EUR-Lex Access to European Union law

Back to EUR-Lex homepage

This document is an excerpt from the EUR-Lex website

Document 32000D0518

2000/518/EC: Commission Decision of 26 July 2000 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data provided in Switzerland (notified under document number C(2000) 2304) (Text with EEA relevance.)

OJ L 215, 25.8.2000, p. 1–3 (ES, DA, DE, EL, EN, FR, IT, NL, PT, FI, SV)
Special edition in Czech: Chapter 16 Volume 001 P. 116 - 118
Special edition in Estonian: Chapter 16 Volume 001 P. 116 - 118
Special edition in Latvian: Chapter 16 Volume 001 P. 116 - 118
Special edition in Lithuanian: Chapter 16 Volume 001 P. 116 - 118
Special edition in Hungarian Chapter 16 Volume 001 P. 116 - 118
Special edition in Maltese: Chapter 16 Volume 001 P. 116 - 118
Special edition in Polish: Chapter 16 Volume 001 P. 116 - 118
Special edition in Slovak: Chapter 16 Volume 001 P. 116 - 118
Special edition in Slovene: Chapter 16 Volume 001 P. 116 - 118
Special edition in Bulgarian: Chapter 16 Volume 001 P. 61 - 63
Special edition in Romanian: Chapter 16 Volume 001 P. 61 - 63
Special edition in Croatian: Chapter 16 Volume 001 P. 28 - 30

Legal status of the document In force: This act has been changed. Current consolidated version: 17/12/2016

ELI: http://data.europa.eu/eli/dec/2000/518/oj

32000D0518

2000/518/EC: Commission Decision of 26 July 2000 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data provided in Switzerland (notified under document number C(2000) 2304) (Text with EEA relevance.)

Official Journal L 215 , 25/08/2000 P. 0001 - 0003


Commission Decision

of 26 July 2000

pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data provided in Switzerland

(notified under document number C(2000) 2304)

(Text with EEA relevance)

(2000/518/EC)

THE COMMISSION OF THE EUROPEAN COMMUNITIES,

Having regard to the Treaty establishing the European Community,

Having regard to Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data(1), and in particular Article 25(6) thereof,

Whereas:

(1) Pursuant to Directive 95/46/EC Member States are required to provide that the transfer of personal data to a third country may take place only if the third country in question ensures an adequate level of protection and if the Member State's laws implementing other provisions of the Directive are complied with prior to the transfer.

(2) The Commission may find that a third country ensures an adequate level of protection. In that case, personal data may be transferred from the Member States without additional guarantees being necessary.

(3) Pursuant to Directive 95/46/EC the level of data protection should be assessed in the light of all the circumstances surrounding a data transfer operation or a set of data transfer operations, and in respect of given conditions. The Working Party on Protection of Individuals with regard to the processing of Personal Data established under that Directive has issued guidance on the making of such assessments(2).

(4) Given the different approaches to data protection in third countries, the adequacy assessment should be carried out and any decision based on Article 25(6) of Directive 95/46/EC should be enforced in a way that does not arbitrarily or unjustifiably discriminate against or between third countries where like conditions prevail nor constitute a disguised barrier to trade, regard being had to the Community's present international commitments.

(5) As regards the Swiss Confederation, the legal standards on the protection of personal data have binding legal effect at both Federal and cantonal level.

(6) The Federal Constitution, which was amended by referendum on 18 April 1999 and which entered into force on 1 January 2000, gives every person the right to have his privacy respected and, in particular, to be protected from the misuse of data concerning him. The Federal Court has, on the basis of the previous Constitution, which did not contain any such provision, developed a case-law laying down the general principles applicable to the processing of personal data concerning, in particular, the quality of the data processed, the right of access of the persons concerned, and the right to request the correction or destruction of data. These principles are binding both on the Federation and on each canton.

(7) The Swiss Data Protection Act of 19 June 1992 entered into force on 1 July 1993. The implementing rules for certain provisions of the Act concerning, in particular, the right of access of the persons concerned, the notification of processing operations to the independent supervisory authority, and the transfer of data to a foreign country were laid down by order of the Federal Council. The Act applies to the processing of personal data by Federal bodies and by the entire private sector, and to processing operations carried out by cantonal bodies pursuant to Federal law, where such processing is not subject to cantonal provisions on data protection.

(8) Most of the cantons have adopted legislation on data protection for the areas for which they are competent, in particular public hospitals, education, direct cantonal taxes and the police. In the remaining cantons, such data processing is governed by regulatory acts or by the principles of cantonal case-law. Whatever the source and content of the cantonal provisions, or even if no cantonal provisions exist, cantons must adhere to the constitutional principles. In their field of responsibility, the cantonal authorities may have to transfer personal data to public authorities in neighbouring countries, mainly for the purpose of mutual assistance to safeguard important public interests or, in the case of public hospitals, to protect the vital interest of the persons concerned.

