-
- Art. 3 FC
- Art. 5a FC
- Art. 6 FC
- Art. 10 FC
- Art. 13 FC
- Art. 16 FC
- Art. 17 FC
- Art. 20 FC
- Art. 22 FC
- Art. 26 FC
- Art. 29a FC
- Art. 30 FC
- Art. 31 FC
- Art. 32 FC
- Art. 42 FC
- Art. 43 FC
- Art. 43a FC
- Art. 45 FC
- Art. 51 FC
- Art. 52 FC
- Art. 55 FC
- Art. 56 FC
- Art. 60 FC
- Art. 68 FC
- Art. 69 FC
- Art. 74 FC
- Art. 75b FC
- Art. 77 FC
- Art. 81 FC
- Art. 96 para. 1 FC
- Art. 96 para. 2 lit. a FC
- Art. 110 FC
- Art. 117a FC
- Art. 118 FC
- Art. 119a FC
- Art. 122 FC
- Art. 123a FC
- Art. 123b FC
- Art. 130 FC
- Art. 136 FC
- Art. 164 FC
- Art. 166 FC
- Art. 170 FC
- Art. 176 FC
- Art. 178 FC
- Art. 189 FC
- Art. 191 FC
-
- Art. 11 CO
- Art. 12 CO
- Art. 50 CO
- Art. 51 CO
- Art. 84 CO
- Art. 97 CO
- Art. 98 CO
- Art. 99 CO
- Art. 100 CO
- Art. 143 CO
- Art. 144 CO
- Art. 145 CO
- Art. 146 CO
- Art. 147 CO
- Art. 148 CO
- Art. 149 CO
- Art. 150 CO
- Art. 633 CO
- Art. 701 CO
- Art. 713 CO
- Art. 715 CO
- Art. 715a CO
- Art. 734f CO
- Art. 785 CO
- Art. 786 CO
- Art. 787 CO
- Art. 788 CO
- Art. 808c CO
- Transitional provisions to the revision of the Stock Corporation Act of June 19, 2020
-
- Art. 2 PRA
- Art. 3 PRA
- Art. 4 PRA
- Art. 6 PRA
- Art. 10 PRA
- Art. 10a PRA
- Art. 11 PRA
- Art. 12 PRA
- Art. 13 PRA
- Art. 14 PRA
- Art. 15 PRA
- Art. 16 PRA
- Art. 17 PRA
- Art. 19 PRA
- Art. 20 PRA
- Art. 21 PRA
- Art. 22 PRA
- Art. 23 PRA
- Art. 24 PRA
- Art. 25 PRA
- Art. 26 PRA
- Art. 27 PRA
- Art. 29 PRA
- Art. 30 PRA
- Art. 31 PRA
- Art. 32 PRA
- Art. 32a PRA
- Art. 33 PRA
- Art. 34 PRA
- Art. 35 PRA
- Art. 36 PRA
- Art. 37 PRA
- Art. 38 PRA
- Art. 39 PRA
- Art. 40 PRA
- Art. 41 PRA
- Art. 42 PRA
- Art. 43 PRA
- Art. 44 PRA
- Art. 45 PRA
- Art. 46 PRA
- Art. 47 PRA
- Art. 48 PRA
- Art. 49 PRA
- Art. 50 PRA
- Art. 51 PRA
- Art. 52 PRA
- Art. 53 PRA
- Art. 54 PRA
- Art. 55 PRA
- Art. 56 PRA
- Art. 57 PRA
- Art. 58 PRA
- Art. 59a PRA
- Art. 59b PRA
- Art. 59c PRA
- Art. 60 PRA
- Art. 60a PRA
- Art. 62 PRA
- Art. 63 PRA
- Art. 64 PRA
- Art. 67 PRA
- Art. 67a PRA
- Art. 67b PRA
- Art. 73 PRA
- Art. 73a PRA
- Art. 75 PRA
- Art. 75a PRA
- Art. 76 PRA
- Art. 76a PRA
- Art. 90 PRA
-
- Art. 1 IMAC
- Art. 1a IMAC
- Art. 3 para. 1 and 2 IMAC
- Art. 8 IMAC
- Art. 8a IMAC
- Art. 11b IMAC
- Art. 16 IMAC
- Art. 17 IMAC
- Art. 17a IMAC
- Art. 32 IMAC
- Art. 35 IMAC
- Art. 47 IMAC
- Art. 48 IMAC
- Art. 54 IMAC
- Art. 56 IMAC
- Art. 55a IMAC
- Art. 63 IMAC
- Art. 67 IMAC
- Art. 67a IMAC
- Art. 74 IMAC
- Art. 74a IMAC
- Art. 80 IMAC
- Art. 80a IMAC
- Art. 80b IMAC
- Art. 80c IMAC
- Art. 80d IMAC
- Art. 80h IMAC
- Art. 80k IMAC
-
- Vorb. zu Art. 1 FADP
- Art. 1 FADP
- Art. 2 FADP
- Art. 3 FADP
- Art. 4 FADP
- Art. 5 lit. c FADP
- Art. 5 lit. d FADP
- Art. 5 lit. f und g FADP
- Art. 6 para. 3-5 FADP
- Art. 6 Abs. 6 and 7 FADP
- Art. 7 FADP
- Art. 10 FADP
- Art. 11 FADP
- Art. 12 FADP
- Art. 14 FADP
- Art. 15 FADP
- Art. 18 FADP
- Art. 19 FADP
- Art. 20 FADP
- Art. 21 FADP
- Art. 22 FADP
- Art. 23 FADP
- Art. 25 FADP
- Art. 26 FADP
- Art. 27 FADP
- Art. 28 FADP
- Art. 29 FADP
- Art. 31 para. 2 lit. e FADP
- Art. 33 FADP
- Art. 34 FADP
- Art. 35 FADP
- Art. 38 FADP
- Art. 39 FADP
- Art. 40 FADP
- Art. 41 FADP
- Art. 42 FADP
- Art. 43 FADP
- Art. 44 FADP
- Art. 44a FADP
- Art. 45 FADP
- Art. 46 FADP
- Art. 47 FADP
- Art. 47a FADP
- Art. 48 FADP
- Art. 49 FADP
- Art. 50 FADP
- Art. 51 FADP
- Art. 52 FADP
- Art. 54 FADP
