- Federal revision of Büpf and FMG provides for stricter identity checks and retention of ID copies, including the right to block in the event of unclear identity.
- Division of tasks between Bakom and the PTSS is unclear; PTSS coordinates with law enforcement, audit should improve supervisory strength and sanctions.
Submitted text
According to Article 58 of the Telecommunications Act (TCA), the federal authority (Bakom and Comcom) monitors compliance with international and national telecommunications law. If necessary, it can lift or add conditions to licenses granted and impose administrative sanctions or fines (Art. 60 TCA). In some cases, the identities of unsuspecting citizens have been misused to connect telephone numbers, usually mobile numbers, which have then been used to commit crimes. It is not clear exactly how this could have happened. However, it is probably due to the fact that the employees of the telecommunications companies did not check the identification documents. In view of the need to combat this abuse, I put the following questions to the Federal Council:
1. what are the conditions and requirements for activating a mobile number? Is the user’s identity also checked in the process by keeping a copy of the identification document?
2 Does the supervisory authority check, if necessary by means of spot checks, whether the relevant requirements are being complied with by the telecommunications companies?
3. what measures does the federal authority usually take against a rogue telecommunications company if the criminal authority has established an identity misuse?
4. does the federal agency stay in close contact with law enforcement to prevent abuses?
5. do current regulations (TCA and other laws and regulations) allow the federal authority to intervene appropriately with telecommunications companies to prevent telephone numbers from being activated without verification of the user’s identity?
6. does the Federal Council believe that the legislation needs to be amended to better prevent identity abuses?
7. Have administrative sanctions (Art. 58 et seq. TCA) been imposed on telecommunications companies in the last five years? If so, for which violations of the regulations?
8. Does the Federal Council consider the federal authority’s supervisory powers in the telecommunications sector to be generally sufficient to prevent abuses, or might the legal provisions need to be tightened up?
Response of the Federal Council
1 When concluding contracts with end customers, telecommunications service providers are obliged to comply, inter alia, with the provisions of the Federal Act of 6 October 2000 on the Surveillance of Postal and Telecommunications Traffic (Büpf; SR 780.1) and the corresponding implementing provisions (in particular Art. 19a of the Ordinance on the Surveillance of Postal and Telecommunications Traffic, Vüpf; SR 780.11). Telecommunications service providers must ensure that when prepaid SIM cards are sold, the personal details of customers (surname, first name, address, date of birth) are recorded on the basis of a valid passport, identity card or other travel document admissible for crossing the border into Switzerland. In addition, the type of ID and the ID number must be recorded; however, the retention of a copy of the document presented is not legally required. No corresponding regulation is envisaged for subscription contracts (postpaid offers), since it can be assumed that the providers of telecommunications services identify their customers out of their own interest in order to be able to ensure payment of the bills. The draft revision of the Büpf (13.025) provides that the Federal Council can regulate how telecommunications service providers must collect the personal data of customers. This concerns data collection both by telecommunications service providers and by professional resellers of cards and similar means. For example, the Federal Council will be able to decide that identification must be provided and a copy kept not only when prepaid SIM cards are sold, but also when subscriptions are taken out.
2.-5 The question of responsibility in the area of supervision of the Büpf is not clearly regulated today. The current Büpf does not have any specific provisions on supervision, nor does it contain any penal provisions. As the supervisory authority, the Federal Office of Communications (OFCOM) monitors compliance with international telecommunications law, the Telecommunications Act, the implementing regulations and the licences (Art. 58 TCA). It does not carry out any checks on the correct recording of personal data in the case of prepaid offers and subscriptions. It is not Bakom but the Postal and Telecommunications Traffic Surveillance Service (Dienst Überwachung Post- und Fernmeldeverkehr, ÜPF), which is administratively attached to the FDJP, which is in constant contact with the law enforcement authorities. In current practice, the ÜPF service solves the specific problems directly with the telecommunications service providers concerned. Since the division of responsibilities between the authorities under current law and current practice is subject to certain uncertainties, it is described in more detail in the dispatch on the Büpf revision (commentary on Art. 41, BBl 2013 2683, 2763).
6 The Federal Council’s draft on the Büpf is intended to enable more effective supervisory intervention against telecommunications service providers (see in particular Message, commentary on Art. 41, BBl 2013 2683, 2763). The draft revision also provides that the TCA is to be supplemented with a provision obliging telecommunications service providers to block access to telecommunications services if the identity of the customer is false or unclear or if the modalities of data collection have not been complied with. In addition, the violation of documentation obligations (in particular the recording of personal or customer data) is to be punished, irrespective of the existence of a subscription relationship. In addition, the Federal Council is tasked with drafting a penalty provision against identity misuse in fulfillment of the Comte 14.3288 motion adopted by Parliament.
7 Within its area of responsibility, OFCOM has carried out various supervisory procedures within the meaning of Articles 58 and 60 TCA. In several cases, these involved sanction procedures in connection with the non-delivery of data for telecommunications statistics.
8 The Federal Council considers the supervisory possibilities of OFCOM in the area of telecommunications services to be sufficient. In the case of telecommunications surveillance, which is of interest in the present case, the revision of the Federal Law on Telecommunications (Büpf), which is currently underway, will strengthen the supervisory possibilities of the ÜPF service in particular.