On 01 September 2023, the revised Swiss Data Protection Act (revDSG) will come into force, which will entail new obligations for companies.
the revDSG remedies weaknesses in the current data protection law due to technological developments,
the revDSG ensures an appropriate level of protection in data protection law to guarantee the cross-border exchange of data, especially with EU countries,
the revDSG introduces minimum data security requirements, new fines and higher transparency obligations.
It takes some preparation, but no panic. We have presented the new data protection law for you in compact form on one DIN A4 page, so that you can quickly check whether the revDSG applies to you and which obligations apply. You can find the download below.
We would like to inform you on this page and provide you with a sample data protection declaration. It is expressly pointed out that the contributions published on this page serve information purposes and cannot replace legal advice in individual cases. We assume no liability for the content of linked contributions.
Privacy News
Checklist
Useful links
There is no need to reinvent the wheel. In the following, we provide you with links to existing samples, explanations and contracts that you can use for your work. In many cases, the samples can be used immediately or with minor adjustments.
Request for information from e.g. companies: Sample (PDF)
Provision of information: sample template (DOCX)
Withdrawal of consent to data processing: sample (DOCX)
Objection to processing of personal data: Sample(DOCX)
Directory of processing activities: Sample (PDF)
Directory of processing activities for associations: sample (PDF)
Directory of processing activities for lawyers: sample (XLSX)
Leaflet on data protection impact assessment pursuant to Art. 22 and 23 FADP (PDF)
Data protection impact assessment: fact sheet and form (link)
Technical-organizational-measures (TOM) checklist: Sample (PDF)
Technical-organizational measures (TOM) for law firm: sample (PDF)
Standard Contractual Clauses (SCC): Model contract - German (PDF)
Standard Contractual Clauses (SCC): Model contract - English (PDF)
Clauses Contractuelles Types: Model contract - French (PDF)
Standard Contractual Clauses / Strandard-Contractual Clauses (SCC): Sample contracts - all languages (ZIP)
Samples, checklists and presentations of the Data Protection Authority Principality of Liechtenstein (link)
Privacy policy DSGVO for website operators: sample with explanation (DOCX)
Online data breach/data protection breach notification form (link Databreach FDPIC).
Notification of data protection violations by data subjects (link FDPIC)
Important laws, regulations and opinions:
Ordinance on data protection (Data Protection Ordinance, DSV August 31, 2022)
Ordinance on Data Protection Certification (VDSZ August 31, 2023)
The new data protection law from the perspective of the FDPIC
FDPIC fact sheet concerning the investigation of violations of the FADP
The FDPIC on the use of Office 365 (using the example of Suva) of 13.06.2022
Communication Suva on the opinion of the FDPIC on the use of Office 365 of 09.06.2022
FAQ from the European Commission on the EU-US GDPR Adequacy Decision of July 10, 2023.
EU-US Adequacy decision for the EU-US Data Privacy Framework -PDF)
FDPIC: List of countries with adequate level of data protection - Status: 08.09.2022 (PDF)
Privacy policy generator
Create a privacy policy for your website easily and without entering personal data. Whether you need a Swiss or a GDPR declaration depends, among other things, on who your online offer is aimed at (see Art. 3 GDPR). As a Swiss website operator, you need at least one information in terms of the revDSG. You can show and hide text blocks and thus create a privacy policy adapted to your personal needs, which you then compile as a uniform statement and post on your website. You can use the text blocks for your data protection declaration free of charge. We do not accept any liability for the data protection statement you use unless it has been checked for accuracy and completeness by a Wicki Partners AG lawyer. We assume no liability for the accuracy, completeness, timeliness or effectiveness of its use. The use of a generated privacy statement cannot replace individual legal advice.
-
We are happy to inform you about the processing of personal data when using our website. We are available at any time to answer any questions you may have about this, and we will provide you with the necessary information within the scope of our legal obligations under the revDSG.
■ This website offering is provided by:
Name(specify a natural person with first name and surname)
Contact details (address, telephone, email, company name if applicable)
-
■ For clarification of terms, we reproduce Art. 5 revDSG below:
a. Personal data: any information relating to an identified or identifiable natural person;
b. data subject: natural person about whom personal data are processed;
c. personal data requiring special protection:
1. data on religious, ideological, political or trade union views or activities,
2. data concerning health, privacy or racial or ethnic affiliation,
3. genetic data,
4. biometric data that uniquely identify a natural person,
5. data on administrative and criminal prosecutions or sanctions,
6. data on social assistance measures;
d. Processing: any handling of personal data, regardless of the means and procedures used, in particular the acquisition, storage, retention, use, modification, disclosure, archiving, deletion or destruction of data;
e. Disclosure: the transmission or making available of personal data;
f. Profiling: any automated processing of personal data consisting in using such data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects relating to that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or change of location;
g. High-risk profiling: profiling that entails a high risk to the personality or fundamental rights of the data subject by leading to a combination of data that allows an assessment of essential aspects of the personality of a natural person;
h. Data breach: a breach of security that results in Personal Data being inadvertently or unlawfully lost, deleted, destroyed or altered, or disclosed or accessed by unauthorized persons;
i. Federal body: agency or department of the Confederation or person entrusted with public duties of the Confederation;
j. Responsible party: private person or federal body that alone or together with others decides on the purpose and means of processing;
k. Data processor: private person or federal body that processes personal data on behalf of the data controller.
