Podcast
Questions and Answers
What is the maximum cost one may incur for a request for information?
What is the maximum cost one may incur for a request for information?
What is the general deadline within which a request for information must be responded to?
What is the general deadline within which a request for information must be responded to?
Which of the following is NOT a recognized form of submitting a request?
Which of the following is NOT a recognized form of submitting a request?
Who is authorized to make a request for their own data?
Who is authorized to make a request for their own data?
Signup and view all the answers
What must be done before responding to a request involving personal data?
What must be done before responding to a request involving personal data?
Signup and view all the answers
What type of applicability do some cantonal data protection laws provide for?
What type of applicability do some cantonal data protection laws provide for?
Signup and view all the answers
What is one of the key features of the electronically readable water meters used by municipality X?
What is one of the key features of the electronically readable water meters used by municipality X?
Signup and view all the answers
Which entity conducts supervision over the processing of personal data under the FADP?
Which entity conducts supervision over the processing of personal data under the FADP?
Signup and view all the answers
How often does municipality X receive the current meter reading data from the electronic water meters?
How often does municipality X receive the current meter reading data from the electronic water meters?
Signup and view all the answers
Is the measurement of water consumption dependent on the radio module being activated?
Is the measurement of water consumption dependent on the radio module being activated?
Signup and view all the answers
What is the legal basis for municipality X to introduce electronic water meters?
What is the legal basis for municipality X to introduce electronic water meters?
Signup and view all the answers
What type of data is primarily transmitted from the radio water meters?
What type of data is primarily transmitted from the radio water meters?
Signup and view all the answers
What step would differ when processing personal data by a private individual compared to a municipality?
What step would differ when processing personal data by a private individual compared to a municipality?
Signup and view all the answers
Which statement accurately reflects the territorial scope of GDPR in relation to personal data processing?
Which statement accurately reflects the territorial scope of GDPR in relation to personal data processing?
Signup and view all the answers
What differentiates data from information?
What differentiates data from information?
Signup and view all the answers
Which of the following best defines personal data according to the provided content?
Which of the following best defines personal data according to the provided content?
Signup and view all the answers
In what way is the identification of a person determined according to the context provided?
In what way is the identification of a person determined according to the context provided?
Signup and view all the answers
Why is incorrect personal data still classified as personal data?
Why is incorrect personal data still classified as personal data?
Signup and view all the answers
Which example is NOT a condition under which GDPR applies?
Which example is NOT a condition under which GDPR applies?
Signup and view all the answers
What is required for a person to be identifiable?
What is required for a person to be identifiable?
Signup and view all the answers
How does GDPR view the citizenship and nationality of the data subject?
How does GDPR view the citizenship and nationality of the data subject?
Signup and view all the answers
What is required for information to be provided in a comprehensible form according to the DPO?
What is required for information to be provided in a comprehensible form according to the DPO?
Signup and view all the answers
Under what circumstance can the right to information be limited?
Under what circumstance can the right to information be limited?
Signup and view all the answers
Who is obligated to fulfill the information requirements regarding data processing?
Who is obligated to fulfill the information requirements regarding data processing?
Signup and view all the answers
What does a Data Protection Impact Assessment (DPIA) evaluate?
What does a Data Protection Impact Assessment (DPIA) evaluate?
Signup and view all the answers
What does the burden of proof concerning data transmission lie with?
What does the burden of proof concerning data transmission lie with?
Signup and view all the answers
What does the principle of 'data protection by design' aim to achieve?
What does the principle of 'data protection by design' aim to achieve?
Signup and view all the answers
Which entities are required to keep a record of processing activities?
Which entities are required to keep a record of processing activities?
Signup and view all the answers
When must a DPIA be carried out?
When must a DPIA be carried out?
Signup and view all the answers
What does the prevailing doctrine say about data ownership under the Civil Code?
What does the prevailing doctrine say about data ownership under the Civil Code?
Signup and view all the answers
Which of the following statements is true regarding the protection of databases?
Which of the following statements is true regarding the protection of databases?
Signup and view all the answers
In the Civil Code, what does ownership entail?
In the Civil Code, what does ownership entail?
Signup and view all the answers
What is a requirement for a collection to be protected as a work under copyright law?
What is a requirement for a collection to be protected as a work under copyright law?
Signup and view all the answers
What is one criterion for the choice of law of the injured party under Art. 139 para. 3 PILA?
What is one criterion for the choice of law of the injured party under Art. 139 para. 3 PILA?
Signup and view all the answers
Which right is specifically mentioned in Art. 13 of the Constitution?
Which right is specifically mentioned in Art. 13 of the Constitution?
Signup and view all the answers
What is the main purpose of the Act on Unfair Competition concerning data?
What is the main purpose of the Act on Unfair Competition concerning data?
Signup and view all the answers
What does the FADP apply to according to Art. 2 para. 1?
What does the FADP apply to according to Art. 2 para. 1?
Signup and view all the answers
Which provision governs the ownership rights related to tangible assets according to the Civil Code?
Which provision governs the ownership rights related to tangible assets according to the Civil Code?
Signup and view all the answers
Under what circumstance would the special provisions on data processing for private persons be applicable?
Under what circumstance would the special provisions on data processing for private persons be applicable?
Signup and view all the answers
What type of rights are referred to as sui generis rights in the context of databases?
What type of rights are referred to as sui generis rights in the context of databases?
Signup and view all the answers
What is the definition of a 'federal body' as per Art. 5 let.i FADP?
What is the definition of a 'federal body' as per Art. 5 let.i FADP?
Signup and view all the answers
What primarily distinguishes ownership of data from ownership of a data carrier?
What primarily distinguishes ownership of data from ownership of a data carrier?
