# Data Protection in St. Gallen

> Data protection in the canton of St. Gallen: cantonal law for public bodies, the FADP for private companies, the financial sector, textiles and universities.

- Source: https://www.sidd.swiss/en/insights/data-protection-st-gallen/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

With around 520,000 inhabitants, St. Gallen is an economically diverse canton: a traditional textile and embroidery hub with global clientele, home to the University of St. Gallen (HSG), an important financial centre with Raiffeisen Switzerland, the St. Gallen Cantonal Bank (SGKB), the Notenstein La Roche legacy and a dense independent asset management community, plus strong machine industry (Bühler in Uzwil, SFS Group in Heerbrugg) and a regional hospital network (Cantonal Hospital St. Gallen, Spital Linth). The federal DSG applies to private entities; the cantonal Data Protection Act (DSG-SG, sGS 142.1) applies to public bodies of the canton and the 75 St. Gallen municipalities.

Topics of this article:

- key features of the DSG-SG;
- role and practice of the cantonal Data Protection Office;
- St. Gallen financial centre: FINMA, banking secrecy, asset management;
- textile and embroidery industry with global supply chain;
- HSG and research data protection;
- recommendations for St. Gallen entities.

## The DSG-SG at a glance

The St. Gallen Data Protection Act has been updated in the Schengen reform and in view of the DSG. It governs the processing of personal data by cantonal authorities, the municipalities, the agencies (Cantonal Hospital, SGKB in its public-law arm, pension fund) and private parties entrusted with public tasks.

Central duties: statutory basis for processing sensitive data, proportionality, purpose limitation, the duty to inform on collection, right of access and rectification, DPIA for high-risk processing, breach notification, record of processing activities. Disclosure to third parties is independently governed and bound to clear purpose-limitation rules.

Private companies in St. Gallen are subject to the DSG. Anyone serving the canton, a municipality, the Cantonal Hospital or SGKB as a processor is contractually bound to the DSG-SG duties. Eastern Switzerland also has several municipal associations that coordinate data-protection topics regionally, a pooled-mandate market of interest to external advisers.

## Cantonal Data Protection Office

The St. Gallen Data Protection Office (commissioner for transparency and data protection) is an independent supervisory and advisory body. It supervises compliance with the DSG-SG by public bodies, advises authorities and municipalities, handles complaints and publishes an annual activity report.

Recent focus areas:

1. cloud migrations in schools and hospitals (Microsoft 365 and Google Workspace) with clear requirements on data location, sub-processors and telemetry;
2. police IT under Schengen Directive (EU) 2016/680;
3. data in social services, KESB proceedings and schools (compulsory schooling, learning software);
4. digitalisation of the cantonal administration (e-government, cantonal platforms, cantonal digital identity);
5. cantonal police body cams, with recording and retention rules.

This practice is relevant for private companies where they act as service providers or research partners into the St. Gallen public sector; cantonal procurement increasingly uses data-protection contract schedules that reference GDPR-level requirements.

## The St. Gallen financial centre

After Zurich and Geneva, St. Gallen is a mid-sized but concentrated Swiss financial centre. Raiffeisen Switzerland sits here as the largest cooperative banking group, alongside SGKB, the Notenstein La Roche legacy (now within Vontobel) and many asset managers and family offices. HSG is a key recruitment and incubation hub for banking talent.

In data-protection terms: banking secrecy under Art. 47 BankG remains the primary protection anchor for client data; the DSG complements with individual rights (access, rectification, data portability). FINMA supervises in parallel via Circulars 2008/21, 2018/3 (outsourcing) and 2023/1 (operational risks). Cloud migrations must be notified to FINMA and underpinned with audit and inspection rights.

For independent asset managers (UVVs) and trustees, the FINIG licensing duty has applied since 2020. They are additionally caught by FINMA supervision and supervision by the recognised supervisory organisation (AO). Data-protection relevant: KYC/AML holdings under the GwG, suitability data under FIDLEG, performance reporting to clients in third countries. An external adviser under Art. 10 DSG coordinates these parallel duties and relieves the compliance officer.

## Textile and embroidery: global supply chain

St. Gallen is historically the centre of Swiss embroidery and textile finishing. Today Forster Rohner, Bischoff Textil and others supply global haute-couture brands (Chanel, Dior, Givenchy) and work with designers, modelling agencies, lookbook photographers, brand managers and licensors in Paris, Milan, New York and Tokyo.