- Art. 55 FADP
- Art. 57 FADP
- Art. 58 FADP
- Art. 60 FADP
- Art. 61 FADP
- Art. 62 FADP
- Art. 63 FADP
- Art. 64 FADP
- Art. 65 FADP
- Art. 66 FADP
- Art. 67 FADP
- Art. 69 FADP
- Art. 72 FADP
- Art. 72a FADP
-
- Art. 1 CCC (Convention on Cybercrime)
- Art. 2 CCC (Convention on Cybercrime)
- Art. 3 CCC (Convention on Cybercrime)
- Art. 4 CCC (Convention on Cybercrime)
- Art. 5 CCC (Convention on Cybercrime)
- Art. 6 CCC (Convention on Cybercrime)
- Art. 7 CCC (Convention on Cybercrime)
- Art. 8 CCC (Convention on Cybercrime)
- Art. 9 CCC (Convention on Cybercrime)
- Art. 11 CCC (Convention on Cybercrime)
- Art. 12 CCC (Convention on Cybercrime)
- Art. 16 CCC (Convention on Cybercrime)
- Art. 18 CCC (Convention on Cybercrime)
- Art. 25 CCC (Convention on Cybercrime)
- Art. 27 CCC (Convention on Cybercrime)
- Art. 28 CCC (Convention on Cybercrime)
- Art. 29 CCC (Convention on Cybercrime)
- Art. 32 CCC (Convention on Cybercrime)
- Art. 33 CCC (Convention on Cybercrime)
- Art. 34 CCC (Convention on Cybercrime)
-
- Art. 2 para. 1 AMLA
- Art. 2a para. 1-2 and 4-5 AMLA
- Art. 2 para. 2 AMLA
- Art. 2 para. 3 AMLA
- Art. 3 AMLA
- Art. 7 AMLA
- Art. 7a AMLA
- Art. 8 AMLA
- Art. 8a AMLA
- Art. 9 AMLA
- Art. 11 AMLA
- Art. 14 AMLA
- Art. 15 AMLA
- Art. 20 AMLA
- Art. 23 AMLA
- Art. 24 AMLA
- Art. 24a AMLA
- Art. 25 AMLA
- Art. 26 AMLA
- Art. 26a AMLA
- Art. 27 AMLA
- Art. 28 AMLA
- Art. 29 AMLA
- Art. 29a AMLA
- Art. 29b AMLA
- Art. 30 AMLA
- Art. 31 AMLA
- Art. 31a AMLA
- Art. 32 AMLA
- Art. 33 AMLA
- Art. 34 AMLA
- Art. 38 AMLA
FEDERAL CONSTITUTION
FEDERAL ACT ON DIRECT FEDERAL TAX
MEDICAL DEVICES ORDINANCE
CODE OF OBLIGATIONS
FEDERAL LAW ON PRIVATE INTERNATIONAL LAW
LUGANO CONVENTION
CODE OF CRIMINAL PROCEDURE
CIVIL PROCEDURE CODE
FEDERAL ACT ON POLITICAL RIGHTS
CIVIL CODE
FEDERAL ACT ON CARTELS AND OTHER RESTRAINTS OF COMPETITION
FEDERAL ACT ON INTERNATIONAL MUTUAL ASSISTANCE IN CRIMINAL MATTERS
DEBT ENFORCEMENT AND BANKRUPTCY ACT
FEDERAL ACT ON DATA PROTECTION
CRIMINAL CODE
CYBERCRIME CONVENTION
COMMERCIAL REGISTER ORDINANCE
FEDERAL ACT ON COMBATING MONEY LAUNDERING AND TERRORIST FINANCING
FREEDOM OF INFORMATION ACT
FEDERAL ACT ON THE INTERNATIONAL TRANSFER OF CULTURAL PROPERTY
FEDERAL ACT ON MEDICINAL PRODUCTS AND MEDICAL DEVICES
TAX HARMONISATION ACT
- I. General Provisions
- II. Computer System (Let. A)
- III. Computer Data (Letter b)
- IV. Service Provider (subpar. c)
- V. Traffic Data (Letter d)
- Bibliography
- Travaux législatifs
I. General Provisions
1The Convention on Cybercrime begins by providing, in Article 1, four definitions of the key concepts referred to in the various articles that follow. The drafters of the Convention did, however, specify in their Explanatory Report that the Parties would not be required to reproduce verbatim, in their domestic laws, the four concepts defined in Article 1 of the Convention. However, they did specify that national laws must cover these concepts in a manner consistent with the principles of the Convention and provide an equivalent framework for its implementation. The purpose of these definitions is therefore clear: to place all Parties on an equal footing to ensure that they are referring to the same concepts. This helps, in particular, toavoid disputes, such as a Party refusing to enforce certain provisions on the grounds that it interprets a concept differently from another Party.
