Insights

Our SIDD team carefully curates the latest information on data protection, information security and artificial intelligence to keep you up to date. Use the search field to find articles by specific keywords. You can subscribe to our newsletter for free below.

OUR LATEST ‘INSIGHTS’

Categories
kunstliche-intelligenz

EU AI Act for Medical AI, Your Healthcare Action Plan

A practical action plan for the EU AI Act and medical AI: which systems are high-risk, how the AI Act dovetails with MDR/IVDR, and why an inventory and classification now matter more than any deadline.

infosec

The 24-Hour Reporting Duty for Hospitals, ISG/BACS in Practice

What a hospital must report, how the clock runs, what BACS expects, including a reporting workflow to rehearse in a tabletop and the distinction from NIS2.

kunstliche-intelligenz

The EU AI Act for B2B SaaS With AI Features: What to Classify Now

What the EU AI Act means for B2B SaaS providers shipping AI features: transparency duties for most, high-risk for some, GPAI duties for model providers, the provider vs deployer split, and how it interlocks with your DPA and the vendor security review.

infosec

Answer Security Questionnaires Faster: A Trust Center and Answer Library for B2B SaaS

A practical guide for B2B SaaS: answer CAIQ, SIG and bespoke security questionnaires faster, build a trust center, and stop deals stalling in procurement.

infosec

SOC 2 vs ISO 27001 for B2B SaaS: A Decision Guide for Vendor Security Reviews

SOC 2 or ISO 27001 first? A decision guide for B2B SaaS providers who want to answer customer security questionnaires fast and win the deal.

infosec

Choosing a Healthcare Security and Data-Protection Partner, A Decision Guide

A neutral decision guide for hospitals, practices and HealthTech: which criteria matter when choosing a security and data-protection partner, with a buyer's checklist.

datenschutz

Processing for B2B SaaS Vendors – GDPR Art. 28, the Swiss nDSG and the DPA Customers Demand

Legal guide for SaaS vendors as processors: GDPR Art. 28, Swiss nDSG, the DPA, sub-processor list, ROPA Art. 30(2), Art. 32, 72h notice, SCCs and TIA. With a checklist.

infosec

Supply-Chain and Third-Party Risk in Healthcare – The Hospital Blind Spot

Cloud, EHR and MedTech suppliers are part of your liability: due diligence, risk tiering, contractual controls, DPAs, ISMS integration (A.5.19–A.5.23) and continuity escrow.

alle

FINMA Risk Monitor 2024: Cyber Threats and Market Volatility in Detail

The FINMA Risk Monitor 2024 is the annual situational assessment by the Swiss Financial Market Supervisory Authority. It prioritises cyber risks, third-party dependencies and market volatility as central supervisory focus areas for 2025.

infosec

You Don't Treat Your Own Toothache – So Why Treat Your Own Cyber Risk?

Sick → doctor. Taxes → accountant. Machine down → technician. Cyber attack → "our IT guy handles that." Why that one reflex is the most expensive line in your P&L.

kunstliche-intelligenz

High-Risk AI Systems, How to Tell If You're In Scope

Annex III walkthrough with concrete examples, exemption pathways, conformity-assessment obligations.

kunstliche-intelligenz

AI Act × nDSG × GDPR, Where Three Regimes Overlap

Article-level mapping: where AI Act conformity overlaps with DSFA/DPIA, automated-decision rules, transparency duties.

kunstliche-intelligenz

Prohibited AI Practices Under the AI Act, Examples for Swiss SMEs

Art. 5 prohibited practices (since Feb 2025) with realistic scenarios (HR scoring, workplace emotion AI, real-time biometric).

kunstliche-intelligenz

AI Policy Template for Swiss SMEs

Ready-to-adapt internal AI usage policy: permitted tools, data categories, IP/confidentiality, human-in-the-loop, incident reporting.

kunstliche-intelligenz

AI Regulation Switzerland, 2026 Status and Outlook

Federal Council consultation outcome, sector-specific overlays (FINMA, Swissmedic), EDÖB positions on AI.

infosec

Building an ISMS, Step-by-Step to ISO 27001

12-step roadmap: scope, GAP, risk method, SoA, control implementation, internal audit, management review, Stage 1/2 audit.

