Data Protection for Law Firms, Attorney–Client Privilege × DSG

6 min readLast updated By Dominic Staiger

Introduction

A Swiss law firm operates at an unusual intersection in data-protection terms: the attorney–client privilege under Art. 13 of the Federal Act on the Free Movement of Lawyers (BGFA) and Art. 321 of the Swiss Criminal Code (SCC) is one of the oldest and most strongly protected professional secrecy duties in Swiss law – while at the same time the revised Federal Act on Data Protection (DSG) grants a broad right of access (Art. 25 DSG) that can collide with that secrecy. Add highly sensitive matter content (criminal defence, M&A, family law, arbitration), cross-border e-discovery demands, the realities of cloud hosting and rising regulatory expectations on cyber security, and the picture is challenging. Running a Swiss firm in 2026 without a clean data-protection and security foundation risks disciplinary complaints, FINMA-relevant consequences for bank clients and loss of client trust.

This article clarifies:

  • The tension between attorney–client privilege and Art. 25 DSG access rights
  • How far the duties to inform and to maintain a register reach
  • E-discovery and cross-border data production
  • Cloud hosting of matter files: legal and technical preconditions
  • Practical TOMs and a realistic implementation path

Attorney privilege in Swiss law

Swiss legal privilege rests on several pillars: Art. 13 BGFA obliges lawyers to confidentiality without time or scope limit on everything entrusted to them in professional capacity; Art. 321 SCC criminalises breach (complaint-based, up to three years imprisonment); Art. 264a(1)(d) CPC and Art. 171(1) StPO grant the right to refuse to testify. Lawyer-client correspondence is protected from seizure under Art. 248 StPO (sealing) and Art. 246 CPC.

Four practical points stand out in 2026: first, the identity of the client is itself privileged – the client list is sensitive material. Second, the duty binds the entire firm and all auxiliaries (secretariat, IT provider, cloud vendor, shredding service); engagement requires an express commitment to the privilege. Third, the privilege can only be lifted by the client or the cantonal bar supervisory authority. Fourth, the privilege regularly collides with disclosure duties to tax authorities (Art. 127 DBG vs privilege), prosecutors (protected under Art. 264a StPO) and foreign courts (subpoenas) – each request must be analysed per matter and is usually to be refused.

Where DSG collides

The DSG applies to a law firm's processing of personal data just as it does to any other organisation. Four friction points with privilege deserve attention:

  1. Right of access (Art. 25 DSG): an opposing party may ask under Art. 25 DSG to know what data the firm processes about them. The request is often tactical. Prevailing doctrine and practice allow refusal where privilege is concerned (Art. 26(2)(b) DSG: overriding third-party interests). The refusal must be reasoned but not exposed in detail.
  2. Information duty (Art. 19 DSG): the firm must transparently inform clients about processing – including sub-processors, cloud locations, retention periods. A written client privacy notice belongs to the engagement contract.
  3. Record of processing activities (Art. 12 DSG): because of regular processing of sensitive personal data, firms are required to maintain a register regardless of headcount.
  4. Breach notification (Art. 24 DSG): the FDPIC (EDÖB) must be informed of high-risk breaches – again with care for privilege, ideally pseudonymised or aggregated.

E-discovery and cross-border production

Swiss firms are increasingly confronted with e-discovery orders from US proceedings (FRCP 26), English disclosure proceedings or European courts. Here legal privilege, Swiss criminal law (Art. 271 SCC: prohibited acts for a foreign state) and the DSG (Art. 16-17 DSG: cross-border disclosure under strict conditions) collide. Direct production of client files to a foreign court or investigating authority outside formal mutual legal assistance is a criminal offence.

The correct sequence is: 1. immediate verification of the requesting party's status (private party vs authority), 2. mutual legal assistance through the Federal Office of Justice (FOJ) for authority requests, 3. client consultation and – where needed – judicial authorisation under Art. 271(1) SCC for private discovery proceedings, 4. privilege review per document before any release, 5. pseudonymisation of third-party personal data, 6. controlled transfer with evidence record. Practically, firms need an e-discovery playbook, a document management system with fine-grained privilege logic and a vetted Art. 271 SCC authorisation workflow. Many Swiss firms run this in parallel with internal data rooms or via specialised Swiss providers.