(9) On 2 October 1997, Switzerland ratified the Council of Europe Convention on the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention No 108)(3), which aims to reinforce the protection of personal data and to ensure free circulation between the contracting parties, subject to any exceptions which these parties may provide for. Without being directly applicable, the Convention lays down the international commitments of both the Federation and the cantons. These commitments concern not only the basic principles of protection which each contracting party must implement in its internal law but also the mechanisms of cooperation between the contracting parties. In particular, the competent Swiss authorities must provide the authorities of the other contracting parties which so request with any information on the law and administrative practice regarding data protection, and with information on any specific instance of automatic processing of data. They must also assist any person residing abroad in exercising his right to be informed about the existence of processing operations on data concerning him, the right to access his data or to ask for them to be corrected or deleted, and the right of judicial remedy.

(10) The legal standards applicable in Switzerland cover all the basic principles necessary for an adequate level of protection for natural persons, even if exceptions and limitations are also provided for in order to safeguard important public interests. The application of these standards is guaranteed by judicial remedy and by independent supervision carried out by the authorities, such as the Federal Commissioner invested with powers of investigation and intervention. Furthermore, the provisions of Swiss law regarding civil liability apply in the event of unlawful processing which is prejudicial to the persons concerned.

(11) In the interests of transparency and in order to safeguard the ability of the competent authorities in the Member States to ensure the protection of individuals as regards the processing of their personal data, it is necessary to specify in this Decision the exceptional circumstances in which the suspension of specific data flows may be justified, notwithstanding the finding of adequate protection.

(12) The Working Party on Protection of Individuals with regard to the processing of Personal Data established under Article 29 of Directive 95/46/EC has delivered Opinions on the level of protection provided by Swiss law which have been taken into account in the preparation of this Decision(4).

(13) The measures provided for in this Decision are in accordance with the opinion of the Committee established under Article 31 of Directive 95/46/EC,

HAS ADOPTED THIS DECISION:

Article 1

For the purposes of Article 25(2) of Directive 95/46/EC, for all the activities falling within the scope of that Directive, Switzerland is considered as providing an adequate level of protection for personal data transferred from the Community.

Article 2

This Decision concerns only the adequacy of protection provided in Switzerland with a view to meeting the requirements of Article 25(1) of Directive 95/46/EC and does not affect other conditions or restrictions implementing other provisions of that Directive that pertain to the processing of personal data within the Member States.

Article 3

1. Without prejudice to their powers to take action to ensure compliance with national provisions adopted pursuant to provisions other than Article 25 of Directive 95/46/EC, the competent authorities in Member States may exercise their existing powers to suspend data flows to a recipient in Switzerland in order to protect individuals with regard to the processing of their personal data in cases where:

(a) a competent Swiss authority has determined that the recipient is in breach of the applicable standards of protection; or

(b) there is a substantial likelihood that the standards of protection are being infringed; there are reasonable grounds for believing that the competent Swiss authority is not taking or will not take adequate and timely steps to settle the case at issue; the continuing transfer would create an imminent risk of grave harm to data subjects and the competent authorities in the Member State have made reasonable efforts in the circumstances to provide the party responsible for processing established in Switzerland with notice and an opportunity to respond.

The suspension shall cease as soon as the standards of protection are assured and the competent authority concerned in the Community is notified thereof.

2. Member States shall inform the Commission without delay when measures are adopted on the basis of paragraph 1.

3. The Member States and the Commission shall also inform each other of cases where the action of bodies responsible for ensuring compliance with the standards of protection in Switzerland fails to secure such compliance.

4. If the information collected under paragraphs 1, 2 and 3 provides evidence that any body responsible for ensuring compliance with the standards of protection in Switzerland is not effectively fulfilling its role, the Commission shall inform the competent Swiss authority and, if necessary, present draft measures in accordance with the procedure under Article 31 of Directive 95/46/EC with a view to repealing or suspending this Decision or limiting its scope.

Article 4

1. This Decision may be amended at any time in the light of experience with its functioning or of changes in Swiss legislation.

The Commission shall evaluate the functioning of this Decision on the basis of available information, three years after its notification to the Member States and report any pertinent findings to the Committee established under Article 31 of Directive 95/46/EC, including any evidence that could affect the finding in Article 1 of this Decision that protection in Switzerland is adequate within the meaning of Article 25 of Directive 95/46/EC and any evidence that this Decision is being implemented in a discriminatory way.

2. The Commission shall, if necessary, present draft measures in accordance with the procedure established by Article 31 of Directive 95/46/EC.

Article 5

Member States shall take all the measures necessary to comply with this Decision at the latest at the end of a period of 90 days from the date of its notification to the Member States.

Article 6

This Decision is addressed to the Member States.

Done at Brussels, 26 July 2000.

For the Commission

Frederik Bolkestein

Member of the Commission

(1) OJ L 281, 23.11.1995, p. 31.

(2) Opinion 12/98, adopted by the Working Party on 24.7.1998: "Transfers of personal data to third countries. Applying Articles 25 and 26 of the EU Data Protection Directive" (DG MARKT D/5025/98), available on Europa, the website hosted by the European Commission: http://europa. eu.int/comm/internal_market/en/media/dataprot/wpdocs/index.htm.

(3) Available on website: http://conventions.coe.int/treaty/EN/cadreintro.htm.

(4) Opinion 5/99 adopted by the Working Party on 7.6.1999 (DG MARKT 5054/99), available on the Europa website cited in footnote 2.

Top