2The drafters of the Convention were clearly aware of the rapid evolution of information technology. This is undoubtedly why they decided to formulate the definitions in Article 1 of the CCC as technologically neutral as possible, limiting themselves to a functional description of each concept. This strategy has paid off, since, twenty-five years later, these definitions remain relevant despite the considerable technological advances that have taken place during this period.
II. Computer System (Let. A)
3The definition adopted by the drafters of the Convention on Cybercrime consists of three aspects. First, it presupposes the existence of a device. This device may be standalone or networked. The definition therefore encompasses both personal computers and interconnected computer environments. The second element is the presence of a program. The device must therefore operate on the basis of pre-established instructions. The device cannot be purely mechanical. A music box or a clock, therefore, are not computer systems. Finally, data processing must occur automatically. It is not sufficient for the device to merely store data passively; it must automatically perform a process to transform that data. A camera, a voice recorder, or a USB flash drive are therefore not computer systems.
4In its guidelines, the Committee of the Convention on Cybercrime clarified that the definition of “computer system” includes, for example, modern mobile phones that are multifunctional and have, among their functions, the ability to generate, process, and transmit data—such as accessing the Internet, sending emails, transmitting attachments, and downloading content or documents. The same applies to personal digital assistants, with or without wireless functionality, which also generate, process, and transmit data.
5The definition adopted deliberately approaches the computer system from the perspective of its functionality, rather than its form. This approach provides sufficient flexibility for the definition to evolve over time and include technologies that did not yet exist in 2001, such as smartphones, the Internet of Things (IoT), or cloud computing.
A. A System
6 Computer science is fundamentally based on data processing. This concept will be discussed in more detail below in Section III. At this stage, data can be defined as intangible digital information. However, in order to be processed, this information requires a set of hardware components that enable both its processing and storage.
7Although it is not the most important component of a computer system, the motherboard nevertheless serves as its backbone. It is a large electronic board that serves as the foundation for all the system’s components. The truly central element of the computer system is the processor. It represents the heart of the system, in that it processes all the instructions and requests it receives from the various components. Once the data has been processed, the processor must be able to store it temporarily somewhere, since it has no memory of its own. The data is therefore temporarily stored in RAM. However, this memory can only store data while the computer system is powered on. When it is turned off, all data contained in this memory is lost. It is therefore necessary to provide permanent storage for this data on an appropriate device, such as a hard drive, an external hard drive, a USB flash drive, a DVD, etc.
8The final components essential to the operation of a computer system are peripherals. Input devices allow data to be entered into the system, such as a mouse, keyboard, or scanner. In contrast, output devices display the data processed by the system, such as a monitor, printer, or DVD burner. All these physical elements are called hardware and together form a system.
9 However, it would be simplistic to assume that all the components making up the system must necessarily be located in a single place in a compact configuration, as this would limit the concept of a system to a personal computer or a smartphone. In fact, there are currently supercomputers that each occupy an entire hall. Conversely, there are also systems whose components are scattered all over the globe.
10 A system can operate in an isolated manner or in an interconnected manner. Before the widespread adoption of the Internet in the mid-1990s, most systems operated in isolation. Since then, this mode of operation has become the exception, reserved for situations requiring the highest level of security—particularly to prevent any intrusion via external connections.
11 Devices are interconnected when they are linked to one another via a wired or wireless connection—such as radio waves, infrared links, fiber optics, or satellite links—thereby forming a network. This network may be limited to a specific geographic area, such as a home, a business, or a university. This is known as a local area network (Local Area Network or LAN). However, such a network can also extend over a much larger area, such as a city, a country, or a continent. This is referred to as a wide area network (Wide Area Network or WAN). The largest wide area network is the Internet, since it consists of a multitude of interconnected networks spanning the entire globe.
12 Finally, the concept of a device also includes other devices that enable computers connected to networks to exchange data. As such, servers, routers, switches, modems, and gateways must also be classified as devices.
B. A Program
13 In contrast to hardware components are software components, which encompass all the programs that enable the operation and use of the various components of the computer system.
14 A program can be defined as a set of commands that, when executed by a computer system, produce a specific result.
15 Just as with hardware components, programs should be distinguished based on the task they perform. The “boot” program for any computer system is the BIOS (Basic Input and Output System) or UEFI (Unified Extensible Firmware Interface). It is contained in a chip connected to the motherboard and provides the elements necessary for booting the system. In addition, it handles the basic management of the computer system’s various hardware components and acts as an interface between these components and the operating system.
