Information Technology 2026

SWITZERLAND Law and Practice Contributed by: Dirk Spacek, Wenger Plattner

sector-specific concentration rather than broad-based growth or decline. 6.5 IP and AI/Computer-Created Works Under Swiss law, AI or computer-generated works are not explicitly regulated by a dedicated provision. Pro - tection under the CopA requires a human intellectual creation with an individual character. Works generated autonomously by AI without sufficient human crea - tive input in the prompts are generally considered not protected by copyright. Purely machine-generated outputs therefore typically fall into the public domain from a copyright perspective. For other IP rights, such as patents or trade secrets, AI-assisted inventions may be protectable if they meet the relevant statutory criteria, but the inventor must be a human. In current practice, protection of such works is often achieved through contractual arrange - ments and trade secret protection rather than relying on copyright for AI-generated content. 7. Data Protection Considerations 7.1 Relevant Laws and Regulations for Data Protection The main Swiss data protection law is the revised FADP complemented by the Federal Data Protection Ordinance (FDPO, SR 235.11). It sets core principles for lawful, proportionate and secure processing of personal data, supervised by the FDPIC. Cybersecurity and information security obligations are mainly indirect, ie, arising from the FADP’s security requirements and sector-specific rules (eg, telecoms, finance and critical infrastructure). The new Swiss Federal Information Security Act (FISA) applies to federal authorities and critical infrastructures. Additional protections are found in the SCC, which sanctions unlawful access to data and cybercrime, and guidance from the National Cyber Security Centre (NCSC). 7.2 Data Transfer Restrictions Under the FADP, transfers of personal data to third countries are restricted if the destination does not

ensure an adequate level of data protection. The Swiss Federal Counsel maintains a list of adequate jurisdictions to which transfers are generally permit - ted. If no adequacy decision exists, transfers can still be legitimised through safeguards such as data transfer agreements under the EU-standard contractual claus - es (SCCs) (as has been also approved by the FDPIC with a Swiss finish), binding corporate rules (for intra- group transfers), or other contractual or organisational measures ensuring equivalent protection. In specific cases, explicit consent, necessity for contract perfor - mance, legal claims, or overriding public interest may serve as a justification for transfers in countries with no adequacy decision. 7.3 Information Security and Cybersecurity Standards Swiss law does not impose mandatory use of specific security standards such as ISO 27001, NIS2, or CSA CCM. Instead, the FADP stipulates that controllers and processors must implement “appropriate tech - nical and organisational measures” to ensure data security, based on a risk-oriented and state-of-the- art approach. ISO 27001 is widely used in practice as evidence of compliance, but it is not legally required. Sector-specific rules may impose stricter obligations, particularly in banking, telecoms, healthcare, or critical infrastructure, where regulators may expect alignment with recognised standards. NIS2 does not apply in Switzerland directly, though Swiss companies operat - ing in the EU may need to comply extraterritorially. The newly enacted Swiss FISA operates as the equivalent of NIS2 in the EU. It stipulates data security require - ments for federal governmental entities and critical infrastructures. Overall, Switzerland follows a principles-based approach: security measures must be appropriate to the risk, but organisations have flexibility in choosing the applicable framework to demonstrate compliance. 7.4 Information Notification Requirements Under the FADP, security incidents involving personal data must be notified if they are likely to result in a high risk to individuals’ rights or privacy.

84 CHAMBERS.COM

Powered by