Available only in Switzerland

Schweizerform is currently available exclusively for users in Switzerland. Account creation from your region is restricted.
Back to Blog

Whistleblowing in Switzerland — What the Law Actually Requires

Switzerland has no general whistleblower-protection statute: the Code of Obligations revision failed in Parliament in 2020 and nothing replaced it. What exists instead is a duty of loyalty, a reporting cascade built by the courts, an abusive-dismissal remedy capped at six months' salary, a separate regime for federal employees, and the EU Directive reaching Swiss groups through their EU subsidiaries. What that means for anyone building an internal reporting channel.

Whistleblowing in Switzerland — What the Law Actually Requires

Almost everyone who searches for Swiss whistleblowing law is trying to confirm something they have already half heard: that there isn't one. They are right, and the confirmation matters, because the absence is not a gap that gets quietly filled by general principles. It changes what a Swiss employer must do, what a Swiss employee may safely do, and — the part that gets missed — how much protection a reporting channel has to supply on its own, because the statute book supplies so little.

The short version

Switzerland has no general whistleblower-protection statute. A revision of the Code of Obligations was worked on for roughly seventeen years and was definitively rejected by Parliament in March 2020; nothing has replaced it. Private-sector employees rely on the duty of loyalty in Art. 321a CO, a reporting cascade developed by the courts (internal first, then the authority, the public only as a last resort), and the abusive-dismissal rules in Art. 336/336a CO — under which the dismissal remains valid and compensation is capped at six months' salary. Federal employees have a genuine regime: Art. 22a Federal Personnel Act obliges them to report ex-officio offences, lets them report other irregularities to the Swiss Federal Audit Office (anonymously if they wish), and protects them against professional disadvantage. Private employers have no general duty to operate a reporting channel — unless the EU Directive catches their EU subsidiaries, or a sector regulator requires one. Which is precisely why the credibility of a voluntary channel rests on its architecture rather than on the law.

This article covers the Swiss position. Its companion on the EU side — thresholds, deadlines, multilingual intake — is the EU Whistleblowing Directive and compliant reporting channels.

The Law That Never Arrived

The story is worth two paragraphs because it explains why Swiss guidance on this subject is so inconsistent — much of it was written in anticipation of a law that never came into force.

A parliamentary motion in 2003 asked the Federal Council to protect employees who report irregularities at work. A draft followed, then a revised draft after the first was sent back as too complicated, then years of shuttling between the two chambers. In March 2020 Parliament ended it. The criticism came from both directions at once: business representatives thought the scheme burdensome, and the trade unions argued it would have made things worse, because it codified an elaborate procedural cascade without improving protection against dismissal. The Swiss Trade Union Confederation openly welcomed the failure. That is an unusual coalition, and it is the reason no successor bill has advanced since.

International bodies have not let the subject drop — the OECD's Working Group on Bribery has repeatedly criticised Switzerland's lack of protection for private-sector whistleblowers and raised the pressure again in 2022 — but criticism is not legislation. As of July 2026 the position is unchanged: no general statute, no obligation for a private Swiss employer to operate a reporting channel, and no purpose-built protection for the person who uses one.

Why this matters for the channel you are building

In the EU, a reporter has a statute behind them: retaliation is prohibited, the burden of proof reverses, and remedies exist. In Switzerland a private-sector reporter has a cascade to follow and, if it goes wrong, up to six months' salary. Ask an employee to trust an internal channel in that legal environment and the honest answer is that the law will not save them — so the confidentiality of the channel is not a nice-to-have feature. It is the entire protection.

What Swiss Law Does Say — Four Provisions That Decide Cases

Art. 321a CO — the duty of loyalty, and why it points inward

Employees must safeguard their employer's legitimate interests in good faith and must not exploit or disclose confidential facts. That duty is the starting point of every Swiss whistleblowing analysis, and it runs in the opposite direction to reporting. It does not make reporting unlawful — a legitimate public interest can outweigh it — but it is why the courts require the reporter to choose the least damaging effective route, and why an employee who goes to the press first is usually the one who loses the case.

