Take-Aways (AI)
  • The EU Com­mis­si­on con­firms the con­tin­ued ade­qua­cy of Swiss data pro­tec­tion law; the revi­sed DPA and the rati­fi­ca­ti­on of Con­ven­ti­on 108+ increa­sed con­ver­gence with the GDPR.
  • Access by Swiss aut­ho­ri­ties is sub­ject to clear, pre­cise rest­ric­tions as well as super­vi­so­ry and redress mecha­nisms; the EU moni­tors ade­qua­cy decis­i­ons on an ongo­ing basis.

On Janu­ary 15, 2024, the Euro­pean Com­mis­si­on pre­sen­ted the eager­ly awai­ted report on the review of ade­qua­cy decis­i­ons based on the Data Pro­tec­tion Direc­ti­ve: “Report […] on the first review of the func­tio­ning of the ade­qua­cy decis­i­ons adopted pur­su­ant to Artic­le 25(6) of Direc­ti­ve 95/46/EC”. One of the rea­sons why this report has taken so long is that the EU wan­ted to take the Schrems II ruling into account; it the­r­e­fo­re sus­pen­ded the work for a cer­tain peri­od of time.

This also inclu­des the Appro­pria­ten­ess of Swiss law (in addi­ti­on to Andor­ra, Argen­ti­na, Cana­da (par­ti­al­ly), the Faroe Islands, Guern­sey, the Isle of Man, Isra­el, Jer­sey, New Zea­land and Uruguay).

The Ade­qua­cy of Swiss data pro­tec­tion law con­firm­ed. The Com­mis­si­on thus reco­gnizes that Switzerland’s cur­rent data pro­tec­tion law is “essen­ti­al­ly equi­va­lent” to the GDPR in the light of the Char­ter, i.e. it meets the stan­dard set by the ECJ in 2015 in Schrems I set and in Schrems II had con­cre­ti­zed (the “Ade­qua­cy Refe­ren­ti­als” of the Euro­pean Data Pro­tec­tion Board more). To be more pre­cise: the ade­qua­cy of Swiss law, becau­se the assess­ment is not limi­t­ed to data pro­tec­tion law in the strict sen­se, but also inclu­des, for exam­p­le, regu­la­ti­ons on access by public aut­ho­ri­ties and in par­ti­cu­lar whe­ther the­se meet the “Essen­ti­al Gua­ran­tees”, i.e. the requi­re­ments of the EU Char­ter on the rule of law. A press release from the FDJP on this is here to find.

The state­ments in the report its­elf are quite brief; fur­ther infor­ma­ti­on can be found in the working docu­ment “SWD(2024) 3” (SWD means Staff Working Docu­ment), which is not yet available. The Com­mis­si­on says the fol­lo­wing about Switzerland:

The Com­mis­si­on wel­co­mes the deve­lo­p­ments in the Swiss legal frame­work sin­ce the adop­ti­on of the ade­qua­cy decis­i­on, inclu­ding legis­la­ti­ve amend­ments, case law and acti­vi­ties of over­sight bodies, which have con­tri­bu­ted to an increa­sed level of data pro­tec­tion. In par­ti­cu­lar, the moder­ni­zed Fede­ral Act on Data Pro­tec­tion that has fur­ther increa­sed the con­ver­gence with the EU’s data pro­tec­tion frame­work, nota­b­ly with respect to the pro­tec­tions for sen­si­ti­ve data and the rules on inter­na­tio­nal data trans­fers. Switz­er­land also streng­the­ned its inter­na­tio­nal com­mit­ments in the field of data pro­tec­tion by rati­fy­ing Con­ven­ti­on 108+ in Sep­tem­ber 2023.

In the area of govern­ment access to per­so­nal data, public aut­ho­ri­ties in Switz­er­land are sub­ject to clear, pre­cise and acce­s­si­ble rules under which such aut­ho­ri­ties can access and sub­se­quent­ly use for public inte­rest objec­ti­ves, in par­ti­cu­lar for cri­mi­nal law enforce­ment and natio­nal secu­ri­ty pur­po­ses, data trans­fer­red from the EU. The­se limi­ta­ti­ons and safe­guards fol­low from the over­ar­ching legal frame­work and inter­na­tio­nal com­mit­ments, nota­b­ly the Swiss Fede­ral Con­sti­tu­ti­on, the ECHR and Con­ven­ti­on 108+, as well as from Swiss data pro­tec­tion rules, inclu­ding the Fede­ral Act on Data Pro­tec­tion and spe­ci­fic data pro­tec­tion rules that app­ly to cri­mi­nal law enforce­ment (e.g., the Cri­mi­nal Pro­ce­du­re Code) and natio­nal secu­ri­ty aut­ho­ri­ties (e.g., the Intel­li­gence Ser­vice Act). In addi­ti­on, Swiss law impo­ses a num­ber of spe­ci­fic limi­ta­ti­ons on the access to and use of per­so­nal data for cri­mi­nal law enforce­ment and natio­nal secu­ri­ty pur­po­ses, and it pro­vi­des over­sight and redress mecha­nisms in this area.

Based on the over­all fin­dings set out in the SWD, the Com­mis­si­on con­clu­des that Switz­er­land con­ti­nues to pro­vi­de an ade­qua­te level of pro­tec­tion for per­so­nal data trans­fer­red from the EU

Ade­qua­cy is asses­sed on an ongo­ing basis; in this sen­se, it is not an entitlement:

The Com­mis­si­on will con­ti­n­ue to clo­se­ly moni­tor deve­lo­p­ments in the pro­tec­tion frame­works and actu­al prac­ti­ce of the count­ries and ter­ri­to­ries con­cer­ned. In case of deve­lo­p­ments in an ade­qua­te coun­try or ter­ri­to­ry that would nega­tively affect the level of data pro­tec­tion found ade­qua­te, the Com­mis­si­on will, whe­re neces­sa­ry, make use of its powers under Artic­le 45(5) GDPR to sus­pend, amend or with­draw an ade­qua­cy decision.

The EU sees ade­qua­cy decis­i­ons not mere­ly as a basis for trans­fers from the EEA, but as a Stra­te­gic instru­ment of a for­eign data poli­cyThis is becau­se the ade­qua­cy regime has an impact on legi­ti­mizati­on in third count­ries (not a new insight for Switz­er­land), and the EU’s ade­qua­cy decis­i­ons are also respec­ted or adopted by other sta­tes, which has a cer­tain net­work effect (in addi­ti­on to Switz­er­land, this also inclu­des Argen­ti­na, Colom­bia, Isra­el, Moroc­co and Uruguay).