Il Diario

lunedì, 29 giugno 2026

Dr. iur. Servatius von Tatzenberg

June's last Monday: five sanctions updates in the queue, three enforcement angles from FINMA landing simultaneously, and Switzerland's Bilaterale III obligations acquiring the legal weight that policy memos never had.

Four Swiss Sanctions Lists Updated in June — Run Q2 Screening Before Month-End

FINMA (de)

Russia/Belarus (Anhang 8, effective 15 June at 23:00), Sudan (Anhang 2, effective 4 June at 23:00), ISIL/Al-Qaeda (effective 31 March), Iran (Anhänge 12 and 14, 14 April): four separate ordinances, four entry-into-force timestamps — and FINMA's publication notices post-date entry into force by up to one day, meaning an analyst working from the FINMA URL date rather than the ordinance gazette backdates the screening obligation. The Sudan update amends SR 946.231.18 — the same ordinance where the structural 20-day lag behind EU listings was mapped in May. The ISIL/Al-Qaeda list runs on the UN 1267 channel and bypasses the country-level filter that most screening stacks apply to Russia and Sudan — flagged here when SR 946.231.08 was designated in March 2025. The Iran entry amends the December 2025 ordinance that replaced the JCPOA architecture wholesale; if your screening workflow still references pre-totalrevision registers, that framework no longer exists. A monitoring calendar indexed to SR numbers — not just "SECO" generically — is the minimum viable infrastructure. If yours is still keyed to country only, this month has shown exactly what you are missing.

Previsione: A Russia/Belarus list amendment is likely in July when the EU finalises the 21st sanctions package.

FINMA's Enforcement Trilogy — Personal Bans, VAG Intermediaries, and Product Governance Land Together

FINMA / Unter Vorbehalt (en)

Three pieces from von Tatzenberg in today's edition, and they compose a single governance map. The individual enforcement article establishes that the Berufsverbot is now FINMA's normalised escalation tool — not a post-Credit Suisse anomaly — and asks which named officers in your supervised entities carry a traceable individual footprint. The VAG intermediary piece confirms the two-year reform signals have not softened: FINMA's posture on licensable activity at the supervised perimeter is exactly where it said it would be, and the GwV-FINMA revision tightens the same boundary from the AML side. The product governance piece closes the loop: product selection within a discretionary mandate runs accountability back to the bank and, through the individual enforcement article, potentially to a named officer. These do not function as three separate compliance updates — read them as a set.

Bilaterale III Converts EU Rule-Making Into Swiss Statutory Obligation

SWI swissinfo.ch / Unter Vorbehalt (en)

The SWI Brexit comparison is useful backdrop; today's von Tatzenberg analysis is the operative read. Under the dynamic adoption mechanism, EU legislation enacted post-ratification in covered sectors enters Swiss law automatically — the parliamentary opt-out exists in the treaty text, but Switzerland has not invoked it in any sector and faces real political costs if it does. The exposure for in-house counsel sits in commercial contracts: agreements in Bilaterale III sectors (electricity, land and air transport, research) that use a Swiss-law clause without an adaptation mechanism may be carrying EU regulatory risk that was not priced at signing. The cantonal subsidy regime already operates under EU state-aid rules as a direct consequence of this mechanism — that is the template, not an anomaly. The full dynamic adoption primer from May remains the reference for the legal mechanics.

Art. 89 GDPR Is Not an AI Training Pass — and State Data Requests Hit the Same Outer Limit

Unter Vorbehalt (en)

Two pieces from Casimir von Firn today that belong on the same desk. The Art. 89 GDPR piece extends the June analysis of the research privilege into the safeguard gap: most analytics and AI training programmes that invoke the carve-out have not implemented the pseudonymisation and purpose-limitation controls that actually make it defensible under supervisory scrutiny. The state-access piece is the inverse problem: when a public authority seeks customer financial data, bank discretion does not expand because the requester is domestic rather than foreign. Art. 47 BankG and Art. 271 StGB define the only lawful channel — full stop. The connection worth filing: the dataset your analytics team wants to mine is the same dataset a regulator can formally request. If your data governance policy has not mapped those two access paths against each other, you have an exposure in both directions simultaneously.

Limitation-of-Liability Clauses Under Swiss Law — Art. 100 OR Voids the Clause You Think You Have

Fedlex / Unter Vorbehalt (de)

Art. 100 Abs. 1 OR is not a drafting technicality — it is the structural ceiling on Swiss liability clauses, and it operates regardless of how the exclusion is worded. A blanket liability exclusion is null where it purports to cover gross negligence; that consequence cannot be contracted around. The May primer laid out the mechanics; today's von Tatzenberg piece is the contract audit. The test at review is not whether a limitation clause exists — it is whether the cap holds at the amount you are relying on, for the fault level your counterparty will allege. Any clause drafted as an absolute exclusion for consequential loss is the drafting that breaks. A hard CHF cap indexed to contract value is structurally more defensible, and even that requires the right formulation on fault gradation.

