When conducting business in Switzerland, one should be conscious of the laws in place to protect individuals’ and companies’ data. The main regulation of data protection in Switzerland is found in the Federal Act on Data Protection of 19 June 1992 (“DPA”) and the corresponding Ordinance to the Federal Act on Data Protection of 14 June 1993 (“DPO”). The law in respect of data protection is wide-reaching and has formed a pivotal part of the Swiss legal system since 1992. In light of vast changes being made in respect of banking secrecy and advancements in internet technology, it is essential for Swiss businesses and individuals alike to be aware of their rights and obligations with respect to data protection laws in Switzerland as well as the limits thereupon.
This newsletter forms part of a set of four publications discussing and analyzing data protection in Switzerland. The current publication sets out the well-established data protection laws as well as the limits and applicable remedies and penalties. The second publication, for release in November 2015, will present one of the most important and relevant areas in respect of Swiss data protection, being banking secrecy and the current and planned restrictions thereof. The third publication, for release in early 2016, will look at significant challenges faced by data protection. This includes matters arising as a result of the internet, such as cloud computing and cookies, as well as cross-border protection and assignment of data to third parties. The fourth and final publication, also for release in early 2016, will present a comparison of the Swiss data protection laws with European Union and United States’ data protection laws.
Data protection in Swiss law
Personal data can be considered an essential and often invaluable asset to most businesses in today’s society. Data allows a business to predict the purchases a consumer might make or what services may best suit a client of a bank. Conversely, to remain competitive, the respective legal system must uphold the protection of data so that the information is not exploited and the subjects disadvantaged.
The Swiss legal system provides clear rules governing the collection and use of personal data, which are set out below.
The Swiss Constitution
The protection of data is first and foremost enshrined in the Federal Constitution of the Swiss Confederation of 19 April 1999 (“Constitution”).
Article 13(1) of the Constitution states that all persons have the right to privacy in their private life, family life and in their homes as well as in respect of mail and telecommunications. Article 13(2) of the Constitution goes to the heart of actual protection by giving the right to persons to be protected against misuse of their personal data.
Personal data is not defined in the Constitution but rather in the DPA (see directly below).
Federal Act on Data Protection
The basis and boundaries of data protection is set out in the DPA. It is interesting to observe that provisions contained therein are generally broad in nature and put the protection of data as widely as possible. Where the protection is in any way limited, exhaustive limitations are subsequently provided.
“Data” or “personal data” (these terms are used interchangeably) is defined in Article 3 as “all information relating to an identified or identifiable person.” This broad definition infers that it is all-inclusive, whereby information would prima facie be considered personal data.
The term “sensitive personal data” is also used in the DPA and refers to data on religious, ideological, political or trade union-related views or activities, health or racial origin, social security measures or administrative or criminal proceedings and sanctions.
A “personality profile” is defined to include a collection of data that permits an assessment of essential characteristics of the personality of a natural person.
The main action in respect of the data as referred to in the DPA is “processing”, which is also very broadly defined and refers to any operation undertaken in connection with data.
The DPA applies to data pertaining to natural and legal persons, whereby the data is processed by private persons and federal bodies.
Each Canton in Switzerland has in place a data protection act, which are directed at cantonal governmental bodies or specific sectors.
How is data protected?
The Swiss perspective on data protection is succinctly summarized in Article 1 of the DPA, which provision states that the purpose of the DPA is “to protect the privacy and the fundamental rights of persons when their data is processed.”
The principles in respect of data protection as well as the processing of personal data flow therefrom and are as follows:
- personal data may only be processed lawfully;
- the processing of personal data must be carried out in good faith and must be proportionate in the circumstances;
- personal data can only be processed for the purpose given at the time of collection;
- if consent is required for the processing by the data subject, such consent is only valid if given voluntarily and if adequate information is provided. For the processing of sensitive personal data or personality profiles, express consent must be provided;
- anyone processing personal data must ascertain that the data is correct and must take reasonable measures to ensure that incorrect or incomplete data in light of the purpose of its collection is either corrected or destroyed;
- personal data must be protected against unauthorized processing through implementing proper technical and organizational measures;
- the privacy of the data subject must not be breached in the processing of personal data;
- data must not be processed against a person’s express wish without justification;
- sensitive personal data and personality profiles must not be disclosed to third parties without justification;
- federal bodies may only process personal data if there is a statutory basis for doing so;and
- federal bodies may only process sensitive personal data and personality profiles if a formal enactment expressly provides for it, if the Federal Council authorizes the processing because the rights of the subject are not endangered, or if the data subject has given his consent or made their data generally accessible and not expressly prohibited its processing.
