This page covers the essential concepts and links to more specialised resources. Capabilities, constraints and rules must always be checked against the relevant site and use case.
The ten-second rule: protect a site, do not observe people
Robotic surveillance is neither prohibited in principle nor authorised merely because equipment has been purchased. As soon as a person can be identified from an image, voice, registration plate or combination of clues, the Federal Act on Data Protection (FADP) applies. Employment law, criminal law governing audio and aviation rules for drones may apply alongside it. The applicable guidance is set out in Federal Act on Data Protection (FADP) (Fedlex).
Start with the operation: which hazard must be detected, in which zone, at what times and for which human response? A night-time intrusion into a closed depot is not the same as the everyday passage of employees or neighbours. The more continuous, mobile or unavoidable surveillance becomes, the stronger its safeguards need to be.
This page provides general information current as at 27 July 2026. It does not replace legal advice based on the canton, site, employment contracts, flight plan and processing operations actually configured.
Possible, subject to conditions
It is generally possible to record your own property to protect people or assets, use a mobile camera there, or fly a drone in the open category if every rule is met. Coverage, schedules, retention and access must remain necessary. A security interest does not remove the rights of people recorded.
- Intrusion detection in a closed private area, activated by an event and verified by a person.
- A robotic patrol outside operating hours on a route excluding sensitive zones.
- A VLOS flight in the open category after checking restrictions and privacy.
Strictly controlled or generally best avoided
Recording employees or the street, capturing sound, tracking people or using biometrics sharply increases risk. According to the FDPIC, generalised real-time facial recognition and comprehensive surveillance are incompatible with informational self-determination. A BVLOS flight normally enters the specific category and requires a procedure with FOCA. The applicable guidance is set out in Recording conversations (FDPIC) and Geographical flight restrictions (FOCA).
- Avoid a permanent camera directed at a workstation or unrestricted zoom over employees.
- Generally not permitted for a private party: monitoring public space to maintain public order.
- Disable by default: the microphone on a robot or camera.
Swiss FADP: map the processing before choosing technology
The FADP protects natural persons whose data is processed. A genuinely anonymous image differs from a video in which a face, vehicle or time makes somebody recognisable. Even an alert without an image becomes personal when linked to a person’s badge or schedule.
The controller determines the purpose and essential means of processing. It must explain what is collected, why, for how long, with whom and in which country. Purchasing a platform or outsourcing remote monitoring does not transfer that responsibility.
Six principles that change the design
Lawfulness, good faith, transparency, proportionality, purpose limitation and security require technical choices: masking neighbouring windows, detecting rather than identifying, event-based activation, encryption, named accounts and automatic deletion. Data protection by design and by default under Article 7 FADP calls for the least intrusive settings.
- State a specific purpose, not merely “improve security”.
- Compare locks, lighting, access control and non-imaging sensors.
- Never automatically repurpose a security alert to assess staff.
Consent, overriding interests and reasonable expectations
In the private sector, an infringement of personality requires justification through consent, an overriding private or public interest, or the law. Consent must be freely given, informed and specific, which is difficult at work or where a monitored zone cannot be avoided. A substantiated proportionality assessment is more defensible than an artificial tick box.
For a deeper analysis, read Robotic security in Switzerland: legal framework. Review the essential legal principles for a Swiss project.
Field of view: the legal boundary follows the image, not the wall
According to the FDPIC, private surveillance should remain within the controller’s own property: neighbouring land and public space such as a pavement should not enter the frame. The camera’s physical location is not enough; what it can see after rotation or zoom matters more. The applicable guidance is set out in Video surveillance by private individuals (FDPIC) and Video surveillance of public space by private individuals (FDPIC).
A strip of road captured “just in case” remains problematic. Private parties generally have no right to maintain public order there. Seek another position, a mask that an ordinary user cannot bypass, or less intrusive technology; any exception requires careful examination.
Neighbours, visitors and intimate areas
Windows, balconies, shared entrances and rest areas demand maximum care. In jointly owned property, a shared car park or a leased site, authority to decide does not necessarily belong to the system user. The lease, regulations and powers of the relevant body must be checked.
- Test during day and night and with every PTZ or tracking mode.
- Mask unnecessary areas and prevent ordinary accounts reactivating them.
- Provide an unrecorded circulation route where necessary.
