Take-Aways (AI)
  • The DPA is based on prin­ci­ple-ori­en­ted rules, per­mits data pro­ce­s­sing if the data pro­tec­tion prin­ci­ples are com­plied with and reli­e­ves SMEs of the obli­ga­ti­on to keep a pro­ce­s­sing register.
  • Unneces­sa­ry tigh­tening, such as the new cate­go­ry of “high-risk pro­fil­ing” and the imprac­ti­cal obli­ga­ti­on to name indi­vi­du­al reci­pi­ent count­ries, are problematic.
  • The per­so­nal cri­mi­nal lia­bi­li­ty for data pro­tec­tion vio­la­ti­ons is serious, with high fines and ent­ries in cri­mi­nal records, which can lead to exce­s­si­ve cau­ti­on and inhi­bi­ti­on of innovation.

The date has not yet been set, but it will be some­time in 2022: The new data pro­tec­tion law will come into force. Final­ly, one must add. The Euro­pean Gene­ral Data Pro­tec­tion Regu­la­ti­on (GDPR) will have been in force for a full four years by then.

The Swiss legis­la­tu­re took its time and dis­cus­sed the DPA in detail. The result can be loo­se­ly sum­ma­ri­zed accor­ding to Ser­gio Leo­ne: The Good, the Bad and the Ugly.

The Good

First, on the posi­ti­ve side, the Swiss legis­la­tor has remain­ed true to its tried-and-tested prin­ci­ple-based legis­la­ti­on and has not beco­me ent­an­gled in an unma­na­geable num­ber of detail­ed regu­la­ti­ons like its Euro­pean coun­ter­part. For­t­u­n­a­te­ly, the DPA is also much shorter in scope than the ver­bo­se GDPR.

It is also plea­sing that the DPA has not fol­lo­wed the con­cept of the GDPR, accor­ding to which any hand­ling of per­so­nal data is initi­al­ly pro­hi­bi­ted and must be justi­fi­ed. If the data pro­tec­tion prin­ci­ples are com­plied with, the use of per­so­nal data in Switz­er­land will also be per­mit­ted in prin­ci­ple in the future. Only if the­se prin­ci­ples can­not be com­plied with must the data pro­ce­s­sing be spe­ci­fi­cal­ly justi­fi­ed and con­sent obtai­ned, for example.

For­t­u­n­a­te­ly, the FADP does not make the mista­ke of the GDPR of wan­ting to put the hairdresser’s salon and the bak­ery on the same foo­ting as the big tech com­pa­nies and other sup­po­sed “data octo­puses”. For exam­p­le, it exempts SMEs wit­hout sen­si­ti­ve data pro­ce­s­sing from the obli­ga­ti­on to main­tain a pro­ce­s­sing direc­to­ry. This is more than a foot­no­te: in cor­po­ra­te prac­ti­ce, the pro­ce­s­sing direc­to­ry is one of the most labor-inten­si­ve acti­vi­ties in data protection.

The Bad

Howe­ver, the new DSG does not only con­tain plea­sant things, but also a few annoy­ing, as unneces­sa­ry “Swiss Finishes”.

In par­ti­cu­lar, the regu­la­ti­on on pro­fil­ing, which was con­tro­ver­si­al until the last minu­te and which crea­tes the new legal con­cept of “high-risk pro­fil­ing,” was unsuc­cessful. The GDPR makes a simi­lar distinc­tion. The­re, howe­ver, the addi­tio­nal obli­ga­ti­ons for pro­fil­ing only take effect when pro­fil­ing is the basis for a decis­i­on that has legal effects or simi­lar nega­ti­ve effects, and not, as in Switz­er­land, alre­a­dy when pro­fil­ing allo­ws the assess­ment of “essen­ti­al aspects of personality”.

In Switz­er­land, data pro­tec­tion impact assess­ments will the­r­e­fo­re pro­ba­b­ly have to be car­ri­ed out more fre­quent­ly in con­nec­tion with pro­fil­ing than in the EEA. This is only a small, but nevert­hel­ess unneces­sa­ry tigh­tening com­pared to the GDPR. After all, it should be clear that even pro­fil­ing with high risk does not requi­re con­sent per se – even though some par­lia­men­ta­ri­ans seem to have assu­med exact­ly that until the very end.

