Cameras, radar sensors and AI can detect falls and alert care staff. However, when technical assistance is used in bedrooms, patient rooms or other private areas, there is a great deal at stake. The FDPIC and privatim set out the limits imposed by data protection law in a new guide. For hospitals and care homes, this means above all that surveillance must not become standard practice – and data protection must be taken into account right from the outset, when the technology is procured.
New guidelines on digital surveillance in hospitals and care homes
The Federal Data Protection and Information Commissioner (FDPIC) and privatim, the Conference of Swiss Data Protection Commissioners, published a joint guidance note on the monitoring of residents on 16 September 2026. This follows the increasing use of digital assistance and monitoring systems in hospitals, care homes and similar establishments. In addition to traditional cameras, infrared sensors, radar and, in some cases, artificial intelligence are increasingly being used.
The technology offers practical benefits. For example, systems can detect whether a person has fallen and automatically alert care staff. From a data protection perspective, however, there is a significant difference between high-resolution images being continuously transmitted to a monitor and a local system merely detecting a fall and subsequently transmitting a warning signal or an abstract pictogram. It is precisely this distinction that the new guidance addresses.
In our view, the guidance is therefore on the right track. The crucial question is not whether digital surveillance in care homes is, in principle, permissible or impermissible, but rather how much surveillance is actually necessary to achieve a legitimate care objective. Particularly in view of the increasing use of smart assistance systems, this technology-neutral approach is to be welcomed.
The bedroom is not an ordinary surveillance area
The FDPIC and privatim classify the surveillance of people in care as a particularly intensive form of data processing. People in need of care often find themselves in a vulnerable situation. In the case of longer-term stays, the monitored room may, in effect, constitute the private home of the person concerned. Surveillance therefore does not merely encroach on any living area, but may potentially intrude upon the private or even intimate sphere.
This has practical consequences: what is technically possible or organisationally convenient is by no means permissible under data protection law. In particular, according to the guidelines, a purely logistical or organisational interest is, in principle, insufficient. Surveillance should, first and foremost, serve the welfare of the person receiving care. Using a system solely for the purpose of, for example, determining whether a bed has been made or a meal has been finished does not meet these requirements. Furthermore, surveillance must not be introduced across the board for all residents. The specific situation of the individual concerned must be taken into account.
Whilst this individualised approach is consistent with data protection law, it is likely to pose considerable challenges for care homes in practice. Standardised technical solutions are easier to operate than a system whose use must be assessed separately for each resident and, where necessary, configured differently. It is precisely here that a fundamental tension arises: the more a care home standardises its monitoring measures, the more efficient its operation becomes – but at the same time, the greater the risk that the specific needs and personal rights of the individual will be overlooked.
Public or private? The applicable law must first be clarified
When making a legal assessment, a distinction must first be drawn between who operates the institution and the framework within which it operates.
Public institutions are generally subject to the relevant cantonal data protection law and the principle of legality. A sufficient legal basis is therefore required for data processing. According to the guidelines, for example, monitoring carried out as part of a treatment plan may, under certain circumstances, be based on the statutory duty of care. However, the consent of the data subject cannot replace a required legal basis.
Private institutions are subject to the Federal Act on Data Protection (FADP). Of particular importance here are the processing principles and the requirements regarding protection against unlawful infringements of personal rights. It is also important to note a key distinction made in the guidelines: the legal form alone is not the deciding factor. Even a clinic organised under private law may be treated as a public institution for certain activities, provided it fulfils a corresponding cantonal mandate.
For operators, this means that the question of which data protection law applies must be addressed at the outset of any surveillance project, rather than at the end of the technical procurement process. From a practical point of view, however, it is rather unsatisfactory that comparable surveillance systems may be subject to different sets of data protection regulations depending on their governing body and cantonal service mandate. For manufacturers, operators of multiple facilities and corporate groups operating throughout Switzerland, this makes it difficult to develop uniform compliance standards. This makes it all the more important not to determine the legal classification schematically on the basis of legal form.
Consent is not a free pass under data protection law
The comments on consent are particularly relevant in practice. Whilst the FDPIC and privatim consider it desirable to obtain consent where possible, they warn against interpreting it as a universal legal basis for surveillance measures.
Particularly in a care setting, the question arises as to how freely consent is actually given. Residents may feel under pressure due to their dependence on the care home. Consequently, the absence of an objection does not automatically mean that the surveillance is lawful. Additional difficulties arise in the case of persons lacking capacity.
For private care homes, this brings the question of whether there is an overriding interest to the fore. In the view of the FDPIC and privatim, the primary aim of a surveillance system should be to improve the standard of care.
This cautious approach to consent is convincing. Particularly in a care relationship, there is a risk that formally declared consent suggests greater legal certainty than it actually provides. In our view, therefore, a signature should not be allowed to lead to a shortening of the prior assessment of purpose, necessity and proportionality. The decisive factor remains whether the specific surveillance measure is objectively justified and designed to be as non-intrusive as possible.
Data protection through technology: an alarm may be better than a video stream
The new guidance also serves as a plea for ‘privacy by design’.
For fall detection, for example, care staff do not necessarily need to view a live feed from the room. A system can process image or sensor data locally and only transmit a signal or an abstract pictogram when a specific event is actually detected. As long as nothing happens, no relevant information leaves the monitored area.
