Swiss Data Protection Advisor, Duty, Role, Skill Profile
Introduction
Since the DSG entered into force on 1 September 2023, the Swiss data protection advisor role has been anchored in Art. 10 DSG. Unlike the EU Data Protection Officer (DPO) under Art. 37 et seq. GDPR, the role is voluntary in Switzerland, but it is linked to a concrete procedural advantage and is practically essential in many constellations. Underestimating the role means foregoing a valuable function in the compliance architecture and risking an inability to discharge the burden of proof in an incident.
This article provides the essentials for the decide-or-not question and for selecting the right person or function:
- Art. 10 DSG in detail and its differences from the GDPR;
- tasks and responsibilities of the advisor in daily operations;
- expected skill profile (legal, technical, organisational, methodological);
- reporting line to the supervisory board and structural independence;
- personal liability for fines under Art. 60 et seq. DSG;
- the choice between in-house and external solution.
Targets are executive boards, supervisory boards, HR and compliance leads aiming to set up or re-issue a DPO mandate. The complementary article on the operational external model is at External Data Protection Officer Switzerland.
Art. 10 DSG in detail
Art. 10 DSG governs the appointment of a data protection advisor by private controllers. Four elements shape the provision:
Voluntariness: Unlike the GDPR, Swiss law contains no appointment duty, neither for public bodies nor for private companies, not even for large-scale processing of sensitive personal data. This liberality was contested in the legislative process and remains so; it reflects the Swiss tradition of self-regulation.
Requirements on the person: The advisor must possess the necessary expertise. The statute does not further specify, but the Federal Council message and FDPIC practice point to legal knowledge of data protection law, organisational understanding and ideally a basic technical grasp.
Independence: The advisor is not bound by instructions in performing their duties and must be in a position to act independently. They may not take on tasks that are incompatible with their advisor duties (no conflict of interest).
Notification to the FDPIC: The controller files the advisor's contact details with the FDPIC. This serves transparency, the FDPIC keeps a list of appointed advisors which it uses as the contact point in proceedings.
The central procedural advantage: where a Data Protection Impact Assessment (DPIA) reveals high residual risk despite measures, the controller can dispense with the FDPIC consultation under Art. 23(4) DSG if the advisor was involved and supports the residual-risk assessment. That saves up to two months per project. For organisations with frequent data-protection-relevant projects (marketing platforms, AI deployments, cloud migrations), this is a major speed advantage.
Practical reasons to appoint
Independently of the procedural benefit, several practical reasons argue for appointing an advisor, even in non-mandatory constellations:
- Clear responsibility: Data protection questions need an addressee. Without a named role, access requests, complaints and authority correspondence land on shifting desks.
- External compliance signal: Customers, contracting partners, investors and auditors expect a DPO. The absence is regularly treated as a maturity deficit in tenders and due diligence.
- Risk reduction for the board: Personal fine addressing under Art. 60 DSG lands on executive management by default. An appointed advisor with a clearly documented mandate shifts operational responsibilities and creates a substantial defence line.
- Insurance requirements: Cyber policies increasingly require a designated data protection function as a condition for full cover.
- Contractual obligations: DPAs with larger contracting partners (particularly B2B) routinely contain an obligation to maintain a data protection advisor.
- Group efficiency: If the parent already maintains a DPO/advisor, appointment in the subsidiaries is a consistent complement.
In sectors such as law firms, trust companies, medical practices, hospitals, insurers, online shops and SaaS providers, appointment is de facto standard even where not mandatory. Anyone abstaining here stands out negatively, with all the consequences for customer acquisition and audit performance.
Tasks in daily operations
The advisor's tasks are outlined in Art. 10(2) DSG and refined by administrative practice. Seven core blocks shape operational reality:
- Advisory and training: First point of contact for data protection questions across functions. Training for the board, staff, IT, marketing, sales. At least annually.
- Processing register: Build, maintenance and annual review of the register under Art. 12 DSG. Ensures new processing operations are registered.
- Data Protection Impact Assessments (DPIA): Steering and sign-off on DPIAs for high-risk processing (AI, biometrics, profiling, tracking).
- Access and rectification requests: Inbound channel, triage, response within 30 days (Art. 25 DSG), escalation on refusals.
- Data breaches: Triage, risk assessment, support for the FDPIC notification under Art. 24 DSG, communication with data subjects.
- Contract review: DPAs with processors, cross-border transfer assessments, EU SCC, Swiss-US DPF.
