GDPR Compliance, The 8-Point Self-Assessment
Introduction
«Are we GDPR-compliant?» is an imprecise question. GDPR compliance is not a state but a system. Once you understand the system, you can determine in an hour whether the eight key duties are met, and where rework is needed. This article walks you through a structured self-assessment with eight stations that follow the GDPR's logic. It is designed as an SME tool: in 60–90 minutes you have a clear maturity picture.
What you will take away:
- the eight duty categories in which every processing of personal data must be anchored;
- for each point, a concrete question, a legal anchor and a typical SME piece of evidence;
- a heuristic for whether you score green, amber or red on each point;
- the parallel Swiss duties (DSG), so dual-regulated SMEs can check both regimes at once.
Important: this self-assessment is not a substitute for a Data Protection Impact Assessment or case-specific advice, it is a screening that identifies the gaps. Anyone scoring amber or red on multiple points should consult a data protection officer.
Point 1, Legal basis for every processing
Anchor: Art. 6 GDPR (parallel Art. 31 DSG, read with Art. 6 DSG).
Question: Do you know, for each individual processing activity, which of the six legal bases you rely on?
The six legal bases under Art. 6(1) GDPR:
- lit. a consent, for newsletters, cookies, marketing profiles;
- lit. b contract performance, for customer data needed to perform the contract;
- lit. c legal obligation, for accounting data (10 years CO 958f), social insurance;
- lit. d vital interests, rare application;
- lit. e public task, primarily for public authorities;
- lit. f legitimate interests, for direct marketing to existing customers, fraud prevention, IT security.
Typical evidence: a «legal basis» column in your records of processing activities.
Traffic light: green = every processing has a documented legal basis; amber = some processing, no documentation; red = unclear or never analysed.
Point 2, Records of processing activities
Anchor: Art. 30 GDPR (parallel Art. 12 DSG, exemption under Art. 24 DSV / Art. 30(5) GDPR for SMEs <250 employees without high risk).
Question: Do you have a complete record of all processing activities with the eight items required by Art. 30 GDPR?
Minimum entries:
- name and contact of the controller (and where applicable DPO/representative);
- purposes of processing;
- description of the categories of data subjects and personal data;
- categories of recipients (internal departments, processors);
- transfers to third countries and safeguards;
- retention periods;
- general description of the TOMs per Art. 32 GDPR;
- legal basis (de facto mandatory even though not explicitly required by Art. 30).
Practice: in Switzerland you maintain a single record that satisfies both Art. 30 GDPR and Art. 12 DSG. Excel is enough for SMEs; from around 200 employees a tool pays off (OneTrust, Caralegal, Priverion).
Traffic light: green = complete, updated within the past 12 months; amber = present but gaps or outdated; red = not in place.
Point 3, Information duty and privacy notice
Anchor: Art. 13–14 GDPR (parallel Art. 19 DSG).
Question: Is your privacy notice complete, easily accessible and up to date?
Mandatory components: identity and contact of the controller; DPO contact (if appointed); processing purposes and legal bases; recipients; third-country transfers and safeguards; retention periods; data subject rights (access, rectification, erasure, restriction, portability, objection, withdrawal of consent); right to lodge a complaint with the supervisory authority; existence of automated decision-making including profiling, where applicable.
Typical mistakes: last update more than 24 months ago; cookie list missing; no mention of processors; no DPO contact; «legitimate interests» mentioned wholesale without specifying the purpose.
Practical test: if a layperson cannot understand from your privacy notice which data you process for what purpose, it is probably too generic or too legalistic.
Traffic light: green = complete, reviewed in the past 12 months, intelligible; amber = present but incomplete or outdated; red = missing.
Point 4, Data Processing Agreements (DPAs)
Anchor: Art. 28 GDPR (parallel Art. 9 DSG).
Question: Do you have a signed DPA with every processor (cloud provider, newsletter tool, IT service provider, payroll service, marketing agency)?
