Article 5
Definitions
In this Act:
- a. personal data means any information relating to an identified or identifiable natural person;
- b. data subject means a natural person whose personal data is processed;
- c. sensitive personal data means:
- data relating to religious, philosophical, political or trade union-related views or activities,
- data relating to health, the private sphere or affiliation to a race or ethnicity,
- genetic data,
- biometric data that uniquely identifies a natural person,
- data relating to administrative and criminal proceedings or sanctions,
- data relating to social assistance measures;
- d. processing means any handling of personal data, irrespective of the means and procedures used, in particular the collection, storage, keeping, use, modification, disclosure, archiving, deletion or destruction of data;
- e. disclosure means transmitting personal data or making such data accessible;
- f. profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
- g. high-risk profiling means profiling that poses a high risk to the data subject's personality or fundamental rights by matching data that allow an assessment to be made of essential aspects of the personality of a natural person;
- h. breach of data security means a breach of security that leads to the accidental or unlawful loss, deletion, destruction or modification or unauthorised disclosure or access to personal data;
- i. federal body means an authority or service of the Confederation or a person entrusted to carry out public tasks on behalf of the Confederation;
- j. controller means a private person who or federal body which, alone or jointly with others, determines the purpose and the means of processing personal data;
- k. processor means a private person or federal body that processes personal data on behalf of the controller.