datenschutz

Setting Up Calendly in a GDPR/nDSG-Compliant Way

Calendly DPA, data flows, EU-region option, embedding & cookie behaviour, alternative tools.

kunstliche-intelligenz

ChatGPT at Work, What Swiss Employers Must Regulate

Practical playbook: AUP, data-classification rules, prompt-leak risks, OpenAI's data handling, employer monitoring limits.

datenschutz

Cookie Banner Switzerland: nDSG-Compliant Setup (Templates)

How nDSG/UWG/Telekommunikationsgesetz interact for cookies in CH (different from DSGVO opt-in regime); concrete banner templates.

datenschutz

Cookie Banners & Tracking: nDSG Obligations in Detail

Deep-dive into the legal anchors for cookies in CH: nDSG, FMG/UWG-art-3, eIDAS, when consent is required, when info notice suffices.

infosec

Cyber Security Switzerland, Consulting, Audits, Awareness

Service-page-style overview of how a CH security consultancy structures its offer: assessment, ISMS, pentest, awareness, SOC.

infosec

Cyber Security for Swiss Companies, The 2026 Guide

Pillar: threat landscape CH 2026, NCSC/BACS, ISG, key controls (CIS18-mapped), incident handling, KMU vs Konzern priorities.

datenschutz

Reporting a Data Breach to the FDPIC, 5-Step Guide

Practical workflow: detection → assessment of 'high risk' → 72h notification path → contents of notification (Art. 24 nDSG) → data subject notice trigger.

datenschutz

Data Protection in Aargau

AG IDAG specifics, kantonaler DSB, industrial KMU privacy profile.

datenschutz

Data Protection in Basel-Stadt

BS IDG-overlay, cross-border German employee context, pharma-cluster privacy demands.

datenschutz

Data Protection Bern, nDSG and Cantonal KDSG

BE-specific KDSG, two-tier kantonale/kommunale structure, kantonaler DSB practice.

datenschutz

Data Protection Geneva, Cantonal LIPAD and Federal nDSG

GE LIPAD overlay (public-sector + transparency), bilingual practice, international-organisation data handling.

datenschutz

Data Protection for Hotels and Hospitality

PMS choice, payment data, marketing consent, Schengen meldedienst (Art. 16 AuG), loyalty programmes.

datenschutz

Data Protection for Insurers and Brokers

VVG/VAG + nDSG intersection, claims data, profiling under AI Act, FINMA-VersAG reporting.

datenschutz

Data Protection for Law Firms, Attorney–Client Privilege × nDSG

Art. 13 BGFA Berufsgeheimnis vs nDSG access rights, ediscovery/cross-border production, cloud-hosting of mandate files.

datenschutz

Data Protection in Lucerne

LU ÖDSG / kantonale DSB office, tourism and hospitality data flows.

datenschutz

Data Protection Officer in the Canton of Zurich

Local market overview: which ZH industries demand DSB-aaS, intersection with kantonales IDG-ZH and the public-sector DSB regime.

datenschutz

Data Protection Officer, When Does My Company Need One?

DSGVO Art. 37 mandatory triggers, voluntary CH DSB role, comparison of internal vs external/CISO-DSB conflicts.

datenschutz

Data Protection in Real Estate Management

Tenant data, applicant screening, surveillance cameras in buildings, OR-Mietrecht intersection.

datenschutz

Data Protection in Schools and Education Institutions

Kantonale Schulgesetze + IDG overlay, parental consent for under-16s, learning analytics, M365 in schools.

datenschutz

Data Protection in St. Gallen

SG DSG-SG, financial-services & textile-industry data context.

datenschutz

Data Protection for Swiss Associations

ZGB-association governance, member-data handling, photo publishing, newsletter & event consent rules.

datenschutz

Data Protection in Swiss Medical Practices, nDSG, Patient Records, EPR

Berufsgeheimnis (Art. 321 StGB), KVG/EPDG/ePD obligations, GDK-recommendations, practical TOMs.

datenschutz

Data Protection in Swiss Online Shops

Checkout flow privacy notice, Trusted-Shops, retargeting cookies, payment-data handling, UWG obligations.

datenschutz

Data Protection for Swiss Trustees, FINMA, Banking Secrecy, nDSG

Article 47 BankG bank secrecy meets nDSG and FINMA outsourcing rules; cross-border tax info flows.

