Take-Aways (AI)
  • Exami­na­ti­on of the appro­pria­ten­ess of a right to be for­got­ten on the Inter­net and its legal spe­ci­fi­ca­ti­on, espe­ci­al­ly for social net­works and search engines.
  • Uncon­trol­led, often per­ma­nent publi­ca­ti­on of per­so­nal data can result in per­so­nal inju­ry and dama­ge to reputation.
  • Right to be for­got­ten inclu­des era­su­re obli­ga­ti­ons, mini­mizati­on of data sto­rage and pri­va­cy-fri­end­ly default settings.
  • The Fede­ral Coun­cil has eva­lua­ted the Data Pro­tec­tion Act and wants to exami­ne the spe­ci­fi­ca­ti­on of the right to be for­got­ten as part of a revision.

Postu­la­te Schwa­ab (12.3152): Right to be for­got­ten on the Internet
Accept­ed (15.06.2012)

Sub­mit­ted text

The Fede­ral Coun­cil is ins­truc­ted to exami­ne whe­ther it is expe­di­ent to include a “right to be for­got­ten on the Inter­net” in the legis­la­ti­on and to spe­ci­fy this right, par­ti­cu­lar­ly in con­nec­tion with social net­works and search engi­nes. In addi­ti­on, it is to be exami­ned how users can bet­ter assert this right.

Justi­fi­ca­ti­on

Users of the Inter­net lea­ve traces – some­ti­mes uncon­scious­ly, often against their will – in the form of various per­so­nal data. Usual­ly, they have no con­trol over what hap­pens to the data coll­ec­ted about them on social net­works and acce­s­si­ble through search engi­nes. This data can remain on the net­work inde­fi­ni­te­ly and con­sti­tu­te a vio­la­ti­on of pri­va­cy, espe­ci­al­ly if it is sen­si­ti­ve, out­da­ted or incom­ple­te data, or if the data is taken out of con­text. Dama­ge to repu­ta­ti­on occurs fre­quent­ly and is usual­ly irreparable.

That is why the­re are more and more calls for a right to be for­got­ten. The EU, for exam­p­le, is in the pro­cess of intro­du­cing such a right (cf. Euro­pean Com­mis­si­on press release, Janu­ary 25, 2012). The issue is also being con­side­red in the USA (cf. White Hou­se White Paper, “Con­su­mer Data Pri­va­cy in a Net­work­ed World,” Febru­ary 2012). In Switz­er­land, the Fede­ral Data Pro­tec­tion and Infor­ma­ti­on Com­mis­sio­ner (Edöb) also recom­mends the intro­duc­tion of this right (cf. 18th Acti­vi­ty Report of Edöb, p. 119).

The right to be for­got­ten inclu­des, in par­ti­cu­lar, the obli­ga­ti­on of social net­works to limit the sto­rage of per­so­nal data to an abso­lu­te mini­mum, the obli­ga­ti­on to pro­gram the default set­ting in such a way as to gua­ran­tee that no data is made public, and the obli­ga­ti­on of per­sons respon­si­ble for pro­ce­s­sing per­so­nal data to dele­te it defi­ni­tively at the request of a data sub­ject, unless the­re is a legi­ti­ma­te rea­son for kee­ping it.

State­ment of the Fede­ral Council

The Fede­ral Office of Justi­ce recent­ly con­duc­ted a com­pre­hen­si­ve eva­lua­ti­on of the Fede­ral Act of 19 June 1992 on Data Pro­tec­tion (FADP, SR 235.1). The Fede­ral Coun­cil adopted its report on this eva­lua­ti­on on Decem­ber 9, 2011, and in it came to the con­clu­si­on that it should be exami­ned to what ext­ent the­re is a need for legis­la­ti­ve action due to the rapid­ly advan­ced tech­no­lo­gi­cal and socie­tal deve­lo­p­ments and of what natu­re this is. In the report, the Fede­ral Coun­cil has alre­a­dy out­lined objec­ti­ves that the legis­la­ti­ve revi­si­on work should tar­get. The­se include, among other things, an impro­ve­ment in data con­trol and data gover­nan­ce. In line with the postu­la­te, a more pre­cise defi­ni­ti­on of the right to be for­got­ten is also to be exami­ned in this con­text (see BBl 2012 350).