Federal Act
on the Swiss Financial Market Supervisory Authority
(Financial Market Supervision Act, FINMASA)

Art. 13 Staff 28

1 The em­ploy­ment of FINMA staff is gov­erned by pub­lic law.

2 Art­icle 6a of the Fed­er­al Per­son­nel Act of 24 March 200029 ap­plies by ana­logy.

3 The oc­cu­pa­tion­al pen­sion scheme for the staff is gov­erned by the le­gis­la­tion on the Fed­er­al Pen­sion Fund.

4 The Board of Dir­ect­ors reg­u­lates in an or­din­ance:

the em­ploy­ment of per­son­nel and in par­tic­u­lar salar­ies, ad­di­tion­al be­ne­fits, work­ing hours, duty of loy­alty and ter­min­a­tion of em­ploy­ment;
the com­pos­i­tion, elec­tion and or­gan­isa­tion of the Joint Com­mit­tee for the FINMA Pen­sion Fund.

5 The Board of Dir­ect­ors shall sub­mit the or­din­ance to the Fed­er­al Coun­cil for ap­prov­al.

Art. 13a30Data processing

1 FINMA shall pro­cess, in hard copy or in one or more in­form­a­tion sys­tems, the data on its em­ploy­ees and on job ap­plic­ants ne­ces­sary for per­form­ing the tasks in ac­cord­ance with this Act. It may del­eg­ate the pro­cessing to a pro­cessor. The data pro­cessed re­late in par­tic­u­lar to:31

the ap­plic­a­tion pro­cess;
cre­at­ing, ex­ecut­ing and ter­min­at­ing an em­ploy­ment re­la­tion­ship;
per­son­nel and wage man­age­ment;
per­son­nel de­vel­op­ment;
per­form­ance ap­prais­al;
re­in­teg­ra­tion meas­ures in the event of ill­ness and ac­ci­dent.

2 It may pro­cess the fol­low­ing data per­tain­ing to its em­ploy­ees ne­ces­sary for per­form­ing the tasks set out in para­graph 1, in­clud­ing sens­it­ive per­son­al data:34

per­son­al de­tails;
state of health de­tails with re­gard to work­ing abil­ity;
per­form­ance and po­ten­tial in­form­a­tion, as well as data on per­son­al and pro­fes­sion­al de­vel­op­ment;
data re­quired with­in the frame­work of par­ti­cip­a­tion in the im­ple­ment­a­tion of so­cial se­cur­ity law;
case files and au­thor­it­ies' de­cisions as­so­ci­ated with work.

3 It shall is­sue im­ple­ment­ing reg­u­la­tions with re­gard to:

the ar­chi­tec­ture, or­gan­isa­tion and op­er­a­tion of the in­form­a­tion sys­tem(s);
the pro­cessing of data, par­tic­u­larly gath­er­ing, stor­age, archiv­ing and de­struc­tion;
data pro­cessing au­thor­isa­tions;
the data cat­egor­ies un­der para­graph 2;
data pro­tec­tion and se­cur­ity.

