ARTICLE
15 February 2017

The Swiss Privacy Shield Opens For Business On April 12

SS
Seyfarth Shaw LLP

Contributor

With more than 900 lawyers across 18 offices, Seyfarth Shaw LLP provides advisory, litigation, and transactional legal services to clients worldwide. Our high-caliber legal representation and advanced delivery capabilities allow us to take on our clients’ unique challenges and opportunities-no matter the scale or complexity. Whether navigating complex litigation, negotiating transformational deals, or advising on cross-border projects, our attorneys achieve exceptional legal outcomes. Our drive for excellence leads us to seek out better ways to work with our clients and each other. We have been first-to-market on many legal service delivery innovations-and we continue to break new ground with our clients every day. This long history of excellence and innovation has created a culture with a sense of purpose and belonging for all. In turn, our culture drives our commitment to the growth of our clients, the diversity of our people, and the resilience of our workforce.
The Swiss Privacy Shield will allow transfers of Swiss personal data to the United States in compliance with Swiss data protection requirements.
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

Beginning on April 12, 2017, U.S. organizations that are subject to the investigatory and enforcement powers of the FTC or the Department of Transportation will be able to self-certify to the newly adopted Swiss–U.S. Privacy Shield Framework ("Swiss Privacy Shield"). The Swiss Privacy Shield will allow transfers of Swiss personal data to the United States in compliance with Swiss data protection requirements. The Swiss Privacy Shield will replace the U.S.–Swiss Safe Harbor Framework and will impose similar data protection requirements established last summer for cross-border transfers of personal data from the EU under the EU–U.S. Privacy Shield ("Privacy Shield").

With the adoption of the Swiss Privacy Shield, transfers of personal data from Switzerland under the Swiss Safe Harbor Framework will no longer be permitted. Organizations currently registered with the Swiss Safe Harbor would need to certify under the Swiss Privacy Shield or implement alternative methods for complying with Swiss data transfer restrictions, such as Standard Contractual Clauses and Binding Corporate Rules. To join the Swiss Safe Harbor, organizations would need to ensure that their privacy policies, notices, statements, and procedures are in compliance with the new framework. The Department of Commerce provides sample language that can be used in an organization's privacy policy to signify its participation in the Swiss Privacy Shield.

Organizations with active Privacy Shield certifications will be able to add the Swiss Privacy Shield registration to their existing Privacy Shield accounts, at a separate annual fee. Similarly to the Privacy Shield, the fee for participation in the Swiss Privacy Shield will be tiered based on the organization's annual revenue. The exact fee structure will be made available sometime before April 12.

Notably, organizations with dual registrations, would need to recertify under both the Privacy Shield and the Swiss Privacy Shield one year from the date the first of their two certifications was finalized. That means, for instance, that an organization that registered for the Privacy Shield on September 1, 2016, which then registers for the Swiss Privacy Shield on May 1, 2017, would need to complete its annual recertification under both frameworks by September 1, 2017.

While the requirements of the two frameworks are nearly identical, there are a few differences:

  • The EU Data Protection Authorities' Swiss counterpart, Swiss Federal Data Protection and Information Commissioner (FDPIC), is given the same authority in the Swiss Privacy Shield, as the DPAs are given under the Privacy Shield.
    • For instance, under the Swiss Privacy Shield, an organization may satisfy points (a)(i) and (a)(iii) of the Recourse, Enforcement and Liability Principle by committing to cooperate with the FDPIC.
    • With respect to Swiss HR data received for use in the context of the employment relationship, organizations must commit to cooperation and compliance with the advice of the FDPIC. Under the Privacy Shield, the comparable commitment is to cooperate with the EU DPAs.
  • The definition of "sensitive data" under the Choice Principle is modified under the Swiss Privacy Shield to include "ideological or trade union-related views or activities, or information on social security measures or administrative or criminal proceedings and sanctions, which are treated outside pending proceedings."
  • At the first annual review, the Department of Commerce will work with the Swiss Government to put in place the binding arbitration option in Annex I of the Swiss Privacy Shield Framework.

Importantly, the Swiss Privacy Shield does not allow for a grace period to revise third-party contracts in compliance with the Privacy Principles. Last year, early Privacy Shield adopters were given a nine-month grace period to bring their third-party contracts in compliance, and for many organizations that time is still running. Practically speaking, those companies that plan to also certify under the Swiss Privacy Shield may hasten their grace period in order to comply with both frameworks.

As the Swiss Privacy Shield enters into force, the Privacy Shield continues to face criticism in the EU, including two separate challenges that have been lodged against the EU framework with the Court of Justice since September 2016, arguing that the framework fails to appropriately address the concerns raised by the Schrems judgment that toppled the U.S.–EU Safe Harbor on October 6, 2015. Additionally, President Trump's week-old Executive Order affecting foreigners' access to the Privacy Act may represent a unique challenge to the EU framework, adding to the criticism. This year, personal data transfers from the EU and Switzerland will remain an area to be closely monitored by U.S. companies striving to achieve compliance.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More