# External Data Protection Officer Switzerland, Model, Costs, Use Cases

> External data protection officer in Switzerland: legal framework in CH and the EU, when the model fits, scope of services, costs and conflicts of interest.

- Source: https://www.sidd.swiss/en/insights/external-dpo-switzerland/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

The external data protection officer model, in Swiss terms *Datenschutzberater* under Art. 10 DSG, in EU terms *DPO* under Art. 37 et seq. GDPR, is the standard vehicle in Switzerland for companies without an in-house data protection function. It combines expertise, independence and cost control in a predictable monthly arrangement. This article provides the essentials for choosing such a mandate:

- the legal basis in Switzerland (Art. 10 DSG, voluntary) and in the EU (Art. 37 GDPR, partly mandatory);
- typical use cases where the external model fits better than building in-house;
- the components of a good mandate (SLA, scope, escalation paths, interfaces);
- market price ranges for Swiss SMEs (based on our mandate practice);
- independence requirements, conflicts of interest, professional secrecy;
- risk reporting to the FDPIC, supervisory board and cyber insurer.

The audience is executive boards, CFOs and supervisory boards of SMEs with 10 to 500 employees facing their first or second DSG audit, as well as groups with distributed Swiss entities seeking a unified data protection stack across multiple subsidiaries. For the complementary article on the role of the data protection officer, see [Swiss Data Protection Advisor, Duty, Role, Skill Profile](https://www.sidd.swiss/einblicke/datenschutzberater-schweiz-rolle).

## Legal framework Switzerland vs. EU

The names differ, the substance largely does not. Three points stand out.

**Switzerland, voluntary, but recommended:** Art. 10 DSG provides for the appointment of a data protection advisor by private actors; it is *not* mandatory. However, if the company does appoint an advisor, it may dispense with consulting the FDPIC under Art. 23 DSG in a Data Protection Impact Assessment, provided the advisor was involved and the residual risk is not high. This procedural benefit is substantial, it saves two months of waiting per DPIA.

**EU, partly mandatory:** Art. 37 GDPR requires a DPO for public authorities, for actors carrying out regular and systematic large-scale monitoring of data subjects, and for large-scale processing of special categories. Member State law may add obligations (Germany: from 20 persons engaged in automated processing).

**Notification to the FDPIC:** The advisor must be notified to the FDPIC (Art. 10(3) DSG, with contact details). This step is straightforward in the external arrangement, the external advisor is filed with role and contact, while the engaging company remains the controller.

In practice the contractual setup of external mandates in Switzerland and the EU is very similar: both require a clearly defined scope, an independence covenant and escalation paths. Where a company operates under both regimes (typical for e-commerce, SaaS, industry with DACH distribution), a well-built mandate combines [Swiss data protection advisory](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) and EU DPO in a single contract and unlocks synergies (see also [EU Data Protection Officer](https://www.sidd.swiss/en/services/data-protection-officer-eu)).

## When the external model fits better

The choice external vs. in-house depends mostly on size, sector and maturity. From our mandate practice the external model is superior in the following situations:

- **SMEs up to ~250 employees:** An in-house DPO is usually under-utilised (rule of thumb: 0.3–0.5 FTE), the employment does not pay off. An external advisor delivers in 1–2 days per month the depth that would otherwise require building in-house.
- **High complexity, low frequency:** Law firms, trust companies, asset managers, small to mid-size hospitals, insurance brokers, high data sensitivity but data protection questions are not daily. On-demand expertise fits better.
- **Groups with decentralised subsidiaries:** A unified external solution across multiple Swiss sites or group entities is cheaper and more consistent than parallel in-house roles.
- **Acute after a breach or FDPIC proceedings:** When compliance must be built quickly, the external model wins because the advisor starts on day one, not after three months of recruitment.
- **International setup with a DACH focus:** Where DSG, GDPR and possibly UK GDPR run in parallel, a combined external advisor with dual qualification is often the only realistic option.

Conversely, the in-house DPO is preferred for: high data intensity (>500 employees), daily data protection topics, regulated industries with their own compliance function (mid-size banks and insurers). We also frequently see a hybrid model, where an in-house DPO carries operations and the external advisor complements as sparring partner, DPIA specialist or EU bridging function.

## Scope and SLA components

A robust external mandate is not advice-on-call. It defines measurable deliverables, response times and escalation paths. Standard components:

1. **Onboarding phase (typically 6–12 weeks):** Inventory, processing register under Art. 12 DSG, gap analysis, priority of actions. Outcome: an action plan with deadlines.
2. **Ongoing advisory:** Monthly steering meeting with executive management or the data protection committee. Response time on ad-hoc queries (e.g. 48h by email, 4h in declared emergencies).
3. **Access and complaint handling:** Inbound channel with defined SLA (e.g. acknowledgement within 5 business days, processing within 30 days per Art. 25 DSG).
4. **Breach support:** 24/7 reachability for initial analysis, preparation of FDPIC notification, support for communications with data subjects.
5. **Training:** At least one board and one staff training per year, often through our [privacy workshops for SMEs](https://www.sidd.swiss/en/services/data-protection-workshop-sme).
6. **Contract reviews:** Support in concluding new DPAs, cross-border transfer assessments, EU SCC application.
7. **Reporting:** Quarterly report to the board with status, open items, risk picture, planned measures.
8. **Audit support:** Support in external audits (customer audits, ISO 27701, FDPIC proceedings).

