# Data Security in Switzerland: Best Practices under the DSG and ISO/IEC 27001

> Best practices for data security in Switzerland: TOMs under Art. 8 DSG, mapping to ISO/IEC 27001:2022 Annex A, FDPIC notification duty, audit readiness.

- Source: https://www.sidd.swiss/en/insights/data-security-in-switzerland-a-guide-to-current-best-practices/
- Language: en
- Published: 2026-03-21
- Last updated: 2026-05-24
- Author: Philipp Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Data Security under Art. 8 DSG: The Risk Yardstick

Data security in Swiss law is anchored primarily in Art. 8 DSG and obliges controllers and processors alike to implement technical and organizational measures (TOMs) that ensure a level of protection commensurate with the risk. The Swiss Data Protection Ordinance (DSV) concretises the requirements in Articles 1 to 6 DSV around the protection objectives of confidentiality, integrity, availability and traceability. Decisive criteria are the state of the art, the cost of implementation and the nature, scope and purpose of the processing. This guide maps those duties onto the controls of ISO/IEC 27001:2022 and thereby complements the [DSG pillar guide (German-language pillar)](https://www.sidd.swiss/einblicke/dsg-fadp-leitfaden/) with the operational perspective.

The term TOM covers far more than purely technical security measures: it encompasses policies, roles, training programmes and contractual arrangements. Unlike the GDPR, Art. 8 DSG does not prescribe an exhaustive level of detail but demands appropriateness that must be justified in the specific processing context. The documented risk assessment therefore gains central importance. Those who can present a plausible, periodically updated risk analysis discharge the burden of proof in supervisory proceedings considerably more easily than a company with isolated single measures lacking documented justification.

## Protection-Needs Analysis and Risk Inventory

A protection-needs analysis is the first practical step to implementing Art. 8 DSG and identifies, per processing activity, the protection objectives and the likelihood of occurrence. The risk inventory builds on this and supports the Data Protection Impact Assessment (DPIA) under Art. 22 DSG. Methodologically, this approach aligns with Clause 6.1 of ISO/IEC 27001:2022 (Actions to address risks and opportunities). A uniform risk grid that brings together compliance, information security and business risk is advisable. The result is a traceable selection of Annex A controls and of the specific TOMs that reduce the risk.

A three-tier protection-needs category (normal, high, very high) for the protection objectives confidentiality, integrity and availability has proven effective. The category results from the magnitude of damage that would occur on a breach of the protection objective and the likelihood of occurrence. For processing with a high protection need, a full Data Protection Impact Assessment under Art. 22 DSG is mandatory; the methodology can follow the FDPIC guideline or the EDPB Guidelines 4/2019. The risk inventory must be updated at least annually and on material change.

## Mapping Art. 8 DSG onto ISO/IEC 27001:2022 Annex A

Mapping the DSG requirements onto the 93 Annex A controls makes TOMs auditable. Confidentiality corresponds to A.5.10 (Acceptable use), A.5.15 to A.5.18 (Access control), A.8.3 (Information access) and A.8.5 (Secure authentication). Integrity is covered by A.8.28 (Secure coding) and A.8.32 (Change management). Availability requires A.5.30 (ICT readiness), A.8.13 (Backups) and A.8.14 (Redundancy). Traceability is secured by A.8.15 (Logging) and A.8.16 (Monitoring). Processor engagements are addressed via A.5.19 to A.5.23 (Supplier relationships, cloud services). The duties to notify data protection breaches are finally operationalised through A.5.24 to A.5.28.

Also relevant are A.5.7 (Threat intelligence) for threat analysis, A.8.7 (Protection against malware), A.8.8 (Management of technical vulnerabilities) and A.8.16 (Monitoring activities) for SIEM-based detection. Data classification is mapped through A.5.12 (Classification of information) and A.5.13 (Labelling of information). These mappings are not rigid and allow for different emphases depending on the business model. A neatly documented mapping table serves both internal steering and external auditing and materially shortens the preparation for the certification audit.

## Access Control and Identity Management

Access control is the most resource-intensive TOM component and at the same time the one with the greatest risk-reduction potential. Recommended are a documented authorisation concept on the need-to-know principle, multi-factor authentication for privileged and external access and regular access reviews. The relevant controls are A.5.15 to A.5.18, A.8.2 (Privileged access rights) and A.8.5. For cloud services, conditional access, geo-based access rules and session timeouts are standard. From a DSG perspective, the duty derives from Art. 1 DSV (access control, input control, disclosure control).

For authentication we recommend the transition to phishing-resistant procedures (FIDO2, WebAuthn) for privileged and administrative accounts. Passkeys will progressively replace classic passwords and significantly reduce the risk of credential-stuffing attacks. Identity life cycles must cleanly map the onboarding, change and offboarding process; orphaned accounts are one of the most frequent causes of data breaches. A central identity-governance solution with just-in-time entitlements for privileged access narrows the attack window and supplies the evidence required for Clause 9.2 of ISO/IEC 27001:2022.

