Search

Data protection: More legislation and rights in Switzerland

  • Extension of rights of affected parties
  • Rules on forwarding data to third parties
  • It is new that the law now only applies to natural persons, not legal ones.

As of 1 September 2023, new data protection regulations apply in Switzerland too. In light of the European General Data Protection Regulation (GDPR) which came into force in 2018, the finalization and introduction of the revised Swiss Data Protection Act (DPA) became a matter of urgency, especially as the old Data Protection Act from 19 June 1992 no longer met the increased requirements.

After extensive political wrangling, the Parliament passed the law on 25 September 2020. The Federal Council then issued the associated decree on 31 August 2022. The revised Swiss Federal Act on Data Protection (DPA) comes into force on 1 September 2023.

The most important updated points mainly relate to the extension of the rights of the affected parties: 

  • Extended information obligation when obtaining personal data
  • Extended right of information
  • Right to correction, erasure or restriction of processing and disclosure
  • Right to data portability
  • Rules for profiling with high risk and for automated case-by-case decisions

What is new is that the law only applies to natural persons, not legal ones.

Daniel Bucklar
Corporate Legal Counsel, EOS Schweiz

The DPA also governs disclosing data to third parties and standardization of order processing. Another key area relates to data transfer abroad and the organizational measures to be taken when processing personal data.

New organizational obligations for companies

The Data Protection Act sets out new organizational obligations for companies, e.g. keeping a record of data processing activities (for companies with ≥ 250 employees), reporting data protection infringements, data protection follow-up assessment and handling of data protection through technology and default settings. 

It is also new that the law only applies to natural persons, not legal ones. Last but not least, the sanctions for deliberate infringements have been made substantially stronger, with fines of up to 250,000 francs for private individuals.

EOS is putting up a group-wide data protection shield

Data protection involves not only organizational measures, but is also closely linked to IT security. This article explains what EOS is doing for cyber security across the group.

Cyber Security hat für EOS höchste Priorität. Dafür baut das Unternehmen einen internationalen Schutzschirm auf.

Further information on data protection in Switzerland? Just get in touch.

Explore more from EOS

Dr. Stephan Ohlmeyer sitzt auf einem Stuhl und schaut in die Ferne.

Fiscal year 2025/26: EOS Group consolidates position in Central Europe

4 min.
Fiscal year 2025/26 proved demanding for Central Europe. Nevertheless, revenue was able to match the high level of the previous year. Dr. Stephan Ohlmeyer reflects on key developments and formative ex
Learn more
Das Bild zeigt Marwin Ramcke, CEO der EOS Gruppe, und Dr. Eva Griewel, CFO der EOS Gruppe, gemeinsam.

Fiscal year 2025/26: EOS consolidates receivables management position

4 min.
Interview with Marwin Ramcke (CEO) and Dr. Eva Griewel (CFO): Whether unsecured or secured portfolios, EOS is one of the leading experts in European receivables management.
Learn more
Zu sehen ist ein Mann in Business-Bekleidung, der mit freundlich-engagiertem Ausdruck etwas erklärt. Vor ihm steht eine andere Person, die offensichtlich Zuhörer ist. Im Hintergrund ist ein White-Board mit einer Skizze zu sehen.

Forward-flow agreements benefit everyone.

6 min.
Why do companies continuously purchase defaulted receivables from other businesses? We explain how the forward-flow business works – and why this is a successful solution for everyone involved.
Learn more