{"id":1143,"date":"2023-08-30T20:07:59","date_gmt":"2023-08-30T18:07:59","guid":{"rendered":"https:\/\/www.voxlegal.ch\/the-revised-dpa-comes-into-force-on-september1\/"},"modified":"2023-12-21T16:49:40","modified_gmt":"2023-12-21T15:49:40","slug":"the-revised-dpa-comes-into-force-on-september1","status":"publish","type":"post","link":"https:\/\/www.voxlegal.ch\/en\/the-revised-dpa-comes-into-force-on-september1\/","title":{"rendered":"The revised DPA comes into force on September 1<sup>st<\/sup>!"},"content":{"rendered":"\n<p>The long-awaited revision of the Federal Data Protection Act (&#8220;DPA&#8221;) comes into force this Friday. Contrary to what we often see when legislation is passed, this revision does not provide for a transitional period. This means that from September 1, 2023, a number of new obligations will apply to the processing of personal data covered by <a href=\"https:\/\/www.fedlex.admin.ch\/eli\/oc\/2022\/491\/fr#art_2\" title=\"\">art. 2 of the DPA<\/a>. But in concrete terms, what are these new features for you?<\/p>\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<div class=\"wp-bootstrap-blocks-row row justify-content-center align-items-center\">\n\t\n\n<div class=\"col-12\">\n\t\t\t<div class=\"h-100 d-flex flex-column justify-content-center\">\n\t\t\t\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<figure class=\"wp-block-image aligncenter size-full is-style-width-50\"><img loading=\"lazy\" decoding=\"async\" width=\"1271\" height=\"643\" src=\"https:\/\/www.voxlegal.ch\/wp-content\/uploads\/2023\/08\/Padlock-3.png\" alt=\"\" class=\"wp-image-791\" srcset=\"https:\/\/www.voxlegal.ch\/wp-content\/uploads\/2023\/08\/Padlock-3.png 1271w, https:\/\/www.voxlegal.ch\/wp-content\/uploads\/2023\/08\/Padlock-3-300x152.png 300w, https:\/\/www.voxlegal.ch\/wp-content\/uploads\/2023\/08\/Padlock-3-1024x518.png 1024w, https:\/\/www.voxlegal.ch\/wp-content\/uploads\/2023\/08\/Padlock-3-768x389.png 768w, https:\/\/www.voxlegal.ch\/wp-content\/uploads\/2023\/08\/Padlock-3-500x253.png 500w\" sizes=\"auto, (max-width: 1271px) 100vw, 1271px\" \/><figcaption class=\"wp-element-caption\">Image generated with Midjourney<\/figcaption><\/figure>\n<\/div>\n<\/div>\n\n\t\t<\/div>\n\t<\/div>\n\n<\/div>\n\n<h3 class=\"wp-block-heading\"><strong><u>Are you concerned<\/u>?<\/strong><\/h3>\n\n<p>As a preliminary point, a distinction must be made between the situation of entities that were already complying with the obligations arising from the General Data Protection Regulation (&#8220;GDPR&#8221;), and entities that were not affected by it.<\/p>\n\n<p>Indeed, for many Swiss companies, compliance with the GDPR has already been necessary, for example because they were processing personal data targeting European residents. For these companies, implementing the requirements of the DPA is not normally problematic, as the GDPR is deemed, with a few exceptions, to be more protective of personal data than the DPA.<\/p>\n\n<p>On the other hand, for companies that have not had to comply with the GDPR, some adjustments to their processes are likely to be necessary. It should be noted from the outset that for private individuals, personal use is not covered by the scope of the DPA (<a href=\"https:\/\/www.fedlex.admin.ch\/eli\/oc\/2022\/491\/fr#art_2\" title=\"\">art. 2 al. 2 let. a LPD<\/a><a href=\"https:\/\/www.fedlex.admin.ch\/eli\/cc\/1993\/1945_1945_1945\/fr#art_2\" title=\"\">).<\/a><\/p>\n\n<h3 class=\"wp-block-heading\"><strong><span style=\"text-decoration: underline;\">What is &#8220;personal&#8221; data?<\/span> <\/strong>?<\/h3>\n\n<p>This is nothing new in the DPA, but it is worth remembering that only personal data is concerned. For data to be <span style=\"text-decoration: underline;\">personal<\/span>, it must relate to an identified or <span style=\"text-decoration: underline;\">identifiable <\/span> natural person (watch out for &#8220;pseudomnymization&#8221;). In practical terms, this could be contact details or any other personal information. The definition is extremely broad, and even includes IP addresses, for example, where these can be used to identify a user.<\/p>\n\n<p>On the other hand, anonymous data is not covered by the DPA. However, when the data subject is identifiable, even if only with difficulty, the data is not anonymous.<\/p>\n\n<h3 class=\"wp-block-heading\"><strong>What is <span style=\"text-decoration: underline;\">a treatment<\/span>?<\/strong><\/h3>\n\n<p>The law defines processing as &#8220;any operation relating to personal data, whatever the means and procedures used, in particular the collection, recording, storage, use, modification, communication, archiving, erasure or destruction of data&#8221;. Although this is nothing new, it is worth remembering that this definition is extremely broad in scope.<\/p>\n\n<h3 class=\"wp-block-heading\"><strong>What&#8217;s <span style=\"text-decoration: underline;\">new<\/span>?<\/strong><\/h3>\n\n<p>Below are some of the most important changes brought by the revision of the DPA. These are just a few examples, and are not intended to be exhaustive.<\/p>\n\n<p><span style=\"text-decoration: underline;\">Increased focus on data protection<\/span>:<\/p>\n\n<p>As in European regulations, the DPA adopts the principles of &#8220;Privacy by Design&#8221; and &#8220;Privacy by Default&#8221;<a href=\"https:\/\/www.fedlex.admin.ch\/eli\/oc\/2022\/491\/fr#art_7\" title=\"\">(art. 7 DPA<\/a>).<\/p>\n\n<p>The &#8220;Privacy by Design&#8221; principle means that privacy concerns must be taken into account right from the design stage of a new product or service.<\/p>\n\n<p>The &#8220;Privacy by Default&#8221; principle implies that a new product or service must be configured to respect the privacy of its users. In other words, users should not have to change their settings to protect themselves against the use of their personal data.<\/p>\n\n<p><span style=\"text-decoration: underline;\">Greater transparency<\/span>:<\/p>\n\n<p>The collection of personal information must now be notified in advance to the persons concerned <a href=\"https:\/\/www.fedlex.admin.ch\/eli\/oc\/2022\/491\/fr#art_19\" title=\"\">(art. 19 LPD<\/a>). Until now, this has only been the case for sensitive data.<\/p>\n\n<p><span style=\"text-decoration: underline;\">Obligation to keep a register of processing activities<\/span>:<\/p>\n\n<p>It is now compulsory to keep a register of processing activities <a href=\"https:\/\/www.fedlex.admin.ch\/eli\/oc\/2022\/491\/fr#art_12\" title=\"\">(art. 12 LPD<\/a>). Companies with fewer than 250 employees, which do not engage in large-scale processing or high-risk profiling, are exempt from this obligation.<\/p>\n\n<p>However, even for exempt companies, there are good reasons to keep a register, so as to be better able to meet the other requirements of the DPA.<\/p>\n\n<p><span style=\"text-decoration: underline;\">Obligation to report violations promptly<\/span>:<\/p>\n\n<p>In the event of a security breach likely to create a high risk for the personal rights and fundamental entitlements of the data subject, the company must inform the Federal Data Protection and Information Commissioner as soon as possible <a href=\"https:\/\/www.fedlex.admin.ch\/eli\/oc\/2022\/491\/fr#art_24\" title=\"\">(art. 24 DPA<\/a>).<\/p>\n\n<p><span style=\"text-decoration: underline;\">New criminal penalties<\/span>:<\/p>\n\n<p>Under the DPA, fines of up to CHF 250,000 can be imposed for failure to comply with the law <a href=\"https:\/\/www.fedlex.admin.ch\/eli\/oc\/2022\/491\/fr#art_60\" title=\"\">(art. 60 DPA<\/a>). Unlike the RGPD, it&#8217;s the individual responsible for the damage who gets fined, not the company.