Skip to main content
Required by EU law for organizations with 50+ employees

Whistleblower law in Switzerland #

Switzerland has no general whistleblower protection law. The Federal Council’s partial revision of the Code of Obligations, Protection in the event of reporting irregularities in the workplace, was rejected by the National Council on 5 March 2020 by 147 votes to 42, after an earlier version had already been sent back to the Federal Council for redrafting. The business was closed the same day. What governs instead is ordinary employment and criminal law, a separate statutory regime for federal public employees, and sectoral supervision.

Applicable law #

Does Directive (EU) 2019/1937 apply? #

No. Switzerland is neither an EU nor an EEA member, and the Directive does not extend to it through the bilateral agreements.

The exposure runs through subsidiaries in both directions, and the two directions are not symmetrical:

Who must establish an internal channel #

No Swiss law requires one. Two provisions nevertheless make the absence of a channel expensive.

Corporate criminal liability (Art. 102 para. 2 SCC). For bribery, money laundering, terrorism financing and criminal-organisation offences, the undertaking is penalised irrespective of the criminal liability of any natural person, provided it “failed to take all the reasonable organisational measures that are required in order to prevent such an offence”. Article 102 para. 1 caps the corporate fine at CHF 5 million. Swiss law does not enumerate those measures, so an organisation that has no way of learning about the conduct in the first place is arguing from a weak position.

The reporting cascade. Swiss case law permits a report to an authority only after an internal attempt has failed or would plainly be futile. FINMA states this in its own guidance : “According to case law for permitted whistleblowing you are fundamentally required first of all to attempt to report the suspected irregularity within the institution concerned. Only if this is not successful or appears futile is an external report to FINMA as the supervisory authority justified (so-called cascade system of permitted whistleblowing).” The regulator goes on to warn reporters that they “otherwise run the risk by submitting your report to FINMA of being liable to prosecution due to a potential breach of your duty of confidentiality.”

An employer with no internal route does not thereby keep reports in-house. It pushes workers straight to the step that carries the most legal risk for them, and the least control for the employer.

What protection a private-sector whistleblower has #

Very little, and it is worth being plain about that rather than implying otherwise.

Article 273 is the provision multinational groups underestimate. Where a report crosses the Swiss border — into a group intake abroad, or to a foreign authority — the routing decision is a question of Swiss criminal law, not of system architecture.

The federal public sector #

Federal employees are covered by a real statutory regime. Art. 22a of the Federal Personnel Act obliges them to report felonies and misdemeanours prosecuted ex officio that they observe in the course of their duties, to the prosecution authorities, their superiors or the Swiss Federal Audit Office (SFAO). Paragraph 4 gives them the right to report other irregularities to the SFAO, which then establishes the facts and takes the necessary measures. Paragraph 5 provides that anyone who reports in good faith or testifies as a witness may not be disadvantaged in their professional position as a result.

The SFAO operates an external reporting platform at whistleblowing.admin.ch , open to federal employees and to the public, covering the federal administration, affiliated organisations and subsidy recipients.

Article 22a covers employers under the Federal Personnel Act. Cantonal and communal employees fall under cantonal personnel law instead, which varies by canton.

External reporting authority #

There is no general external whistleblowing authority for the Swiss private sector. Reporting runs through whichever supervisory body has jurisdiction over the subject matter:

Data protection authority #

The competent authority is the Federal Data Protection and Information Commissioner (FDPIC) , under the Federal Act on Data Protection of 25 September 2020 , in force since 1 September 2023.

Key compliance points #

Official sources #

Primary law

Parliament and authorities


Deploy your reporting channel →

Last updated: