- The DPA is based on principle-oriented rules, permits data processing if the data protection principles are complied with and relieves SMEs of the obligation to keep a processing register.
- Unnecessary tightening, such as the new category of “high-risk profiling” and the impractical obligation to name individual recipient countries, are problematic.
- The personal criminal liability for data protection violations is serious, with high fines and entries in criminal records, which can lead to excessive caution and inhibition of innovation.
The date has not yet been set, but it will be sometime in 2022: The new data protection law will come into force. Finally, one must add. The European General Data Protection Regulation (GDPR) will have been in force for a full four years by then.
The Swiss legislature took its time and discussed the DPA in detail. The result can be loosely summarized according to Sergio Leone: The Good, the Bad and the Ugly.
The Good
First, on the positive side, the Swiss legislator has remained true to its tried-and-tested principle-based legislation and has not become entangled in an unmanageable number of detailed regulations like its European counterpart. Fortunately, the DPA is also much shorter in scope than the verbose GDPR.
It is also pleasing that the DPA has not followed the concept of the GDPR, according to which any handling of personal data is initially prohibited and must be justified. If the data protection principles are complied with, the use of personal data in Switzerland will also be permitted in principle in the future. Only if these principles cannot be complied with must the data processing be specifically justified and consent obtained, for example.
Fortunately, the FADP does not make the mistake of the GDPR of wanting to put the hairdresser’s salon and the bakery on the same footing as the big tech companies and other supposed “data octopuses”. For example, it exempts SMEs without sensitive data processing from the obligation to maintain a processing directory. This is more than a footnote: in corporate practice, the processing directory is one of the most labor-intensive activities in data protection.
The Bad
However, the new DSG does not only contain pleasant things, but also a few annoying, as unnecessary “Swiss Finishes”.
In particular, the regulation on profiling, which was controversial until the last minute and which creates the new legal concept of “high-risk profiling,” was unsuccessful. The GDPR makes a similar distinction. There, however, the additional obligations for profiling only take effect when profiling is the basis for a decision that has legal effects or similar negative effects, and not, as in Switzerland, already when profiling allows the assessment of “essential aspects of personality”.
In Switzerland, data protection impact assessments will therefore probably have to be carried out more frequently in connection with profiling than in the EEA. This is only a small, but nevertheless unnecessary tightening compared to the GDPR. After all, it should be clear that even profiling with high risk does not require consent per se – even though some parliamentarians seem to have assumed exactly that until the very end.
The requirement to specify the individual recipient countries for transmissions abroad is also unnecessary and unworkable. Maintaining an actual list of countries would be an administrative burden with no additional benefit for customers. In practice, a generous blind eye will probably be turned and the specification of geographical regions – or even “worldwide” – will suffice.
The Ugly
So far so good. If only the new DPA didn’t contain this one major faux pas that is hard to digest: personal criminal liability. In Switzerland, it is not companies that are to be punished for data protection violations, but people. With up to a quarter of a million fine, often combined with an entry in the criminal record. That’s no mean feat. It is also unique, because practically everywhere else, companies are held accountable for data protection violations. Anyone who has ever told foreign colleagues about personal criminal liability under the future DPA knows the reaction: wide eyes, followed by incredulous shaking of the head.
The often-heard argument that the Swiss legal system does not recognize corporate criminal liability is not convincing. In this country, too, it is the companies and not the people acting on their behalf who are prosecuted for competition violations. Why should it not be possible to do in data protection law what has long been the case in competition law? Also the Appeasements of the Federal CouncilAccording to which primarily managers would be held responsible, this is not very reassuring. There is no such restriction in the law. And experience from other areas shows that there are certainly operational functions are held accountablewhen errors occur at the operational level.
À propos mistakes happen: After all, data protection violations are only punishable if they are intentional. But as we all know, intent also includes acceptance. Anyone who has ever been involved with data protection in a company knows how difficult it is to always meet all requirements in view of increasingly complex data structures. It will not be so rare for those involved to be aware that a piece of information might not be complete or correct in all respects, and to accept this. Such a situation would be punishable in the future. But what should they do? After all, not providing any information at all is not an option either.
The all-clear is therefore out of place. The criminal provisions of the new DPA must be taken seriously. Activists and troublemakers will routinely threaten to file criminal charges and will also regularly carry out their threats. It is quite possible that the law enforcement agencies will have better things to do than pursue data protection violations. But who wants to rely on that? Law enforcement is regulated on a cantonal basis and is therefore very fragmented. There will be one or two prosecutors with an affinity for data protection.
The personal criminal liability of the new DPA is misguided in terms of legal policy and undermines the much-cited risk-based approach. It will lead to an overly cautious advisory practice and an increase in “cover-your-ass” emails. Given the stiff penalties, who wants to be the one who waved through a scheme without reservations? Such incentives are not good news for Switzerland as a location for innovation.
The author is Head of Data Protection and Data Protection Officer at the Federation of Migros Cooperatives. He gives his personal opinion.