The FDPIC and privatim therefore generally prefer indirect and situational systems to permanent real-time surveillance. Functions such as audio recording, zoom or particularly high image resolution should be deactivated if they are not necessary for the intended purpose. According to the guidance note, the long-term storage of raw or processed data is also generally not justified in a typical care setting if it extends beyond the technically necessary processing period and there is no specific legitimate purpose.
This means that the choice of product itself becomes a decision under data protection law. In our view, this is one of the most important messages of the guidance. With such systems, data protection can only be ‘remedied’ to a limited extent retrospectively through regulations or declarations of consent. If, from a technical perspective, a product only provides for a permanent video stream, unnecessarily high resolutions or permanent cloud storage, the scope for action under data protection law is already considerably restricted at the procurement stage. The most data-protection-friendly decision is therefore often not made during subsequent use, but at the very outset when choosing the system.
AI and the cloud: convenience creates additional risks
The guidance devotes particular attention to AI-based systems. AI can be used in a data-protection-friendly manner if, for example, it analyses a camera image locally and merely transmits an alarm. At the same time, new risks arise.
In the view of the FDPIC and privatim, AI processing should take place locally wherever possible. Cloud solutions are viewed critically because they can give rise to additional access and security risks. Furthermore, the subsequent use of the collected data to train AI models is not automatically covered by the original purpose for which the data was processed. Among other things, the guidance highlights risks relating to data transfer, storage and re-identification, and questions the necessity of such training for the provision of care in practice.
Anyone purchasing an AI-based care product should therefore clarify exactly where the raw data is processed, whether providers can access it, whether data is stored, and whether it may be used to train further models.
On a positive note, the guidance does not view AI as an additional data protection risk across the board. When used correctly, automated analysis in particular can help to minimise the amount of personal information passed on to people. A system that detects a fall locally and merely triggers an alarm can protect privacy considerably better than continuous visual surveillance. AI and data protection are therefore not necessarily at odds with one another, even in this sensitive area – the specific technical architecture is what matters.
Plan a data protection impact assessment at an early stage
In the case of particularly high-risk processing operations, a data protection impact assessment (DPIA) may also be required. For private data controllers, this obligation arises from Article 22 of the Data Protection Act (DSG) if processing may entail a high risk to the personality or fundamental rights of the data subjects. The FDPIC cites, amongst other things, the extensive processing of personal data requiring special protection as a possible risk indicator.
A DPIA should document the purpose and procedure of the data processing, the locations where processing takes place, the risks and the intended protective measures. If, despite the measures put in place, a high residual risk remains in relation to processing subject to the DSG, Article 23 of the DSG generally provides for prior consultation with the EDÖB; for public bodies, the relevant obligations are governed by the respective cantonal law.
A DPIA should not, however, be reduced to a mere documentation exercise. Its practical value lies precisely in the fact that it compels data controllers to question at an early stage whether the intended technology is actually necessary and whether there are alternatives that are more data protection-friendly. If it is only drawn up shortly before go-live, once the product, provider and technical architecture have already been finalised, it can hardly fulfil this function.
What organisations should do in practice
For hospitals, care homes and other care facilities, a clear project workflow can be derived from the new guidance:
- Define the need and specific purpose: What specific risk is the monitoring intended to reduce?
- Clarify the applicable law: Is the organisation acting in a private capacity or within the framework of a public contract?
- Examine less intrusive alternatives: Would a simple fall detector, for example, be sufficient?
- Implement data minimisation technically: Event-based alarms and pictograms are preferable to continuous video transmission, provided they fulfil the purpose equally well.
- Assess manufacturers and service providers: Access rights, raw data, storage locations, cloud components, updates and any potential use of the data for AI training should all be included in the assessment.
- Prepare a data protection impact assessment (DPIA) and documentation: Alternatives, risks, configurations and decisions should be documented in a transparent manner right from the procurement stage.
- Establish regulations and training programmes: Who is authorised to activate the system and when? Who is granted access? When is it deactivated? How are data subjects, visitors and staff informed?
- Re-evaluate the system regularly: A one-off assessment prior to purchase is not sufficient. The FDPIC and privatim require ongoing monitoring of data protection compliance.
Conclusion: Data protection is determined right from the product procurement stage
The new guidance makes it clear that digital assistance in care is not, in itself, at odds with data protection. On the contrary, automated and event-based systems can even be designed to be more data-protection-friendly than constant human or camera-based monitoring. In our view, the guidance should therefore be understood less as a warning against new technology and more as a call for its careful design. This is to be welcomed: a blanket ban on digital assistance systems would do justice neither to the possibilities of modern care nor to the interests of those receiving care. At the same time, the guidelines rightly set strict limits where surveillance is to be used for reasons of convenience, efficiency or mere organisational control.
It is crucial, however, that care providers do not start from the available product, but from the specific purpose of care. Only then should a decision be made as to which data is actually required for this purpose.
For data controllers, this means that the data protection assessment must take place much earlier in the process: the definition of purpose, legal basis, choice of technology, data minimisation, data protection impact assessment (DPIA), supplier assessment and technical configuration must already form part of the procurement project. Particularly in the case of AI and cloud solutions, it is not sufficient to rely on the manufacturer’s product claims. The FDPIC and privatim expressly require that technical information be obtained and risks be documented in a transparent manner.
Anyone planning to introduce new monitoring technology in the care sector should therefore not view data protection as the final compliance hurdle before going live – but rather as a requirement for the system design itself. This is precisely where an opportunity lies: those who integrate data protection into the procurement and design of such systems from the outset do not have to pit innovation against the protection of personal data.