The Swiss Data Protection Act (DSG) is now a revised version of the first DSG, which came into force in 1992. From September 1, 2023, the new law will come into force with the revised and updated changes to reflect the current needs of today’s internet environment. The aim of this regulation is to protect the privacy and fundamental rights of the persons whose data is being processed.
“This law aims to protect the privacy and fundamental rights of natural persons about whom personal data are processed.”
The main changes compared to the first publication are that companies must now explain why they collect personal data from their customers and that they must clearly state which third parties are involved in sharing their personal data. Individuals also now have the right to know how long their data will be stored and for what purpose.
The DSG applies to natural persons (formerly legal persons) and to commercial and non-commercial organizations that process personal data of Swiss citizens.
The geographical scope of the DSG works similar to that of the GDPR. The exact definition here is that this ordinance applies to data protection matters that “have effects in Switzerland, even if they are caused abroad”.
…”which have an effect in Switzerland, even if they are initiated abroad”.
Comparable to the requirements of the GDPR, the DSG now requires companies to create a “record of processing activities” (Art. 12 DSG). The responsible person and the order processor are primarily responsible for this. This must contain the following:
As already mentioned, this law focuses on the protection of the personal data of the data subject. Thus, the data subject is protected with the following rights:
The FDPIC is responsible for the application of and compliance with the FADP. He is also responsible for clarification, advice and the protection of personal data in Switzerland. The agency is appointed by the Bundesrat (the executive body of the Swiss federal government).
If a person violates the laws of the DSG, they will be fined up to CHF 250,000. As with the GDPR, the penalty is not tied to the company, but to the responsible natural person.
Start now and make sure you are ready before the FADP comes into force in September 2023. Companies based in Switzerland, or if you do business in Switzerland, should take the following measures:
Not surprisingly, the current version of the DSG is being redesigned to keep up with technological developments. And even if you’re already GDPR compliant, you may still need to take some action. Make sure your organization is compliant and has a legally compliant consent tool in place.
You are not quite sure whether your company meets the upcoming requirements of the DSG? Speak to one of our experts or check with our consent management tool here .
On August 7, the President of the Polish Data Protection Authority (UODO), together with other members of the Authority and external experts, organized a seminar to support companies in the implementation in their business processes. The main points of discussion are summarized here: Expanding the definition of a Whistleblower During the seminar, it was clarified […]
On September 3rd, our webinar on the topic of “How to set up and install consentmanager cookie consent solution correctly” took place. In this webinar, Jan Winkler , CEO of consentmanager , led us through the most important functions and gave valuable insights into the new user interface of the consentmanager CMP interface. The webinar […]