Before data files are opened, federal bodies must register the files with the Federal Data Protection and Information Commissioner (“Commissioner”). Federal bodies must declare data files to the Commissioner in order for the files to be registered and before they can be opened.
If private persons regularly process sensitive personal data or personality profiles, or disclose personal data to third parties, the data files must be declared. This must be performed before the file is opened.
Data files do not have to be declared if the controller is a private person and the data is being processed in accordance with a statutory obligation, if the Federal Council has exempted the registration, if the data is used exclusively for publication in a periodically published medium or is processed by journalists to use as a personal work aid, if a data protection officer has been appointed, or if the controller’s data processing system or program has been certified.
There are specific limits on cross-border disclosure contained in Article 6 of the DPA, which will be discussed in the third publication of this series.
Limits on and exceptions to the protection of data in Switzerland
Rather than listing all instances in which data is protected, the DPA lists the specific cases in which protection is not afforded as well as instances where data will not be released by the controller.
In that regard, the DPA expressly excludes the protection of data that is processed by a natural person exclusively for personal use and not disclosed to outsiders.
Data not for release
Any person may prima facie request information from the controller of a data file in respect of whether data is being processed in relation to them.
The DPA specifically does not apply to deliberations of the Federal Assembly and in parliamentary committees. Pending civil proceedings, criminal proceedings and proceedings under constitutional or administrative law (other than administrative proceedings of first instance), public registers based on private law and personal data processed by the International Committee of the Red Cross are also expressly excluded.
Where formal enactment provides or where overriding interests of third parties must be protected, the controller of a data file may refuse or restrict the provision of information. Additionally, a federal body may also refuse, restrict or defer the provision of information if it is required to protect the overriding public interest or Switzerland’s security, or if the information would jeopardize the outcome of criminal proceedings or other investigations. A private controller of data may refuse, restrict or deter the provision of information where their own interests override and so long as they do not disclose the personal data to third parties. In all of the above circumstances, Article 9(5) of the DPA requires the controller to provide reasons for so refusing, restricting or deferring access to information.
The DPA also limits the provision of information by journalists.
Article 13 of the DPA states that any breach of privacy is considered unlawful, unless it is justified for any of the below reasons:
- consent of the affected party is given;
- by matter of law (such as disclosure of relevant information pursuant to the Federal Act on Combatting Money Laundering and Terrorist Financing of 10 October 1997, to be discussed in the second publication of this series);
- the data is processed in direct connection with the conclusion or performance of a contract and the data relates to an involved party;
- the person processing the data is or intends to be in commercial competition with another but the data is not disclosed to third parties;
- the data being processed is neither sensitive personal data nor a personality profile and is used to verify creditworthiness for the conclusion or performance of a contract with the data subject;
- the personal data is processed on a professional basis for publication in the edited section of a publication;
- the data is for purposes not relating to a specific person; or
- the data is collected on a person of public interest and the data relates to the public activities of the person.
Under the DPA and the DPO, the Commissioner is given a broad range of powers with respect to data protection compliance. Those powers are summarized as follows:
- The Commissioner may advise private personswith respect to data protection matters.
- The Commissioner may supervise federal bodies(except the Federal Council), either on their own initiative or at the request of another.
- The Commissioner may also supervise data collection in the private sector, either on their own initiative or at the request of another, if:
- the methods of processing are capable of breaching the privacy of a large number of persons;
- there is a requirement to register data files in accordance with Article 11aof the DPA (keeping a register); or
- there is a duty to provide information for cross-border disclosure.
- With respect to both federal bodies and the private sector, the Commissioner has the power to:
- request files, obtain information and ask to view processed data;
- recommend changes to the method of data processing or recommend it be abandoned should it transpire that the federal body or the member of the private sector has breached the data protection laws;and
- refer the matter to the relevant department or the Federal Chancellery for a decision if a recommendation is not complied with or is rejected,.