A mobile robot changes the collection perimeter
A ground robot enjoys no legal exemption. Movement does, however, multiply contexts: a route that is defensible at night may be disproportionate during a break. Mapping needs geofences, schedules, prohibited zones, a safe speed, emergency stop and inward-facing orientation if positioning is lost.
Information, retention and access: rules for useful evidence
Surveillance must be recognisable before a person enters its range. A visible sign announces the system and, where necessary, identifies the controller and contact for exercising rights. A detailed notice may supplement the symbol. Signage never makes excessive coverage lawful.
Retention covers only the time needed to discover an incident. The FDPIC generally refers to 24 hours for private surveillance and 24 to 72 hours in the workplace, depending on purpose. These are not automatic entitlements: an extension requires justification, while an incident extract may be isolated. The applicable guidance is set out in Video surveillance in the workplace (FDPIC).
Restricted, traceable and reversible access
Live feeds and archives should be available only to necessary roles. Use named accounts, strong authentication, access logs and encrypted exports. The organisation must be able to respond to access requests, rectify or delete data without improperly revealing third-party images.
- Separate live viewing, search, export, administration and changes to privacy masks.
- Delete routine material automatically; isolate only the documented event.
- Provide offence-related footage to authorities, never social media.
Audio: leave the switch off
Listening to or recording a non-public conversation without every participant’s consent may breach Articles 179bis and 179ter of the Swiss Criminal Code, even where the operator participates. Ambient audio should therefore remain disabled. Clearly indicated, occasional intercom use differs from continuous recording.
For a deeper analysis, read Intelligent video surveillance and data protection. Configure purpose, framing, access, retention and transparency.
Employees: security must not become behavioural monitoring
Article 26 of Ordinance 3 to the Employment Act prohibits systems intended to monitor workers’ behaviour. When a system serves another reason, particularly security or production, it must impair neither health nor freedom of movement. Articles 328 and 328b of the Code of Obligations also protect employees’ personality.
Consent does not readily cure an excessive system: the subordinate employment relationship limits free choice. A continuous camera over a checkout or desk creates pressure even when nobody watches. Information, consultation and unrecorded areas supplement proportionality; they do not replace it.
More defensible configurations
Entrances, car parks, hazardous installations, strongrooms and sensitive stock may justify cameras depending on circumstances. Coverage should avoid workers. On a construction site, motion activation at night is easier to defend than permanent monitoring of progress.
- Schedule robotic patrols while staff are absent.
- Blur people and frame the hazard area.
- Prohibit footage being used to measure breaks, pace or performance.
Suspected wrongdoing: do not improvise covert tracking
A concrete suspicion may alter the balance of interests without giving an employer free rein. The FDPIC recommends allowing police to act where possible. Covert surveillance generally conflicts with good faith, and a court decides whether evidence is admissible. Any targeted measure calls for legal advice. The applicable guidance is set out in Guide to data security breaches (FDPIC).
AI and biometrics: detection is not identification
Detecting a human shape within a restricted zone is not facial recognition. Detection may reduce the images transmitted; identification uses templates. Biometric data that uniquely identifies a person is sensitive personal data under the FADP and requires stronger safeguards.
The FADP applies directly to AI. The FDPIC calls for transparency about purpose, operation and sources, and rejects generalised real-time facial recognition. The prudent course is to classify the event, minimise identification and keep a human responsible for decisions. The applicable guidance is set out in Decision on PostFinance voice recognition (FDPIC).
Two Swiss cases illustrate the dividing line
In October 2025, the FDPIC closed its examination of intelligent cameras at certain Coop checkouts. The system examined did not recognise faces or shopping habits; its processing was compliant and did not present an increased risk. That finding does not apply to every “AI camera”. The applicable guidance is set out in Coop intelligent-camera investigation (FDPIC).
By contrast, its decision of 16 May 2025 concerning PostFinance requires express consent before creating voiceprints and deletion of voiceprints without consent. An appeal was pending when the decision was published. The case illustrates the sensitivity of a persistent biometric identifier.
When a data protection impact assessment becomes central
A DPIA is required where processing is likely to present a high risk to personality or fundamental rights. Relevant cases include new technologies, large-scale sensitive data and systematic monitoring of extensive areas of public space. If a high residual risk remains, the FDPIC must be consulted unless an applicable exception applies. The applicable guidance is set out in Data protection impact assessments (FDPIC), AI and data protection (FDPIC) and Outsourcing and data processing (FDPIC).
