Take-Aways (AI)
  • FISA allo­ws US aut­ho­ri­ties access to for­eign data in US com­pa­nies, poten­ti­al­ly jeo­par­di­zing Swiss pri­va­cy rights.
  • The Fede­ral Coun­cil is awa­re of the risk, but has no spe­ci­fic FISA cases; pre­ven­ti­on is pri­ma­ri­ly achie­ved through user edu­ca­ti­on and Edöb advice.
  • Swiss enforce­ment against for­eign pro­vi­ders is ter­ri­to­ri­al­ly limi­t­ed; legal chan­nels exist, enforce­ment abroad remains difficult.
  • Fede­ral Coun­cil exami­nes inter­na­tio­nal talks, agree­ments and FADP revi­si­on to address data pro­tec­tion vio­la­ti­ons by for­eign laws.

Inter­pel­la­ti­on Schwa­ab (13.3033): How can per­so­nal data of Swiss citi­zens be pro­tec­ted in the hands of Ame­ri­can companies?
Writ­ten off (20.03.2015)

Sub­mit­ted text

In the U.S., the For­eign Intel­li­gence and Sur­veil­lan­ce Act (FISA) allo­ws aut­ho­ri­ties to demand that U.S. com­pa­nies hand over per­so­nal data from the cloud of citi­zens from third count­ries. Among the data that can be con­trol­led are, for exam­p­le, tho­se rela­ted to poli­ti­cal orga­nizati­ons. Among the com­pa­nies that have very lar­ge amounts of data from Swiss citi­zens are names such as Goog­le, Face­book and Twit­ter. Basi­cal­ly, this means that it could hap­pen to anyo­ne living in Switz­er­land that their per­so­nal data is trans­fer­red to for­eign aut­ho­ri­ties and used by them in dis­re­gard of the Fede­ral Data Pro­tec­tion Act (FADP) and/or pro­ce­du­ral gua­ran­tees, espe­ci­al­ly tho­se of cri­mi­nal pro­ce­e­dings. The Euro­pean Uni­on (EU) is con­cer­ned by this Ame­ri­can law and admits to having neglec­ted this point “despi­te the pro­blems rela­ted to data sove­reig­n­ty and the pro­tec­tion of citi­zens’ rights” (cf. Euro­pean Par­lia­ment report “Fight­ing cyber crime and pro­tec­ting pri­va­cy in the cloud”, 2012).

For this rea­son, I ask the Fede­ral Coun­cil the fol­lo­wing questions:

1. is he awa­re of the effects of the Ame­ri­can Fisa? What is his assess­ment of this law and what steps has he taken in this context?

2. what does it intend to do to pre­vent vio­la­ti­ons of the DPA by for­eign com­pa­nies that pro­cess the per­so­nal data of Swiss nationals?

3. what does it intend to do to gua­ran­tee the appli­ca­ti­on of Swiss data pro­tec­tion pro­vi­si­ons to data coll­ec­ted in Switz­er­land by for­eign com­pa­nies that do not them­sel­ves have a branch in Switzerland?

4. will he inter­ve­ne with the U.S. (or other count­ries that have simi­lar legal pro­vi­si­ons to Fisa) to ensu­re that the appli­ca­ti­on of such pro­vi­si­ons does not con­tra­dict our legis­la­ti­on on data protection?

5. how does it intend to gua­ran­tee the pro­ce­du­ral rights of citi­zens (cri­mi­nal or civil pro­ce­e­dings, under Swiss or for­eign law) who­se data are dis­c­lo­sed or con­trol­led on the basis of Fisa?

6. how does it intend to ensu­re that the moni­to­red data are not used for legal acts that are not sub­ject to Swiss cri­mi­nal law (e.g., “cri­mes of opinion”)?

7. can the­se ope­ra­ti­ons be pre­ven­ted with the cur­rent laws? If not, when will he pro­po­se tigh­tening them?

<

h1>Statement of the Fede­ral Council

<

h1>

Obtai­ning data wit­hout the know­ledge of the per­sons con­cer­ned is part of the modus ope­ran­di of intel­li­gence ser­vices. Howe­ver, new tech­no­lo­gies – name­ly the decen­tra­li­zed, loca­ti­on-inde­pen­dent sto­rage and pro­ce­s­sing of lar­ge amounts of data (“cloud com­pu­ting”) – are ope­ning up lar­ge-sca­le oppor­tu­ni­ties for the sur­veil­lan­ce of Swiss citi­zens by for­eign aut­ho­ri­ties who may not have the same under­stan­ding of data pro­tec­tion or of the tasks of the intel­li­gence ser­vice as in Switz­er­land. With refe­rence to the For­eign Intel­li­gence Sur­veil­lan­ce Amend­ment Act of the USA (Fisa), a stu­dy of the Euro­pean Par­lia­ment points out the risk of such sur­veil­lan­ce; howe­ver, this risk does not exist sole­ly on the part of the USA.

