Take-Aways (AI)
  • Fede­ral revi­si­on of Büpf and FMG pro­vi­des for stric­ter iden­ti­ty checks and reten­ti­on of ID copies, inclu­ding the right to block in the event of unclear identity.
  • Divi­si­on of tasks bet­ween Bakom and the PTSS is unclear; PTSS coor­di­na­tes with law enforce­ment, audit should impro­ve super­vi­so­ry strength and sanctions.

Que­sti­on Roma­no (14.1115): Misu­se of iden­ti­ty when con­nec­ting tele­pho­ne num­bers. Super­vi­so­ry mea­su­res and sanc­tions for tele­com­mu­ni­ca­ti­ons companies

Sub­mit­ted text

Accor­ding to Artic­le 58 of the Tele­com­mu­ni­ca­ti­ons Act (TCA), the fede­ral aut­ho­ri­ty (Bakom and Com­com) moni­tors com­pli­ance with inter­na­tio­nal and natio­nal tele­com­mu­ni­ca­ti­ons law. If neces­sa­ry, it can lift or add con­di­ti­ons to licen­ses gran­ted and impo­se admi­ni­stra­ti­ve sanc­tions or fines (Art. 60 TCA). In some cases, the iden­ti­ties of unsu­spec­ting citi­zens have been misu­s­ed to con­nect tele­pho­ne num­bers, usual­ly mobi­le num­bers, which have then been used to com­mit cri­mes. It is not clear exact­ly how this could have hap­pen­ed. Howe­ver, it is pro­ba­b­ly due to the fact that the employees of the tele­com­mu­ni­ca­ti­ons com­pa­nies did not check the iden­ti­fi­ca­ti­on docu­ments. In view of the need to com­bat this abu­se, I put the fol­lo­wing que­sti­ons to the Fede­ral Council:

1. what are the con­di­ti­ons and requi­re­ments for acti­vat­ing a mobi­le num­ber? Is the user’s iden­ti­ty also checked in the pro­cess by kee­ping a copy of the iden­ti­fi­ca­ti­on document?

2 Does the super­vi­so­ry aut­ho­ri­ty check, if neces­sa­ry by means of spot checks, whe­ther the rele­vant requi­re­ments are being com­plied with by the tele­com­mu­ni­ca­ti­ons companies?

3. what mea­su­res does the fede­ral aut­ho­ri­ty usual­ly take against a rogue tele­com­mu­ni­ca­ti­ons com­pa­ny if the cri­mi­nal aut­ho­ri­ty has estab­lished an iden­ti­ty misuse?

4. does the fede­ral agen­cy stay in clo­se cont­act with law enforce­ment to pre­vent abuses?

5. do cur­rent regu­la­ti­ons (TCA and other laws and regu­la­ti­ons) allow the fede­ral aut­ho­ri­ty to inter­ve­ne appro­pria­te­ly with tele­com­mu­ni­ca­ti­ons com­pa­nies to pre­vent tele­pho­ne num­bers from being acti­va­ted wit­hout veri­fi­ca­ti­on of the user’s identity?

6. does the Fede­ral Coun­cil belie­ve that the legis­la­ti­on needs to be amen­ded to bet­ter pre­vent iden­ti­ty abuses?

7. Have admi­ni­stra­ti­ve sanc­tions (Art. 58 et seq. TCA) been impo­sed on tele­com­mu­ni­ca­ti­ons com­pa­nies in the last five years? If so, for which vio­la­ti­ons of the regulations?

8. Does the Fede­ral Coun­cil con­sider the fede­ral authority’s super­vi­so­ry powers in the tele­com­mu­ni­ca­ti­ons sec­tor to be gene­ral­ly suf­fi­ci­ent to pre­vent abu­ses, or might the legal pro­vi­si­ons need to be tigh­ten­ed up?

Respon­se of the Fede­ral Council

1 When con­clu­ding con­tracts with end cus­to­mers, tele­com­mu­ni­ca­ti­ons ser­vice pro­vi­ders are obli­ged to com­ply, inter alia, with the pro­vi­si­ons of the Fede­ral Act of 6 Octo­ber 2000 on the Sur­veil­lan­ce of Postal and Tele­com­mu­ni­ca­ti­ons Traf­fic (Büpf; SR 780.1) and the cor­re­spon­ding imple­men­ting pro­vi­si­ons (in par­ti­cu­lar Art. 19a of the Ordi­nan­ce on the Sur­veil­lan­ce of Postal and Tele­com­mu­ni­ca­ti­ons Traf­fic, Vüpf; SR 780.11). Tele­com­mu­ni­ca­ti­ons ser­vice pro­vi­ders must ensu­re that when pre­paid SIM cards are sold, the per­so­nal details of cus­to­mers (sur­na­me, first name, address, date of birth) are recor­ded on the basis of a valid pass­port, iden­ti­ty card or other tra­vel docu­ment admis­si­ble for crossing the bor­der into Switz­er­land. In addi­ti­on, the type of ID and the ID num­ber must be recor­ded; howe­ver, the reten­ti­on of a copy of the docu­ment pre­sen­ted is not legal­ly requi­red. No cor­re­spon­ding regu­la­ti­on is envi­sa­ged for sub­scrip­ti­on con­tracts (post­paid offers), sin­ce it can be assu­med that the pro­vi­ders of tele­com­mu­ni­ca­ti­ons ser­vices iden­ti­fy their cus­to­mers out of their own inte­rest in order to be able to ensu­re payment of the bills. The draft revi­si­on of the Büpf (13.025) pro­vi­des that the Fede­ral Coun­cil can regu­la­te how tele­com­mu­ni­ca­ti­ons ser­vice pro­vi­ders must coll­ect the per­so­nal data of cus­to­mers. This con­cerns data coll­ec­tion both by tele­com­mu­ni­ca­ti­ons ser­vice pro­vi­ders and by pro­fes­sio­nal resel­lers of cards and simi­lar means. For exam­p­le, the Fede­ral Coun­cil will be able to deci­de that iden­ti­fi­ca­ti­on must be pro­vi­ded and a copy kept not only when pre­paid SIM cards are sold, but also when sub­scrip­ti­ons are taken out.

