A Fribourg municipality holds data on residents, taxpayers, pupils and recipients of social assistance. A care home or a mandated institution does the same. Yet when these entities look for their obligations, they come across articles devoted to the federal law, which does not concern them directly.

The canton of Fribourg does in fact have its own law. This article explains who it targets, what it requires, and above all what it changes for private SMEs acting as service providers to a municipality or a public institution. This last point is the least well known, and the most costly to discover partway through a mandate.

Two laws, two audiences: how to tell them apart

The split is simpler than it looks, but it is almost always poorly explained.

The federal act on data protection (FADP, RS 235.1) governs the processing of data by federal bodies and by private parties. It is the one that applies to your SME, your fiduciary firm, your garage. We cover it in detail in the article on your FADP obligations.

Cantonal law, on the other hand, governs processing by cantonal and municipal bodies. In Fribourg, this is the act of 12 October 2023 on data protection (LPrD, RSF 17.1), which came into force on 1 January 2024. It replaced a 1994 text, written before the web became widespread.

EntityLaw generally applicableSupervisory authority
Private Fribourg SME (trade, craft, services)Federal law (FADP)FDPIC
Municipality, association of municipalities, municipal departmentFribourg LPrDATPrDM
Cantonal institution, legal entity under public lawFribourg LPrDATPrDM
Private party carrying out a public-law taskFribourg LPrD for that taskATPrDM
Private company acting as a municipality’s processorFADP, plus the contractual obligations imposed by the municipalityFDPIC, the municipality remains responsible

This table gives the general orientation. Mixed situations exist: the same entity may fall under both regimes depending on the activity concerned.

Who is actually subject to the LPrD?

Article 2 of the law is short and decisive. It applies to the following public bodies:

  • State bodies, municipalities and other legal entities under public law;
  • private parties and bodies of private institutions when they carry out public-law tasks.

It is the second category that surprises people. The entity’s legal status is not enough to settle the question: what matters is the nature of the task carried out. An association, a foundation or a company may find itself subject to the cantonal law for the part of its activity that constitutes a delegated public task.

Do not confuse a subsidy with a public task

Receiving public money does not automatically make an association subject to the LPrD. The test in article 2 is carrying out a public-law task, not funding. An out-of-school care facility mandated by a municipality is not in the same situation as a sports club that is simply subsidised. The boundary is a legal one and is decided case by case: have it qualified rather than guessing at it.

Conversely, article 3 excludes certain processing, notably that carried out in the context of ongoing judicial proceedings and that carried out by a public body in economic competition with private parties.

What does the LPrD require from a municipality day to day?

Four obligations have visible effects within a municipal administration.

Declaring processing activities. This is the most significant mechanical difference from the federal law. Under the FADP, an SME keeps its own register, or is exempted from it under certain conditions. Under the LPrD, article 38 provides that it is the supervisory authority that keeps a public register, and that each controller declares its activities and their subsequent changes to it. Article 39 excepts certain purely internal administrative processing: address lists, correspondence, accounting records.

Implementing technical and organisational measures. Article 40 requires appropriate measures, decided from the design stage of the processing operation. It adds two often-overlooked requirements: default settings that limit processing to the minimum required, and documentation of the measures adopted.

Carrying out an impact assessment when the risk is high. Article 41 gives typical cases: large-scale processing of sensitive data, profiling, systematic surveillance of large parts of the public domain, processing of an unusual scale. If the assessment confirms a high risk requiring particular precautionary measures, article 42 requires consulting the supervisory authority, which in principle has two months to respond, extendable by one month for complex processing. This deadline needs to be planned for: it should not be discovered three days before going live.

Handling security breaches. We come back to this below.

One scheduling point is worth flagging. Article 62 gave processing operations already under way a two-year period from entry into force to achieve compliance, with articles 43 and 44 directly applicable from the outset. This transitional period has now ended.

You are a municipality’s service provider: what falls on you

This is the most common situation for an SME in French-speaking Switzerland, and the least well documented. You sell software, you host a website, you provide IT management, you digitise archives. Your client is a municipality.

