revFADP checklist for Swiss SMEs
For: Swiss SMEs
Updated: 2026-10
A Swiss SME implements the revFADP in eight steps: capture data flows, determine obligations, review providers and contracts, safeguard international transfers, align the privacy policy with reality, define data security, and rehearse procedures for data breaches and access requests.
The revised Swiss data protection act has applied since 1 September 2023. Many SMEs responded with a new privacy policy without capturing the underlying processing. This checklist starts earlier: with what actually happens to personal data.
It is designed for companies without a dedicated data protection function and names, for each step, how you know it is done.
The checklist
- 01
Capture data flows
For each area — website, customers, staff, suppliers, marketing — record which personal data is collected for what purpose and in which systems it sits.
Done when: An overview names data categories, purpose and system per area, and area owners have confirmed it.
- 02
Determine obligations
Clarify whether records of processing are required, whether sensitive data is processed, and whether the GDPR also applies because people in the EU are deliberately targeted.
Done when: The answers to these three questions are recorded in writing with reasons.
- 03
Review providers
List all external services processing personal data on your behalf and check whether processing is contractually governed.
Done when: For every provider the contract or processing agreement is on file or recorded as an open task with a date.
- 04
Safeguard international transfers
For providers with servers outside Switzerland, check whether the destination has adequate protection or whether additional safeguards such as standard contractual clauses or a certification are needed.
Done when: For each provider it is noted where the data sits and on what basis it is transferred.
- 05
Align the privacy policy with reality
Reconcile the policy with the data-flow overview: name all actual processing and recipients, remove what no longer exists.
Done when: Every service named in the policy exists, and every relevant service in use is named.
- 06
Define data security
Define access rights, multi-factor login, backups, encryption and retention periods for the key systems.
Done when: For each system with personal data it is recorded who has access and how long data is kept.
- 07
Breach procedure
Define who assesses a possible breach and who triggers notification to the Federal Data Protection and Information Commissioner if a high risk is likely.
Done when: A one-page procedure with names and contact details exists and has been rehearsed once.
- 08
Access request procedure
Define who receives requests, how identity is verified and how all of the person's data is gathered from the systems. The deadline is generally 30 days.
Done when: A test request for an internal person has been answered completely and on time.
Common mistakes
- —The privacy policy is copied from a template and describes services not actually in use.
- —Cloud services introduced by individual staff are missing from every overview.
- —Records of processing are considered unnecessary although sensitive data is processed on a large scale.
- —During a data breach it is unclear who decides, and valuable time is lost.
What this checklist does not cover
- —This checklist does not replace legal advice. Contested questions need the assessment of a specialised law firm.
- —It covers the GDPR only to the extent of determining whether it applies. Additional GDPR obligations must be checked separately.
- —Industry-specific rules, for example in healthcare or financial services, come on top.
Parent service: Data Protection Consulting
Matching offers
revFADP implementation for SMEs: from status quo to evidence
A bounded package that takes a Swiss SME from uncertainty to a documented state: capture data flows and providers, determine obligations, review contracts and international transfers, provide privacy-policy groundwork and set clear procedures for data breaches and access requests.
GDPR & revDSG audit for SaaS
A data protection audit for SaaS checks whether data flows, processing agreements, deletion concept, and technical measures are GDPR- and revDSG-compliant. The output is a concrete finding with prioritised fixes — from people who run SaaS themselves.
FAQ
Does the revFADP apply to sole proprietorships?
Yes. It applies to all private persons and companies processing personal data, regardless of size.
Do we need consent for every processing activity?
No. The revFADP does not generally require consent. It is needed in certain cases, such as sensitive data or high-risk profiling.
Who enforces compliance?
The Federal Data Protection and Information Commissioner (FDPIC) can open investigations. Criminal provisions are prosecuted by the cantonal authorities.
More checklists
EU AI Act conformity: a checklist for the first pass
A workable first pass through the EU AI Act has six parts: know which AI runs in the business, determine your role for each system, classify under Article 6, check transparency duties separately, ensure AI literacy, and file everything so it can be found under scrutiny.
High risk or not: reasoning an Annex III classification properly
High-risk classification follows a fixed order: first the deployment area under Annex III, then whether the system plays a substantive role in the decision, then the exemption in Article 6(3). Each of those steps has to be documented with reasoning.
AI literacy under Article 4: from intention to evidence that holds
Article 4 asks for a sufficient level of AI literacy, measured against role, context and the people affected. It becomes workable in four moves: form roles, set a depth per role, train accordingly, and record attendance with date, content and the link to the role.