The requi­re­ment to spe­ci­fy the indi­vi­du­al reci­pi­ent count­ries for trans­mis­si­ons abroad is also unneces­sa­ry and unwor­kab­le. Main­tai­ning an actu­al list of count­ries would be an admi­ni­stra­ti­ve bur­den with no addi­tio­nal bene­fit for cus­to­mers. In prac­ti­ce, a gene­rous blind eye will pro­ba­b­ly be tur­ned and the spe­ci­fi­ca­ti­on of geo­gra­phi­cal regi­ons – or even “world­wi­de” – will suffice.

The Ugly

So far so good. If only the new DPA did­n’t con­tain this one major faux pas that is hard to digest: per­so­nal cri­mi­nal lia­bi­li­ty. In Switz­er­land, it is not com­pa­nies that are to be punis­hed for data pro­tec­tion vio­la­ti­ons, but peo­p­le. With up to a quar­ter of a mil­li­on fine, often com­bi­ned with an ent­ry in the cri­mi­nal record. That’s no mean feat. It is also uni­que, becau­se prac­ti­cal­ly ever­y­whe­re else, com­pa­nies are held accoun­ta­ble for data pro­tec­tion vio­la­ti­ons. Anyo­ne who has ever told for­eign col­le­agues about per­so­nal cri­mi­nal lia­bi­li­ty under the future DPA knows the reac­tion: wide eyes, fol­lo­wed by inc­re­du­lous shaking of the head.

The often-heard argu­ment that the Swiss legal system does not reco­gnize cor­po­ra­te cri­mi­nal lia­bi­li­ty is not con­vin­cing. In this coun­try, too, it is the com­pa­nies and not the peo­p­le acting on their behalf who are pro­se­cu­ted for com­pe­ti­ti­on vio­la­ti­ons. Why should it not be pos­si­ble to do in data pro­tec­tion law what has long been the case in com­pe­ti­ti­on law? Also the Appease­ments of the Fede­ral Coun­cilAccor­ding to which pri­ma­ri­ly mana­gers would be held respon­si­ble, this is not very reassu­ring. The­re is no such rest­ric­tion in the law. And expe­ri­ence from other are­as shows that the­re are cer­tain­ly ope­ra­tio­nal func­tions are held accoun­ta­blewhen errors occur at the ope­ra­tio­nal level.

À pro­pos mista­kes hap­pen: After all, data pro­tec­tion vio­la­ti­ons are only punis­ha­ble if they are inten­tio­nal. But as we all know, intent also inclu­des accep­tance. Anyo­ne who has ever been invol­ved with data pro­tec­tion in a com­pa­ny knows how dif­fi­cult it is to always meet all requi­re­ments in view of incre­a­sing­ly com­plex data struc­tures. It will not be so rare for tho­se invol­ved to be awa­re that a pie­ce of infor­ma­ti­on might not be com­ple­te or cor­rect in all respects, and to accept this. Such a situa­ti­on would be punis­ha­ble in the future. But what should they do? After all, not pro­vi­ding any infor­ma­ti­on at all is not an opti­on either.

The all-clear is the­r­e­fo­re out of place. The cri­mi­nal pro­vi­si­ons of the new DPA must be taken serious­ly. Acti­vists and trou­ble­ma­kers will rou­ti­ne­ly threa­ten to file cri­mi­nal char­ges and will also regu­lar­ly car­ry out their thre­ats. It is quite pos­si­ble that the law enforce­ment agen­ci­es will have bet­ter things to do than pur­sue data pro­tec­tion vio­la­ti­ons. But who wants to rely on that? Law enforce­ment is regu­la­ted on a can­to­nal basis and is the­r­e­fo­re very frag­men­ted. The­re will be one or two pro­se­cu­tors with an affi­ni­ty for data protection.

The per­so­nal cri­mi­nal lia­bi­li­ty of the new DPA is mis­gui­ded in terms of legal poli­cy and under­mi­nes the much-cited risk-based approach. It will lead to an over­ly cau­tious advi­so­ry prac­ti­ce and an increa­se in “cover-your-ass” emails. Given the stiff pen­al­ties, who wants to be the one who waved through a sche­me wit­hout reser­va­tions? Such incen­ti­ves are not good news for Switz­er­land as a loca­ti­on for innovation.

The aut­hor is Head of Data Pro­tec­tion and Data Pro­tec­tion Offi­cer at the Fede­ra­ti­on of Migros Coope­ra­ti­ves. He gives his per­so­nal opinion.