Swiss Data Protection Checklist: 28-Point DSG Self-Assessment

6 min readLast updated By Marc Grob

Introduction

This checklist is designed as a self-assessment: a managing director, an internal data-protection coordinator or an IT lead can run through it in 60-90 minutes and arrive at a reliable baseline. The 28 points cover the duties of the revised Federal Act on Data Protection (DSG, in force since 1 September 2023) along the seven compliance building blocks of records of processing, information, processor management, third countries, data-subject rights, security and data breaches, and indicate where the GDPR additionally applies.

The checklist does not replace a full audit but identifies the most common gaps that recurred across more than 200 SIDD mandate intakes in 2024-2025. After the self-assessment you have:

  • a list of concrete open points per compliance building block;
  • an initial prioritisation (Mandatory / High / Medium) for a remediation programme;
  • an indication of whether an internal data-protection adviser under Art. 10 DSG makes sense;
  • an overview of whether the GDPR additionally applies and which extra duties this triggers;
  • the anchors needed to launch an external audit or mandate onboarding efficiently.

If you flag more than 5 points "red" at the end of the checklist, you should plan a 60-minute call with a data-protection specialist.

Block 1: records of processing and data map (points 1-4)

The records of processing under Art. 12 DSG are the foundation of any compliance programme. Without current records, neither the privacy policy, nor a DPIA, nor data-breach handling can be performed cleanly. The threshold for the records duty is 250 employees or processing of specially protected data / high-risk profiling, in practice we recommend the records to every SME from 10 employees, because evidence in any FDPIC procedure is hard to build without them.

  1. Records of processing exist and contain per processing activity: purpose, data categories, recipients, retention, and where applicable third-country transfers (Art. 12 para. 2 DSG in conjunction with Art. 24 DPO).
  2. Records reviewed within the last 12 months, typically on material tool, process or organisational changes.
  3. Data map available: a visualised view of data flows between systems (CRM, ERP, marketing tool, cloud storage), including interfaces.
  4. Records aligned with the privacy policy, recipients and purposes correspond; no tools in the policy that are missing from the records, and vice versa.

Common gap: marketing tools that marketing staff introduce on their own (newsletter service, analytics, heatmaps) appear neither in the records nor in the policy, and only surface during the audit.

Block 2: information and privacy policy (points 5-9)

Art. 19 DSG requires "adequate" information at every collection of personal data. The privacy policy is the central carrier of that information, but not the only one: at the point of collection (form, checkout) a notice with a link is additionally needed.

  1. Privacy policy in the footer of every page, in every published language, with a stable URL and a version stamp.
  2. Mandatory disclosures under Art. 19 paras. 2-4 DSG complete: identity/contact of the controller, purpose, recipient categories, third countries with safeguard. For indirect collection additionally data categories (Art. 19 para. 3 DSG).
  3. Profiling and automated individual decision explicitly named (Art. 21 DSG), where applicable.
  4. Cookie banner and privacy policy consistent, see Cookie banner Switzerland.
  5. Information "at collection": at the point of data collection (newsletter signup, contact form, application, checkout), a notice with a deep link into the privacy policy is integrated.

Common gap: application forms on job postings that contain no notice on processing, even though Art. 328b CO and Art. 19 DSG together form a mandatory set.

Block 3: DPAs and processor management (points 10-13)

Every processor under Art. 9 DSG needs a written DPA. The most common gaps are with "silent" processors, tools introduced by individual staff without a formal procurement process (shadow IT). A second frequent gap concerns sub-processing: who hosts the data of the newsletter tool? Who is the sub-cloud of the CRM provider?

  1. DPA inventory exists and contains all active processors with contract status, contract date, effective date and next review.
  2. Every DPA covers the mandatory contents, see Swiss DPA template: scope of processing, binding instructions, TOMs, sub-processing, audit rights, contract end with data return/deletion.
  3. Sub-processing documented: per processor a list of sub-cloud providers and third countries.
  4. Shadow IT identified: at least annual elicitation with business units on which tools are actually used, reconciled with the DPA inventory.

Tip: a simple shadow-IT indicator is a comparison of department credit-card statements against the DPA inventory. What shows up in the marketing budget as a SaaS line but has no DPA is shadow IT.

