Our SIDD team carefully curates the latest information on data protection, information security and artificial intelligence to keep you up to date. Use the search field to find articles by specific keywords. You can subscribe to our newsletter for free below.
A practical action plan for the EU AI Act and medical AI: which systems are high-risk, how the AI Act dovetails with MDR/IVDR, and why an inventory and classification now matter more than any deadline.
What a hospital must report, how the clock runs, what BACS expects, including a reporting workflow to rehearse in a tabletop and the distinction from NIS2.
What the EU AI Act means for B2B SaaS providers shipping AI features: transparency duties for most, high-risk for some, GPAI duties for model providers, the provider vs deployer split, and how it interlocks with your DPA and the vendor security review.
A practical guide for B2B SaaS: answer CAIQ, SIG and bespoke security questionnaires faster, build a trust center, and stop deals stalling in procurement.
SOC 2 or ISO 27001 first? A decision guide for B2B SaaS providers who want to answer customer security questionnaires fast and win the deal.
A neutral decision guide for hospitals, practices and HealthTech: which criteria matter when choosing a security and data-protection partner, with a buyer's checklist.
Legal guide for SaaS vendors as processors: GDPR Art. 28, Swiss nDSG, the DPA, sub-processor list, ROPA Art. 30(2), Art. 32, 72h notice, SCCs and TIA. With a checklist.
Cloud, EHR and MedTech suppliers are part of your liability: due diligence, risk tiering, contractual controls, DPAs, ISMS integration (A.5.19–A.5.23) and continuity escrow.
The FINMA Risk Monitor 2024 is the annual situational assessment by the Swiss Financial Market Supervisory Authority. It prioritises cyber risks, third-party dependencies and market volatility as central supervisory focus areas for 2025.
Sick → doctor. Taxes → accountant. Machine down → technician. Cyber attack → "our IT guy handles that." Why that one reflex is the most expensive line in your P&L.
Annex III walkthrough with concrete examples, exemption pathways, conformity-assessment obligations.
Article-level mapping: where AI Act conformity overlaps with DSFA/DPIA, automated-decision rules, transparency duties.
Art. 5 prohibited practices (since Feb 2025) with realistic scenarios (HR scoring, workplace emotion AI, real-time biometric).
Ready-to-adapt internal AI usage policy: permitted tools, data categories, IP/confidentiality, human-in-the-loop, incident reporting.
Federal Council consultation outcome, sector-specific overlays (FINMA, Swissmedic), EDÖB positions on AI.
12-step roadmap: scope, GAP, risk method, SoA, control implementation, internal audit, management review, Stage 1/2 audit.
Calendly DPA, data flows, EU-region option, embedding & cookie behaviour, alternative tools.
Practical playbook: AUP, data-classification rules, prompt-leak risks, OpenAI's data handling, employer monitoring limits.
How nDSG/UWG/Telekommunikationsgesetz interact for cookies in CH (different from DSGVO opt-in regime); concrete banner templates.
Deep-dive into the legal anchors for cookies in CH: nDSG, FMG/UWG-art-3, eIDAS, when consent is required, when info notice suffices.
Service-page-style overview of how a CH security consultancy structures its offer: assessment, ISMS, pentest, awareness, SOC.
Pillar: threat landscape CH 2026, NCSC/BACS, ISG, key controls (CIS18-mapped), incident handling, KMU vs Konzern priorities.
Practical workflow: detection → assessment of 'high risk' → 72h notification path → contents of notification (Art. 24 nDSG) → data subject notice trigger.
AG IDAG specifics, kantonaler DSB, industrial KMU privacy profile.
BS IDG-overlay, cross-border German employee context, pharma-cluster privacy demands.
BE-specific KDSG, two-tier kantonale/kommunale structure, kantonaler DSB practice.
GE LIPAD overlay (public-sector + transparency), bilingual practice, international-organisation data handling.
PMS choice, payment data, marketing consent, Schengen meldedienst (Art. 16 AuG), loyalty programmes.
VVG/VAG + nDSG intersection, claims data, profiling under AI Act, FINMA-VersAG reporting.
Art. 13 BGFA Berufsgeheimnis vs nDSG access rights, ediscovery/cross-border production, cloud-hosting of mandate files.
