Data protection guidelines: Everything new in Switzerland? On September 1, 2023, the revised data protection guidelines will come into force in Switzerland(revDSG). The aim is to improve the compatibility of Swiss law with EU law, in particular with the General Data Protection Regulation (GDPR). In this blog post, we'll show you what's new and what you need to watch out for. Revision of data protection guidelines The revision of the Data Protection Act in Switzerland is a response to the constantly growing challenges in the area of data protection and data security. The new provisions aim to strengthen the protection of personal data and provide your company with clear guidelines for handling sensitive information. What is personal data? Personal data includes everything that uniquely identifies a person. This includes, for example, date of birth, name or gender. But it also includes technical information such as an IP address or a unique user ID. Personal data is particularly worthy of protection as it concerns an individual person, their privacy and personal rights. Important changes summarized The revision entails obligations for your company. In return, it brings more transparency and security for the persons concerned. Below we briefly summarize the most important points for you. Detailed data protection guidelines: Based on the obligation to provide information and the right to information, there are more detailed requirements for the data protection policy. Comprehensive information about the controller, the purpose of processing and the personal data processed are examples of the information required. If your company passes on the data to third parties (e.g. Google Analytics), corresponding contracts and control mechanisms are mandatory. Rights of data subjects: In addition to information in the privacy policy, data subjects have the right to information about their personal data. Under certain circumstances, they may even be able to request that you disclose their data. You are also obliged to ensure appropriate data security and integrity. Data protection of technology and documentation: There are various technical and organizational measures that form the basis of data protection. You are obliged to take possible steps as standard. Important points are, for example, encryption, anonymization, but also internal training and guidelines. In certain cases, companies must carry out data protection impact assessments in order to identify and minimize potential risks to the privacy of data subjects. You can find detailed information on the changes to the revDSG on the FDPIC website. Adjustments for companies To meet the requirements of the revised privacy policy, your website must fulfill the following requirements. We will be happy to help you if you have any questions. IP anonymization: It must be ensured that personal data, in particular IP addresses, are anonymized or pseudonymized. Privacy policy: Every website needs a privacy policy. This declaration must be revised and adapted to the expanded information obligations. It should be clear and understandable, explain the rights of data subjects and transparently disclose information about data processing. Cookies and other personal data: Particular attention should be paid to the handling of personal data. Companies must provide clear information about the data and its purpose. Comparison of Switzerland and the EU The amendment to the Swiss Data Protection Act takes a step towards its counterpart in the EU. However, the GDPR goes even further in some respects. In particular, the processing of personal data is regulated more strictly. In most cases, the explicit consent of the data subject is required. It is therefore important to assess whether or not the GDPR applies to your website. Informative cookie notice Conclusion The revision of the data protection guidelines in Switzerland from September 1, 2023 brings with it important changes that companies must observe. We recommend the following points, regardless of the size of your company: Review your privacy policy Ensure technical measures such as IP anonymization and data security Clear and transparent information about data such as cookies or social media The protection of personal data should always be the focus in order to maintain customer trust and comply with legal requirements. What next? Is your head spinning from all this information? No problem, get in touch with us. We'll help you adapt your website to the new data protection guidelines without the risk of fire. Share on Back to the magazine Your contact person: Mathias Schürmann mschuermann@rocket.ch +41 41 500 10 10