# Data Security vs Data Protection, The Difference Simply Explained

> Data protection and data security explained simply: different objects of protection, legal bases and roles, and where they meet in the TOMs.

- Source: https://www.sidd.swiss/en/insights/data-security-vs-data-protection/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

«Data protection and data security, aren't they the same thing?» I hear this in almost every initial call. The answer is no. They are two different disciplines with different protected assets, different legal bases and different responsible roles, but they overlap at one decisive place: in the technical and organisational measures (TOMs) under Art. 8 DSG and Art. 32 GDPR. Anyone who does not understand the distinction builds compliance programmes that are either too narrow (IT security only) or too legal (only policies, no implementation).

This article explains the difference simply and shows where the overlap matters in practice. What you will take away:

- definitions of both terms and their protected assets;
- the legal bases in Switzerland and the EU;
- the roles DSB vs ISB/CISO and their interface;
- the TOM interface as the joint working field;
- a practical comparison matrix.

The audience is executive boards, IT leaders and HR leaders who need to allocate resources correctly between data protection and data security.

## Definitions: what is what

**Data protection** is the legal concept that protects the personality of natural persons against unlawful processing of their personal data. The protected asset is *informational self-determination*, the right of every person to decide who has which data about them and what these data are used for. Data protection addresses *every* form of processing: collection, storage, use, disclosure, deletion, digital or on paper.

**Data security** is the technical and organisational concept that protects data against loss, alteration and unauthorised access. The protected asset are the three classical security objectives **CIA**: *Confidentiality*, *Integrity* and *Availability*. Often extended by authenticity and non-repudiation. Data security applies to *all* data, personal data as well as trade secrets, engineering drawings, source code.

In short: data protection answers *«am I allowed to do this?»*, data security answers *«how do I protect it?»*. Both are needed: an organisation can be technically perfectly protected and still infringe data protection (e.g. unlawful profiling with state-of-the-art encryption). Or the opposite: document every legal obligation, but store the data on an unprotected cloud server.

## Legal bases in Switzerland

In Switzerland both disciplines have legal anchors, but in different places.

**Data protection** is governed by the *Federal Act on Data Protection (DSG, SR 235.1)* and the *Data Protection Ordinance (DSV, SR 235.11)*. Core provisions:

- processing principles (Art. 6 DSG);
- duty to inform (Art. 19 DSG);
- right of access (Art. 25 DSG);
- Data Protection Impact Assessment (Art. 22 DSG);
- duty to notify breaches to the EDÖB (Art. 24 DSG, 72h convention).

**Data security** is primarily governed by the *Information Security Act (ISG, SR 128)* since 1 January 2024 for the federal administration. For the private sector it follows from Art. 8 DSG (TOMs for personal data), Art. 9 DSV (specific requirements), sector-specific rules (e.g. FINMA Circular 2023/1 for banks, the Health Insurance Act for hospitals, the confidentiality duty under Art. 320 SCC for medical professions) and standards such as ISO/IEC 27001:2022. Since 1 January 2025 the **duty to report cyber attacks on critical infrastructures** to BACS applies (Art. 74a ff. ISG, 24h).

In the EU the split into the GDPR (data protection) and the NIS2 Directive (cyber security) for essential entities is explicit. Both regimes require TOMs and incident reporting, but to different authorities and on different timelines.

## Roles: DSB vs ISB/CISO

The accountable roles follow the split of the disciplines.

**Data Protection Advisor (DSB)** under Art. 10 DSG is a legal-leaning function. Duties:

- advising the executive board on data protection matters;
- handling access requests under Art. 25 DSG;
- accompanying Data Protection Impact Assessments under Art. 22 DSG;
- acting as point of contact for the EDÖB under Art. 23(4) DSG;
- training employees on data protection.

**Information Security Officer (ISB)** or **Chief Information Security Officer (CISO)** is a technical-organisational function. Duties:

- building and running an Information Security Management System (ISMS) per ISO/IEC 27001;
- maintaining the risk register per ISO/IEC 27005;
- coordinating technical and organisational measures (access control, encryption, backup, monitoring);
- incident response and forensics;
- reporting to BACS or FINMA in cyber incidents.

In personal data breaches DSB and ISB work hand in hand: the ISB analyses the security incident, the DSB assesses the risk to the data subject and decides on the EDÖB notification under Art. 24 DSG. A clean RACI matrix avoids duplication and role conflicts.

## The TOM interface, where the two meet

There is one place where data protection and data security overlap inevitably: in the **technical and organisational measures (TOMs)**. Art. 8 DSG requires the controller to take «appropriate technical and organisational measures» so that data processing complies with the Act, in particular to prevent data security breaches. Art. 32 GDPR is phrased almost identically.