Block 4: third countries and EU representative (points 14-17)

Third-country transfers are the largest source of gaps in over 60 % of SIDD mandate intakes in 2024-2025. The most frequent constellation: a US SaaS tool without Swiss-U.S. DPF certification and without SCCs.

  1. List of all third-country recipients exists with country, safeguard (adequacy, Swiss-U.S. DPF, SCCs, BCRs) and date of last review.
  2. US recipients without active DPF certification have SCCs, typically the FDPIC-recognised version of 27 August 2021.
  3. GDPR applicability checked (marketplace principle Art. 3(2) GDPR): do you actively ship into the EU, address EU customers in their language, track EU users with cookies?
  4. If the GDPR applies: Art. 27 GDPR EU representative appointed, with address in the privacy policy and an active mandate contract (see EU representative).

Frequent follow-on error: those who name the EU representative only after a complaint have a documented compliance failure for the period in between, a typical "easy win" for an EU supervisory authority.

Block 5: data-subject rights, DPIA, security (points 18-23)

Data-subject rights (Art. 25-32 DSG) must be operationalised, not merely announced in the privacy policy. Anyone who receives an access request has 30 days (Art. 25 para. 7 DSG), and needs a person, a tool and a workflow.

  1. Dedicated e-mail channel for data-protection requests ([email protected] or equivalent), with internal escalation routing.
  2. Access process documented: identity check, data search across all systems, redaction (third-party references), delivery, logging.
  3. DPIA process established: triggers under Art. 22 DSG (high risk, particularly with profiling, sensitive data, new technologies) are catalogued; procedure with risk analysis and remediation plan in place.
  4. TOMs under Art. 8 DSG documented: encryption in transit and at rest, access control, backup, patch management, logging, ideally mapped to ISO 27001 Annex A:2022 (see ISO 27001 checklist).
  5. MFA for administrative access to databases, cloud consoles, mailboxes.
  6. Data-protection training at least annually, documented and with a knowledge check.

Tip: training without a knowledge check is not robust in an FDPIC procedure, a simple 10-question test per year suffices.

Block 6: data breaches and governance (points 24-28)

The 72-hour deadline in Art. 24 DSG is a hard deadline and starts with awareness of a data-security breach with high risk. Reporting the incident to the FDPIC days late risks a supervisory procedure, details in our article Report a data breach to the FDPIC.

  1. Incident response plan exists with escalation matrix, triage criteria (high risk yes/no), templates for FDPIC notification and, where applicable, communication to data subjects.
  2. Data-breach log maintained: every incident (including non-notifiable ones) documented with date, description, cause, measures.
  3. Tabletop exercise in the last 12 months: a realistic scenario played through, 72-hour deadline met.
  4. Data-protection lead appointed (internal or external as DSB under Art. 10 DSG); with a GDPR nexus additionally a DPO under Art. 37 GDPR.
  5. Annual report from the data-protection adviser with status, actions taken and budget proposal for the coming year, exonerating for the adviser and decision-relevant for management.

Anyone scoring less than 3 of 5 in this block has a structural governance gap that typically becomes more expensive in a damage case than the investment in building it up.

How SIDD supports you

SIDD offers this 28-point self-assessment as an interactive online version with automated evaluation via our contact form, you then receive a PDF evaluation with prioritisation and remediation proposal. Anyone with more than 5 "red" points should plan a 60-minute deep-dive call; with more than 10 red points we recommend uptake into a full compliance programme.

Operationally we bundle gap closure typically in a DSB mandate with the Priverion platform for records, DPA inventory and privacy policy. GDPR-bound companies get additional GDPR DPO services and an EU representative. For a concrete fixed-price quote to close the gaps from your self-assessment, use the quote request. A data-protection workshop for management and key stakeholders is bookable separately at Data-protection workshop SME.

Need help putting this into practice? SIDD operates the matching service.
See service →

Swiss Data Protection Checklist: 28-Point DSG Self-Assessment

INSIGHT

Data Protection
24 May 2026
Marc Grob
Data protection checklist for Swiss SMEs: 28 points on records, privacy notice, processors, third countries, security and data breaches.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.