The reporting cascade — a rule of case law, not of statute

Because the revision failed, the cascade was never codified. It nonetheless governs, having been developed in case law and doctrine out of Art. 321a. It runs in three steps, and each one requires the previous step to have failed or to be futile.

StepWhen it is permissibleWhat defeats it
1. Internal reportAlways the first step: to the employer, a superior, the internal reporting office or the audit functionNothing — this step is expected. Skipping it is what usually goes wrong
2. Report to the competent authorityWhen the internal route failed, was ignored, or would obviously be pointless — for example where management itself is implicatedGoing to the authority first without a reason recorded at the time; a suspicion raised in bad faith
3. Going publicLast resort, where the authority does not act and the public interest is weightyAlmost anything else: an untried internal route, an authority not yet given time, disclosure wider than the matter requires

Two practical consequences. For the employee: document each step and the date, because the defence to a breach-of-loyalty claim is the record showing that the earlier rung was tried. For the employer: an internal channel that is visibly serious is a legal asset. If your channel is credible and used, reports arrive at step one; if it is a shared HR mailbox nobody trusts, the cascade is satisfied in form and your first knowledge of the problem is a phone call from a journalist.

Art. 336 and 336a CO — abusive dismissal, and the six-month ceiling

A dismissal for making a legitimate report can be abusive under Art. 336 CO. Two features of Swiss dismissal law dominate everything that follows. First, an abusive dismissal is still effective — the employment ends; there is no reinstatement in the private sector. Second, the compensation under Art. 336a CO is capped at six months' salary, and awards in practice are usually well below the ceiling.

For a mid-career employee weighing whether to report misconduct by their own management, that is the arithmetic: the best realistic outcome of winning is a few months' pay and no job. This is the single most important fact on this page, because it explains a behaviour every compliance officer observes and few explain — Swiss employees overwhelmingly prefer anonymous channels, and they are not being paranoid. They have read the same arithmetic.

Art. 328 and 328b CO — the employer's own duties

Art. 328 CO requires the employer to protect the employee's personality and integrity — the basis for the argument that once a report of harassment, discrimination or safety failure has arrived, the employer must actually handle it, and must protect the reporter from retaliation by colleagues. Art. 328b limits the processing of employee data to what concerns their suitability for the role or is necessary to perform the contract. The FDPIC's long-standing position is that Art. 328b cannot be departed from to the employee's detriment even with consent — a point that also decides how much an investigation file may collect and how long it may be kept.

The criminal-law backstop nobody mentions until it is too late

External reporting can collide with criminal secrecy provisions: business secrets under Art. 162 SCC, banking secrecy under Art. 47 Banking Act, professional secrecy under Art. 321 SCC for regulated professions and their auxiliary staff, official secrecy under Art. 320 SCC in the public sector. Reporting to the competent authority is generally the safe route precisely because it is the one the cascade contemplates; taking documents home, or sending them to a foreign outlet, is where prosecutions have arisen. If you operate in one of those sectors, say so in your policy — the reporter needs to know which door is safe.

The Public Sector Is a Different Country

Federal employees have the regime the private sector was denied. Art. 22a of the Federal Personnel Act sets out three things:

  • A duty to report. Federal employees must report offences prosecuted ex officio that they learn of in the course of their work — to the criminal prosecution authorities, to their superior, or to the Swiss Federal Audit Office.
  • A right to report. Other irregularities may be reported to the Federal Audit Office, and this may be done anonymously — the Audit Office operates a dedicated secure platform for it.
  • Protection. Under para. 5, anyone who reports in good faith or testifies as a witness must not suffer professional disadvantage as a result, dismissal in particular.

Cantonal and communal employees are governed by cantonal personnel law, which varies: some cantons have their own reporting offices or ombudsman arrangements, others have essentially nothing. There is no national answer — check your canton, and note the date on which you checked, because these rules have been moving.