First point: you do not become subject to the LPrD merely by entering into this contract. You remain a private company under the FADP. But the municipality remains fully responsible, and the law requires it to oversee you. Its obligations therefore become your contractual clauses.

Articles 18 to 21 govern outsourcing. Article 19 lists what the contract must describe at a minimum:

  • the subject, nature, purpose and duration of the outsourcing;
  • the categories of data concerned;
  • the obligations and rights of each party;
  • the rights and possibilities of oversight over the processor, in other words a right to audit you;
  • the prohibition on you subcontracting further without prior written authorisation;
  • your duty to immediately inform the controller if a foreign law or court decision requires you to disclose the data to a foreign authority.

Article 18 para. 2 adds a structuring requirement: processing locations must at all times be situated on Swiss territory or on the territory of a State guaranteeing an adequate level of protection. If your tool relies on infrastructure outside this perimeter, or if one of your own providers processes the data there, you generally will not be able to respond to the tender without making changes.

Article 20 requires that the integrity, authenticity, availability and confidentiality of outsourced data be guaranteed by measures proportionate to the risk, and that business continuity be ensured in the event of an incident. Article 21 goes further for sensitive data and data covered by a legal duty of confidentiality: a commitment not to access the content without express consent, keeping an access log, and the status of an auxiliary of the holder of the secret. Lastly, article 37 recalls that the controller must ensure that you are able to guarantee data security, which implies that you must be able to demonstrate it.

Turn the constraint into a sales argument

Prepare a two-page file before your next public tender: exact hosting location, list of your subcontractors, security measures, incident notification procedure, and data return deadline at the end of the contract. Your competitors will not have one. The cyber check-up gives you the material for this file in a few minutes.

In the event of a data breach at a public entity

Article 43 organises the response. When it becomes aware of a breach of personal data security, the controller immediately takes appropriate measures to end it and minimise its effects. It records in an internal document the nature of the breach, the type of data and the categories of persons affected, the likely consequences and the measures taken.

Notification to the authority then follows, as soon as possible, for cases likely to entail a high risk to the fundamental rights of the person concerned. As at federal level, no fixed deadline such as 72 hours is set, which obviously does not permit any delay.

For a service provider, paragraph 4 is the most important: the controller must ensure that the processor reports without delay any breach that occurs on its side. There is no threshold of severity for you to assess. You detect it, you report it. Same logic as under federal law, covered in detail in our article on reporting a data breach.

Article 44 deals with informing the person concerned, with the possibility of a public communication when the breach affects a large number of people. Our feature on data theft and leaks describes the most common scenarios.

What you risk, and where to start

The LPrD relies on administrative oversight rather than individual fines. Article 56 authorises the commissioner to inspect, on their own initiative or following a complaint, a controller or a processor, to require the production of documents and to carry out inspections. Article 57 allows the commissioner to issue a recommendation, and article 58 allows the commission to order the suspension, modification or termination of processing, or even the erasure of data. Article 35 further reserves compensation for damage and non-material harm suffered by an affected person.

For a service provider, the real sanction lies elsewhere: a suspension of processing ordered against your client is your solution being shut down. And the loss of a public contract has knock-on effects on the next ones.

These issues arise in a context where incidents remain numerous: the National Cyber Security Centre recorded 64,733 voluntary reports in 2025, against 62,954 in 2024 (NCSC, half-year report 2025/II, 30 March 2026).

Four first steps, in this order:

  1. Qualify your situation. Public body, private party carrying out a public-law task, or simple processor? Everything follows from this answer.
  2. Map the location of your data, including at your own suppliers. This is the most common sticking point with article 18.
  3. Review your existing public contracts against the list in article 19. Mandates predating 2024 are rarely up to date.
  4. Write your incident notification procedure, with a name, a number and a deadline. Two paragraphs are enough, and they will save you a lot of wasted time one day.

This article presents the general framework and does not constitute legal advice. On a sensitive point, the ATPrDM answers questions from bodies subject to the law, and a specialised advisor remains advisable for a delicate qualification. The other obligations applicable in Switzerland are grouped in the Regulations pillar.