# Data Protection in Basel-Stadt

> Data protection in Basel-Stadt: the IDG BS for public bodies, the FADP for private companies, the life sciences cluster and cross-border commuters.

- Source: https://www.sidd.swiss/en/insights/data-protection-basel-stadt/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Basel-Stadt is a special case in data-protection terms: a half-canton with a highly concentrated life-sciences industry (Roche, Novartis, Lonza, Bachem, Idorsia), a busy trading and logistics hub, the trinational labour market of the Regio Basiliensis with roughly 70,000 daily cross-border commuters from Germany and France, and a relatively dense public sector with the University, the University Hospital and the cantonal administration. Private companies are subject to the DSG; public bodies of the canton are subject to the cantonal Information and Data Protection Act (IDG BS).

Topics of this article:

- scope and key features of the IDG BS;
- role of the Data Protection Commissioner of Basel-Stadt;
- pharma cluster: clinical studies, genomic data, pharmacovigilance;
- cross-border commuters and HR data protection in the trinational labour market;
- processors for the canton and University Hospital;
- practical recommendations.

The piece is aimed at Basel-based life-sciences companies, their suppliers and service providers, and at SMEs and public bodies with BS exposure.

## IDG BS at a glance

The Information and Data Protection Act of Basel-Stadt (SG 153.260) combines, like its Zurich counterpart, data protection and the principle of transparency in one statute. It governs the processing of personal data by cantonal authorities, the administrations of the resident municipalities Basel, Riehen and Bettingen, public institutions (University Hospital, the University of Basel in its public-law arm, IWB, BVB) and private parties entrusted with public tasks.

The core duties correspond to modern data-protection standards: proportionality, purpose limitation, the duty to inform, right of access, the duty to carry out a DPIA for high-risk processing, breach notification to the supervisory authority. In detail, the IDG BS differs from other cantonal regimes by an unusually tight link to the principle of transparency: access to official documents is broadly available and is supervised by the data-protection commissioner in parallel.

Private companies established in BS or directing their activity primarily to BS fall under the federal DSG. Anyone acting as a processor for the canton, the University Hospital or the University is contractually bound to the IDG duties and should make sure during contract negotiations that the requirements can actually be implemented in its ISMS.

## Commissioner of Basel-Stadt

The Data Protection Commissioner of the Canton of Basel-Stadt is an independent authority supervising compliance with the IDG BS, advising cantonal bodies and the resident municipalities and handling complaints from data subjects. She publishes an annual activity report that regularly addresses topics from school IT, healthcare, police and urban development.

Particularly notable in BS practice are:

1. a differentiated stance on cloud solutions in schools and hospitals, focused on contractual safeguards, sub-processors and telemetry configuration;
2. a rather restrictive stance on police video surveillance in public spaces, aligned with FDPIC guidance;
3. close engagement with the digitalisation of the city administration (e-government, cantonal digital identity, smart-city pilots);
4. active involvement in research with personal data (Human Research Act, ethics committee approvals).

For private companies this practice is relevant where they act as service providers or research partners into the public sector, particularly in biomedical research with the University Hospital and the University.

## Pharma and life-sciences cluster

The Basel pharma cluster, with annual turnover in the high double-digit billions and more than 30,000 employees, is the world's densest life-sciences location per capita. In data-protection terms this means: extremely large data volumes from clinical studies (multinational, with participants from the EU and US), pharmacovigilance databases, genomic data, real-world evidence platforms, AI-driven drug discovery.

Core topics in our mandate practice:

- **Clinical studies:** interfaces to the Human Research Act (HFG), the Ordinance on Clinical Trials (KlinV) and, for EU participants, the GDPR. Data flows between sponsor, CRO, investigator site and EMA/Swissmedic must be cleanly documented.
- **Pharmacovigilance:** spontaneous reports to Swissmedic and EMA contain sensitive patient data. Anonymisation and aggregation rules apply, but transfer-risk analyses remain necessary.
- **Genomic data and biobanks:** heightened sensitivity (Art. 5 lit. c DSG, Art. 9 GDPR), often with re-identification risk. Pseudonymisation and encryption standards must keep pace with the science.
- **AI in drug discovery:** generative models, AlphaFold derivatives, proprietary LLMs for literature analysis. The EU AI Act increasingly bites here, particularly for high-risk applications (see [AI Act High-Risk Systems](https://www.sidd.swiss/einblicke/ai-act-hochrisiko-systeme)).
- **Employee health tracking:** wellbeing programmes, health apps, insurance benefits, sensitive in group-wide practice.

