Auditors, lawyers, tax consultants and management consultants: Four perspectives. One solution. Worldwide. Find out …
Our clients entrust us with their most important legal matters. Learn more about our legal services!
Tax laws are complex and dynamic. We face the challenge of tax law together with you - find out more.
US tariffs: Short term optimization – medium-term preparation
Germany’s Coalition Agreement and Tax Law – A Document to Fiscal Pragmatism
Capmont takes over DFH Deutsche Fertighaus Holding AG with Baker Tilly
BAG overturns forfeiture clause for share options after termination
Traditional Braunschweig logistics company Wandt is entering debtor-in-possession management with Baker Tilly
Probationary period in a fixed-term employment contract - how long can it be?
Industry-specific knowledge is essential in order to create the best conditions for customised solutions. Find out …
Baker Tilly advises biotech startup Real Collagen GmbH investment by US investor
Energy study: Uncertainty slows down investments by industry and utilities in Germany
After ECJ ruling: Financial investors still have no direct access to medical care centers
Benefit from bundled interdisciplinary competencies, expert teams and individual solutions. Learn more!
Baker Tilly offers a wide range of individual and innovative consulting services. Find out more!
From September 1, 2023: (New) data protection requirements for German businesses in Switzerland
On September 1, 2023, a new Data Protection Act (“DPA”) will come into effect in Switzerland. The DPA will apply to such data protection cases with “an effect in Switzerland even if they are initiated abroad”. Consequently, the law will affect German businesses if these process an individual’s data in Switzerland as so-called controller, for example, because they offer goods or services to individuals in Switzerland, or if they come into contact with personal data as service provider (“processor”) for Swiss companies.
The DPA resembles the General Data Protection Regulation (GDPR) in many respects; however, some points must be observed: for example, contrary to the GDPR, where the responsible company is liable in case of a data protection breach, the DPA provides for a primary personal liability of the responsible person. Such liability may affect not only the managing director, but the relevant decision maker. Fines of up to CHF 250,000 may be imposed.
Companies processing personal data in Switzerland should therefore ensure data protection compliance and absolutely avoid any data protection breach, not least with regard to the personal liability.
What’s new? In structural terms, the permissibility of data processing is based on a quite pragmatic approach: In Switzerland, the processing of data is – unlike under the GDPR – generally admissible and prohibited only in exceptional cases. However, data processing must not unlawfully violate the data subject’s personality (Art. 30 DPA). Insofar, the requirements to compliance with Swiss data protection law are comparably strict to those of the GDPR.
The already mentioned personal liability of the decision-maker in case of a data protection breach also significantly differs from the GDPR’s liability provisions. According to the DPA, it is possible to sentence the company to pay the fine instead of the individual only in case of violations involving a fine of no more than CHF 50,000 and if the efforts to identify the offending person within the business would be unreasonable.
Apart from that, similar requirements to the GDPR apply. The fact that the DPA’s implementation requires a careful review despite its GDPR compliance is to be demonstrated by the following examples:
Information requirements (data protection notices)
Conclusion of a processing agreement
Representative in Switzerland You must appoint a representative in Switzerland if the following data processing requirements are cumulatively met:
The processing involves a high risk for the personality of the persons concerned.
Companies that process data of individuals in Switzerland should definitely ensure their data protection compliance in order to prevent a data protection breach in any case, not least with regard to personal liability.
We will be happy to support you in implementing these requirements!
View all news