16 The operating system, for its part, is the central program of the computer system. It ensures the overall and consistent operation of the system by coordinating the various requests sent to the computer system by the user, as well as the interactions between hardware components and other programs. In other words, the operating system acts as an essential interface between application software and the system’s hardware components.
17 Finally, application programs each perform a specific function. For example, Word© is used for word processing, Photoshop© for image processing, and Outlook© for sending and receiving emails. These programs, however, rely on the operating system to access hardware resources and perform the tasks for which they were designed.
C. Automated Data Processing
18 Automated data processing refers to the fact that data is processed automatically by a program, without the need for direct human intervention. This processing may involve the acquisition, storage, or retrieval of data.
19 As we will see below in Section III, data constitutes intangible digital information. In order to be processed by a computer system, information from the physical world must be converted into a language understandable by the device. Thus, pressing a keyboard key, a mouse button, or a touchscreen is translated into binary code and converted into electrical, logical, or optical signals.
20 Once the physical information has been converted into electrical, logical, or optical signals, the program is able to perform automated data processing. When processing is complete, the data is once again translated into a language intelligible to the user. The program can thus, for example, display alphabetic characters on a screen when a user presses keys on a keyboard, send the visual information displayed on the screen to a printer so that it is reproduced on paper when the the user clicks the “print” icon, or even establish a phone call when the user taps the green phone icon on the touchscreen of their smartphone. Each instruction given by the user to the computer system results in the creation of computer data, which is processed automatically by programs and then returned to the user in a form they can understand.
D. Outlook
1. The Dematerialization of Computer Systems
21 As early as the 1980s, the idea of distributed computing emerged, notably through the slogan coined by Sun Microsystems: “The network is the computer!” This approach is based on the pooling of computing resources to process larger volumes of data. From this perspective, when the network in question is the Internet, the “computer” it represents consists of all the computers connected to it, which amounts to a particularly vast computing capacity. It was in this context that, starting in the late 1990s and with the widespread adoption of the Internet, distributed computing projects began to emerge. These projects involve offering individuals the opportunity to make the computing power of their personal computers available via the Internet when they are not using them, in order to perform calculations that require very high processing capabilities.
22 Over time, this concept of resource sharing expanded beyond just the processor. The entire computer architecture has gradually been reimagined to become a distributed architecture, in the sense that the various available resources are no longer necessarily located in the same place or on the same machine. A prime example of a distributed architecture that experienced explosive growth in the early 2000s is the so-called “peer-to-peer” (peer-to-peer) model. This model enables file sharing within an architecture in which each computer acts as both a client and a server.
23 Between the late 2000s and the early 2010s, cloud computing (“cloud computing”), which involves using remote computer servers connected to the Internet to store, manage, and process data, rather than relying on a local server or a personal computer. In particular, this technology allows users to create a virtual computing system, install an operating system and applications on it, and generate, process, and save data there. All that is needed is a device connected to the Internet; all other resources are made available virtually and in a decentralized manner, originating from various locations and sometimes from different service providers around the world. In such a configuration, it is easy to see how the term “system” can become problematic, since there is no longer a physical unity of components.
2. The Internet of Things (IoT)
24 In recent years, we have witnessed a veritable explosion in the number of connected objects. Whether they are watches, ovens, televisions, or vehicles, virtually all everyday objects exist in a form that can be connected to the Internet.
25 In the 1990s, SCHMID asserted, citing the Federal Council’s Message, that vending machines for food, gasoline, and tickets, photocopiers, or slot machines could not be classified as computer systems, on the grounds that the federal legislature had intended to limit the concept of a computer system solely to devices capable of performing so-called “higher-level” functions.”
26 This view can no longer be defended today. Connected devices are now an integral part of the Internet, can be controlled remotely, and are capable of performing so many tasks that they meet all the criteria for being classified as computer systems within the meaning of Art. 1(a) of the Swiss Civil Code (CCC). This paradigm shift, however, raises serious problems. Connected devices generally do not benefit from security measures equivalent to those of traditional computers. Cybercriminals can therefore more easily gain unauthorized access to a smartwatch to extract the payment methods it it contains, unlock a door connected to a home automation system to enter a residence, or even gain access to a corporate network by connecting without authorization to the connected coffee machine in the cafeteria, than by accessing a personal computer that is specifically protected against unauthorized access. As a result, the scope of application of Art. 2 of the Swiss Civil Code (CCC), for states that do not require—as Switzerland does—that the offense be committed in violation of security measures, is particularly broad and is likely to expand even further in the coming years.
3. Artificial Intelligence
27 As noted above (in Section II, Subsection B), the definition set forth in Art. 1(a) CCC presupposes that a computer system is equipped with a program. In principle, this program executes a series of commands predefined by humans. With the rise of artificial intelligence, the immutable nature of programs is no longer necessarily a given. Systems based on artificial intelligence are, in fact, capable of autonomous learning and can, in certain configurations, modify their own source code or adapt the parameters of the environment in which they operate. This raises the question of whether the concept of a computer system, as currently defined, remains broad enough to encompass these technological developments, or whether a redefinition is necessary to account for future advancements in the field of artificial intelligence. In our view, the current definition is broad enough to encompass the technological developments known to date. Indeed, even if artificial intelligence is capable of rewriting a program’s source code to adapt to its environment, the computer system continues to operate on the basis of a program.