Mandatory content under Art. 28(3) GDPR: subject matter and duration; nature and purpose; types of personal data; obligations and rights of the controller; confidentiality obligation of the personnel; technical and organisational measures; sub-processing; assistance with data subject rights; assistance with notification duties; deletion/return after end of contract; audit right.
Practice: most large providers (Microsoft, Google, AWS, Salesforce) supply a standard DPA acceptable per click. For smaller vendors you often need to request the DPA yourself. Swiss processors need a DPA that satisfies both Art. 9 DSG and Art. 28 GDPR, EDÖB templates are a good starting point.
Traffic light: green = DPA register complete, every processor with a signed DPA recorded; amber = partially in place, no systematic register; red = DPA not systematically used.
Point 5, Data breach process
Anchor: Art. 33–34 GDPR (parallel Art. 24 DSG).
Question: Do your employees know what to do in a data breach, and can you meet the 72-hour notification deadline?
Minimum elements of an effective process:
- a central reporting point (DPO or data protection function) with 24/7 availability;
- an escalation plan with roles (Incident Manager, Forensics, Legal, Communications);
- a threshold logic for notification (risk assessment by likelihood and severity);
- prepared notification templates for the supervisory authority (EDÖB, Lead Supervisory Authority);
- an annual tabletop exercise with the executive board;
- training for all employees on recognising a data breach.
Supervisory practice: the 72-hour deadline under Art. 33 GDPR begins on the controller's becoming aware, not on completion of forensics. An initial notification can be «preliminary», with details submitted later. In Switzerland the deadline under Art. 24 DSG is «as soon as possible», EDÖB practice orients to the 72 hours.
Traffic light: green = documented process, exercised in the past 12 months; amber = process in place, not exercised; red = no process.
Points 6–8, DPIA, transfers, governance
Point 6, Data Protection Impact Assessment (DPIA). Anchor: Art. 35 GDPR (parallel Art. 22 DSG). Question: For each processing posing a high risk (e.g. systematic monitoring, profiling, large-scale processing of special categories), have you carried out a documented DPIA? Supervisory authorities publish lists of DPIA-required processing (EDPB, EDÖB). Evidence: a written DPIA with risk assessment, measures and residual risk evaluation.
Point 7, Third-country transfers. Anchor: Art. 44–49 GDPR (parallel Art. 16–18 DSG). Question: Do you know to which third countries your data flow, and do you have a legal basis for each transfer (adequacy decision, DPF, SCC, BCR, Art. 49 GDPR derogations)? For US recipients since 10 July 2023 (EU) and 15 September 2024 (CH), the EU/CH-US Data Privacy Framework applies. For other third countries, regularly SCC plus a Transfer Impact Assessment (Schrems II).
Point 8, Governance. Anchor: Art. 24 GDPR (accountability) and Art. 37 GDPR (DPO). Question: Do you have a named data protection function (internal or external), regular employee training (Art. 39(1)(b) GDPR), a written data protection policy and an internal audit system? A Swiss parallel structure under Art. 10 DSG (Data Protection Advisor) is a sensible complement.
How SIDD supports you
SIDD runs this 8-point self-assessment as a structured data protection audit in 5–10 days for SMEs, hospitals and associations. The output is a prioritised action catalogue with effort estimates, responsibilities and a realistic timeline. Where required we implement the measures directly, as your Data Protection Advisor under Art. 10 DSG, as your GDPR DPO per Art. 37 GDPR or as your EU representative per Art. 27 GDPR.
Typical follow-on mandates: ROPA build and maintenance; privacy notice for CH/EU/UK websites; DPA standardisation with sub-processor tracking; third-country strategy under DPF and SCC; awareness training in data protection workshops; technical TOM verification via penetration test and vulnerability scan.
Would you like to run the 8-point check in your organisation in a structured way? Request a non-binding quote or reach out via the contact form. In a 30-minute initial call we will clarify scope and effort for your organisation.