2.-5 The que­sti­on of respon­si­bi­li­ty in the area of super­vi­si­on of the Büpf is not cle­ar­ly regu­la­ted today. The cur­rent Büpf does not have any spe­ci­fic pro­vi­si­ons on super­vi­si­on, nor does it con­tain any penal pro­vi­si­ons. As the super­vi­so­ry aut­ho­ri­ty, the Fede­ral Office of Com­mu­ni­ca­ti­ons (OFCOM) moni­tors com­pli­ance with inter­na­tio­nal tele­com­mu­ni­ca­ti­ons law, the Tele­com­mu­ni­ca­ti­ons Act, the imple­men­ting regu­la­ti­ons and the licen­ces (Art. 58 TCA). It does not car­ry out any checks on the cor­rect recor­ding of per­so­nal data in the case of pre­paid offers and sub­scrip­ti­ons. It is not Bakom but the Postal and Tele­com­mu­ni­ca­ti­ons Traf­fic Sur­veil­lan­ce Ser­vice (Dienst Über­wa­chung Post- und Fern­mel­de­ver­kehr, ÜPF), which is admi­ni­stra­tively atta­ched to the FDJP, which is in con­stant cont­act with the law enforce­ment aut­ho­ri­ties. In cur­rent prac­ti­ce, the ÜPF ser­vice sol­ves the spe­ci­fic pro­blems direct­ly with the tele­com­mu­ni­ca­ti­ons ser­vice pro­vi­ders con­cer­ned. Sin­ce the divi­si­on of respon­si­bi­li­ties bet­ween the aut­ho­ri­ties under cur­rent law and cur­rent prac­ti­ce is sub­ject to cer­tain uncer­tain­ties, it is descri­bed in more detail in the dis­patch on the Büpf revi­si­on (com­men­ta­ry on Art. 41, BBl 2013 2683, 2763).

6 The Fede­ral Council’s draft on the Büpf is inten­ded to enable more effec­ti­ve super­vi­so­ry inter­ven­ti­on against tele­com­mu­ni­ca­ti­ons ser­vice pro­vi­ders (see in par­ti­cu­lar Mes­sa­ge, com­men­ta­ry on Art. 41, BBl 2013 2683, 2763). The draft revi­si­on also pro­vi­des that the TCA is to be sup­ple­men­ted with a pro­vi­si­on obliging tele­com­mu­ni­ca­ti­ons ser­vice pro­vi­ders to block access to tele­com­mu­ni­ca­ti­ons ser­vices if the iden­ti­ty of the cus­to­mer is fal­se or unclear or if the moda­li­ties of data coll­ec­tion have not been com­plied with. In addi­ti­on, the vio­la­ti­on of docu­men­ta­ti­on obli­ga­ti­ons (in par­ti­cu­lar the recor­ding of per­so­nal or cus­to­mer data) is to be punis­hed, irre­spec­ti­ve of the exi­stence of a sub­scrip­ti­on rela­ti­on­ship. In addi­ti­on, the Fede­ral Coun­cil is tas­ked with draf­ting a penal­ty pro­vi­si­on against iden­ti­ty misu­se in ful­fill­ment of the Comte 14.3288 moti­on adopted by Parliament.

7 Within its area of respon­si­bi­li­ty, OFCOM has car­ri­ed out various super­vi­so­ry pro­ce­du­res within the mea­ning of Artic­les 58 and 60 TCA. In seve­ral cases, the­se invol­ved sanc­tion pro­ce­du­res in con­nec­tion with the non-deli­very of data for tele­com­mu­ni­ca­ti­ons statistics.

8 The Fede­ral Coun­cil con­siders the super­vi­so­ry pos­si­bi­li­ties of OFCOM in the area of tele­com­mu­ni­ca­ti­ons ser­vices to be suf­fi­ci­ent. In the case of tele­com­mu­ni­ca­ti­ons sur­veil­lan­ce, which is of inte­rest in the pre­sent case, the revi­si­on of the Fede­ral Law on Tele­com­mu­ni­ca­ti­ons (Büpf), which is curr­ent­ly under­way, will streng­then the super­vi­so­ry pos­si­bi­li­ties of the ÜPF ser­vice in particular.