Intelligence Service Act (IntelSA)

By Steph6
12345678910111213141516171819202122
In The Matter OfIntelligence Service Act (IntelSA)
Exhibit A
Scroll to open

English is not an official language of the Swiss Confederation. This translation is provided for information purposes only and has no legal force.

Section 1 Principles, Quality Assurance and Data P

Art. 44 Principles

1 The FIS and the cantonal executive authorities are authorised to process personal data, including personal data that permits an assessment of the level of risk that a person poses, irrespective of whether the data are sensitive personal data or not. 2 The FIS may also process information that proves to be disinformation or false information if this is necessary in order to assess the situation or a source. It shall mark the relevant data as incorrect. 3 It may transfer the same data to several information systems. The specifications for the information system concerned apply. 4 It may record data within an information system through a network and evaluate it automatically.

Para. 1 — Amended by Annex 1 No II 2 of the Data Protection Act of 25 Sept. 2020, in force since 1 Sept. 2023 (AS 2022 491; BBl 2017 6941).

Art. 45 Quality assurance

1 The FIS shall assess the relevance and accuracy of personal data before recording it in an information system. Reports that contain several sets of personal data shall be assessed in their entirety before they are recorded in the filing system. 2 It shall only record data that may be used to fulfil the tasks in accordance with Article 6, subject to compliance with Article 5 paragraphs 5–8. 3 It shall destroy data that may not be recorded in any information system or return it to the sender for further investigation or for processing on the sender’s own initiative. 4 It shall periodically check in all information systems whether the recorded sets of personal data are still required to carry out its tasks. It shall delete data records that are no longer required. Incorrect data shall be corrected immediately or deleted; Article 44 paragraph 2 remains reserved. 5 The FIS’s internal quality assurance service shall carry out the following tasks: a. it shall review the personal data in the

Art. 46 Data processing in the cantons

1 The cantonal executive authorities shall not maintain any databases of their own in application of this Act. 2 If the cantons process data on their own initiative, they shall ensure that the cantonal data makes no reference to the existence or content of federal data. 3 The cantonal executive authorities may pass on situation assessments and data that they receive from the FIS if this is necessary in order to assess measures to safeguard security or to avert a significant danger. The Federal Council shall regulate the agencies and the extent to which assessments and data may be passed on.

Para. 1 — Amended by Annex 1 No II 2 of the Data Protection Act of 25 Sept. 2020, in force since 1 Sept. 2023 (AS 2022 491; BBl 2017 6941).

Section 2 Intelligence Information Systems

Art. 47 FIS information systems

1 The FIS shall operate the following information systems in order to carry out its tasks in accordance with Article 6: a. IASA FIS (Art. 49); b. IASA-GEX FIS (Art. 50); c. INDEX FIS (Art. 51); d. GEVER FIS (Art. 52); e. ESD (Art. 53); f. OSINT portal (Art. 54); g. Quattro P (Art. 55); h. ISCO (Art. 56); i. residual data memory (Art. 57). 2 For each FIS information system, the Federal Council shall regulate: a. the catalogue of personal data; b. responsibilities for data processing; c. access rights; d. the frequency of quality assurance, taking account of the seriousness of the interference in constitutional rights caused by data processing; e. the retention period for the data, taking account of the specific needs of the FIS in relation to the task areas concerned; f. the deletion of the data; g. data security.

Art. 48 Allocation of data to the information systems

The FIS shall allocate incoming data as follows: a. data with information about violent extremism: to the IASA-GEX FIS system; b. data with information that initiates administrative processes only: the GEVER FIS system; c. data with information related to security measures only: the ESD system; d. data from publicly accessible sources: the OSINT portal system; e. data from border and customs checks: the Quattro P system; f. data that is used only for task management and for controlling radio and cable communications intelligence: the ISCO system; g. other data: the residual data memory system.

