Take-Aways (AI)
  • Fede­ral Coun­cil com­mis­si­ons FDJP with preli­mi­na­ry draft revi­si­on of the Data Pro­tec­tion Act (DPA), taking into account Euro­pean developments.
  • The issue of the “right to be for­got­ten” is being exami­ned as part of the ongo­ing revi­si­on of the FADP.
  • Plan­ned con­sul­ta­ti­on draft for the FADP revi­si­on will be sub­mit­ted to the Fede­ral Coun­cil by the end of August 2016.
  • Switz­er­land is repre­sen­ted in the EU Dapix working group and takes into account EU reforms to safe­guard cross-bor­der data traffic.

Inter­pel­la­ti­on Munz (15.3657): Right to be for­got­ten for Inter­net users
Done (25.09.2015)

Sub­mit­ted text

1. how far advan­ced is the imple­men­ta­ti­on of postu­la­te Schwa­ab 12.3152, “right to be for­got­ten on the internet”?

2. are chan­ges in the law plan­ned and when are they expected?

3 The EU is curr­ent­ly deve­lo­ping com­mon stan­dards for data pro­tec­tion on the Inter­net. Is Switz­er­land invol­ved in this process?

Justi­fi­ca­ti­on

New stan­dards for data pro­tec­tion on the Inter­net will soon app­ly in Euro­pe, and they will be the same for all 28 EU mem­ber sta­tes. The EU justi­ce mini­sters recent­ly agreed on a reform to this effect. Euro­pean users of the Inter­net are to be given more rights and bet­ter pro­tec­tion of their per­so­nal data against lar­ge Inter­net cor­po­ra­ti­ons such as Goog­le and Face­book. The core of the reform is to be the “right to be for­got­ten. This is inten­ded to make it pos­si­ble to have per­so­nal data and pho­tos dele­ted from the web accor­ding to cer­tain cri­te­ria. For exam­p­le, search engi­nes would be requi­red to remo­ve links to con­tent that vio­la­tes the right to pri­va­cy and data pro­tec­tion in online searches.

Sin­ce Inter­net cor­po­ra­ti­ons tend to estab­lish them­sel­ves in count­ries with low data pro­tec­tion stan­dards, Euro­pean or inter­na­tio­nal stan­dards are important for rea­sons of con­su­mer protection.

State­ment of the Fede­ral Council

On April 1, 2015, the Fede­ral Coun­cil com­mis­sio­ned the FDJP to prepa­re a preli­mi­na­ry draft for a revi­si­on of the Fede­ral Data Pro­tec­tion Act (FADP; SR 235.1), also taking into account deve­lo­p­ments at the Euro­pean level. With the revi­si­on of the FADP, the Fede­ral Coun­cil aims, among other things, to impro­ve the data con­trol and gover­nan­ce of the per­sons about whom data is processed.

1 As the Fede­ral Coun­cil sta­ted in its state­ment on the postu­la­te Schwa­ab 12.3152, “Right to be for­got­ten on the inter­net”, the con­cerns of the postu­la­te are being exami­ned as part of the ongo­ing revi­si­on work on the FADP. The “right to be for­got­ten” was also the sub­ject of the deli­be­ra­ti­ons of the sup­port group set up by the Fede­ral Office of Justi­ce, which dis­cus­sed the need for legis­la­ti­ve action on the FADP from Sep­tem­ber 2012 to Octo­ber 2014. The results of the dis­cus­sions of this advi­so­ry group are sum­ma­ri­zed in a report (see www.bj.admin.ch/bj/de/home/staat/gesetzgebung/datenschutzstaerkung.html).

2 It is plan­ned that the FDJP will sub­mit a con­sul­ta­ti­on draft for a revi­si­on of the FADP to the Fede­ral Coun­cil by the end of August 2016.

In the con­text of the EU data pro­tec­tion reforms curr­ent­ly under­way, Switz­er­land is repre­sen­ted in the rele­vant Coun­cil working group on the exch­an­ge of infor­ma­ti­on and data pro­tec­tion (Dapix), inso­far as the­se reform pro­jects repre­sent a fur­ther deve­lo­p­ment of the Schen­gen acquis for our coun­try. In addi­ti­on, the EU data pro­tec­tion reforms are also being taken into account in the revi­si­on work on the DPA. It is true that Switz­er­land is only bound by the new EU data pro­tec­tion decrees within the frame­work of the Schengen/Dublin asso­cia­ti­on. Howe­ver, faci­li­ta­ti­ons of cross-bor­der data traf­fic with the EU are in prin­ci­ple sub­ject to the con­di­ti­on that the EU reco­gnizes the level of data pro­tec­tion in Switz­er­land as ade­qua­te. For this rea­son, Switz­er­land also has an inte­rest in streng­thening its data pro­tec­tion regu­la­ti­ons in light of Euro­pean standards.