Public bodies also carry a second constraint that private employers do not: cantonal data protection law governs their processing, and in November 2025 privatim, the conference of Swiss data protection commissioners, adopted a resolution on international cloud services that treats provider access as the decisive criterion, with a narrow exception where the public body encrypts the data itself and the provider holds no key. For a reporting channel run by an administration, that is not a footnote — it points directly at the architecture. See which form tools are hosted in Switzerland.

When the EU Directive Binds You Anyway

Directive (EU) 2019/1937 does not apply in Switzerland. It applies to legal entities established in the EU, and that is how it reaches a large number of Swiss companies: through their subsidiaries.

Your situationDirective obligation?Notes
Swiss company, Swiss sites onlyNoNo EU legal entity, no obligation. A channel is voluntary — and, for the reasons above, worth having
Swiss group with an EU subsidiary of 50+ workersYes, at that subsidiary250+ had to comply by 17 Dec 2021; 50–249 by 17 Dec 2023. Implementation is national law, so check the member state
Swiss group with an EU subsidiary in financial servicesYes, regardless of headcountFinancial-sector entities are covered irrespective of the 50-worker threshold
Swiss company with EU-based employees but no EU entityGenerally noThe obligation attaches to the establishment, not to the employee's residence — but the local employment law of that country may say more
Federal administrationNo (Art. 22a Federal Personnel Act applies)A Swiss regime with a real protection clause, and anonymous intake at the Federal Audit Office

Where it does apply, the requirements that shape the tooling are: confidentiality of the reporter's identity, an acknowledgement of receipt within seven days, feedback within three months, the ability to report in writing and orally, and channels accessible to the workforce in a language they actually speak. Anonymous reporting is left to each member state to permit or not — so a group operating in several member states typically ends up supporting it everywhere, because the alternative is running different rules per country.

One trap worth naming: a group-wide channel run out of Zurich for a French subsidiary does not automatically discharge the French obligation. The Commission's position has been that entities of 50–249 workers may share resources for investigating reports, but the local entity must still maintain its own channel for receiving them. Build the channel so each entity has its own intake point and its own case handler, then share the back office where the law allows it.

Sector Rules That Apply Inside Switzerland

«No general statute» is not the same as «no obligations». Several Swiss sectors expect internal reporting arrangements as part of their governance requirements, and supervisors run their own external channels alongside them:

  • Financial institutions. FINMA's corporate-governance expectations for supervised institutions include an internal reporting process, and FINMA operates its own secure whistleblowing channel for reports about supervised entities. A report can therefore go around you, which is an argument for making your internal route the more attractive one.
  • Companies with an internal audit or compliance function. Where governance rules or the auditors expect a reporting mechanism, its documentation — policy, log, statistics, outcomes — is what actually gets examined, not the intention.
  • Groups subject to foreign law by contract. Anti-corruption commitments in supplier contracts and US or UK compliance programmes routinely impose a channel on a Swiss counterparty. Read the contract; this is a common source of an obligation people believe they do not have.
  • Cantonal public bodies. Cantonal personnel and administrative law, plus the cantonal data protection act — the combination differs canton by canton.

What Data Protection Law Requires of the Channel Itself

This is the part that is genuinely regulated in Switzerland, and it is where most reporting channels fail an inspection. A report is a small package of highly charged personal data about at least two people — the reporter and the accused — and often several bystanders who never chose to be in it.

