Data Protection Zug, DPO for Crypto Valley Companies
Introduction
The Canton of Zug, home to over 1,000 blockchain and DLT companies, hosts the densest Crypto Valley in the world, from the Ethereum Foundation through large centralised exchanges, custodians and stablecoin issuers to DeFi start-ups and wallet providers. For all of them a dense web of rules applies in parallel: the revised Federal Act on Data Protection (DSG), the Anti-Money-Laundering Act (GwG) including the FATF travel-rule requirements, the DLT Act of 2021 (amendments to BankG, FinIG, FINMAG), supervision by the Federal Financial Market Supervisory Authority (FINMA) for SRO-affiliated or licensed financial intermediaries, and increasingly MiCA (Markets in Crypto-Assets Regulation) where EU customers are served. The Zug Data Protection Act (DSG ZG, BGS 157.1) additionally applies to public bodies of the canton, but not to private companies.
This article addresses Crypto Valley players and their advisers. Topics:
- specifics of the DSG for Web3 firms in the Canton of Zug;
- KYC and AML data flows in tension with data protection and the travel rule;
- data-protection challenges on-chain (pseudonymity, immutability, GDPR conflict);
- FINMA interface and outsourcing;
- cross-border data flows, EU representative, MiCA exposure;
- practical recommendations for Zug DPO mandates.
DSG ZG and DSG in the Canton of Zug
The Zug Data Protection Act, like its sister cantonal regimes, governs the processing of personal data by public bodies (cantonal administration, municipalities, cantonal agencies such as Zug Cantonal Hospital, Zug Cantonal Bank in its public-law arm, pension fund). It has been modernised in recent years, is compatible with the DSG and contains the typical elements: statutory basis, proportionality, purpose limitation, right of access, duty to inform, DPIA for high-risk processing, breach notification.
Crypto Valley companies are consistently private-sector controllers and are therefore subject to the DSG. They have no specific duty to designate a data-protection officer under Art. 10 DSG but benefit substantially from a voluntary appointment: the consultation of the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) for a DPIA with high residual risk falls away (Art. 22(5) DSG), and the DPO is a valuable interface in the FINMA supervisory process (outsourcing notifications, operational-risk audit).
The cantonal data-protection commissioner of Zug is not competent for private companies; the FDPIC in Bern is the supervisory authority. Zug-based companies should still know the cantonal practice, since it can be relevant in cantonal authority enquiries (e.g. tax administration, economic development) and in research cooperations with HSLU or the University of Zurich.
KYC, AML and the travel rule
Crypto-Asset Service Providers (CASPs) in the Canton of Zug that qualify as financial intermediaries under Art. 2(3) GwG are subject to AML duties: identification of the contractual partner (Art. 3 GwG), identification of the beneficial owner (Art. 4 GwG), clarification of the business relationship (Art. 6 GwG), retention of records for 10 years (Art. 7 GwG), notification to MROS on reasonable suspicion (Art. 9 GwG). These duties generate substantial personal-data holdings: passport and ID data, address, PEP-screening outcomes, wealth background, source attestations.
In data-protection terms the FDPIC requires for KYC holdings: clear purpose limitation (no use for marketing), strict access control, documented retention with subsequent deletion. Onward transfer to third-party providers (KYC hubs) requires a clean data-processing agreement and, for third-country transfers, SCCs and a TIA.
The FATF travel rule (Recommendation 16, transposed in Switzerland via the FINMA AML Ordinance) has required since 2024 that CASPs transmit identification data between sending and receiving VASPs for crypto-transactions from CHF 1,000. In data-protection terms this means: regular disclosure of personal data to foreign VASPs, often in third countries without adequacy. SCCs and logging are mandatory; travel-rule data must be explicitly listed in the privacy notice.
On-chain data, pseudonymity and DSG/GDPR
One of the hardest data-protection issues in the Crypto Valley is the treatment of on-chain data: wallet addresses, transaction histories, NFT ownership data, ENS names. This data is pseudonymous but re-identifiable, especially where a VASP can link a wallet address to a KYC profile. From the FDPIC's standpoint and in EU practice (EDPB pseudonymisation guidelines) a wallet address that can be linked to an identified person is personal data.
This produces three structural conflicts with data-protection law:
- Right to rectification and erasure (Art. 32 DSG, Arts. 16-17 GDPR): on-chain data is technically immutable. Workable approaches: split off-chain PII (erasable) from on-chain data (anonymisable through wallet burns); zero-knowledge architectures; storage models with encrypted pointers.
- Transfer to third countries: an on-chain transaction is visible globally. Structurally this is disclosure to "everyone". Most supervisors therefore require a transparency and risk notice rather than a formal transfer safeguard.
