GDPR Explained, The 12 Most Important Obligations
Introduction
The General Data Protection Regulation (GDPR) has been in force since May 2018, yet many Swiss companies with EU exposure do not fail individual provisions but the question of which duties actually have to land in daily operations. We have condensed the regulation's roughly 99 articles into twelve operational obligation clusters that must be visible in every compliance programme. The selection follows the logic of the supervisory authorities: it mirrors what the Federal Data Protection and Information Commissioner (FDPIC / EDÖB), CNIL, BayLDA and Garante have actually asked for in recent enforcement.
For each cluster this article explains the legal basis, the typical pitfall and the concrete deliverable that satisfies an external review. We cover:
- The principles under Art. 5 GDPR and the accountability rule
- Legal bases under Art. 6 and 9 GDPR
- Transparency duties under Art. 13 and 14 GDPR
- Data subject rights under Art. 15 to 22 GDPR
- Controller accountability, privacy by design and the record of processing (Art. 24, 25, 30)
- Security, breach notification, DPIA, DPO, third-country transfers (Art. 32, 33, 35, 37, 44 et seq.)
The order maps an implementation path: starting at the top leaves fewer gaps at the bottom. Anyone who begins with the record of processing (cluster 8) without first clarifying the legal bases (cluster 2) will land back at the starting point in every audit.
Obligations 1 and 2, Principles and lawful basis
Art. 5 GDPR defines six principles that every single processing must respect: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. On top sits the accountability principle in Art. 5(2), which obliges the controller to demonstrate compliance at any time. In enforcement, this principle is regularly used to double the fine if no evidence can be produced within a few weeks.
The second duty is the clean assignment of a legal basis under Art. 6(1) GDPR. In practice, consent works far less often than assumed, it is freely revocable under Art. 7 and rarely truly voluntary in an employment context. We recommend the following heuristic:
- Processing for contract performance: lit. b
- Accounting, tax, social security: lit. c (legal obligation)
- Marketing, web analytics, profiling: lit. f (legitimate interest with documented LIA) or lit. a (consent via banner)
- Special categories under Art. 9: only via the narrow exceptions, typically explicit consent or health and social legislation
For each processing, the chosen legal basis belongs in the record of processing, and for lit. f a Legitimate Interest Assessment belongs in the annex. Without it, the processing will be treated as unlawful in a dispute, triggering deletion and damages exposure.
Obligations 3 and 4, Transparency and data subject rights
Art. 13 and 14 GDPR demand complete information to data subjects at the point of collection. The mandatory list is long: identity of the controller, contact details of the DPO, purposes, legal bases, recipients, third-country transfers including safeguards, retention periods, all rights, the right to complain to a supervisory authority and, if applicable, the logic of any automated decision-making under Art. 22. A bare cookie policy has not been enough for years; what is needed is a modular, layered privacy notice with one entry per processing scenario.
The fourth duty is the operational handling of data subject rights under Art. 15 to 22 GDPR: access, rectification, erasure, restriction, portability, objection and the right not to be subject to a solely automated decision. Under Art. 12(3), the response window is one month by default, extendable by two months for complex requests. Operationally, you need a documented workflow with identity verification (no name-matching without cause), searches across all systems including backup indices, redaction of third-party data and a four-eyes release. Anyone without this standardised chain risks six-figure fines, in our experience, the right of access is the single most common trigger for CNIL and BayLDA proceedings.
Obligations 5 and 6, Accountability and privacy by design
Art. 24 GDPR requires the controller to take appropriate technical and organisational measures and to demonstrate their effectiveness. This is not decorative wording: in enforcement, authorities regularly test whether policies are actually lived, meaning training records, audit logs and spot checks must exist. We recommend an annual Management Review that bundles all relevant KPIs (open access requests, breach reports, training coverage, audit findings) and is signed off at board level.
The sixth duty is privacy by design and by default under Art. 25 GDPR. Privacy must be thought into every product development process, not bolted on later. In agile teams, the following pattern works:
- Privacy threat modelling inside the design sprint
- Privacy requirements written as user stories with acceptance criteria
- Privacy reviews as part of the Definition of Done
- Automated compliance checks in the CI/CD pipeline (secrets, logging filters, pseudonymisation)
By default, settings must be restrictive: tracking off, profiles private, newsletter opt-in empty. Anyone forced to retrofit privacy by design typically pays five to ten times the original implementation cost.
