Swiss Data Protection Checklist: 28-Point DSG Self-Assessment
Introduction
This checklist is designed as a self-assessment: a managing director, an internal data-protection coordinator or an IT lead can run through it in 60-90 minutes and arrive at a reliable baseline. The 28 points cover the duties of the revised Federal Act on Data Protection (DSG, in force since 1 September 2023) along the seven compliance building blocks of records of processing, information, processor management, third countries, data-subject rights, security and data breaches, and indicate where the GDPR additionally applies.
The checklist does not replace a full audit but identifies the most common gaps that recurred across more than 200 SIDD mandate intakes in 2024-2025. After the self-assessment you have:
- a list of concrete open points per compliance building block;
- an initial prioritisation (Mandatory / High / Medium) for a remediation programme;
- an indication of whether an internal data-protection adviser under Art. 10 DSG makes sense;
- an overview of whether the GDPR additionally applies and which extra duties this triggers;
- the anchors needed to launch an external audit or mandate onboarding efficiently.
If you flag more than 5 points "red" at the end of the checklist, you should plan a 60-minute call with a data-protection specialist.
Block 1: records of processing and data map (points 1-4)
The records of processing under Art. 12 DSG are the foundation of any compliance programme. Without current records, neither the privacy policy, nor a DPIA, nor data-breach handling can be performed cleanly. The threshold for the records duty is 250 employees or processing of specially protected data / high-risk profiling, in practice we recommend the records to every SME from 10 employees, because evidence in any FDPIC procedure is hard to build without them.
- Records of processing exist and contain per processing activity: purpose, data categories, recipients, retention, and where applicable third-country transfers (Art. 12 para. 2 DSG in conjunction with Art. 24 DPO).
- Records reviewed within the last 12 months, typically on material tool, process or organisational changes.
- Data map available: a visualised view of data flows between systems (CRM, ERP, marketing tool, cloud storage), including interfaces.
- Records aligned with the privacy policy, recipients and purposes correspond; no tools in the policy that are missing from the records, and vice versa.
Common gap: marketing tools that marketing staff introduce on their own (newsletter service, analytics, heatmaps) appear neither in the records nor in the policy, and only surface during the audit.
Block 2: information and privacy policy (points 5-9)
Art. 19 DSG requires "adequate" information at every collection of personal data. The privacy policy is the central carrier of that information, but not the only one: at the point of collection (form, checkout) a notice with a link is additionally needed.
- Privacy policy in the footer of every page, in every published language, with a stable URL and a version stamp.
- Mandatory disclosures under Art. 19 paras. 2-4 DSG complete: identity/contact of the controller, purpose, recipient categories, third countries with safeguard. For indirect collection additionally data categories (Art. 19 para. 3 DSG).
- Profiling and automated individual decision explicitly named (Art. 21 DSG), where applicable.
- Cookie banner and privacy policy consistent, see Cookie banner Switzerland.
- Information "at collection": at the point of data collection (newsletter signup, contact form, application, checkout), a notice with a deep link into the privacy policy is integrated.
Common gap: application forms on job postings that contain no notice on processing, even though Art. 328b CO and Art. 19 DSG together form a mandatory set.
Block 3: DPAs and processor management (points 10-13)
Every processor under Art. 9 DSG needs a written DPA. The most common gaps are with "silent" processors, tools introduced by individual staff without a formal procurement process (shadow IT). A second frequent gap concerns sub-processing: who hosts the data of the newsletter tool? Who is the sub-cloud of the CRM provider?
- DPA inventory exists and contains all active processors with contract status, contract date, effective date and next review.
- Every DPA covers the mandatory contents, see Swiss DPA template: scope of processing, binding instructions, TOMs, sub-processing, audit rights, contract end with data return/deletion.
- Sub-processing documented: per processor a list of sub-cloud providers and third countries.
- Shadow IT identified: at least annual elicitation with business units on which tools are actually used, reconciled with the DPA inventory.
