General Data Protection Regulation (GDPR), 2026 Guide
What is the GDPR (General Data Protection Regulation)?
The General Data Protection Regulation (GDPR, German Datenschutz-Grundverordnung / DSGVO) is the European regulation that governs the protection of natural persons in the processing of personal data and the free movement of such data within the EU. It was enacted on 27 April 2016 as Regulation (EU) 2016/679 and has applied directly in all EEA Member States since 25 May 2018.
As a regulation, the GDPR is directly applicable without any national transposition act. Member States have nevertheless adopted supplementary national statutes, such as the German BDSG, the Austrian DSG or the French Loi Informatique et Libertés. The purpose of the GDPR under Art. 1 GDPR is to protect the fundamental rights and freedoms of natural persons, in particular their right to the protection of personal data, while also ensuring the free movement of personal data within the Union.
The Regulation comprises 99 articles and 173 recitals. It governs, among other matters: the principles relating to processing (Art. 5 GDPR), lawfulness of processing (Art. 6 GDPR), the processing of special categories of data (Art. 9 GDPR), the rights of data subjects (Art. 12–22 GDPR), the obligations of controllers and processors (Art. 24–43 GDPR), international data transfers (Art. 44 et seq. GDPR), supervisory authorities (Art. 51 et seq. GDPR) and sanctions (Art. 83, 84 GDPR).
The GDPR is YMYL-relevant for any company with an EU nexus. Infringements may trigger administrative fines of up to EUR 20 million or 4 percent of global annual turnover (Art. 83 GDPR), whichever is higher.
GDPR vs DSG (FADP), what Swiss companies need to know
The GDPR and the Swiss DSG (Federal Act on Data Protection / FADP) pursue similar protective goals but differ in scope, sanction architecture and detailed rules. Swiss companies with an EU nexus are frequently subject to both regimes in parallel. Further detail on the DSG is available in the Swiss Data Protection Act guide.
Territorial scope. The GDPR applies under Art. 3 GDPR where there is an establishment in the EU, where goods or services are offered to persons in the EU, or where behaviour is monitored within the EU. The DSG attaches under Art. 3 DSG to the place of effect in Switzerland. A Swiss SaaS provider with customers in Germany is typically subject to both statutes.
Sanctions. The GDPR imposes administrative fines on undertakings of up to EUR 20 million or 4 percent of global annual turnover (Art. 83 GDPR). The DSG, by contrast, imposes criminal fines of up to CHF 250,000 on responsible natural persons (Art. 60 DSG). The addressee of the sanction is therefore fundamentally different.
Breach notification deadline. The GDPR requires notification within 72 hours (Art. 33 GDPR). The DSG requires notification "as soon as possible" (Art. 24 DSG) without a fixed deadline. An entity subject to both regimes complies with the stricter GDPR deadline.
Data Protection Officer. The GDPR provides for a mandatory designation under Art. 37 GDPR in defined constellations. The DSG only recognises the optional Data Protection Adviser under Art. 10 DSG, with a consultation privilege in the context of the DPIA.
EU Representative. Under Art. 27 GDPR, controllers and processors without an EU establishment are generally required to designate a representative in the Union in writing. The DSG contains no comparable obligation for foreign controllers, apart from Art. 14 DSG on designating a representative in Switzerland.
Adequacy. The European Commission confirmed Switzerland on 15 January 2024 with an updated adequacy decision. Data flows from the EU to Switzerland are permitted without additional safeguards.
Which companies are subject to the GDPR? (territorial scope, Art. 3 GDPR)
The GDPR applies irrespective of the controller's place of establishment, provided one of the three connecting factors in Art. 3 GDPR is met. The territorial scope is deliberately broad in order to protect EU citizens against third-country providers as well.
Establishment principle (Art. 3(1) GDPR). The GDPR applies to the processing of personal data carried out in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing itself takes place in the Union. An establishment requires effective and real exercise of activity through stable arrangements (CJEU, Weltimmo, C-230/14).
