# Data Protection Officer in the Canton of Zurich

> External data protection officer in the canton of Zurich: FADP and IDG ZH, industries with demand, tasks in a mandate, interfaces and engagement models.

- Source: https://www.sidd.swiss/en/insights/data-protection-officer-canton-zurich/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

With over 1.5 million inhabitants and around 100,000 companies, the Canton of Zurich is Switzerland's economic centre. UBS, ZKB, Swiss Re, Zurich Insurance and a dense SME landscape make it home to the country's largest data processors. In parallel, the canton runs an equally data-intensive public sector with the University Hospital, the University, ETH and more than 160 municipalities. Private companies are subject to the revised Federal Act on Data Protection (DSG); public bodies of the canton and Zurich municipalities are subject to the cantonal Information and Data Protection Act (IDG ZH).

This article explains what an external data-protection adviser or officer in the Canton of Zurich actually does, when their appointment is advisable or legally required, and how the private-law concept of "data-protection adviser under Art. 10 DSG" differs from the public-law "data-protection officer under section 33 IDG ZH". Topics:

- conceptual clarification: "adviser" under DSG vs. "officer" under IDG ZH;
- which ZH sectors typically use DPO-as-a-service;
- practice of the cantonal data-protection commissioner;
- core tasks of a Zurich-based mandate;
- interfaces to the Federal Financial Market Supervisory Authority (FINMA), the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) and the EU GDPR.

## DSB under DSG vs. IDG ZH

The DSG does not recognise a mandatory "data-protection officer" but a voluntary "data-protection adviser" (Art. 10 DSG). Anyone who appoints such an adviser and notifies the FDPIC benefits in particular from a relief under Art. 22(5) DSG: the otherwise required consultation of the FDPIC for a data-protection impact assessment falls away if the independent adviser reviews and signs off the DPIA. For many Zurich companies this is the economic driver to engage an external adviser.

The IDG ZH (LS 170.4) by contrast requires that public bodies of the canton and the municipalities designate a data-protection officer (sections 5 et seq. IDG ZH). At cantonal level the function is held by the "Datenschutzbeauftragte des Kantons Zürich" (an independent authority based in central Zurich) that also acts as the supervisory body. Municipalities, schools, hospitals and pension funds must either appoint their own officer or join cantonal or regional pooled mandates.

Private companies acting as processors for public bodies (e.g. an IT provider for a Zurich municipality) remain subject to the DSG but are contractually bound to the IDG obligations of the controller and should pay attention to this during contract negotiations.

## Zurich sectors with high DPO demand

From our mandate practice in the Canton of Zurich a few sectors clearly stand out in their demand for DPO-as-a-service:

1. Financial service providers and family offices: parallel requirements from FINMA Circulars 2008/21, 2018/3 (outsourcing), 2023/1 (operational risks) and Swiss banking secrecy under Art. 47 BankG apply. An external adviser brings the necessary independence from management and the compliance line.
2. Insurance and brokerage: credit enquiries, claims files, telematics in motor insurance, health tracking. Interfaces to ZIK/ZEK and the supervisory framework of the Insurance Supervision Act (VAG).
3. Healthtech and hospitals: clinic groups such as Hirslanden, Stadtspital, University Hospital and many private practices with the electronic patient record (EPDG). High sensitivity: patient data is sensitive within the meaning of Art. 5 lit. c DSG.
4. SaaS and platform providers: many Zurich-based scale-ups with EU customers combine [DSG advice](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) with a [GDPR DPO](https://www.sidd.swiss/en/services/data-protection-officer-eu) mandate.
5. Law firms and trust offices: secrecy-relevant data in cloud solutions, cross-border discovery, client correspondence. See in depth [Data Protection for Law Firms](https://www.sidd.swiss/einblicke/datenschutz-anwaltskanzlei).
6. Retail and online shops (see [Data Protection in Swiss Online Shops](https://www.sidd.swiss/einblicke/datenschutz-onlineshop-schweiz)): loyalty programmes, CRM profiles, EU shipping.

In all of these contexts, the ability to reach the adviser on short notice, an understanding of local circumstances and the capacity to represent the client before the FDPIC and, for public-sector mandates, the cantonal data-protection commissioner is a decisive advantage of a Zurich-rooted adviser.

## Tasks in a typical ZH mandate

An externally staffed DPO mandate in a Zurich SME or mid-sized enterprise typically includes:

- building and maintaining the record of processing activities under Art. 12 DSG;
- producing and annually reviewing the privacy notice (website, app, contracts);
- advising on new IT projects (privacy by design, Art. 7 DSG);
- conducting and signing off data-protection impact assessments under Art. 22 DSG;
- training management, HR, marketing and engineering;
- handling access requests (Art. 25 DSG) and complaints;
- managing data breaches and notification to the FDPIC (Art. 24 DSG);
- negotiating data-processing agreements and SCCs for third-country transfers;
- preparing an annual report to management;
- representing the client before the FDPIC in investigations or supervisory proceedings.