LU ÖDSG / kantonale DSB office, tourism and hospitality data flows.
Local market overview: which ZH industries demand DSB-aaS, intersection with kantonales IDG-ZH and the public-sector DSB regime.
DSGVO Art. 37 mandatory triggers, voluntary CH DSB role, comparison of internal vs external/CISO-DSB conflicts.
Tenant data, applicant screening, surveillance cameras in buildings, OR-Mietrecht intersection.
Kantonale Schulgesetze + IDG overlay, parental consent for under-16s, learning analytics, M365 in schools.
SG DSG-SG, financial-services & textile-industry data context.
ZGB-association governance, member-data handling, photo publishing, newsletter & event consent rules.
Berufsgeheimnis (Art. 321 StGB), KVG/EPDG/ePD obligations, GDK-recommendations, practical TOMs.
Checkout flow privacy notice, Trusted-Shops, retargeting cookies, payment-data handling, UWG obligations.
Article 47 BankG bank secrecy meets nDSG and FINMA outsourcing rules; cross-border tax info flows.
ZG ÖDSG, FINMA-DLT intersection, KYC/AML-data handling at crypto-valley firms.
ZH-specific IDG provisions, public-sector duties, kantonale DSB rulings worth knowing.
Classic FAQ: legal/rights side vs technical/CIA side; how they overlap in TOMs.
FINMA RS 23/01 op-risk, outsourcing RS 18/03 mapping against DORA's 5 pillars.
Step-by-step to building a RoI: data points, ESA reporting template, supplier criticality classification.
Pillar: 5 DORA pillars, ICT third-party risk, Register of Information, TLPT, intersection with FINMA RS 23/01, incident reporting.
When DORA reaches Swiss financial entities (EU branch/sub, EU customers, ICT TPP serving EU FE).
Detail to companion #25: phased entry into force, sandbox provisions, GPAI codes of practice timing.
Pillar: extraterritoriality, risk pyramid, GPAI tier, phased deadlines (02/2025–08/2027), interaction with nDSG/DSGVO/sectoral CH law.
When the external DSB model fits, typical SLAs/scope, monthly retainer ranges, conflict-of-interest considerations.
Authoritative explainer of the Eidg. Datenschutz- und Öffentlichkeitsbeauftragter, structure, sanctions powers under nDSG, recent rulings.
8-point flow: lawful basis, ROPA, info notice, AVV, breach, DSFA, transfers, governance.
Pillar: Art. 5/6/13/14/15-22/24/25/30/32/33/35/37, the 12 obligation clusters mapped to concrete deliverables.
Cookie/tracker scanners (CookieBot, Usercentrics, OneTrust) vs legal-substance audits; where the line is.
Article-by-article TL;DR, Art. 1–99 in 1-sentence summaries grouped by chapter.
When does a Swiss-only business additionally fall under DSGVO; what extra obligations arise; how Art. 27 representation works.
Pillar: extraterritorial reach (Art. 3), when a Swiss company falls under GDPR, EU-Vertreter requirement, fines, parallel application with nDSG.
What an ISB does, where it differs from CISO, when external ISB-aaS makes sense, typical mandates.
Pillar: standards landscape (ISO 27001/27002/27005/27701/NIST CSF/CIS18/BSI), CH-specific overlays (ISG, FINMA), role of ISB/CISO/DSB.
Business-profile data flows to Meta, Insights data, bio-link notice, Schrems-aftermath U.S. transfer.
Risks of using WhatsApp/WhatsApp Business in CH organisations: contact-list scraping, US transfers, employer-DPA gap, alternatives.
Annex A restructure (114→93 controls, 4 themes, 11 new), management-system clause edits, transition timeline (closed 31 Oct 2025).
Annual plan structure, sampling, evidence types, nonconformity classification, OPI/CAPA loop.
Stage 1 / Stage 2 / surveillance / re-cert flow, accredited CBs in CH, realistic 12–18 month timeline, cost ranges by company size.
Annex A 2022 controls grouped (organisational/people/physical/technological) with applicability questions and evidence prompts.
Pillar: history, 2022 revision, clauses 4–10, Annex A, certification path, integration with nDSG/DSGVO/NIS2/DORA.