Art. 49 IASA FIS

1 The FIS integral analysis system (IASA FIS) is used for the intelligence evaluation of data. 2 It contains data relating to the task areas in Article 6 paragraph 1, with the exception of data on violent extremism. 3 FIS employees that have the task of recording, researching, evaluating and assuring the quality of the data have online access to IASA FIS. They may carry out data searches with the aid of IASA FIS in all FIS information systems to which they hold access rights.

Art. 50 IASA-GEX FIS

1 The FIS integral analysis system for violent extremism (IASA-GEX FIS) is used for recording, processing and evaluating information relating to violent extremism. 2 It contains data relating to violent extremism. 3 FIS employees that have the task of recording, researching, evaluating and assuring the quality of the data have online access to IASA-GEX FIS.

Art. 51 INDEX FIS

1 The INDEX FIS information system is used: a. to establish whether the FIS is processing data relating to a person, an organisation, a group, an object or an event; b. to store reports prepared by the cantonal executive authorities; c. to process data from preliminary investigations carried out by the cantonal executive authorities. 2 It enables authorities that are not connected to the specially secured FIS network to access data that they need to fulfil their statutory tasks, and the secure transmission of such data. 3 It contains: a. data for the identification of the persons, organisations, groups, objects and events recorded in the IASA FIS and IASA-GEX FIS information systems; b. the reports prepared by the cantonal executive authorities independently or on behalf of the FIS; c. data from preliminary investigations carried out by the cantonal executive authorities. 4 The following persons have online access to the following data in INDEX FIS: a. FIS employees have access to the

Para. 4 let. d — Amended by Annex 1 No 2 of the Information Security Act of 18 Dec. 2020, in force since 1 Jan. 2024 (AS 2022 232; 2023 650; BBl 2017 2953). Para. 4 let. d — SR 128

Art. 52 GEVER FIS

1 The FIS information system for records and process management (GEVER FIS) is used for the processing and control of business and to ensure efficient work processes. 2 It contains: a. data on administrative transactions; b. all outgoing FIS intelligence products; c. data that was used to prepare content in terms of letters a and b; d. information required for the business controls, in particular in connection with personnel security screening procedures. 3 FIS employees have online access to GEVER FIS.

Art. 53 ESD

1 The Electronic Situation Display system (ESD) is used by the competent federal authorities and the cantons as a management instrument and for disseminating information with a view to controlling and implementing security policy measures, in particular in the event of incidents in which acts of violence are anticipated. 2 It contains data about incidents and about measures to safeguard internal or external security. 3 FIS employees and the responsible federal and cantonal authorities that have the task of managing security policy or assessing or dealing with situation-relevant incidents have online access to the ESD. 4 In the case of special incidents, the FIS may also allow private agencies and foreign security and police authorities temporary online access. Access is limited to the data in the system that these agencies and authorities require to fulfil their tasks in dealing with the incident concerned.

Art. 54 OSINT portal

1 The FIS uses the Open Source Intelligence Portal (OSINT portal) to obtain data from publicly accessible sources. 2 It contains data that is available when using publicly accessible sources. 3 FIS employees have online access to the OSINT portal. 4 Employees of the cantonal executive authorities may be allowed online access to certain data in the OSINT portal.

Art. 55 Quattro P

1 The FIS may operate an information system (Quattro P) that is used to identify certain categories of foreign nationals that enter or leave Switzerland and to monitor their entry and exit data. 2 It contains data obtained at border posts in the course of border and customs checks which may be used to identify the persons and track their travel movements. 3 FIS employees that are required to identify persons in order to fulfil tasks in accordance with Article 6 have online access to Quattro P. 4 The Federal Council shall determine in a non-public list the categories of persons to be recorded in Quattro P; in doing so it shall take account of the threat situation at the time.

Art. 56 ISCO

1 The communications monitoring information system (ISCO) is used to monitor and direct radio and cable communications intelligence. 2 It contains data to operate the intelligence gathering equipment and for controlling and reporting. 3 FIS employees that have the task of carrying out radio and cable communications intelligence have online access to ISCO.

