# Swiss Data Protection Checklist: 28-Point DSG Self-Assessment

> Data protection checklist for Swiss SMEs: 28 points on records, privacy notice, processors, third countries, security and data breaches.

- Source: https://www.sidd.swiss/en/insights/swiss-data-protection-checklist/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

This checklist is designed as a self-assessment: a managing director, an internal data-protection coordinator or an IT lead can run through it in 60-90 minutes and arrive at a reliable baseline. The 28 points cover the duties of the revised Federal Act on Data Protection (DSG, in force since 1 September 2023) along the seven compliance building blocks of records of processing, information, processor management, third countries, data-subject rights, security and data breaches, and indicate where the GDPR additionally applies.

The checklist does not replace a full audit but identifies the most common gaps that recurred across more than 200 SIDD mandate intakes in 2024-2025. After the self-assessment you have:

- a list of concrete open points per compliance building block;
- an initial prioritisation (Mandatory / High / Medium) for a remediation programme;
- an indication of whether an internal data-protection adviser under Art. 10 DSG makes sense;
- an overview of whether the GDPR additionally applies and which extra duties this triggers;
- the anchors needed to launch an external audit or mandate onboarding efficiently.

If you flag more than 5 points "red" at the end of the checklist, you should plan a 60-minute call with a data-protection specialist.

## Block 1: records of processing and data map (points 1-4)

The records of processing under Art. 12 DSG are the foundation of any compliance programme. Without current records, neither the privacy policy, nor a DPIA, nor data-breach handling can be performed cleanly. The threshold for the records duty is 250 employees or processing of specially protected data / high-risk profiling, in practice we recommend the records to every SME from 10 employees, because evidence in any FDPIC procedure is hard to build without them.

1. **Records of processing exist** and contain per processing activity: purpose, data categories, recipients, retention, and where applicable third-country transfers (Art. 12 para. 2 DSG in conjunction with Art. 24 DPO).
2. **Records reviewed within the last 12 months**, typically on material tool, process or organisational changes.
3. **Data map available**: a visualised view of data flows between systems (CRM, ERP, marketing tool, cloud storage), including interfaces.
4. **Records aligned with the privacy policy**, recipients and purposes correspond; no tools in the policy that are missing from the records, and vice versa.

Common gap: marketing tools that marketing staff introduce on their own (newsletter service, analytics, heatmaps) appear neither in the records nor in the policy, and only surface during the audit.

## Block 2: information and privacy policy (points 5-9)

Art. 19 DSG requires "adequate" information at every collection of personal data. The privacy policy is the central carrier of that information, but not the only one: at the point of collection (form, checkout) a notice with a link is additionally needed.

1. **Privacy policy in the footer of every page**, in every published language, with a stable URL and a version stamp.
2. **Mandatory disclosures under Art. 19 paras. 2-4 DSG complete**: identity/contact of the controller, purpose, recipient categories, third countries with safeguard. For indirect collection additionally data categories (Art. 19 para. 3 DSG).
3. **Profiling and automated individual decision explicitly named** (Art. 21 DSG), where applicable.
4. **Cookie banner and privacy policy consistent**, see [Cookie banner Switzerland](https://www.sidd.swiss/einblicke/cookie-banner-schweiz).
5. **Information "at collection"**: at the point of data collection (newsletter signup, contact form, application, checkout), a notice with a deep link into the privacy policy is integrated.

Common gap: application forms on job postings that contain no notice on processing, even though Art. 328b CO and Art. 19 DSG together form a mandatory set.

## Block 3: DPAs and processor management (points 10-13)

Every processor under Art. 9 DSG needs a written DPA. The most common gaps are with "silent" processors, tools introduced by individual staff without a formal procurement process (shadow IT). A second frequent gap concerns sub-processing: who hosts the data of the newsletter tool? Who is the sub-cloud of the CRM provider?

1. **DPA inventory exists** and contains all active processors with contract status, contract date, effective date and next review.
2. **Every DPA covers the mandatory contents**, see [Swiss DPA template](https://www.sidd.swiss/einblicke/avv-auftragsbearbeitungsvertrag-schweiz): scope of processing, binding instructions, TOMs, sub-processing, audit rights, contract end with data return/deletion.
3. **Sub-processing documented**: per processor a list of sub-cloud providers and third countries.
4. **Shadow IT identified**: at least annual elicitation with business units on which tools are actually used, reconciled with the DPA inventory.

Tip: a simple shadow-IT indicator is a comparison of department credit-card statements against the DPA inventory. What shows up in the marketing budget as a SaaS line but has no DPA is shadow IT.