28 Two emerging issues, however, may require a redefinition in the coming years. The first is autonomous, deployed agent-based artificial intelligence—that is, agents capable of negotiating, migrating between environments, creating other agents, or modifying their own infrastructure without human intervention. This raises the issue of the unity of the computer system, as it would no longer be possible to clearly determine at what point a swarm of agents still constitutes a single computer system or multiple systems. Furthermore, the Convention does not address the concept of ephemeral, distributed, and self-organizing computer systems. The second issue concerns neuromorphic artificial intelligence—that is, AI without separate programs. An example of this is Intel’s Loihi chips, which mimic the human brain. Unlike traditional processors, these chips process information event-driven and integrate memory into the processor. There is therefore no longer a “program ” distinct from the hardware. Execution and learning are inseparable, meaning that the current definition of a computer system would become obsolete.
29 In the medium term, it would therefore be necessary toexpand the definition of a computer system to include, on the one hand, deployed autonomous agents and, on the other hand, to any hardware or hybrid device that performs data processing through machine learning, even when execution does not rely on a separate program.
III. Computer Data (Letter b)
30 Computer data is defined as “any representation of facts, information, or concepts in a form suitable for computer processing, including a program capable of causing a computer system to perform a function” (Art. 1, Letter b, CCC). This definition, taken from that of the International Organization for Standardization (ISO), is characterized by its technological neutrality. This has given it the advantage of having withstood remarkably well the rapid evolution of technologies since the Convention’s adoption in 2001.
A. The Form of Data
31 Computer systems use a language that is fundamentally different from that of humans. A text, an image, or a musical work created by humans has, in and of itself, no meaning for a computer. To be understood and processed, this information must be converted into a language that is intelligible to the machine. It is in this context that the definition of “computer data” adopted in the Convention uses the terms “which lends itself to processing.” This means that the representation of facts, information, or concepts must be capable of being processed directly by a computer system, without requiring prior transformation to enable the system to recognize it. Computer data is therefore information that can be directly understood and utilized by a computer.
32 Computing is based on a binary system, which means it uses only the digits 0 and 1. This basic unit of information is called a bit. A sequence of eight bits constitutes a byte (e.g., 10011101), which can represent 28, or 256 distinct values. This system makes it possible to translate information from human language into instructions that a machine can understand. Depending on the program being used, a byte can represent a number, a letter, a color, or even a sound. For example, when a user presses the letter “a” on their computer keyboard in a word processing program, this action is converted into binary code as “01100001.” This byte constitutes data that the computer can process by displaying an “a” on the screen. Similarly, colors are converted into values distributed across three axes: red, green, and blue. A value of 0 indicates that the color is absent, and a value of 255 indicates that the color is at maximum intensity. Thus, an apricot-colored pixel in a drawing program will be represented by the values 230 on the red scale, 126 on the green scale, and 48 on the blue scale—which, in binary, is “111001101111111011000000.” This 24-bit data allows the drawing program to display an apricot-colored pixel on the white page.
33 The preceding examples illustrate that, in computer science, a data unit is the basic unit that contains information. Conversely, when a set of data is combined to form a coherent whole, it is referred to as a file. This can be text, an image, a video, or an audio recording.
B. Types of Data
34 The definition in Art. 1(b) of the Swiss Civil Code (CCC) makes no distinction between different types of data. All computer data is covered, whether personal or not, private or public, understandable by humans or only by machines. The content of the data is also irrelevant, whether it consists of factual data (dates, times, measurements, etc.), information (reports, analyses, etc.) or abstract concepts (models, algorithms, codes, etc.). Therefore, data stored on storage media, temporary data, data in transit, metadata, and even encrypted data all constitute “data” within the meaning of Art. 1(b) of the Swiss Civil Code (CCC).
35 In our view, in addition to human-generated data, we must include data automatically produced by a computer system from preexisting data—referred to as derived or inferred data—particularly through processes of transformation, combination, or algorithmic analysis. Examples include user profiles, scores, predictions, or classifications generated without direct human intervention. Although this data is not initially provided by a user, we believe it should also be included in the definition of Art. 1(b) of the Swiss Civil Code (CCC), provided that it is suitable for computer processing and can be utilized by a computer system.
36 In our view, the definition of computer data also extends to volatile (or ephemeral) data, including data temporarily stored in a system’s random-access memory, dynamically generated during program execution, or intended to disappear automatically after a very short period of time. Although its lifespan is brief, such data is of particular importance in the context of criminal investigations, especially in cases of unlawful access (Art. 2 CCC) or a violation of system integrity (Art. 5 CCC) through a distributed denial-of-service attack.
37 Given that the definition of computer data focuses solely on function, it is irrelevant whether the data is intelligible to a human being. Data remains computer data even when it is encrypted, compressed, fragmented, or stored in a form that does not allow for immediate reading. Data encryption is not relevant from a legal standpoint, as it constitutes merely a technical method of data processing intended to restrict access. Consequently, the legal status of the data does not change simply because it is encrypted or temporarily rendered unusable by cybercriminals.
