nFADP · revised DSG · compliance for SMEs

FADP Compliance (revised Swiss DSG): Implementation for SMEs

The revised Data Protection Act (revDSG/nFADP) has applied since 1 September 2023. In the event of violations, the responsible individuals face fines of up to CHF 250,000. SIDD brings your SME into FADP compliance with an audit, documentation and training, at a fixed fee.

Fines up to CHF 250,000 Fixed fee Active since 2017
FADP compliance and revised DSG implementation for Swiss SMEs
Mandate under Art. 321 SCC Professional secrecy

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide

FADP compliance: what does the revised DSG require?

In brief

The fully revised Swiss Data Protection Act (revDSG, colloquially the new DSG or nFADP) has applied since 1 September 2023. It requires every company that processes personal data to take demonstrable technical and organisational measures, to inform transparently and to document its processes.

FADP compliance means implementing these duties in a structured way and being able to evidence them at any time. SIDD takes your SME to compliance as a fixed-fee project, from the baseline assessment to the finished documentation.

What the revised DSG concretely requires of your company

  • Maintain a record of processing activities
  • Data protection impact assessment (DPIA) for high-risk processing
  • Report data security breaches to the FDPIC as soon as possible
  • Ensure data subject rights: access, rectification, erasure and data portability
  • Disclose data abroad only with adequate protection or appropriate safeguards

Revised DSG and GDPR: one approach for both

Many Swiss companies are subject to both the revised DSG and the EU GDPR, for example because they sell to customers in the EU. We set up compliance so that both laws are covered in a single approach, instead of documenting everything twice. Where needed, we also act as your EU Representative under Art. 27 GDPR.

Data protection in Geneva: revised DSG and LIPAD combined

Public and semi-public bodies in the Canton of Geneva are subject not only to the federal revised DSG but also to the LIPAD (the cantonal law on public information, access to documents and the protection of personal data). We address both regimes in a single approach, so that your Geneva organisation meets the revised DSG and the LIPAD at the same time.

How we bring you into FADP compliance

Baseline assessment, action plan, implementation of documentation and processes, and training for your staff: you receive a clearly scoped fixed-fee package and a named contact. On request, we then take on the ongoing mandate as your external data protection advisor.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your nDSG compliance, concretely: LexCommand drafts the processing register and DPIA as tracked Word documents with sources in the footnotes and maps revDSG and GDPR duties side by side, so a single set of measures provably covers both laws.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Ready for FADP compliance without the internal workload?

Request a fixed-fee quote or book an initial consultation directly. Enquiries are subject to professional confidentiality.