- Triggers include biometrics, multi-camera tracking, many individuals or correlation with badges.
- Test bias, errors, night conditions, false alerts and human challenge.
- Retain versions, settings and validations needed to explain an alert.
Drones: combine aviation law with protection of privacy
Switzerland applies rules closely aligned with EASA’s. In the open category: a maximum height of 120 metres, no flight over assemblies of people, A1/A2/A3 distances and direct visual line of sight. Geographical restrictions, DABS, priority for manned aircraft, remote identification where applicable and qualifications all require verification.
The operator generally registers; an exception notably covers a drone below 250 grams that has no sensor capable of capturing personal data. Above 250 grams, FOCA requires third-party liability insurance of at least one million Swiss francs. Low weight removes neither privacy duties nor airspace rules. The applicable guidance is set out in Rules applicable to drone flights (FOCA) and Drone registration and insurance FAQs (FOCA).
VLOS: an automated patrol remains under visual control
In the open category, the remote pilot clearly follows both the drone and surrounding airspace. A docking station therefore does not authorise flight beyond visual line of sight. Night flight remains possible under VLOS with the required lights and at reduced range. Before every mission, check the official map, DABS, weather, third parties and authorisations.
BVLOS: specific category, declaration or authorisation
BVLOS, flight above 120 metres, an aircraft of 25 kilograms or more, flight over assemblies of people or transport of dangerous goods falls within the specific category. FOCA authorisation is required or, where every condition of an applicable standard scenario is met, a declaration. STS-02 governs certain BVLOS operations below 120 metres over a controlled, sparsely populated ground area using a C6 drone. The applicable guidance is set out in Introduction to the specific category (FOCA) and STS standard scenarios (FOCA).
- Name the UAS operator, remote pilot and mission lead.
- Document the ground area, emergencies, lost link and safe termination.
- Assess separately the right to record neighbours or unknown people.
For a deeper analysis, read Security drones on Swiss property. Connect FOCA rules, flight planning, neighbours and data protection.
Cloud, processors and cybersecurity: accountability cannot be outsourced
A customer remains responsible when entrusting video or alerts to an integrator or cloud provider. Article 9 FADP requires the processor to follow instructions, maintain confidentiality, secure data and refrain from appointing a further processor without authorisation. The contract also covers access, deletion, return and audit.
Storage, support and backup locations need to be known. A transfer abroad requires an adequate country or recognised safeguards, followed by information where required. “Hosted in Europe” remains vague if logs or support access travel elsewhere.
Secure the full chain from robot to operator workstation
Remove default passwords, encrypt communications, segment networks, restrict interfaces, log operations and inventory versions. Leaked footage of a villa or maps of blind areas may facilitate intrusion.
A breach likely to result in a high risk must be reported to the FDPIC as soon as possible, and to affected people where necessary for their protection. A processor informs the controller without delay; contracts and exercises make the escalation workable.
- Plan account revocation, credential rotation and patches.
- Separate machine metadata and images when linking them is unnecessary.
- Test safe stopping, obstacles, signage and manual recovery.
Physical safety and liability
A robot may collide with a person or block an exit. Product and machinery safety, instructions, maintenance, local hazards and employer duties all belong in the project. After damage, product, contract, operation and fault will matter; clarify roles and insurance before commissioning. The applicable guidance is set out in Machinery and product safety (SECO).
Evidence and governance: show what actually happened
Video is not automatically decisive: a court determines the admissibility of privately obtained footage. An AI alert adds a model version, threshold, camera, timestamp and human intervention. The evidence chain preserves the original and distinguishes automated detection from human observation.
After an incident, a procedure defines who searches, exports, checks integrity, records access and hands over the item. Timestamps should be synchronised and the original file retained without editing; a working copy can mask irrelevant third parties. Every transfer records a recipient, date and reason. A preserved extract follows the case retention period while routine material continues to be deleted normally.
The minimum compliance file
The file brings together the processing record where required, fields and masks, necessity, retention, access, signs, processors, countries, security, rights, breach plan and any DPIA. For drones, it includes registration, competence, insurance, category, zones and procedures.
Photograph signs, export settings, test deletion and simulate an access request. Check that operators distinguish an alert, an observation and a conclusion: a software score proves neither identity nor intention. Every new camera, AI function, robot route, cloud service or work arrangement triggers review.