C. Programs
38 The clarification “including a program,” intended by the drafters of the Convention, aims to remove any ambiguity regarding the inclusion of programs in the definition of Art. 1(b) CCC. This approach is entirely consistent for two reasons. From an IT perspective, a program is a set of instructions contained in source code, which itself consists of a multitude of characters—that is, data—that determine how the data provided to it is to be processed. From a systematic perspective, the inclusion of programs in the definition of computer data is consistent with the Convention drafters’ clearly stated intention not to distinguish between different types of data.
D. Outlook
39 Although it was impossible, at the time the Convention was drafted, to foresee future developments in information technology, the choice of a technologically neutral definition has made it possible to include all new types of data that have emerged since 2001. This is particularly true of crypto-assets, data generated by connected devices, and datasets—that is, structured collections of data intended for training machine learning models.
E. Digression: The Distinction Between Subscriber Data, Traffic Data, and Content Data in Swiss Criminal Law
40 The rapid evolution of technology over the past thirty years has necessitated significant legislative changes to distinguish which types of data could be obtained and under what conditions. The first Act on the Surveillance of Postal and Telecommunications Correspondence (LSCPT) was adopted on October 6, 2000, and entered into force on January 1, 2002. It was completely revised in 2016 and subsequently underwent several partial revisions, including a major one in 2024.
41 The legislature considered that not all data were of equal importance. It proceeded from the premise that the greater the infringement on privacy—guaranteed by Art. 13 of the Constitution—the stricter the conditions under which such data could be obtained would have to be. The law thus distinguishes between three types of data: subscriber data (Bestandesdaten), traffic data (Randdaten), and content data (Inhaltsdaten).
42 The Convention on Cybercrime makes this same distinction in Article 18.
1. Subscriber data
43 Subscriber data includes the identification information of the subscriber of a connection. This includes, in particular, the last name, first name, date of birth, address, and, if known, the user’s occupation (Art. 21(1)(a) LSCPT), as well as addressing resources (Art. 21(1)(b) LSCPT) and types of services (Art. 21(1)(c) LSCPT) that were used.
44 This data corresponds to that listed inArt. 18 § 3 CCC, namely: the type of communication service used, the technical measures taken in this regard, and the service period (subpar. a); the subscriber’s identity, postal or geographic address, and telephone number, as well as any other access number, and data concerning billing and payment, available on the basis of a contract or service agreement (subparagraph b); any other information regarding the location of the communications equipment, available on the basis of a contract or service agreement (subparagraph c) .
45 These are the least sensitive data. Obtaining them constitutes only a minimal intrusion into privacy. Under Swiss law, obtaining such data is therefore subject solely to the conditions of Art. 197(1) of the Swiss Criminal Procedure Code and does not require authorization from the Court for Coercive Measures.
2. Traffic data (or secondary data)
46 Traffic data consists of information indicating with whom, when, for how long, and from where the person under surveillance has communicated or is communicating, as well as the technical characteristics of the communication in question (Art. 8(b) of the Interception of Communications and Telecommunications Act).
47 In a landmark ruling, the Federal Supreme Court specifically held that the history of IP addresses of members who have logged into a social network constitutes traffic data and not subscriber data. This ruling, which has been heavily criticized in legal scholarship, was recently upheld in an unpublished decision.
48 The Convention on Cybercrime defines them in Art. 1(d) CCC. They will be examined in detail in Chapter V below.
49 This data is more sensitive than subscriber data. The Swiss legislature has therefore decided to impose stricter requirements for obtaining it. Consequently, the conditions set forth in Art. 197, paras. 1 and 2, and Art. 273, para. 1, of the Swiss Criminal Procedure Code (CPP) must all be met cumulatively. Obtaining this data is therefore possible only when there are serious grounds for suspecting that a crime or misdemeanor has been committed. Mere assumptions or vague suspicions are not sufficient. Nor is it possible to obtain this data in cases involving a minor offense. In addition, the collection must be justified in light of the seriousness of the offense (principle of proportionality) and that the measures taken thus far as part of the investigation have been unsuccessful, or the investigations would have no chance of success or would be excessively difficult in the absence of surveillance (principle of subsidiarity).
50 Furthermore, obtaining this data is only possible with theauthorization of the Court for Coercive Measures (Art. 274 CCP).
3. Content Data
51 Content data corresponds to the very substance of communications (Art. 8(a) LSCPT). This refers to the written or oral expression of human thought, in particular the text composed by the author of an email or message or the words spoken by a party during a telephone conversation.
52 Surveillance of content data is the most intrusive form of surveillance and constitutes the most serious infringement of the secrecy of telecommunications and privacy. It therefore goes without saying that the requirements established by the Swiss legislature are the strictest of the three types of data.
53 Content data is referred to in Art. 21 of the Swiss Civil Code (CCC). The drafters of the Convention also held the view that such data could not be obtained to prosecute just any offense. They therefore incorporated the principle of proportionality by stipulating that such data could be collected only to prosecute certain serious offenses that must be defined under domestic law.
54 The collection of content data is governed by Art. 269 of the Swiss Criminal Procedure Code (CPP). It requires the existence of serious suspicion that a crime or misdemeanor has been committed, as exhaustively listed in Art. 269(2) of the CPP. In this case as well, mere assumptions or vague suspicions are not sufficient. The collection of such data must also be justified in light of the seriousness of the offense (principle of proportionality). It is therefore not sufficient that the offense being prosecuted appears on the list in Art. 269(2) of the Criminal Procedure Code; rather, the specific gravity of the offense in the particular case must also justify the surveillance measure. Finally, the measures taken thus far during the investigation must have been unsuccessful, or the investigation would have no chance of success or would be excessively difficult without surveillance (principle of subsidiarity).
