Data Protection Challenges in the Digital Age: A Swiss Guide
Why data protection needs to be rethought
Digitalisation does not change the subject matter of data protection law, but it does change its reach. Personal data is now generated as a by-product: in telemetry, in cookies, in sensor streams, in voice assistants and in the input fields of generative AI. The Swiss DSG (Federal Act on Data Protection / FADP) entered into force on 1 September 2023 and requires controllers to keep these new data flows under control. In parallel, the GDPR applies extraterritorially to many Swiss organisations under its Art. 3(2) as soon as they offer goods or services to persons in the EU or monitor their behaviour.
This guide focuses on six challenges that arise most often in SIDD mandates: tracking and cookies, AI in HR processes, cloud migration, the Internet of Things, generative AI in customer interaction, and cross-border data flows. For each challenge we identify the relevant rules and a workable solution. Readers who want to build the legal framework comprehensively will find the structural foundations in the DSG/FADP guide (German-language pillar) and in the GDPR guide.
Tracking, cookies and the Swiss special path
Websites routinely process personal data as soon as they deploy tracking scripts, advertising pixels or third-party cookies. In the EU, Art. 5(3) of the ePrivacy Directive requires prior active consent for every cookie that is not strictly necessary. Switzerland, by contrast, only requires information with an opt-out under Art. 45c lit. b FMG. Swiss organisations that serve an international audience must therefore implement the stricter GDPR regime in practice.
Operationally this means: a consent-management solution offering a genuine choice, a cookie inventory capturing purpose, retention and recipient, and a privacy notice that names the tracking recipients. Pre-ticked defaults satisfy neither Art. 6(6) DSG nor Art. 7 GDPR. The FDPIC has repeatedly highlighted opaque cookie banners in its 2024 activity report. For webshops with EU reach, avoiding dark patterns is advisable, for example by offering equally weighted accept and reject buttons.
Artificial intelligence in HR and people processes
AI-supported pre-screening of applications, automated performance review or sentiment analysis of internal communication touch several layers of protection at once. Under Art. 21 DSG, data subjects have the right not to be subject to a decision based exclusively on automated processing that has a significant effect on them. Art. 22 GDPR provides an analogous rule with additional information duties.
Since 2 February 2025, Art. 5 of the EU AI Act has also been applicable and prohibits, among other things, social scoring and the biometric categorisation of sensitive attributes at the workplace. AI systems used to evaluate candidates qualify as high-risk under Annex III and trigger conformity obligations as soon as they are deployed in the EU. Swiss employers that procure such tools should review vendor contracts for transparency, training-data provenance and bias testing. A DPIA (Data Protection Impact Assessment) under Art. 22 DSG is regularly required. Further reading in the AI compliance guide (German-language pillar).
Cloud migration, adequacy and the CLOUD Act
Moving workloads to hyperscaler clouds is often commercially unavoidable, but under data protection law it requires justification. The relevant provisions are Art. 16 and 17 DSG for cross-border disclosure and Art. 9 DSG for processing on behalf. By decision of 15 January 2024, the European Commission again recognised Switzerland as a third country with an adequate level of protection, which simplifies EU-to-CH data flows. For transfers to third countries without an adequacy decision, Standard Contractual Clauses (SCCs) and a Transfer Impact Assessment remain mandatory.
The US CLOUD Act of 2018 constitutes a distinct risk class: it obliges US providers to disclose data to US authorities regardless of storage location. Swiss controllers should therefore evaluate data classification, encryption with customer-held key material and sovereign-cloud options. ISO/IEC 27001:2022, with the Annex A controls A.5.23 (cloud services) and A.8.24 (cryptography), provides the operational structure. Details in the ISO 27001 guide.
Internet of Things and privacy by design
Connected devices, from heating controls to industrial scales, continuously generate telemetry. Where this data can be related to identifiable persons, the full body of data protection law applies. Art. 7 DSG enshrines privacy by design and privacy by default as obligations of the controller; Art. 25 GDPR formulates it in analogous terms. Manufacturers and operators must therefore embed data protection in the product architecture itself, not only in operations.
In practice this means: data-minimising telemetry profiles, local pre-processing rather than raw-data transfer, transparent defaults with opt-out, cryptographic device identity and a clearly documented lifecycle including patch supply. The EU Cyber Resilience Act, which becomes fully applicable from December 2027, sharpens these requirements further for connected products. Swiss manufacturers that export to the EU should plan for conformity duties and CE marking at an early stage. For ongoing oversight, an ISMS modelled on ISO/IEC 27001 with emphasis on Annex A.8.9 (configuration management) and A.8.16 (monitoring) is recommended.
Generative AI in customer interaction
Chatbots and voice assistants based on large language models process inputs in real time, typically via cloud APIs located outside Switzerland. Three aspects deserve particular attention. First, the legal basis: where special-category personal data within the meaning of Art. 5(c) DSG / Art. 9 GDPR is entered, such as health or social-assistance data, Art. 31 DSG requires explicit consent or another qualified basis. Second, transparency: Art. 50 EU AI Act requires that users can recognise that they are interacting with an AI. Third, training use: inputs must not be silently re-used to improve the model.
Operationally we recommend ring-fenced enterprise tariffs with zero-retention clauses, input filters against sensitive data categories, documented prompt logging with deletion deadlines and staff training. Swiss authorities and hospitals are additionally bound by cantonal requirements and by professional secrecy under Art. 320 and 321 SCC. SIDD practice always recommends a written DPIA with risk matrix before any productive deployment.
Cross-border data flows and group structures
Intra-group data flows between parent, subsidiary and service entities are not automatically uncritical from a data protection perspective. Under Art. 16 DSG every recipient country must offer an adequate level of protection or appropriate safeguards. The Federal Council maintains a country list; current adequacy decisions cover, among others, the EU Member States, the United Kingdom and, since January 2024, the EU on a reciprocal basis.
For countries without adequacy, three routes remain available: Standard Contractual Clauses (SCCs) under Art. 16(2) lit. d DSG, Binding Corporate Rules under Art. 17 DSG and the narrow exemptions of Art. 17. Each route requires a transfer risk assessment, an inventory of recipients and an updated privacy notice. In US, China or India scenarios, controllers should additionally examine governmental access powers, encryption standards and emergency-clause language. SIDD experience shows that data flows are frequently hidden not in the main contract but in support agreements, maintenance windows and SaaS sub-processor lists.
How SIDD supports Swiss organisations
The six challenges described cannot be solved by a one-off project; they require ongoing data protection management. SIDD and Priverion support Swiss organisations of all sizes with the following approach. First, a focused baseline assessment with Records of Processing Activities (ROPA), a data flow map and a gap analysis against the DSG, GDPR and, where applicable, the EU AI Act. Then prioritised measures with clear responsibilities, deadlines and success criteria. Finally, ongoing operations with training, incident management and periodic re-assessment.
For mandated tasks our services stand ready: the role of Swiss data protection advisor, the EU representative and Data Protection Officer under GDPR, and building an ISMS to ISO/IEC 27001. Sanction risks are real: violations of the DSG may be sanctioned under Art. 60 with fines of up to CHF 250,000 against the responsible natural person, and violations of the GDPR under Art. 83 with up to EUR 20 million or 4 per cent of worldwide group turnover. Effective compliance is therefore not only a legal but a commercial necessity.