datenschutz

Data Protection Zug, DPO for Crypto Valley Companies

ZG ÖDSG, FINMA-DLT intersection, KYC/AML-data handling at crypto-valley firms.

datenschutz

Data Protection Zurich, nDSG and Cantonal IDG

ZH-specific IDG provisions, public-sector duties, kantonale DSB rulings worth knowing.

datenschutz

Data Security vs Data Protection, The Difference Simply Explained

Classic FAQ: legal/rights side vs technical/CIA side; how they overlap in TOMs.

infosec

DORA × FINMA, Where the Regimes Overlap and Where They Don't

FINMA RS 23/01 op-risk, outsourcing RS 18/03 mapping against DORA's 5 pillars.

infosec

DORA ICT Third-Party Risk & Register of Information

Step-by-step to building a RoI: data points, ESA reporting template, supplier criticality classification.

infosec

DORA, Operational Resilience Duties for Swiss Financial Services

Pillar: 5 DORA pillars, ICT third-party risk, Register of Information, TLPT, intersection with FINMA RS 23/01, incident reporting.

infosec

DORA Switzerland, What FINMA-Regulated EU Cross-Border Actors Must Implement

When DORA reaches Swiss financial entities (EU branch/sub, EU customers, ICT TPP serving EU FE).

kunstliche-intelligenz

EU AI Act, Phases, Obligations, Deadlines for Swiss Companies

Detail to companion #25: phased entry into force, sandbox provisions, GPAI codes of practice timing.

kunstliche-intelligenz

EU AI Act, The Guide for Swiss Companies

Pillar: extraterritoriality, risk pyramid, GPAI tier, phased deadlines (02/2025–08/2027), interaction with nDSG/DSGVO/sectoral CH law.

datenschutz

External Data Protection Officer Switzerland, Model, Costs, Use Cases

When the external DSB model fits, typical SLAs/scope, monthly retainer ranges, conflict-of-interest considerations.

datenschutz

FDPIC (EDÖB), Tasks, Powers and Reporting Channels Explained

Authoritative explainer of the Eidg. Datenschutz- und Öffentlichkeitsbeauftragter, structure, sanctions powers under nDSG, recent rulings.

datenschutz

GDPR Compliance, The 8-Point Self-Assessment

8-point flow: lawful basis, ROPA, info notice, AVV, breach, DSFA, transfers, governance.

datenschutz

GDPR Explained, The 12 Most Important Obligations

Pillar: Art. 5/6/13/14/15-22/24/25/30/32/33/35/37, the 12 obligation clusters mapped to concrete deliverables.

datenschutz

GDPR Scanners & Audit Tools, What They Measure and What They Miss

Cookie/tracker scanners (CookieBot, Usercentrics, OneTrust) vs legal-substance audits; where the line is.

datenschutz

GDPR Summary, The Key Articles on One Page

Article-by-article TL;DR, Art. 1–99 in 1-sentence summaries grouped by chapter.

datenschutz

GDPR Switzerland Checklist – What Applies Beyond the nDSG

When does a Swiss-only business additionally fall under DSGVO; what extra obligations arise; how Art. 27 representation works.

datenschutz

GDPR Switzerland, What Swiss Companies Need to Know

Pillar: extraterritorial reach (Art. 3), when a Swiss company falls under GDPR, EU-Vertreter requirement, fines, parallel application with nDSG.

infosec

Information Security Officer (ISB) as a Service

What an ISB does, where it differs from CISO, when external ISB-aaS makes sense, typical mandates.

infosec

Information Security, Standards, Roles and Duties in Switzerland

Pillar: standards landscape (ISO 27001/27002/27005/27701/NIST CSF/CIS18/BSI), CH-specific overlays (ISG, FINMA), role of ISB/CISO/DSB.

datenschutz

Instagram Profile under GDPR/nDSG, Privacy Notice and Duties

Business-profile data flows to Meta, Insights data, bio-link notice, Schrems-aftermath U.S. transfer.

datenschutz

Is WhatsApp GDPR-Compliant?, 2026 Update

Risks of using WhatsApp/WhatsApp Business in CH organisations: contact-list scraping, US transfers, employer-DPA gap, alternatives.

infosec

ISO 27001:2022, What Has Actually Changed Since 2013

Annex A restructure (114→93 controls, 4 themes, 11 new), management-system clause edits, transition timeline (closed 31 Oct 2025).

