235.13•Ordinance on Data Protection Certification
235.13DPCOFederal Council OrdinanceSep 1, 2023
{
"legislation": {
"type": "Federal Council ordinance",
"number": "235.13",
"source": "ch-fedlex",
"inForceTo": null,
"abstractUri": "https://fedlex.data.admin.ch/eli/cc/2022/569",
"documentDate": "2022-08-31",
"inForceSince": "2023-09-01"
},
"content": {
"number": "235.13",
"abstractUri": "https://fedlex.data.admin.ch/eli/cc/2022/569",
"fedlexMetadata": {
"id": "235.13",
"hash": "827f02a70bc2d4ca1a5a33261960ead2619da98adb70061e72e8fe4a3929e246",
"type": "Federal Council ordinance",
"number": "235.13",
"source": "ch-fedlex",
"inForceTo": null,
"languages": [
"de",
"en",
"fr",
"it"
],
"scrapedAt": "2026-04-19T19:18:43.899Z",
"sourceUrl": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2022/569/20230901/de/xml/fedlex-data-admin-ch-eli-cc-2022-569-20230901-de-xml-4.xml",
"abstractUri": "https://fedlex.data.admin.ch/eli/cc/2022/569",
"documentDate": "2022-08-31",
"inForceSince": "2023-09-01",
"manifestations": [
{
"title": "Verordnung vom 31. August 2022 über Datenschutzzertifizierungen (VDSZ)",
"fileUrl": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2022/569/20230901/de/xml/fedlex-data-admin-ch-eli-cc-2022-569-20230901-de-xml-4.xml",
"language": "de",
"shortTitle": "VDSZ",
"manifestationUri": "https://fedlex.data.admin.ch/eli/cc/2022/569/20230901/de/xml"
},
{
"title": "Ordinance of 31 August 2022 on Data Protection Certification (DPCO)",
"fileUrl": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2022/569/20230901/en/xml/fedlex-data-admin-ch-eli-cc-2022-569-20230901-en-xml-2.xml",
"language": "en",
"shortTitle": "DPCO",
"manifestationUri": "https://fedlex.data.admin.ch/eli/cc/2022/569/20230901/en/xml"
},
{
"title": "Ordonnance du 31 août 2022 sur les certifications en matière de protection des données (OCPD)",
"fileUrl": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2022/569/20230901/fr/xml/fedlex-data-admin-ch-eli-cc-2022-569-20230901-fr-xml-4.xml",
"language": "fr",
"shortTitle": "OCPD",
"manifestationUri": "https://fedlex.data.admin.ch/eli/cc/2022/569/20230901/fr/xml"
},
{
"title": "Ordinanza del 31 agosto 2022 sulle certificazioni in materia di protezione dei dati (OCPD)",
"fileUrl": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2022/569/20230901/it/xml/fedlex-data-admin-ch-eli-cc-2022-569-20230901-it-xml-4.xml",
"language": "it",
"shortTitle": "OCPD",
"manifestationUri": "https://fedlex.data.admin.ch/eli/cc/2022/569/20230901/it/xml"
}
]
},
"manifestationUri": "https://fedlex.data.admin.ch/eli/cc/2022/569/20230901/en/xml"
}
}(DPCO)
of 31 August 2022 (Status as of 1 September 2023)
The Swiss Federal Council,
on the basis of Article 13 paragraph 2 of the Data Protection Act of
25 September 20201(FADP),
ordains:
The Swiss Accreditation Service shall consult the Federal Data Protection and Information Commissioner (FDPIC) on the accreditation procedure and the follow-up inspection as well as on the suspension or the withdrawal of accreditation.
The FDPIC in consultation with the SAS shall recognise foreign certifications provided it is guaranteed that the requirements of the Swiss legislation are fulfilled.
A private controller may only dispense with conducting a data protection impact assessment in accordance with Article 22 paragraph 5 FADP if the certification covers the processing that would have to be assessed in the data protection impact assessment.
The Ordinance on Data Protection Certification of 28 September 20075is repealed.
This Ordinance comes into force on 1 September 2023.
(Art. 1 para. 4)
The staff who certify management systems must when taken together hold the following qualifications: – knowledge of the field of data protection law: a minimum of two years’ practical experience in the field of data protection or a successfully completed course of studies of a minimum of one year in duration at a university or university of applied sciences with data protection law as the main subject; – knowledge of the field of information security: a minimum of two years’ practical experience in the field of information security or a successfully completed course of studies of a minimum of one year in duration at a university or university of applied sciences with information security as the main subject; – knowledge of developments in data protection law and in information security; – training as a management systems auditor which meets the internationally specified requirements of the following standards6in particular: – SN EN ISO/IEC 17021-1, conformity assessments, requirements for bodies providing audit and certification of management systems, Part 1: Requirements, – SN EN ISO/IEC 17021-3, conformity assessment, requirements for bodies providing audit and certification of management systems, Part 3: Competence requirements for auditing and certification of quality management systems, and – SN EN ISO/IEC 27006, Information technology, security techniques, requirements for bodies providing audit and certification of information security management systems.
The certification body must have qualified staff for the individual fields. The assessment of management systems by an interdisciplinary team is permitted.
The staff who certify products, services or processes must when taken together hold the following qualifications: – knowledge of the field of data protection law: a minimum of two years’ practical experience in the field of data protection or a successfully completed course of studies of a minimum of one year in duration at a university or university of applied sciences with data protection law as the main subject; – knowledge of the field of information security: a minimum of two years’ practical experience in the field of information security or a successfully completed course of studies of a minimum of one year in duration at a university or university of applied sciences with information security as the main subject; – knowledge of developments in data protection law and in information security; – specialist knowledge relating to the certification of products, services or processes that meets the requirements for certification programmes and FDPIC’s guidelines as well as the internationally specified requirements, in particular in accordance with the applicable technical standards and the standard«SN EN ISO/IEC 170657, Conformity assessment, requirements for bodies certifying products, processes and services».
The certification body must have qualified staff for the individual fields. The assessment of products, services and processes by an interdisciplinary team is permitted.
SR 235.1 ↩
SR 946.512 ↩
SR 946.512 ↩
The standards mentioned may be viewed free of charge or purchased for a fee at the Swiss Association for Standardization (SAS), Sulzerallee 70, 8404 Winterthur; www.snv.ch ↩
AS 2007 5003; 2010 949; 2016 3447 ↩
The standards mentioned may be viewed free of charge or purchased for a fee at the Swiss Association for Standardization (SAS), Sulzerallee 70, 8404 Winterthur; www.snv.ch ↩
The standards mentioned may be viewed free of charge or purchased for a fee at the Swiss Association for Standardization (SAS), Sulzerallee 70, 8404 Winterthur; www.snv.ch ↩