SWITZERLAND Law and Practice Contributed by: Dirk Spacek, Wenger Plattner
• This covers personal data breaches such as unau - thorised access, loss or disclosure of personal data. • Notifications must be made to the FDPIC; sec - tor regulators may also need to be informed in regulated industries (eg, FINMA must be notified of cyberbreaches occurring in regulated financial institutions). • Notification must be made without undue delay; no fixed deadline is specified, but “as soon as possi - ble” usually implies as soon as tangible and reliable forensic analysis is at hand. In Swiss practice, notification periods between five and ten working days can be seen, depending on the severity of the case. Contractually, notification duties are often performed by the supplier (processor), but legal responsibility generally remains with the customer (controller). 7.5 Supply Chain Requirements 7.5.1 Risk Assessments and Due Diligence on Suppliers and Extended Supply Chains There is no general Swiss statutory obligation requir - ing formal supplier or extended supply chain risk assessments across all sectors. However, under the FADP, controllers and processors must implement appropriate technical and organisational measures, which in practice requires risk-based due diligence when engaging IT suppliers and sub-processors. Overall, while not expressly mandated in detail, sup - plier due diligence is effectively required as part of compliance with Swiss data protection and sectoral risk governance standards. 7.5.2 Data Protection or Information/Cybersecurity Terms in Supply Agreements Under Swiss law, there is a mandatory requirement to include data protection terms when a supplier pro - cesses personal data on behalf of a customer and sub-processors are also involved. Under the FADP, the relationship must then be governed in a data process - ing agreement (DPA) or equivalent contractual provi - sions. Such terms should usually regulate: • subject matter, duration, nature and purpose of processing;
• types of personal data and categories of data subjects; • obligations and rights of the controller; • processor obligations to process data only on documented instructions; • confidentiality; • technical and organisational security measures; • use of sub-processors; and • assistance with data subject rights and breach notifications. There is no general statutory requirement to include cybersecurity clauses beyond this, but the FADP requires “appropriate security measures” for any type of hired data processing with the help of processors, so it is typically implemented contractually. Sector- specific rules (eg, finance, telecoms and critical infra - structure) may impose further security and outsourc - ing provisions. 7.5.3 The Application of Laws Relevant to Supply Chains Under the FADP, the customer (data controller) carries primary responsibility for ensuring lawful processing, including selecting suitable processors and ensuring appropriate contractual safeguards. However, the supplier (data processor) is also subject to statutory and contractual obligations, such as processing data only on instructions, ensuring confidentiality, imple - menting adequate security measures, and co-oper - ating with the controller. In addition, sector-specific regulations (eg, financial services, telecoms and critical infrastructure) may impose direct outsourcing, risk management, and security obligations on both parties.
8. Legislative and Regulatory Adaptation and Advancement 8.1 AI-Related Legal Adaptation
Switzerland is not expected to adopt a standalone AI law comparable to the EU AI Act. Instead, regulation will likely evolve in a sectoral and principles-based way, building on existing frameworks such as data protection, product safety, liability, and contract law. The Federal Council has indicated a preference for a
85 CHAMBERS.COM
Powered by FlippingBook