Available only in Switzerland

Schweizerform is currently available exclusively for users in Switzerland. Account creation from your region is restricted.
Back to Blog

Professional Secrecy and Online Forms in Switzerland (Art. 321 SCC)

Data protection law tells you how to process personal data. Art. 321 of the Swiss Penal Code tells doctors, lawyers, dentists, psychologists, pharmacists and their staff that disclosing what they learned is a criminal offence carrying up to three years. It binds auxiliary persons too — which is where your software vendor enters the picture. Who is covered (and who, like veterinarians, is not), what a valid release declaration needs, why a signed DPA does not settle the question, and the one architecture that keeps a provider outside the secrecy perimeter entirely.

Professional Secrecy and Online Forms in Switzerland (Art. 321 SCC)

Most conversations about form tools in a medical practice or a law firm are conducted entirely in the vocabulary of data protection: legal basis, processing agreement, transfer abroad. That is the wrong first vocabulary. Before any of it applies, there is a criminal provision that says the practitioner may not reveal what was entrusted to them — and unlike the nFADP, it is enforced with a custodial sentence rather than an administrative fine.

The short version

Art. 321 of the Swiss Penal Code makes breaching professional secrecy a criminal offence punishable, on complaint, by a custodial sentence of up to three years or a monetary penalty. It binds auxiliary persons as well as the professional — the practice assistant, the locum, the secretary, and arguably the IT provider. Release requires the consent of the person the secret belongs to, or written authorisation from the supervisory authority — nothing else works, and no contract with a vendor substitutes for it. The contested question is whether handing readable data to a cloud provider is a disclosure at all: the dominant view says the provider is an auxiliary person, so it is not, subject to real duties of care; a serious minority view says you cannot label a provider an «auxiliary person» simply to route around the protection. The way out of the argument is to make sure the provider never holds readable data in the first place.

Who Is Actually Bound — the List Is Longer Than You Think, and Shorter

Art. 321 names its professions explicitly, and the list has grown over the years to cover much of the health sector: clergy, lawyers, defence counsel, notaries, patent attorneys, auditors bound to secrecy under the Code of Obligations, physicians, dentists, chiropractors, pharmacists, midwives, psychologists, nursing professionals, physiotherapists, occupational therapists, nutritional advisers, optometrists and osteopaths — and their auxiliary persons.

Two consequences people get wrong

First, «and their auxiliary persons» is not decorative. The medical practice assistant, the legal secretary, the intern and the locum are personally exposed to the same criminal provision. Anyone who touches the intake data is inside the perimeter. Second, the list is exhaustive, so some professions that feel like they belong are not there — veterinarians, for instance, are not named in Art. 321, and neither are teachers in most settings (public-school staff are usually caught by the official-secrecy provision instead). Their duty of discretion is real, but it comes from the mandate, professional rules and data protection law, not from this article. Knowing which duty you are actually under determines what a breach costs and who can release you.

Three neighbouring regimes matter in the same breath. Art. 320 covers official secrecy in the public sector. Art. 47 of the Banking Act covers banking secrecy. And for lawyers, Art. 13 of the Lawyers Act creates a separate professional-secrecy duty that is unlimited in time and extends to auxiliaries — a distinct secret area from Art. 321 rather than a copy of it, which matters when a firm is deciding what it may put in a shared system.

What Counts as Disclosure

The offence is revealing a secret entrusted because of the profession or learned in its exercise. Three things follow that are relevant to a form:

  • The fact of the relationship is itself secret. That someone is a patient at an oncology practice, or a client of a criminal defence firm, is protected before any content is discussed. An intake form's existence in a given inbox can carry the secret.
  • Disclosure does not require publication. Making the information available to one person outside the perimeter is enough. This is precisely why the vendor question is a secrecy question and not only a data protection question.
  • It is prosecuted on complaint. In practice that means the risk materialises when a relationship goes wrong: a dispute, a complaint to the cantonal supervisory authority, a disgruntled ex-employee. Nobody audits you into an Art. 321 case; a person brings it.

Being Released From the Secret — and What a Release Declaration Must Contain

There are exactly two routes: the consent of the person the secret belongs to, or written authorisation from the superior authority. That is why release-from-secrecy declarations exist, and why the ones circulating as free templates are so often useless — a blanket «I release Dr. X from professional secrecy» is not informed consent to anything in particular.

A declaration that will survive being challenged is specific on five points:

  1. Who is released — the named practitioner or practice, not «the treating team» in the abstract.
  2. Towards whom — the named recipient. A release towards an insurer is not a release towards an employer, and a release towards one specialist is not a release towards a clinic group.
  3. What exactly — the report, the period, the specific findings. «All medical information» invites a later argument that consent was not informed.
  4. For what purpose, and for how long — a purpose that ends, and a date on which the release lapses.
  5. Revocability — stated plainly, because it is revocable, and the person should know that when they sign.

Where release declarations go wrong in practice

A release signed under pressure — at the counter, on a form bundled with the appointment booking, as a condition of treatment — is exactly the consent that fails when it matters. The FDPIC's general position on consent in imbalanced relationships applies with full force here. Separate the release from the intake: two documents, two moments, two decisions. And never make treatment conditional on a release that is not strictly necessary for the treatment.

One practical note on collecting these digitally: a release is a document that must be attributable to a specific person, kept unaltered, and produced years later. That argues for a signed record with a stored timestamp rather than a checkbox in a spreadsheet. See informed consent in the digital age for the consent-capture side, and our templates for the intake forms these usually accompany — we do not currently publish a release-from-secrecy template, and a boilerplate one would be worse than none.

The Vendor Question — Genuinely Contested, and Worth Understanding

Here is the question that decides whether your online form is a problem: when patient or client data lands on a third-party server in readable form, has the secret been disclosed?

