External Data Protection Officer · DSG & GDPR Compliant, No Internal Resource Needed
Switzerland's revised DSG has been enforceable since September 2023. Violations carry personal fines of up to CHF 250,000, not against the company, but against your employees. We take on the mandate before it becomes a liability.
Three qualified lawyers with DSG and GDPR expertise
Combined: legal competence and ISO 27001 information security
Data-protection advisors (DPOs) are appointed by a company or organisation to monitor compliance with the revised FADP, to advise the company and to oversee implementation. The person must have the necessary expertise and independence and may not be disadvantaged or dismissed in the exercise of this role.
In Switzerland, appointment is generally voluntary (Art. 10 revised FADP). It is nonetheless advisable if you wish to complete high-risk data protection impact assessments (DPIAs) without consulting the FDPIC, demonstrate your accountability and protect your employees from fines of up to CHF 250'000.
Do you need a data-protection advisor?
These four scenarios are the most common triggers for a DPO mandate at Swiss SMEs and corporate groups.
1
You regularly process personal data on a large scale or sensitive data (health, financial, biometric).
2
You operate in a regulated sector (FINMA, MedTech, EPRA obligations, pharma, aviation) and must document compliance.
3
You sell to EU customers, and must additionally comply with the GDPR.
4
You want to complete DPIAs without consulting the FDPIC, thereby shortening time-to-market in data-intensive projects.
Unsure? Our price calculator clarifies in 60 seconds whether a DPO mandate makes sense for you, and gives you the matching rate straight away.
Swiss SMEs are subject to the same revised FADP as large corporations, usually without an in-house data protection function. SIDD handles data protection for SMEs as a lean fixed-fee mandate: revFADP baseline assessment, record of processing activities, privacy policy and staff training.
Cloud data protection
Microsoft 365, AWS and Azure can be operated in an FADP-compliant way when data processing, data residency and transfer mechanisms are properly governed. We review your cloud configuration, put the required data processing agreements (DPAs) in place and document the safeguards for data transfers to the USA and other third countries.
Data protection in healthcare and for medical practices
Medical practices, clinics and MedTech companies process sensitive health data and are additionally subject to the EPRA and medical confidentiality. SIDD sets up data protection for medical practices and healthcare in an FADP-compliant way, from IT in the practice to patient records.
Swiss FADP (nDSG) Compliance Consulting
The revised Swiss Data Protection Act (revFADP, also known as nFADP) has applied since 1 September 2023. We bring your organisation into FADP compliance: record of processing activities, data protection impact assessments, breach notification procedures and the duties towards the FDPIC.
GDPR Compliance for Swiss Companies
As soon as you offer goods or services to people in the EU or monitor their behaviour, the GDPR also applies. SIDD brings Swiss companies into GDPR compliance and, where needed, acts as your EU Representative under Art. 27 GDPR.
Industries with special data-protection needs
We know the sector rules that go beyond the revised DSG.
Aviation
Healthcare
HR / Human Resources
Finance (FINMA)
Tool-supported with the Priverion Platform
We work with the Priverion Platform, the Swiss data-protection software of our sister company. Record of processing, DPIA, risk register and audit modules in one place, hosted in Switzerland.
Data-protection law and contracts, not just technology
Our mandate also covers the legal side: data processing agreements (DPAs), privacy notices, data-subject requests, contracts with service providers and correspondence with the FDPIC. Led by lawyers admitted to the bar, not only IT specialists.
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your external DPO mandate, concretely: LexCommand backs every revDSG and GDPR statement in the processing register, the DPIA and the data processing agreements with an exact primary source, keeps the Swiss and EU duties cleanly separate, and surfaces overlapping obligations side by side.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions before engaging us
What does an external data-protection advisor cost?
Our entry-level Standard package starts at CHF 500 per month for SMEs with manageable data-protection volumes. Premium mandates with a flexible annual quota from 30 hours typically range between CHF 1'200 and CHF 3'500 per month. Corporate mandates are priced individually.
You can determine the right rate for your situation in 60 seconds using our price calculator.
How long is the contract commitment?
Standard and Premium mandates run for 12 months with annual renewal. Corporate contracts typically run for several years with quarterly reviews. We impose no hidden notice periods, ordinary termination is always possible at the end of the contract term.
What happens if we build up an internal DPO function?
We support the transition. You receive all mandate documents, the ROPA and a knowledge-transfer workshop for your internal DPO function. We optionally remain available as a sparring partner with an hourly quota.
Do you also cover the GDPR and UK GDPR?
Yes. Dr. Staiger is an Attorney at Law (New York) and a Solicitor (UK). We take on the dual mandate as Data Protection Officer (revised FADP) and Data Protection Officer (Art. 37 GDPR), and can additionally act as your EU representative under Art. 27 GDPR or as your UK representative.
Who is liable in the event of a data breach?
Responsibility for the processing remains with the company, even an external DPO does not change that (Art. 5 revised FADP). We minimise the risk through ongoing monitoring, documented recommendations on technical and organisational measures, and a clear incident playbook. Executive management and the board of directors are included in our reporting.
How quickly do you respond?
Initial response to client enquiries within 24 hours, typically within 4 hours on business days. In the event of data breaches and contact with authorities, you can reach us via a 24/7 emergency line under the Premium and Corporate plans.
Is the communication subject to professional secrecy?
Yes. Enquiries to SIDD are subject to Swiss professional secrecy under Art. 321 SCC. Your client communications and all insights obtained are therefore protected against access by the state within a framework similar to that of a law firm.
Book a free consultation
30 minutes. We tell you exactly where you stand, no jargon, no sales pitch.