Find the right data protection service for your business

Switzerland · Free product

Swiss Data Privacy
Check-Up

A free Swiss FADP readiness snapshot to help you decide whether you need an Article 14 representative, a data protection adviser, or broader compliance support.

No setup feeFADP snapshotFDPIC-aware guidance
The Data Protection Officers team in a modern office

Practical support, clearly scoped

Switzerland · Swiss FADP

Plans and inclusions

Swiss Data Privacy Check-Up: free readiness check-up

Free for every company size, with no setup fee or commitment to purchase another service.

  • FADP readiness snapshot
  • Gap analysis summary
  • Practical recommendations
  • No commitment required

The check-up provides a readiness snapshot and recommendations. An ongoing appointment, implementation project, or incident engagement has its own scope.

Request your free check-up

Understand your Swiss privacy position

The revised Swiss FADP creates distinct obligations for foreign companies active in Switzerland. The Swiss Data Privacy Check-Up helps you identify the right product before you buy.

We review your Swiss-facing processing, including Cross-Border Data Transfers and Privacy Risk Assessments, and return a practical summary of gaps and next steps under the FADP.

Why start with a check-up

Swiss law combines representative duties, adviser roles, and personal liability concepts that are easy to confuse. The check-up gives you a clear map before appointing anyone or conducting Employee Privacy Training.

Applicable legal framework

Swiss FADP

  • Revised Swiss FADP
    The Federal Act on Data Protection as modernised in 2023.
  • FDPIC oversight
    The Federal Data Protection and Information Commissioner supervises compliance and coordinates enforcement.

How the service works

A straightforward Swiss readiness workflow:

1

Intake

Share your Swiss processing footprint and current Privacy Documentation.

2

Assessment

We review your position against core FADP obligations, including readiness for a Data Breach Response.

3

Gap summary

You receive a concise readiness report.

4

Product guidance

We recommend representative, adviser, or wider support as needed.

Unsure whether you need a Swiss representative or adviser?

Use the free check-up to choose the right Swiss product path.

Book a free check-up

Product snapshot

RolePrivacy Readiness Check-Up
RegulationSwiss FADP
Supervisory authorityFDPIC
Setup feeNone
PricingFree

How we help

See how this service fits your organisation

Use the sections below to understand what we review, what you receive, what your team provides, and how you can keep the result useful after delivery.

01 · Fit

Is the Swiss FADP Data Privacy Check-Up right for your organisation?

If you process Swiss personal data but need a practical first view of your Federal Act on Data Protection position, this check-up gives you a focused starting point. It can help a foreign business choose between a representative, an adviser, focused documentation, or a wider Swiss privacy workstream.

A company entering Switzerland may already have EU GDPR documentation, but that material does not answer every Swiss FADP question. A check-up is useful when the team wants to understand its Swiss connection, notices, high-risk processing, vendor access, transfers, and local contact position before choosing a representative, adviser, or focused workstream.

02 · Decision

What you will be able to decide

The check-up should make the Swiss-specific decision clearer without pretending that a GDPR checklist answers every FADP question. It looks at the company’s processing, Swiss connection, contact obligations, risk, documentation, and available owners before pointing toward a paid service.

The review keeps the Swiss position distinct while showing where existing European controls can be reused. You receive a prioritised view of role and documentation questions, evidence gaps, and operational actions. This lets leadership decide whether the next step is a narrow correction, a Swiss advisory product, or a broader programme with an owner and deadline.

03 · Trigger

When to bring us in

A Swiss launch, a customer questionnaire, a vendor change, a high-risk processing project, an incident, or uncertainty about Article 14 representation can justify the review. It is also useful when a company has imported European privacy material without checking how Swiss notices and records operate.

04 · Evidence

What we need from your team

Bring the Swiss-facing processing, offer or monitoring facts, categories of people and data, locations, vendors, notices, rights route, risk assessments, incident process, and current local contact. The review should mark where the business knows the facts and where it is relying on assumptions.

We compare Swiss-facing products and services with the actual processing records behind them: categories of people and data, purposes, locations, vendors, transfers, notices, rights routes, security material, and risk assessments. We also record which assumptions were imported from an EU programme and need a Swiss-specific confirmation.

05 · People

Who should join the work

Your Swiss business owner, privacy contact, technical or security owner, and customer-support contact normally provide the most useful evidence. Leadership adds the commercial deadline and risk tolerance, particularly when you are choosing between a representative and an adviser with different responsibilities.

06 · Method

How we will work together

We start with your Swiss scope, test the most material processing and documentation, and return a short gap and priority view. We distinguish local contact-point questions from broader governance, DPIA, security, transfer, or training work.

The output can be used in a launch review or customer diligence response. Findings are grouped by practical consequence, such as a public wording change, a missing record, a local representation question, or a technical owner that needs to confirm access. The team sees what to do first and which unresolved issue needs specialist attention.

07 · Output

What you will receive

You receive a concise snapshot with the facts reviewed, unknowns, priority actions, and a recommended service path. Your team can discuss and maintain it without turning it into a long list that no one owns after the first call.

08 · Friction

What can make this harder

A common shortcut is to translate a GDPR conclusion into a Swiss conclusion without checking the local facts. Another is to appoint a contact person before deciding what evidence, access, and escalation route that person will need to perform the role.

09 · Maintenance

How you keep it current

Keep a simple Swiss change log for products, vendors, data categories, notices, incidents, and risk assessments. Revisit the snapshot after a material change or a significant customer or authority question. A point-in-time check is strongest when it leads to a maintainable operating habit.

Revisit the snapshot after a Swiss launch, a new high-risk activity, a new vendor or transfer, an incident, a notice change, or a change to the Swiss representative position. If the business is stable, an annual refresh can test the original assumptions. Keep the source list and decision date with the result.