## Block 4: third countries and EU representative (points 14-17)

Third-country transfers are the largest source of gaps in over 60 % of SIDD mandate intakes in 2024-2025. The most frequent constellation: a US SaaS tool without Swiss-U.S. DPF certification and without SCCs.

1. **List of all third-country recipients exists** with country, safeguard (adequacy, Swiss-U.S. DPF, SCCs, BCRs) and date of last review.
2. **US recipients without active DPF certification have SCCs**, typically the FDPIC-recognised version of 27 August 2021.
3. **GDPR applicability checked** (marketplace principle Art. 3(2) GDPR): do you actively ship into the EU, address EU customers in their language, track EU users with cookies?
4. **If the GDPR applies: Art. 27 GDPR EU representative appointed**, with address in the privacy policy and an active mandate contract (see [EU representative](https://www.sidd.swiss/en/services/eu-representative)).

Frequent follow-on error: those who name the EU representative only after a complaint have a documented compliance failure for the period in between, a typical "easy win" for an EU supervisory authority.

## Block 5: data-subject rights, DPIA, security (points 18-23)

Data-subject rights (Art. 25-32 DSG) must be operationalised, not merely announced in the privacy policy. Anyone who receives an access request has 30 days (Art. 25 para. 7 DSG), and needs a person, a tool and a workflow.

1. **Dedicated e-mail channel for data-protection requests** (privacy@company.ch or equivalent), with internal escalation routing.
2. **Access process documented**: identity check, data search across all systems, redaction (third-party references), delivery, logging.
3. **DPIA process established**: triggers under Art. 22 DSG (high risk, particularly with profiling, sensitive data, new technologies) are catalogued; procedure with risk analysis and remediation plan in place.
4. **TOMs under Art. 8 DSG documented**: encryption in transit and at rest, access control, backup, patch management, logging, ideally mapped to ISO 27001 Annex A:2022 (see [ISO 27001 checklist](https://www.sidd.swiss/einblicke/iso-27001-checkliste)).
5. **MFA for administrative access** to databases, cloud consoles, mailboxes.
6. **Data-protection training** at least annually, documented and with a knowledge check.

Tip: training without a knowledge check is not robust in an FDPIC procedure, a simple 10-question test per year suffices.

## Block 6: data breaches and governance (points 24-28)

The 72-hour deadline in Art. 24 DSG is a hard deadline and starts with awareness of a data-security breach with high risk. Reporting the incident to the FDPIC days late risks a supervisory procedure, details in our article [Report a data breach to the FDPIC](https://www.sidd.swiss/einblicke/datenpanne-melden-edoeb).

1. **Incident response plan exists** with escalation matrix, triage criteria (high risk yes/no), templates for FDPIC notification and, where applicable, communication to data subjects.
2. **Data-breach log maintained**: every incident (including non-notifiable ones) documented with date, description, cause, measures.
3. **Tabletop exercise in the last 12 months**: a realistic scenario played through, 72-hour deadline met.
4. **Data-protection lead appointed** (internal or external as DSB under Art. 10 DSG); with a GDPR nexus additionally a DPO under Art. 37 GDPR.
5. **Annual report from the data-protection adviser** with status, actions taken and budget proposal for the coming year, exonerating for the adviser and decision-relevant for management.

Anyone scoring less than 3 of 5 in this block has a structural governance gap that typically becomes more expensive in a damage case than the investment in building it up.

## How SIDD supports you

SIDD offers this 28-point self-assessment as an interactive online version with automated evaluation via [our contact form](https://www.sidd.swiss/en/contact), you then receive a PDF evaluation with prioritisation and remediation proposal. Anyone with more than 5 "red" points should plan a 60-minute deep-dive call; with more than 10 red points we recommend uptake into a full compliance programme.

Operationally we bundle gap closure typically in a [DSB mandate](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) with the [Priverion platform](https://www.sidd.swiss/en/priverion-platform) for records, DPA inventory and privacy policy. GDPR-bound companies get additional [GDPR DPO services](https://www.sidd.swiss/en/services/data-protection-officer-eu) and an [EU representative](https://www.sidd.swiss/en/services/eu-representative). For a concrete fixed-price quote to close the gaps from your self-assessment, use the [quote request](https://www.sidd.swiss/en/quote). A data-protection workshop for management and key stakeholders is bookable separately at [Data-protection workshop SME](https://www.sidd.swiss/en/services/data-protection-workshop-sme).

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
