Secu­ri­ty

The requi­re­ments for data secu­ri­ty are pri­ma­ri­ly a que­sti­on of the indi­vi­du­al case. Data pro­tec­tion law only pro­vi­des a fair­ly gene­ral frame­work for exami­ning the risks, the pos­si­ble mea­su­res and the mea­su­res to be taken. 

On the que­sti­on of whe­ther the DPA and the DPO sti­pu­la­te mini­mum data pro­tec­tion requi­re­ments, the vio­la­ti­on of which may be punis­ha­ble by law, cf. here.

Breach Noti­fi­ca­ti­on

on report­ing obli­ga­ti­ons for incidents

Data secu­ri­ty brea­ches may have to be repor­ted to the FDPIC – in the case of high risks for data sub­jects – and/or com­mu­ni­ca­ted to the data sub­jects (if their self-pro­tec­tion is important). The FDPIC pro­vi­des here form, albeit one with con­sidera­ble dis­ad­van­ta­ges. It should be bor­ne in mind that the FDPIC is unfort­u­n­a­te­ly sub­ject to the prin­ci­ple of publi­ci­ty under the Fede­ral Data Pro­tec­tion Act.

Howe­ver, the­re may be addi­tio­nal report­ing obli­ga­ti­ons that are not moti­va­ted by data pro­tec­tion law, but by the spe­ci­fic objec­ti­ves of the respec­ti­ve legal system. The­se include the following: 

  • Report­ing obli­ga­ti­ons from a con­tract, also from a fidu­cia­ry duty
  • Art. 29 FINMASA (e.g. for banks, insu­r­ers or finan­cial insti­tu­ti­ons); see the Super­vi­so­ry noti­ce 03/2024
    and the Super­vi­so­ry noti­ce 05/2020 and the requi­re­ments of the RS Ope­ra­tio­nal risks and resilience
  • Listing Rules: Listed com­pa­nies must report pri­ce-sen­si­ti­ve facts in accordance with the SIX Listing Rules
  • Artic­le 96 of the Tele­com­mu­ni­ca­ti­ons Ser­vices Ordi­nan­ce (FDV)
  • Fede­ral Act on the Elec­tro­nic Pati­ent Record: Obli­ga­ti­ons of the parent companies
  • Medi­cal devices: report­ing obli­ga­ti­on to Swiss­me­dic under cer­tain circumstances
  • Ener­gy sup­plier: cf. ENTSO‑E, Code for cyber security
  • ISG: revi­sed pro­vi­si­ons with a report­ing obli­ga­ti­on for cer­tain cri­ti­cal infrastructures

Das Bun­des­ge­setz über die Infor­ma­ti­ons­si­cher­heit beim Bund (ISG) wird um Bestim­mun­gen zur Mel­de­pflicht der Betrei­be­rin­nen bestimm­ter kri­ti­scher Infra­struk­tu­ren ergänzt. Die revi­dier­ten Bestim­mun­gen tre­ten am 1. April 2025 in Kraft

A sum­ma­ry of the rele­vant pro­vi­si­ons, the cor­re­spon­ding dis­patch, the Cyber­se­cu­ri­ty Ordi­nan­ce and the expl­ana­to­ry report is available here in Ger­man and English:

Updates

the latest artic­les in the field of security

Obli­ga­ti­on to report cyber attacks on cri­ti­cal infras­truc­tures applies from April 1, 2025
FDPIC: Gui­de­lines on data breaches
FINMA: Super­vi­so­ry Com­mu­ni­ca­ti­on 03/2024 on cyber risks
ECJ
ECJ C‑340/21: Ade­qua­te data secu­ri­ty (con­cept and bur­den of pro­of); lia­bi­li­ty for breaches
VBS
Fede­ral Depart­ment of Defen­se, Civil Pro­tec­tion and Sport (DDPS): Man­da­to­ry report­ing of cyber­at­tacks on cri­ti­cal infras­truc­tures will pro­ba­b­ly come in 2025
FINMA Risk Moni­tor 2023: Cyber risks and outsourcing
Fede­ral Coun­cil: ISG and ordi­nan­ce law in force as of 1.1.2024
FDPIC: Secu­ri­ty breach noti­fi­ca­ti­on por­tal, new infor­ma­ti­on on website
1 2 3 4 7 8 9