10 · Boundaries

What stays with your organisation

The check-up is general readiness information, not a formal legal opinion or compliance certification. The company remains responsible for processing decisions, security, records, notices, and responses. Paid work is appropriate when the identified gaps need a professional to implement or monitor them.

11 · Scope

What to prepare before you start

To start, identify your Swiss-facing activities, foreign or domestic entity, current documents, local contacts, and deadline. If you are unsure whether you need a representative and an adviser, bring that uncertainty directly into the intake.

  • Swiss-facing activities and entity or representative facts
  • FADP-specific questions separated from reusable GDPR controls
  • Risk, notice, transfer, and vendor evidence
  • Priority action that fits current owners and timing
  • Clear boundary between a snapshot and ongoing advice

12 · Buyer brief

What your first working brief should contain

Send Swiss facts, not only a GDPR pack. Describe the Swiss-facing offer or monitoring, relevant entities, data categories, purposes, systems, vendors, transfers, risk assessments, notices, request route, security owner, and any question about an Article 14 representative. Note where the team has assumed that an EU document answers the Swiss position. Those assumptions help focus the work. Include the commercial deadline so the review can distinguish a launch blocker from an improvement that can be planned later.

The result should be discussed by the Swiss business owner and the person who controls the underlying evidence. Translate each finding into a local action, such as checking a notice, documenting a processing activity, assessing a transfer, appointing a contact, or seeking continuing advice. Keep reusable global controls and Swiss-specific decisions separate in the follow-up record. Reopen the snapshot when Switzerland, the vendor chain, product, data, or local contact changes. It is a decision aid, not a certification or a substitute for implementation.

13 · First test

What we will test first

The first review tests Swiss-facing products, entity and representative facts, data categories, notices, vendors, transfers, request handling, risk material, and the owners who can confirm them. We identify which controls can be reused from an EU programme and which require a Swiss-specific decision. The check-up should end with a priority that a Swiss business or project owner can act on, not a general statement that more work may be needed. Keep the source evidence and the commercial trigger with the snapshot. Reopen it when Swiss processing, a vendor, a high-risk activity, a notice, or a local contact changes. That gives the team a controlled way to decide whether to buy advisory, representation, documentation, transfer, risk, or ongoing programme support.

14 · Working record

How the result stays usable

A useful result has a home after delivery. Keep the source evidence, decision, owner, scope, open actions, and next review together in a register, project record, contract file, or management routine that your team already uses. The format can be short; it just needs to make the next action and the reason for reopening the question visible. That is how professional input stays connected to the business instead of becoming a document that no one can find when the facts change.

15 · Progress

How you can judge progress

Judge progress by what your team can use and explain. Look for a supported decision, an owner who understands the action, a route that works in practice, and evidence that the agreed output reached the right system, notice, contract, ticket, or meeting. A large document or a high-level score is not enough on its own. The stronger signal is fewer repeated questions, clearer escalation, and a review date that responds to actual change.

16 · Proportion

What a proportionate scope looks like

A proportionate scope should leave you with enough detail to act and enough clarity to know what remains outside the work. We will ask for the facts that can change the answer, explain material uncertainty, and keep specialist dependencies visible. You should be able to tell a manager what was reviewed, an operating owner what to do next, and a future reviewer what event would reopen the question. That balance protects your budget and makes the result more likely to stay useful after delivery.

17 · Handoff

What remains with your organisation

Your organisation remains responsible for the processing, resources, implementation, and final business decision. We can review the supplied facts, provide professional direction, prepare agreed outputs, and make open issues easier to act on. Bring in security, technical, employment, communications, or specialist legal expertise when the question needs it. Before you buy, name the decision, evidence, owner, deadline, and boundary so the selected scope is proportionate and easy to judge.

In practice

See what you can expect

Each view shows a different part of the buyer journey: the evidence, decision, working route, safeguards, and review point behind the service.

Editorial still life showing a Swiss FADP readiness review with alpine contours, assessment cards, and a magnifying glass
Editorial still life showing a Swiss FADP readiness review with alpine contours, assessment cards, and a magnifying glass; evidence view for this page
Editorial still life showing a Swiss FADP readiness review with alpine contours, assessment cards, and a magnifying glass; decision view for this page
Editorial still life showing a Swiss FADP readiness review with alpine contours, assessment cards, and a magnifying glass; workflow view for this page
Editorial still life showing a Swiss FADP readiness review with alpine contours, assessment cards, and a magnifying glass; safeguard view for this page
Editorial still life showing a Swiss FADP readiness review with alpine contours, assessment cards, and a magnifying glass; review view for this page

Frequently Asked Questions

Common questions about the Swiss Data Privacy Check-Up.

Is the Swiss check-up free?

Yes. It is free with no setup fee.

Does it cover Article 14 representation?

Yes. We assess whether Article 14 representation appears necessary for your situation.

Can I move to a paid Swiss product afterwards?

Yes. The check-up is designed to lead into our representative or adviser services.

Swiss Data Privacy Check-Up by location

Explore practical business scenarios, preparation steps, and the relevant jurisdiction for your location.

Start with a free Swiss readiness snapshot

Understand your FADP position before appointing a representative or adviser.

Get the free check-up

Disclaimer: This content is for informational purposes only and does not constitute legal advice or create a solicitor-client relationship. Data protection regulations are subject to change and specific application depends on the context of your processing activities. Please consult directly with our legal team for advice tailored to your organization.

Choose the Right Data Protection Service

Compare the role and scope that fit the jurisdictions and processing activities that matter to your business.

Find the Right Data Protection Service in Minutes

Select your jurisdictions, compare annual pricing, and continue with the service that fits your scope.

View Data Protection Services