infosec

ISO 27001 Audit, Internal Audit Plan & Template

Annual plan structure, sampling, evidence types, nonconformity classification, OPI/CAPA loop.

infosec

ISO 27001 Certification Switzerland, Process, Timeline, Costs

Stage 1 / Stage 2 / surveillance / re-cert flow, accredited CBs in CH, realistic 12–18 month timeline, cost ranges by company size.

infosec

ISO 27001:2022 Checklist, 93 Controls as Self-Assessment

Annex A 2022 controls grouped (organisational/people/physical/technological) with applicability questions and evidence prompts.

infosec

ISO 27001, The Complete Guide for 2026

Pillar: history, 2022 revision, clauses 4–10, Annex A, certification path, integration with nDSG/DSGVO/NIS2/DORA.

infosec

ISO 27001 Certification Costs, Realistic Range for Swiss SMEs

Internal-effort vs consulting vs CB-fee breakdown by FTE bracket (<25 / 25–250 / >250).

infosec

ISO 27001 for SMEs, A Simplified Scope Approach

Lean ISMS pattern: narrow scope, owner-driven risk, minimal documentation set, what auditors expect.

infosec

ISO 27001 Recertification After 3 Years

What changes in year-3 audit vs surveillance, how to prepare, what management review must cover.

infosec

ISO 27001:2022, Building a Correct Statement of Applicability

SoA columns explained, mapping of risk treatment to A.5–A.8 controls, common audit findings, template.

infosec

ISO 27701, Layering PIMS on Top of ISO 27001

How ISO 27701 extends 27001, controller vs processor controls, mapping to DSGVO/nDSG, joint audit feasibility.

datenschutz

Jimdo Privacy Policy Switzerland

Jimdo's built-in generator vs custom drafting; CH-specific gaps to plug.

datenschutz

Running Microsoft 365 in a Privacy-Compliant Way in Switzerland

EU Data Boundary, customer key, sensitivity labels, audit logs, transfer-impact, configuration baselines.

kunstliche-intelligenz

Microsoft Copilot Data Protection, Configuring the M365 Tenant Properly

Tenant data-boundary, Sensitivity Labels, DLP, MIP integration with Copilot, audit logs, training-data carve-out.

datenschutz

Microsoft Teams Data Protection, Swiss Configuration Guide

Chat retention, recording/transcription, eDiscovery vs nDSG access rights, sensitivity labels in Teams.

infosec

NCSC / BACS, When Swiss Companies Must Report Cyber Incidents

ISG (Informationssicherheitsgesetz) reporting duty for critical infrastructures, who is in scope, what counts as 'erheblicher Cyberangriff', timelines.

infosec

NCSC Switzerland, Critical Infrastructure Reporting Duties in 2026

Up-to-date overview of the cyber-incident reporting regime for KRITIS operators after the ISG entered into force.

datenschutz

nDSG Fines, Who Is Personally Liable, and How Much

Art. 60–66 nDSG: personal criminal liability of individuals (CHF 250'000), constellations, evidentiary practice, comparison with DSGVO.

datenschutz

Swiss nDSG vs EU GDPR, The 12 Most Important Differences for SMEs

Side-by-side: scope, lawful bases, breach window, DSB requirement, fines, profiling, automated decisions, transfers, kid-consent age.

infosec

NIS2 Directive, What Swiss Groups with EU Exposure Must Do

Pillar: scope (essential vs important), why CH groups with EU subs are pulled in, supply-chain pull-through, ISO 27001 ↔ NIS2 mapping.

infosec

NIS2, Does My Swiss Company Fall Under It? Self-Assessment

Decision-tree: EU establishment, sector match, size thresholds, supply-chain pull-through. Print-ready flow.

infosec

NIS2 Supply-Chain Obligations, What Awaits Swiss Suppliers

Art. 21 NIS2 supplier risk-management, contractual flow-down patterns, real-world auditor expectations.

infosec

NIS2 vs ISO 27001, Gap Analysis With Mapping Table

Side-by-side: which Annex A controls cover which NIS2 minimum measures (Art. 21(2)), remaining gaps to close.

infosec

Penetration Testing Switzerland, Black/Grey/White-Box Compared

Scoping, the three knowledge-levels, OSSTMM/PTES standards, retest cycles, reporting expectations.

