# Data Protection Bern, DSG and Cantonal KDSG

> Data protection in the canton of Bern: the cantonal KDSG for canton and municipalities, the FADP for private companies, supervision and practical advice.

- Source: https://www.sidd.swiss/en/insights/data-protection-bern/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Bern is not only the federal capital but also, with over one million inhabitants, the largest canton in German-speaking Switzerland by area, with a strikingly diverse economic profile: federal administration and federal agencies, medtech (Insel Group, Lindenhof, CSL Behring), precision and machine engineering (Emmental, Bernese Jura), tourism (Bernese Oberland), insurance (Allianz Suisse, Mobiliar) and over 300 municipalities. In data-protection terms the federal DSG applies to private controllers, while the cantonal data-protection act of Bern (KDSG BE) applies to public bodies.

This dual structure creates a specifically Bernese practice. Topics of this article:

- scope and key features of the KDSG BE;
- two-tier cantonal and municipal level with municipal data-protection officers;
- position and practice of the cantonal data-protection supervisory authority (DSAB BE);
- interfaces to federal administration, FDPIC and the EU;
- typical sectors in Bern and their data-protection topics;
- practical recommendations for Bernese companies and public bodies.

Addressees are management, city and municipal administrations, hospital CIOs and external advisers with Bernese clients.

## The KDSG BE at a glance

The Data Protection Act of the Canton of Bern (BSG 152.04) governs data protection for the public bodies of the canton and the Bernese municipalities. It was completely revised in 2019 and harmonised with the Schengen reform (Directive (EU) 2016/680 for law enforcement) and the DSG. This makes Bern one of the most modern cantonal regimes in German-speaking Switzerland: record of processing activities, data-protection impact assessment, breach notification and a standalone right to rectification are explicitly anchored.

The KDSG BE applies to the canton, the municipalities, the burgher communes, the cantonally recognised church parishes and all public-law institutions (Insel Hospital, Bernese Pension Fund, BKW in its public area). Private entities entrusted with public tasks are functionally included to the extent of fulfilling those tasks.

Core duties are proportionality (Art. 5 KDSG BE), purpose limitation (Art. 6), statutory basis for processing (Art. 4), information and access rights (Arts. 14-15, 18), the duty to carry out a DPIA in high-risk processing (Art. 19) and the duty to notify breaches to the supervisory authority (Art. 20). Security measures are specified in the data-protection ordinance of the cantonal government.

## Two-tier system: canton and municipalities

A Bernese specificity is the two-tier supervisory and advisory system. At cantonal level the Data Protection Supervisory Authority of the Canton of Bern (DSAB BE), an independent authority organisationally attached to the judiciary, acts as supervisor over all cantonal bodies and as appeals instance for data subjects.

At municipal level all Bernese municipalities must designate a data-protection officer (Art. 36 KDSG BE). Small municipalities often share an external officer regionally. This function is not supervisory but advisory; supervision remains with the DSAB BE. For external advisers this opens an unusually broad market: Bern has over 330 political municipalities, almost all of which need external support to fulfil this duty.

Private companies acting as processors for municipalities or the canton (e.g. an IT provider for a city administration, a cloud provider for a hospital) remain subject to the DSG but are contractually bound to the KDSG duties of their controllers. These cascaded duties must be neatly captured in a DPA and should be addressed explicitly in contract negotiations (see [DPA Switzerland](https://www.sidd.swiss/einblicke/avv-auftragsbearbeitungsvertrag-schweiz)).

## Practice of the DSAB Bern

The Bernese supervisor publishes an annual activity report and opinions on practical questions. Recurring themes are:

1. cloud solutions for schools and hospitals, in particular the migration to Microsoft 365 or Google Workspace with clear requirements on data location, sub-processors and telemetry;
2. video surveillance in public spaces, sports facilities and school buildings;
3. data processing in the social sector (social services, guardianship, KESB), where sensitive data converges;
4. access control and logging in criminal proceedings (police, prosecution) under the Schengen directive;
5. employee data protection in the cantonal administrations, particularly when new HR systems are rolled out.

The line of the DSAB Bern broadly tracks that of the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) but diverges in details, such as DPIA methodology or the level of detail expected in the record of processing activities. Anyone cooperating with the Bernese administration should actively consult the annual activity reports and published recommendations.

