SWITZERLAND Trends and Developments Contributed by: David Vasella, Jürg Schneider, Hugh Reeves and Yannick Caballero Cuevas, Walder Wyss Ltd
in recent months and years by adapting its cyberse - curity framework on a number of levels. The FADP and Data Protection Ordinance The revised Federal Data Protection Act (FADP), which entered into force on 1 September 2023, introduced improved enforcement powers for the Swiss data protection authority, the Federal Data Protection and Information Commissioner (FDPIC). The FADP also introduced new requirements around data breach reporting, requiring controllers to inform the FDPIC as soon as possible about data security breaches that lead to a high risk and, where necessary, to commu - nicate the breach to the affected data subjects. The reporting obligation is similar to that under the GDPR, but the threshold is higher (high risk under the FADP, and any relevant risk under the GDPR). In addition, the FADP and the Federal Data Protection Ordinance (DPO) provide for a general requirement to ensure an appropriate level of data security in relation to personal data. The FADP calls for state-of-the-art data security measures, without specifying specific technical standards. This is a deliberate approach from the legislator, who chose to maintain a future-proof, technologically neutral philosophy. However, a specif - ic security requirement is the obligation to ensure that data operations are logged by federal authorities, and by private actors that process sensitive personal data on a large scale or carry out “high-risk profiling”, a form of profiling that leads to personality profiles. The FDPIC has provided guidance for implementing these logging obligations. As Switzerland is not a member of the European Economic Area (EEA), incident noti - fications in the EEA under the GDPR do not exempt companies from notification obligations towards the FDPIC under the FADP, if applicable, and vice versa. The FADP provides that individuals (not legal entities, in contrast to the GDPR) who breached data secu - rity provisions and thereby failed to comply with the minimum requirements in that respect, will face crimi - nal fines of up to CHF250,000. It remains unclear at this time if a general failure to implement a sufficiently robust level of data security can lead to a fine, but giv - en the potential risks for business managers who may have a personal exposure, these fines are expected to
work as an incentive for businesses to ensure state- of-the-art cybersecurity practices. The Information Security Act While the FADP applies to personal data only and, as noted, is fairly high-level, the Swiss Federal Council enacted the Information Security Act (ISA) and four implementing ordinances on 8 November 2023, effec - tive as of 1 January 2024. The ISA is a response to the increasing number of cyber-attacks on public authori - ties and private individuals, and places high demands on information security. For example, it requires authorities to maintain an information security man - agement system and to ensure that the third parties and providers they work with take necessary security measures. The ISA has also centralised cybersecurity activities under the NCSC; as discussed hereunder. A significant feature of the ISA is the introduction of a reporting obligation for cyber-attacks for public authorities such as universities and federal, cantonal and municipal agencies; inter-cantonal, cantonal and intercommunal organisations; and providers of critical infrastructures, for example, in the energy, finance, healthcare, insurance, transport and communication and IT sectors. In-scope organisations must report cyber-attacks to the NCSC within 24 hours, where the relevant thresholds and definitions are met. This reporting obligation entered into force on 1 April 2025, and is in addition to other incident notifications, such as the obligation to report personal data security breaches to the FDPIC. Updated government organisation at a federal level The ISA and ensuing legislation have also reworked the government’s security organisation. The NCSC, which is a federal office within the DDPS, now serves as the centre of competence for cybersecurity, act - ing as the primary point of contact for the economy, administration, educational institutions and the public on cyber-related issues. Its tasks include raising pub - lic awareness, receiving reports on cyber-incidents and supporting operators of critical infrastructures in managing these incidents. Protection of the federal administration against cyber-attacks is now a key task of a new specialist unit within the new State Secretar - iat for Security Policy (SEPOS), also within the DDPS.
387 CHAMBERS.COM
Powered by FlippingBook