Group companies with headquarters in Basel and global subsidiaries typically need Binding Corporate Rules or comprehensive SCC frameworks for their international data flows.

## Cross-border commuters and trinational HR data protection

Some 70,000 people commute daily from Germany (Baden-Württemberg) and France (Alsace) to work in Basel-Stadt and Basel-Landschaft. For HR departments this means: the employee data of these cross-border commuters is processed in Switzerland (Swiss employer, DSG), but a GDPR-relevant nexus often arises in parallel, for example through salary reports to German tax authorities, social-security notifications via DVKA/CLEISS, or confirmations for residence-country health insurers.

Practical questions:

- Which data may be transmitted to the foreign tax authority (withholding tax, tariff negotiations), and on what basis?
- How should data transfer to private German or French health insurers be structured (third-country transfer, SCCs, consent)?
- What duties apply to credit checks of German employees with SCHUFA disclosure?
- How should whistleblowing reports from commuters be handled under the German HinSchG and the DSG?

Basel companies with a large share of cross-border commuters should keep a dedicated HR data-protection concept that cleanly maps the interfaces to the GDPR, German BDSG and French Loi Informatique et Libertés. Where needed we recommend the parallel appointment of an EU representative under Art. 27 GDPR (see [EU representative](https://www.sidd.swiss/en/services/eu-representative)).

## Processors in the public sector

IT providers, cloud vendors, research platforms and consulting houses serving the Canton of Basel-Stadt, the University Hospital, the University of Basel or IWB are subject to the DSG in their own operations but are contractually bound to IDG BS duties. The cantonal procurement bodies increasingly use standardised data-protection contract schedules aligned with GDPR-level requirements.

Particularly important are:

1. data location (typically Switzerland or EEA, with documented exceptions);
2. sub-processors with approval or objection rights of the controller;
3. encryption standards (at least AES-256, ideally with customer-managed keys);
4. audit and inspection rights;
5. data-breach notification with a defined response time (often 24-48 hours to the controller, then consolidated notification to the cantonal commissioner);
6. deletion and return obligations at the end of the contract with proof.

Anyone not prepared for the procurement practice risks delays or even exclusion from tenders. Prior compliance documentation (ISMS certification, ISO 27001, DPIA) is increasingly mandatory in the Basel market. For more on ISO 27001 see [ISMS / ISO 27001](https://www.sidd.swiss/en/services/iso-27001-isms).

## Practical recommendations for Basel entities

Recommendations for companies, public bodies and research organisations with BS exposure:

1. Multilingual privacy notice (DE/FR/EN) for tourism, research and pharma distribution.
2. Record of processing activities with a "Clinical Research" and "Pharmacovigilance" section for life-sciences actors.
3. Trinational HR data-protection module mapping to GDPR, BDSG and the French Loi Informatique et Libertés.
4. Robust DPIA methodology with documented templates for cloud migrations, clinical research and AI deployment.
5. External data-protection adviser under Art. 10 DSG with notification to the FDPIC; public bodies follow their own IDG obligation.
6. Incident-response plan with cascaded notification to the FDPIC (72 h), the BS commissioner (for public-sector mandates), BACS (critical infrastructure, 24 h) and, in pharma, Swissmedic.
7. ISMS / ISO 27001 as a baseline for IT providers in the public sector.
8. Group-wide SCC or BCR architecture for international data flows, reviewed annually.

The strength of Basel practice lies in the interlock of legal and technical expertise, particularly in the pharma cluster, where data protection, research ethics and regulatory requirements (Swissmedic, FDA, EMA) go hand in hand.

## How SIDD supports you

SIDD looks after Basel life-sciences groups, SMEs, public bodies and research organisations across the full range of data protection. We bring experience from pharma, medtech and clinical-research mandates as well as trinational HR data protection, and work closely with compliance, research and IT teams.

Concretely we combine an external [Swiss data-protection adviser](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) under Art. 10 DSG with an [EU GDPR DPO](https://www.sidd.swiss/en/services/data-protection-officer-eu), an [EU representative](https://www.sidd.swiss/en/services/eu-representative) under Art. 27 GDPR for manufacturers without an EU establishment, an [ISMS / ISO 27001 build-out](https://www.sidd.swiss/en/services/iso-27001-isms) for the parallel security requirements, and [data-protection workshops](https://www.sidd.swiss/en/services/data-protection-workshop-sme) for your teams. Write to us via the [contact form](https://www.sidd.swiss/en/contact) or request a tailored [quote](https://www.sidd.swiss/en/quote) for your Basel organisation.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
