revFADP implementation for SMEs: from status quo to evidence
Swiss SMEs that know the revFADP applies but are not sure what it concretely requires of them.
Updated: 2026-10
A bounded package that takes a Swiss SME from uncertainty to a documented state: capture data flows and providers, determine obligations, review contracts and international transfers, provide privacy-policy groundwork and set clear procedures for data breaches and access requests.
When the revFADP came into force, many SMEs published a new privacy policy and left it at that. The policy then often describes processes and services that do not exist, while cloud services actually in use are missing.
The real risk lies less in an inspection than in an emergency: a data breach, an access request or a customer enquiry during a supplier audit. That is when it shows whether the documentation reflects reality.
What you get
Data-flow overview
Which personal data is processed where, for what, and by which providers.
Obligation assessment
What applies to your company — including whether records of processing are required and whether the GDPR applies in addition.
Contracts and transfers
Review of processor arrangements and safeguards for international transfers per provider.
Privacy-policy groundwork
A factual basis matching actual processing; final legal review by a law firm remains possible.
Breach and access procedure
Who does what in a breach, and how access requests are answered on time.
How it runs
- 01
Workshop
Capture systems, providers and processes together.
- 02
Analysis
Determine obligations and prioritise gaps by risk.
- 03
Implementation
Draft documents, review contracts and define procedures.
- 04
Handover
Set responsibilities and update triggers.
Price framing
As a bounded package at a fixed price. We name the frame after a short first call, depending on size and number of systems.
Indicative, not a binding quote — the frame is confirmed during scoping.
What drives the price? → Cost guide
Parent service: Data Protection Consulting
FAQ
Does this replace legal advice?
No. We implement data protection organisationally and technically. For legal assessments of individual cases we recommend a law firm, to which we hand an orderly set of facts.
We have customers in the EU. Is the revFADP enough?
Not necessarily. Anyone deliberately targeting people in the EU also falls under the GDPR. We clarify this as part of the package.
How much effort is it for us?
Most of it is on our side. From you we need one workshop and contacts for questions about systems and processes.
revFADP implementation for SMEs: from status quo to evidence
Swiss SMEs that know the revFADP applies but are not sure what it concretely requires of them.
