Skip to content
Innopulse Consulting
09 · Compliance

Data Protection Consulting

Implementing the revFADP and GDPR — in processes, systems and documents, not just on paper.

Data protection consulting for Swiss and DACH companies with a technical focus: records of processing, data protection impact assessments, processor agreements, international transfers, and data protection in software and websites. Pragmatic, documented, auditable.

In practice data protection rarely fails for lack of legal knowledge. It fails because nobody knows exactly which data sits where, which of the twenty cloud services in use process personal data, and who in the company is responsible for what. Good data protection consulting therefore starts not with template texts but with an honest inventory.

revFADP and GDPR: what applies to whom

The revised Swiss data protection act has applied since 1 September 2023 to all private companies in Switzerland that process personal data. The GDPR is added as soon as a Swiss company deliberately offers goods or services to people in the EU or monitors their behaviour, for example via tracking. Many obligations are similar, but they differ in detail: breach notification, records of processing, the question of an EU representative, and sanctions. The revFADP provides for fines of up to CHF 250,000 directed at the responsible individuals — a key difference from the GDPR, which fines companies.

Inventory: where the data really is

We start with data flows. Which data is collected, through which channels — website, forms, CRM, accounting, HR, email, cloud storage? Which providers process it, and where are their servers? This overview is the basis for everything else: the records of processing, processor agreements, the assessment of international transfers and the privacy policy.

Records, DPIA, contracts

Records of processing document purpose, data categories, recipients, retention and safeguards per processing activity. Processing with high risk for the people concerned — extensive profiling, sensitive data or new technologies, for example — requires a data protection impact assessment. Providers that process data on your behalf need processor agreements, and transfers to countries without adequate protection need additional safeguards such as standard contractual clauses.

We draft these documents to fit your actual organisation and to be maintainable. A record nobody updates is worthless after six months; a lean, owned record with clear update triggers stays useful.

Data protection in software and websites

This is our particular focus. Privacy by design and by default are not slogans but concrete architecture decisions: data minimisation in the data model, tenant isolation via row-level security, encryption, deletion concepts that actually delete, and export functions for access requests. On websites we check which services transfer data without consent — embedded fonts, maps, videos, analytics — and integrate them so they match the privacy policy.

Breaches and access requests

Two situations almost always arrive unprepared: a data breach and the first access request from a data subject. Under the revFADP a data security breach must be reported to the Federal Data Protection and Information Commissioner as soon as possible if it is likely to result in a high risk; the GDPR sets a 72-hour deadline. We define a short, rehearsed procedure for who does what, and how an access request is answered completely within the deadline.

What we are not

We are not a law firm and do not provide legal representation. Our strength is implementation at the intersection of law, organisation and technology. Where a question is legally contested, such as the permissibility of a specific processing activity or in proceedings, we recommend involving a specialised law firm and prepare the facts for it.

Why Innopulse

We run our own SaaS products with data held in Switzerland and the EU and implement the requirements we advise on every day. That is how we know where data protection actually breaks in software — and where it can be solved cleanly with little effort.

If you are unsure where your company stands on data protection, a first call clarifies the starting point. The first 30 minutes are free.

Approach

How an engagement runs

01

Inventory

Capture data flows, systems, providers and responsibilities; clarify applicable law (revFADP, GDPR).

02

Gap analysis

Compare against obligations and prioritise by risk to data subjects and the company.

03

Implementation

Records, DPIA, contracts, technical measures and procedures for breaches and access requests.

04

Embedding

Responsibilities, update triggers and training so the documentation stays current.

FAQ

Frequently asked questions about Data Protection Consulting

Does my company need a data protection advisor under the revFADP?

The revFADP does not require private companies to appoint one. Those that do may benefit from relief in data protection impact assessments. Whether a GDPR data protection officer is required depends on the type and scale of processing.

Do small companies have to keep records of processing?

Under the revFADP, companies with fewer than 250 employees are exempt unless they process sensitive personal data on a large scale or carry out high-risk profiling. The GDPR has its own, similar exemptions.

Are you a law firm?

No. We implement data protection in organisation and technology. For legal assessments of individual cases and representation we recommend a specialised law firm.

May we use US cloud services?

In many cases yes, under conditions. Since 15 September 2024 the Swiss-U.S. Data Privacy Framework applies to certified US companies; otherwise additional safeguards are required. We check this per service.

Data Protection Consulting at Innopulse

A short conversation clarifies more than a long proposal. The first 30 minutes are free.