Swiss Federal Act on Data Protection (DSG / FADP), 2026 Guide

21 min readLast updated 5 Aug 2026By Dr. Dominic Staiger

What is the Swiss Federal Act on Data Protection (DSG / FADP)?

The Swiss Federal Act on Data Protection (Swiss DSG, English Federal Act on Data Protection / FADP) is the national federal statute that governs the processing of personal data by private persons and federal bodies in Switzerland. It was adopted by the Federal Council on 25 September 2020 and entered into force on 1 September 2023. Since that date, the correct short name is simply "DSG".

The DSG replaced the act of 1992 and aligns Swiss data protection substantively, to a large extent, with the European General Data Protection Regulation (GDPR). Its purpose under Art. 1 DSG is to protect the personality and the fundamental rights of natural persons whose personal data are processed. In contrast to the GDPR, the DSG covers exclusively the data of natural persons, not that of legal entities.

Across 74 articles, it governs, among other matters: the principles of data processing (Art. 6 DSG), data security (Art. 8 DSG), the Records of Processing Activities (Art. 12 DSG), the duty to inform (Art. 19 DSG), the Data Protection Impact Assessment (Art. 22 DSG), the duty to notify data security breaches (Art. 24 DSG), as well as the rights of access, rectification and erasure of data subjects (Art. 25 et seq. DSG). The supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC), seated in Bern. The provisions are supplemented by the Data Protection Ordinance (DSV) and the Ordinance on Data Protection Certifications (DSZV).

The DSG is not merely formal compliance law. It is YMYL-relevant for any company that processes customer data, personnel data or supplier data. Infringements may give rise to criminal liability of responsible natural persons, with fines of up to CHF 250,000 (Art. 60 et seq. DSG).

DSG vs GDPR, the key differences

The DSG and the GDPR pursue similar protective goals but differ markedly in scope, sanction architecture and detailed rules. An entity operating in Switzerland that also processes EU customer data is, as a rule, subject to both regimes in parallel.

Territorial scope. The DSG applies under Art. 3 DSG to circumstances that produce effects in Switzerland, even where they were initiated abroad. The GDPR attaches under Art. 3 GDPR where there is an establishment in the EU, or where goods or services are offered to persons in the EU, as well as where behaviour is monitored within the EU. A Swiss online shop that ships to the EU is typically subject to both statutes.

Personal scope. The DSG protects only the data of natural persons (Art. 5 lit. a DSG). The GDPR likewise. Before the revision, the old Swiss DSG also protected legal entities; this no longer applies since 1 September 2023.

Role designations. The DSG refers to the "controller" (Art. 5 lit. j DSG) and the "processor" (Art. 5 lit. k DSG). The GDPR uses "controller" (Art. 4 No. 7 GDPR) and "processor" (Art. 4 No. 8 GDPR). Substantively the roles are largely congruent.

Sensitive personal data. The Swiss catalogue (Art. 5 lit. c DSG) extends beyond the GDPR categories (Art. 9 GDPR) to also include data on administrative and criminal proceedings and sanctions, as well as data on social assistance measures.

Sanctions. The GDPR provides for administrative fines against undertakings of up to EUR 20 million or 4 percent of global annual turnover (Art. 83 GDPR). The DSG imposes criminal fines against natural persons of up to CHF 250,000 (Art. 60 DSG). The addressee is therefore fundamentally different: in the EU primarily the undertaking, in Switzerland the responsible person within the undertaking.

Supervisory authority. In Switzerland the FDPIC, in the EU the respective competent national supervisory authority, coordinated through the European Data Protection Board.

Data transfers to third countries. Both statutes work with a list of adequate countries, standard contractual clauses and binding corporate rules. The EU confirmed Switzerland as an adequate third country by decision of 15 January 2024; the Federal Council, for its part, maintains a country list under Art. 8 DSV.

Which companies must comply with the DSG?

The DSG must be complied with by any company whose data processing produces effects in Switzerland, irrespective of the company's seat. The decisive factor is the place of effect, not the seat of the processing entity (Art. 3 para. 1 DSG).

