlag.ch/img/uploads/pdf/oa_pdf-021-1633456506.pdf, besucht am 19.3.2026.
Powell Julian/Obrecht Liliane, Regelung automatisierter Einzelentscheidungen im Lichte der KI-Konvention des Europarates, SJZ 122 (2026), S. 287–299.
Prince Anya E.R./Schwarcz Daniel, Proxy Discrimination in the Age of Artificial Intelligence and Big Data, Iowa Law Review 2020, S. 1257–1318.
Räz Tim, COMPAS: zu einer wegweisenden Debatte über algorithmische Risikobeurteilung, Forensische Psychiatrie, Psychologie, Kriminologie 2022, S. 300–306.
Rechsteiner David, Der Algorithmus verfügt, Jusletter 26.11.2018.
David Rosenthal, Der Entwurf für ein neues Datenschutzgesetz, in: Jusletter 27.11.2017 (zit. Entwurf).
Rosenthal David, Das neue Datenschutzgesetz, Jusletter 16.11.2020 (zit. nDSG).
Roth Simon, Die automatisierte Einzelentscheidung, digma 2017, S. 104–109.
Škorjanc Žiga, Automatisierte Kreditentscheidungen, CB 2020, S. 70–74.
Schindler Benjamin, Kommentierung zu Art. 5 BV, in: Ehrenzeller Bernhard et al. (Hrsg.), St. Galler Kommentar, Bundesverfassung, 4. Aufl., Zürich/St. Gallen 2023 (zit. SGK).
Schmidt Christoph, Quo vadis, Finanzverwaltung? Potenziale und Herausforderungen eines künftigen behördlichen KI-Einsatzes, Teil I: Entscheidungsunterstützung im Rahmen der hybridgen Fallbearbeitung, REthinking tax, Januar 2022, S. 70–81 (zit. Teil I).
Schmidt Christoph, Quo vadis, Finanzverwaltung? Potenziale und Herausforderungen eines künftigen behördlichen KI-Einsatzes, Teil II: Spezifische Chancen und Problemfelder der vollständigen Entscheidungsautomatisierung im Überblick, REthinking tax, September 2022, S. 31–42 (zit. Teil II).
Stöcklin Fabia, Robot Recruiting, sui generis 2022, abrufbar unter https://sui-generis.ch/article/view/4045/2949, besucht am 19.3.2026.
Styczynski Zbigniew A./Rudion Krzysztof/Naumann André, Einführung und Grundbegriffe der Expertensysteme, in: Styczynski Zbigniew A./Rudion Krzysztof/Naumann André (Hrsg.), Einführung in Expertensysteme, Berlin 2017, S. 1–20.
Thouvenin Florent et al., Positionspapier «Ein Rechtsrahmen für Künstliche Intelligenz», Zürich 2021, abrufbar unter https://www.dsi.uzh.ch/de/research/projects/strategy-lab/strategy-lab-21.html, besucht am 19.3.2026.
Thouvenin Florent/Früh Alfred, Automatisierte Entscheidungen: Grundfragen aus der Perspektive des Privatrechts, SZW 2020, S. 3–17.
Thouvenin Florent/Früh Alfred/George Damian, Datenschutz und automatisierte Entscheidungen, Jusletter 26.11.2018.
Thouvenin Florent/Früh Alfred/Henseler Simon, Article 22 GDPR on Automated Individual Decision-Making: Prohibition or Data Subject Right?, EDPL 2 (2022), S. 183–198.
Thurnherr Daniela, Automatisierte Verwaltungsverfahren auf Bundesebene, in: Braun Binder Nadja/Bussjäger Peter/Eller Mathias (Hrsg.), Auswirkungen auf die Erlassung und Zuordnung behördlicher Entscheidungen, Wien/Hamburg 2021, S. 133–157.
Tsai Chun-Wie/Lai Chin-Feng/Chao Han-Chieh/Vasilakos Athanasios V., Big data analytics: a survey, Journal of Big Data 2015, abrufbar unter https://link.springer.com/article/10.1186/s40537-015-0030-3, besucht am 19.3.2026.