infosec

Phishing Simulation for SMEs, Setup, KPIs, Reporting

Practical: campaign cadence, lure types, just-in-time training, click-rate vs report-rate as the right KPI pair.

datenschutz

Privacy by Design in Swiss Law, 7 Principles

Cavoukian's 7 principles mapped to Art. 7 nDSG and Art. 25 DSGVO with concrete dev/product checkpoints.

datenschutz

Privacy Policy Generator Comparison: SIDD vs Swissanwalt vs ActiveMind

Honest comparison of the leading CH privacy-policy generators on coverage of nDSG vs DSGVO, integrations, multi-language, audit trail.

datenschutz

Privacy Policy Template, Mandatory Content Under nDSG 2026

Field-by-field annotation of an nDSG-compliant data-protection notice with copy-paste blocks.

infosec

Red Team / Blue Team / Purple Team, Concepts & Use Cases

What each engagement type is, when to choose which, deliverables, MITRE ATT&CK overlay.

datenschutz

Schrems II for Swiss Companies, What It Still Means Today

Post-DPF (Data Privacy Framework) state of play, transfer-impact-assessment (TIA) practice, residual risk for non-DPF US recipients.

infosec

Security Awareness Training Switzerland, Vendors, Setup, KPIs

Vendor landscape (KnowBe4, SoSafe, Hoxhunt, Mimecast), campaign rhythm, click-rate baselining, board reporting.

datenschutz

Shopify Privacy Policy Switzerland, Setup Guide

Shopify's processor stance, app vetting, EU-customer-data handling, cookie/pixel apps under nDSG.

infosec

SOC as a Service Switzerland, Buyer's Guide 2026

When MDR/SOC-aaS pays off, key vendor selection criteria, integration scope, CH data residency considerations.

datenschutz

Spark Mail Data Protection, What IT Admins Need to Know

Readdle's mail-proxy architecture, OAuth scopes, OPTI-In vs OPT-Out, CH risk view.

datenschutz

Using Standard Contractual Clauses (SCCs) Correctly

Module choice (1–4), Swiss addendum, docking-clause, TIA companion, sub-processor flow-down.

infosec

Swiss Cyber Security Days 2026, Recap & Conference Guide

Recap of headline themes/talks/booths plus annual prep guide for attendees.

datenschutz

Swiss Data Processing Agreement (AVV), Template + Explanation

Auftragsbearbeitung under Art. 9 nDSG vs Art. 28 DSGVO, must-have clauses, sub-processor handling, audit rights, template.

datenschutz

Swiss Data Protection Advisor, Duty, Role, Skill Profile

The DSB role under Art. 10 nDSG, voluntary in CH unlike DSGVO, but practical reasons to appoint; required skill set; reporting line; independence.

datenschutz

Swiss Data Protection Checklist: 28-Point nDSG Self-Assessment

Practical 28-point list a Swiss SME can run through in 1 hour, covers Verzeichnis, DSFA trigger, AVV inventory, TOMs, breach response, EU-Vertreter check.

datenschutz

Swiss Privacy Policy Generator: Free Online Builder

Buyer-intent article comparing generator tools and explaining how SIDD's flow plugs into an internal Verzeichnis.

datenschutz

Swiss Federal Act on Data Protection (nDSG), The Complete Guide

Pillar piece: scope, definitions, principles, rights, obligations, breach regime, sanctions, role of EDÖB, every link cluster anchors here.

datenschutz

Swiss Privacy Policy, Everything That Belongs in It in 2026

Pillar: Art. 19/20 nDSG mandatory items + multilingual handling + interaction with DSGVO Art. 13/14 if both apply.

datenschutz

Swiss Privacy Policy – nDSG-Compliant Generator 2026

Online generator/template article showing every clause that the revised nDSG (Art. 19, 13, 20) requires in a Swiss privacy policy; differentiates from DSGVO…

datenschutz

Swiss Privacy Policy Template (nDSG 2026, Free)

Downloadable template walkthrough, what each section must contain under nDSG Art. 19/20 and how to adapt for cantonal IDG.

infosec

Threat-Led Penetration Testing (TLPT) Under DORA

TIBER-EU lineage, frequency (3y), scope, RTI/CTI/TI providers, test-team accreditation, deliverables.

infosec

Vulnerability Scan vs Pentest, When Is Each Enough?