- Privacy by design: Art. 7 DSG requires privacy-friendly defaults. In Web3 products this means minimising on-chain PII, using layer-2 / state-channel solutions and ZK proofs in place of cleartext identification.
The EU has piled on pressure with MiCA (2023) and the AML package (AMLR/AMLD6); Swiss VASPs with EU exposure must be able to document the GDPR conformity of their on-chain architecture.
FINMA supervision and outsourcing
Crypto Valley companies licensed as banks, securities firms, DLT trading venues, fund management companies, insurers or portfolio managers (FINIG) are subject to FINMA supervision. Their data processing thus becomes part of compliance and operational-risk supervision. Relevant FINMA circulars:
- FINMA Circular 2008/21 "Operational Risks Banks" and FINMA Circular 2023/1 "Operational Risks and Resilience, Banks";
- FINMA Circular 2018/3 "Outsourcing, Banks and Insurers";
- FINMA Circular 2023/1 on cyber incidents: notification of serious cyber incidents to FINMA within 24 hours;
- supervisory communications on DLT / crypto custody, stablecoins and the travel rule.
Data-protection relevant: outsourcing to cloud providers (AWS, GCP, Azure) must be notified to FINMA and requires contractual assurance of audit and inspection rights. Crypto custody located abroad adds further layers (contractual data flows, transparency to customers).
An external data-protection adviser under Art. 10 DSG can act here as a coordinator between Compliance Officer, CISO and FINMA liaison. SIDD often combines this function with an external CISO/ISB mandate.
Cross-border data flows and MiCA
Crypto Valley companies are almost always international: customers in the EU, UK, US, Asia; staff in several jurisdictions; processors (KYC hubs, custody, trading engines, compliance tools) spread across continents. In data-protection terms this means:
- EU customers: GDPR exposure; possibly an EU representative under Art. 27 GDPR; for licensed MiCA actors with an EU establishment, the GDPR DPO duty;
- UK customers: UK GDPR and a UK representative;
- US customers: sectoral privacy (CCPA/CPRA, NYDFS, BSA), no comprehensive federal regime;
- data flows to KYC hubs in Singapore, UK, US, each with its own mechanism (SCC/IDTA).
Since the end of 2024 MiCA requires CASPs with an EU establishment to be licensed, capitalised, governed and to safeguard consumers, including data-protection conformity. Swiss CASPs serving EU customers without an EU establishment navigate a hybrid regime of FINMA + MiCA reverse solicitation + GDPR. The EU representative is here not only formally but also operationally a valuable anchor.
Stablecoin issuers and custodians with US exposure must additionally monitor the emerging US federal stablecoin legislation (GENIUS Act and successor statutes).
Practical recommendations for Zug CASPs
Recommendations for Crypto Valley companies headquartered or focused in Zug:
- Record of processing activities under Art. 12 DSG with separate sections for KYC/AML, travel rule, on-chain data flows, custody, trading, HR;
- Privacy notice in at least DE and EN, transparent on travel-rule transmissions, third-country processors and the treatment of wallet data;
- External adviser under Art. 10 DSG with notification to the FDPIC; in parallel, a GDPR DPO for the EU establishment or a representative model;
- FINMA-compliant outsourcing inventory (cloud, custody sub-providers, compliance tools) with DPAs, SCCs and TIAs;
- Privacy-by-design reviews of every new product (especially DeFi front-ends, wallet apps, treasury tools);
- Incident-response plan with three cascaded notification paths: FDPIC (breach, 72 h), FINMA (cyber incident, 24 h), BACS (critical infrastructure, 24 h), possibly EU supervisors;
- Security architecture: ISO 27001, pentests, bug bounties; for custody also SOC 2 Type II and cold-wallet procedural reviews;
- Staff training in data protection, the travel rule, phishing and social engineering, with a focus on custody operations and compliance.
Zug practice often requires a single external partner that can cover both legal advice and technical delivery.
How SIDD supports you
SIDD has served Crypto Valley firms for years as an external data-protection adviser under Art. 10 DSG and, where needed, as a GDPR DPO and EU representative. We understand the interfaces between the DSG, AML, FINMA and MiCA and work shoulder to shoulder with legal, compliance, CISO and engineering. Our mandates range from stablecoin issuers to custody providers, DeFi front-ends and institutional tokenisation platforms.
Concretely we combine a Swiss data-protection adviser under Art. 10 DSG with an EU GDPR DPO, an EU representative under Art. 27 GDPR, a UK representative, an external CISO/ISB, an ISMS / ISO 27001 build-out and a penetration test. Write to us via the contact form or request a concrete quote for your Crypto Valley company.
