The EU’s new General Data Protection Regulation comes into effect on May 25, 2018. The preliminary draft of the complete revision of the Federal Act on Data Protection (FADP) has already been published. In both cases, compliance duties and sanctions for non-compliance will be increased. From a technical vantage point, Knowledge Management not only increases innovation, but is also useful in meeting the regulatory duties and minimizing risk. How do you combine the unpleasant with the useful?

Datenschutz symbolbild 384

A Knowledge Management system that provides an overview of aggregate data and its content streamlines compliance with data protection regulation. Data referring to a person is identified more quickly and classified into the appropriate category; for example, relevancy to the business. Not only is the duty of disclosure met more easily, but corrections and deletions are easier to execute. Private and confidential data unintentionally entering business infrastructure through various ways can be identified and will be disposed of as though it were toxic waste.

Identity Management will be a key factor alongside Knowledge Management. It is the basis of pseudonymization and Privacy by Design. State-of-the-art identification uses surnames or email addresses containing name components. If they are linked to relevancy to the business data, deletion is difficult or even impossible. In practice, there are countless authentication mechanisms besides Single-Sign-On (SSO) that all too quickly become challenging to manage.

At the SwissHoldings event ‘Datenwirtschaft, Datenpolitik, Daten­regulierung’ on January 30, 2017, three panels comprising corporate and government representatives discussed future data protection regulation. The audience heard numerous controversial statements. This is common at this stage of a legislative project. We agree that innovation must not be impeded. However, in view of the steep sanctions and obligations to combine data, we are concerned because that is what Big Data and Machine Learning is all about. The resulting innovation is difficult to grasp through conventional patterns of thought. That informational self-determination will be valued more highly is to be welcomed. Hopefully, it will be possible to integrate some intelligent ideas before passage of the bill, so that it’s not just a simple increase of duties and steeper sanctions.

Data Protection Act

The Swiss Data Protection Act underwent a complete revision in 2020, and its new version took effect on September 1, 2023, along with the new Data Protection Ordinance (DPO). The revision itself is complete, but its practical application continues to evolve. The topic of AI is particularly relevant: On May 8, 2025, the FDPIC confirmed that the DPA is technology-neutral and applies directly to all AI applications. In practice, this means, among other things, that users must know whether they are interacting with AI (transparency requirement, Art. 19), and that a data protection impact assessment is mandatory in cases of high risk—such as profiling or facial recognition (Art. 22). The Federal Office of Justice (FOJ) is drafting a consultation document on AI regulation to be completed by the end of 2026. With this, Switzerland will implement the Council of Europe's AI Convention.

Eurospider Information Technology AG
Winterthurerstrasse 92
8006 Zürich

 

Cookies make it easier for us to provide you with our services. With the usage of our services you permit us to use cookies.
More information Ok Decline