55 As with traffic data, the collection of content data is possible only with theauthorization of the Court for Coercive Measures (Art. 274 CPP).
IV. Service Provider (subpar. c)
56 According to Art. 1, subpar. c, of the Swiss Civil Code (CCC), “the term ‘service provider’ refers to any public or private entity that offers users of its services the ability to communicate via a computer system, and any other entity that processes or stores computer data for this communication service or its users.” This definition distinguishes between two types of providers: access providers and storage or content providers.
A. Access Providers
57 The service providers referred to in Art. 1(c)(1) CCC are access providers (access provider), that is, those who enable users to connect to a network and communicate with one another via a computer system.
58 These are primarily telecommunications operators (e.g., Swisscom, SFR, Deutsche Telekom, Vodafone, TIM) that enable individuals to connect to the Internet. In our view, this definition must be understood much more broadly and extended to include all entities that provide access to a network via a computer system. This includes private companies or public entities that provide users with Internet access points (e.g., railroads, hotels, municipalities, etc.), private companies or public entities that operate a private network and provide their users with access to that network, as well as individuals who have an Internet access point or a home network—particularly in the form of a Wi-Fi hotspot—and who offer third parties the opportunity to connect to it.
59 This broad interpretation is confirmed by the drafters of the Convention, who emphasize in their Explanatory Report that it is irrelevant whether the users form a closed group or whether the provider offers its services to the public, free of charge or for a fee. The closed group may consist of employees of a private company to whom services are provided via a corporate network.
60 In our view, the phrase “that offers users of its services the ability to communicate” encompasses not only public or private entities that provide network access, but also all those that make communication physically possible. The concept of “access provider” thus extends to all entities that make available infrastructure or a service enabling the transmission, routing, or forwarding of data across the network, provided that they offer a functional communication service to users. However, this does not apply to purely technical or industrial actors who limit themselves to manufacturing, supplying, or maintaining equipment without themselves offering a communication service.
61 From a purely functional perspective, the definition in Art. 1(c)(1) of the Swiss Civil Code (CCC) also covers certain categories ofnetwork intermediaries who, without providing traditional Internet access, play a decisive role in enabling effective communication via a computer system. This is particularly the case for providers of virtual private network (VPN) services, who provide their users with secure and anonymous access to resources available via the network, combining functions of routing, transmission, and encryption of communications.
62 From a functional perspective, Art. 1(c)(1) of the Swiss Civil Code (CCC) may also apply to operators of infrastructure services essential to Internet communication, such as providers of publicly accessible domain name system (DNS) resolution services or operators of Internet exchange points (Internet Exchange Points or IXPs), provided they offer a service that enables the routing or interconnection of communications between users or network providers.
B. Hosting and Content Providers
63 The service providers covered by Art. 1(c)(2) CCC are those that make storage space (hosting providers) or content for websites (content providers) available, either free of charge or for a fee.
64 Storage providers (hosting providers) are entities that offer Internet users servers that enable the storage or processing of data. They fall into two categories: those that store or process data on behalf of the entities mentioned in point (i) and those that store or process data on behalf of users of the services offered by the persons referred to in point (ii):
65 The first category includes hosting providers that process or store data from access providers. This includes, in particular, traffic data (see Section V below), data from the Domain Name System (DNS)—which associates domain names with the IP addresses of the servers on which they are hosted—and data concerning the various servers through which emails pass.
66 The second category concerns providers that store or process data belonging to the users of internet service providers. This includes, in particular, entities that host websites, provide space for deploying virtual computing systems, or offer environments in which data can be backed up, managed, or processed remotely (cloud computing).
67 In the context of cloud computing, the classification as a service provider within the meaning of Art. 1(c)(2) of the Swiss Civil Code (CCC) applies equally to the various commonly distinguished service models, namely Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (Software as a Service or SaaS). Regardless of the form adopted, these models all involve the storage, processing, or provision of computer data on behalf of third parties, which justifies their inclusion in the definition of service providers covered by Art. 1(c)(2) of the Swiss Code of Obligations (CCC).
68 Service providers also include entities that operate content delivery networks
(Content Delivery Networks or CDN). These entities provide caching, temporary storage, and optimized distribution of data through geographically distributed servers.
69 However, the definition in Art. 1(c)(2) of the Swiss Civil Code (CCC) is not intended to apply to a mere content provider (e.g., a person who enters into a contract with a hosting provider to host their website) if that provider does not also offer communication services or other data processing services. Conversely, in our view, websites that, in addition to making content available, provide communication services—such as websites that offer email accounts, instant messaging, or discussion forums—fall within the scope of the definition in Art. 1(c)(2) of the Swiss Civil Code (CCC). The same applies to websites that offer data processing services, including data encryption, text translation, financial data analysis, and the automated collection of unstructured data and its conversion into organized data (web scraping).