Specifically affected are:

  • Swiss SMEs seated in Switzerland that process personnel data, customer data, supplier data or website data, that is, in practice every company with at least one employee or one customer.
  • Swiss groups with intra-group data flows, in particular with subsidiaries in the EU/EEA or in third countries without an adequate level of protection.
  • Foreign companies that offer goods or services to persons in Switzerland, monitor their behaviour in Switzerland, or otherwise produce effects in Switzerland (marketplace providers, SaaS providers, online retailers).
  • Federal bodies within the scope of the federal administration. Cantonal and municipal authorities are subject to the respective cantonal data protection law.

The DSG contains no general de minimis threshold. Even a sole proprietorship with two employees and an accounting software processes personal data and is subject to the DSG. Relief for SMEs exists only selectively: under Art. 12 para. 5 DSG in conjunction with Art. 24 DSV, companies with fewer than 250 employees are exempt from the Records of Processing Activities, provided their data processing entails only a low risk of a violation of the personality of the data subjects. An entity that processes sensitive personal data on a large scale or carries out high-risk profiling cannot rely on the SME exemption.

SME example: A 40-person trust company in Zug processes health data of its employees (salary statement, daily sickness benefits) and financial data of its clients. It is fully subject to the DSG but may, in some circumstances, dispense with the Records of Processing Activities. Group example: A Swiss industrial group with subsidiaries in Germany and India is subject to the DSG, the GDPR, and, for Indian data flows, the rules on international data transfers under Art. 16 et seq. DSG.

Which obligations arise from the DSG? (overview)

The DSG imposes on controllers and processors a range of substantive obligations that in practice are mostly implemented in parallel with the GDPR. The principal duties at a glance:

  • Processing principles (Art. 6 DSG): lawfulness, good faith, proportionality, purpose limitation, recognisability, accuracy of data, data security. Where processing is carried out without a justification ground (Art. 31 DSG), consent is required.
  • Data security (Art. 8 DSG in conjunction with Art. 1 et seq. DSV): controllers and processors must ensure, through appropriate technical and organisational measures (TOMs), a level of data security appropriate to the risk. The DSV concretises the requirements (confidentiality, integrity, availability, traceability).
  • Privacy by Design / by Default (Art. 7 DSG): data protection must be built into the processing from the planning stage, and default settings must be privacy-friendly.
  • Records of Processing Activities (Art. 12 DSG): documented overview of all processing operations, with an SME exemption.
  • Duty to inform (Art. 19 DSG): transparent information of data subjects upon collection of personal data.
  • Processing on behalf (Art. 9 DSG): a written or electronic agreement with every processor (data processing agreement, DPA).
  • Data Protection Impact Assessment (Art. 22 DSG): where there is a high risk to personality or fundamental rights.
  • Duty to notify data security breaches (Art. 24 DSG): notification to the FDPIC as soon as possible.
  • Data subject rights (Art. 25–32 DSG): access, rectification, erasure, data release and portability, objection to automated individual decisions (Art. 21 DSG).
  • International data transfers (Art. 16–18 DSG): disclosure abroad only where adequate protection is ensured.
  • External or internal Data Protection Adviser (Art. 10 DSG): optional for private controllers, mandatory for federal bodies.

The list is not exhaustive. Sector-specific statutes (FINMA law, KVG, ATSG, the Therapeutic Products Act) supplement the DSG with sector-specific duties.

Records of Processing Activities (Art. 12 DSG)

The Records of Processing Activities (ROPA) is the documented overview of all data processing operations of a controller or processor. It must be maintained under Art. 12 DSG and constitutes the central compliance document for any data protection organisation.

Content of the records (Art. 12 para. 2 DSG): identity of the controller, purpose of processing, categories of data subjects and of processed personal data, categories of recipients, retention period or criteria for determining the period, a general description of the technical and organisational measures, as well as, in the case of disclosure abroad, the recipient state and, where applicable, the safeguards under Art. 16 para. 2 DSG or the application of an exception under Art. 17 DSG.

Processors maintain their own, leaner records (Art. 12 para. 3 DSG) with particulars of the relevant controller, the categories of processing, and the recipient states and safeguards.

SME exemption (Art. 12 para. 5 DSG in conjunction with Art. 24 DSV): companies with fewer than 250 employees are exempt from the obligation, provided the data processing entails only a low risk of a violation of the personality of the data subjects. In practice the exemption is narrow: as soon as sensitive personal data are processed on a large scale, or high-risk profiling takes place, the obligation applies. We recommend that every SME maintain the records nonetheless, since they would in any event have to be produced at short notice in the event of an FDPIC inquiry, a data breach or an access request.

