Data Protection Statement
Effective date: 13 August 2026
1. What is this Data Protection Statement about?
Gabriele Banfi practises law under the name GBLaw – Law Firm and is based in Lugano. In this Statement, GBLaw is also referred to as “GBLaw”, the “Firm”, “we” or “us”.
In the course of our professional activities, we collect and process personal data, in particular personal data relating to current and prospective clients, persons connected with clients or matters, opposing parties and their representatives, courts, public authorities and other public bodies, correspondent lawyers, consultants, experts, translators and other professionals, suppliers and contractual partners, visitors to our website, and other persons or organisations with whom we come into contact, including their respective contact persons and employees.
“Personal data” means any information relating to an identified or identifiable individual.
This Statement explains the principal processing activities carried out by GBLaw. We may provide additional information for particular processing activities, for example in mandate agreements, powers of attorney, forms, communications or specific clauses.
If a person provides us with personal data concerning third parties, such as family members, representatives, employees, opposing parties or other persons involved, we assume that the person is authorised to do so, that the data is accurate and that, where a duty to provide information applies, those third parties have been informed of the disclosure and of this Statement.
Sending a communication or documents to the Firm does not constitute acceptance of a mandate. An attorney-client relationship is established only after the Firm has expressly accepted the mandate and completed any necessary conflict-of-interest checks.
2. Who is the controller?
The controller for the processing described in this Statement is:
Gabriele Banfi, attorney-at-law
GBLaw – Law Firm
Via Giosuè Carducci 4
CH-6900 Lugano
Switzerland
Telephone: +41 91 923 77 77
Email: info@gblaw.ch
Questions concerning data protection and requests to exercise data-protection rights may be sent to the contact details above.
3. For what purposes do we process personal data?
In the course of our activities, we may process different categories of personal data for the purposes described below.
Communications
We process personal data in order to communicate with current and prospective clients, opposing parties, courts, public authorities, advisers, suppliers and other persons by email, telephone, post or other agreed channels. For this purpose, we may process in particular:
- first name, surname, title and function;
- postal address;
- email address;
- telephone number;
- language of communication;
- the content of correspondence;
- documents and information transmitted;
- the date, time and other metadata relating to communications.
Where a person must be identified for legal, professional or security reasons, we may request additional information or documents.
Preparation and conclusion of contractual relationships
Before accepting a mandate or entering into another contractual relationship, we process the data necessary to understand the request, identify the persons and entities involved, check for possible conflicts of interest, assess the proposed engagement, define the subject matter and terms of the mandate, and comply with applicable legal and professional obligations.
For these purposes, we may process identification and contact data, information about the parties involved, powers of attorney, declarations, documents, financial and asset-related information, and other data received from the data subject, third parties or publicly accessible sources.
Management and performance of mandates
We process personal data in order to perform our obligations towards clients and, in particular, to provide legal advice, assistance and representation. Depending on the nature of the matter, the data processed may include:
- personal and family data;
- professional and corporate information;
- financial, banking and asset-related data;
- contracts, powers of attorney, legal documents and correspondence;
- minutes, notes, opinions and documents prepared by the Firm;
- information received from clients, opposing parties, courts, public authorities, public registers, advisers and other persons;
- data relating to civil, criminal, administrative, enforcement, insolvency or arbitration proceedings;
- decisions, judgments, decrees, orders and other official documents;
- information relating to professional services, invoices and payments.
In the course of mandates, we may also process sensitive personal data where necessary. Depending on the matter, this may include data concerning health, the private or intimate sphere, religious, philosophical, political or trade-union views or activities, social assistance measures, administrative or criminal proceedings and sanctions, and other data to which applicable law affords special protection.
Processing may also be necessary to establish, exercise or defend legal claims and to represent clients before courts, public authorities or other bodies.
Administration and compliance
We process personal data in order to:
- open and administer files;
- record professional services;
- issue and manage invoices;
- record payments;
- maintain accounts;
- comply with tax obligations;
- manage suppliers and other contractual relationships;
- archive and administer documents;
- manage receivables;
- comply with legal, professional and ethical obligations;
- respond to lawful requests from courts and public authorities.