Market principle (Art. 3(2) GDPR). The GDPR also applies to controllers or processors without an EU establishment where they offer goods or services to data subjects in the Union (lit. a) or monitor their behaviour in the Union (lit. b). Indicators of an offer directed at the EU under Recital 23 include: EU languages, EU currency, EU top-level domains, delivery to EU states, EU telephone numbers.
Public international law principle (Art. 3(3) GDPR). The GDPR also applies in places where Member State law applies by virtue of public international law (e.g. embassies, ships under an EU flag).
Constellations affected in practice:
- Swiss SMEs with an online shop that ships to Germany, Austria or France.
- Swiss SaaS providers with EU customers, a single paying DACH customer can suffice if the offering is deliberately addressed to persons in the EU.
- Swiss groups with subsidiaries, employees or sites in the EEA.
- Global platforms without an EU establishment that track EU user behaviour (cookies, pixels, fingerprinting).
Mere accessibility of a website from the EU is not sufficient under Recital 23. The decisive factor is whether the offering is targeted, assessed case by case.
Which obligations arise from the GDPR? (overview)
The GDPR imposes a comprehensive catalogue of obligations on controllers and processors. The principal duties at a glance:
- Processing principles (Art. 5 GDPR): lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. To these is added the accountability principle (Art. 5(2) GDPR).
- Legal basis (Art. 6 GDPR): every processing operation requires one of the six legal bases. Special categories of data require additionally Art. 9 GDPR.
- Information duties (Art. 13, 14 GDPR): for direct collection and for collection from third parties, a privacy notice containing all mandatory disclosures.
- Data subject rights (Art. 12–22 GDPR): access, rectification, erasure, restriction, data portability, objection, the right against automated individual decisions.
- Records of Processing Activities (Art. 30 GDPR): documented overview of all processing operations.
- Processor engagement (Art. 28 GDPR): a written data processing agreement (DPA) with mandatory minimum contents.
- Security of processing (Art. 32 GDPR): technical and organisational measures reflecting the state of the art.
- Notification duty (Art. 33, 34 GDPR): notification to the supervisory authority within 72 hours, and where applicable additional communication to data subjects.
- Data Protection Impact Assessment (Art. 35 GDPR): where processing is likely to result in a high risk.
- Data Protection Officer (Art. 37–39 GDPR): mandatory designation in defined cases.
- Privacy by Design / by Default (Art. 25 GDPR): data protection from the design stage and through privacy-friendly default settings.
- International data transfers (Art. 44 et seq. GDPR): transfers to third countries only under the conditions of Art. 45–49 GDPR.
- EU Representative (Art. 27 GDPR): for third-country controllers without an EU establishment.
The list is not exhaustive. Sector-specific rules (ePrivacy Directive, NIS2 Directive, DSA, DMA, AI Act) supplement the GDPR.
Legal bases for processing (Art. 6 GDPR)
Every processing operation involving personal data requires one of the six legal bases under Art. 6(1) GDPR. Without a valid legal basis the processing is unlawful, irrespective of the sensitivity of the data or the diligence of the security measures.
Consent (Art. 6(1)(a) GDPR). A freely given, specific, informed and unambiguous indication of the data subject's wishes. The requirements follow from Art. 7 GDPR: demonstrability, clear and intelligible language, withdrawal at any time. For children under the age of 16, additional requirements apply under Art. 8 GDPR (Member States may lower the age threshold to 13).
Performance of a contract (Art. 6(1)(b) GDPR). Processing is necessary for the performance of a contract to which the data subject is a party or for pre-contractual steps taken at the data subject's request. Classic examples: order processing, shipping, invoicing.
Legal obligation (Art. 6(1)(c) GDPR). Processing is necessary for compliance with a legal obligation to which the controller is subject. Examples: commercial retention duties, tax record-keeping obligations, social-insurance reporting requirements.
Vital interests (Art. 6(1)(d) GDPR). Protection of the vital interests of the data subject or of another natural person. In the private sector, this basis is rarely relevant in practice.