Internal-effort vs consulting vs CB-fee breakdown by FTE bracket (<25 / 25–250 / >250).
Lean ISMS pattern: narrow scope, owner-driven risk, minimal documentation set, what auditors expect.
What changes in year-3 audit vs surveillance, how to prepare, what management review must cover.
SoA columns explained, mapping of risk treatment to A.5–A.8 controls, common audit findings, template.
How ISO 27701 extends 27001, controller vs processor controls, mapping to DSGVO/nDSG, joint audit feasibility.
Jimdo's built-in generator vs custom drafting; CH-specific gaps to plug.
EU Data Boundary, customer key, sensitivity labels, audit logs, transfer-impact, configuration baselines.
Tenant data-boundary, Sensitivity Labels, DLP, MIP integration with Copilot, audit logs, training-data carve-out.
Chat retention, recording/transcription, eDiscovery vs nDSG access rights, sensitivity labels in Teams.
ISG (Informationssicherheitsgesetz) reporting duty for critical infrastructures, who is in scope, what counts as 'erheblicher Cyberangriff', timelines.
Up-to-date overview of the cyber-incident reporting regime for KRITIS operators after the ISG entered into force.
Art. 60–66 nDSG: personal criminal liability of individuals (CHF 250'000), constellations, evidentiary practice, comparison with DSGVO.
Side-by-side: scope, lawful bases, breach window, DSB requirement, fines, profiling, automated decisions, transfers, kid-consent age.
Pillar: scope (essential vs important), why CH groups with EU subs are pulled in, supply-chain pull-through, ISO 27001 ↔ NIS2 mapping.
Decision-tree: EU establishment, sector match, size thresholds, supply-chain pull-through. Print-ready flow.
Art. 21 NIS2 supplier risk-management, contractual flow-down patterns, real-world auditor expectations.
Side-by-side: which Annex A controls cover which NIS2 minimum measures (Art. 21(2)), remaining gaps to close.
Scoping, the three knowledge-levels, OSSTMM/PTES standards, retest cycles, reporting expectations.
Practical: campaign cadence, lure types, just-in-time training, click-rate vs report-rate as the right KPI pair.
Cavoukian's 7 principles mapped to Art. 7 nDSG and Art. 25 DSGVO with concrete dev/product checkpoints.
Honest comparison of the leading CH privacy-policy generators on coverage of nDSG vs DSGVO, integrations, multi-language, audit trail.
Field-by-field annotation of an nDSG-compliant data-protection notice with copy-paste blocks.
What each engagement type is, when to choose which, deliverables, MITRE ATT&CK overlay.
Post-DPF (Data Privacy Framework) state of play, transfer-impact-assessment (TIA) practice, residual risk for non-DPF US recipients.
Vendor landscape (KnowBe4, SoSafe, Hoxhunt, Mimecast), campaign rhythm, click-rate baselining, board reporting.
Shopify's processor stance, app vetting, EU-customer-data handling, cookie/pixel apps under nDSG.
When MDR/SOC-aaS pays off, key vendor selection criteria, integration scope, CH data residency considerations.
Readdle's mail-proxy architecture, OAuth scopes, OPTI-In vs OPT-Out, CH risk view.
Module choice (1–4), Swiss addendum, docking-clause, TIA companion, sub-processor flow-down.
Recap of headline themes/talks/booths plus annual prep guide for attendees.
Auftragsbearbeitung under Art. 9 nDSG vs Art. 28 DSGVO, must-have clauses, sub-processor handling, audit rights, template.
The DSB role under Art. 10 nDSG, voluntary in CH unlike DSGVO, but practical reasons to appoint; required skill set; reporting line; independence.
Practical 28-point list a Swiss SME can run through in 1 hour, covers Verzeichnis, DSFA trigger, AVV inventory, TOMs, breach response, EU-Vertreter check.
Buyer-intent article comparing generator tools and explaining how SIDD's flow plugs into an internal Verzeichnis.
Pillar piece: scope, definitions, principles, rights, obligations, breach regime, sanctions, role of EDÖB, every link cluster anchors here.
Pillar: Art. 19/20 nDSG mandatory items + multilingual handling + interaction with DSGVO Art. 13/14 if both apply.
