The 60-second summary
On 1 October 2026, the FDPIC announced a decision dated 29 September ordering BLT Baselland Transport AG to cease personal-data processing through bodycams and delete the data obtained and further processed. The regulator concluded that existing federal transport legislation did not provide the required authorisation for recording passengers and crew. This is a case-specific enforcement decision under the Swiss FADP; the announcement does not establish a universal ban on bodycams.
Timeline that matters
26 February 2026
Investigation opened
The FDPIC investigated BLT bodycam use.
29 September 2026
Decision dated
The regulator issued cessation and deletion orders.
1 October 2026
Announcement published
The FDPIC explained its conclusion on legislative authorisation.
Not specified in the announcement
Execution and appeal details
Check the operative decision and obtain specialist advice.
What changed
The investigation resulted in cessation and deletion orders. The FDPIC acknowledged safety interests but concluded that they did not resolve the missing legislative authorisation. Proposed regulatory work remains separate from current permission to process. The announcement gives no general implementation deadline and does not describe appeal status.
Who should pay attention?
Legal and privacy
Review the precise authority for each recording activity and entity role.
Security and operations
Assess whether recording is permitted before evaluating operating safeguards.
Procurement and vendors
Map recordings, copies, exports and downstream processing.
Records and assurance
Prepare verified cessation and deletion workflows.
What the guidance clarifies
- Case-specific scope
- The order concerns BLT and the statutory authorisation for its transport surveillance.
- Separate camera types
- Permission for an established camera system should not be assumed to cover new wearable recording.
- Status boundaries
- The announcement reports an order; appeal status and a precise execution timetable are not stated.
- Future regulation
- Proposed authorisation must not be treated as current permission.
Global relevance — assess authority before deployment
Why this matters for global organisations.
A safety objective does not by itself establish permission to record. Teams should assess each new capture capability, then connect the approved scope to device settings, vendor processing, retention and verifiable deletion.
- Assess audio and wearable capture independently from existing surveillance.
- Include derived transcripts, analytics and exported copies in lifecycle controls.
- Keep future regulatory proposals separate from launch approvals.
- Build cessation and deletion capabilities into procurement and operating procedures.
15 actions to start now
- Inventory wearable, fixed, mobile and audio recording separately.
- Identify the operating entity, public-task context and applicable statutory framework.
- Obtain a documented legal-authority assessment before launch or expansion.
- Define each purpose and reject unsupported secondary uses.
- Map recording, upload, storage, export, transcription and analytics flows.
- Assess necessity, alternatives, affected people and incidental capture.
- Complete an appropriate impact assessment before deployment.
- Set activation rules, audio controls and access permissions.
- Review notices against actual recording behaviour.
- Define retention and deletion across devices, cloud services, backups and exports.
- Control vendor access, subprocessors and downstream AI analysis.
- Prepare a method to stop capture and disable onward processing.
- Test deletion and obtain evidence from every relevant provider.
- Assign owners for legal changes, exceptions, complaints and incident escalation.
- Monitor operative orders, appeal developments and enacted regulatory changes.
Suggested next steps
- Recheck for the operative decision, appeal information and enacted authorisation changes.
Evidence worth retaining
- Recording-system and data-flow inventory.
- Entity-role and statutory-authority assessment.
- Purpose, necessity and alternatives analysis.
- Impact assessment and approved mitigation register.
- Device configuration and activation test results.
- Notices, access logs and staff training records.
- Vendor contracts and subprocessor inventory.
- Retention settings, deletion tests and destruction confirmations.
- Cessation plan, execution logs and exception approvals.
- Legal-source register and review decisions.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Which provision authorises this entity to conduct this recording?
- Does the authority cover audio, wearable capture and all affected people?
- Would a less intrusive measure meet the operational purpose?
- Where are copies or derived transcripts held?
- Can capture and onward processing be stopped promptly?
- How will deletion be verified across providers and exports?
- Which preservation obligations require specialist analysis?
- Do proposed rules actually apply yet?
- What does the operative decision say about execution and appeal?
- Who signs off changes to scope or secondary use?
Official sources
- FDPIC — bodycam cessation and deletion announcement, 1 October 2026
- FDPIC — official 2026 communications register
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.