70 This analysis also applies to online platforms and social networks which, beyond the distribution of content, offer structured features for communication and interaction among users. These services generally involve the creation of accounts, the exchange of messages, the publication of content, as well as the automated processing of data for the purposes of classification, targeted advertising, or moderation.
C. Outlook
71 Finally, like the definition adopted for computer data, the definition of “service provider” is designed to be technology-neutral. This approach has allowed it to incorporate the new types of services that have emerged since 2001, particularly entities that offer services based on artificial intelligence to process or generate data. It should be noted, however, that it is not artificial intelligence per se that is covered by the definition, but rather the functions of storing, processing, or communicating computer data that it enables.
V. Traffic Data (Letter d)
72 The final definition provided by the Convention appears in Art. 1, Letter d of the CCC, according to which “traffic data” “means any data relating to a communication passing through a computer system, produced by that system as part of the communication chain, indicating the origin, destination, route, time, the date, the size and duration of the communication, or the type of underlying service”. This data has a special legal status, insofar as it can serve as evidence—or even proof—in criminal investigations. It is generated by the various computer systems involved in the communication chain in order to route the communication from its point of origin to its destination. It is therefore an auxiliary element of the communication itself itself.
73 Traffic data is necessary to identify the source of the communication; it serves as a starting point for gathering further evidence or as a constituent element of the evidence of the offense. However, due to the enormous volume of communications exchanged daily, the data relating to these communications has a very limited retention period. It is therefore essential to act swiftly to trace the route of the suspicious communication before the traces disappear. Given the often lengthy duration of ordinary international mutual legal assistance procedures in criminal matters, the Convention provides for the option to use the expedited disclosure procedure set forth in Art. 17 CCC. This procedure makes it possible to obtain information on the communication’s route without delay and to gather other evidence before it is deleted, or to identify a suspect. This expedited and less formal procedure remains consistent with the principle of proportionality, insofar as the collection of traffic data constitutes a significantly lesser infringement of personality rights than the collection of content-related data, since it does not reveal the content of the communication, but only its path.
74 Art. 1(d) of the Swiss Civil Code (CCC) sets forth an exhaustive list of categories of traffic data that are subject to special provisions under the Convention, namely: the origin, destination, route, time, date, size, and duration of the communication, or the type of underlying service.
75 The origin and the destination correspond to the points in the network from which a communication is sent and received. Depending on the mode of communication used, they are identified by telephone numbers or, more generally, by IP addresses assigned to the relevant computer systems at a given time. These identifiers do not necessarily allow for the direct identification of an end user, particularly in the case of dynamic, shared, or masked IP addresses resulting from processes such as network address translation (NAT), relay services (e.g., the TOR network), or virtual private networks (VPN). They are of particular importance for criminal investigations, as they make it possible to identify the computer system or network access point at the origin or destination of the communication.
76 The path describes the route taken by the communication through the various relay points in the network, in particular routers, intermediate servers, or other transit infrastructure. It corresponds to the sequence of computer systems through which data is routed from its point of origin to its destination. In practice, this route can be partially or fully reconstructed from the data generated by these various systems, subject to technical limitations related, in particular, to the network architecture, the use of intermediary services, or the encryption of communications.
77 The time and date are expressed in Coordinated Universal Time (UTC). This information is essential when dealing with dynamic IP addresses. Since these addresses are constantly reassigned based on user needs, it is essential to have this information in order to ask the internet service provider to which computer system it assigned an IP address at a given time. This information must be obtained as quickly as possible, since, depending on the country, it is retained for only six to twenty-four months at most. Once this period has elapsed, the data is destroyed, and it becomes impossible to identify the user to whom an IP address was assigned. This difficulty does not exist, however, with static IP addresses, since they are permanently assigned to the same users.
78 The size of the communication is expressed in bits or bytes and corresponds to the volume of data exchanged. It can serve as an indicator for investigators regarding the type of data exchanged, insofar as certain types of content—such as images, audio recordings, or audiovisual content—generally generate larger volumes of data than simple text messages. However, this indicator must be interpreted with caution, given contemporary techniques for compressing, fragmenting, and encrypting data streams.
79 The duration of the communication is measured in hours, minutes, and seconds. It corresponds to the length of time during which a communication was established or a data exchange took place between the computer systems involved. This information can provide contextual details useful to the investigation, particularly for distinguishing one-time communications from prolonged or repeated connections, without, however, revealing the content of the exchanges that occurred during that period.
80 Finally, the type of underlying service refers to the communication method or functional category of service used in the context of the data exchange, such as email, instant messaging services, viewing online audiovisual content, or downloading data. This is a general classification of the service used, which can be difficult to determine precisely when multiple services are combined within a single communication stream or when data is encapsulated or encrypted.
Bibliography
Schmid Niklaus, Computer- sowie Check- und Kreditkartenkriminalität, Zurich 1994.
Travaux législatifs
Conseil de l’Europe, Explanatory Report to the Convention on Cybercrime, Budapest 23.11.2001, disponible sous https://rm.coe.int/16800cce5b, visité le 10.01.2026 (cité : Rapport explicatif de la Convention sur la cybercriminalité).
Comité de la Convention cybercriminalité (T-CY), Guidance Notes, disponible sous https://www.coe.int/fr/web/cybercrime/guidance-notes, visité le 10.01.2026 (cité : Note d’orientation).