- The Commission’s supervision of federal bodies and of the private sector set out herein also allows the Commissioner to apply to the President of the Administrative Court to have interim measurestaken should they deem a data subject is threatened with a disadvantage that cannot be easily remedied. This would be advantageous where a person is suffering, or anticipates suffering, a loss as a result of providing data and requires assistance to stop the wrongdoing.
Remedies and Penalties
Any person with a legitimate interest may request the relevant federal body to refrain from processing personal data unlawfully, to eliminate the consequences of unlawful processing or to ascertain whether such processing is unlawful.
The DPA in Article 15 includes particular civil penalties found in the Swiss Civil Code of 10 December 1907 (“Civil Code”).
Article 28 of the Civil Code allows a person whose personality rights were unlawfully infringed upon to petition the court for protection against those causing the infringement, unless it can be shown consent was provided or there was an overriding private or public interest or by virtue of a law.
Article 28a of the Civil Code states that a person can ask the court to prohibit a threatened infringement, to order that an infringement cease or to declare that an infringement is unlawful if it continues to have an offensive effect. Article 28a(3) of the Civil Code states that claims can be made for damages or an account of profit in accordance with provisions regarding agency without authority.
An aggrieved party, under Article 15 of the DPA, may ask that data processing cease, that it not be disclosed to third parties or that it be corrected or destroyed.
Pursuant to Article 34(1) of the DPA, private persons are liable to a fine if they willfully provide false or incomplete information or willfully fail to inform the data subject that sensitive personal data or personality profiles are being collected. Additionally, if a private person willfully fails to provide to the data subject with the identity of the data controller, the purpose of the processing and the planned categories of recipients of the data, this will give rise to liability under the same provision.
Article 34(2) of the DPA states that private persons are liable to pay a fine if they willfully fail to or willfully provide false information with respect to cross-border disclosure, or where data files must be declared to the Commissioner. A refusal to cooperate with the Commissioner or the provision of false information during an investigation under Article 29 of the DPA will also result in a fine.
A specific criminal penalty applies where one willfully discloses confidential, sensitive personal data or personality profiles which have come into their knowledge as a result of their professional activities, either where such activities required the knowledge or where the person is bound by professional confidentiality or is training with such a person. This penalty remains in force beyond termination of such professional activities or training.
Fines for a breach of the criminal provisions may be issued up to an amount of CHF 10,000.00.
Administrative penalties initiated by the Commissioner are set out herein under the heading “Commissioner’s Role”.
lecocqassociate provides legal advice on fund legal structures. We have experience in structuring Swiss, Maltese, Luxembourg and offshore funds. lecocqassociate provides professional company incorporation and corporate administration services in Switzerland, Malta and the UAE.
This newsletter is for information purposes only. It does not constitute professional advice or an opinion. Please contact Mr. Dominique Lecocq on email@example.com for any questions.
 Confédération suisse, Préposé fédérale à la protection des données et à la transparence, « Protection des données », <http://www.edoeb.admin.ch/datenschutz/00618/00802/00812/index.html?lang=fr > (2014).
 Article 3(c) DPA.
 Article 3(d) DPA.
 Article 2(1) DPA.
 Article 4(1) DPA.
 Article 4(2) DPA.
 Article 4(3) DPA.
 Article 4(5) DPA.
 Article 5 DPA.
 Article 7 DPA.
 Article 12 DPA.
 Article 12(2)(b) DPA.
 Article 12(2)(b) DPA.
 Article 17(1) DPA.
 Article 16 DPO.
 Article 11a(2) DPA.
 Article 11a(3) and (4) DPA.
 Article 11a(5) DPA.
 Article 2(2)(a) DPA.
 Article 8 DPA.
 Article 2(2)(b) to (e) DPA.
 Article 9(1) DPA.
 Article 9(2) DPA.
 Article 8(4) DPA.
 Article 10 DPA.
 Article 28 DPA.
 Article 27(2) DPA.
 Article 29(1) DPA.
 Article 27(3) and Article 29(2) DPA.
 Article 27(4) and Article 29(3) DPA.
 Article 27(5) and Article 27(4) DPA.
 Article 33(2) DPA.
 Article 25 DPA.
 In other words, a breach of Article 14(1) DPA.
 In other words, a breach of Article 14(2) DPA.
 Article 6(3) DPA.
 Article 11a DPA.
 Article 35(1) and (2) DPA.