AI translation of the German original. Legal references and sources remain those of the original document. German version.
¶ Data Security – Who Can Technically Read the Data?
Language versions: Deutsch · Français · Italiano · English · Rumantsch
¶ Four Possible Architectures
The EPFL/C4DT study of 17 July 2026, commissioned by the FOPH, distinguishes four models. It describes options, not an E-GD service that has already been awarded or is in operation.
| Model | Central Protection Idea |
|---|---|
| I: Organisational protection | Encrypted transmission and storage; the operator can decrypt data at interfaces |
| II: Confidential computing | Processing in a protected execution environment; additional technical shielding |
| III: Keys held by the data subject | Patient-controlled key management |
| IV: Distributed key control | Multiple independent parties must cooperate |
The study also addresses recovery, emergency access and metadata. A comprehensive review of all cyber-defence measures is explicitly outside its mandate. Study, pp. 2, 4 and 9–15
¶ What the Legislation Is to Require
The National Council version mandates encryption, privacy by design, protection against outages and data breaches, and recurring security audits. It does not explicitly designate Model III as the only permissible architecture. Art. 5a
¶ Open Source Code
The Federal Chancellery explains the open-source obligations under Art. 9 EMBAG. The National Council makes explicit reference to this for the E-GD software. The Pirate Party's demand for fully publicly auditable code must be distinguished from this: which parts are actually published and which exceptions are claimed is to be monitored in procurement and implementation. Federal Chancellery Art. 5 para. 8 Demand for disclosure
¶ Editorial Assessment of Security Questions
A Swiss storage location and a legal prohibition on access are important properties. They do not alone answer who controls the decryption keys or what happens in the event of compromised accounts. Conversely, strong key control creates new requirements for emergency access, device loss and comprehensible recovery.
The following must therefore also be examined: backups, independent audits, limited administrator rights, traceable accesses and functioning treatments during an outage. "Centralised" or "decentralised" alone is not a sound security judgement.
Further: Criticism · Implementation