Doing Business In..._2026

SWITZERLAND Law and Practice Contributed by: Philippe Nordmann, Marion Bähler, Christian Hagen, Samuel Lieberherr and Dario Glauser, Walder Wyss Ltd

a number of secrecy obligations are enforced with criminal sanctions in various industrial sectors and professions, such as the secrecy obligations appli - cable to lawyers, physicians, banking, etc. • Under Swiss competition law, unfair business practices regarding the unlawful procurement, misappropriation or exploitation of information are prohibited. Violation of these rules may lead to civil liability and criminal sanctions. • Corporate law prohibits the bodies and top man - agement of companies from disclosing or other - wise utilising secret information other than accord - ing to the scope of their mandates. • Employment law prohibits an employee from exploiting confidential information acquired in the course of work. • Agency and procurement law forbids an agent from making use of the trade secrets of the principal it has been entrusted with. Furthermore, Switzerland is a party to the Agreement on Trade-Related Aspects of Intellectual Property Rights (TRIPS). Data protection in Switzerland is mainly regulated by the Federal Act on Data Protection (FADP) and its ordi - nances, particularly the Federal Ordinance on Protec - tion Act. However, sector-specific or overarching data protection legislation may provide for a broader scope of application. The new FADP, which entered into force on 1 September 2023, aligned Swiss data protection with the European legislation to a significant extent and has, amongst other things, implemented: • the principle of data protection by design and by default; • the obligation to perform an impact assessment under certain circumstances; and • the obligation to notify the Federal Data Protection and Information Commissioner (FDPIC) or data subjects of data breaches unless an exception applies. 8. Data Protection 8.1 Applicable Regulations

Given that Switzerland is not a member state of the EU, the EU General Data Protection Regulation only applies under certain circumstances – eg, if a Swiss- based company offers goods or services to individu - als in the EU or monitors the behaviour of such indi - viduals. 8.2 Geographical Scope The FADP is applicable to the processing of personal data that has an effect in Switzerland, even if it was collected abroad. Therefore, if personal data con - cerning natural persons in Switzerland is processed abroad, the controller or processor abroad must com - ply with applicable Swiss law. In addition, private con - trollers domiciled or resident abroad must appoint a representative in Switzerland if they process the per - sonal data of persons in Switzerland. The FADP establishes certain principles, which must be observed by controllers as well as – for most prin - ciples – processors. • Lawfulness – personal data must be processed lawfully, meaning that processing must not violate another norm of Swiss law directly or indirectly aimed at protecting the personality. • Good faith – data shall be processed in good faith, meaning that the processing shall be evident to the data subject. • Transparency and purpose limitation – the collec - tion and usage of personal data must be apparent to the data subject, and use shall be limited to the specified purpose. • Proportionality – processing must be proportion - ate to the purpose (data minimisation) and must be “destroyed or anonymised” as soon as it is no longer needed with regard to the purpose of the processing. • Accuracy – reasonable measures are to be taken to ensure that the personal data is up to date, and that it is possible to correct incorrect data. • Privacy by design and security – controllers must set up technical and organisational measures in order to meet the data protection requirements (privacy by design) and, in particular, to ensure a level of data security appropriate to the risks (data security).

1043 CHAMBERS.COM

Powered by