Data-protection topics arising from this global supply chain:

- **B2B customer communication:** contact data of designers, buyers, brand managers, images from lookbooks, licensing correspondence. B2B data is personal data in the GDPR / DSG sense where it refers to natural persons.
- **Third-country data flows:** customers in the US, UK, Asia, Middle East; suppliers in India, Türkiye, China; showroom staff in several jurisdictions.
- **Employee and supplier data:** credit checks, sub-contractor contracts, compliance with supply-chain due-diligence duties (Swiss Ordinance on Due Diligence and Transparency in matters of Minerals and Metals from Conflict Areas and Child Labour, VSoTr).
- **Trade secrets vs data protection:** patterns, designs and lookbooks are trade secrets; a clean confidentiality architecture must harmonise with the access and transparency duties of the DSG.

Family-owned firms with global clientele benefit from an external adviser fluent in both EU GDPR and DSG.

## HSG, research and education

The University of St. Gallen (HSG) is one of Europe's leading business universities. It processes data of around 9,000 students, alumni data of some 35,000 worldwide, employee data and, in research and executive education, data of senior leaders from global corporates. Data-protection relevant themes:

1. alumni and career platforms, often in cloud solutions with US exposure (adequacy decision, DPF);
2. executive education participants from the EU, UK, US and Asia, each with its own data-protection regime;
3. research data in banking, insurance and asset management with industry partners (employee surveys, real-time studies);
4. AI in teaching and research: LLM-based study aids, research data analysis, plagiarism detection;
5. international doctoral students with GDPR exposure;
6. online lectures with recordings, publication of talks.

In practice HSG runs an independent data-protection organisation in contact with the cantonal office. For research cooperations with industry partners, we recommend a written agreement with clear allocations of responsibility and data flows and, for EU research participants, a dedicated GDPR conformity check.

## Recommendations for St. Gallen entities

Recommendations for St. Gallen companies, municipalities, hospitals and universities:

1. Record of processing activities under Art. 12 DSG or DSG-SG with separate sections by business line; cleanly separate dual roles (controller / processor).
2. Multilingual privacy notice (DE/EN; in textile additionally FR/IT), transparent on third-country transfers.
3. External adviser under Art. 10 DSG, where appropriate combined with a GDPR DPO for EU exposure.
4. For FINMA-supervised entities: outsourcing inventory with DPAs, SCCs and TIAs; FINMA notification for material outsourcing.
5. Cloud strategy with data location, sub-processor list, customer-managed keys for sensitive data.
6. Incident-response plan with notification to the FDPIC (72 h), the cantonal office (public mandates), FINMA (finance, 24 h), BACS (critical infrastructure, 24 h).
7. Training of management, HR, marketing and operations.
8. For textile/embroidery firms: additional module on B2B data flows, trade-secret contract clauses and VSoTr due-diligence.

St. Gallen entities particularly benefit from a regionally rooted adviser who knows the practices of the Cantonal Hospital, SGKB and HSG from mandates and stays in dialogue with the cantonal office.

## How SIDD supports you

SIDD is present in eastern Switzerland and serves St. Gallen banks and asset managers, textile and embroidery firms, SMEs, hospitals, municipalities and universities. We know the practice of the cantonal Data Protection Office, the FINMA-specific expectations for banks and UVVs and the global data flows of the textile sector.

Concretely we offer an external [Swiss data-protection adviser](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) under Art. 10 DSG, an [EU GDPR DPO](https://www.sidd.swiss/en/services/data-protection-officer-eu) for your EU exposure, an [EU representative](https://www.sidd.swiss/en/services/eu-representative) under Art. 27 GDPR for textile and brand businesses without an EU establishment, an [ISMS / ISO 27001 build-out](https://www.sidd.swiss/en/services/iso-27001-isms) for FINMA-compliant security architectures and [data-protection workshops](https://www.sidd.swiss/en/services/data-protection-workshop-sme) for your teams. Write to us via the [contact form](https://www.sidd.swiss/en/contact) or request a concrete [quote](https://www.sidd.swiss/en/quote) for your St. Gallen organisation.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