The dominant view is no. An IT or cloud provider engaged to support the professional activity is treated as an auxiliary person within the meaning of Art. 321, and auxiliary persons are inside the perimeter rather than outside it — they are themselves bound by the provision. On that view, using a cloud service is not per se a breach. It comes with duties that are stated consistently across the professional and cantonal guidance: select the provider carefully, secure the secrecy obligation contractually, ensure the data is used only to perform the contract, and supervise compliance to a reasonable extent.

There is a serious dissenting strand, and it is worth taking seriously rather than dismissing. Its argument is that disclosing a protected fact to an auxiliary person can already be a disclosure, and that defining an IT provider as an «auxiliary person» specifically in order to route around the secrecy protection is not an admissible move. On that view, the auxiliary-person doctrine covers people integrated into the professional activity — the assistant, the locum — and stretches uncomfortably when applied to a foreign platform company with thousands of employees and its own commercial interests.

You do not have to resolve the debate

You have to decide what to do while it is unresolved. Note that both positions agree on one thing: the analysis only bites where the provider can actually read the data. If the provider holds only ciphertext and never holds a key, the disclosure question does not arise on either view — there is nothing to reveal. That is not a clever argument, it is the absence of the fact the argument is about.

This is also the reasoning the Swiss data protection commissioners adopted for public bodies. In November 2025, privatim — the conference of Swiss data protection commissioners — adopted a resolution on international cloud services treating provider access as the decisive criterion, with a narrow exception where the body itself encrypts the data and the provider holds no key. Public hospitals and cantonal institutions carry both Art. 320 and cantonal data protection law, so that resolution is the sharpest available statement of where the line is being drawn. The wider hosting picture is in which form tools are hosted in Switzerland.

Why a Signed DPA Does Not Settle It

A processing agreement is a data protection instrument. It allocates roles, imposes security and confidentiality obligations, and lists sub-processors. It is necessary — but it operates in a different legal system from Art. 321, and it does two things that are frequently overconstrued:

What a DPA doesWhat it does not do
Binds the provider contractually to confidentiality and to processing only on your instructionsRelease you from professional secrecy — only the entitled person or the supervisory authority can
Documents your data protection position for a supervisory authorityChange whether the provider's staff can technically read the content
Gives you a claim against the provider if it breachesPrevent the breach, or undo the disclosure once it has happened
Names sub-processors so you know the chainBind those sub-processors to Swiss criminal secrecy in any practical sense

The blunt version: a DPA is a promise plus a remedy. Professional secrecy is not a domain where a remedy is much comfort — the patient whose file was read does not want damages, and the criminal provision is not satisfied by your having a good contract with the party that read it. What a DPA is genuinely good for is documented in do you need a data processing agreement for your form tool; this article is about the duty that sits above it.

A Practical Standard for a Practice or a Firm

1

Write down which secrecy duty you are actually under

Art. 321, Art. 320, Art. 13 of the Lawyers Act, banking secrecy, or a contractual duty of discretion. They differ in who may release you and what a breach costs. One paragraph, in your practice documentation.

2

List everyone inside the perimeter, including auxiliaries

Practice assistants, locums, the external bookkeeper, the IT support contractor with remote access. They are personally bound; they should know that in writing, and it should be part of onboarding rather than folklore.

3

Ask of every tool: can the provider read this?

Not «is it encrypted» — everything is encrypted in some sense. Can the provider's staff, its support tooling or its sub-processors see the content. That single question sorts your tools far better than any certification badge.

4

Take content out of e-mail first

The highest-volume secrecy exposure in most practices is not the form tool, it is answers arriving by e-mail into several mailboxes and syncing to several phones. Notify without content, read in the system.

5

Separate the release from the intake

A specific, revocable, time-limited release declaration, signed as its own act — never bundled into an appointment form and never a condition of treatment.

6

Restrict access inside your own team

Secrecy is breached from inside more often than from outside. Who in the practice can open which intake, and is that enforced technically or by convention?

7

Prefer architecture over paperwork where you can

For the forms that carry the most sensitive content, choose a tool where the provider cannot read submissions at all. Then the contested doctrinal question above simply does not arise for that data.

Data protection asks whether you were allowed to process it. Professional secrecy asks who else got to see it. The second question has a much shorter list of acceptable answers.

Bottom Line

If you are a physician, dentist, pharmacist, psychologist, physiotherapist, lawyer, notary or one of the other professions named in Art. 321 — or you work for one — your confidentiality obligation is criminal law, it binds you personally as an auxiliary person, and only the patient or client, or the supervisory authority, can release you from it.

Whether putting readable client data on a third-party platform is a disclosure remains genuinely contested. You can spend the next few years following that debate, or you can make it inapplicable to your most sensitive forms by choosing a tool that never holds readable data. The second is cheaper, it is defensible today, and it has the useful property of being true regardless of which way the doctrine settles.

Schweizerform encrypts responses in the respondent's browser before they are sent; we hold ciphertext and no key, so there is no readable copy on our side to disclose. Encrypted submissions are stored in Switzerland. See the legal intake, healthcare, therapy and dental use cases for how practices set this up, and what happens when the government asks for the order-and-disclosure side.

Disclaimer: This article is general information and marketing content, not legal advice, and it does not create a lawyer-client relationship. References to Art. 320 and 321 of the Swiss Penal Code, Art. 47 of the Banking Act, Art. 13 of the Lawyers Act, the nFADP and the privatim resolution of November 2025 are simplified summaries of a position checked in July 2026. The treatment of IT providers as auxiliary persons is a contested question of doctrine presented here as contested — take Swiss legal advice on your own arrangements before relying on either view. Cantonal supervisory practice varies.