IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

The Indicium report implements the position-based, tiered screening depth that Art. 328b OR and the revFADP require — with dated sources and human final review.

Background Checks in Switzerland: Art. 328b OR and the revFADP

Background checks in Switzerland: what Art. 328b OR and the revFADP permit, which limits apply and what a lawful, tiered screening depth looks like.

Background checks are permitted in Switzerland — but regulated differently than in the EU. The framework is set by Art. 328b OR (Swiss Code of Obligations): the employer may only process data about applicants and employees to the extent that it concerns their suitability for the employment relationship or is necessary for the performance of the employment contract. The revised Data Protection Act (revFADP, in force since 1 September 2023) additionally tightens transparency and information obligations. The core standard for every check is therefore proportionality: the depth of screening must fit the specific position.

Art. 328b OR: suitability relevance as the employment-law limit

Art. 328b OR is the central provision for any screening in the Swiss employment context — and it is remarkably clear: data processing is permitted only in two directions, suitability for the specific employment relationship and performance of the contract. From this follows, directly, the position-based approach: what would be disproportionate for a cashier may be warranted for a member of a bank’s executive board. A uniform standard check “for everyone” is just as incompatible with this system as an indiscriminate deep-dive without any connection to the role. Screening categories such as register extracts, creditworthiness or media research must be justifiable for each position — and that justification should be documented.

revFADP: transparency and information as the second pillar

The revised Data Protection Act has applied since 1 September 2023. For background checks, three consequences are particularly relevant in practice:

  • Duty to inform: The person being screened must be informed about the collection of their personal data — even where the data is not obtained from the person directly, for instance from registers or public sources.
  • Processing principles: Proportionality, purpose limitation and accuracy apply to every screening category; outdated or unverified findings must not feed into a decision unchecked.
  • Tightened sanctions: The revFADP provides for fines that — unlike under the GDPR — can be directed at the responsible natural persons. Data protection violations in screening are therefore also a personal risk for those acting.

A covert check “behind the candidate’s back” is not an option under this regime. The lawful route runs through transparency: the candidate knows that a check is taking place and in which categories.

A perennial issue in Swiss practice is reference inquiries with previous employers. They are permissible only if the applicant has named the reference or consented to the inquiry — the informal call to the former supervisor without the candidate’s knowledge violates their personality rights. In substance, too, the information given remains bound by the same standard as the employment reference letter: truthful, complete and benevolent. For structured checks, this means: references belong in the transparent, consent-based part of the process.

Special case of regulated institutions: the FINMA fit-and-proper requirement

For banks and other supervised entities, a supervisory dimension is added: the fit-and-proper requirement (Gewähr) demands that the persons entrusted with administration and management provide assurance of irreproachable business conduct (Art. 3 para. 2 lit. c BankG, the Swiss Banking Act). Anyone nominating a key person without having verified their integrity in advance risks queries and delays in the licensing procedure. Here, in-depth screening is not merely permissible but effectively expected — details on the sector-specific requirements can be found in the industry overviews. For security-sensitive roles with a federal connection, the state personnel security screening applies in addition — see the article PSP under the ISG and PSPV.

The lawful Swiss background check is tiered by position. Specifically: first, classify your roles by risk — client assets, system access, management responsibility, fit-and-proper relevance. Second, define for each tier the screening categories that can be justified under Art. 328b OR, and document that justification. Third, inform candidates transparently and obtain consent where required — particularly for references. This is exactly the model of risk-based report tiers that Indicium implements: audit-proof reports with dated sources and human final review, from €79 per report. What the Swiss counterpart to the German criminal record certificate does and does not deliver is shown in the article Police clearance certificate vs. background check — the structural gaps of a register extract are the same on both sides of the border. For an assessment of your situation: book a demo.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report