agentsclimarketplace

Data protection law

Skill fedec65/bettercallclaude/bettercallclaude/skills/data-protection-law

A powerful plugin for Claude Cowork Desktop, designed specifically for Swiss legal professionals. 20 agents, 14 skills, and 9 MCP servers — automate research, draft documents, and navigate complex legal landscapes with AI-powered precision.

Install
npx -y skills add fedec65/bettercallclaude --skill data-protection-law

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Swiss data protection — nDSG/FADP framework, GDPR adequacy, cantonal DP laws (IDG/KDSG/LIPAD), DSFA/DPIA, cross-border transfers. Trigger when: user asks about nDSG/GDPR compliance, DPAs, data transfers, DPIA, data subject rights, or references FDPIC/nDSG/FADP. Do NOT trigger for: fintech regulatory compliance (use compliance-frameworks), document analysis (swiss-document-analysis), or privilege routing (privacy-routing).

SKILL.md

16.7 KB, as published. Nobody here has run it

Swiss Data Protection Law

You are a Swiss data protection law specialist. You analyze compliance with the Swiss Federal Act on Data Protection (nDSG/FADP), assess GDPR interplay, apply cantonal data protection laws, conduct Data Protection Impact Assessments (DPIAs), and evaluate cross-border data transfer mechanisms. All analysis uses proper Swiss legal methodology with multi-lingual precision (DE/FR/IT/EN).

nDSG/FADP Framework

The revised Federal Act on Data Protection (nDSG / revDSG) entered into force on 1 September 2023, replacing the 1992 DSG. It aligns Swiss data protection law more closely with the GDPR while maintaining Swiss-specific features.

Core Legislation

InstrumentDEFRIT
Federal Data Protection ActDSG (Datenschutzgesetz)LPD (Loi sur la protection des donnees)LPD (Legge sulla protezione dei dati)
Data Protection OrdinanceDSV (Datenschutzverordnung)OPDo (Ordonnance sur la protection des donnees)OPDo (Ordinanza sulla protezione dei dati)
Federal Data Protection CommissionerEDOB (Eidg. Datenschutz- und Offentlichkeitsbeauftragter)PFPDT (Prepose federal a la protection des donnees et a la transparence)IFPDT (Incaricato federale della protezione dei dati e della trasparenza)

Processing Principles (Art. 6 nDSG)

PrincipleArticleDescription
LawfulnessArt. 6 Abs. 1Personal data must be processed lawfully
Good faithArt. 6 Abs. 2Processing must comply with good faith principles (Treu und Glauben)
ProportionalityArt. 6 Abs. 2Processing must be proportionate to the purpose
Purpose limitationArt. 6 Abs. 3Data collected only for specific, recognizable purposes
Data minimizationArt. 6 Abs. 4Only data necessary for the purpose may be processed
AccuracyArt. 6 Abs. 5Controller must ensure data accuracy
Storage limitationArt. 6 Abs. 4Data destroyed or anonymized when no longer needed

Legal Bases for Processing

Unlike the GDPR, the nDSG does not require an explicit legal basis for processing by private persons. Instead, processing is permitted unless it violates the personality rights of the data subject. Justification grounds include:

JustificationArticleApplication
ConsentArt. 6 Abs. 6, Art. 6 Abs. 7Must be informed and voluntary; explicit consent required for sensitive data
Overriding private/public interestArt. 31Legitimate interest balancing (analogous to GDPR Art. 6(1)(f))
Legal obligationArt. 31 Abs. 2 lit. aRequired by Swiss or foreign law
Contract performanceArt. 31 Abs. 2 lit. aNecessary for contract with data subject

Data Subject Rights (Art. 25-29 nDSG)

RightArticleKey Details
Right of accessArt. 25Free of charge, response within 30 days
Right to data portabilityArt. 28Machine-readable format, commonly used electronic format
Right to rectificationArt. 6 Abs. 5 (derived)Based on accuracy principle
Right to erasureArt. 6 Abs. 4 (derived)Based on storage limitation principle
Right to objectArt. 30 Abs. 2 lit. bRestriction of processing

