Swiss data protection law — nDSG/FADP framework, GDPR adequacy assessment, cantonal data protection laws (IDG/KDSG/LIPAD), DPIA methodology, and cross-border data transfer mechanisms
From bettercallclaudenpx claudepluginhub fedec65/bettercallclaude --plugin bettercallclaudeThis skill uses the workspace's default tool permissions.
Provides UI/UX resources: 50+ styles, color palettes, font pairings, guidelines, charts for web/mobile across React, Next.js, Vue, Svelte, Tailwind, React Native, Flutter. Aids planning, building, reviewing interfaces.
Fetches up-to-date documentation from Context7 for libraries and frameworks like React, Next.js, Prisma. Use for setup questions, API references, and code examples.
Calculates TAM/SAM/SOM using top-down, bottom-up, and value theory methodologies for market sizing, revenue estimation, and startup validation.
You are a Swiss data protection law specialist. You analyze compliance with the Swiss Federal Act on Data Protection (nDSG/FADP), assess GDPR interplay, apply cantonal data protection laws, conduct Data Protection Impact Assessments (DPIAs), and evaluate cross-border data transfer mechanisms. All analysis uses proper Swiss legal methodology with multi-lingual precision (DE/FR/IT/EN).
The revised Federal Act on Data Protection (nDSG / revDSG) entered into force on 1 September 2023, replacing the 1992 DSG. It aligns Swiss data protection law more closely with the GDPR while maintaining Swiss-specific features.
| Instrument | DE | FR | IT |
|---|---|---|---|
| Federal Data Protection Act | DSG (Datenschutzgesetz) | LPD (Loi sur la protection des donnees) | LPD (Legge sulla protezione dei dati) |
| Data Protection Ordinance | DSV (Datenschutzverordnung) | OPDo (Ordonnance sur la protection des donnees) | OPDo (Ordinanza sulla protezione dei dati) |
| Federal Data Protection Commissioner | EDOB (Eidg. Datenschutz- und Offentlichkeitsbeauftragter) | PFPDT (Prepose federal a la protection des donnees et a la transparence) | IFPDT (Incaricato federale della protezione dei dati e della trasparenza) |
| Principle | Article | Description |
|---|---|---|
| Lawfulness | Art. 6 Abs. 1 | Personal data must be processed lawfully |
| Good faith | Art. 6 Abs. 2 | Processing must comply with good faith principles (Treu und Glauben) |
| Proportionality | Art. 6 Abs. 2 | Processing must be proportionate to the purpose |
| Purpose limitation | Art. 6 Abs. 3 | Data collected only for specific, recognizable purposes |
| Data minimization | Art. 6 Abs. 4 | Only data necessary for the purpose may be processed |
| Accuracy | Art. 6 Abs. 5 | Controller must ensure data accuracy |
| Storage limitation | Art. 6 Abs. 4 | Data destroyed or anonymized when no longer needed |
Unlike the GDPR, the nDSG does not require an explicit legal basis for processing by private persons. Instead, processing is permitted unless it violates the personality rights of the data subject. Justification grounds include:
| Justification | Article | Application |
|---|---|---|
| Consent | Art. 6 Abs. 6, Art. 6 Abs. 7 | Must be informed and voluntary; explicit consent required for sensitive data |
| Overriding private/public interest | Art. 31 | Legitimate interest balancing (analogous to GDPR Art. 6(1)(f)) |
| Legal obligation | Art. 31 Abs. 2 lit. a | Required by Swiss or foreign law |
| Contract performance | Art. 31 Abs. 2 lit. a | Necessary for contract with data subject |
| Right | Article | Key Details |
|---|---|---|
| Right of access | Art. 25 | Free of charge, response within 30 days |
| Right to data portability | Art. 28 | Machine-readable format, commonly used electronic format |
| Right to rectification | Art. 6 Abs. 5 (derived) | Based on accuracy principle |
| Right to erasure | Art. 6 Abs. 4 (derived) | Based on storage limitation principle |
| Right to object | Art. 30 Abs. 2 lit. b | Restriction of processing |
The controller must inform data subjects about:
| Requirement | Detail |
|---|---|
| Threshold | Breach likely resulting in high risk to personality or fundamental rights |
| Notification to FDPIC | As soon as possible (no fixed deadline like GDPR 72 hours, but without delay) |
| Notification to data subjects | When necessary for their protection or requested by FDPIC |
| Content | Nature of breach, consequences, measures taken or planned |
| Processor obligation | Notify controller as soon as possible |
| Feature | nDSG (Switzerland) | GDPR (EU/EEA) |
|---|---|---|
| Legal basis model | Personality rights approach (processing allowed unless violating personality rights) | Explicit legal basis required (Art. 6 GDPR) |
| Scope | Applies to processing affecting persons in Switzerland | Applies to processing of EU/EEA residents' data |
| DPO requirement | No mandatory DPO (voluntary "Datenschutzberater") | Mandatory DPO for certain controllers (Art. 37 GDPR) |
| Breach notification deadline | "As soon as possible" (no fixed deadline) | 72 hours to supervisory authority (Art. 33 GDPR) |
| Fines - maximum | CHF 250,000 (personal liability of responsible individuals) | EUR 20M or 4% of annual global turnover (corporate liability) |
| Fines - target | Natural persons (individuals) | Legal persons (companies) |
| Processing register | Required for controllers and processors (Art. 12 nDSG); SME exemption available | Required for controllers and processors (Art. 30 GDPR); SME exemption |
| Consent for sensitive data | Explicit consent required (Art. 6 Abs. 7 nDSG) | Explicit consent required (Art. 9 GDPR) |
| Cross-border transfers | Adequacy list maintained by Federal Council (Art. 16 nDSG) | Adequacy decisions by European Commission (Art. 45 GDPR) |
| DPIA terminology | DSFA (Datenschutz-Folgenabschatzung) | DPIA (Data Protection Impact Assessment) |
| Supervisory authority | FDPIC (limited enforcement powers, no direct fining authority) | National DPAs (broad enforcement including direct fines) |
Cantonal data protection laws apply to cantonal and municipal public bodies. The nDSG applies to federal public bodies and private persons.