Cloud hosting of matter files

In 2026 cloud hosting of client matters is largely accepted but tightly conditioned. The FDPIC has clarified in several guidance papers (notably on M365 in the public sector) that processing sensitive data – and matter data is by definition sensitive – in the cloud is permissible where TOMs technically preserve privilege, the cloud vendor is contractually bound as an auxiliary under Art. 321(1) SCC, and any international transfer rests on a valid legal basis.

In practice cantonal bars (Zurich, Geneva, Bern) tolerate cloud-hosted practice IT where the following are in place: data centres in Switzerland or the EU/EEA; sub-processor transparency with a veto right for the firm; encryption at rest with customer-held keys (BYOK or HYOK) for particularly sensitive mandates; phishing-resistant MFA (FIDO2/WebAuthn); role-based access on need-to-know per matter; tamper-evident audit logs; contractual commitment to attorney privilege with sanctions for breach; prior client information where matters are particularly sensitive (criminal proceedings, arbitration involving politically exposed persons, pre-announcement M&A). Microsoft 365, Google Workspace, Swiss-specific solutions (Tocario, Winjur, Bratschi-Connect) and pure Swiss cloud providers can all meet the bar depending on configuration. Caution is warranted with US-centric backup tools without EU residency and with document-review platforms hosted exclusively in the US.

Technical and organisational measures

In 2026 Swiss law firms are increasingly the target of focused attacks – not just opportunistic ransomware but targeted compromises aimed at specific matters. The following TOMs are not optional below market standard:

  • Phishing-resistant MFA on all accounts (FIDO2 security keys instead of SMS OTP).
  • EDR/XDR on every endpoint, with 24x7 triage internally or via MDR.
  • Client separation: technical segregation between matters and clients in the DMS, need-to-know permissions, automated conflict checking.
  • Classification: three-tier classification (public, matter-internal, highly confidential) with corresponding handling rules (printing, transmission, retention).
  • Secure e-mail: enforced TLS, S/MIME or encrypted attachments for highly confidential correspondence, clear rules on external sharing.
  • Print and mobile: follow-me printing, MDM for all mobile devices, remote wipe on loss.
  • Backup and DR: daily backups with off-site copy, monthly recovery test, rehearsed ransomware playbook (RTO under 24 hours for critical matters).
  • Awareness and exercise: mandatory annual training, simulated phishing, tabletop exercise "client data stolen" with management.

Data breach in a law firm

A breach in a Swiss law firm – ransomware with exfiltration, mistaken e-mail to the opposing party, laptop theft at the airport – triggers several duties at once: DSG notification to the FDPIC (Art. 24 DSG), client notification (Art. 24(3) DSG), notification to the cantonal bar supervisor (cantonal law dependent), potentially criminal complaint for breach of privilege by third parties, and for FINMA-related mandates information to the client's reporting line.

Operationally the following workflow has proven itself: 1. immediate containment (lock account, isolate system, e-mail recall), 2. forensic preservation by a specialised third party, 3. matter-level risk assessment (which matters are affected, how sensitive, which clients are politically or regulatorily exposed), 4. communication strategy with management, crisis communications and bar supervisor, 5. FDPIC notification, preserving privilege through pseudonymisation where possible, 6. individual notification of affected clients with clear description of the incident and measures, 7. criminal complaint against perpetrators, 8. lessons-learned and adjustment of TOMs, documented. A rehearsed chain here is worth more than any insurance – it decides whether the firm survives the incident.

How SIDD supports you

SIDD advises Swiss law firms of every size – from solo practices to international business firms – as external data-protection adviser and CISO. Our team combines legal expertise (Dr iur with Swiss and EU data-protection focus) with operational security capability. We deliver the processing register, the client privacy notice, DPA templates for cloud and sub-processor integration, an e-discovery playbook with an Art. 271 SCC workflow, and a breach playbook aligned with your cantonal bar. Our data-protection adviser mandate for firms is tailored to privilege realities. Many firms combine the adviser mandate with an external CISO mandate, an ISO 27001 certification (increasingly requested by large clients) and regular penetration testing of the firm IT. Speak with us via our contact form or request a confidential quote – advice is delivered under NDA and with mutual respect for professional privilege.

Need help putting this into practice? SIDD operates the matching service.
See service →

Data Protection for Law Firms, Attorney–Client Privilege × DSG

INSIGHT

Data Protection
24 May 2026
Dr. Dominic Staiger
Data protection in law firms: legal privilege and the FADP right of access, cross-border disclosure, cloud hosting of client files and data breaches.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.