Data Protection in Aargau
Introduction
Aargau, with more than 730,000 inhabitants, is Switzerland's fourth-largest canton and one of its most industrial: ABB Switzerland is headquartered in Baden, Hitachi Energy is rooted in Aargau, the canton is home to the Beznau and Leibstadt nuclear plants, the pharma toll-manufacturer Siegfried in Zofingen, machine tools, food (Migros Aare) and a dense SME landscape. In data-protection terms, the federal DSG applies to private entities, while the cantonal Public Information, Data Protection and Archives Act (IDAG, SAR 150.700) applies to public bodies of the canton and its 198 municipalities.
This article covers:
- scope and key points of the IDAG;
- role of the Data Protection Commissioner of Aargau;
- industry and SME profile with typical data-protection topics;
- energy and critical-infrastructure dimension;
- HR data protection in industrial settings;
- practical recommendations for Aargau organisations.
The IDAG at a glance
The IDAG combines data protection, the principle of transparency and archives in one statute. It applies to cantonal authorities, the Aargau municipalities, the independent agencies (Aarau Cantonal Hospital, Baden Cantonal Hospital, Aargau Cantonal Bank in its public-law arm, AEW Energy AG) and to private parties entrusted with public tasks.
The central duties of public bodies are: a statutory basis for processing sensitive data, proportionality and purpose limitation, the duty to inform on collection, the data subject's right of access, disclosure restrictions, a DPIA for high-risk processing, breach notification and a record of processing activities. With the revisions since 2020, the IDAG has been aligned with the DSG and Directive (EU) 2016/680.
Private business in Aargau is consistently subject to the federal DSG. Anyone providing IT services, cloud solutions or consultancy to the canton or an Aargau municipality is, however, contractually bound to IDAG duties, with the same effects as in other cantons.
The Aargau Data Protection Commissioner
The Data Protection Commissioner of the Canton of Aargau is an independent supervisory and advisory office that statutorily oversees IDAG compliance cantonwide, advises authorities and municipalities, comments on legislative drafts with data-protection relevance, handles complaints and reports annually to the cantonal parliament.
Recent practical focal points:
- cloud migrations in school and hospital environments, particularly Microsoft 365 with telemetry configuration and sub-processor transparency;
- smart-city pilots, connected traffic infrastructure and municipal sensors;
- social-services, guardianship and KESB data with elevated sensitivity;
- employee data protection in the cantonal administration, particularly when new performance-management and time-tracking systems are rolled out.
The commissioner broadly orients her practice on the FDPIC but is visible with her own opinions. Anyone serving the Aargau administration should be familiar with the published recommendations in advance and in particular be able to meet the expectations on sub-processor lists and telemetry deactivation in cloud platforms.
Industry and SME profile in Aargau
Aargau is an industrial canton with a dense SME structure. Characteristic data-protection themes locally:
- Machine and plant engineering: ABB Switzerland, Hitachi Energy, Bühler suppliers, machine-tool makers. Data flows with global customers, maintenance and service data, IoT telemetry, remote-service platforms.
- Toll manufacturing and chemistry/pharma: Siegfried, DSM Nutritional Products, Lonza suppliers. Clinical studies, health data in active-ingredient manufacturing, regulatory interfaces with Swissmedic, FDA, EMA.
- Logistics and retail: Migros Aare, Coop sites, a dense logistics network. Loyalty programmes, CRM data, supplier and employee data.
- Energy: Axpo, AEW Energy AG, NOK legacy; classified as critical infrastructure with KRITIS-style requirements.
- Food and consumer goods: Hero in Lenzburg, Lindt in Olten, Florena lines.
Typical data-protection issues in this industrial structure are: transfers of customer and employee data to foreign group headquarters (Sweden, Japan, US), maintenance of global HR and payroll systems, IoT telemetry from machines on customer sites, AI use in predictive maintenance and whistleblowing systems. See further Data Protection Checklist Switzerland.
