top of page

Bern’s Modernised Data Protection Act Centralises Oversight of More Than 1,000 Municipal Bodies

Sep 3
6 min read

The revised cantonal framework takes effect on 1 September 2026 and gives Bern’s central data protection authority direct responsibility for most municipal and municipal-law bodies.


Bern’s Modernised Data Protection Act Centralises Oversight of More Than 1,000 Municipal Bodies

On 1 September 2026, the Canton of Bern’s revised Data Protection Act, known by its German abbreviation KDSG, enters into force. The reform changes more than the wording of local privacy rules. It reallocates supervisory responsibility across the canton, bringing more than 1,000 municipalities and bodies governed by municipal law under the direct oversight of the cantonal data protection authority.1 2

 

The four largest municipal authorities—Bern, Biel/Bienne, Köniz and Thun—are the principal exception. They retain their own data protection offices. Other large public-law bodies may also keep a separate supervisory function where they exceed the statutory threshold of 25,000 affected residents, members or associated persons.3

 

The policy choice is clear: most municipalities will no longer need to maintain or arrange their own independent data protection supervision. Instead, they will deal with one cantonal authority that can consolidate specialist knowledge, provide standardised guidance and apply oversight across local government.

 

Why Bern is changing the system

Bern’s reform responds to two connected pressures. First, municipal administrations differ substantially in size, staffing and access to specialist legal and technical expertise. A small municipality may process sensitive information about residents, social services, schools, taxes, public safety or health without having a permanent privacy professional on its staff.

 

Second, public-sector data processing has become technically more demanding. Cloud platforms, outsourced information technology, connected devices and information-security risks require expertise that is difficult to reproduce in every municipality. The cantonal authority has already received questions from municipal administrations, according to reporting on the parliamentary process. The reform therefore treats centralisation as a way to reduce duplicated legal analysis and make specialised advice more available.4

 

The change also reflects a shift in the expected role of a data protection authority. The revised terminology places emphasis on authorities rather than only supervisory offices. In practice, the cantonal body is expected not merely to investigate and sanction, but also to advise, guide and train public authorities.4

 

Who comes under the KDSG?

The cantonal definition of a public authority is broad. It covers the canton’s organs and administrative units, municipal administrations and councils, municipal parliaments, commissions with decision-making powers, schools, hospitals and the University of Bern where they perform public functions. It can also cover private organisations when they carry out a public task delegated by the canton or a municipality.3

 

This scope matters because municipal data protection is not limited to town halls. A municipality may rely on external providers for software, hosting, social care, education, waste management or other public services. The legal question is not simply who owns the organisation. It is also why the personal data is being processed and under which public mandate.

 

Category

Supervisory position from 1 September 2026

Most Bernese municipalities and municipal-law bodies

Directly supervised by the cantonal data protection authority

Bern, Biel/Bienne, Köniz and Thun

Retain their own data protection offices

Certain large municipal, church or intermunicipal bodies above 25,000 affected persons

May be required to maintain their own supervisory function under the revised framework

Private organisations performing public tasks

The KDSG may apply to the public task; private activity generally remains under the federal Data Protection Act

The threshold is based on the number of people affected by the public body, not simply on its political importance. The official guidance identifies large church bodies and intermunicipal organisations, such as wastewater associations, as examples of entities that may fall within the exception.3

 

New duties for public authorities

The revised law introduces expanded information and reporting duties for authorities. It also defines the rights of affected individuals more clearly.1 These changes create practical work for municipal administrations even where supervisory responsibility has moved to the canton.

 

A municipality will still need to know what personal data it processes, why it processes it, how long it retains it and which service providers can access it. It must communicate relevant information to individuals, manage incidents and assess whether a proposed processing activity creates particular risks. Central supervision does not transfer those operational responsibilities to the cantonal authority.

 

The revised KDSG is accompanied by a new cantonal Data Protection Ordinance. The ordinance provides additional rules, including provisions on the processing of personal data by commissioned third parties and disclosures of personal data abroad.1 Municipalities and their suppliers will therefore need to review contracts, data flows and technical safeguards rather than treating the start date as a purely administrative change.

 

The boundary between cantonal and federal law

Switzerland’s data protection system has more than one level. Private companies are generally governed by the federal Data Protection Act and supervised by the Federal Data Protection and Information Commissioner. A private organisation can, however, be subject to the Bernese KDSG when it processes data while performing a cantonal or municipal public task.3

 

The official example of a listed hospital illustrates the distinction. Employee data processed in the hospital’s private business may fall under federal law. Patient data processed within a public basic-care mandate may fall under the KDSG and the supervision of Bern’s cantonal authority. Services outside that public mandate can return to the federal framework.3

 

This means that one organisation may work under two legal regimes. The purpose and context of the processing determine the applicable rules. Where both public and private functions are involved, the cantonal authority and the federal commissioner may share or coordinate supervision.

 

Benefits and implementation risks

Centralisation can improve consistency. Municipalities should receive a more uniform interpretation of the law, while residents should find it easier to identify the responsible supervisory authority. Shared expertise may also improve the quality of reviews involving cloud services, artificial intelligence, video surveillance and information security.

 

The reform creates capacity requirements for the canton. The cantonal authority expects its workload to increase and four additional full-time positions were included in the 2026 budget, according to Inside IT’s account of the parliamentary process.4 Those resources will be important if centralisation is to produce faster advice rather than a larger queue of unanswered requests.

 

Municipalities also face a transition challenge. They must identify which responsibilities have moved to the canton, update internal contacts and ensure that staff understand the difference between seeking advice and reporting a legally significant incident. Larger municipalities that retain their own offices will need to coordinate with the cantonal authority where services, data systems or intermunicipal arrangements cross institutional boundaries.

 

The first test will be practical rather than symbolic: whether a small municipality can obtain timely, technically credible guidance before deploying a new system, sharing data with a provider or responding to a security incident. A central authority can offer scale, but it must remain accessible to administrations with very different levels of capacity.

 

What residents should expect

For residents, the reform should make the supervisory route more predictable in most cases. Questions or complaints concerning data processed by a typical Bernese municipality will generally be directed to the cantonal data protection authority. Residents of Bern, Biel/Bienne, Köniz and Thun may instead encounter the respective municipal data protection office.

 

The reform does not remove the underlying rights of individuals. It reorganises who supervises the public bodies that process personal data. Individuals should still expect public authorities to explain relevant processing, respect applicable access and correction rights, protect information against unauthorised use and respond appropriately when a data incident occurs.

 

A governance reform with national relevance

Bern’s model is a significant example of how a decentralised public administration can reorganise privacy supervision without abolishing local accountability. The canton is not making municipalities irrelevant. It is separating daily responsibility for lawful processing from the institutional task of independent supervision.

 

If implementation is properly resourced, the result could be a clearer division of labour: municipalities remain responsible for compliant services, while a stronger central authority provides consistent oversight and technical support. If capacity is insufficient, centralisation could instead concentrate unresolved cases in one office. The outcome will depend on staffing, guidance, cooperation with municipal providers and the authority’s ability to explain the new system in practical terms.

 

The 1 September 2026 start date therefore marks the beginning of an operating model, not the end of the reform process. Its success will be measured by the quality of protection delivered to residents across both large cities and small communities.

 

References

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page