The controller and the processor shall guarantee a level of data security appropriate to the risk by taking suitable technical and organisational measures.
The measures must make it possible to avoid breaches of data security.
The Federal Council shall issue provisions on the minimum requirements for data security.