Art. 57 Residual data memory

1 The residual data memory is used to store data that cannot be immediately allocated to another system in accordance with Article 48. 2 If an information entry in the residual data memory contains personal data, an assessment of relevance and accuracy in accordance with Article 45 paragraph 1 is made for the entry as a whole and not in relation to the individual personal data. An individual assessment is made if the personal data is transferred to another information system. 3 FIS employees that have the task of recording, researching, evaluating and assuring the quality of the data have online access to the residual data memory. 4 The maximum retention period for the data is 10 years.

Section 3 Data from Information Gathering Measures

Art. 58

1 The FIS shall store the data from information gathering measures requiring authorisation in accordance with Article 26 on a case-related basis and separately from the information systems listed in Article 47. 2 It shall ensure that personal data originating from information gathering measures requiring authorisation that is not related to the specific threat situation is not used and is destroyed at the latest 30 days after conclusion of the measure. 3 If the information gathering measure requiring authorisation relates to a person who belongs to any of professional groups mentioned in Articles 171–173 CrimPC, data that is not related to the specific threat situation shall be separated and destroyed under the supervision of the Federal Administrative Court. If the information gathering measure requiring authorisation relates to another person, data about which a person has the right to refuse to testify in accordance with Articles 171–173 CrimPC must also be destroyed. 4 In specific

Para. 3 — SR 312.0 Para. 3 — Corrected by the Federal Assembly Drafting Committee (Art. 58 para. 1 ParlA; SR 171.10).

Section 4 Special Provisions on Data Protection

Art. 59 Verification before disclosure

The FIS shall ensure before disclosing any personal data or products that the personal data satisfies the legal requirements of this Act and that its disclosure is lawful and necessary in the case concerned.

Art. 60 Disclosure of personal data to Swiss authorities

1 The FIS shall disclose personal data to domestic authorities if this is necessary in order to safeguard internal or external security. The Federal Council shall determine the authorities concerned. 2 Where information obtained by the FIS may be used by other authorities to prosecute offences, prevent serious offences or to maintain public order, the FIS shall while protecting its sources make this data available to them without being requested to do so or on request. 3 The FIS shall always disclose data from information gathering measures requiring authorisation to a prosecution authority if it contains specific evidence of an offence in connection with the prosecution of which the prosecution authority would have been entitled to order a comparable criminal procedural measure. 4 The FIS shall advise the prosecution authorities of the origin of the data. The subsequent procedure is governed by the CrimPC or the Military Criminal Procedure Code of 23 March 1979.

Para. 4 — SR 312.0 Para. 4 — SR 322.1

Art. 61 Disclosure of personal data to foreign authorities

1 The FIS may disclose personal data or lists of personal data to foreign countries. It shall verify before any disclosure whether the legal requirements for disclosure are met. 2 If the legislation of the receiving state does not guarantee appropriate data protection, the personal data may be disclosed to this state in derogation from Article 16 paragraph 1 of the Data Protection Act of 25 September 2020 on (FADP) only if Switzerland maintains diplomatic relations with that state and one of the following requirements is met: a. Switzerland is required by law or by an international agreement to disclose the personal data to the state. b. Disclosure is required to safeguard an overriding public security interest in Switzerland or in the receiving state such as preventing a serious criminal offence which is also a serious offence in Switzerland or bringing its perpetrators to justice. c. It is necessary in order to justify a request for information from Switzerland. d. It is in the inter

Para. 2 — SR 235.1 Para. 2 — Amended by Annex 1 No II 2 of the Data Protection Act of 25 Sept. 2020, in force since 1 Sept. 2023 (AS 2022 491; BBl 2017 6941). Para. 5 — SR 0.101

Art. 62 Disclosure of personal data to third parties

The disclosure of personal data to third parties is only permitted if: a. the person concerned has consented to disclosure or disclosure is indisputably in the interest of the person concerned; b. disclosure is necessary in order to repel a serious immediate danger; c. disclosure is necessary in order to justify a request for information.

