TranspaReg: Frames request deferral for cyber risk (cross-border guide)

Server room with blue LED lights symbolizing cybersecurity and financial transparency in Switzerland.

National Councillor Lorenzo Quadri asks to suspend the entry into force on 1 October, citing the case of Liechtenstein.

Context

In breve

  • Quadri chiede di sospendere TranspaReg al 1° ottobre
  • Rischio informatico per dati di 500'000 entità
  • Caso Liechtenstein: dati di 31'000 aziende sottratti
  • Obiettivo GAFI: trasparenza ADE senza centralizzazione

Fatti chiave

  • Chi: Consigliere nazionale Lorenzo Quadri (Lega dei Ticinesi)
  • Quando: Entrata in vigore prevista il 1° ottobre
  • Cosa: Registro svizzero per la trasparenza degli ADE
  • Dove: Svizzera (scala nazionale)
  • Rischio: Attacchi informatici su database centralizzato

Il Consigliere nazionale Lorenzo Quadri, rappresentante della Lega dei Ticinesi, ha presentato una mozione al Consiglio federale con una richiesta precisa: sospendere l’entrata in vigore della TranspaReg, prevista per il prossimo 1° ottobre. L’obiettivo è guadagnare tempo per valutare soluzioni alternative alla centralizzazione dei dati, che Quadri considera troppo rischiosa. Il nuovo registro svizzero per la trasparenza degli aventi economicamente diritto (ADE) ha lo scopo di raccogliere le informazioni sulle persone fisiche che controllano effettivamente società, fondazioni, trust e altre strutture giuridiche. Si tratta di un passo cruciale per la conformità alle norme internazionali, ma il consigliere mette in guardia contro i pericoli di un database unico.

Operational details

L’analisi delle implicazioni pratiche della mozione di Quadri rivela un conflitto tra obblighi internazionali e sicurezza informatica. Il registro TranspaReg mira a soddisfare i requisiti del GAFI (Gruppo di Azione Finanziaria), che impone la trasparenza degli aventi economicamente diritto per lotta al riciclaggio e al finanziamento del terrorismo. Tuttavia, la modalità di implementazione, se centralizzata, crea un rischio sistematico. Il caso del Liechtenstein, citato nella mozione, è un precedente allarmante: a fine luglio, il registro analogo del Principato è stato colpito da un attacco informatico con la sottrazione di dati relativi agli ADE di circa 31'000 aziende, fondazioni e trust. Questo incidente dimostra che il rischio non è teorico, ma concreto e attuale.

Key points

For those who live or work in Switzerland, the TranspaReg issue directly impacts corporate data management and tax planning. Although the motion calls for a postponement, businesses must continue to monitor regulatory developments to ensure compliance. Here is what to do concretely during this period of regulatory transition.

Operational steps for businesses

1. Verify your registration: ensure that ADE data is up to date and consistent with current regulations, regardless of the final archiving platform. 2. Monitor official communications: follow updates from the Federal Council and the FOPDP regarding the timing and implementation methods of the register. 3. Assess cybersecurity: companies may need to strengthen their IT defenses while awaiting clarity on data centralization. It is advisable to consult cybersecurity experts to evaluate system resilience. 4. Plan for compliance: prepare for possible changes in filing procedures, which may vary depending on the final decision between a centralized or decentralized system.

Frequently Asked Questions
Why does Lorenzo Quadri ask to suspend the TranspaReg?
Lorenzo Quadri, of the Ticino League, filed a motion to suspend the entry into force scheduled for October 1. The main reason is cyber risk: centralizing the data of over 500,000 entities in a single database would make it an attractive target for cybercrime, with possible damage to Switzerland's financial reputation.
What happened in Liechtenstein that worried Quadri?
The motion cites an incident that occurred at the end of July: Liechtenstein's similar registry was hit by a cyber attack that led to the theft of data relating to HADES from about 31,000 companies, foundations and trusts. This case is used to demonstrate that the risk of breach of a centralized database is not theoretical but concrete.
What alternatives to centralization does Quadri suggest?
Quadri calls on the Federal Council to verify whether the transparency objectives required by the FATF can be achieved through more secure, e.g. decentralised, systems. This approach would fragment the data, making a massive attack more difficult and avoiding a single point of failure, while maintaining the traceability requirements of HADES.

Related articles