
The Federal Council has confirmed that Switzerland’s long-debated Flugpassagierdatengesetz (Passenger Name Record, PNR) will enter into force on 1 November 2026, with operational data transfers due from 1 February 2027. The law aligns Switzerland with EU and UK practices that harness airline booking data to combat terrorism and serious crime. Under the legislation, airlines serving Swiss airports must transmit passenger reservation data to a new Passenger Information Unit (PIU) housed within the Federal Police (fedpol). The PIU will start with eight staff and expand to 30 full-time equivalents by 2030 as more routes are connected. Eight separate ordinances – including changes to the national sections of the Schengen Information System and the RIPOL police database – have been amended to provide the necessary legal scaffolding. For carriers and global travel programmes the timeline is tight. IT departments will have just over three months to ensure compliant data-feeds, message formats and cyber-security safeguards before the first uploads begin. Corporate travel managers should liaise with preferred airlines to confirm that naming conventions, passport fields and frequent-flyer numbers are handled in line with Swiss privacy rules, which differ in places from EU GDPR. From an immigration-control perspective, the PIU will enable earlier risk-profiling of inbound passengers based on itinerary patterns, payment methods and contact details. While the focus is crime prevention, mobility practitioners expect some knock-on effect at the border: advanced screening typically reduces secondary inspections, speeding flows for low-risk travellers once the system beds in. Companies relocating staff to or through Switzerland should update privacy notices and inform employees that PNR data will now be shared with Swiss authorities. HR teams may also need to adjust record-retention policies to reflect the five-year storage limit embedded in the new regulation.
Source: Federal Council press release