## Encryption, Pseudonymisation and Data Minimisation

Encryption protects data in transit and at rest and is today state of the art. Recommended are TLS 1.3 for transport connections, AES-256 for stored data and a dedicated key management in line with A.8.24. Pseudonymisation reduces risk in analytics and test environments; anonymisation is only achieved where re-identification is excluded with reasonable effort (see Recital 26 GDPR as interpretive guidance). Data minimisation under Art. 6(3) DSG (purpose limitation) is the most effective TOM of all: data not collected need not be protected. This logic is reflected in A.8.10 (Information deletion) and A.8.11 (Data masking).

A documented deletion concept with clear retention periods for each data category is the operational implementation of data minimisation. Recommended are automated deletion routines in the source systems and secure destruction of data carriers under A.7.14 and A.8.10. Backup strategies must reflect the deletion duty; a pure backup-forever logic conflicts with Art. 6(4) DSG. For test and development environments, the use of synthetic data or pseudonymised production data is mandatory; a frequent audit finding is the use of unprotected production data in test systems.

## Notification of Data Breaches under Art. 24 DSG

A breach of data security must be notified to the FDPIC as quickly as possible under Art. 24 DSG where it is likely to lead to a high risk to the personality or fundamental rights of the data subject. The GDPR sets a hard 72-hour deadline in Art. 33; the FDPIC has signalled a comparable tempo in its explanatory materials. Operationally this requires a practised incident-response process, a 24/7 reachability concept, forensic capability and templates for notifications via the FDPIC portal. The relevant controls are A.5.24 (Planning), A.5.25 (Assessment), A.5.26 (Response), A.5.27 (Learning from incidents) and A.5.28 (Collection of evidence).

Notification to the FDPIC is submitted via the DataBreach portal and requires structured information on the nature and scope of the incident, the categories of data affected, the likely consequences and the measures taken or planned. Where the information cannot be gathered in full within the deadline, an initial notification with subsequent supplementation is permissible. In parallel, the information of data subjects under Art. 24(4) DSG must be considered; it is required in particular where this is necessary to protect against consequential harm or where the FDPIC demands it. Pre-prepared communication templates accelerate the legally sound response.

## Supplier Management and Cloud Outsourcing

Outsourcing to cloud providers or other service providers is processor engagement under Art. 9 DSG and requires a written contract with a clear description of subject matter, duration, purpose and nature of the processing. Annex A controls A.5.19 to A.5.23 require a complete supplier inventory, contractually anchored security requirements, regular monitoring and a documented approach to cloud services. For cross-border transfers, Art. 16 DSG additionally applies; SCCs are configured in the Swiss variant via the FDPIC annex. A deeper discussion of the parallel GDPR duties is found in the [GDPR pillar guide](https://www.sidd.swiss/en/insights/gdpr-guide-2026/).

Supplier risks are increasingly evaluated through structured assessments (Vendor Risk Management). The control covers pre-contract due diligence (security questionnaires, certification evidence such as SOC 2 Type II or ISO/IEC 27001), contractual anchoring of security requirements and continuous monitoring through audit reports or penetration-test results. For sub-processing, the cascade must be reflected contractually so that the security requirements apply along the entire supply chain. Cloud-specific, A.5.23, the provider's shared-responsibility matrix and the clean separation between IaaS, PaaS and SaaS responsibilities are central.

## Audit Readiness and Certification

Audit readiness is the measure of whether the TOMs are not only documented but also effective. An annual internal audit cycle under Clause 9.2 of ISO/IEC 27001:2022 is recommended, complemented by a management review under Clause 9.3 and continual improvement under Clause 10. An external certification under ISO/IEC 27001:2022 provides the robust proof of appropriate TOMs and accelerates supplier reviews. SIDD works with CIS Cert (Quality Austria Group, ISO/IEC 17021-accredited) and supports mandates as [Swiss DSG Data Protection Advisor](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland), as [External DPO under GDPR Art. 37](https://www.sidd.swiss/en/services/data-protection-officer-eu) and in the build-up of an [ISMS under ISO/IEC 27001](https://www.sidd.swiss/en/services/iso-27001-isms). The legal framework is provided by the [DSG pillar guide (German-language pillar)](https://www.sidd.swiss/einblicke/dsg-fadp-leitfaden/).

Certification typically runs in two stages: the Stage 1 audit reviews the documentation and audit readiness, the Stage 2 audit reviews operational effectiveness through samples and interviews. Building up an ISMS takes between six and twelve months depending on maturity; the annual surveillance audits and the re-certification after three years maintain currency. An integrated certification under ISO/IEC 27001 plus ISO/IEC 27701 covers information security and data protection in one process. This significantly reduces the overall audit effort; at the same time the market value of the certificate rises vis-a-vis EU clients who request a DPO mandate.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