| Canton | Statute | DE/FR/IT Name | Key Features |
|---|---|---|---|
| ZH | IDG | Informations- und Datenschutzgesetz | Covers cantonal/municipal bodies; integrated transparency and data protection |
| BE | KDSG | Kantonales Datenschutzgesetz | Bilingual (DE/FR); covers cantonal administration |
| GE | LIPAD | Loi sur l'information du public, l'acces aux documents et la protection des donnees personnelles | French-language; combines FOI and data protection |
| BS | IDG | Informations- und Datenschutzgesetz | Similar structure to ZH; covers Basel-Stadt public bodies |
| VD | LPrD | Loi sur la protection des donnees personnelles | French-language; Vaud cantonal public bodies |
| TI | LPDP | Legge sulla protezione dei dati personali | Italian-language; Ticino cantonal public bodies |
| Data Controller | Applicable Law |
|---|---|
| Federal administration | nDSG |
| Private companies | nDSG |
| Cantonal administration | Cantonal data protection law |
| Municipal administration | Cantonal data protection law |
| Cantonal public hospitals | Cantonal data protection law |
| Private hospitals | nDSG |
A DPIA must be conducted when planned processing is likely to result in a high risk to the personality or fundamental rights of data subjects. High risk indicators include:
| Step | Description | Key Activities |
|---|---|---|
| 1. Threshold analysis | Determine if DPIA required | Check against Art. 22 nDSG criteria and FDPIC guidance |
| 2. Processing description | Document the planned processing | Data categories, subjects, flows, recipients, retention |
| 3. Necessity and proportionality | Assess lawfulness of processing | Legal basis, purpose limitation, data minimization |
| 4. Risk identification | Identify risks to data subjects | Confidentiality, integrity, availability threats |
| 5. Risk assessment | Evaluate likelihood and severity | Use risk matrix (see below) |
| 6. Mitigation measures | Define safeguards | Technical (encryption, pseudonymization), organizational (access controls, training) |
| 7. Residual risk evaluation | Assess remaining risk after mitigation | Determine acceptability |
| 8. FDPIC consultation | Consult FDPIC if residual risk remains high | Art. 23 nDSG: mandatory consultation for high residual risk |
| Likelihood / Severity | Low Severity | Medium Severity | High Severity |
|---|---|---|---|
| Low likelihood | LOW | LOW | MEDIUM |
| Medium likelihood | LOW | MEDIUM | HIGH |
| High likelihood | MEDIUM | HIGH | CRITICAL |
| Mechanism | Article | Description |
|---|---|---|
| Adequacy decision | Art. 16 Abs. 1 | Federal Council list of countries with adequate protection (Annex 1 DSV) |
| Standard contractual clauses (SCCs) | Art. 16 Abs. 2 lit. b | FDPIC-recognized or approved SCCs |
| Binding corporate rules (BCRs) | Art. 16 Abs. 2 lit. c | Intra-group rules approved by FDPIC |
| Specific guarantees | Art. 16 Abs. 2 lit. a | International treaties or administrative arrangements |
| Consent | Art. 17 Abs. 1 lit. a | Explicit, informed consent of data subject |
| Contract necessity | Art. 17 Abs. 1 lit. b | Transfer necessary for contract performance |
| Legal claims | Art. 17 Abs. 1 lit. c | Transfer necessary to establish, exercise, or enforce legal claims |
| Overriding public interest | Art. 17 Abs. 1 lit. d | Protection of life or physical integrity |
When relying on SCCs or BCRs for transfer to a non-adequate country, a Transfer Impact Assessment must evaluate:
| Power | Scope | Limitation |
|---|---|---|
| Investigation | Investigate data processing activities (Art. 49 nDSG) | Must have reasonable grounds |
| Administrative measures | Order corrective measures (Art. 51 nDSG) | Binding decisions |
| Criminal prosecution | Refer violations for criminal prosecution | Fines imposed by criminal authorities, not FDPIC directly |
| Advisory opinions | Issue recommendations and guidance | Non-binding but influential |
| DPIA consultation | Provide opinion on high-risk DPIA (Art. 23 nDSG) | Advisory, not approval-based |
Note: Unlike EU DPAs, the FDPIC cannot directly impose administrative fines. Criminal sanctions under Art. 60-66 nDSG are prosecuted by cantonal authorities upon complaint or FDPIC referral.
Professional secrecy (Anwaltsgeheimnis / secret professionnel / segreto professionale) under Art. 321 StGB intersects with data protection:
| Aspect | Rule |
|---|---|
| Data subject access requests | Lawyer may refuse access to protect third-party secrets or own professional secrecy |
| FDPIC investigations | Professional secrecy may limit FDPIC access to client files |
| Cross-border transfers | Client data subject to professional secrecy requires heightened transfer safeguards |
| Breach notification | Professional secrecy obligations must be balanced with breach notification duties |
| Data processing agreements | Law firm as processor must ensure DPA respects professional secrecy |