Brokers and trustees continuously handle client data that goes far beyond name and address: income details, health information in insurance files, asset holdings, and sometimes debt collection records. Since the revised Swiss Data Protection Act (revDSG) came into force, many small and mid-sized firms have been asking the same questions: which data actually counts as particularly sensitive? What does «adequate data security» mean in the day-to-day work of a brokerage or trust office? And where does your own responsibility for handling personal data begin? This article outlines the key points as general guidance — not as legal advice for your specific situation.
Which Client Data Counts as Particularly Sensitive
The Data Protection Act distinguishes between «ordinary» personal data and particularly sensitive personal data. The second category includes, among other things, health information – for example in daily sickness benefit, life, or supplementary insurance files. Other details, such as debt collection records or detailed asset information, do not necessarily fall into this legal category, but in practice they still call for extra care. Wherever particularly sensitive data is processed, stricter requirements apply for access restrictions, data security, and documentation than for ordinary contact details.
In practice, this means not every staff member needs access to every file, and a loose email attachment containing a health questionnaire is rarely the right way to store it. Firms that structure their files clearly and manage access per client in a traceable way have already taken an important step.
The Core Principles at a Glance: Purpose Limitation, Security, Retention
- Purpose limitation: Data may only be processed for the purpose for which it was collected. A file created for a health insurance policy is not a blank cheque to reuse the same information, without consent, for an unrelated cross-selling offer.
- Data security: The law requires adequate technical and organisational measures, scaled to the risk associated with the data being processed. These typically include encryption, controlled access, and the ability to trace who accessed what afterwards.
- Retention and deletion: Personal data should not be kept any longer than necessary. Industry-standard and statutory retention periods must be observed; after that, documents should be consistently deleted or properly archived.
- Transparency: Clients must be able to see who processes their data and for what purpose – a clear, understandable privacy policy is part of that.
Your Responsibility — Even When Using External Service Providers
For their own mandates, brokers and trustees generally act as the controller themselves: they decide which data is collected for which purpose. At the same time, most firms rely on external tools – from their email program to a client portal – that process data on their behalf. Anyone who engages such service providers remains responsible towards their own clients and should make sure the systems they use are hosted in Switzerland, encrypt data, and keep mandates cleanly separated from one another. Whether a data processing agreement is additionally required in a given case, and how your own situation should be classified, depends on the details – when in doubt, it is worth consulting a specialist.
How a Secure Client Portal Makes Compliance Easier
Many of the requirements above are difficult to uphold consistently through organisational rules alone – it is all too easy for a sensitive document to end up in the wrong email inbox or on a private device. A secure client portal takes a lot of this burden off your shoulders: clients submit documents directly through a requirements checklist instead of an email attachment, every file release happens digitally and is fully traceable, and an access log shows afterwards exactly who accessed which file and when.
Equally important is the technical separation between mandates: each client sees only their own documents, and each staff member only the files they are responsible for. Combined with hosting exclusively in Switzerland and end-to-end encryption, this covers a large part of the revDSG's data security requirements in everyday practice – without every staff member needing to know the details of the statute.
A well-structured client portal is no substitute for legal advice – but it makes the technical implementation of your due-diligence duties noticeably easier.
A First Step for Your Firm
finra is a Swiss client portal for brokerage and trust firms that brings files, contacts, contracts, and deadlines together in one place – hosted exclusively in Switzerland, with mandate separation, encryption, and an access log for every file. If you would like to see how this could work for your firm, you can try finra free for 30 days – no credit card required, with plans starting at CHF 29 per month.