Data Protection and Privacy 2025

SWITZERLAND Trends and Developments Contributed by: Jürg Schneider, David Vasella and Hugh Reeves, Walder Wyss Ltd

following key steps for the future: incorporation of the Council of Europe’s AI Convention into Swiss law; sector-specific legislation as far as required (cross-sector regulation, to be limited to central areas relevant to fundamental rights); and non-binding measures. Hot Topic Three: Introduction of a Cyber- Attack Reporting Obligation Cyber-attacks on organisations in Switzerland continue to be on the rise. The manufacturing industry and financial service providers remain a particular focus for cybercriminals. In addition to ransomware, the National Cyber Security Cen - tre of Switzerland (NCSC) records high potential damages to companies with respect to invoice manipulation fraud (business email compro - mise). The relevance of cyber-risk awareness is therefore increasing in all organisations. There is also a high level of awareness of cyber-risks in Switzerland’s management bodies. Introducing a reporting obligation for cyber- attacks on critical infrastructure and anchoring the NCSC as the national reporting office are seen as additional important steps to improve Switzerland’s cybersecurity. Therefore, the new Information Security Act, which is aimed at fed - eral authorities and entered into force on 1 Janu - ary 2024, has been revised to include a reporting obligation on operators of critical infrastructures and will set out the tasks of the NCSC in this regard, which is intended to act as the central reporting office for cyber-attacks. The revision will come into force on 1 April 2025.

The reporting obligation will apply to operators of critical infrastructures, including, for example, providers in the energy sector, financial services, healthcare, transportation, telecommunications, search engines and cloud services, among oth - ers. Reportable incidents include cyber-attacks that have the potential to cause significant dam - age. Specifically, these are attacks that endan - ger the proper functioning of critical infrastruc - tures or are associated with extortion, threats or coercion. Additional incident reporting obligations are set forth in the FADP (see above) and may apply, depending on the circumstances, to regulated companies such as financial institutions, tel - ecommunications providers and providers of medical devices, and to listed entities.

439 CHAMBERS.COM

Powered by