Online generator/template article showing every clause that the revised nDSG (Art. 19, 13, 20) requires in a Swiss privacy policy; differentiates from DSGVO…
Downloadable template walkthrough, what each section must contain under nDSG Art. 19/20 and how to adapt for cantonal IDG.
TIBER-EU lineage, frequency (3y), scope, RTI/CTI/TI providers, test-team accreditation, deliverables.
Automated scanning (Tenable/Qualys/OpenVAS) vs human pentest; risk profiles where one suffices.
Embedding the privacy notice in a CMS (WordPress/Webflow/Wix), cookie-consent integration, footer links, multi-language handling.
Disambiguation: DSG (Datenschutzgesetz) vs DSG (Direktschaltgetriebe), focused on the law side.
Definitional piece for early-stage SERP, personal data, principles, the two regimes most relevant in CH (nDSG/DSGVO).
Wix's data flows, GDPR pages, where to fix for nDSG, third-party apps in App Market.
The 2025 data protection trends bundle the regulatory and technical developments most relevant for Swiss companies. This article positions the AI Act, DORA, FINMA expectations and FDPIC practice in concrete terms.
Administrative court proceedings between controllers and supervisory authorities in Mecklenburg-Vorpommern concretise the requirements for GDPR implementation. The article situates the structural lessons and transfers them to DACH practice.
The Swiss DSG (Federal Act on Data Protection / FADP) has applied since 1 September 2023. This article analyses the legal framework, the duties of controllers and the role of the FDPIC.
Consent in the employment relationship means the explicit agreement by employees to the processing of their personal data. Because of the power imbalance, it is rarely the right legal basis in Switzerland.
The German C5 Equivalence Ordinance defines which cloud security attestations are recognised as equivalent within the scope of the C5 catalogue. It has indirect but relevant implications for Swiss cloud consumers and providers.
CJEU case law has been concretising the interpretation of the GDPR since 2018 and increasingly shapes the application of the Swiss DSG. The article analyses the key lines and derives concrete duties for controllers in the DACH region.
Data protection in the digital age means handling personal data lawfully across connected, automated and cloud-based processes. This guide sets out six concrete challenges for Swiss organisations.
The Swiss DSG (FADP) sits within a dense network of international requirements. This article positions adequacy, the DPF, SCCs and BCRs, and the tension between DSG, GDPR and the US CLOUD Act.
Data security under Swiss law requires risk-based technical and organizational measures (TOMs) under Art. 8 DSG. This guide shows how to map those requirements concretely onto ISO/IEC 27001:2022 Annex A.
Inquiry IN-19-9-3 of Ireland's Data Protection Commission targeted Meta Platforms Ireland and concretised the legal bases for contract-based processing. The article analyses the decision and transfers it to DACH practice.
The preliminary reference C-383/23 ILVA concerns the interpretation of Art. 83 GDPR and in particular the relevant turnover concept for fine calculation. The article analyses the procedural questions and derives consequences for DACH compliance.
Swiss occupational pension funds (Pensionskassen) process special-category personal data of the second pillar and are subject simultaneously to BVG supervision and DSG duties. This guide shows how both regimes can be combined in practice.
Browser extensions are small programs with far-reaching access to the entire web traffic. This analysis sets out the permission model, typical attack patterns and how organisations can protect themselves, using Microsoft Edge add-ons as the worked example.
AI data protection in Switzerland refers to the duty, when using ChatGPT, Copilot or in-house models, to comply with the DSG and to observe EU rules wherever they apply extraterritorially.
FINMA supervisory notice 03/2024 specifies the expectations on cyber risk management for supervised institutions. It summarises lessons from notifications under Art. 29 FINMASA and sharpens supervisory practice and audit focus.
The C5 attestation is a cloud assurance report defined by BSI and issued under ISAE 3000. It assesses whether a cloud provider meets the C5 catalogue requirements and is gaining relevance for Swiss cloud consumers.
In proceeding EXP202213023 the AEPD (Agencia Española de Protección de Datos) sanctioned the deficient implementation of the right to erasure. The article situates the fine and transfers the lessons to GDPR and Swiss DSG compliance for Swiss controllers.
FINMA Circular 2023/01 'Operational Risks and Resilience - Banks' has been in force since 1 January 2024. It consolidates the requirements on operational risk management, ICT risks and operational resilience.