Skipping the SLA layer is a frequent error in first mandates. Without response times and defined outputs, expectation gaps emerge that surface in the first breach incident at the latest.

## Price ranges and contract design

Market prices for an external DPO mandate in Switzerland fall into the following bands, always depending on complexity, data intensity and maturity:

- **Micro-SMEs (10–30 employees), low data risk:** CHF 800–1,500 per month as retainer, with ~4–8h of included advisory. Typical for architects, trust boutiques, small consultancies.
- **Mid-sized SMEs (30–150 employees):** CHF 1,500–4,000 per month, with 8–20h of included advisory, monthly steering meeting, one training every six months. Typical for e-commerce, law firms, mid-size hospitals.
- **Larger SMEs and group subsidiaries (150–500 employees):** CHF 4,000–10,000 per month, depending on sites, DPIAs per year, regulated industry. EU DPO function often included.
- **Groups and highly regulated entities:** Bespoke pricing, often combined with ISMS/CISO mandates and partial sourcing into our platform.

Contractually we recommend a 12-month term with automatic 12-month renewal and a 3-month mutual notice period. Shorter terms are possible but make onboarding effort hard to amortise. Key clauses: liability (capped to the fees paid over 12 months, with defined carve-outs for intent and gross negligence), confidentiality, conflict-of-interest declaration, data protection clause between advisor and client (typically qualifying as data processing).

## Independence and conflicts of interest

Art. 10 DSG requires the data protection advisor to act *independently and without instructions*. In the external setting independence is structurally given, the advisor is not an employee and not subject to internal instructions. Four risks must be addressed:

1. **Sale of other services to the same client:** If the advisory firm also sells marketing or sales services, a conflict arises since these areas are subject to DPO oversight. Resolution: organisational separation or no sale of conflict-creating services.
2. **DPO + processor combination:** If the advisor operates a SaaS platform that the client uses, the platform must be reviewed structurally by the DPO, not controlled by themselves. Solution: third-party reviews, transparent disclosure, no bundling where doubtful.
3. **Mandate continuation at any cost:** If the DPO raises substantive criticism, the mandate must not be saved by uneasy concessions. Contract clauses that hinder one-sided termination after critical reports (long notice periods, high penalties) point the wrong way.
4. **Dual mandates within groups:** Where the same advisor serves parent and subsidiary, conflict-escalation paths must be clearly defined, including substitution.

In its recent activity reports the FDPIC has repeatedly emphasised that it tests independence not just formally but materially. We recommend renewing the independence declaration annually and confirming it explicitly in the DPO report to the supervisory board.

## Pitfalls in running the mandate

From our practice we see recurring pitfalls that undermine or even nullify a good mandate.

- **No escalation path to the board:** If the DPO only talks to middle management, critical information does not reach decision-makers. A contractually agreed direct line to the CEO or supervisory board is mandatory.
- **Onboarding stalls:** The processing register is still not complete after three months because internal stakeholders do not deliver. Solution: smaller sprint goals, clear owners, external pressure on deadlines.
- **DPO learns of an incident from the news:** The internal escalation chain is not trained. Solution: tabletop exercise in the first mandate year.
- **Mixing with counsel role:** The DPO is not an attorney; where defence vis-à-vis authorities is needed, legal representation must be cleanly demarcated.
- **Reactivity without proactivity:** If the advisor only answers questions, the strategic dimension is missing. Quarterly risk picture and action plan are expected.
- **Contract term too short for impact:** Compliance build takes 12–18 months. Mandates under 12 months generate friction and little value.

Avoiding these points captures the maximum from the external model. A well-run mandate is not just compliance insurance but an operational lever: faster DPIAs, cleaner DPAs, clearer privacy notices and, in a crisis, a battle-tested team.

## How SIDD supports you

SIDD runs external DPO mandates for SMEs, group subsidiaries and regulated actors across German-speaking Switzerland and the Romandie. Our mandates combine Swiss data protection expertise with the EU DPO function in a single contract, define clear SLAs and deliver measurable outputs, not advice on call. Standard package: onboarding in 12 weeks, monthly steering meeting, quarterly report, 24/7 reachability for incidents.

See our service descriptions [Swiss data protection advisor](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) and [EU Data Protection Officer](https://www.sidd.swiss/en/services/data-protection-officer-eu). On request we extend to [Art. 27 EU representative](https://www.sidd.swiss/en/services/eu-representative), [ISMS / ISO 27001 build](https://www.sidd.swiss/en/services/iso-27001-isms) and [external CISO/ISB function](https://www.sidd.swiss/en/services/vciso), integrated into the same mandate.

Write to us via the [contact form](https://www.sidd.swiss/en/contact) or request a [quote](https://www.sidd.swiss/en/quote) with concrete price bands and onboarding timeline. We respond within one business day with a proposal tailored to your size, sector and starting point.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