  1. It is sensitive data. Art. 5 lit. c nFADP expressly includes data on administrative and criminal proceedings and sanctions. A report alleging fraud, harassment or a safety breach is in that category from the moment it arrives — with the heightened security and documentation expectations that follow.
  2. A data protection impact assessment is likely required. Art. 22 nFADP triggers a DPIA where processing entails a high risk to personality or fundamental rights; a system that collects allegations about identified employees, with a power imbalance and a retaliation risk, is the textbook case. Do it once, keep it with the policy.
  3. Proportionality applies to the form fields. Art. 6 nFADP, and Art. 328b CO on top of it. Ask what happened, when, who was involved and what evidence exists. Do not ask for the reporter's department, function and line manager «for context» — three such fields identify most people in an organisation of any size.
  4. The accused has rights too — but not unlimited ones. The right of access under Art. 25 nFADP can be restricted under Art. 26 where an overriding third-party interest requires it, and cantonal data protection authorities have accepted the reporter's interest in not being exposed to retaliation as exactly such an interest. Restricting access is a documented decision on the individual case, not a blanket policy line.
  5. Information duties are deferrable, not disposable. The accused normally has to be informed; where doing so immediately would frustrate the investigation, that can be deferred on the basis of an overriding interest — and then done.
  6. Retention has to be short and written down. Substantiated cases follow the retention period of the resulting proceedings; unsubstantiated reports should be deleted once the assessment is closed, with the deletion recorded. See form data retention.
  7. Cross-border matters here more than anywhere. A report about a Swiss manager sitting in a US-hosted case-management system is a disclosure abroad that needs its Art. 16/17 basis documented — and, more to the point, is exactly the fact that will circulate internally and kill usage of the channel. See which form data can legally leave Switzerland.

The failure mode: reports arriving by e-mail

A reporting address that forwards to an HR mailbox produces unencrypted copies of highly sensitive allegations in several inboxes, on several phones, with several years of backups behind them, and with an IT administrator able to read all of it. It also silently records the reporter's e-mail address and message headers. If you take one operational point from this article: alert your case handler that a report has arrived, never send the content.

Anonymity Versus Confidentiality — The Distinction That Decides Whether the Channel Is Used

These two words are used interchangeably in vendor material and they mean very different things. Confidential means the organisation knows who reported and undertakes to restrict who else learns it. Anonymous means the organisation cannot know, because the identity was never collected. Confidentiality is a promise, backed by process; anonymity is a property, backed by architecture. In a country where the legal remedy for retaliation is six months' salary, employees understand that difference instinctively.

Anonymity has real costs and it is dishonest to pretend otherwise. Anonymous reports are harder to investigate, follow-up questions may be impossible, and an anonymous accusation is harder to weigh fairly against the accused's interests. The workable middle ground is an anonymous channel with a two-way return path: the reporter keeps a token or a code that lets them come back and answer questions without revealing who they are. It preserves the investigation without spending the reporter's protection.

If you promise anonymity, the promise has to survive inspection of the system, not just of the policy. Three things break it in practice:

  • Technical identifiers collected without anyone deciding to collect them — IP addresses, browser and device data, account identifiers if the form sits behind a corporate login, e-mail headers if the report arrives by mail. Any of these turns an «anonymous» report into a pseudonymous one that internal IT can resolve.
  • Free text. The reporter writes «I raised this with my team lead in March» and has identified themselves to anyone who knows the team. No platform can prevent this; the policy and the form's guidance text can warn about it, and should.
  • Provider access. If the platform's operator can read submissions, the set of people who could learn the reporter's identity extends past your organisation entirely. For a whistleblowing channel that is not a theoretical objection — it is the objection the workforce will raise.

The mechanics of the first point — which identifiers are worth keeping, what a hashed IP does and does not protect, how to prevent abuse of an open channel without building an identity register — are covered in preventing spam, bots and duplicate submissions without breaking anonymity and in anonymous forms versus pseudonymous forms.

Setting Up a Channel That Holds Up

1

Decide the scope and write it down

Which conduct the channel is for — criminal offences, corruption, harassment, safety, environmental, accounting — and which it is not. A channel with no scope becomes a complaints box and loses the seriousness that made it useful.

2

Name who receives reports, and who never does

Two named case handlers is the usual minimum, with a defined substitute route for reports concerning them. Explicitly exclude the line-management chain of the person reported. Access must be enforced technically, not by asking people not to look.

3

Choose anonymity mode deliberately

Anonymous with a return path is the default we would recommend in Switzerland. If you allow identified reports as well, make clear which one the reporter is choosing at the moment they submit, not in a policy PDF.