Vasella David/Henseler Simon, Kommentierung von Art. 21 DSG, in Blechta Gabor-Paul/Vasella David (Hrsg.), Basler Kommentar, Datenschutzgesetz/Öffentlichkeitsgesetz, 4. Aufl., Basel 2014 (zit. BSK).
Waldmann Bernhard, Kommentierung zu Art. 29 BV, in: Waldmann Bernhard/Belser Eva Maria/Epiney Astrid (Hrsg.), Basler Kommentar, Bundesverfassung, 2. Aufl., Basel 2025.
Weber Rolf H., Automatisierte Entscheidungen: Perspektive Grundrechte, SZW 2020, S. 18–26 (zit. Grundrechte).
Weber Rolf H., Dürfen Maschinen über Menschen entscheiden?, Eine rechtliche Auslegeordnung im Lichte neuer Technologien, Schweizer Monat 2019, Ausgabe 1063, S. 72–74 (zit. Maschinen).
Weder Regina, Verfahrensgrundrechtliche Anforderungen an automatisierte Verwaltungsverfahren, in: Simmler Monika (Hrsg.), Smart Criminal Justice, Basel 2021, S. 237–262.
Wiederkehr René/Meyer Christian, Schranken, Ausnahmen und Relativierungen des rechtlichen Gehörs: Insbesondere mit Blick auf automatisierte Verwaltungsverfahren, AJP 2022, S. 1092–1108.
Wiederkehr René/Meyer Christian/Böhme Anna, Orell Füssli Kommentar, Bundesgesetz über das Verwaltungsverfahren und weiteren Erlassen, Zürich 2022.
Winkler Markus, Credit Scoring, AML Software & Risk Profiling: Automatisierte Entscheidungen im Rahmen von Finanzdienstleistungen, SZW 2020, S. 62–72.
Materials
Bundesamt für Justiz, Rechtliche Basisanalyse im Rahmen der Auslegung zu den Regulierungsansätzen im Bereich künstliche Intelligenz, August 2024 (zit. BJ, Rechtliche Basisanalyse).
Botschaft zur Änderung des Schwerverkehrsabgabegesetzes und zum Verpflichtungskredit für die Finanzierung eines neuen Systems für die Erhebung der leistungsabhängigen Schwerverkehrsabgabe vom 31. August 2022, BBl 2022 2323 (zit. Botschaft SVAG 2022).
Botschaft zum Bundesgesetz über die Totalrevision des Bundesgesetzes über den Datenschutz und die Änderung weiterer Erlasse zum Datenschutz vom 15. September 2017, BBl 6941 7192 ff. (zit. Botschaft DSG 2017).
bitkom e.V. - Bundesverband Informationswirtschaft, Telekommunikation und neue Medien e.V., Entscheidungsunterstützung mit Künstlicher Intelligenz, Berlin 2017, abrufbar unter https://www.bitkom.org/sites/main/files/file/import/171012-KI-Gipfelpapier-online.pdf, besucht am 19.3.2026.
Bundesamt für Justiz, Erläuternder Bericht zum Vorentwurf für das Bundesgesetz über die Totalrevision des Datenschutzgesetzes und die Änderung weiterer Erlasse zum Datenschutz vom 21. Dezember 2017 (zit. Erläuternder Bericht Vorentwurf DSG).
Botschaft zur Änderung des Bundesgesetzes über den Datenschutz (DSG) und zum Bundesbeschluss betreffend den Beitritt der Schweiz zum Zusatzprotokoll vom 8. November 2001 zum Übereinkommen zum Schutz des Menschen bei der automatischen Verarbeitung personenbezogener Daten bezüglich Aufsichtsbehörden und grenzüberschreitende Datenübermittlung vom 19. Februar 2003, BBl 2003 2101 (zit. Botschaft DSG 2003).
Richtlinien für die Bearbeitung von Personendaten in der Bundesverwaltung vom 16. März 1981, BBl 1981 I 1298 (zit. Richtlinien 1981).