Public interest (Art. 6(1)(e) GDPR). Performance of a task carried out in the public interest or in the exercise of official authority. Primarily relevant for public bodies.
Legitimate interests (Art. 6(1)(f) GDPR). Processing for the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights of the data subject. A documented balancing test (Legitimate Interest Assessment, LIA) is required. This basis is not available to public authorities in the performance of their tasks.
Special categories of data (Art. 9 GDPR). Processing of health data, biometric data, data on sexual orientation, religious beliefs and similar categories is prohibited in principle, unless one of the exceptions in Art. 9(2) GDPR applies, notably explicit consent.
Data subject rights (Art. 12–22 GDPR)
Articles 12 to 22 GDPR set out the rights of data subjects. The controller must facilitate the exercise of these rights and must, as a rule, respond free of charge, in a concise, transparent and intelligible form within one month (Art. 12(3) GDPR; extendable by two months).
Right of access (Art. 15 GDPR). The data subject may request information on whether and which personal data are being processed, on the purposes of processing, the categories of data, the recipients, the storage period, additional rights, the right to lodge a complaint and, in the case of third-country transfers, the appropriate safeguards. The data subject is further entitled to a copy of the data.
Right to rectification (Art. 16 GDPR). Inaccurate data must be rectified; incomplete data must be completed.
Right to erasure (Art. 17 GDPR). The data subject may request erasure where the data are no longer necessary for the purposes, consent has been withdrawn, an objection has been raised or processing was unlawful. The right is not absolute, exceptions exist for statutory retention duties and the assertion of legal claims.
Right to restriction (Art. 18 GDPR). Suspension of processing where there is a dispute about accuracy or lawfulness.
Right to data portability (Art. 20 GDPR). Where processing is based on consent or contract and carried out by automated means, the data subject may receive the data in a structured, commonly used and machine-readable format or have them transmitted directly to another controller.
Right to object (Art. 21 GDPR). Processing based on legitimate interests or public tasks may be objected to at any time, absolutely and without justification in the case of direct marketing.
Automated individual decisions (Art. 22 GDPR). The data subject has the right not to be subject to a decision based solely on automated processing which produces legal effects or similarly significantly affects the data subject, unless exceptions apply.
The practical consideration is decisive: a documented workflow with deadline tracking, identity verification and escalation. The right of access is, by volume, the most frequent request in practice.
Records of Processing Activities (Art. 30 GDPR)
The Records of Processing Activities (ROPA) is the documented overview of all processing operations of a controller or processor. It is required under Art. 30 GDPR and is the central compliance document for any GDPR-regulated organisation.
Content for the controller (Art. 30(1) GDPR): name and contact details of the controller and, where applicable, of the Data Protection Officer and the EU representative; the purposes of processing; the categories of data subjects and of personal data; the categories of recipients, including those in third countries; where applicable, transfers to third countries with documentation of the safeguards under Art. 46(2) GDPR; envisaged retention periods; a general description of the technical and organisational measures pursuant to Art. 32(1) GDPR.
Content for the processor (Art. 30(2) GDPR): a leaner record containing the relevant controller, the categories of processing, third-country transfers and TOMs.
SME exemption (Art. 30(5) GDPR). Enterprises or organisations employing fewer than 250 persons are exempt, unless the processing is likely to pose a risk to the rights and freedoms of data subjects, is not occasional, or includes special categories of data under Art. 9 or Art. 10 GDPR. The exemption must be construed narrowly: HR files, customer databases and CRM systems are typically not processed "occasionally", the exemption is therefore rarely available in practice.
Duty of disclosure (Art. 30(4) GDPR). The record must be made available to the supervisory authority on request. Failure to produce the record can itself attract an administrative fine under Art. 83(4)(a) GDPR.
Format. Written, including electronic form. Established practice: Excel templates for SMEs, dedicated tools (OneTrust, DataGuard, Datenschutzcockpit) for mid-sized and larger organisations.
