Swiss data protection act draft

On August 31, 2022, the Swiss Federal Council adopted the ordinance on the new Swiss Data Protection Act and decided that the new act and the ordinance will enter into force on September 1, 2023. With this, the legislative work on the revision of the Swiss data protection law is complete. Companies now have a year to implement the new requirements.

New DPA enters into force on September 1, 2023

What did the Federal Council decide today?

While Parliament had approved the new Swiss Data Protection Act (DPA) already in September 2020 (see our Bulletin of September 25, 2020 and the text of the DPA available here), the revision of the Data Protection Ordinance (DPO) continued until today. On August 31, 2022, the Federal Council now adopted the new DPO (available here)[1] and decided that the new DPA and the new DPO shall enter into force on September 1, 2023. At the same time, the Federal Council also adopted the new Ordinance on Data Protection Certifications. With this, the legislative work on the revision of the Swiss data protection law is complete.

What is the impact of today’s decisions of the Federal Council?

With today’s decisions by the Federal Council, it is clear which implementing provisions must be taken into account in addition to the DPA and when the revision will enter into force. Companies are now required to take the necessary steps to ensure compliance with the requirements of the new DPA and the DPO by September 1, 2023.

What are the most important regulations of the Data Protection Ordinance?

Which countries does the Federal Council acknowledge to have an adequate level of data protection?

Annex 1 of the DPO lists those countries which have appropriate data protection legislation. In principle, the disclosure of personal data to these countries is permitted. In particular, the list includes all member states of the EU and the EEA and the United Kingdom, as well as Canada in certain areas. Furthermore, the list includes: Andorra, Argentina, Faroe Islands, Gibraltar, Guernsey, Iceland, Isle of Man, Israel, Jersey, Monaco, New Zealand and Uruguay.

Disclosures of personal data to other countries – including in particular to the USA – require either the application of a specific exemption set forth in the DPA or the implementation of alternative protective measures to ensure adequate data protection.

Why is there a need for the Data Protection Ordinance in addition to the DPA?

The DPA empowers the Federal Council to issue certain implementing regulations, which is why the Federal Council adopts the DPO.

Has the new Data Protection Ordinance been toned down from the June 2021 draft?

The draft of the new DPO published in June 2021 was sharply criticized in the public consultation process. This is because the draft contained numerous provisions that would have had a significant impact on the companies subject to the DPA, and which, in terms of content, went far beyond mere implementing provisions. Fortunately, the Federal Council has at least taken partial account of the criticism from the consultation. The final DPO that is now available has been toned down compared to the draft. For example, the Federal Council has considerably streamlined the regulation of the modalities of the duty to inform as well as the requirements for the role of the data protection advisor compared to the draft and has also waived certain written form requirements. However, the final DPO still appears to be excessive in the area of data security requirements, where in particular the implementation of the obligation to log certain data processing appears to be challenging.

What measures are to be undertaken in view of the entry into force of the new DPA?

Projects for implementation of the new DPA in companies should now be tackled promptly so that companies are DPA-compliant on September 1, 2023. For many companies, it will be particularly necessary to review internal processes and documentation (such as data protection declarations, processing records, data protection impact assessments, contracts regarding the processing of personal data, etc.) and, if necessary, update them or introduce new ones. A short checklist giving an overview on implementation work is available for download here.