Operation and security of the website and IT systems
When our website is visited, the server and technical services used may automatically record data such as the IP address, date and time of access, pages and resources requested, referring page, browser type and version, operating system, device type, language settings, amount of data transferred, status codes, error messages and other technical connection information.
We process this data to provide the website, ensure its stability and security, diagnose errors and anomalies, prevent and detect unauthorised access, counter cyberattacks, document security incidents, and administer and technically improve the website and IT systems.
Compliance, security and protection of rights
We may also process personal data to comply with legal, professional and ethical requirements, safeguard professional secrecy, prevent unlawful or abusive conduct, manage professional, technical and organisational risks, document operations and communications, assert or defend claims, manage disputes, and protect the rights, interests and security of the Firm, its clients and third parties.
4. Where does the personal data come from?
Data provided directly
Most of the personal data we process is provided directly by the data subject, the client or a person acting on their behalf, for example during a meeting, through correspondence, by telephone or by sending documents.
The device used to access our website also automatically communicates certain technical data.
Data subjects are generally not required to provide personal data. However, without the necessary data, it may be impossible to assess or accept a mandate, provide a requested service, comply with a legal obligation or use certain website functions correctly.
Data received from third parties or public sources
We may also collect or receive personal data from:
- clients and persons connected with them;
- opposing parties and their representatives;
- courts and public authorities;
- lawyers, notaries, advisers, experts, translators and other professionals;
- banks and insurers;
- employers, principals or representatives;
- public registers, including commercial registers, land registers and debt enforcement registers;
- official publications;
- the media;
- publicly accessible Internet sources;
- providers of technical or administrative services;
- other persons involved in the matter.
5. To whom do we disclose personal data?
In connection with the purposes described in this Statement, we may disclose personal data to the categories of recipients set out below. Disclosure takes place subject to professional secrecy and only to the extent necessary and permitted. Where required, we obtain the data subject’s consent or a release from professional secrecy in accordance with applicable law.
Service providers
We may use service providers in Switzerland and abroad, in particular in the fields of:
- information technology and maintenance;
- hosting;
- email and telecommunications;
- cloud services;
- archiving and document management;
- IT security;
- accounting and administration;
- management of cookie preferences and consent.
Such providers may process data on our behalf and under our instructions, jointly with us where applicable, or under their own responsibility for certain processing activities.
Where a provider processes personal data on our behalf, we require, to the extent applicable, appropriate obligations concerning confidentiality, security and data protection.
Clients and other contractual partners
We may disclose data to our clients and other contractual partners where this is necessary to perform the contractual relationship or mandate.
This category also includes correspondent lawyers, other law firms, advisers and legal expenses insurers with whom we cooperate. Such recipients generally process personal data under their own responsibility.
Courts and public authorities
We may disclose personal data to courts, judicial, administrative, tax, debt enforcement, criminal, supervisory or other public authorities in Switzerland and abroad where this is necessary to perform a mandate or where we are legally required or authorised to do so.
Such recipients process personal data under their own responsibility.
Opposing parties and other persons involved
To the extent necessary to perform a mandate or protect legal rights, we may disclose personal data to:
- opposing parties and their representatives;
- witnesses and persons with relevant information;
- guarantors and funders;
- banks and insurers;
- advisers, experts, translators, mediators and arbitrators;
- other persons involved in the matter.
Other recipients
We may disclose data to other recipients where their involvement follows from the purposes described in this Statement, where disclosure is required or permitted by law, or where it is necessary to establish, exercise or defend a legal claim.
The categories of recipients listed above may themselves use service providers or agents, with the result that personal data may also become accessible to them. We can regulate the processing carried out by certain recipients, particularly providers acting on our behalf, but not the independent processing carried out by courts, public authorities, banks, insurers, opposing parties or independent professionals.
Information covered by professional secrecy is disclosed only to the extent permitted by applicable legal and professional rules.
6. Is personal data also processed abroad?
Personal data may be processed in Switzerland and abroad.
In matters involving international elements, data may be disclosed in the countries concerned, for example to clients, opposing parties, courts, public authorities, correspondent lawyers, advisers, experts or other persons involved. Depending on the mandate, this may potentially involve any country in the world.