<\/p>\n\n<p><span style=\"text-decoration: underline;\">Other news<\/span>:<\/p>\n\n<p>We will also mention the following points without going into them in detail:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>The DPA now provides for extraterritorial application, in a similar way to the RGPD;<\/li>\n\n\n\n<li>Sensitive personal data now includes ethnic, genetic and biometric data;<\/li>\n\n\n\n<li>The concept of profiling is introduced in the DPA, with various requirements specific to it;<\/li>\n\n\n\n<li>The Data Protection Impact Assessment, known under the aegis of the RGPD, is introduced in the DPA.<\/li>\n<\/ul>\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n<h3 class=\"wp-block-heading\"><strong><span style=\"text-decoration: underline;\">How can we help you<\/span>?<\/strong><\/h3>\n\n<p>If you&#8217;re unfamiliar with most of the above concepts, it&#8217;s likely that an assessment of your company&#8217;s situation from a data protection perspective would be beneficial. This may, if necessary, be accompanied by a strategy for implementing data protection rules.<\/p>\n\n<p>In the absence of a transitional period, companies are advised to move quickly to comply. Indeed, in view of the revision of the DPA, the vast majority of professionals should be asking themselves a few questions about the protection of the personal data they process.<\/p>\n\n<p>If you have any questions about data protection, please contact the author.<\/p>\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<figure class=\"wp-block-image alignleft size-full is-resized is-style-rounded\"><a href=\"https:\/\/www.voxlegal.ch\/en\/team\/alexandre-osti\/\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.voxlegal.ch\/wp-content\/uploads\/2023\/04\/alexandre-web-edited.jpg\" alt=\"Alexandre Osti\" class=\"wp-image-702\" width=\"250\" height=\"250\" srcset=\"https:\/\/www.voxlegal.ch\/wp-content\/uploads\/2023\/04\/alexandre-web-edited.jpg 900w, https:\/\/www.voxlegal.ch\/wp-content\/uploads\/2023\/04\/alexandre-web-edited-300x300.jpg 300w, https:\/\/www.voxlegal.ch\/wp-content\/uploads\/2023\/04\/alexandre-web-edited-150x150.jpg 150w, https:\/\/www.voxlegal.ch\/wp-content\/uploads\/2023\/04\/alexandre-web-edited-768x768.jpg 768w\" sizes=\"auto, (max-width: 250px) 100vw, 250px\" \/><\/a><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/www.voxlegal.ch\/en\/team\/alexandre-osti\/\" title=\"\">Alexandre OSTI<\/a><\/h2>\n\n\n\n<p>Avocat, associ\u00e9 | Attorney, partner<\/p>\n\n\n\n<p><a href=\"mailto:a.osti@voxlegal.ch\" title=\"\">a.osti@voxlegal.ch<\/a><\/p>\n\n\n\n<p><a href=\"tel:+41 21 637 60 30\">+41 21 637 60 30<\/a><\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The long-awaited revision of the Federal Data Protection Act (&#8220;DPA&#8221;) comes into force this Friday. Contrary to what we often see when legislation is passed, this revision does not provide for a transitional period. This means that from September 1, 2023, a number of new obligations will apply to the processing of personal data covered [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":884,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[22],"tags":[],"class_list":["post-1143","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.voxlegal.ch\/en\/wp-json\/wp\/v2\/posts\/1143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.voxlegal.ch\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.voxlegal.ch\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.voxlegal.ch\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.voxlegal.ch\/en\/wp-json\/wp\/v2\/comments?post=1143"}],"version-history":[{"count":13,"href":"https:\/\/www.voxlegal.ch\/en\/wp-json\/wp\/v2\/posts\/1143\/revisions"}],"predecessor-version":[{"id":1171,"href":"https:\/\/www.voxlegal.ch\/en\/wp-json\/wp\/v2\/posts\/1143\/revisions\/1171"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.voxlegal.ch\/en\/wp-json\/wp\/v2\/media\/884"}],"wp:attachment":[{"href":"https:\/\/www.voxlegal.ch\/en\/wp-json\/wp\/v2\/media?parent=1143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.voxlegal.ch\/en\/wp-json\/wp\/v2\/categories?post=1143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.voxlegal.ch\/en\/wp-json\/wp\/v2\/tags?post=1143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}