Format. The act does not prescribe a specific form. Established practice favours Excel templates for SMEs and dedicated tools (OneTrust, Datenschutzcockpit) for groups. The FDPIC provides a template on its website that serves as a minimum standard.

Duty to inform (Art. 19 DSG) and privacy notice

The duty to inform under Art. 19 DSG requires every controller to inform the data subject in an appropriate manner upon every collection of personal data. The central form of implementation for companies is the privacy notice on the website, together with supplementary information documents in the application, contract and customer process.

Mandatory content (Art. 19 para. 2 DSG): identity and contact details of the controller, purpose of processing, and where applicable the recipients or categories of recipients. In the case of disclosure of personal data abroad, the state or international body must additionally be named, together with, where applicable, the safeguards under Art. 16 para. 2 DSG or the application of an exception under Art. 17 DSG (Art. 19 para. 4 DSG).

Where the personal data are not collected from the data subject themselves, the categories of processed personal data must additionally be communicated under Art. 19 para. 3 DSG.

Exceptions (Art. 20 DSG): The duty to inform lapses, among other situations, where the data subject already has the relevant information, where the processing is provided for by law, or where there are overriding interests of third parties. The exceptions are to be construed narrowly.

Format. The DSG does not prescribe a specific form but requires intelligibility. The information must be provided in a form that is recognisable and comprehensible to the data subject. Mere incorporation by reference in the general terms and conditions is not sufficient. For Swiss websites with a mixed target audience, we recommend a German-language privacy notice as the primary version, supplemented by French and English translations.

Practice. The privacy notice should contain the following sections: controller and contact; categories of data processed; purposes of processing; legal bases; recipients and processors; data transfers abroad; retention period; rights of data subjects; cookies and tracking; contact for exercising rights; reservation of amendment.

Data Protection Impact Assessment (Art. 22 DSG)

The Data Protection Impact Assessment (DPIA) is the ex-ante risk analysis of a planned data processing operation. It must be carried out mandatorily under Art. 22 DSG where a processing operation may give rise to a high risk to the personality or the fundamental rights of the data subject.

When mandatory. A high risk exists under Art. 22 para. 2 DSG in particular in the case of extensive processing of sensitive personal data, or systematic extensive monitoring of publicly accessible areas. High-risk profiling and the use of new technologies typically trigger the obligation as well. The FDPIC has published an indicative list on this; in the individual case, an independent risk assessment must be carried out.

Content (Art. 22 para. 3 DSG): description of the planned processing, assessment of the risks to the personality or the fundamental rights of the data subject, and the measures envisaged to mitigate the risk.

Consultation of the FDPIC (Art. 23 DSG): If the DPIA shows that the planned processing entails a high risk despite the measures envisaged, the FDPIC must be consulted beforehand. Where a Data Protection Adviser has been appointed under Art. 10 DSG, the consultation may be dispensed with, provided that the Adviser has been consulted.

Who carries it out. Responsibility formally remains with executive management. In practice the internal or external Data Protection Adviser coordinates the process, gathers input from the business unit, IT security and the legal department, and documents the outcome. The DPIA is not a one-off document but must be updated in the event of material changes to the processing.

Relationship to the GDPR DPIA. An entity that has already prepared a DPIA under Art. 35 GDPR for a processing operation can generally re-use it for the DPIA under Art. 22 DSG, provided that the Swiss specificities (in particular the broader sensitive data under Art. 5 lit. c DSG) are added.

Notification of data security breaches (Art. 24 DSG)

The duty to notify under Art. 24 DSG requires the controller to notify the FDPIC of data security breaches that are likely to result in a high risk to the personality or the fundamental rights of the data subject. The duty has applied since 1 September 2023 to all private controllers and federal bodies.

Notification deadline. Notification must be made "as soon as possible" (Art. 24 para. 1 DSG). The DSG does not provide for a rigid 72-hour deadline as in Art. 33 GDPR. In practice the FDPIC recommends orienting towards a similarly short timeframe in order to preserve responsiveness towards the supervisory authority. Processors likewise notify the controller of incidents as soon as possible (Art. 24 para. 3 DSG).

Content of notification (Art. 24 para. 2 DSG): the nature of the breach, the consequences, and the measures taken or envisaged. The FDPIC provides the "DataBreach" notification form on its website, which structures the mandatory particulars.