Art. 1–6 DSV operationalise the TOMs for Switzerland and reference in practice the eight classical protection objectives: physical access control, system access control, data access control, transmission control, input control, availability control, separation control, pseudonymisation/encryption. In practice these map onto ISO/IEC 27001:2022 Annex A:

- **Access control** ↔ Annex A.5.15 (Access Control);
- **Encryption** ↔ Annex A.8.24 (Use of Cryptography);
- **Backup/availability** ↔ Annex A.8.13 (Information Backup);
- **Input control/logging** ↔ Annex A.8.15 (Logging);
- **Employee training** ↔ Annex A.6.3 (Information Security Awareness, Education and Training).

Anyone building an ISO/IEC 27001 ISMS thereby covers about 70% of the TOM duty under Art. 8 DSG / Art. 32 GDPR. The remaining 30% concern purely data-protection aspects (e.g. pseudonymisation as protection against re-identification, sensitivity-based data classification, deletion and retention concepts under Art. 6(4) DSG).

## Practical examples, when which applies

Concrete scenarios make the difference tangible:

- **Example 1, data protection breach without security incident:** a case worker accidentally sends an Excel list with customer data to the wrong email recipient. Technically everything is correct (encrypted transmission, MFA, backup). Legally there is a breach of processing principles (Art. 6 DSG) and possibly a data breach (Art. 24 DSG).
- **Example 2, security incident without data protection nexus:** a ransomware attack encrypts a company's engineering drawings. No personal data are affected. Data protection does not apply, data security (and the BACS reporting duty for critical infrastructures) very much does.
- **Example 3, both at once:** theft of a laptop with an unencrypted customer database. Data protection breach (Art. 8/24 DSG), security incident (Annex A.8.24 ISO 27001 not implemented), reporting duties to the EDÖB *and* potentially BACS.
- **Example 4, unlawful processing with perfect security:** a company collects detailed profiles of its website visitors without a legal basis. The data are technically perfectly protected, but the processing violates Art. 6(3) DSG (purpose limitation). An EDÖB investigation follows after a complaint by a data subject.

These examples show: the two disciplines are complementary. An organisation needs both, with clearly assigned responsibility and a shared operating model.

## Comparison matrix, six dimensions

For quick orientation, a comparison matrix along six dimensions:

- **Protected asset:** data protection protects the personality of natural persons; data security protects CIA for all data.
- **Data types:** data protection addresses personal data only (DSG/GDPR); data security addresses all data (personal data, trade secrets, IP).
- **Legal basis Switzerland:** DSG/DSV for data protection; ISG, Art. 8 DSG, FINMA circulars, ISO/IEC 27001 for data security.
- **Role:** DSB (Data Protection Advisor, legal); ISB/CISO (technical-organisational).
- **Notification duty:** EDÖB within 72h for personal data breaches; BACS within 24h for critical infrastructures; FINMA within 24h for banks/insurers.
- **Sanction:** DSG criminal liability against natural persons up to CHF 250,000 (Art. 60–66 DSG); GDPR administrative fines against companies up to EUR 20m / 4% turnover (Art. 83); data security often sector-specific (FINMA measures, BACS oversight).

Operationally, data protection and data security should be run jointly, ideally in an integrated governance model (e.g. ISO/IEC 27001 plus ISO/IEC 27701 or a single integrated ISMS/PIMS). This saves duplicated work and raises the effectiveness of both disciplines.

## How SIDD supports you

SIDD combines both disciplines under one roof. Our [Data Protection Advisors under Art. 10 DSG](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) work hand in hand with our [external CISOs/ISBs](https://www.sidd.swiss/en/services/vciso), so you get a consistent compliance programme, without duplication and without gaps at the TOM interface.

We build your [ISMS per ISO/IEC 27001:2022](https://www.sidd.swiss/en/services/iso-27001-isms) with an integrated data-protection module (PIMS per ISO/IEC 27701), run [penetration tests](https://www.sidd.swiss/en/services/penetration-test) and [vulnerability scans](https://www.sidd.swiss/en/services/vulnerability-scan), and train your employees in [data protection](https://www.sidd.swiss/en/services/data-protection-workshop-sme) and [IT security workshops](https://www.sidd.swiss/en/services/it-security-workshop-sme).

Would you like to know where your organisation stands today on both disciplines? Request a non-binding [quote](https://www.sidd.swiss/en/quote) or contact us via the [contact form](https://www.sidd.swiss/en/contact). In a 30-minute initial call we will clarify the right setup for your industry and size.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
