FADP · revFADP · External Data Protection Officer

External Data Protection Officer · DSG & GDPR Compliant, No Internal Resource Needed

Switzerland's revised DSG has been enforceable since September 2023. Violations carry personal fines of up to CHF 250,000, not against the company, but against your employees. We take on the mandate before it becomes a liability.

  • Three qualified lawyers with DSG and GDPR expertise
  • Combined: legal competence and ISO 27001 information security
  • Mandate active within 5 business days
External data-protection advisor advising Swiss SMEs on the revised FADP
Mandate under Art. 321 SCC Professional secrecy
Swiss provider, Zurich
Fixed fee
Free 30-min consultation
Quote within 24h
Active since 2017

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide

⚠️ Act now

The DSG is live. Companies without a data protection structure today are exposed, not eventually, but now.

When do you need an external DPO?

  • You conduct Data Protection Impact Assessments (DPIAs)
  • You process sensitive personal data
  • Clients or partners require a named DPO
  • You want to demonstrate that you take accountability seriously
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

Supporting international and Swiss companies in complex data-protection mandates since 2013. Reports directly to your executive management.

LinkedIn profile

What is a data-protection advisor (DPO)?

Brief definition

Data-protection advisors (DPOs) are appointed by a company or organisation to monitor compliance with the revised FADP, to advise the company and to oversee implementation. The person must have the necessary expertise and independence and may not be disadvantaged or dismissed in the exercise of this role.

In Switzerland, appointment is generally voluntary (Art. 10 revised FADP). It is nonetheless advisable if you wish to complete high-risk data protection impact assessments (DPIAs) without consulting the FDPIC, demonstrate your accountability and protect your employees from fines of up to CHF 250'000.

Do you need a data-protection advisor?

These four scenarios are the most common triggers for a DPO mandate at Swiss SMEs and corporate groups.

1

You regularly process personal data on a large scale or sensitive data (health, financial, biometric).

2

You operate in a regulated sector (FINMA, MedTech, EPRA obligations, pharma, aviation) and must document compliance.

3

You sell to EU customers, and must additionally comply with the GDPR.

4

You want to complete DPIAs without consulting the FDPIC, thereby shortening time-to-market in data-intensive projects.

Unsure? Our price calculator clarifies in 60 seconds whether a DPO mandate makes sense for you, and gives you the matching rate straight away.

Which activities do we take on as your external DPO?

A comprehensive DPO mandate under Art. 10 revised FADP, operational, advisory and supervisory.

  • Informing and advising controllers, processors and employees on FADP obligations
  • Monitoring compliance with the FADP, other data protection regulations and internal policies
  • Advising on data protection impact assessments (DPIAs) and monitoring their implementation
  • Cooperation with and point of contact for the competent supervisory authority (FDPIC)
  • Maintaining the records of processing activities (ROPA)
  • Support with data-subject rights (access, rectification, erasure, objection)
  • Drafting and updating internal data protection policies
  • Regular security review of data processing with recommendation of technical and organisational measures (TOMs)
  • Improvement proposals for existing processing operations
  • Training sessions and workshops on data protection for employees and stakeholders

How much effort does a DPO entail?

The effort depends heavily on company size, sector and IT complexity. Effort drivers are:

  • Company size, larger organisations with more complex data flows require more time for monitoring and implementation.
  • Sector, health, finance and aviation are subject to additional sector-specific rules (FINMA, EPRA, ICAO).
  • Regulatory dynamics, the revised FADP, GDPR updates, NIS2 and the EU AI Act require ongoing adjustments.
  • Training needs, number of employees, international locations, languages.
  • TOM maturity level, the lower it is, the higher the initial effort for implementation and audits.
  • Incident management, DPIAs, data-subject requests and communication with authorities add to day-to-day operations.

~10 h

typical weekly effort for 250 employees

24 h

guaranteed initial response to client enquiries

CHF 250k

maximum fine for breaches of the revised FADP (Swiss DSG)

Which packages do we offer?

Three clear pricing tiers, from an SME entry option to a tailored group mandate. All prices include access to the SIDD platform.

Standard · SME

from CHF 500 / month

Fixed quarterly mandate: half a day per quarter plus availability for standard enquiries. Ideal for SMEs with 25–150 employees.

  • DPO mandate under Art. 10 revised FADP
  • quarterly meeting with executive management
  • ROPA maintenance
  • Response time 24 h
  • additional activities at the daily rate

Group · Custom

On request

Mandate within a regulated or multinational group structure, typically with a dual GDPR/revised FADP mandate and a FINMA or EPDG dimension.

  • dedicated team (lead + backup)
  • multi-jurisdiction coverage
  • FINMA / EPDG / EU compliant
  • tailored SLA and reporting
  • crisis management stand-by

How does the collaboration work?

From contract to ongoing support in six steps. Typical onboarding period: 14 days.

Contract

Digital service contract with a clearly defined scope of services as DPO.

Kick-off

Workshop to get to know each other, align expectations and agree on next steps.

Analysis

Inventory of data-protection-relevant processes, systems and documents.

Concept

Action plan: privacy notices, ROPA, DPIAs, data processing agreements, internal policies.

Implementation

Support with practical implementation, advice, training, review, communication with authorities.

