Data Protection Policy
Last updated: 27 April 2026
BENSAID AVOCATS attaches particular importance to the protection of the personal data you entrust to us. This policy describes how we collect, use and protect your personal data, in accordance with the General Data Protection Regulation (EU 2016/679, GDPR) and the new Federal Act on Data Protection (nFADP, in force since 1 September 2023). Both regimes apply in parallel given our dual registration with the Paris and Geneva Bars.
1. Controller
BENSAID AVOCATS SA (Geneva) and BENSAID AVOCATS (Paris) act as joint controllers for the processing operations covered by this policy.
To exercise your rights or for any question regarding data protection, please contact: contact@bensaid-avocats.ch
The firm has not appointed a Data Protection Officer (DPO), being below the thresholds set out in Article 37 GDPR and Article 10 nFADP.
2. Processing purposes and legal basis
We process your data for the following purposes:
| Purpose | GDPR legal basis | nFADP legal basis |
|---|---|---|
| Provision of legal advice or representation | Performance of contract (art. 6.1.b) | Performance of contract (art. 31.2.a) |
| Compliance with professional obligations | Legal obligation (art. 6.1.c) | Legal obligation (art. 31.2.c) |
| Administrative and accounting management | Legal obligation (art. 6.1.c) | Legal obligation (art. 31.2.c) |
| Anti-money laundering compliance | Legal obligation (art. 6.1.c) | Legal obligation (Swiss AMLA) |
| Contact via website and forms | Legitimate interest (art. 6.1.f) | Overriding interest (art. 31.1) |
| Anonymised audience statistics | Legitimate interest (art. 6.1.f) | Overriding interest (art. 31.1) |
| Newsletters and firm publications | Consent (art. 6.1.a) | Consent (art. 31.1) |
3. Categories of data collected
- Identification data: surname, first name, postal address, email, phone
- Professional data: company, position, sector
- Wealth data (clients): asset composition, structures, planned transactions
- Tax data (clients): tax domicile, income, returns
- Site connection data: IP address, browser type, pages visited (anonymised statistics)
4. Recipients
Your data is accessible to the firm's lawyers and staff strictly within the scope of their assignments, as well as to the following providers strictly necessary to our activity:
- Hosting: OVH (Roubaix, France)
- Electronic communication tools (secure messaging, digital signature)
- Accounting and chartered accountant services
- Co-counsel, fiduciaries and notaries involved in your matter (with prior notice to you)
- Tax, judicial or regulatory authorities when legally required
No data is transferred to third parties for commercial purposes.
5. Transfers outside EU/Switzerland
Some operations may require transfers to jurisdictions outside the EU/Switzerland (United Kingdom, United States, Luxembourg). Such transfers are governed by the European Commission Standard Contractual Clauses (decision 2021/914) and, for Switzerland, by the safeguards under Article 16 nFADP. The detailed list of recipient countries is available on request.
6. Retention period
- Client data: duration of the engagement, then 5 years (general statute of limitations) or 10 years for accounting and AML obligations
- Prospects: 3 years from last contact
- Newsletters: as long as consent is valid
- Site connection logs: 13 months maximum
- Accounting data: 10 years (legal obligation)
7. Your rights
Pursuant to GDPR and nFADP, you have the following rights:
- Right of access to your personal data
- Right to rectification of inaccurate or incomplete data
- Right to erasure ("right to be forgotten"), subject to legal retention obligations
- Right to restriction of processing
- Right to data portability (GDPR only)
- Right to object to processing based on legitimate interest
- Right to withdraw your consent at any time, without affecting prior processing
- Right to issue post-mortem directives regarding your data (Article 85 of the French Data Protection Act)
To exercise these rights, write to contact@bensaid-avocats.ch attaching a copy of an identity document. We will respond within one month (GDPR) or 30 days (nFADP).
8. Security
The firm implements appropriate technical and organisational measures to ensure a security level adapted to the risk: encryption of electronic communications, file access control, regular backups, staff awareness reinforced by the professional secrecy rules of the Paris and Geneva Bars.
9. Complaint to a supervisory authority
If you consider that the processing of your data does not comply with the applicable regulation, you may lodge a complaint with:
For GDPR (European Union)
CNIL — French Data Protection Authority
3 place de Fontenoy · TSA 80715 · 75334 Paris Cedex 07
www.cnil.fr/en
For nFADP (Switzerland)
FDPIC — Federal Data Protection and Information Commissioner
Feldeggweg 1 · 3003 Bern · Switzerland
www.edoeb.admin.ch
10. Updates
This policy may be updated at any time to reflect legislative changes or the firm's practices. Any substantial modification will be announced on this page with a new update date.