Technical providers and their subprocessors may also process personal data using infrastructure located abroad. The countries concerned depend on the services actually used and on the locations in which the relevant providers or subprocessors operate.
For the management of cookie preferences, we use CookieYes Limited, which is based in the United Kingdom and may use subprocessors located in other countries.
If a recipient is located in a country that does not provide a level of data protection recognised as adequate, we take measures, where necessary, to ensure an appropriate level of protection, in particular through:
- recognised standard contractual clauses;
- amendments required by Swiss law;
- other appropriate contractual, technical or organisational safeguards;
- recognised transfer mechanisms.
We may also disclose personal data to a country without an adequate level of protection where an exception under applicable law is available, in particular where the disclosure:
- is necessary for the performance of a contract;
- is necessary in connection with judicial, administrative or arbitration proceedings abroad;
- is necessary to establish, exercise or defend a legal claim;
- serves an overriding public interest;
- is based on the data subject’s consent;
- is necessary to protect the life or physical integrity of a person;
- concerns data made generally accessible by the data subject without objection to its processing;
- concerns data from a register provided for by law to which we have lawfully obtained access.
Further information about principal recipients, countries concerned and safeguards used may be requested from the Firm. Disclosure of such information may be limited where required by professional secrecy, security, the rights of third parties or other overriding interests.
7. What rights do data subjects have?
In accordance with applicable law, a data subject may in particular request:
- information about the processing of their personal data;
- access to their personal data;
- correction of inaccurate or incomplete data;
- deletion or destruction of data;
- cessation or restriction of certain processing activities;
- the right to object to processing;
- delivery of certain data in a commonly used electronic format;
- transmission of data to another controller where the applicable requirements are met;
- withdrawal, with effect for the future, of consent previously given.
To exercise these rights, please contact the Firm using the details set out in section 2.
To prevent abuse, we may request information or documents reasonably necessary to verify the identity of the person making the request. There is no need to send a copy of an identity document unless we ask for one.
These rights are not absolute. Their exercise may be subject to conditions, exceptions or restrictions, in particular where this is necessary to:
- comply with professional secrecy;
- meet a legal retention obligation;
- protect the rights and interests of third parties;
- protect confidential information;
- preserve the integrity of proceedings;
- establish, exercise or defend a legal claim;
- protect other overriding public or private interests.
For reasons of confidentiality or the protection of third parties, we may redact certain information or provide only extracts from documents.
A data subject may also contact the Federal Data Protection and Information Commissioner (FDPIC) or the competent courts in accordance with applicable law.
8. How do we use cookies and similar technologies?
Technical data and cookies
Use of our website generates data that may be stored in server and technical-service logs. We may also use cookies and similar technologies. A cookie is a small file or piece of information stored on a device or in a browser and may enable the website to operate, remember preferences and, where configured, provide additional functions.
Depending on the circumstances, technical data and information contained in cookies may be linked with other data and become attributable to an individual.
Managing preferences through CookieYes
To manage cookie preferences, we use CookieYes, a service provided by CookieYes Limited in the United Kingdom. CookieYes is used to:
- display the cookie banner;
- classify cookies detected on the website;
- allow acceptance or rejection of non-essential cookies;
- record the preferences selected;
- manage activation of cookie categories;
- document the choices made;
- allow users subsequently to change or withdraw their preferences.
For these purposes, CookieYes may process a consent identifier, the relevant domain, the date and time of the choice, overall consent status, the preferences selected for each category, country or region where available, evidence of the choice made and a masked IP address.
CookieYes may use technically necessary cookies, including the "cookieyes-consent" cookie, to store and link the choices made. CookieYes processes such data on our behalf to the extent necessary to provide the service and may use subprocessors. Information on processing abroad is set out in section 6.
Cookie Policy
The categories and individual cookies actually present on the website, including their purpose, provider and duration, are described in the separate Cookie Policy and in the preference centre. Analytics tools, external content and third-party services are listed only if they are actually installed or detected on the website.
Non-essential cookies and services are activated in accordance with the preferences selected through the banner.