Information of data subjects (Art. 24 para. 4 DSG): Where necessary for the protection of the data subject, or where the FDPIC so requires, the controller must also inform the data subject. Exceptions exist under Art. 24 para. 5 DSG.

Difference from the GDPR. The GDPR provides for a notification deadline of 72 hours (Art. 33 para. 1 GDPR) and a lower triggering threshold (risk, not high risk). An entity subject to both regimes must orient towards the stricter GDPR deadline.

Criminal liability. The wilful breach of the duties to provide information, access and cooperation, but not the breach of the notification duty itself, is punishable under Art. 60 DSG. Failure to notify can, however, indirectly lead to supervisory measures and reputational damage.

Practical recommendation. Every company should maintain a documented incident-response process with clear escalation paths, predefined responsibilities and a prepared notification template. The initial response determines the assessment by the FDPIC.

External Data Protection Adviser (Art. 10 DSG), when is it advisable?

The Data Protection Adviser is the internal or external specialist who advises and trains a company on all data protection matters. Art. 10 DSG governs its role and tasks. For private controllers the appointment is optional, for federal bodies it is mandatory under Art. 25 DSV.

Tasks (Art. 10 para. 2 DSG): training and advising the controller, participation in the application of data protection rules, point of contact for data subjects and for the FDPIC.

Requirements (Art. 10 para. 3 DSG): the Data Protection Adviser must possess the expertise required for the function, exercise the task vis-à-vis the controller in a professionally independent and instruction-free manner, and must not carry out activities incompatible with the task.

Privilege of DPIA consultation (Art. 23 para. 4 DSG). An entity that appoints a Data Protection Adviser and consults them can dispense with consulting the FDPIC in the context of a DPIA. This is a considerable efficiency advantage and, in practice, the strongest argument for the formal appointment.

When an external adviser makes sense. For SMEs without their own legal department, an external Data Protection Adviser is usually more efficient than building up the function internally. Advantages: an independent perspective, the pooling of experience from several mandates, a clear separation of roles from operational functions, and no conflict of interest with IT or HR. Groups often opt for a hybrid model: an internal group DPO plus an external adviser for specialist topics (M&A, international transfers, audits).

GDPR parallel. An entity that is also subject to the GDPR and must designate a Data Protection Officer under Art. 37 GDPR can bundle both functions in one person, provided qualification and independence are ensured.

SIDD takes on the mandate as external Data Protection Adviser under Art. 10 DSG both for Swiss SMEs and for international groups with a Swiss touchpoint.

Sanctions and fines (Art. 60–66 DSG)

The DSG sanctions infringements under criminal law. Unlike the GDPR, with its administrative-fine regime against undertakings, the Swiss sanction system is directed in principle against the responsible natural person. This is the central, often underestimated peculiarity of the DSG.

Maximum fine (Art. 60 DSG). Whoever wilfully breaches the duties to provide information, access and cooperation is, upon complaint, punished with a fine of up to CHF 250,000. Liability requires intent; negligence is not sufficient.

Breach of duties of care (Art. 61 DSG). Punishable conduct includes, in particular, the unauthorised disclosure of personal data abroad in breach of Art. 16 and 17 DSG, the unauthorised assignment of processing to a processor without a corresponding agreement, and the disregard of the minimum requirements for data security (Art. 8 para. 3 DSG in conjunction with the DSV). Fine of up to CHF 250,000.

Breach of professional confidentiality (Art. 62 DSG). Whoever unlawfully discloses secret personal data that became known to them in the course of their professional activity is punished with a fine of up to CHF 250,000.

Disregard of rulings (Art. 63 DSG). Wilful disregard of rulings of the FDPIC or decisions of the appellate instances is punishable with a fine of up to CHF 250,000.

Addressee of the penalty (Art. 64 DSG). Punishable in principle is the natural person who committed the infringement. Within a company, the relevant person is the member of executive management within whose area of responsibility the infringement falls. The company itself may be fined up to CHF 50,000 under Art. 64 para. 2 DSG where identifying the punishable person would entail disproportionate effort.

Prosecution. Criminal prosecution falls to the cantonal authorities (Art. 65 DSG). The FDPIC itself does not impose fines but can issue rulings and file complaints.

Consequence for practice. The statement "the fine hits the company" is not correct for the DSG. Members of executive management, and CEOs in particular, are personally liable. This makes a documented compliance organisation, records, DPIA, contracts, training, a protective shield for corporate officers.

