Take-Aways (AI)
  • The law crea­tes a legal basis for basic digi­tal ser­vices such as elec­tro­nic iden­ti­fi­ca­ti­on, cen­tral web access and the digi­tal work­place (DAP).
  • §17 regu­la­tes cloud use: ser­ver in CH/EU, strict encryp­ti­on and key sove­reig­n­ty for sen­si­ti­ve data; risk-based mea­su­res for other data.

The can­ton of Zurich is sub­mit­ting a new “Law on basic digi­tal ser­vices” for con­sul­ta­ti­on. Docu­ments (Web­site Can­ton ZHSearch for “Basic services”):

The new law is inten­ded to regu­la­te the fol­lo­wing points, among others:

  • the Elec­tro­nic iden­ti­fi­ca­ti­on using the authen­ti­ca­ti­on ser­vice of the fede­ral govern­ment (AGOV Having regard to the EMBAG(the Can­ton of Zurich was a pilot part­ner), part­ly becau­se the can­ton only had limi­t­ed powers to crea­te a can­to­nal E‑ID, which was being con­side­red at the time, and
  • a cen­tral Web access to elec­tro­ni­cal­ly offe­red ser­vices of public bodies (“Züri­kon­to”);
  • Use of the digi­tal work­place (DAP) as an inter­nal admi­ni­stra­ti­on basic ser­vice, inclu­ding cloud-based appli­ca­ti­ons such as Micro­soft 365;
  • Inter­ope­ra­bi­li­ty basic ser­vices, i.e. the inter­ac­tion of the systems of various bodies within the can­ton and in coope­ra­ti­on with bodies of other can­tons and the Confederation;
  • the Fur­ther deve­lo­p­ment basic digi­tal services.

The law will be sup­ple­men­ted by ordi­nan­ces issued by the Govern­ment Coun­cil. – The Act does not cover topics such as e‑participation or e‑voting, nor does it cover egov­part­nera coope­ra­ti­ve orga­nizati­on of the can­ton and the muni­ci­pa­li­ties (see here). Spe­cia­list laws are also not adapt­ed within this framework.

Use of cloud-based services

§ Sec­tion 17 of the Act

Inte­re­st­ing is the Deal­ing with the topic of the cloud in the draft law. To this end, a pro­vi­si­on is to be crea­ted that gene­ral­ly requi­res sto­rage in Switz­er­land or the EU and dif­fe­ren­tia­tes bet­ween spe­cial per­so­nal data and con­fi­den­ti­al or secret data on the one hand and bet­ween other per­so­nal data and infor­ma­ti­on on the other with regard to encryp­ti­on requirements:

17. 1 The public body may dele­ga­te the pro­ce­s­sing of infor­ma­ti­on in digi­tal work­place appli­ca­ti­ons to pro­vi­ders of cloud-based IT ser­vices if their Data cen­ters in Switz­er­land or the Euro­pean Uni­on and if:

  • a. the public body effec­tively dis­c­lo­ses spe­cial per­so­nal data and con­fi­den­ti­al infor­ma­ti­on or infor­ma­ti­on sub­ject to sec­re­cy to the cloud pro­vi­der as well encrypt­ed, so that the cloud pro­vi­der can­not access it wit­hout the invol­vement of the public body can and
  • b. the public body pro­vi­des the other infor­ma­ti­on by pro­tects all rea­sonable orga­nizatio­nal, tech­ni­cal and con­trac­tu­al mea­su­res and the remai­ning Risk dis­clo­sure, in par­ti­cu­lar in view of the importance of the infor­ma­ti­on, the pur­po­se and man­ner of its pro­ce­s­sing and the fun­da­men­tal rights of the data sub­jects justi­fia­ble is.

2 In all other respects, the pro­vi­si­ons of the Infor­ma­ti­on and Data Pro­tec­tion Act apply

Gene­ral explanations

The gene­ral expl­ana­ti­ons (“Preli­mi­na­ry remarks”) con­tain not­hing new per se (empha­sis added):