When Alice sends a message to Bob with an electronic certificate, Bob needs to trust the certification authority and can use the public key to verify Alice's certificate. This means Bob can only be sure that Alice is the sender if he trusts the certification body.

bitcoin 384

In Switzerland, the Ordinance on Certification Services in relation to Electronic Signatures (VZertES) regulates the accreditation of certification authorities by the Swiss Accreditation Service (SAS) of the State Secretariat for Economic Affairs. Ultimately, Bob needs to trust the power of the state. In a letter to the NZZ, André Golliez of Swiss Data Alliance said that this was the only solution to this issue (NZZ, May 16, 2017, page 9).

There is absolutely no central trust center in a bitcoin transaction; instead, authenticity is checked using a hash function. Rather than relying on a certificate, a bitcoin transaction is confirmed with a number (cryptographic nonce) which, together with the transaction data, creates a hash value with easy-to-verify characteristics. These properties can be checked with very little effort and without the need to trust anyone. However, finding the number is a much more laborious process, as this ‘mining’ demands incredible processing power. Bitcoin transactions are entered into the blockchain, preventing the same bitcoins from being used more than once. For bitcoins, the blockchain is distributed redundantly across many instances, meaning you don't need to trust a single bitcoin instance, but rather the entire network. As a result, bitcoins are also based on a bond of trust, but not a single centralized one.

Data Protection Act

The Swiss Data Protection Act underwent a complete revision in 2020, and its new version took effect on September 1, 2023, along with the new Data Protection Ordinance (DPO). The revision itself is complete, but its practical application continues to evolve. The topic of AI is particularly relevant: On May 8, 2025, the FDPIC confirmed that the DPA is technology-neutral and applies directly to all AI applications. In practice, this means, among other things, that users must know whether they are interacting with AI (transparency requirement, Art. 19), and that a data protection impact assessment is mandatory in cases of high risk—such as profiling or facial recognition (Art. 22). The Federal Office of Justice (FOJ) is drafting a consultation document on AI regulation to be completed by the end of 2026. With this, Switzerland will implement the Council of Europe's AI Convention.

Eurospider Information Technology AG
Winterthurerstrasse 92
8006 Zürich