Data security and data protection are playing an increasingly important role. A cyber attack or data breach usually has serious consequences.
It is therefore more important than ever to protect, back up and store data securely. On 1 September 2023 the new Swiss Data Protection Act (nDSG) came into force, which also resulted in adjustments to data storage. BrokerStar and BrokerWeb are prepared for this.
Data security deals with the general protection of data and documents. Thus, security in any form falls under the term data security, as does personal data. The Data protection on the other hand, relates exclusively to the storage and use of personal data, at least as far as the legal provisions are concerned.
Data security and data protection therefore pursue the goal of securing data of all kinds against threats, manipulation, unauthorised access or knowledge. Analogue and digital measures can be taken to achieve this. First of all, there are technical and organisational measures, which are also used in the context of data protection.
In the digital sector, the implementation of IT security solutions in the form of virus scanners, firewalls etc. contributes to the security of data. Physical measures, on the other hand, include access controls, fireproof filing cabinets or safes for sensitive and confidential documents. Data backups, such as the creation of backup copies on a separate storage medium, are also essential. A solid network infrastructure and regular updates are the basic prerequisites for achieving data security goals. Data protection, on the other hand, is essentially about how personal data is used and stored.
It is therefore important to take organisational and personnel policy precautions to ensure a high standard of security within the company. Employee training and further education, as well as the deployment of specialists such as IT security officers and data protection officers, contribute to data security and are sometimes mandatory for compliance reasons. IT security and data protection officers are dedicated to analysing potential security gaps in your company and creating appropriate measures to achieve the data security objective.
The terms are therefore not only closely linked, but also influence each other. For example, complete data security cannot be achieved without data protection measures, as otherwise personal data may not be adequately protected. On the other hand, comprehensive data security measures are a prerequisite for effective data protection in accordance with legal requirements and best practice.
The following aspects of the new Data Protection Act are important:
- Keep track of exactly what data is being processed and for what purpose. You can provide information about this at any time and avoid unpleasant surprises.
- Critically review the collection of personal data. What is effectively necessary for you?
- Reduce the query criteria for your customers to a minimum.
- Restrict internal data access in the company to as few people as possible.
- Check your privacy policy in detail and amend it if necessary.
- Check and improve the technical default settings and user-friendliness.
- Train your employees to sensitise them to the importance of the topic.
Details on the new data protection law can be found here and on the official site of the federal government
Sources, Profi Engineering, 2021, SME digitalisation 2022, Data protection partner 2022, www.admin.ch
Templates and documents (Sources: SIBA, IG B2B, WMC)