Energy and critical infrastructure
With the Beznau and Leibstadt nuclear plants, hydropower in the Aare valley, the Bickigen converter station and many transformer substations, Aargau is a key canton for Swiss energy supply. These assets are critical infrastructure under the Information Security Act (ISG) and have been subject, since 1 April 2025, to the obligation to notify cyber incidents to BACS within 24 hours.
Multiple regimes interlock in data-protection terms:
- the DSG for the processing of personal data of employees, suppliers and customers;
- ENSI safety rules for nuclear plant operation, including data classification and access controls;
- the ISG for critical infrastructure, with notification duties to BACS;
- in the electricity sector, emerging Swiss practice equivalent to NIS2 and, for cross-border players, the GDPR and EU NIS2.
For service providers in the energy sector this means significantly heightened security expectations: ISO 27001 or comparable standards, BACS-compliant incident processes, documented supply chains and sub-processor audits. SIDD supports the establishment of an ISMS to ISO 27001, an external CISO/ISB mandate and regular penetration tests.
HR data protection in industrial settings
HR data protection is a particularly prominent topic in industrial Aargau. Reasons: shift work with time-tracking systems, access control with badge logs, video surveillance in production halls, in-house medical services, recruitment with background checks, international transfers within groups, whistleblowing hotlines and AI-supported shift planning.
Practically relevant themes:
- Time tracking and performance monitoring: under Art. 26 ArGV 3 and Art. 4 ArG only under clear conditions; tracking must not become continuous monitoring of work behaviour.
- Occupational health service: professional secrecy (Art. 321 StGB), strict separation between medical findings (not to the employer) and fitness statements (which may be communicated).
- Whistleblowing hotlines: more strongly regulated in Switzerland since 2024 (proposed OR revision; many groups already aligned with EU Whistleblower Directive 2019/1937). Data-protection relevant: protection of identity, retention, third-country transfers to US hotline providers.
- Employee health apps, occupational health promotion: only with transparent consent and purpose limitation.
- Group-wide HR system (Workday, SuccessFactors, Cornerstone): requires intra-group SCCs or BCRs and a DPIA under Art. 22 DSG.
HR data protection is often the area in which most access requests arise, particularly in separations or conflicts.
Practical recommendations for Aargau entities
Recommendations for Aargau companies, municipalities and energy utilities:
- Build a record of processing activities under Art. 12 DSG / IDAG with separate sections for production, HR, customer management and critical infrastructure.
- Build a group-wide data-flow map for foreign parents and subsidiaries; implement SCCs or BCRs.
- Appoint an external data-protection adviser under Art. 10 DSG; public bodies and municipalities designate their own DPO, often as a regional pooled mandate.
- Review the cloud strategy: data location, sub-processors, customer-managed keys, telemetry configuration.
- Run a whistleblowing system with transparent data-protection information and short retention for non-pursued reports (typically three months after closure).
- Incident-response plan with three cascaded notification paths: FDPIC (data breach, 72 h), BACS (cyber incident in critical infrastructure, 24 h), cantonal commissioner (for IDAG processing).
- ISO 27001 or at least a documented ISMS for IT providers in the public sector and for critical-infrastructure operators.
- Training of operational shop-floor staff, not only management.
Whoever addresses these eight points well not only satisfies cantonal requirements but also reduces reputational and fines risks from GDPR exposure.
How SIDD supports you
SIDD looks after Aargau industrial companies, SMEs, energy utilities, municipalities and hospitals in all matters of data protection and information security. Our advantage in industrial settings is the combination of legal advice and technical delivery: from records of processing activities to DPIAs, penetration tests and ISO 27001 certification from a single provider.
Concretely we combine an external Swiss data-protection adviser under Art. 10 DSG with an external CISO/ISB, an ISMS / ISO 27001 build-out, a penetration test and, for EU exposure, an EU GDPR DPO and an EU representative under Art. 27 GDPR. Write to us via the contact form or request a concrete quote for your Aargau organisation.