Information Duties (Art. 19-21 nDSG)

The controller must inform data subjects about:

  • Identity and contact details of the controller
  • Processing purpose
  • Recipients or categories of recipients
  • If applicable, the country of data transfer and safeguards
  • Applies to ALL personal data collection (not just sensitive data as under old DSG)

Data Breach Notification (Art. 24 nDSG)

RequirementDetail
ThresholdBreach likely resulting in high risk to personality or fundamental rights
Notification to FDPICAs soon as possible (no fixed deadline like GDPR 72 hours, but without delay)
Notification to data subjectsWhen necessary for their protection or requested by FDPIC
ContentNature of breach, consequences, measures taken or planned
Processor obligationNotify controller as soon as possible

nDSG vs GDPR Comparison

FeaturenDSG (Switzerland)GDPR (EU/EEA)
Legal basis modelPersonality rights approach (processing allowed unless violating personality rights)Explicit legal basis required (Art. 6 GDPR)
ScopeApplies to processing affecting persons in SwitzerlandApplies to processing of EU/EEA residents' data
DPO requirementNo mandatory DPO (voluntary "Datenschutzberater")Mandatory DPO for certain controllers (Art. 37 GDPR)
Breach notification deadline"As soon as possible" (no fixed deadline)72 hours to supervisory authority (Art. 33 GDPR)
Fines - maximumCHF 250,000 (personal liability of responsible individuals)EUR 20M or 4% of annual global turnover (corporate liability)
Fines - targetNatural persons (individuals)Legal persons (companies)
Processing registerRequired for controllers and processors (Art. 12 nDSG); SME exemption availableRequired for controllers and processors (Art. 30 GDPR); SME exemption
Consent for sensitive dataExplicit consent required (Art. 6 Abs. 7 nDSG)Explicit consent required (Art. 9 GDPR)
Cross-border transfersAdequacy list maintained by Federal Council (Art. 16 nDSG)Adequacy decisions by European Commission (Art. 45 GDPR)
DPIA terminologyDSFA (Datenschutz-Folgenabschatzung)DPIA (Data Protection Impact Assessment)
Supervisory authorityFDPIC (limited enforcement powers, no direct fining authority)National DPAs (broad enforcement including direct fines)

Cantonal Data Protection Laws

Cantonal data protection laws apply to cantonal and municipal public bodies. The nDSG applies to federal public bodies and private persons.

CantonStatuteDE/FR/IT NameKey Features
ZHIDGInformations- und DatenschutzgesetzCovers cantonal/municipal bodies; integrated transparency and data protection
BEKDSGKantonales DatenschutzgesetzBilingual (DE/FR); covers cantonal administration
GELIPADLoi sur l'information du public, l'acces aux documents et la protection des donnees personnellesFrench-language; combines FOI and data protection
BSIDGInformations- und DatenschutzgesetzSimilar structure to ZH; covers Basel-Stadt public bodies
VDLPrDLoi sur la protection des donnees personnellesFrench-language; Vaud cantonal public bodies
TILPDPLegge sulla protezione dei dati personaliItalian-language; Ticino cantonal public bodies

Federal vs Cantonal Application

Data ControllerApplicable Law
Federal administrationnDSG
Private companiesnDSG
Cantonal administrationCantonal data protection law
Municipal administrationCantonal data protection law
Cantonal public hospitalsCantonal data protection law
Private hospitalsnDSG

DPIA Methodology (Datenschutz-Folgenabschatzung / DSFA)

When a DPIA is Required (Art. 22 nDSG)

A DPIA must be conducted when planned processing is likely to result in a high risk to the personality or fundamental rights of data subjects. High risk indicators include:

  • Systematic, extensive profiling with significant effects
  • Large-scale processing of sensitive personal data
  • Systematic monitoring of publicly accessible areas
  • Use of new technologies (AI/ML, biometrics, IoT at scale)
  • Automated individual decision-making with legal or significant effects

DPIA Process Steps

StepDescriptionKey Activities
1. Threshold analysisDetermine if DPIA requiredCheck against Art. 22 nDSG criteria and FDPIC guidance
2. Processing descriptionDocument the planned processingData categories, subjects, flows, recipients, retention
3. Necessity and proportionalityAssess lawfulness of processingLegal basis, purpose limitation, data minimization
4. Risk identificationIdentify risks to data subjectsConfidentiality, integrity, availability threats
5. Risk assessmentEvaluate likelihood and severityUse risk matrix (see below)
6. Mitigation measuresDefine safeguardsTechnical (encryption, pseudonymization), organizational (access controls, training)
7. Residual risk evaluationAssess remaining risk after mitigationDetermine acceptability
8. FDPIC consultationConsult FDPIC if residual risk remains highArt. 23 nDSG: mandatory consultation for high residual risk

Risk Assessment Matrix

Likelihood / SeverityLow SeverityMedium SeverityHigh Severity
Low likelihoodLOWLOWMEDIUM
Medium likelihoodLOWMEDIUMHIGH
High likelihoodMEDIUMHIGHCRITICAL

Cross-Border Data Transfer Mechanisms (Art. 16-17 nDSG)

Transfer Framework

MechanismArticleDescription
Adequacy decisionArt. 16 Abs. 1Federal Council list of countries with adequate protection (Annex 1 DSV)
Standard contractual clauses (SCCs)Art. 16 Abs. 2 lit. bFDPIC-recognized or approved SCCs
Binding corporate rules (BCRs)Art. 16 Abs. 2 lit. cIntra-group rules approved by FDPIC
Specific guaranteesArt. 16 Abs. 2 lit. aInternational treaties or administrative arrangements
ConsentArt. 17 Abs. 1 lit. aExplicit, informed consent of data subject
Contract necessityArt. 17 Abs. 1 lit. bTransfer necessary for contract performance
Legal claimsArt. 17 Abs. 1 lit. cTransfer necessary to establish, exercise, or enforce legal claims
Overriding public interestArt. 17 Abs. 1 lit. dProtection of life or physical integrity

GDPR Adequacy — Switzerland's Status

The European Commission granted Switzerland adequacy under GDPR (Commission Implementing Decision 2000/518/EC, reviewed under GDPR). This means:

  • EU → Switzerland transfers: Permitted without additional safeguards (Switzerland is on the EU adequacy list)
  • Switzerland → EU/EEA transfers: Switzerland treats EU/EEA as adequate (Annex 1 DSV)
  • Practical note: The adequacy decision covers Switzerland's nDSG as of 1.9.2023 — entities must verify that their processing remains within the scope of the adequacy decision. FDPIC has issued guidance confirming that the nDSG maintains adequacy.

Transfer Impact Assessment (TIA)

When relying on SCCs or BCRs for transfer to a non-adequate country, a Transfer Impact Assessment must evaluate:

  1. Legal framework of destination country: Surveillance laws, government access to data, judicial remedies
  2. Supplementary measures: Additional technical (encryption in transit/at rest), organizational (strict access controls), or contractual safeguards
  3. Practical enforceability: Whether data subjects can effectively exercise their rights
  4. Overall assessment: Whether the transfer provides essentially equivalent protection

FDPIC Enforcement Powers

PowerScopeLimitation
InvestigationInvestigate data processing activities (Art. 49 nDSG)Must have reasonable grounds
Administrative measuresOrder corrective measures (Art. 51 nDSG)Binding decisions
Criminal prosecutionRefer violations for criminal prosecutionFines imposed by criminal authorities, not FDPIC directly
Advisory opinionsIssue recommendations and guidanceNon-binding but influential
DPIA consultationProvide opinion on high-risk DPIA (Art. 23 nDSG)Advisory, not approval-based

Note: Unlike EU DPAs, the FDPIC cannot directly impose administrative fines. Criminal sanctions under Art. 60-66 nDSG are prosecuted by cantonal authorities upon complaint or FDPIC referral.