Automated scanning (Tenable/Qualys/OpenVAS) vs human pentest; risk profiles where one suffices.

datenschutz

Website Privacy Policy Switzerland: Template + Implementation Guide

Embedding the privacy notice in a CMS (WordPress/Webflow/Wix), cookie-consent integration, footer links, multi-language handling.

datenschutz

What Does "DSG" Mean?, The Legal Definition in 90 Seconds

Disambiguation: DSG (Datenschutzgesetz) vs DSG (Direktschaltgetriebe), focused on the law side.

datenschutz

What Is Data Protection?, A Quick Introduction

Definitional piece for early-stage SERP, personal data, principles, the two regimes most relevant in CH (nDSG/DSGVO).

datenschutz

Wix Privacy Policy Switzerland

Wix's data flows, GDPR pages, where to fix for nDSG, third-party apps in App Market.

alle

Data Protection Trends 2025: Insights for Swiss Companies

The 2025 data protection trends bundle the regulatory and technical developments most relevant for Swiss companies. This article positions the AI Act, DORA, FINMA expectations and FDPIC practice in concrete terms.

alle

Data Protection Case Law in Mecklenburg-Vorpommern: Structural Lessons for DACH Controllers

Administrative court proceedings between controllers and supervisory authorities in Mecklenburg-Vorpommern concretise the requirements for GDPR implementation. The article situates the structural lessons and transfers them to DACH practice.

alle

Data Protection in Switzerland: the Legal Framework in Detail

The Swiss DSG (Federal Act on Data Protection / FADP) has applied since 1 September 2023. This article analyses the legal framework, the duties of controllers and the role of the FDPIC.

alle

Employee Consent: When It Holds Up, When It Does Not

Consent in the employment relationship means the explicit agreement by employees to the processing of their personal data. Because of the power imbalance, it is rarely the right legal basis in Switzerland.

alle

C5 Equivalence Ordinance: Impact on Data Protection in Switzerland

The German C5 Equivalence Ordinance defines which cloud security attestations are recognised as equivalent within the scope of the C5 catalogue. It has indirect but relevant implications for Swiss cloud consumers and providers.

alle

GDPR in the Mirror of CJEU Case Law: Lines, Trends and Consequences for DACH Controllers

CJEU case law has been concretising the interpretation of the GDPR since 2018 and increasingly shapes the application of the Swiss DSG. The article analyses the key lines and derives concrete duties for controllers in the DACH region.

alle

Data Protection Challenges in the Digital Age: A Swiss Guide

Data protection in the digital age means handling personal data lawfully across connected, automated and cloud-based processes. This guide sets out six concrete challenges for Swiss organisations.

alle

Swiss Data Protection Law in the International Context

The Swiss DSG (FADP) sits within a dense network of international requirements. This article positions adequacy, the DPF, SCCs and BCRs, and the tension between DSG, GDPR and the US CLOUD Act.

alle

Data Security in Switzerland: Best Practices under the DSG and ISO/IEC 27001

Data security under Swiss law requires risk-based technical and organizational measures (TOMs) under Art. 8 DSG. This guide shows how to map those requirements concretely onto ISO/IEC 27001:2022 Annex A.

alle

DPC Ireland IN-19-9-3: Structural Analysis of the Meta Decision and Consequences for DACH Controllers

Inquiry IN-19-9-3 of Ireland's Data Protection Commission targeted Meta Platforms Ireland and concretised the legal bases for contract-based processing. The article analyses the decision and transfers it to DACH practice.

alle

CJEU Preliminary Reference C-383/23 ILVA: Fine Calculation and the Undertaking Concept in GDPR Sanctioning Law

The preliminary reference C-383/23 ILVA concerns the interpretation of Art. 83 GDPR and in particular the relevant turnover concept for fine calculation. The article analyses the procedural questions and derives consequences for DACH compliance.

alle

Data Protection Obligations for Pension Funds in Switzerland

Swiss occupational pension funds (Pensionskassen) process special-category personal data of the second pillar and are subject simultaneously to BVG supervision and DSG duties. This guide shows how both regimes can be combined in practice.

