Take-Aways (AI)
  • DPO Report 2022 docu­ments exten­si­ve con­sul­ta­ti­ons, pri­or checks and focus are­as such as cloud, poli­ce, schools and infor­ma­ti­on security.
  • Cloud use requi­res legal basis ana­ly­sis, decla­ra­ti­on of con­fi­den­tia­li­ty and deter­mi­na­ti­on of for­eign access rights (CLOUD Act) befo­re risk mitigation.
  • Data sub­ject to spe­cial offi­ci­al or pro­fes­sio­nal sec­re­cy may only be out­sour­ced if it is encrypt­ed and only tho­se respon­si­ble have keys.
  • Risk assess­ment is part of the sub­jec­ti­ve facts of the case; a low pro­ba­bi­li­ty of unlawful access alo­ne does not justi­fy a state­ment of illegality.

The Data Pro­tec­tion Com­mis­sio­ner of the Can­ton of Zurich (DPO) has sub­mit­ted its acti­vi­ty report for the calen­dar year 2022. It is available online and as a PDF here: https://www.datenschutz.ch/tb/2022.

The acti­vi­ty report con­cerns the fol­lo­wing topics in extracts:

  • Exten­si­ve con­sul­ta­ti­ons and preli­mi­na­ry checks
  • The new IDG takes shape
  • Poli­ce: data exch­an­ge across can­to­nal bor­ders and sta­te levels
  • PJZ: Visi­tor manage­ment and secu­ri­ty sup­port system
  • Elec­tro­nic moni­to­ring in civil law or the respon­si­bi­li­ty of the public
    Organ
  • Hos­pi­tals’ push into the cloud
  • Uni­ver­si­ty Insti­tu­te of Psy­cho­lo­gy and Micro­soft 365
  • Bio­me­tric eva­lua­ti­on in online assessment
  • Pro­por­tio­na­li­ty in online examinations
  • Streng­thening infor­ma­ti­on secu­ri­ty at municipalities
  • Spe­cial pro­tec­tion for reli­gious activities
  • Prac­ti­cal tips for digi­tizati­on in administration
  • ZKB, new GTC and the super­vi­si­on of DPOs
  • Exce­s­si­ve data processing
  • Data pro­tec­tion super­vi­si­on in the courts
  • Schools, school admi­ni­stra­ti­on, parent coun­cil and the infor­ma­ti­on flows
  • A data pro­tec­tion inci­dent in the spotlight
  • More data pro­tec­tion inci­dents reported

The topic of the cloud is cer­tain­ly inte­re­st­ing and in focus. Here, the acti­vi­ty report repeats the DPO’s fami­li­ar stance:

First of all, an ana­ly­sis of the legal basis must be car­ri­ed out. For this pur­po­se, the appli­ca­ble sec­re­cy obli­ga­ti­ons must be eli­ci­ted. Access pos­si­bi­li­ties of for­eign aut­ho­ri­ties (CLOUD Act) must be deter­mi­ned. Only then can and must risk miti­ga­ti­on be con­side­red through tech­ni­cal and orga­nizatio­nal measures.

Then fol­lows the core statement:

In the case of per­so­nal data that is sub­ject to spe­cial offi­ci­al or pro­fes­sio­nal sec­re­cy, the law sti­pu­la­tes that the per­son respon­si­ble for the data is lia­ble to pro­se­cu­ti­on if it even gives unaut­ho­ri­zed per­sons the oppor­tu­ni­ty to take note of such data.. So the decis­i­on is simp­le. Data sub­ject to spe­cial offi­ci­al sec­re­cy or pro­fes­sio­nal sec­re­cy may only be out­sour­ced if it is encrypt­ed and only the per­son respon­si­ble or his or her assi­stants know the key.