## Federal-cantonal-EU interfaces

Bern is the federal seat: federal administration, the federal courts (the Supreme Court sits in Lausanne but has Bernese ties), numerous federal offices and general secretariats are anchored here. This creates a special situation for IT providers and consultancies: mandates for the federal administration are subject to the federal DSG (for federal bodies, with the FDPIC as supervisor), while mandates for the Bernese administration are subject to the KDSG BE. The two regimes are broadly harmonised but not identical, in particular as to scope, notification deadlines and DPIA requirements.

For companies with additional GDPR exposure, such as medtech makers selling in the EU, insurance brokers with cross-border clients or tourism platforms for German and French guests, the obligations of Art. 27 GDPR (EU representative) and the third-country transfer mechanism for inter-administrative cooperation must be added.

Equally important is the interface with the French-speaking administration of the Canton of Jura and the Bernese Jura: inter-administrative data flows are captured by the disclosure principles of Art. 9 KDSG BE and generally require a statutory basis or consent of the data subjects.

## Bernese sectors with specific themes

In our Bernese practice the following sectors stand out for their data-protection topics:

- **Medtech and hospital networks:** Insel Group, Lindenhof, Spitäler fmi, CSL Behring, Ypsomed, processing of patient data, clinical studies, device telemetry. Interfaces to the Human Research Act and the electronic patient record (EPDG).
- **Insurance and pension funds:** Mobiliar, Allianz Suisse, Bernese Pension Fund, Visana, credit data, claim files, telematics. High regulatory density across the Insurance Supervision Act, occupational benefits law and the DSG.
- **Tourism and hospitality:** Bernese Oberland, Adelboden, Interlaken, Gstaad, international guests, multilingual privacy notices, EU GDPR exposure through booking EU guests. See further [Data Protection in Hotels and Gastronomy](https://www.sidd.swiss/einblicke/datenschutz-hotel-gastronomie).
- **Machine and precision engineering:** Emmental, Bernese Jura, customer data from the EU and US, employee data, manufacturing IoT. Often additionally ISO 27001 relevant.
- **Federally adjacent providers:** IT and consulting houses working for the federal administration, with elevated security requirements (BSI baseline-protection adaptation, BACS conformity, ISDS-style protection-needs analysis).

These sector clusters materially drive priority-setting in mandate work.

## Practical recommendations for Bernese entities

Recommendations for Bernese private companies, municipalities and hospitals:

1. Clarify whether KDSG BE, the federal DSG or the GDPR applies, and in what combination. Where multiple regimes apply, work with a clear responsibility matrix.
2. Maintain a record of processing activities under Art. 12 DSG or Art. 13 KDSG BE and review it at least annually.
3. Update the privacy notice under Art. 19 DSG or Art. 14 KDSG BE; in a bilingual context (DE/FR in the bilingual canton, EN for tourism) maintain all language versions.
4. Appoint an external data-protection adviser under Art. 10 DSG for private controllers; public bodies designate a data-protection officer under Art. 36 KDSG BE, often as a regional pooled mandate.
5. Conduct cloud migrations with a documented risk analysis, contractual safeguards and, for sensitive data, customer-managed keys or Swiss data localisation.
6. Implement a breach process with a 72-hour deadline to the FDPIC (private sector) or to the DSAB BE (public bodies); for cyber incidents add the 24-hour notification to BACS for critical infrastructure.
7. Train and raise awareness at least annually, ideally with cantonal case examples.
8. For bilingual municipalities, keep bilingual templates for access requests and privacy notices on hand.

A well-run Bernese mandate differs from a Zurich one chiefly through the multitude of small clients (municipalities, parishes, burgher communes) and the parallel federal exposure.

## How SIDD supports you

SIDD supports Bernese companies, municipalities and hospitals across the full range of data protection. We know the practice of the Data Protection Supervisory Authority of the Canton of Bern, the structure of the Bernese administration and the regulatory interfaces to the federal administration, the FDPIC and the EU. For municipalities and small public bodies we offer external DPO functions in pooled mandates; for private companies an external adviser under Art. 10 DSG.

Concretely we combine our [Swiss data-protection adviser](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) under Art. 10 DSG with, where relevant, an [EU GDPR DPO](https://www.sidd.swiss/en/services/data-protection-officer-eu), an [external CISO/ISB](https://www.sidd.swiss/en/services/vciso) for the parallel security requirements, and [data-protection workshops](https://www.sidd.swiss/en/services/data-protection-workshop-sme) for your teams. Write to us via the [contact form](https://www.sidd.swiss/en/contact) or request a concrete [quote](https://www.sidd.swiss/en/quote) for your Bernese organisation.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
