Data protection consulting for Geneva
Updated: 2026-10
Geneva's NGOs and foundations handle some of the most sensitive personal data there is: beneficiaries in vulnerable situations, donors, staff in many countries. As private entities they fall under the Swiss revFADP, often alongside the GDPR. We implement data protection in their processes and systems and document it in English. We do not work in French.
Your region: Geneva
Intergovernmental organisations in Geneva operate under their own legal frameworks. NGOs, foundations and associations, however, are generally private entities subject to Swiss data protection law. Their data flows are often international: field offices, partner organisations, cloud tools and donor platforms in many jurisdictions. Each transfer needs a basis, and beneficiary data may include information about health, ethnicity or legal status that requires particular care.
We map these flows, set up records and procedures that a small team can maintain, and implement technical safeguards. We are not a law firm; contested questions go to specialised counsel. We are based in Zug and work remotely, with on-site sessions in Geneva.
How we deliver
Beneficiary data with care
Minimisation, access restrictions and retention rules for sensitive information about vulnerable people.
International transfers
Field offices, partners and cloud tools mapped, with the right safeguards per transfer.
Donor data
Clear purposes and consent for fundraising communication.
Maintainable by small teams
Documentation and procedures sized for organisations without a dedicated privacy function.
Why Innopulse
- —Experience with sensitive data and international flows.
- —Technical and organisational implementation.
- —Clear separation from legal advice; English and German only.
Parent service: Data Protection Consulting
Matching offers
revFADP implementation for SMEs: from status quo to evidence
A bounded package that takes a Swiss SME from uncertainty to a documented state: capture data flows and providers, determine obligations, review contracts and international transfers, provide privacy-policy groundwork and set clear procedures for data breaches and access requests.
GDPR & revDSG audit for SaaS
A data protection audit for SaaS checks whether data flows, processing agreements, deletion concept, and technical measures are GDPR- and revDSG-compliant. The output is a concrete finding with prioritised fixes — from people who run SaaS themselves.
FRIA & DPIA for AI systems
This package produces the impact assessments an AI system often needs simultaneously: the fundamental rights impact assessment (FRIA) under Article 27 of the AI Act and the data protection impact assessment (DPIA) under Article 35 GDPR — integrated rather than duplicated, as one audit-ready assessment with a clear approval decision.
More regions
Data protection consulting in Zug
International companies in Zug frequently need data protection work in English: group policies reconciled with Swiss law, transfers to entities abroad, and the question of whether an EU representative is required. We handle this from our office in Zug, in person, and implement the results in your systems.
Data protection consulting in Zurich
International companies in Zurich often operate under two regimes at once: the Swiss revised Federal Act on Data Protection and, for EU customers or group companies, the GDPR. Their headquarters may expect documentation in English. We implement both in processes and systems and document the result in English, with local German versions where staff or authorities need them.
Software development in Zug
Zug is our home base and one of Switzerland's most international business locations. We build custom software for holding companies, trading firms, fintechs and service providers based here — in English when that is your working language, with workshops in person in Zug and data hosted in Switzerland.
Software development in Basel
Basel's life sciences ecosystem works largely in English, and its software needs are specific: capturing data where it is generated, sharing it securely with partners, and documenting systems for environments where traceability matters. We build focused applications for these needs, in English, with honest clarity about which validation steps remain with you.
FAQ
Does the Swiss data protection act apply to our NGO?
NGOs and foundations are generally private entities and subject to the revFADP. Intergovernmental organisations have their own regimes.
Can we use US cloud tools for beneficiary data?
It depends on certification, contracts, encryption and the sensitivity of the data. For highly sensitive beneficiary data many organisations choose Swiss or EU hosting.
Do you work in French?
No. We document in English and German. For French-language information duties towards staff or beneficiaries, texts can be produced by professional translators from our English version.