-
■ Processing purpose
Your data will be processed for the following purpose(s)(include only those used by you):
Use of our website offer
Contact and communication
Use of cookies to ensure the basic functionality of the website
Use of cookies to analyze user behavior and/or transmission to third-party providers
Provision of a newsletter or other marketing opportunities
Evaluation of the use of the website through the use of so-called analysis tools
Compliance with legal and regulatory requirements or obligations, insofar as we are obliged to do so
Integration of third-party offers for a better user experience or ensuring a high quality of our offer
■ Recipients or category of recipients (specify specific recipients or the category/superordinates).
Webmaster/Web agency
Service provider of the web offer
Employees
integrated third party providers
Payment provider/payment processor
Package/Shipping Service Provider
Service providers for the preparation of offers e.g. insurers, craftsmen, manufacturers, developers)
Supplier
Commissioned data processor
-
■ Processed personal data
When visiting our website, the following personal data is collected, which is automatically collected by the browser or which you have provided to us. (Indication of the specific personal data collected).
their actual IP address, unless it has been hidden or changed by the website user,
E-mail address, as far as it is entered by the website user,
Name, address, other data, as far as these are entered by the website user,
Bank data, insofar as these are entered by the website user,
Health data, insofar as these are entered by the website user or are transferred with consent,
■ Data security
We use the widespread SSL procedure (Secure Socket Layer) in conjunction with the encryption level supported by your browser to visit our website. You can tell whether the page of our website is transmitted in encrypted form by the closed display of the key or lock symbol in the status bar of your browser.
■ Rights of the data subject
Your rights to information and correction, among other things, are governed by the statutory provisions of the revDSG.
■ Use of cookies
Cookies are text files to ensure the use of the website, to improve the website or to track the use of the website (so-called "tracking technology"). Some cookies are stored only for the duration of the visit to the website (so-called "session cookies"). Other cookies are stored for a longer period of time and are only deleted after a set period of time, e.g. to recognize returning users, to analyze user behavior or visit patterns, or to improve website functionality for all users.
You can usually set which cookies you want to allow in the settings of your browser. If all cookies are rejected ("functional cookies"), the visit to our website may be restricted or unavailable. You can find help on cookie management for common browsers here:
- Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-loeschen-daten-von-websites-entfernen
- Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
- Google Chrome: https://support.google.com/accounts/answer/61416?hl=de
- Opera: http://www.opera.com/de/help
- Safari: https://support.apple.com/kb/PH17191?locale=de_DE&viewlocale=de_DE.
■ Use of analysis tools
We have integrated analysis tools on our website in order to analyze user behavior, evaluate advertising measures or create visitor statistics. (List and describe analytics tools and refer to their privacy agreements).
■ Integration of social media services
We have integrated so-called social media services on our website. We point out that the data is processed outside of Switzerland and the European Union. We link on our website to our company profiles in the social networks. However, please note that already by calling up our website or by clicking on the link, personal data may be transferred to the social networks on their servers. For information about the respective processing and respective objection options, we refer to the privacy information of the providers. We have integrated the following providers, whose data protection information can be found below. (List providers and their privacy policy and objection).
■ Integration of external online services
We have integrated external online services (e.g. map service) on our website. When you visit our website and consent to the transfer of data abroad, data is transferred to the online service. (Please refer to the online service, collected data and objection options or data protection notice).
■ Changes to the privacy policy
We have made every effort to provide the legally required and legally required information in the data protection declaration. We reserve the right to change and adapt the privacy policy at any time.
-
■ When visiting our website, personal data may be transferred abroad to the following countries or international bodies.
Country group 1
Country2
Country3
The transfer is based on the following guarantees according to Art. 16 para. 2 or exceptions according to Art. 17 revDSG.
Country group1: Art. 16 para. 1 rev FADP - Determination of adequate level of data protection by Federal Council
Country2: Art. 16 (2) revDSG - appropriate data protection e.g. through standard data protection clauses
Country3: Exception according to Art. 17, e.g. consent of the data subject, conclusion of a contract, protection of public interest or enforcement of legal claims.
-
A sample data protection declaration with explanation is provided by Prof. Thomas Hoeren as of 09/2022 (incl. TTDSG). Download in Word format (DOC)
Do you have questions about data protection and IT law? We can provide you with comprehensive and practical advice on implementing the new data protection requirements. Please feel free to contact Sven Kohlmeier.