Art. 63 Right to information

1 The right to information relating to the ESD, OSINT portal and Quattro P information systems, the administrative data in GEVER FIS and data in the storage systems in accordance with Articles 36 paragraph 5 and 58 is governed by the FADP. 2 If a person requests information on whether the FIS is processing data on them in the IASA FIS, IASA-GEX FIS, INDEX FIS or ISCO information systems, the residual data memory or in the GEVER FIS intelligence data, the FIS shall defer its response: a. if and to the extent that there are overriding interests that are justified in the files in preserving secrecy in relation to the data about the person that is being processed that are connected with: 1. the fulfilment of a task in accordance with Article 6, or 2. a prosecution or other investigation; b. if and to the extent that it is required because of overriding interests of third parties; or c. if no data about the applicant is being processed. 3 The FIS shall notify the applicant that it is deferr

Para. 1 — SR 235.1

Art. 64 Examination by the FDPIC

1 The FDPIC shall conduct an examination in accordance with Article 63 paragraph 3 if so requested by the applicant. 2 It shall notify the applicant either that no data relating to the applicant has been unlawfully processed or that it has identified errors relating to the deferral of the provision of information and has opened an investigation under Article 49 FADP. 3 … 4 If it identifies errors while processing the data or when deferring the provision of information, it shall order the FIS to rectify the same. 5 If the applicant credibly shows that a deferral of the provision of information will cause him or her considerable harm that cannot be rectified, the FDPIC may order the FIS to issue information immediately by way of exception provided this will not pose a risk to internal or external security.

Para. 2 — SR 235.1 Para. 2 — Amended by Annex 1 No II 2 of the Data Protection Act of 25 Sept. 2020, in force since 1 Sept. 2023 (AS 2022 491; BBl 2017 6941). Para. 3 — Repealed by Annex 1 No II 2 of the Data Protection Act of 25 Sept. 2020, with effect from 1 Sept. 2023 (AS 2022 491; BBl 2017 6941). Para. 4 — Amended by Annex 1 No II 2 of the Data Protection Act of 25 Sept. 2020, in force since 1 Sept. 2023 (AS 2022 491; BBl 2017 6941). Para. 5 — Amended by Annex 1 No II 2 of the Data Protectio

Art. 65

Repealed by Annex 1 No II 2 of the Data Protection Act of 25 Sept. 2020, with effect from 1 Sept. 2023 (AS 2022 491; BBl 2017 6941).

Art. 66 Form of notification and exclusion of appeals

1 The notifications in accordance with Articles 63 paragraph 3 and 64 paragraph 2 shall always be worded in the same way and do not contain a statement of reasons. 2 The persons concerned may not contest the notifications.

Para. 1 — Amended by Annex 1 No II 2 of the Data Protection Act of 25 Sept. 2020, in force since 1 Sept. 2023 (AS 2022 491; BBl 2017 6941).

Art. 67 Exception from the principle of freedom of information

The Freedom of Information Act of 17 December 2004 does not apply to access to official documents relating to information gathering in terms of this Act.

SR 152.3

Section 5 Archiving

Art. 68

1 The FIS shall offer data and files that are no longer required or that are earmarked for destruction to the Federal Archives. The Federal Archives shall archive data and files from the FIS in specially secured rooms. They are subject to a 50‑year retention period. 2 For archive materials that originate from foreign security services, the Federal Council may extend the retention period on several occasions for a limited period in accordance with Article 12 of the Archiving Act of 26 June 1998 if the foreign security service concerned expresses reservations against any inspection. 3 The FIS may in specific cases inspect personal data during the retention period that it has passed to the Federal Archives for archiving in order to assess specific threats to internal or external security or to safeguard any other overriding public interest. 4 It shall destroy data and files that the Federal Archives has designated as not worth archiving.

Para. 2 — SR 152.1