Technical and organisational measures (Art. 32 GDPR)
Art. 32 GDPR requires controllers and processors, taking into account the state of the art, the cost of implementation, the circumstances of processing and the likelihood and severity of risks for the rights and freedoms of natural persons, to implement appropriate technical and organisational measures (TOMs) ensuring a level of security appropriate to the risk.
Protection objectives (Art. 32(1)(a)–(d) GDPR). Pseudonymisation and encryption; ensuring the confidentiality, integrity, availability and resilience of systems and services; restoration of availability after an incident; processes for regularly testing, assessing and evaluating the effectiveness of the measures.
Risk-based approach. The GDPR does not prescribe specific measures. The individual risk of the processing operation is decisive. An HR database containing health data demands a higher level of protection than a publicly published newsletter distribution list.
State of the art. Concretised by internationally recognised standards. ISO/IEC 27001 (Information Security Management Systems) and ISO/IEC 27701 (Privacy Information Management) in particular provide a recognised framework. Implementation of an ISMS in accordance with ISO/IEC 27001 covers a significant portion of the Art. 32 duties. For certification in Switzerland and the DACH region SIDD works with CIS Cert (Quality Austria Group, ISO/IEC 17021-accredited).
Typical TOM components: access control (need-to-know, RBAC, MFA); encryption (at rest, in transit); backup and recovery; patch and vulnerability management; logging and monitoring; network segmentation; awareness training; incident-response processes; supplier management.
NIS2 nexus. For companies within the scope of the NIS2 Directive ((EU) 2022/2555), Art. 32 GDPR and Art. 21 NIS2 complement each other within the security architecture. An integrated security concept reduces duplication of effort substantially.
Documentation. TOMs must be described in the Art. 30 GDPR record and typically in a TOM document at the entity level. The evidence forms part of the accountability obligation under Art. 5(2) GDPR.
Data Protection Impact Assessment (Art. 35 GDPR)
The Data Protection Impact Assessment (DPIA) is the ex-ante risk analysis of a planned processing operation. It is mandatory under Art. 35 GDPR where a type of processing, in particular involving new technologies, is, given its nature, scope, context and purposes, likely to result in a high risk to the rights and freedoms of natural persons.
Mandatory cases (Art. 35(3) GDPR). A DPIA is required in particular for systematic and extensive evaluation of personal aspects by automated processing (profiling) producing legal effects; large-scale processing of special categories under Art. 9 or data on criminal convictions under Art. 10; systematic large-scale monitoring of publicly accessible areas.
Supervisory authority lists (Art. 35(4) GDPR). Each national supervisory authority publishes a list of processing operations for which a DPIA is mandatory. The EDPB has additionally adopted guidelines (WP248) defining nine criteria, meeting at least two of them generally triggers a DPIA.
Content (Art. 35(7) GDPR): systematic description of the envisaged processing operations and purposes; assessment of necessity and proportionality; assessment of the risks to the rights and freedoms; envisaged remedial measures.
Consultation of the Data Protection Officer (Art. 35(2) GDPR). The DPO must be consulted as part of the DPIA.
Prior consultation of the supervisory authority (Art. 36 GDPR). If the DPIA indicates that the processing would result in a high risk despite the measures envisaged, the supervisory authority must be consulted beforehand. The authority responds within eight weeks (extendable by six weeks).
Relationship to the DSG DPIA. A DPIA under Art. 35 GDPR can generally be re-used for the DPIA under Art. 22 DSG, provided that Swiss specificities (in particular the broader category of sensitive data under Art. 5(c) DSG) are added.
Data Protection Officer (Art. 37–39 GDPR)
The Data Protection Officer (DPO) is the formally designated function that monitors and advises on GDPR compliance within the organisation. Unlike the Swiss Data Protection Adviser under Art. 10 DSG, the designation is mandatory in defined cases.