International data transfers (Art. 16 et seq. DSG)

International data transmission is governed in the DSG by Art. 16 to 18 and by Art. 8–12 DSV. Personal data may be disclosed abroad only where adequate protection is ensured. The framework corresponds systematically to Art. 44 et seq. GDPR.

Adequate third countries (Art. 16 para. 1 DSG). The Federal Council maintains a list of states with an adequate level of data protection (Annex 1 DSV). The list includes, among others, the EU/EEA states, the United Kingdom, Canada (commercial organisations), Argentina and others. The list is updated periodically; the version in force at the relevant time is decisive.

Safeguards for non-adequate states (Art. 16 para. 2 DSG). Where an adequate level of protection is lacking, the transfer is only permissible if adequate protection is ensured by other means. Options include: an international treaty, data protection clauses in a contract between the controller and the recipient (the Swiss standard contractual clauses, or the EU SCCs recognised by the FDPIC), specific safeguards of the competent federal body, and binding corporate rules (BCR) that have been approved in advance by the FDPIC or by the competent authority of a state with an adequate level of protection.

Exceptions (Art. 17 DSG). Disclosure without safeguards is permissible, among other situations, with the explicit consent of the data subject, in direct connection with the conclusion or performance of a contract, to safeguard overriding public interests, or for the assertion of legal claims.

United States. For data transfers to the United States, the Federal Council has recognised the Swiss-US Data Privacy Framework as an additional basis. Transfers to companies certified there are deemed to rest on an adequate basis. For non-certified US recipients, standard contractual clauses plus a Transfer Impact Assessment are required, analogous to the Schrems II logic under the GDPR.

Documentation. Every transfer abroad must be documented in the Records of Processing Activities (Art. 12 para. 2 lit. g DSG).

FDPIC, the Swiss supervisory authority

The Federal Data Protection and Information Commissioner (FDPIC), seated at Feldeggweg 1, 3003 Bern, is the national supervisory authority for data protection in Switzerland. It supervises both private controllers and federal bodies and represents Switzerland internationally (Art. 43 et seq. DSG).

Tasks (Art. 49 DSG). Supervision of the application of the DSG, informing the public, advising federal bodies and private persons, issuing opinions on draft legislation with a data protection nexus, international cooperation, and maintaining the register of Data Protection Advisers (Art. 10 para. 4 DSG).

Investigatory powers (Art. 49–51 DSG). The FDPIC may open an investigation against a controller or processor, ex officio or upon a complaint, where there are sufficient indications that a data processing operation could infringe data protection rules. It can request files, obtain information and conduct on-site inspections.

Ruling powers (Art. 51 DSG). Where the FDPIC establishes an infringement, it can order the adjustment, suspension or cessation of the processing, require the erasure of personal data, and prohibit the disclosure of personal data abroad or make it subject to conditions. The rulings are appealable before the Federal Administrative Court.

Complaint (Art. 49 para. 2 DSG). Any person may report an infringement of data protection rules to the FDPIC. The FDPIC decides, in the exercise of its dutiful discretion, whether to open an investigation procedure.

Practice. The FDPIC publishes guidelines, templates and activity reports on its website (www.edoeb.admin.ch). These are a valuable orientation aid in the practical interpretation of the DSG, without being formally legally binding. For contested questions of interpretation, the Federal Administrative Court and, at second instance, the Federal Supreme Court are ultimately competent.

DSG compliance checklist for SMEs (10 steps)

The following checklist summarises the steps with which a Swiss SME builds a DSG-compliant data protection organisation. It does not replace individual advice but serves as a structuring aid.