Internal statistics without cookies
To understand in aggregate form how our website is used, we operate a statistics tool hosted on our own server. This tool works without cookies and without storing visitors’ IP addresses.
To estimate the number of distinct visitors during a given day, an anonymous, irreversible fingerprint is generated from technical connection data and renewed every day; it does not allow the individual to be identified or recognised from one day to the next. The data collected is purely technical and aggregated and relates in particular to the page visited, the source of the traffic and the type of device.
Because this tool uses no cookies and stores no identifying data, the related processing does not require consent and is based on our legitimate interest in ensuring the operation, security and improvement of the website. The information obtained is not used to identify individual visitors.
Changing or withdrawing preferences
Preferences may be changed or withdrawn at any time through the “Cookie Settings” control available on the website. Changes take effect for the future and do not affect processing carried out before the change.
Cookies may also be blocked or deleted through browser settings. Blocking technically necessary cookies may, however, impair the proper operation of parts of the website.
External links and services
The website may contain links to pages or services operated by third parties. A simple link does not necessarily transmit data to the external website operator before the link is selected. Once an external page is accessed, the terms and data-protection statements of the relevant operator apply.
9. What else should be considered?
Data security
We take technical and organisational measures appropriate to the nature of the data, the purposes of processing and the risks involved, with the aim of protecting personal data against unauthorised access, loss, destruction, unavailability, improper alteration, unauthorised disclosure, misuse and other unlawful processing.
Such measures may include access controls, authorisation management, protection of devices and systems, technical updates, backups, organisational procedures, confidentiality obligations and physical protection of documents.
Internet and email communications may involve security risks. Before a mandate has been accepted and any conflicts of interest have been checked, particularly confidential documents or information should not be sent unless an appropriate channel has been agreed with the Firm.
Data obtained in the course of our professional activities is also processed subject to professional secrecy.
Possible application of the GDPR
We consider that the European Union General Data Protection Regulation (“GDPR”) does not apply to the data processing carried out by us. However, if the GDPR were exceptionally to apply to particular processing activities, the following provisions would apply in addition, solely for the purposes of the GDPR and to the processing subject to it.
In that event, we would base the processing of personal data in particular on the fact that:
- processing is necessary for taking steps to enter into, conclude, perform, administer or enforce a contract, or for taking pre-contractual steps at the request of the data subject (Article 6(1)(b) GDPR);
- processing is necessary for the purposes of legitimate interests pursued by us or by a third party, in particular communications, preparation and management of mandates, administration of the Firm, operation and security of the website and IT systems, compliance with applicable requirements, risk management, documentation, protection of legal rights and other legitimate interests (Article 6(1)(f) GDPR);
- processing is necessary or required in order to perform our mandate or function under the law of the European Union, the European Economic Area or a Member State (Article 6(1)(c) GDPR), or is necessary to protect the vital interests of the data subject or another individual (Article 6(1)(d) GDPR);
- the data subject has separately consented to the processing, for example by making a specific declaration on the website (Article 6(1)(a) and, where applicable, Article 9(2)(a) GDPR).
We process personal data for as long as required by the purposes described in this Statement, by statutory retention periods and by our legitimate interests, in particular for documentation and evidential purposes, and where storage is technically necessary, for example in backups or document-management systems.
Where no legal or contractual obligation or technical reason justifies further retention, we delete, destroy or anonymise the data upon expiry of the relevant retention or processing period as part of our ordinary procedures.
Failure to provide certain personal data may make it impossible to provide the requested service, assess or accept a mandate, or enter into or perform a contract. Where possible, we indicate what personal data are required in the particular case.
If you disagree with the way in which we handle your rights or data protection, please let us know using the contact details in section 2. If you are located in the European Economic Area and the GDPR applies to the processing concerned, you also have the right to lodge a complaint with the competent supervisory authority in your country.
10. May this Statement be amended?
This Data Protection Statement does not form part of a contract and does not establish an attorney-client relationship.
We may amend it where necessary to reflect legislative, organisational, contractual or technical changes.
The version published on our website shall apply. The date of the latest update is stated at the beginning of the Statement.