Designation obligation (Art. 37(1) GDPR). A DPO must be designated where processing is carried out by a public authority or body (lit. a); where the core activities consist of regular and systematic monitoring of data subjects on a large scale (lit. b); where the core activities consist of large-scale processing of special categories under Art. 9 or criminal data under Art. 10 (lit. c).
National stricter rules. Member States may impose additional obligations. Germany requires designation under § 38 BDSG where at least 20 persons are permanently engaged in automated processing of personal data. Austria follows the GDPR threshold without additional requirements. Entities operating in several Member States must check the respective national thresholds.
Qualification (Art. 37(5) GDPR). Professional qualities, in particular expert knowledge of data protection law and practice, as well as the ability to perform the tasks under Art. 39 GDPR.
Position (Art. 38 GDPR). Early involvement in all data protection matters; provision of necessary resources; freedom from instructions; no disadvantage for performing the tasks; direct reporting to the highest management level; duty of secrecy; absence of conflicts of interest (e.g. with IT, HR or executive management).
Tasks (Art. 39 GDPR). Informing and advising; monitoring compliance; advising on the DPIA; cooperation with and acting as the contact point for the supervisory authority.
Internal or external. The DPO may be a staff member or an external service provider (Art. 37(6) GDPR). For Swiss companies with a GDPR nexus an external DPO is generally advisable, particularly where the Swiss and the European function are bundled in one person. SIDD provides the external DPO in personal union with the Swiss Data Protection Adviser and, where applicable, with the EU representative under Art. 27 GDPR.
EU Representative (Art. 27 GDPR), when required?
The EU Representative is the natural or legal person established in the Union whom a third-country controller or processor must designate in writing. The representative acts as the point of contact for supervisory authorities and data subjects. The function is governed by Art. 27 GDPR.
Mandatory designation (Art. 27(1) GDPR). An EU Representative must be designated where the controller or processor has no establishment in the Union and falls within the scope of Art. 3(2) GDPR (market principle).
Exemptions (Art. 27(2) GDPR). No designation is required for processing that is occasional, does not include large-scale processing of special categories or criminal data, and is unlikely to result in a risk to the rights and freedoms of natural persons taking into account the nature, context, scope and purposes. Public authorities and bodies are also exempt.
Who is affected. Swiss controllers without an EU establishment that fall within the market principle, typically:
- Swiss SaaS providers with EU customers;
- Swiss online retailers shipping to the EU;
- Swiss app providers with EU users;
- Swiss marketing platforms with EU tracking.
Seat of the representative (Art. 27(3) GDPR). In a Member State in which the data subjects whose data are processed are located. In practice, Swiss companies often choose Germany, Austria or Ireland.
Tasks. Contact point for supervisory authorities (Art. 27(4) GDPR); contact point for data subjects on all matters of processing; cooperation in maintaining the Art. 30 GDPR record. The EU Representative is not subsidiarily liable for the controller's infringements but may itself be the addressee of an administrative fine for breach of its own duties.
Designation. In writing, with clear responsibilities and accessibility. The designation must be made transparent in the privacy notice and in the Art. 30 GDPR record. SIDD provides the EU Representative under Art. 27 GDPR based in the EEA.
Notification of personal data breaches (Art. 33, 34 GDPR)
Articles 33 and 34 GDPR govern the notification duties in the event of a personal data breach. Notification to the supervisory authority follows Art. 33 GDPR; communication to data subjects follows Art. 34 GDPR. Both duties must be assessed independently of each other.
Notification to the supervisory authority (Art. 33 GDPR). The controller must notify the competent supervisory authority of a breach without undue delay and, where feasible, within 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification is delayed, the reasons for the delay must be provided.
Content of notification (Art. 33(3) GDPR): description of the nature of the breach including the categories and approximate number of data subjects and records concerned; contact details of the DPO or other point of contact; likely consequences; measures taken or proposed. Where not all information is immediately available, the notification may be provided in phases (Art. 33(4) GDPR).
