Ordinance on Data Protection Certification (DPCO)

By Steph3
12345678910111213141516171819202122
In The Matter OfOrdinance on Data Protection Certification (DPCO)
Exhibit A
Scroll to open

English is not an official language of the Swiss Confederation. This translation is provided for information purposes only and has no legal force.

Art. 4 Subject matter of certification

1 The following may be certified: a. management systems; b. products, services and processes. 2 The certification of management systems may cover the entire system, individual parts of the organisational structure or individual, separable procedures. 3 The certification of products, services and processes may include the following: a. products that are primarily used for processing personal data or in the use of which personal data is generated; b. services or processes that are primarily used for processing personal data or that generate personal data.

Art. 5 Requirements for the certification programme

1 In the certification programme, the following must be regulated as a minimum: a. the checking criteria and the resulting requirements that the items to be certified must meet; b. the details of the procedure, in particular the course of action in the event that irregularities are detected. 2 When establishing the certification programme, the following must be taken into account: a. the personal data to be processed; b. the electronic infrastructure used to process the personal data; c. the organisational measures in connection with processing the personal data. 3 The checking criteria must comply with all the principles set out in Article 6 FADP. 4 The certification programme must meet the standards applicable in accordance with Annex 2 AccDO and other applicable technical standards.

Para. 4 — SR 946.512

Art. 6 Requirements for the certification of management systems

1 The subject matter of the assessment of management systems is in particular: a. the data protection policy; b. the documentation on objectives, risks and measures relating to the guarantee of data protection and data security; c. the organisational and technical arrangements to be made to achieve the goals and the measures laid down, in particular for rectifying any deficiencies detected. 2 The FDPIC shall issue guidelines on the minimum requirements for the management system. In doing so, it shall take account of the international requirements relating to the construction, operation, monitoring and improvement of such management systems and in particular the following technical standards: a. SN EN ISO 9001 quality management systems, requirements; b. SN EN ISO 27001, information technology, IT security procedures, information security management systems, requirements; c. SN EN ISO/IEC 27701, IT security procedure, extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information

Para. 2 — The standards mentioned may be viewed free of charge or purchased for a fee at the Swiss Association for Standardization (SAS), Sulzerallee 70, 8404 Winterthur; www.snv.ch

Art. 7 Requirements for the certification of products, services and processes

1 The subject matter of the assessment of products, services and processes is in particular the guarantee: a. of the confidentiality, integrity, availability and traceability of the personal data being processed; b. of avoiding the processing of personal data that is not required in view of the purpose of the product, service or process; c. of transparency of the processing of personal data; d. of technical measures to support the user in complying with further data protection principles and obligations under data protection law, in particular with the rights of the data subjects. 2 The FDPIC shall issue guidelines on any further criteria under data protection law according to which the assessment must be carried out.

Art. 8 Grant and validity of data protection certification

1 The certification body shall certify the management system, the product, the service or the process if the requirements under data protection law and under this Ordinance, the guidelines issued by the FDPIC or other equivalent standards are met. Certification may be made subject to additional requirements. 2 The certification is valid for three years. The certification body must assess each year whether the requirements are still being met.

Art. 9 Recognition of foreign data protection certification

The FDPIC in consultation with the SAS shall recognise foreign certifications provided it is guaranteed that the requirements of the Swiss legislation are fulfilled.

Art. 10 Exemption from the obligation to conduct a data protection impact assessment

A private controller may only dispense with conducting a data protection impact assessment in accordance with Article 22 paragraph 5 FADP if the certification covers the processing that would have to be assessed in the data protection impact assessment.