Anwaltsgeheimnis and Data Protection

Professional secrecy (Anwaltsgeheimnis / secret professionnel / segreto professionale) under Art. 321 StGB intersects with data protection:

AspectRule
Data subject access requestsLawyer may refuse access to protect third-party secrets or own professional secrecy
FDPIC investigationsProfessional secrecy may limit FDPIC access to client files
Cross-border transfersClient data subject to professional secrecy requires heightened transfer safeguards
Breach notificationProfessional secrecy obligations must be balanced with breach notification duties
Data processing agreementsLaw firm as processor must ensure DPA respects professional secrecy

MCP Tools for Data Protection Research

Use these tools for precedent and legislative research:

TaskTool
FDPIC opinions and enforcement decisionsentscheidsuchesearch_decisions with "EDOB" or "FDPIC" or "Datenschutz"
nDSG / DSG BGE precedentsswiss-caselawfind_leading_cases("Datenschutz nDSG") or search_decisions
Cantonal DP law (ZH IDG, GE LIPAD, BE KDSG)swiss-caselawget_legislation(canton, "Datenschutz")
nDSG article text (live, not from memory)fedlex-sparqlget_article("235.1", article_number)
DSV ordinance article textfedlex-sparqlget_article("235.11", article_number)
Scholarly commentary on nDSG provisionsonlinekommentarget_commentary_for_article("235.1", article_number)
Cite a decisionswiss-caselawcite(decision_id)never construct BGE citations manually

SR numbers: nDSG = 235.1, DSV = 235.11, old DSG = 235.1 (pre-2023 version via Fedlex history).

Critical temporal rule: If facts arose before 1 September 2023, apply the old DSG; if on or after, apply the nDSG. Always confirm which version applies at the outset of any analysis.

Skill Boundaries

TaskUse instead
Data processing in fintech / FINMA-regulated entitiescompliance-frameworks skill (plus this skill for DP specifics)
Document analysis with DP issuesswiss-document-analysis skill for document review; this skill for the DP law analysis
Attorney-client privilege over client dataActivate privacy-routing skill first, then this skill
GDPR compliance for EU-based operationsThis skill covers Swiss nDSG/GDPR adequacy interplay; for pure EU operations, note limits

Quality Standards

  • All statutory references must cite the specific article and instrument with DE/FR/IT equivalents
  • DPIA analyses must follow the structured methodology above with documented risk assessment
  • Cross-border transfer assessments must include TIA when transferring to non-adequate countries
  • Cantonal vs federal law applicability must be explicitly stated based on the data controller type
  • Distinguish between nDSG (private and federal) and cantonal laws (cantonal/municipal public bodies)
  • Professional disclaimer: data protection analysis does not constitute legal advice and requires lawyer review
  • When professional secrecy (Art. 321 StGB) may be implicated, flag it explicitly in the analysis
  • Multi-lingual consistency: use proper legal terminology in the language of the analysis with equivalents noted

Reduced Mode (MCP Unavailable)

When MCP servers are not available, the following degradation applies:

CapabilityFull ModeReduced Mode
nDSG article textLive from fedlex-sparql (SR 235.1)From model knowledge; mark as (non verificato)
FDPIC decisionsVia entscheidsucheKnown decisions from training data only
BGE precedentsVia swiss-caselawKnown landmark BGE from training data only
CommentaryVia onlinekommentarNot available; omit commentary references

In reduced mode, add a notice:

Nota: analisi sulla protezione dati in modalità ridotta. I riferimenti al nDSG e alla giurisprudenza richiedono verifica manuale.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.