In practice data protection rarely fails for lack of legal knowledge. It fails because nobody knows exactly which data sits where, which of the twenty cloud services in use process personal data, and who in the company is responsible for what. Good data protection consulting therefore starts not with template texts but with an honest inventory.
revFADP and GDPR: what applies to whom
The revised Swiss data protection act has applied since 1 September 2023 to all private companies in Switzerland that process personal data. The GDPR is added as soon as a Swiss company deliberately offers goods or services to people in the EU or monitors their behaviour, for example via tracking. Many obligations are similar, but they differ in detail: breach notification, records of processing, the question of an EU representative, and sanctions. The revFADP provides for fines of up to CHF 250,000 directed at the responsible individuals — a key difference from the GDPR, which fines companies.
Inventory: where the data really is
We start with data flows. Which data is collected, through which channels — website, forms, CRM, accounting, HR, email, cloud storage? Which providers process it, and where are their servers? This overview is the basis for everything else: the records of processing, processor agreements, the assessment of international transfers and the privacy policy.
Records, DPIA, contracts
Records of processing document purpose, data categories, recipients, retention and safeguards per processing activity. Processing with high risk for the people concerned — extensive profiling, sensitive data or new technologies, for example — requires a data protection impact assessment. Providers that process data on your behalf need processor agreements, and transfers to countries without adequate protection need additional safeguards such as standard contractual clauses.
We draft these documents to fit your actual organisation and to be maintainable. A record nobody updates is worthless after six months; a lean, owned record with clear update triggers stays useful.
Data protection in software and websites
This is our particular focus. Privacy by design and by default are not slogans but concrete architecture decisions: data minimisation in the data model, tenant isolation via row-level security, encryption, deletion concepts that actually delete, and export functions for access requests. On websites we check which services transfer data without consent — embedded fonts, maps, videos, analytics — and integrate them so they match the privacy policy.
Breaches and access requests
Two situations almost always arrive unprepared: a data breach and the first access request from a data subject. Under the revFADP a data security breach must be reported to the Federal Data Protection and Information Commissioner as soon as possible if it is likely to result in a high risk; the GDPR sets a 72-hour deadline. We define a short, rehearsed procedure for who does what, and how an access request is answered completely within the deadline.
What we are not
We are not a law firm and do not provide legal representation. Our strength is implementation at the intersection of law, organisation and technology. Where a question is legally contested, such as the permissibility of a specific processing activity or in proceedings, we recommend involving a specialised law firm and prepare the facts for it.
Why Innopulse
We run our own SaaS products with data held in Switzerland and the EU and implement the requirements we advise on every day. That is how we know where data protection actually breaks in software — and where it can be solved cleanly with little effort.
If you are unsure where your company stands on data protection, a first call clarifies the starting point. The first 30 minutes are free.