Ongoing support

A fixed point of contact, ongoing monitoring and updates to reflect new regulatory conditions.

Why choose SIDD as your external data-protection advisor?

We are neither a pure law firm nor a pure IT shop, we are both. That makes us resilient for regulated mandates.

Save time and costs

You fully outsource the recruiting, training and backup of an internal DPO function to us.

In-depth expertise

Over 10 years of international data-protection practice, three lawyers with a doctorate and an ISO 27001 lead auditor.

Minimise risk

Actively avoid fines, reputational damage and personal liability for executive management and the board of directors.

Independent advice

An external perspective free from internal company politics, an advantage in conflicts with other departments.

Build trust

A clear data-protection practice increases the trust of customers, employees and business partners.

Professional secrecy

All enquiries are subject to professional secrecy under Art. 321 SCC, just as with a law firm.

References from regulated industries

We handle DPO mandates in aviation, healthcare, HR tech and consulting, from SMEs to large corporations.

Data protection for SMEs

Swiss SMEs are subject to the same revised FADP as large corporations, usually without an in-house data protection function. SIDD handles data protection for SMEs as a lean fixed-fee mandate: revFADP baseline assessment, record of processing activities, privacy policy and staff training.

Cloud data protection

Microsoft 365, AWS and Azure can be operated in an FADP-compliant way when data processing, data residency and transfer mechanisms are properly governed. We review your cloud configuration, put the required data processing agreements (DPAs) in place and document the safeguards for data transfers to the USA and other third countries.

Data protection in healthcare and for medical practices

Medical practices, clinics and MedTech companies process sensitive health data and are additionally subject to the EPRA and medical confidentiality. SIDD sets up data protection for medical practices and healthcare in an FADP-compliant way, from IT in the practice to patient records.

Swiss FADP (nDSG) Compliance Consulting

The revised Swiss Data Protection Act (revFADP, also known as nFADP) has applied since 1 September 2023. We bring your organisation into FADP compliance: record of processing activities, data protection impact assessments, breach notification procedures and the duties towards the FDPIC.

GDPR Compliance for Swiss Companies

As soon as you offer goods or services to people in the EU or monitor their behaviour, the GDPR also applies. SIDD brings Swiss companies into GDPR compliance and, where needed, acts as your EU Representative under Art. 27 GDPR.

Industries with special data-protection needs

We know the sector rules that go beyond the revised DSG.

Aviation
Healthcare
HR / Human Resources
Finance (FINMA)

Tool-supported with the Priverion Platform

We work with the Priverion Platform, the Swiss data-protection software of our sister company. Record of processing, DPIA, risk register and audit modules in one place, hosted in Switzerland.

Data-protection law and contracts, not just technology

Our mandate also covers the legal side: data processing agreements (DPAs), privacy notices, data-subject requests, contracts with service providers and correspondence with the FDPIC. Led by lawyers admitted to the bar, not only IT specialists.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your external DPO mandate, concretely: LexCommand backs every revDSG and GDPR statement in the processing register, the DPIA and the data processing agreements with an exact primary source, keeps the Swiss and EU duties cleanly separate, and surfaces overlapping obligations side by side.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions before engaging us

What does an external data-protection advisor cost?

Our entry-level Standard package starts at CHF 500 per month for SMEs with manageable data-protection volumes. Premium mandates with a flexible annual quota from 30 hours typically range between CHF 1'200 and CHF 3'500 per month. Corporate mandates are priced individually.

You can determine the right rate for your situation in 60 seconds using our price calculator.

How long is the contract commitment?

Standard and Premium mandates run for 12 months with annual renewal. Corporate contracts typically run for several years with quarterly reviews. We impose no hidden notice periods, ordinary termination is always possible at the end of the contract term.

What happens if we build up an internal DPO function?

We support the transition. You receive all mandate documents, the ROPA and a knowledge-transfer workshop for your internal DPO function. We optionally remain available as a sparring partner with an hourly quota.

Do you also cover the GDPR and UK GDPR?

Yes. Dr. Staiger is an Attorney at Law (New York) and a Solicitor (UK). We take on the dual mandate as Data Protection Officer (revised FADP) and Data Protection Officer (Art. 37 GDPR), and can additionally act as your EU representative under Art. 27 GDPR or as your UK representative.

Who is liable in the event of a data breach?

Responsibility for the processing remains with the company, even an external DPO does not change that (Art. 5 revised FADP). We minimise the risk through ongoing monitoring, documented recommendations on technical and organisational measures, and a clear incident playbook. Executive management and the board of directors are included in our reporting.

How quickly do you respond?

Initial response to client enquiries within 24 hours, typically within 4 hours on business days. In the event of data breaches and contact with authorities, you can reach us via a 24/7 emergency line under the Premium and Corporate plans.

Is the communication subject to professional secrecy?

Yes. Enquiries to SIDD are subject to Swiss professional secrecy under Art. 321 SCC. Your client communications and all insights obtained are therefore protected against access by the state within a framework similar to that of a law firm.

Book a free consultation

30 minutes. We tell you exactly where you stand, no jargon, no sales pitch.

30-minute consultation with Philipp Staiger, free and no obligation Book an appointment