This article explores the intersection of data protection and artificial intelligence by examining both the legal and technical challenges, as well as the opportunities that arise from their interaction.
In a recent case handled by the Spanish Data Protection Authority (AEPD), the role of consent as a fundamental basis for lawful personal data processing was highlighted. The case emphasizes the significance of transparent communication and clearly defined processes in data management to ensure compliance with data protection laws.
With the rapid growth of artificial intelligence (AI), regulatory frameworks face complex challenges. Switzerland is actively working on establishing a framework to ensure fairness, transparency, and accountability.
This article explores the implications of Case C-413/23, EDPS v. SRB, for Switzerland, focusing in particular on the associated data protection challenges and strategies for addressing them.
The introduction of artificial intelligence (AI) in financial institutions offers numerous benefits but also presents regulatory challenges. The Federal Financial Market Supervisory Authority (FINMA) has developed guidelines to ensure the safe use of AI.
The EDPB has imposed a landmark ban on Meta involving the use of personal data without express consent. This article explains why this ban was enacted, which legal framework is affected, and what effects it could have on companies in Switzerland.
In the digital economy, contract processors play a crucial role in data protection. These experts help those responsible for data processing meet numerous obligations under the GDPR. In this article, we explore the roles and responsibilities of contract processors in Switzerland.
Data breaches pose a significant threat to businesses. This article outlines the recommendations from the Federal Data Protection and Information Commissioner (FDPIC) on how to effectively handle such incidents.
The European Commission has published clear guidelines on the concept of an AI system. This article highlights their significance, the impact on Swiss legislation and future measures to ensure data protection.
Compliance in an increasingly digital world can be complex. In Switzerland, the use of artificial intelligence (AI) presents a promising solution for automating and optimizing compliance processes while ensuring adherence to data protection regulations.
This article examines the implications of the European Court of Justice (ECJ) ruling on the concept of data protection fines under the GDPR and explores the potential consequences for companies in Switzerland. Particular attention is given to how this ruling may influence enforcement practices, legal certainty, and risk management for cross-border data processing activities.
The use of cookies and similar technologies is widespread, but many companies face challenges in complying with privacy regulations. This overview of the FDPIC guidelines provides clear instructions and recommendations for implementing these technologies in accordance with data protection laws.
Fingerprint tracking allows companies to identify users without using traditional cookies. This potentially constitutes a circumvention of European data protection guidelines and could also raise data protection concerns in Switzerland.
The use of AI technologies presents both opportunities and risks for Swiss companies. In this article, we examine the key legal aspects and provide guidance on ensuring compliance with data protection regulations.
Implementing ISO 27001 presents companies with a decision: Develop it in-house or use a packaged solution? This analysis highlights the benefits of both approaches, particularly in the context of the Swiss data protection landscape.
Get expert advice on how to successfully achieve ISO 27001 certification.
Master the ISO 27001 audit process in 30 days with our comprehensive guide.
Discover the basics of compliance with Article 27 of the GDPR. Learn more about EU representatives, exemptions, and key obligations.
The Future of Data Protection in the Light of the Digital Operational Resilience Act (DORA) and Its Impact on the Financial Sector
The Data Protection Aspects of Corporate Acquisition/M&A, Be It Share Deals (Share Acquisition) or Asset Deals
On December 14, 2023, the Bundestag adopted a bill to speed up digitization.
FADP Audit in Switzerland: What Changes Are Relevant for Your Company or SME
Activity Reports from European Data Protection Authorities
ISO 27001 Certification is Becoming Increasingly Important for Small and Medium-Sized Enterprises (SMEs)
Learn how to become a Data Protection Officer with those 5 steps.
With external data protection officers, you gain security.
Data Protection Law requires a risk-based Approach in defining TOM
Data Protection, Consultants, and Management Systems as Key Elements of Compliance
Reliable Data Protection as a Key Differentiator for Your Start-Up or ICT Company
How to Start, Implement, and Successfully Complete a Data Protection Project
The Future of Data Protection in the Light of the Role of the EU Representative for Companies Outside the European Union
In accordance with Article 4(12) GDPR, a personal data breach refers to a security violation.