Signup and view all the answers
Which article states that public bodies participating in economic competition function differently under data processing laws?
Which article states that public bodies participating in economic competition function differently under data processing laws?
Signup and view all the answers
What does the territorial scope of the EU General Data Protection Regulation cover?
What does the territorial scope of the EU General Data Protection Regulation cover?
Signup and view all the answers
What does the principle of legality refer to in the context of data processing?
What does the principle of legality refer to in the context of data processing?
Signup and view all the answers
Study Notes
Data Protection and Data Management
-
Companies and judicial persons are not protected under the Federal Supervisory Authority.
-
Chapters 1-4 of the Federal Data Protection Act (FADP) apply to private and public law.
-
Chapter 1-4 of the FADP apply to private and public law.
-
Ownership of data is not in the sense of the Civil Code.
-
The prevailing doctrine does not consider data under ownership rights, but rather securing factual control and using contractual measures.
-
Distinguish between ownership to data and data carriers (e.g. hard drives).
-
Copyright protects literary and artistic intellectual creations with individual character.
-
Collections are protected as works in their own right if they are intellectual creations with individual character.
-
EU-Database rights are distinct from other forms of protection such as copyright.
-
Copyright and EU-Database rights may both apply under specific conditions.
-
Unfair competition law protects investment in a person's work.
-
A person acts unfairly when taking over another's work product ready for the market or exploiting the works of others.
-
A breach of manufacturing or trade secrecy occurs under specific circumstances.
-
Breach of manufacturing trade secrecy is defined under the Act on Unfair Competition.
-
Breach of manufacturing or trade secrecy is also a criminal offence (Art. 162 Criminal Code)
-
Important topics in contracts regarding data include Data “ownership”, protection of Know-How and confidentiality, rights of use, type of data, compilation, quantity of records, availability, and completeness.
-
Federal Act on Data Protection (FADP): Purpose is to protect natural persons' personality and fundamental rights.
-
Territorial scope is determined by Swiss law or cantonal law.
-
General data protection law sector-specific data protection law (e.g., private/public law).
-
A Private International Law (PILA) governs private law aspects and criminal code governs criminal law aspects.
-
A person whose personal data is processed has rights of personality and fundamental rights.
-
Incorrect personal data is still considered personal data.
-
Identifiability of a person is relevant to the holder of the information.
-
Anonymization and pseudonymization mean that identifiability is removed from personal data.
-
Sensitive personal data includes data on religious/philosophical/political views; health/relationships; racial/ethnic background; genetic data; biometric data; administrative/criminal procedures and sanctions; and social assistance measures.
-
Automated processing of data to evaluate personal aspects like performance at work, economic situation, health, preferences, interests, reliability, behaviour, location, etc. is considered profiling
-
High-risk profiling poses high risk to personality or fundamental rights of the data subject.
-
Disclosure (transmitting or making personal data accessible).
-
Controller is a person/federal body determining processing purpose/means.
-
Processor is a person/federal body processing data for the controller.
-
Data storage providers offer services, storing data.
-
Company ABC wishes to get information about users.
-
A U.S. citizen traveling in Europe will not be subject to European data laws in all cases.
-
A Taiwanese bank with customers holding German citizenship processes data not under European data protection.
-
The Federal Data Protection Act (FADP) defines when data processing by private persons is permitted (preventing unlawful breaches).
-
A person is allowed to process data if not prohibited (consistent with EU legislation of permitted processing of data).
-
A violation of personality rights can occur if data is processed contrary to articles 6 and 8; contrary to the wishes of the data subject; or data is disclosed to third parties without reason.
-
Consent needs to be explicit for processing sensitive personal data and for high-risk profiling.
-
There should be a legal basis for processing data and only processing of sensitive personal data may be permitted with overriding interest.
-
Breach of data subject's personality rights may also be justified by consent and/or overriding private or national interest.
-
Data subjects may have grounds to challenge the processing.
-
Overriding interests must be weighed between controller and interest of data subject.
-
Federal agencies have a legal/statutory basis for processing data.
-
Federal bodies may process data with explicit legal basis and if the rights of the data subject are not at risk.
-
Disclosure by Federal bodies requires a statutory basis.
-
Federal bodies have their own, specific obligations for handling requests for information.
-
Cantonal data protection law features unique details from the Federal Act (e.g., public bodies, private persons).
-
Some cantons may have their own data privacy laws which may differ from the Federal one (i.e., some cantons have special Data laws.)
-
EU regulations and data protection laws have global reach and consistency.
-
Data protection in Swiss law has special provisions for private and public entities.
-
Data processing (automatic analysis of personal data) may entail high risk which would require assessment.
-
Data protection impact assessments (DPO) help determine if processing risks are sufficiently protected (e.g., ensuring suitability and proportionality measures).
-
Specific regulations may apply to data concerning specific sectors and/or circumstances.
-
Principles (lawfulness, good faith, proportionality), principles and obligations regarding time.
-
Personal data accuracy, and principles of compliance.
-
Requirements (form, costs, etc.) exist concerning the data processing.
-
Privacy notices or data protection notices may need to fulfil certain legal requirements for transparency.
-
Data protection by design (and default) and considerations concerning the risks from data processing (and risk assessments).
-
Data security breaches need notification to the supervisory authority and data subject (proportionate to risk).
-
Specific aspects of data processing by processors (or any private person).
-
Requirements for data portability (Art. 28 and 29 FADP).
-
Processing of data beyond national borders, including special cases.
-
Laws in particular regions or countries have certain considerations relevant to the process.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
Test your knowledge on data protection laws and regulations, specifically focusing on the Federal Act on Data Protection (FADP). This quiz covers various aspects, including request submission, data handling, and municipal practices. Assess your understanding of how personal data is managed in accordance with relevant laws.