Experience puts the effort somewhere between 4 and 30 hours per month, depending on sector, headcount and cloud complexity. The function is independent under Art. 10 DSG with a direct reporting line to top management, and must not include operational processing tasks that would conflict with the advisory role.

## Practice of the cantonal commissioner

The Data Protection Commissioner of the Canton of Zurich is one of the most active cantonal data-protection supervisors in Switzerland. She publishes annual activity reports with concrete case examples (schools, police, social welfare, healthcare) and regularly carries out audits in cantonal and municipal bodies. For Zurich-based private companies the practice is indirectly relevant: anyone acting as a processor for a public body is drawn in through the cascaded IDG obligations in the contract.

The ZH commissioner's line on cloud services from US hyperscalers (Microsoft 365, AWS, Google Workspace) is noteworthy: a mere adequacy status or a DPF self-certification is not enough; instead, the supervisor requires a concrete transfer risk analysis and, for sensitive data, additional technical measures such as encryption, pseudonymisation or customer-managed keys. This line largely tracks the FDPIC's post-Schrems II practice and provides private companies with a valuable yardstick.

Anyone bidding for or accepting contracts from ZH administration must also expect detailed data-protection schedules that tend to reference GDPR-level requirements. Contract negotiations are worthwhile; the cantonal commissioner accepts documented risk assessments.

## Interfaces to FINMA, FDPIC and GDPR

In the Zurich financial centre three supervisory regimes interlock: data protection (FDPIC), financial supervision (FINMA), and, where EU customers are served, the GDPR. An external data-protection adviser in the Canton of Zurich who brings only the DSG perspective is too narrowly positioned. In our practice, a DPO routinely coordinates with the compliance officer (AML, market integrity), the CISO (information security, FINMA Circular 2023/1) and the foreign DPOs of affiliated EU subsidiaries.

Concretely this means: outsourcing notifications under FINMA Circular 2018/3 must be prepared in data-protection terms; cloud migrations require both a DPIA and a FINMA-compliant risk analysis; and incident-response plans must cover the parallel notification duties to the FDPIC (Art. 24 DSG, 72 hours), FINMA (Circular 2023/1, 24 hours for serious cyber incidents) and the Federal Office for Cyber Security (BACS / NCSC) (Cybersecurity Act, 24 hours for critical infrastructure).

For Zurich companies with GDPR exposure (EU subsidiary, EU sales, EU customers) we recommend combining an DSG adviser with a [GDPR DPO](https://www.sidd.swiss/en/services/data-protection-officer-eu) and, where there is no EU establishment, an [EU representative](https://www.sidd.swiss/en/services/eu-representative) under Art. 27 GDPR. SIDD provides all three building blocks from a single source.

## Pricing models and mandate setups

External DPO mandates in the Canton of Zurich are typically billed under one of three models: (1) hourly with a minimum draw-down (for low frequency, e.g. very small SMEs); (2) monthly flat fee with a defined hours quota (e.g. CHF 1,200-3,500 per month for 8-20 hours); (3) project-based mandates (build-out, audit, M&A due diligence) on a fixed-price basis. For holding structures with multiple subsidiaries, a group-wide engagement with local contacts per entity makes sense.

The written mandate agreement is critical: it must cover independence, confidentiality, liability, resources (system access, information), reporting line to top management and the notification to the FDPIC under Art. 10(4) DSG. Since 2024 the FDPIC operates an electronic notification platform; a correct notification is what actually unlocks the DPIA relief under Art. 22(5) DSG.

In Zurich large law firms, specialised boutiques and pure consulting houses compete in this space. Selection criteria should be: documented sector experience (banking, health, tech), availability at the client's actual location, language combination (DE/EN), mandate volume as a proxy for experience depth (we recommend at least 30 active mandates as a baseline), and the ability to add adjacent services (ISMS, pentest, workshop) from the same provider.

## How SIDD supports you

SIDD is a Zurich-anchored data-protection and information-security consultancy with its own legal-technical team. For years we have held external DPO functions for banks, insurers, healthtechs, law firms, online retailers and cantonal processors in the Canton of Zurich. Our advisers are at home in both worlds, DSG and GDPR, and know the expectations of the Data Protection Commissioner of the Canton of Zurich from numerous mandates.

Concretely we offer you an external [Swiss data-protection adviser](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) under Art. 10 DSG, complemented by an [EU data protection officer](https://www.sidd.swiss/en/services/data-protection-officer-eu) for GDPR mandates, a [data-protection workshop](https://www.sidd.swiss/en/services/data-protection-workshop-sme) for your teams, and an [external CISO/ISB](https://www.sidd.swiss/en/services/vciso) for the parallel security requirements. Write to us via the [contact form](https://www.sidd.swiss/en/contact) or request a tailored [quote](https://www.sidd.swiss/en/quote) for your Zurich-based company.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