alle

Data Security in Browser Extensions: An Examination of Microsoft Edge Add-ons

Browser extensions are small programs with far-reaching access to the entire web traffic. This analysis sets out the permission model, typical attack patterns and how organisations can protect themselves, using Microsoft Edge add-ons as the worked example.

alle

AI and Data Protection in Switzerland: Duties, Contracts, Security

AI data protection in Switzerland refers to the duty, when using ChatGPT, Copilot or in-house models, to comply with the DSG and to observe EU rules wherever they apply extraterritorially.

alle

FINMA Supervisory Notice 03/2024: Expectations on Cyber Risk Management

FINMA supervisory notice 03/2024 specifies the expectations on cyber risk management for supervised institutions. It summarises lessons from notifications under Art. 29 FINMASA and sharpens supervisory practice and audit focus.

alle

C5 Attestation: Relevance and Challenges in Switzerland

The C5 attestation is a cloud assurance report defined by BSI and issued under ISAE 3000. It assesses whether a cloud provider meets the C5 catalogue requirements and is gaining relevance for Swiss cloud consumers.

alle

AEPD Proceeding EXP202213023: What Swiss Companies Can Learn from the Spanish Fine

In proceeding EXP202213023 the AEPD (Agencia Española de Protección de Datos) sanctioned the deficient implementation of the right to erasure. The article situates the fine and transfers the lessons to GDPR and Swiss DSG compliance for Swiss controllers.

alle

Operational Risks and Resilience: FINMA Circular 2023/01 in Practice

FINMA Circular 2023/01 'Operational Risks and Resilience - Banks' has been in force since 1 January 2024. It consolidates the requirements on operational risk management, ICT risks and operational resilience.

kunstliche-intelligenz

Data Protection in the Era of Artificial Intelligence: Opportunities, Risks, and Regulatory Requirements in Switzerland

This article explores the intersection of data protection and artificial intelligence by examining both the legal and technical challenges, as well as the opportunities that arise from their interaction.

datenschutz

Analyzing a Spanish Data Protection Case: The Importance of Consent

In a recent case handled by the Spanish Data Protection Authority (AEPD), the role of consent as a fundamental basis for lawful personal data processing was highlighted. The case emphasizes the significance of transparent communication and clearly defined processes in data management to ensure compliance with data protection laws.

kunstliche-intelligenz

Regulation of Artificial Intelligence in Switzerland: A Deep Insight

With the rapid growth of artificial intelligence (AI), regulatory frameworks face complex challenges. Switzerland is actively working on establishing a framework to ensure fairness, transparency, and accountability.

datenschutz

Data Protection Challenges in Switzerland: Learning from Case C-413/23

This article explores the implications of Case C-413/23, EDPS v. SRB, for Switzerland, focusing in particular on the associated data protection challenges and strategies for addressing them.

datenschutz

Guidelines for the Use of Artificial Intelligence in Financial Institutions in Switzerland

The introduction of artificial intelligence (AI) in financial institutions offers numerous benefits but also presents regulatory challenges. The Federal Financial Market Supervisory Authority (FINMA) has developed guidelines to ensure the safe use of AI.

alle

EDPB Issues Ban on Meta's Processing of Personal Data

The EDPB has imposed a landmark ban on Meta involving the use of personal data without express consent. This article explains why this ban was enacted, which legal framework is affected, and what effects it could have on companies in Switzerland.

datenschutz

Obligations of Contract Processors under the GDPR

In the digital economy, contract processors play a crucial role in data protection. These experts help those responsible for data processing meet numerous obligations under the GDPR. In this article, we explore the roles and responsibilities of contract processors in Switzerland.

alle

Guidance on How to Deal with Data Breaches: Recommendations from the FDOEB

Data breaches pose a significant threat to businesses. This article outlines the recommendations from the Federal Data Protection and Information Commissioner (FDPIC) on how to effectively handle such incidents.

kunstliche-intelligenz

In-Depth Analysis of the EU Commission’s Guidelines on AI System Concepts

The European Commission has published clear guidelines on the concept of an AI system. This article highlights their significance, the impact on Swiss legislation and future measures to ensure data protection.

alle

Automating Compliance with AI in Switzerland: A Guide

Compliance in an increasingly digital world can be complex. In Switzerland, the use of artificial intelligence (AI) presents a promising solution for automating and optimizing compliance processes while ensuring adherence to data protection regulations.