Obligations 7 and 8, Processor contracts and records of processing
As soon as you use an external provider that processes personal data on your behalf, Art. 28 GDPR applies. You need a written data processing agreement (DPA) with the minimum content listed in para. 3, instructions, confidentiality, TOMs, sub-processors, support for data subject rights, deletion or return after the contract ends, audit rights. A generic NDA is not a DPA. Pay particular attention to US cloud providers: here the DPA is only one component, and the third-country safeguards under Chapter V (see cluster 12) come on top.
The eighth duty is the record of processing activities under Art. 30 GDPR. It is the backbone of every compliance file and the first document supervisory authorities ask for. Mandatory contents include:
- Controller and DPO (with contact details)
- Purposes of processing
- Categories of data subjects and categories of data
- Categories of recipients
- Third-country transfers including safeguards
- Retention periods per data category
- General description of the TOMs
In practice we build process-oriented entries (one row per business process), not system-oriented ones. This keeps maintenance manageable and makes later linkage to DPIAs and the risk register much easier.
Obligations 9 and 10, Security and breach notification
Art. 32 GDPR requires risk-appropriate security, explicitly naming pseudonymisation, encryption, confidentiality, integrity, availability, resilience and regular testing. Supervisors typically accept ISO/IEC 27001 or equivalent frameworks (BSI IT-Grundschutz, CIS Controls v8, NIST CSF) as evidence. Without a structured ISMS, you should at least maintain a TOM matrix mapping each measure to a data category and quantifying the residual risk.
The tenth duty is the notification of personal data breaches. Under Art. 33 GDPR, the supervisory authority must be informed within 72 hours unless the risk to data subjects is exceptionally low. The clock starts at the moment of awareness understood as reasonable certainty, not after full forensic confirmation. Data subjects must be informed under Art. 34 as soon as a high risk exists (mass clear-text data, special categories, identity-theft potential). Operationally you need:
- A 24/7 reporting chain with a clear escalation matrix
- A prepared notification template (DE and EN)
- Forensic readiness contracts with short SLAs
- An internal breach register under Art. 33(5)
Caveat: Swiss companies face a double notification duty, to the EU authority under GDPR and to the FDPIC under Art. 24 DSG. Both clocks run in parallel.
Obligations 11 and 12, DPIA, DPO and third-country transfers
The eleventh duty bundles Art. 35 and 37 GDPR. A data protection impact assessment (DPIA) is required when processing is likely to result in a high risk, the EDPB list of nine criteria is the practical starting point. Typical triggers are systematic public-space monitoring, large-scale processing of special categories, AI-based scoring systems and employee surveillance. A DPIA covers description, necessity and proportionality test, risk analysis and mitigation. Without it, the processing is formally unlawful even when every other requirement is met.
The duty to appoint a Data Protection Officer follows from Art. 37 GDPR for core activities of systematic monitoring or large-scale processing of special categories. Swiss companies without an EU establishment often appoint a DPO voluntarily, because the DSG advisor role under Art. 10 DSG has similar functions and strengthens market posture towards EU clients.
The twelfth and hardest-to-control duty is third-country transfers under Chapter V. After Schrems II, SCCs alone are no longer sufficient, they require a Transfer Impact Assessment (TIA) with an evaluation of the recipient country and, where needed, additional measures such as encryption with key custody inside the EU. Since 2023 the EU-US Data Privacy Framework helps for the United States, but only for certified recipients and only as long as the framework is not invalidated again.
How SIDD supports you
SIDD operationalises these twelve duties as a complete package or modularly. Our GDPR DPO mandates combine the legal DPO role under Art. 37 with a running compliance backbone: we maintain your record of processing, run DPIAs, answer access requests, train business units and represent you before supervisory authorities. For companies without an EU establishment we additionally serve as the EU representative under Art. 27 GDPR and, where there is UK exposure, as the UK representative. Where the primary processing footprint is Swiss, the combination with our Swiss data protection advisory is the natural fit.
Operational onboarding typically runs as an eight-week GAP assessment sprint, followed by a roadmap across the twelve clusters. For ongoing team enablement we provide privacy workshops. If you would first like a baseline, arrange an initial call via our contact form or request an offer, we deliver a fixed-price proposal within five working days that clearly sets out scope, effort and service levels.
