Skip to content
Innopulse Consulting

revFADP implementation for SMEs: from status quo to evidence

Swiss SMEs that know the revFADP applies but are not sure what it concretely requires of them.

Updated: 2026-10

In short

A bounded package that takes a Swiss SME from uncertainty to a documented state: capture data flows and providers, determine obligations, review contracts and international transfers, provide privacy-policy groundwork and set clear procedures for data breaches and access requests.

When the revFADP came into force, many SMEs published a new privacy policy and left it at that. The policy then often describes processes and services that do not exist, while cloud services actually in use are missing.

The real risk lies less in an inspection than in an emergency: a data breach, an access request or a customer enquiry during a supplier audit. That is when it shows whether the documentation reflects reality.

What you get

Data-flow overview

Which personal data is processed where, for what, and by which providers.

Obligation assessment

What applies to your company — including whether records of processing are required and whether the GDPR applies in addition.

Contracts and transfers

Review of processor arrangements and safeguards for international transfers per provider.

Privacy-policy groundwork

A factual basis matching actual processing; final legal review by a law firm remains possible.

Breach and access procedure

Who does what in a breach, and how access requests are answered on time.

How it runs

  1. 01

    Workshop

    Capture systems, providers and processes together.

  2. 02

    Analysis

    Determine obligations and prioritise gaps by risk.

  3. 03

    Implementation

    Draft documents, review contracts and define procedures.

  4. 04

    Handover

    Set responsibilities and update triggers.

Price framing

As a bounded package at a fixed price. We name the frame after a short first call, depending on size and number of systems.

Indicative, not a binding quote — the frame is confirmed during scoping.

What drives the price? → Cost guide

Parent service: Data Protection Consulting

FAQ

Does this replace legal advice?

No. We implement data protection organisationally and technically. For legal assessments of individual cases we recommend a law firm, to which we hand an orderly set of facts.

We have customers in the EU. Is the revFADP enough?

Not necessarily. Anyone deliberately targeting people in the EU also falls under the GDPR. We clarify this as part of the package.

How much effort is it for us?

Most of it is on our side. From you we need one workshop and contacts for questions about systems and processes.

LM
Reviewed by
Founder & CEO · MSc Innovation Management (FFHS) · Author of “Identity Over Discipline”
Working on something similar?

revFADP implementation for SMEs: from status quo to evidence

Swiss SMEs that know the revFADP applies but are not sure what it concretely requires of them.