- FISA allows US authorities access to foreign data in US companies, potentially jeopardizing Swiss privacy rights.
- The Federal Council is aware of the risk, but has no specific FISA cases; prevention is primarily achieved through user education and Edöb advice.
- Swiss enforcement against foreign providers is territorially limited; legal channels exist, enforcement abroad remains difficult.
- Federal Council examines international talks, agreements and FADP revision to address data protection violations by foreign laws.
Interpellation Schwaab (13.3033): How can personal data of Swiss citizens be protected in the hands of American companies?
Written off (20.03.2015)
Submitted text
In the U.S., the Foreign Intelligence and Surveillance Act (FISA) allows authorities to demand that U.S. companies hand over personal data from the cloud of citizens from third countries. Among the data that can be controlled are, for example, those related to political organizations. Among the companies that have very large amounts of data from Swiss citizens are names such as Google, Facebook and Twitter. Basically, this means that it could happen to anyone living in Switzerland that their personal data is transferred to foreign authorities and used by them in disregard of the Federal Data Protection Act (FADP) and/or procedural guarantees, especially those of criminal proceedings. The European Union (EU) is concerned by this American law and admits to having neglected this point “despite the problems related to data sovereignty and the protection of citizens’ rights” (cf. European Parliament report “Fighting cyber crime and protecting privacy in the cloud”, 2012).
For this reason, I ask the Federal Council the following questions:
1. is he aware of the effects of the American Fisa? What is his assessment of this law and what steps has he taken in this context?
2. what does it intend to do to prevent violations of the DPA by foreign companies that process the personal data of Swiss nationals?
3. what does it intend to do to guarantee the application of Swiss data protection provisions to data collected in Switzerland by foreign companies that do not themselves have a branch in Switzerland?
4. will he intervene with the U.S. (or other countries that have similar legal provisions to Fisa) to ensure that the application of such provisions does not contradict our legislation on data protection?
5. how does it intend to guarantee the procedural rights of citizens (criminal or civil proceedings, under Swiss or foreign law) whose data are disclosed or controlled on the basis of Fisa?
6. how does it intend to ensure that the monitored data are not used for legal acts that are not subject to Swiss criminal law (e.g., “crimes of opinion”)?
7. can these operations be prevented with the current laws? If not, when will he propose tightening them?
<
h1>Statement of the Federal Council
<
h1>
Obtaining data without the knowledge of the persons concerned is part of the modus operandi of intelligence services. However, new technologies – namely the decentralized, location-independent storage and processing of large amounts of data (“cloud computing”) – are opening up large-scale opportunities for the surveillance of Swiss citizens by foreign authorities who may not have the same understanding of data protection or of the tasks of the intelligence service as in Switzerland. With reference to the Foreign Intelligence Surveillance Amendment Act of the USA (Fisa), a study of the European Parliament points out the risk of such surveillance; however, this risk does not exist solely on the part of the USA.
The Federal Council responds to the questions posed as follows:
1 The Federal Council is aware of the risks highlighted in the interpellation, but has no knowledge of specific cases in which the personal rights of Swiss citizens have been violated on the basis of Fisa. Therefore, to date, he has not taken any steps with the US authorities regarding this law. Anyone using social networks must be aware of the risks involved. These include the loss of control of information once it has been posted on the network and the lack of influence of the Swiss authorities in this context. It is up to each individual to assess such risks correctly and to behave with appropriate caution. In this context, reference should be made to the federal government’s “Youth and Media” program, which aims to raise awareness among children and young people and their parents, teachers and educators of the opportunities and dangers of the new media (http://www.bsv.admin.ch/themen/kinder_jugend_alter/00071/03045/).
2 The Federal Council is of the opinion that it is mainly the task of the Edöb, within the framework of its advisory function, to take measures aimed at sensitizing Internet users and making the owners of data collections aware of their responsibility. The Edöb has therefore also published explanatory notes on cloud computing. Within the limits set by the principle of territoriality, the Edöb also has the competence to clarify and make recommendations to owners of data collections that do not respect Swiss legislation. This is how the Edöb proceeded, for example, in the case of Google Street View (see also BGE 138 II 346).
3 Switzerland’s room for maneuver is limited in the case of data protection violations by foreign companies that are not domiciled in Switzerland. Due to the principle of territoriality, violations of the DPA can only be sanctioned if there is a sufficient link to Switzerland. Such a link was given in the example of Google Street View (BGE 138 II 346 E. 3). The extent to which Switzerland could influence cases of application of the Fisa would have to be assessed on the basis of a specific case.
4 The Federal Council is prepared to raise this issue with the foreign authorities concerned if it becomes aware that Swiss citizens are having their privacy rights repeatedly violated in connection with their use of the Internet. At the same time, it will closely follow the measures taken at European level. It also does not rule out the possibility of concluding bilateral or multilateral agreements with certain states aimed at largely preventing such data protection violations (such as the Safe Harbor agreement with the USA).
5/6 The extent to which providers such as Google, Facebook or Twitter can pass on data of a user residing in Switzerland to third parties is a question of the contract existing between them and the respective user, the content of which essentially depends on the general terms and conditions of the respective provider. The specialist literature tends to qualify such contracts as consumer contracts within the meaning of Article 120 IPRG and within the meaning of the Lugano Convention. Thus, they would be subject to Swiss law. However, this does not preclude the provider from reserving the right to pass on data to third parties in an appropriate form. In the event of a breach of contract, the user could sue in Switzerland (Art. 114 IPRG and Art. 15 LugÜ). The extent to which such a judgment is enforceable against a foreign provider depends on various factors (over which Switzerland has only limited influence), such as the law of the respective country of domicile. This issue will be addressed in the report “Legal Basis for Social Media,” which is currently being prepared in response to the Amherd postulate 11.3912 of September 29, 2011.
7 As the previously cited decision on Google Street View shows, Swiss legislation is not ineffective vis-à-vis foreign companies that publish personal data collected in Switzerland on the Internet. However, as part of the work on the revision of the FADP, the Federal Council will examine whether or not the current law is sufficient in this area.