datenschutz

The ECJ’s Data Protection Fine Concept: A More Detailed Analysis

This article examines the implications of the European Court of Justice (ECJ) ruling on the concept of data protection fines under the GDPR and explores the potential consequences for companies in Switzerland. Particular attention is given to how this ruling may influence enforcement practices, legal certainty, and risk management for cross-border data processing activities.

alle

FDPIC Guidelines on Cookies and Similar Technologies: A Comprehensive Guide

The use of cookies and similar technologies is widespread, but many companies face challenges in complying with privacy regulations. This overview of the FDPIC guidelines provides clear instructions and recommendations for implementing these technologies in accordance with data protection laws.

alle

Fingerprint Tracking: Circumventing Data Protection Guidelines in the EU?

Fingerprint tracking allows companies to identify users without using traditional cookies. This potentially constitutes a circumvention of European data protection guidelines and could also raise data protection concerns in Switzerland.

kunstliche-intelligenz

Legal Aspects of Using AI Providers in Switzerland

The use of AI technologies presents both opportunities and risks for Swiss companies. In this article, we examine the key legal aspects and provide guidance on ensuring compliance with data protection regulations.

infosec

ISO 27001 Implementation: Do it yourself or use a Packaged Solution?

Implementing ISO 27001 presents companies with a decision: Develop it in-house or use a packaged solution? This analysis highlights the benefits of both approaches, particularly in the context of the Swiss data protection landscape.

datenschutz

Navigating ISO 27001 Certification: Tips from the Experts

Get expert advice on how to successfully achieve ISO 27001 certification.

datenschutz

How to Master the ISO 27001 Audit Process in 30 Days

Master the ISO 27001 audit process in 30 days with our comprehensive guide.

datenschutz

Article 27 GDPR Compliance Guide

Discover the basics of compliance with Article 27 of the GDPR. Learn more about EU representatives, exemptions, and key obligations.

kunstliche-intelligenz

AI in HR

AI in HR

infosec

The Future of Data Protection in the Light of the Digital Operational Resilience Act (DORA)

The Future of Data Protection in the Light of the Digital Operational Resilience Act (DORA) and Its Impact on the Financial Sector

datenschutz

The Data Protection Aspects of Corporate Acquisition/M&A

The Data Protection Aspects of Corporate Acquisition/M&A, Be It Share Deals (Share Acquisition) or Asset Deals

infosec

Act to Speed Up the Digitization of Healthcare

On December 14, 2023, the Bundestag adopted a bill to speed up digitization.

datenschutz

Data Protection Regulations in Switzerland

FADP Audit in Switzerland: What Changes Are Relevant for Your Company or SME

datenschutz

Current Activity Reports from Data Protection Authorities

Activity Reports from European Data Protection Authorities

infosec

Experiences from the Use of ISO 27001 in SMEs

ISO 27001 Certification is Becoming Increasingly Important for Small and Medium-Sized Enterprises (SMEs)

datenschutz

How to become a Data Protection Officer in 5 steps

Learn how to become a Data Protection Officer with those 5 steps.

datenschutz

What is Personal Data?

Personal Data and its Regulation in Switzerland

datenschutz

External Data Protection Officer

With external data protection officers, you gain security.

datenschutz

Risk-Based Approach for SMEs

Data Protection Law requires a risk-based Approach in defining TOM

datenschutz

Implementation and Compliance with Data Protection Regulations

Data Protection, Consultants, and Management Systems as Key Elements of Compliance

datenschutz

Data Protection as a Differentiating Criterion

Reliable Data Protection as a Key Differentiator for Your Start-Up or ICT Company

datenschutz

GDPR/Data Protection Project: Tips to get Started

How to Start, Implement, and Successfully Complete a Data Protection Project

datenschutz

The EU Representative

The Future of Data Protection in the Light of the Role of the EU Representative for Companies Outside the European Union

datenschutz

Report to the Data Protection Authority

In accordance with Article 4(12) GDPR, a personal data breach refers to a security violation.

datenschutz

Schrems II: Privacy Shield Invalid

With the ruling of July 16, 2020, the Privacy Shield was declared invalid with immediate effect.

datenschutz

Contact Forms under the GDPR

Contact forms do not require consent under GDPR.

No matching results were found.

NEWSLETTER

Subscribe to our newsletter for free here.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

NEWSLETTER

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.