Processor (Art. 33(2) GDPR). The processor notifies the controller of a breach without undue delay, the processor has no direct notification duty towards the supervisory authority.
Internal documentation (Art. 33(5) GDPR). All breaches must be documented internally, including the facts, effects and measures taken, regardless of whether a notification is made.
Communication to data subjects (Art. 34 GDPR). Where a breach is likely to result in a high risk, the data subject must be informed without undue delay, in clear and plain language, with the information referred to in Art. 33(3)(b), (c), (d). Exceptions apply where prior encryption renders the data unintelligible, subsequent measures mitigate the high risk, or communication would involve disproportionate effort (Art. 34(3) GDPR).
Difference from the DSG. The DSG under Art. 24 DSG does not impose a rigid 72-hour deadline but requires notification "as soon as possible", see the DSG guide. An entity subject to both regimes complies with the stricter GDPR deadline.
Practical recommendation. A documented incident-response process with clear escalation paths, a prepared notification template and a communications plan. The initial response is regularly fine-relevant.
International data transfers (Art. 44 et seq. GDPR, SCCs, Swiss adequacy 2024)
Articles 44 to 49 GDPR govern transfers of personal data to third countries and international organisations. The principle: a transfer is only permissible where the level of protection guaranteed by the GDPR is not undermined in the third country (Art. 44 GDPR).
Adequacy decision (Art. 45 GDPR). The European Commission may find that a third country ensures an adequate level of protection. Transfers to such countries do not require additional safeguards. Currently recognised countries include: Andorra, Argentina, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Uruguay, the United Kingdom, the United States (Data Privacy Framework), and, since 15 January 2024, the updated recognition of Switzerland in the new DSG context.
Appropriate safeguards (Art. 46 GDPR). In the absence of an adequacy decision, a transfer is only permitted with appropriate safeguards: Standard Contractual Clauses (SCCs) of the European Commission (current version: Commission Implementing Decision (EU) 2021/914 of 4 June 2021); Binding Corporate Rules (BCRs); approved codes of conduct (Art. 40); approved certification mechanisms (Art. 42).
Transfer Impact Assessment (TIA). Following the Schrems II ruling of the CJEU (C-311/18), where SCCs are used a third-country assessment is required to determine whether the SCCs are effectively enforceable in the recipient country. State access rights in particular must be evaluated. Where protection is insufficient, additional measures (technical, contractual, organisational) are required, or the transfer must be refrained from.
United States, EU-US Data Privacy Framework. Since the adequacy decision of 10 July 2023, transfers to US recipients certified under the DPF are permitted without SCCs. Non-certified recipients continue to require SCCs plus a TIA.
Switzerland, adequacy 2024. The European Commission confirmed Switzerland on 15 January 2024 with an updated adequacy decision. EU-to-Switzerland transfers are permitted without additional safeguards. Switzerland-to-EU transfers are in any event recognised as adequate under Art. 16 DSG.
Derogations (Art. 49 GDPR). Explicit consent, performance of a contract, important public interests, the establishment of legal claims, vital interests. To be construed restrictively.
Documentation. Each transfer must be recorded in the Art. 30 GDPR record together with the recipient country and the safeguard applied.
Sanctions and fines (Art. 83 GDPR)
Art. 83 GDPR governs administrative fines imposed by supervisory authorities. In contrast to the DSG, with its criminal sanction architecture against natural persons, the GDPR is primarily directed at the undertaking acting as controller or processor.
Fine tier 1 (Art. 83(4) GDPR). Up to EUR 10 million or 2 percent of the total worldwide annual turnover of the preceding financial year, whichever is higher. This tier applies in particular to infringements of the obligations of controllers and processors under Art. 8, 11, 25–39, 42, 43 GDPR (including the record-keeping duty, TOMs, notification, DPO designation, DPIA).
Fine tier 2 (Art. 83(5) GDPR). Up to EUR 20 million or 4 percent of the total worldwide annual turnover of the preceding financial year, whichever is higher. This tier applies in particular to infringements of the fundamental principles of processing (Art. 5, 6, 7, 9), the rights of data subjects (Art. 12–22), international data transfers (Art. 44–49) and orders of a supervisory authority.