- Reporting: At least annually to the board, semi-annually or quarterly in higher-complexity environments. Contents: status report, open findings, risk picture, action plan.
On top come special tasks: audit support (customer audits, ISO 27701 certification), regulatory proceedings (FDPIC correspondence), project advisory (marketing campaigns, AI use, M&A transactions). On average a mid-size Swiss SME requires 8–20 hours per month, with peaks during projects and incidents.
Skill profile and qualifications
The FDPIC does not expect a formal diploma but documented expertise, experience and continuing education. In practice the following profile has become established:
- Legal foundation: Solid knowledge of the DSG, the DSV, the GDPR and relevant sectoral sources (FINMA, KVG, BÜPF, ISG). Ideally a law degree or equivalent experience (e.g. CAS Data Protection Law).
- Basic technical understanding: Security architectures, cloud models, authentication, pseudonymisation, encryption. The advisor must be able to talk on a level with IT architects without being an architect.
- Organisational methodology: Building the processing register, risk analyses, structured DPIAs, delivering training. Experience with ISO 27001, ISO 27701 or NIST CSF is an asset.
- Communication: Board-grade explanation, negotiation with IT, collaboration with marketing, correspondence with authorities. The ability to say No and to enforce it.
- Languages: German and English required; French in Romandie mandates an asset.
- Certifications: CIPP/E, CIPM, IAPP membership, CAS Data Protection HSG/ZHAW/HSLU are established markers.
- Sector experience: Particularly in regulated sectors (health, finance, insurance), sector knowledge makes the difference.
Important: the profile is broad but realistic. Nobody brings all points at peak level. What matters is the combination of a solid foundation with access to specialised expertise, in the external model typically in a team, in the in-house model through training and external sparring.
Reporting line and independence
Independence is not only a personal but also an organisational embedding question. Three structures dominate practice:
Staff function reporting to executive management: The in-house advisor reports directly to CEO or COO, is not anchored in IT (no conflict with IT projects) and not in HR (no conflict with personnel files). The gold standard.
Compliance officer with dual role: In smaller companies the compliance or legal officer takes the advisor function. Works as long as the functions are cleanly separated and no conflict arises.
External advisor: Structurally the most independent variant; see our article on the external advisor model.
What never works: advisor function with the head of IT, the head of marketing or the head of sales. The structural conflicts are too apparent; the FDPIC regularly views them negatively. The advisor function with the managing director is also problematic because they then control themselves.
The reporting line should be captured in a written role description, including direct access to the supervisory board for critical findings. This clause is a compliance standard regularly tested by auditors. Its absence suggests the advisor is politically isolated, a weak spot in any serious audit.
Liability and personal risk
The DSG fines structure (Art. 60 et seq.) addresses the responsible natural person as a matter of principle. If no specific person is appointed, criminal-prosecution authorities can target executive management, usually the CEO. Depending on the facts, the advisor can be addressed as the responsible person if operational steering of data protection was clearly assigned to them.
Four consequences for mandate design follow:
- Clear written allocation of responsibility: Who decides what, who recommends what, who documents what. Role description and delegation matrix.
- D&O insurance with a data protection module: Classic D&O often does not cover data protection fines. Review whether an extended wording or a stand-alone cyber policy is required.
- Evidence trail of own recommendations: The advisor documents in writing what they recommended. If the board does not follow the recommendation, the risk lies with them, not the advisor.
- Exit option: An advisor who is routinely overridden must be able to lay down the function without contractual strangulation. In the external model this is easier (mandate termination); in-house it requires clean employment-law constructions.
In practice personal fine addressing has become rare, most FDPIC proceedings end with recommendations and rulings, not criminal denunciations. Yet preventive defence construction is mandatory because no time remains in an incident.
How SIDD supports you
SIDD offers two complementary solutions for the advisor function: full external takeover as Swiss data protection advisor with clear mandate, defined SLAs and FDPIC notification of your function; or support of your in-house advisor as sparring partner with training, methodology and escalation back-up. Both models integrate on request the EU DPO function and the Art. 27 EU representation.
For organisational depth we add privacy workshops for SMEs (annual mandatory training), the build of an ISMS to ISO 27001 for the security side, and CISO/ISB mandates where cyber security needs its own operational profile.
Write to us via the contact form or request a quote. We respond within one business day with a concrete mandate proposal that names the optimal structure (in-house, external, hybrid) for your size and risk profile.
