- Examination of the appropriateness of a right to be forgotten on the Internet and its legal specification, especially for social networks and search engines.
- Uncontrolled, often permanent publication of personal data can result in personal injury and damage to reputation.
- Right to be forgotten includes erasure obligations, minimization of data storage and privacy-friendly default settings.
- The Federal Council has evaluated the Data Protection Act and wants to examine the specification of the right to be forgotten as part of a revision.
Postulate Schwaab (12.3152): Right to be forgotten on the Internet
Accepted (15.06.2012)
Submitted text
The Federal Council is instructed to examine whether it is expedient to include a “right to be forgotten on the Internet” in the legislation and to specify this right, particularly in connection with social networks and search engines. In addition, it is to be examined how users can better assert this right.
Justification
Users of the Internet leave traces – sometimes unconsciously, often against their will – in the form of various personal data. Usually, they have no control over what happens to the data collected about them on social networks and accessible through search engines. This data can remain on the network indefinitely and constitute a violation of privacy, especially if it is sensitive, outdated or incomplete data, or if the data is taken out of context. Damage to reputation occurs frequently and is usually irreparable.
That is why there are more and more calls for a right to be forgotten. The EU, for example, is in the process of introducing such a right (cf. European Commission press release, January 25, 2012). The issue is also being considered in the USA (cf. White House White Paper, “Consumer Data Privacy in a Networked World,” February 2012). In Switzerland, the Federal Data Protection and Information Commissioner (Edöb) also recommends the introduction of this right (cf. 18th Activity Report of Edöb, p. 119).
The right to be forgotten includes, in particular, the obligation of social networks to limit the storage of personal data to an absolute minimum, the obligation to program the default setting in such a way as to guarantee that no data is made public, and the obligation of persons responsible for processing personal data to delete it definitively at the request of a data subject, unless there is a legitimate reason for keeping it.
Statement of the Federal Council
The Federal Office of Justice recently conducted a comprehensive evaluation of the Federal Act of 19 June 1992 on Data Protection (FADP, SR 235.1). The Federal Council adopted its report on this evaluation on December 9, 2011, and in it came to the conclusion that it should be examined to what extent there is a need for legislative action due to the rapidly advanced technological and societal developments and of what nature this is. In the report, the Federal Council has already outlined objectives that the legislative revision work should target. These include, among other things, an improvement in data control and data governance. In line with the postulate, a more precise definition of the right to be forgotten is also to be examined in this context (see BBl 2012 350).