The Fede­ral Coun­cil responds to the que­sti­ons posed as follows:

1 The Fede­ral Coun­cil is awa­re of the risks high­ligh­ted in the inter­pel­la­ti­on, but has no know­ledge of spe­ci­fic cases in which the per­so­nal rights of Swiss citi­zens have been vio­la­ted on the basis of Fisa. The­r­e­fo­re, to date, he has not taken any steps with the US aut­ho­ri­ties regar­ding this law. Anyo­ne using social net­works must be awa­re of the risks invol­ved. The­se include the loss of con­trol of infor­ma­ti­on once it has been posted on the net­work and the lack of influence of the Swiss aut­ho­ri­ties in this con­text. It is up to each indi­vi­du­al to assess such risks cor­rect­ly and to behave with appro­pria­te cau­ti­on. In this con­text, refe­rence should be made to the fede­ral government’s “Youth and Media” pro­gram, which aims to rai­se awa­re­ness among child­ren and young peo­p­le and their par­ents, tea­chers and edu­ca­tors of the oppor­tu­ni­ties and dan­gers of the new media (http://www.bsv.admin.ch/themen/kinder_jugend_alter/00071/03045/).

2 The Fede­ral Coun­cil is of the opi­ni­on that it is main­ly the task of the Edöb, within the frame­work of its advi­so­ry func­tion, to take mea­su­res aimed at sen­si­tiz­ing Inter­net users and making the owners of data coll­ec­tions awa­re of their respon­si­bi­li­ty. The Edöb has the­r­e­fo­re also published expl­ana­to­ry notes on cloud com­pu­ting. Within the limits set by the prin­ci­ple of ter­ri­to­ri­a­li­ty, the Edöb also has the com­pe­tence to cla­ri­fy and make recom­men­da­ti­ons to owners of data coll­ec­tions that do not respect Swiss legis­la­ti­on. This is how the Edöb pro­ce­e­ded, for exam­p­le, in the case of Goog­le Street View (see also BGE 138 II 346).

3 Switzerland’s room for maneu­ver is limi­t­ed in the case of data pro­tec­tion vio­la­ti­ons by for­eign com­pa­nies that are not domic­i­led in Switz­er­land. Due to the prin­ci­ple of ter­ri­to­ri­a­li­ty, vio­la­ti­ons of the DPA can only be sanc­tion­ed if the­re is a suf­fi­ci­ent link to Switz­er­land. Such a link was given in the exam­p­le of Goog­le Street View (BGE 138 II 346 E. 3). The ext­ent to which Switz­er­land could influence cases of appli­ca­ti­on of the Fisa would have to be asses­sed on the basis of a spe­ci­fic case.

4 The Fede­ral Coun­cil is pre­pared to rai­se this issue with the for­eign aut­ho­ri­ties con­cer­ned if it beco­mes awa­re that Swiss citi­zens are having their pri­va­cy rights repea­ted­ly vio­la­ted in con­nec­tion with their use of the Inter­net. At the same time, it will clo­se­ly fol­low the mea­su­res taken at Euro­pean level. It also does not rule out the pos­si­bi­li­ty of con­clu­ding bila­te­ral or mul­ti­la­te­ral agree­ments with cer­tain sta­tes aimed at lar­ge­ly pre­ven­ting such data pro­tec­tion vio­la­ti­ons (such as the Safe Har­bor agree­ment with the USA).

5/6 The ext­ent to which pro­vi­ders such as Goog­le, Face­book or Twit­ter can pass on data of a user resi­ding in Switz­er­land to third par­ties is a que­sti­on of the con­tract exi­sting bet­ween them and the respec­ti­ve user, the con­tent of which essen­ti­al­ly depends on the gene­ral terms and con­di­ti­ons of the respec­ti­ve pro­vi­der. The spe­cia­list lite­ra­tu­re tends to qua­li­fy such con­tracts as con­su­mer con­tracts within the mea­ning of Artic­le 120 IPRG and within the mea­ning of the Luga­no Con­ven­ti­on. Thus, they would be sub­ject to Swiss law. Howe­ver, this does not pre­clude the pro­vi­der from reser­ving the right to pass on data to third par­ties in an appro­pria­te form. In the event of a breach of con­tract, the user could sue in Switz­er­land (Art. 114 IPRG and Art. 15 LugÜ). The ext­ent to which such a judgment is enforceable against a for­eign pro­vi­der depends on various fac­tors (over which Switz­er­land has only limi­t­ed influence), such as the law of the respec­ti­ve coun­try of domic­i­le. This issue will be addres­sed in the report “Legal Basis for Social Media,” which is curr­ent­ly being pre­pared in respon­se to the Amherd postu­la­te 11.3912 of Sep­tem­ber 29, 2011.

7 As the pre­vious­ly cited decis­i­on on Goog­le Street View shows, Swiss legis­la­ti­on is not inef­fec­ti­ve vis-à-vis for­eign com­pa­nies that publish per­so­nal data coll­ec­ted in Switz­er­land on the Inter­net. Howe­ver, as part of the work on the revi­si­on of the FADP, the Fede­ral Coun­cil will exami­ne whe­ther or not the cur­rent law is suf­fi­ci­ent in this area.