What Does "DSG" Mean?, The Legal Definition in 90 Seconds
Introduction
«DSG» is an acronym with two popular meanings in German-speaking countries: Datenschutzgesetz (Data Protection Act) and Direktschaltgetriebe (direct-shift gearbox). Anyone searching in a legal or compliance context virtually always means the first. This article clarifies the legal meaning in 90 seconds and then provides the depth that is actually needed in practice. What you will take away:
- the short answer: DSG = Swiss Federal Act on Data Protection (SR 235.1);
- disambiguation from «DSG» as Volkswagen gearbox technology;
- the difference between the old aDSG and today's DSG, and why you'll still see «nDSG» in older texts;
- the key duties the DSG has placed on Swiss organisations since 1 September 2023;
- the demarcation against the EU GDPR and the German BDSG.
The article is aimed at executives and compliance leads who encounter the term for the first time in an audit, a customer request or a contract, as well as at employees who need a quick but precise answer.
The short answer in 90 seconds
FADP in a legal context stands for the Federal Act on Data Protection of Switzerland. It governs the processing of personal data by private persons and federal bodies. The current version carries the Classified Compilation number SR 235.1 and entered into force in full on 1 September 2023. Officially the act is simply called the «DSG»; depending on the generation, people add a prefix as a shorthand:
- aDSG, the «old DSG» of 1992, in force until 31 August 2023;
- «nDSG», «new DSG», a transitional label from the revision period that is no longer needed and refers to today's DSG;
- the a/n prefixes are only aids, when current sources cite the «DSG» without a prefix, they mean the act in force since 1 September 2023.
The DSG is complemented by the Data Protection Ordinance (DSV, SR 235.11), which regulates implementing details (e.g. the register under Art. 24 DSV, technical and organisational measures under Art. 1–6 DSV, third-country recognition under Art. 8 DSV).
«DSG» is also widely used as a Volkswagen brand abbreviation for Direktschaltgetriebe (a dual-clutch transmission, DCT). Anyone searching for law or compliance does not mean this, see next section.
Disambiguation: Data Protection Act vs gearbox
The double meaning matters in search behaviour. Anyone typing «buy DSG» is looking for a car. Anyone typing «DSG comply with», «DSG Switzerland», «DSG duty», «DSG access right» is looking for the Data Protection Act. Practical disambiguators:
- Context words «Switzerland», «Federal Act», «data protection» → Data Protection Act;
- Context words «VW», «Audi», «dual clutch», «gearbox» → direct-shift gearbox;
- «Art. X DSG», «nDSG», «DSG» → Data Protection Act (a gearbox has no «articles»);
- «DSG7», «DSG6», «S-tronic» → VW/Audi direct-shift gearbox variants.
This article deals exclusively with the legal meaning. Anyone seeking technical information on VW direct-shift gearboxes will be better served by a car manufacturer or a technical workshop. Everything that follows refers to the Data Protection Act.
What the DSG regulates
The DSG regulates the processing of personal data in five main chapters:
- General provisions (Art. 1–11 DSG): purpose, scope, definitions, processing principles, data security, data protection advisor, data protection impact assessment, register.
- Duties of the controller and the processor (Art. 12–18 DSG): register, processing on behalf, cross-border disclosure, representative for controllers established abroad, data security, technical and organisational measures.
- Duties towards data subjects (Art. 19–24 DSG): information at collection, automated individual decisions, breach notification.
- Rights of the data subject (Art. 25–32 DSG): right of access, data portability, rectification, erasure, further personality protection claims.
- EDÖB, criminal provisions, final provisions (Art. 33–74 DSG): tasks and powers of the EDÖB, criminal sanctions, transitional law.
The Act is complemented by the Data Protection Ordinance (DSV) and, for federal authorities, by sector-specific provisions. The most important interpretive guidance comes from the Federal Data Protection and Information Commissioner (FDPIC/EDÖB) in its activity reports and recommendations at edoeb.admin.ch.
