nDSG in Force Since 1 September 2023

The revised Federal Act on Data Protection (nDSG, neues Datenschutzgesetz) replaces the 1992 DSG and aligns Swiss data protection law with GDPR principles — while maintaining Swiss-specific features. For financial service providers including banks, Treuhänder, fiduciaries, and asset managers, the nDSG creates new obligations that overlap with — but are not identical to — GDPR.

Key New Obligations for Financial Firms

1. Data Processing Register

All firms processing personal data systematically must maintain a Register of Processing Activities (Verzeichnis der Bearbeitungstätigkeiten). Financial firms with complex data flows — client onboarding, KYC, AML, investment management, tax reporting — should audit and document all processing activities. The register must be available to the FDPIC (Eidgenössischer Datenschutzbeauftragter) upon request.

2. Privacy by Design and Privacy by Default

New systems (including AI tools for client analysis, tax intelligence, or risk scoring) must be designed with data minimisation as a default. Collecting more client data than necessary for the stated purpose violates nDSG — even if the client consented to broad terms.

3. Data Protection Impact Assessment (DPIA)

Where processing creates high risks to personality or fundamental rights — profiling, AI scoring, large-scale sensitive data processing — firms must conduct a DPIA before commencing processing. AI-based credit scoring, tax risk profiling, and AML screening tools fall into this category for financial firms.

4. Breach Notification

Data breaches likely to create high risk must be reported to the FDPIC as quickly as possible, and to affected data subjects if the risk is high. Unlike GDPR's 72-hour window, nDSG uses "as quickly as possible" — interpreted in practice as within 72 hours for high-risk breaches.

AI Tools in Swiss Financial Practice — nDSG Implications

The use of external AI tools (e.g. ChatGPT, Copilot, or AI tax intelligence platforms) to process client data raises nDSG questions:

AI tax intelligence tools that process data within Switzerland, do not use client data for training, and maintain a compliant DPA framework are nDSG-compatible for Swiss financial firms.

Professional Secrecy (Berufsgeheimnis) Interaction

Swiss Treuhänder and lawyers are subject to professional secrecy under Art. 321 StGB. Sharing client data with AI tools must be assessed under both nDSG and professional secrecy rules. Anonymised or aggregated data analysis avoids secrecy concerns; individual client data input requires careful scoping.

Source basis: nDSG (Bundesgesetz über den Datenschutz) in force 1 Sept 2023 · FDPIC Guidelines 2023 · Art. 321 StGB (Berufsgeheimnis).