Group turnover. Group turnover is the relevant reference where the individual controller forms part of an economic unit within the meaning of the CJEU's concept of an undertaking. This leads to very high potential fines, in particular for multinational groups.
Assessment criteria (Art. 83(2) GDPR). Nature, gravity and duration of the infringement; intentional or negligent character; measures taken to mitigate damage; degree of responsibility; relevant previous infringements; cooperation with the supervisory authority; categories of data; manner in which the infringement became known; compliance with measures previously ordered; approved codes of conduct or certifications; aggravating or mitigating factors.
Examples from practice. High fines in recent years have been imposed in particular on technology groups (Meta, Amazon, Google) in the three-digit million range. Such magnitudes are unrealistic for SMEs, EDPB Guidelines 04/2022 on the calculation of administrative fines calibrate the framework against turnover. Specific amounts depend on the individual case and on current supervisory authority practice.
Further consequences. Beyond the fine, controllers face injunctions, claims for damages under Art. 82 GDPR, as well as reputational damage and loss of contracts, in particular in B2B business with GDPR-sensitive sectors.
GDPR compliance checklist for SMEs (10 steps)
The following checklist summarises the steps with which a Swiss or DACH small and medium-sized enterprise (SME) builds a GDPR-compliant data protection organisation. It does not replace individual advice but serves as a structuring aid.
- Check applicability (Art. 3 GDPR). Establishment in the EU? Offering directed at persons in the EU? Behaviour monitoring? Where affirmative, the GDPR applies alongside the DSG.
- Inventory processing activities and prepare the Art. 30 GDPR record. HR files, customer and CRM data, applicant data, supplier data, marketing data, website tracking.
- Document the legal basis per processing operation (Art. 6, where applicable Art. 9 GDPR). Consent management (cookie consent tool), LIA for legitimate interests, separate consent documentation for special categories of data.
- Update the privacy notice under Art. 13, 14 GDPR. All mandatory disclosures, EU Representative, DPO, third-country transfers, data subject rights, right to lodge a complaint.
- Conclude data processing agreements under Art. 28 GDPR. With every processor, cloud, SaaS, marketing tools, payroll, hosting. Including third-country clauses (SCCs) and sub-processor lists.
- Document TOMs under Art. 32 GDPR. Ideally within the framework of an ISMS in accordance with ISO/IEC 27001 with certification by an accredited body (e.g. CIS Cert).
- Assess international data transfers. SCCs, BCRs or adequacy decision. TIA for every third country without an adequacy decision. Documentation in the record.
- Establish an incident-response process for Art. 33, 34 GDPR. 72-hour workflow, notification template, internal escalation, communications plan.
- Designate a DPO under Art. 37 GDPR where mandatory, or on a voluntary basis. For Swiss companies with a Swiss and an EU nexus, bundle Art. 10 DSG and Art. 37 GDPR. Plus an EU Representative under Art. 27 GDPR where there is no EU establishment.
- Data-subject-rights workflow (Art. 12–22 GDPR). Intake channel, identity verification, deadline tracking (one month), escalation to the DPO, documentation of the response.
How SIDD supports you on the GDPR
SIDD is the data protection and InfoSec brand of Priverion GmbH (Baar/ZG), founded in 2017. We take on mandates as external Data Protection Officer under Art. 37 GDPR for Swiss and international companies with an EU nexus, provide the EU Representative under Art. 27 GDPR based in the EEA, and prepare records, privacy notices, DPIAs and incident playbooks. For clients additionally subject to the Swiss DSG we bundle the functions in a single hand and leverage the synergies, details on Swiss law in the DSG guide. For ISO/IEC 27001 certification we work with CIS Cert (Quality Austria Group, ISO/IEC 17021-accredited). Talk to our data protection team about a tailored mandate.