The most com­mon holi­stic cloud solu­ti­ons come from US com­pa­nies. They are sub­ject to the CLOUD Act. The CLOUD Act allo­ws Ame­ri­can aut­ho­ri­ties to demand access to the data, regard­less of whe­re it is stored. This cir­cum­vents the agree­ments on mutu­al legal assi­stance. The pro­ce­du­re vio­la­tes the Swiss legal system. Con­trac­tu­al safe­guards do not help. The U.S. com­pa­ny is not free not to com­ply with U.S. law becau­se of a contract.

The legal issue can­not be cir­cum­ven­ted with pro­ba­bi­li­ty cal­cu­la­ti­ons. If an access is unlawful, it does not help that the pro­ba­bi­li­ty of such an access might be small. A public body must always act lawful­ly (prin­ci­ple of lega­li­ty). The state­ments on the cal­cu­la­ti­on of pro­ba­bi­li­ty in the govern­ment coun­cil reso­lu­ti­on on Micro­soft 365 (RRB 542/2022) have sin­ce been put into per­spec­ti­ve. The Finan­cial Direc­to­ra­te rest­ric­ted the use of the ser­vices with the Gene­ral Usa­ge Poli­cy Micro­soft 365 dated June 29, 2022. This also cor­re­sponds to the regu­la­ti­on that applies to the fede­ral administration.

Spe­cial offi­ci­al secret” means a secret that is spe­ci­al­ly regu­la­ted and goes bey­ond offi­ci­al sec­re­cy as defi­ned in Art. 320 StGB.

It is dif­fi­cult to under­stand the opi­ni­on that spe­cial offi­ci­al secrets would per se pre­vent out­sour­cing becau­se the­re would always be a resi­du­al risk of access by for­eign authorities.

Alt­hough also the Attempt at reve­la­ti­on but also the attempt requi­res at least con­tin­gent intent – the­re is no negli­gent attempt. An attempt the­r­e­fo­re requi­res that the pre­sump­ti­ve per­pe­tra­tor with his beha­vi­or – e.g., the use of a cloud for secret data – wants the punis­ha­ble suc­cess, i.e., the dis­clo­sure, or at least con­scious­ly accepts it. This is only pos­si­ble if the per­pe­tra­tor atta­ches a cer­tain pro­ba­bi­li­ty to the suc­cess (even if the pro­ba­bi­li­ty assess­ment alo­ne does not actual­ly indi­ca­te the intent to com­mit the crime).

Here plays the Risk assess­ment If the resi­du­al risk is asses­sed as very low, it can­not be said that the offen­der wants the suc­cess or con­scious­ly accepts it – on the con­tra­ry, he does not want it and assu­mes that it will not occur. It is the­r­e­fo­re wrong to say that the que­sti­on of law is repla­ced by an assess­ment of the risk – rather, the assess­ment of the risk is an ele­ment of the sub­jec­ti­ve ele­ments of the offen­se and thus pre­cis­e­ly part of the rele­vant que­sti­on of law.

Even if, excep­tio­nal­ly, a sec­re­cy pro­vi­si­on express­ly covers the very pos­si­bi­li­ty of obtai­ning know­ledge, which is rare: here, too, not every theo­re­ti­cal pos­si­bi­li­ty is suf­fi­ci­ent, becau­se the­se always exist – no secu­ri­ty mea­su­re is ful­ly effec­ti­ve. It can only be a mat­ter of fac­tu­al increa­se of risk go. If a mini­mal increa­se in risk were to be a con­sti­tu­ent ele­ment, (cri­mi­nal) law would have to defi­ne this in rela­ti­on to a spe­ci­fic, nar­row­ly defi­ned cir­cum­stance of a very excep­tio­nal need for protection.

If you look at the mat­ter from a distance, the con­tra­dic­tion in values beco­mes clear. It does not make sen­se that data should be much more pro­tec­ted against access by for­eign aut­ho­ri­ties than against Rus­si­an hackers.

Any­bo­dy who claims per­fect secu­ri­ty is eit­her lying or they do not know what they are tal­king about (here)