Proton Wins Swiss Surveillance Appeal — Proportionality Now Has Binding Precedent

SWI swissinfo.ch (en)

The Federal Administrative Court confirmed in October 2021 that email and over-the-top communication services are not classified as telecommunications providers under Swiss law and therefore fall outside VÜPF data retention and surveillance obligations — the ruling analysed in depth in May. The Bundesgericht had reached the same classification conclusion six months earlier; both holdings are now binding precedent, not obiter dicta. For providers of business communication platforms, collaboration tools, or workflow software operating in Switzerland: the VÜPF perimeter question turns on classification, not proportionality. If your service is not classified as a telecom provider under Swiss law, data retention and interception obligations do not attach — the operative question is whether your product falls within the statutory definition, not whether a specific state demand would survive a proportionality test. The state-access piece in today's von Firn edition is the financial-data analogue of the same threshold problem — the legal bases differ, but in both cases the prior question is whether the applicable statute brings your business within scope at all.

Switzerland Is Prosecuting More Foreign Bribery — The Organisational Liability Gap Stays Open

SWI swissinfo.ch (en)

"More cases" also means more plea agreements, and the terms of those agreements are setting informal compliance benchmarks that are never published. Switzerland has moved from virtually no foreign bribery prosecutions to a credible enforcement record, but the OECD Working Group on Bribery has consistently flagged the gap: Art. 102 Abs. 2 StGB requires that a Swiss company failed to take adequate organisational precautions, but what those precautions are is not defined in the statute and the courts have moved slowly on the standard. The May piece on the enforcement gap and the Art. 322septies analysis — act-nexus, not a gift threshold — remain the operative reading. Immediate action point from the SWI reporting: if your compliance programme still relies on a generic "no gifts over CHF x" threshold, it is not calibrated to Swiss law as currently enforced.

Previsione: Watch for an OECD Phase 4 follow-up report on Switzerland — that is the mechanism most likely to force clarification of the Art. 102 Abs. 2 StGB organisational precaution standard.

GwV-FINMA Consultation Has Closed — Expect the Revised Ordinance Before Year-End

FINMA (en)

The consultation on the partial revision of the FINMA Anti-Money Laundering Ordinance launched 12 May and has now closed. The three ownership-transparency clauses that shift the due-diligence burden are the operative changes — mapped here when the consultation opened. No finalisation timeline has been announced; given typical FINMA post-consultation schedules, year-end 2026 is plausible but not confirmed. The connection to today's VAG intermediary article is not incidental: FINMA is tightening the AML perimeter through the revised ordinance while simultaneously signalling through enforcement that intermediaries are expected to operate within that perimeter, not in the grey zone adjacent to it. These are coordinated instruments, not concurrent coincidences.

AI at Europe's Borders Is Growing Business — Annex III Obligations Are Still Coming in 2027

SWI swissinfo.ch (en)

The AI Act's Annex III high-risk classification for biometric identification at borders was postponed from August 2026 to 2027 — it was not withdrawn. The May analysis of the extension noted that Swiss providers supplying AI systems to EU border agencies have a preparation window that is shrinking on the left and fixed on the right. The SWI piece confirms commercial interest is filling the pipeline at exactly the moment regulatory obligations are crystallising. If you are procuring or licensing biometric AI for cross-border deployment, 2027 is not a distant deadline: government procurement cycles in this segment run 18 to 24 months from RFP to contract. The compliance preparation for both client and provider needs to have started already.

FINMA Moves to Oerlikon — Read the Institutional Signal, Not the Property News

FINMA (en)

FINMA is relocating its Zurich office from the city centre to Zürich-Oerlikon. The stated reasons — lower operating costs per workstation, more attractive working conditions — are institutional maintenance. The signal worth reading: Oerlikon places FINMA at deliberate physical remove from the Bahnhofstrasse banking district. That distance, however symbolic, reinforces what the enforcement calendar is already communicating. FINMA is not positioning itself as a collegial interlocutor in the same postcode; it is positioning itself as a supervisory authority. The relocation is incidental. The posture is not.

The next update to watch: the EU's 21st Russia/Belarus package, expected July 2026 — the Swiss Anhang 8 amendment will follow within days.