4

Set the deadlines and diarise them

Seven days to acknowledge and three months to give feedback are the EU figures. If you have any EU exposure you will be held to them; if you do not, adopt them anyway — a channel that answers nothing is worse than no channel, because it has already consumed the trust it needed.

5

Publish it in the languages people work in

In Switzerland that means German, French and Italian at minimum, plus English, plus the languages of your workforce. Someone reporting a safety violation on a construction site will not do it in their third language.

6

Run the DPIA and set retention before go-live

Not after the first report arrives. Document the legal basis, the fields collected, who has access, the retention rule for substantiated and unsubstantiated cases, and the deletion evidence. Our nFADP compliance checklist for forms and surveys covers the paperwork item by item.

7

Consult the employee representation and communicate honestly

Where a staff committee or works council exists, involve it — its endorsement is worth more to uptake than any launch e-mail. And state plainly what the channel does and does not protect: in Switzerland that means saying that the law offers limited protection, and explaining what the system does instead.

The test of a reporting channel is not whether it exists. It is whether the person with the most to lose believes it.

Why the Architecture Is Doing the Work Here

Put the pieces together. There is no statute standing behind the reporter. The remedy for retaliation is capped and the job is gone regardless. The report itself is sensitive data about identified people. And the person deciding whether to use the channel is, by definition, someone who suspects that parts of their own organisation cannot be trusted with the information.

In that setting, «we have a policy» is not a persuasive answer, and neither is «the data is encrypted», which for most platforms means encrypted with keys the platform holds. What is persuasive is a channel where the report is encrypted in the reporter's browser before it is sent, where only the named case handlers hold the key that opens it, where the platform operator holds ciphertext and can therefore be compelled to produce nothing else, and where no identifier was collected that would let anyone work backwards to the reporter.

That is a set of properties you can demonstrate rather than promise — and demonstrability is the currency here. It is also, incidentally, what makes the same channel usable by people outside the organisation: suppliers, customers, patients, citizens. The design that satisfies a suspicious employee satisfies everyone else automatically.


Bottom Line

Switzerland has no whistleblower-protection law, and that is the correct answer rather than an incomplete one. What exists is a duty of loyalty, a cascade built by the courts, a dismissal remedy capped at six months' salary, a real regime for federal employees under Art. 22a Federal Personnel Act, sector expectations in finance, and the EU Directive reaching Swiss groups through their EU subsidiaries.

For an employer, the practical reading is that a reporting channel is mostly voluntary and entirely in your interest: it is what keeps the cascade at step one. For an employee, it is that the law will not carry you, so the confidentiality of the route you choose is the protection you actually have. Both readings point the same way — the value of the channel is a function of what it is technically incapable of revealing, and the data protection rules around it (sensitive data, DPIA, restricted access, short retention, documented transfers) are the part of this subject that is genuinely enforceable in Switzerland today.

Schweizerform is used for exactly this: reports encrypted in the reporter's browser, decryptable only by the case handlers holding the Vault key, encrypted submissions stored in Switzerland on every plan, with no provider-side access to content and no requirement that the reporter have an account. See the HR and whistleblower reporting use case for how the workflow is set up, and the secure tip line use case for the external-source variant. If you are still choosing a route, whistleblowing platforms for Swiss companies compared sets out the three options honestly, and privacy-compliant survey tools compared covers the adjacent case where the channel is a survey rather than a report.

Disclaimer: This article is general information and marketing content, not legal advice, and it does not create a lawyer-client relationship. References to the Swiss Code of Obligations (Art. 321a, 328, 328b, 336, 336a), the Swiss Criminal Code (Art. 162, 320, 321), the Federal Personnel Act (Art. 22a), the nFADP (Art. 5 lit. c, 6, 16, 17, 22, 25, 26), the Data Protection Ordinance and Directive (EU) 2019/1937 are simplified summaries of a position checked in July 2026; the law, its interpretation and cantonal rules change. Whistleblowing cases are highly fact-specific — take Swiss legal advice before reporting externally or before dismissing anyone who has reported.