- Retain the purpose, alternatives, field, period and authorised people.
- Produce tests, logs, corrections, training and reviews.
- Measure false alerts and delays, never employees’ hidden performance.
Deploy without legal blind spots: seven decisions
Compliance is decided before the quotation. Start from the risk and expected action, then minimise the data perimeter. Non-imaging sensors, a camera activated by an alert, a robotic patrol while people are absent and human oversight may be more useful than permanent recording.
Test real schedules, night conditions, third parties, robot positions and network loss. Validate signs, contracts, deletion and individual rights. For a drone, verify category, competence, insurance, restrictions, DABS, weather and the recorded area.
The decision checklist
Seven questions reveal the essentials. Any vague answer blocks launch. High risk, biometrics, employees, public space, audio or BVLOS requires specialist validation by a lawyer, data protection adviser, labour inspectorate, canton, municipality or FOCA as appropriate.
- Which event justifies each sensor, and which alternative was compared?
- Who can be identified, and can they avoid the zone?
- Does coverage remain private despite zoom, tracking, a robot or drone?
- What minimum retention is enough, and has deletion been tested?
- Who views, exports, administers and audits access?
- Are employees, audio, biometrics, foreign transfers or high risks involved?
- Which evidence survives the next update?
Compliance that also improves security
Restricting coverage reduces nuisance alerts. Limiting access protects site plans. Short retention prevents unnecessary accumulation. An accountable person handles ambiguity better. The law does not promise zero risk; it requires a system that can be explained, controlled and reviewed.
Frequently asked questions
May I record the pavement in front of my Swiss home?
Generally, no. The FDPIC states that private surveillance should remain within the owner’s property and exclude public space and neighbouring land. A private interest does not usually justify performing a public-security function. Reposition the camera, narrow its angle or apply a mask that cannot be bypassed. A concrete, narrowly limited exception should be legally assessed before installation.
How long may video be retained?
There is no single period for every private system. Images must be deleted once no longer necessary. The FDPIC generally refers to 24 hours for private video surveillance and 24 to 72 hours in the workplace depending on purpose. A sequence linked to an incident may be isolated for longer for the relevant procedure, with a stated reason, restricted access and traceability.
Is a sign enough to make a camera lawful?
No. A sign addresses part of transparency but cannot correct excessive coverage or a disproportionate purpose. It must be visible before entry into the zone and identify the controller or contact point. Lawfulness also depends on necessity, framing, schedules, retention, security, access and the rights of affected people.
May a security robot record sound?
It is generally best avoided and the microphone should be disabled by default. Recording a non-public conversation without every participant’s consent may breach Articles 179bis and 179ter of the Criminal Code as well as the FADP. Clearly indicated, occasional intercom use differs from continuous ambient capture, but its purpose, activation, any recording and access need precise controls.
May a camera record employees to prevent theft?
Surveillance intended to monitor workers’ behaviour is prohibited by Article 26 of Ordinance 3 to the Employment Act. A camera serving another security purpose may be possible where no less intrusive measure is sufficient, employees are captured only exceptionally, and their health and freedom of movement are protected. Concrete suspicion requires case-by-case analysis, ideally with legal advice and the competent authorities.
Is facial recognition prohibited in Switzerland?
There is no binary answer for every use. Biometric templates uniquely identifying a person are sensitive data and require justification and stronger safeguards. The FDPIC considers generalised real-time facial recognition incompatible with privacy protection. For private security, prefer anonymous detection and classification and obtain an assessment before any identification use.
May an automatic drone patrol beyond the pilot’s view?
Not in the open category, which requires direct visual line of sight, or VLOS. BVLOS flight falls within the specific category and needs FOCA authorisation, or a declaration where every condition of an applicable standard scenario is met. A docking station does not change this. Geographical restrictions, competence, insurance, emergency procedures and data protection also apply.
When is a DPIA required for robotic surveillance?
A DPIA is mandatory where planned processing is likely to present a high risk to personality or fundamental rights. Biometrics, multi-camera tracking, extensive systematic surveillance, large volumes of sensitive data or correlation with badges are strong indicators. The assessment describes the system, risks and measures. Where a high residual risk remains, consultation with the FDPIC may be required under Article 23 FADP.
