- The EU Commission confirms the continued adequacy of Swiss data protection law; the revised DPA and the ratification of Convention 108+ increased convergence with the GDPR.
- Access by Swiss authorities is subject to clear, precise restrictions as well as supervisory and redress mechanisms; the EU monitors adequacy decisions on an ongoing basis.
On January 15, 2024, the European Commission presented the eagerly awaited report on the review of adequacy decisions based on the Data Protection Directive: “Report […] on the first review of the functioning of the adequacy decisions adopted pursuant to Article 25(6) of Directive 95/46/EC”. One of the reasons why this report has taken so long is that the EU wanted to take the Schrems II ruling into account; it therefore suspended the work for a certain period of time.
This also includes the Appropriateness of Swiss law (in addition to Andorra, Argentina, Canada (partially), the Faroe Islands, Guernsey, the Isle of Man, Israel, Jersey, New Zealand and Uruguay).
The Adequacy of Swiss data protection law confirmed. The Commission thus recognizes that Switzerland’s current data protection law is “essentially equivalent” to the GDPR in the light of the Charter, i.e. it meets the standard set by the ECJ in 2015 in Schrems I set and in Schrems II had concretized (the “Adequacy Referentials” of the European Data Protection Board more). To be more precise: the adequacy of Swiss law, because the assessment is not limited to data protection law in the strict sense, but also includes, for example, regulations on access by public authorities and in particular whether these meet the “Essential Guarantees”, i.e. the requirements of the EU Charter on the rule of law. A press release from the FDJP on this is here to find.
The statements in the report itself are quite brief; further information can be found in the working document “SWD(2024) 3” (SWD means Staff Working Document), which is not yet available. The Commission says the following about Switzerland:
The Commission welcomes the developments in the Swiss legal framework since the adoption of the adequacy decision, including legislative amendments, case law and activities of oversight bodies, which have contributed to an increased level of data protection. In particular, the modernized Federal Act on Data Protection that has further increased the convergence with the EU’s data protection framework, notably with respect to the protections for sensitive data and the rules on international data transfers. Switzerland also strengthened its international commitments in the field of data protection by ratifying Convention 108+ in September 2023.
In the area of government access to personal data, public authorities in Switzerland are subject to clear, precise and accessible rules under which such authorities can access and subsequently use for public interest objectives, in particular for criminal law enforcement and national security purposes, data transferred from the EU. These limitations and safeguards follow from the overarching legal framework and international commitments, notably the Swiss Federal Constitution, the ECHR and Convention 108+, as well as from Swiss data protection rules, including the Federal Act on Data Protection and specific data protection rules that apply to criminal law enforcement (e.g., the Criminal Procedure Code) and national security authorities (e.g., the Intelligence Service Act). In addition, Swiss law imposes a number of specific limitations on the access to and use of personal data for criminal law enforcement and national security purposes, and it provides oversight and redress mechanisms in this area.
Based on the overall findings set out in the SWD, the Commission concludes that Switzerland continues to provide an adequate level of protection for personal data transferred from the EU
Adequacy is assessed on an ongoing basis; in this sense, it is not an entitlement:
The Commission will continue to closely monitor developments in the protection frameworks and actual practice of the countries and territories concerned. In case of developments in an adequate country or territory that would negatively affect the level of data protection found adequate, the Commission will, where necessary, make use of its powers under Article 45(5) GDPR to suspend, amend or withdraw an adequacy decision.
The EU sees adequacy decisions not merely as a basis for transfers from the EEA, but as a Strategic instrument of a foreign data policyThis is because the adequacy regime has an impact on legitimization in third countries (not a new insight for Switzerland), and the EU’s adequacy decisions are also respected or adopted by other states, which has a certain network effect (in addition to Switzerland, this also includes Argentina, Colombia, Israel, Morocco and Uruguay).