Tip: a simple shadow-IT indicator is a comparison of department credit-card statements against the DPA inventory. What shows up in the marketing budget as a SaaS line but has no DPA is shadow IT.
Block 4: third countries and EU representative (points 14-17)
Third-country transfers are the largest source of gaps in over 60 % of SIDD mandate intakes in 2024-2025. The most frequent constellation: a US SaaS tool without Swiss-U.S. DPF certification and without SCCs.
- List of all third-country recipients exists with country, safeguard (adequacy, Swiss-U.S. DPF, SCCs, BCRs) and date of last review.
- US recipients without active DPF certification have SCCs, typically the FDPIC-recognised version of 27 August 2021.
- GDPR applicability checked (marketplace principle Art. 3(2) GDPR): do you actively ship into the EU, address EU customers in their language, track EU users with cookies?
- If the GDPR applies: Art. 27 GDPR EU representative appointed, with address in the privacy policy and an active mandate contract (see EU representative).
Frequent follow-on error: those who name the EU representative only after a complaint have a documented compliance failure for the period in between, a typical "easy win" for an EU supervisory authority.
Block 5: data-subject rights, DPIA, security (points 18-23)
Data-subject rights (Art. 25-32 DSG) must be operationalised, not merely announced in the privacy policy. Anyone who receives an access request has 30 days (Art. 25 para. 7 DSG), and needs a person, a tool and a workflow.
- Dedicated e-mail channel for data-protection requests ([email protected] or equivalent), with internal escalation routing.
- Access process documented: identity check, data search across all systems, redaction (third-party references), delivery, logging.
- DPIA process established: triggers under Art. 22 DSG (high risk, particularly with profiling, sensitive data, new technologies) are catalogued; procedure with risk analysis and remediation plan in place.
- TOMs under Art. 8 DSG documented: encryption in transit and at rest, access control, backup, patch management, logging, ideally mapped to ISO 27001 Annex A:2022 (see ISO 27001 checklist).
- MFA for administrative access to databases, cloud consoles, mailboxes.
- Data-protection training at least annually, documented and with a knowledge check.
Tip: training without a knowledge check is not robust in an FDPIC procedure, a simple 10-question test per year suffices.
Block 6: data breaches and governance (points 24-28)
The 72-hour deadline in Art. 24 DSG is a hard deadline and starts with awareness of a data-security breach with high risk. Reporting the incident to the FDPIC days late risks a supervisory procedure, details in our article Report a data breach to the FDPIC.
- Incident response plan exists with escalation matrix, triage criteria (high risk yes/no), templates for FDPIC notification and, where applicable, communication to data subjects.
- Data-breach log maintained: every incident (including non-notifiable ones) documented with date, description, cause, measures.
- Tabletop exercise in the last 12 months: a realistic scenario played through, 72-hour deadline met.
- Data-protection lead appointed (internal or external as DSB under Art. 10 DSG); with a GDPR nexus additionally a DPO under Art. 37 GDPR.
- Annual report from the data-protection adviser with status, actions taken and budget proposal for the coming year, exonerating for the adviser and decision-relevant for management.
Anyone scoring less than 3 of 5 in this block has a structural governance gap that typically becomes more expensive in a damage case than the investment in building it up.
How SIDD supports you
SIDD offers this 28-point self-assessment as an interactive online version with automated evaluation via our contact form, you then receive a PDF evaluation with prioritisation and remediation proposal. Anyone with more than 5 "red" points should plan a 60-minute deep-dive call; with more than 10 red points we recommend uptake into a full compliance programme.
Operationally we bundle gap closure typically in a DSB mandate with the Priverion platform for records, DPA inventory and privacy policy. GDPR-bound companies get additional GDPR DPO services and an EU representative. For a concrete fixed-price quote to close the gaps from your self-assessment, use the quote request. A data-protection workshop for management and key stakeholders is bookable separately at Data-protection workshop SME.