The core duties for private companies
For Swiss SMEs and foreign companies with a Swiss nexus, the DSG imposes seven operational core duties:
- Respect the processing principles (Art. 6 DSG): good faith, proportionality, purpose limitation, data accuracy;
- Ensure data security (Art. 8 DSG) with appropriate technical and organisational measures;
- Regulate processing on behalf (Art. 9 DSG) through a written agreement (DPA);
- Maintain a register of processing activities (Art. 12 DSG, exemption under Art. 24 DSV for SMEs <250 employees without high risk);
- Fulfil the duty to inform (Art. 19 DSG) to data subjects at collection;
- Conduct a Data Protection Impact Assessment (Art. 22 DSG) where the risk is high;
- Report data breaches (Art. 24 DSG) to the EDÖB as soon as possible where a high risk to the data subject exists.
On top come the data subject rights, exercisable at any time: right of access under Art. 25 DSG (30-day deadline), data portability under Art. 28 DSG, rectification and erasure under Art. 32 DSG.
Demarcation from GDPR and BDSG
Swiss companies with an EU nexus are also subject to the EU General Data Protection Regulation (GDPR). It has been in force since 25 May 2018 and applies to (a) controllers and processors with an establishment in the EU/EEA, or (b) providers offering goods or services to persons in the EU or monitoring their behaviour (Art. 3 GDPR, market location principle).
The German BDSG (Bundesdatenschutzgesetz) is Germany's national implementation of the GDPR, with special rules among others for employee data protection (§ 26 BDSG) and video surveillance (§ 4 BDSG). It complements but does not replace the GDPR.
Substantively, DSG, GDPR and BDSG converge in their big lines (processing principles, data subject rights, processing on behalf, third-country transfers). But twelve material differences remain between DSG and GDPR, we describe them in a dedicated article: DSG vs GDPR, the 12 most important differences. Anyone subject to both regimes builds the compliance architecture best to the highest common denominator.
Frequent misconceptions about the DSG
In advisory conversations the same misunderstandings recur:
- «The DSG only applies to IT systems.» Wrong. It applies to any processing of personal data, in an Excel list, a paper file, a CRM or a cloud application.
- «The DSG does not apply to B2B data.» Partly wrong. B2B contacts (e.g. name and business email of a supplier's employee) are personal data and fall under the DSG.
- «We have fewer than 250 employees, the DSG does not apply to us.» Wrong. The SME exemption under Art. 24 DSV only releases you from the register, not from all other duties.
- «If we comply with the GDPR, we are automatically DSG-compliant.» Largely correct, but not complete. Certain DSG duties (e.g. Swiss EDÖB reporting paths, personal criminal liability, the specific information duty under Art. 19 DSG) must be added.
- «For a data breach we have 72 hours.» Imprecise. Art. 24 DSG requires reporting «as soon as possible», EDÖB practice accepts the 72-hour convention, but only if you act without undue delay.
- «There are no fines under the DSG.» Wrong. Art. 60–66 DSG provide for criminal fines against natural persons (responsible members of management) up to CHF 250,000, not an administrative fine model like the GDPR, but with personal consequences.
How SIDD supports you
SIDD, as the Institute for Data Protection and Information Security, specialises in interpreting and implementing the DSG. We act as the Data Protection Advisor (DSB) under Art. 10 DSG for SMEs, hospitals, municipalities, financial services and foreign companies with a Swiss nexus.
Typical mandates: DSG baseline assessment with a duties catalogue; ROPA build per Art. 12 DSG / Art. 30 GDPR; privacy notice per Art. 19 DSG / Art. 13–14 GDPR; DPA standardisation per Art. 9 DSG; third-country strategy per Art. 16–18 DSG including Swiss SCC and Transfer Impact Assessment; data protection workshops for executive board and employees; for dual CH/EU processing additionally GDPR DPO mandate and EU representative under Art. 27 GDPR.
Would you like to know which specific DSG duties apply to your organisation? Request a non-binding quote or contact us via the contact form. In a 30-minute initial call we clarify your needs and propose the next step.
