Data Security: The Foundation for Data Protection
Data protection and data security are two sides of the same coin. Data protection defines the legal and ethical framework for handling data, while data security provides the practical means of implementing it. Embedded within the broader concepts of information security and cybersecurity, together they form a comprehensive framework for protecting one of the most valuable resources of our time: information.
This blog post is intended solely to provide basic knowledge about compliance and regulatory requirements and to illustrate that UMB takes these aspects into account in the context of its services.

Data protection is designed to protect personal rights and ensure that personal data is collected and processed in accordance with the law. Personal data refers to any information relating to an identified or identifiable (natural) person. Anonymized data is excluded from this definition.
Clear legal requirements
When personal data is processed, data protection principles must be complied with. Our graphic shows the questions an organization processing data must consider to ensure compliance with principles such as lawfulness, data accuracy, good faith, transparency, purpose limitation, and data security. Breaching these principles constitutes an infringement of personality rights, which may nevertheless be justified in certain cases. The Swiss Federal Act on Data Protection (FADP)[i] recognizes three grounds for justification: the explicit consent of the data subject, an overriding private or public interest, or a legal basis that permits or even requires processing.
Data processing: The customer is king
Particularly relevant for IT service providers: As soon as we process personal data on behalf of our customers, we are considered a data processor — and therefore have clear legal obligations. The following two obligations are particularly important: We may only process data within the scope of the order and in accordance with the customer's instructions. In addition, we must take appropriate technical and organizational measures at all times to ensure that the level of protection is at least equivalent to that which the customer would have to comply with themselves.
Where data protection ends and data security begins
Data security forms the technical and organizational foundation without which effective data protection would not be possible, yet it goes far beyond the protection of personal data. Data security safeguards all corporate data - including trade secrets, financial data, technical documentation, and other sensitive information that has no personal reference. Data security is implemented through a combination of technical and organizational measures. Technical measures include, among others, encryption, modern access and authorization controls, firewalls, intrusion detection systems, antivirus software, and reliable backup and recovery solutions. This is complemented by comprehensive logging and continuous monitoring of relevant systems. From an organizational perspective, UMB relies on clear policies for data classification and handling, regular training and awareness programs for all team members, as well as clearly defined responsibilities and approval processes. Equally important are emergency and recovery plans, regular security audits, and a robust business continuity management framework[ii].
The bigger picture: information security and cybersecurity
Information security is the overarching concept and pursues the classic protection goals of confidentiality, integrity, and availability of information. Proven standards such as ISO 27001 provide the framework for a systematic information security management system (ISMS). For customers who want a more rigorous effectiveness test, reports in accordance with ISAE 3402 Type II, SOC 2, or — depending on the industry — DORA offer additional security.
In an increasingly networked world, modern cyber threats such as ransomware, phishing, and advanced persistent threats are coming into focus. Here, classic IT security, which ensures the protection of infrastructure, and cybersecurity, which is specifically geared toward defending against current attack scenarios, merge into a holistic security strategy. This is part of responsible corporate management and requires clear responsibilities.
Data protection is part of UMB's corporate culture
Data protection and data security are simply indispensable. At UMB, we take this responsibility seriously and consistently implement both technical and organizational measures.
Our customers can rely on this: compliance and reliable protection are not costly add-ons for us, but an integral part of our corporate culture. That is precisely why our customers sleep soundly at night—and so do we. If you would like to learn more, we would be pleased to speak with you at any time.
Data protection principles
What is the reason for processing: a contract, consent or another legal basis (e.g. overriding interest)?
Is the data collected intended solely for my current work process, or may I disclose this data within my company or to third parties?
Does the person concerned understand what happens to the data and what it is used for? Would I understand this myself if I were affected or if it were my data?
Could I carry out the process with less data collected? Is all the data useful or necessary?
Are the answers to all the questions asked here documented in the register of processing activities?
Are the persons concerned aware that their data is being processed?
What is the data collected for and what will be done with it?
Can I continue to store data that has already been collected?
Have I chosen the correct storage location and/or filing location for the data?
Is the data I'm using current?
Your contacts



