- DPO Report 2022 documents extensive consultations, prior checks and focus areas such as cloud, police, schools and information security.
- Cloud use requires legal basis analysis, declaration of confidentiality and determination of foreign access rights (CLOUD Act) before risk mitigation.
- Data subject to special official or professional secrecy may only be outsourced if it is encrypted and only those responsible have keys.
- Risk assessment is part of the subjective facts of the case; a low probability of unlawful access alone does not justify a statement of illegality.
The Data Protection Commissioner of the Canton of Zurich (DPO) has submitted its activity report for the calendar year 2022. It is available online and as a PDF here: https://www.datenschutz.ch/tb/2022.
The activity report concerns the following topics in extracts:
- Extensive consultations and preliminary checks
- The new IDG takes shape
- Police: data exchange across cantonal borders and state levels
- PJZ: Visitor management and security support system
- Electronic monitoring in civil law or the responsibility of the public
Organ - Hospitals’ push into the cloud
- University Institute of Psychology and Microsoft 365
- Biometric evaluation in online assessment
- Proportionality in online examinations
- Strengthening information security at municipalities
- Special protection for religious activities
- Practical tips for digitization in administration
- ZKB, new GTC and the supervision of DPOs
- Excessive data processing
- Data protection supervision in the courts
- Schools, school administration, parent council and the information flows
- A data protection incident in the spotlight
- More data protection incidents reported
The topic of the cloud is certainly interesting and in focus. Here, the activity report repeats the DPO’s familiar stance:
First of all, an analysis of the legal basis must be carried out. For this purpose, the applicable secrecy obligations must be elicited. Access possibilities of foreign authorities (CLOUD Act) must be determined. Only then can and must risk mitigation be considered through technical and organizational measures.
Then follows the core statement:
In the case of personal data that is subject to special official or professional secrecy, the law stipulates that the person responsible for the data is liable to prosecution if it even gives unauthorized persons the opportunity to take note of such data.. So the decision is simple. Data subject to special official secrecy or professional secrecy may only be outsourced if it is encrypted and only the person responsible or his or her assistants know the key.
The most common holistic cloud solutions come from US companies. They are subject to the CLOUD Act. The CLOUD Act allows American authorities to demand access to the data, regardless of where it is stored. This circumvents the agreements on mutual legal assistance. The procedure violates the Swiss legal system. Contractual safeguards do not help. The U.S. company is not free not to comply with U.S. law because of a contract.
The legal issue cannot be circumvented with probability calculations. If an access is unlawful, it does not help that the probability of such an access might be small. A public body must always act lawfully (principle of legality). The statements on the calculation of probability in the government council resolution on Microsoft 365 (RRB 542/2022) have since been put into perspective. The Financial Directorate restricted the use of the services with the General Usage Policy Microsoft 365 dated June 29, 2022. This also corresponds to the regulation that applies to the federal administration.
Special official secret” means a secret that is specially regulated and goes beyond official secrecy as defined in Art. 320 StGB.
It is difficult to understand the opinion that special official secrets would per se prevent outsourcing because there would always be a residual risk of access by foreign authorities.
Although also the Attempt at revelation but also the attempt requires at least contingent intent – there is no negligent attempt. An attempt therefore requires that the presumptive perpetrator with his behavior – e.g., the use of a cloud for secret data – wants the punishable success, i.e., the disclosure, or at least consciously accepts it. This is only possible if the perpetrator attaches a certain probability to the success (even if the probability assessment alone does not actually indicate the intent to commit the crime).
Here plays the Risk assessment If the residual risk is assessed as very low, it cannot be said that the offender wants the success or consciously accepts it – on the contrary, he does not want it and assumes that it will not occur. It is therefore wrong to say that the question of law is replaced by an assessment of the risk – rather, the assessment of the risk is an element of the subjective elements of the offense and thus precisely part of the relevant question of law.
Even if, exceptionally, a secrecy provision expressly covers the very possibility of obtaining knowledge, which is rare: here, too, not every theoretical possibility is sufficient, because these always exist – no security measure is fully effective. It can only be a matter of factual increase of risk go. If a minimal increase in risk were to be a constituent element, (criminal) law would have to define this in relation to a specific, narrowly defined circumstance of a very exceptional need for protection.
If you look at the matter from a distance, the contradiction in values becomes clear. It does not make sense that data should be much more protected against access by foreign authorities than against Russian hackers.
Anybody who claims perfect security is either lying or they do not know what they are talking about (here)