  1. Inventory data flows. Capture all processing operations: personnel data, customer data, applicant data, supplier data, marketing data, website and cookie data.
  2. Prepare the Records of Processing Activities (Art. 12 DSG). Recommended even where the SME exemption applies. Use the FDPIC template or introduce a tool.
  3. Update the privacy notice (Art. 19 DSG). Check the mandatory content, expressly disclose transfers abroad, and design the cookie banner to be DSG- and ePrivacy-compliant.
  4. Conclude data processing agreements (Art. 9 DSG). With every processor (cloud provider, IT service provider, payroll, marketing tools), a written DPA with Swiss specificities.
  5. Assess international data transfers (Art. 16 et seq. DSG). A list of all recipients outside Switzerland and the EU/EEA states. Document the safeguards (SCCs, BCRs, adequacy).
  6. Document the technical and organisational measures (Art. 8 DSG). Access concept, encryption, backup, patch management, awareness training. Where there is ISO/IEC 27001 certification, the TOM documentation can largely be re-used.
  7. Set up an incident-response process (Art. 24 DSG). Notification chain, responsibilities, notification template for the FDPIC, communications plan for data subjects.
  8. Define a Data Protection Impact Assessment process (Art. 22 DSG). A trigger list for high risk, a template, and escalation to the Data Protection Adviser or the FDPIC.
  9. Access and erasure process (Art. 25 et seq. DSG). Deadline of 30 days under Art. 25 para. 7 DSG. A workflow for incoming requests with a responsibility matrix.
  10. Designate a Data Protection Adviser or mandate an external entity (Art. 10 DSG). Even where not mandatory: the consultation privilege for DPIAs, a clear point of contact for the FDPIC and data subjects, and protection of executive management from personal criminal liability.

Frequently asked questions about the DSG (FAQ)

When did the DSG enter into force? The revised Federal Act on Data Protection was adopted by the Federal Council on 25 September 2020 and entered into force on 1 September 2023. Since that date the correct short name is "DSG". It replaces the DSG of 1992 and aligns Swiss data protection largely with the GDPR.

Does the DSG also apply to sole proprietorships? Yes. The DSG contains no general de minimis threshold. Every sole proprietorship that processes personal data, that is, in practice every company with at least one customer, supplier or employee, is subject to the DSG. Relief exists only selectively, for example in relation to the Records of Processing Activities under Art. 12 para. 5 DSG for companies with fewer than 250 employees.

How high are the fines for DSG infringements? The maximum fine is CHF 250,000 (Art. 60 et seq. DSG). It is directed in principle against the responsible natural person, not against the company. On a subsidiary basis, the company may be fined up to CHF 50,000 where identifying the punishable person would entail disproportionate effort (Art. 64 para. 2 DSG).

Do I need a Data Protection Officer as an SME? For private controllers, the appointment of a Data Protection Adviser under Art. 10 DSG is optional. It is nevertheless advisable, as it opens up the consultation privilege for Data Protection Impact Assessments under Art. 23 para. 4 DSG and creates a clear point of contact for the FDPIC and data subjects. For companies subject to the GDPR, an additional obligation under Art. 37 GDPR may apply.

What is the difference between the DSG and the GDPR? Both govern the protection of personal data of natural persons on similar principles. Differences exist in the addressee of the sanctions (DSG: natural persons up to CHF 250,000; GDPR: undertakings up to EUR 20 million or 4 percent of annual turnover), in the notification deadline for data breaches (DSG: as soon as possible; GDPR: 72 hours) and in the sensitive personal data (the DSG catalogue is broader).

Must I notify data breaches immediately? Under Art. 24 DSG, data security breaches likely to result in a high risk to personality or fundamental rights must be notified to the FDPIC as soon as possible. The DSG does not specify a rigid deadline. An entity also subject to the GDPR must additionally comply with the 72-hour deadline under Art. 33 GDPR.

Who supervises compliance with the DSG? The supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC), seated in Bern. It can open investigations, issue rulings and prohibit processing. Criminal prosecution falls to the cantonal criminal authorities. Appeals against FDPIC rulings go to the Federal Administrative Court.

How long does building DSG compliance take for an SME? It depends on the individual case. For an SME with a standardised IT landscape and without complex international data flows, baseline compliance (records, privacy notice, DPA, incident process) is typically achievable within two to four months. Groups with M&A activity, profiling or large-scale processing of sensitive data should anticipate six to twelve months.

How SIDD supports you on the DSG

SIDD is the data protection and InfoSec brand of Priverion GmbH (Baar/ZG), founded in 2017. We take on the mandate as external Data Protection Adviser under Art. 10 DSG for Swiss SMEs and internationally active groups, prepare records, privacy notices, DPIAs and incident playbooks, and support you in FDPIC proceedings. For companies that are also subject to the GDPR, we provide the external EU Data Protection Officer, including the representative under Art. 27 GDPR. For the ISO/IEC 27001 journey we work with CIS Cert (Quality Austria Group) as an accredited certification body. Talk to our Swiss Data Protection Adviser or read our further specialist articles.

Need help putting this into practice? SIDD operates the matching service.
See service →