DE
The Role of Group Companies Under Data Protection Law

The Role of Group Companies Under Data Protection Law

The revised Data Protection Act (DSG) and the accompanying Data Protection Ordinance (DSV) have been in effect in Switzerland since September 1, 2023. This article focuses in particular on the question of how to properly handle the processing of personal data within a corporate group. With regard to intra-group data processing or data transfers between individual subsidiaries within a corporate group, the correct classification of this collaboration is of crucial importance to ensure compliance with the DSG. This is because the DSG (and also the GDPR) does not provide for a so-called “group privilege” under data protection law. This means that every data exchange between group companies within a corporate group must be considered separately and classified accordingly. The key question here is the role that the participating companies play in the respective data exchange. On the one hand, a data processing relationship between a data processor and a data controller is possible; on the other hand, processing by joint controllers is also possible.

More Information

Would you like to learn more?

Do you have any questions about this topic, or would you like a personal consultation? Write to us—we’re happy to help.