SWITZERLAND Law and Practice Contributed by: David Vasella, Jürg Schneider, Hugh Reeves and Yannick Caballero Cuevas, Walder Wyss Ltd
GDPR, but the trigger for notifying a personal data breach to the Swiss data protection authority, the Fed - eral Data Protection and Information Commissioner (FDPIC), is “high risk”, whereas, under the GDPR, any relevant risk requires notification. On 6 February 2025, the FDPIC published non-binding guidance on breach notification obligations under the FADP, which was subsequently updated on 23 April 2025. Another key difference is the level of activity by the relevant authorities: while many supervisory authorities within the European Economic Area (EEA) are more active, providing guidance and/or enforcing the GDPR, the FDPIC is generally reluctant to take a decisive stance and rarely provides guidance for private actors. How - ever, the FDPIC has initiated several investigations under the revised FADP. The FADP and the DPO provide for a general require - ment to ensure an appropriate level of data security in relation to personally identifiable information. The revised FADP calls for state-of-the-art data security measures, without specifying specific technical stand - ards. However, a specific security requirement is the obligation to keep logs to ensure that data operations are logged by federal authorities and private actors that process sensitive data on a large scale or carry out “high-risk profiling”, a form of profiling that leads to personality profiles. These logs must be relatively granular and must be kept for at least one year, sepa - rately from the productive environment. In addition, the revised legislation imposes on controllers and processors, under certain conditions, a duty to notify data security breaches to the FDPIC, and potentially to data subjects. Additional compliance and docu - mentation measures, such as data protection impact assessments and records of processing activities, as well as an obligation to maintain processing regula - tions, have also been introduced. The Information Security Act (ISA) of 18 December 2020, which entered into force on 1 January 2024, governs information security practices within the federal government and its administrative bodies. Under the ISA, several ordinances further specify and implement information security requirements and also repeal (inter alia) the Ordinance on the Protec - tion against Cyber Risks in the Federal Administra - tion (CyRV). Importantly, a significant feature of the
ISA is the introduction of a reporting obligation for cyber-attacks for public authorities such as universi - ties; federal, cantonal and municipal agencies; inter- cantonal, cantonal and intercommunal organisations; and providers of critical infrastructures, for example in the energy, finance, healthcare, insurance, transport, communication and IT sectors. In-scope organisa - tions must report cyber-attacks to the National Cyber Security Centre (NCSC) within 24 hours, where the rel - evant thresholds and definitions are met. This report - ing obligation entered into force on 1 April 2025. Apart from the ISA, cybersecurity remains mostly reg - ulated by a patchwork of various acts and regulatory guidance, which deal explicitly or implicitly with cyber - security in the private sector. These laws include: • the Budapest Convention on Cybercrime (CCC), which entered into force in Switzerland on 1 Janu - ary 2012 and imposes a harmonisation of Switzer - land’s criminal legislation as well as speedy inter - national co-operation mechanisms; • the FADP; • the Federal Telecommunications Act (TCA) of 30 April 1997, including its ordinances, which – as of 1 January 2023 – contain specific information secu - rity and network threat resilience requirements; and • the Federal Act on Financial Market Infrastructures and Market Conduct in Securities and Derivatives Trading (FinMia) of 19 June 2015 – the banking and financial markets legislation also led the financial markets regulator, the Swiss Financial Markets Supervisory Authority (FINMA), to issue various circulars and regulatory notices. However, the Swiss government has given cyberse - curity increasing attention in the past few years, and the absence of an overarching ad hoc law on cyber - security may appear misleading given the importance and national relevance of this topic. Nonetheless, this conclusion is unlikely to lead the Swiss legislator (Par - liament) to issue any additional topical legislation on cybersecurity in the near future. On the contrary, the federal government has been following the National Strategy for the Protection of Switzerland against Cyber Risks (NCS).
377 CHAMBERS.COM
Powered by FlippingBook