Data protection consulting in Zurich
Updated: 2026-10
International companies in Zurich often operate under two regimes at once: the Swiss revised Federal Act on Data Protection and, for EU customers or group companies, the GDPR. Their headquarters may expect documentation in English. We implement both in processes and systems and document the result in English, with local German versions where staff or authorities need them.
Your region: Zurich
A Zurich subsidiary of an international group, or a Zurich-based scale-up with EU customers, typically faces questions the group template does not answer: How does the Swiss act differ from the GDPR on breach notification and records of processing? Which transfers to the parent company need safeguards? Who is responsible for answering a Swiss access request within the deadline?
We map the actual data flows, reconcile group policies with Swiss requirements and implement the technical measures in your systems. We are not a law firm; for contested legal questions we recommend specialised counsel and prepare the facts for them. We are based in Zug and work with Zurich clients remotely and on site.
How we deliver
Two regimes, one framework
revFADP and GDPR requirements reconciled into one set of processes rather than two parallel ones.
Documentation in English
Records, policies and procedures in English for global teams, with German versions where needed locally.
Group transfers clarified
Data flows to parent and sister companies mapped, with the right legal basis for each.
Implemented in systems
Access control, retention and export functions built into the software, not only described.
Why Innopulse
- —Technical and organisational implementation.
- —Experience with Swiss and EU requirements.
- —Clear separation from legal advice.
Parent service: Data Protection Consulting
Matching offers
revFADP implementation for SMEs: from status quo to evidence
A bounded package that takes a Swiss SME from uncertainty to a documented state: capture data flows and providers, determine obligations, review contracts and international transfers, provide privacy-policy groundwork and set clear procedures for data breaches and access requests.
GDPR & revDSG audit for SaaS
A data protection audit for SaaS checks whether data flows, processing agreements, deletion concept, and technical measures are GDPR- and revDSG-compliant. The output is a concrete finding with prioritised fixes — from people who run SaaS themselves.
FRIA & DPIA for AI systems
This package produces the impact assessments an AI system often needs simultaneously: the fundamental rights impact assessment (FRIA) under Article 27 of the AI Act and the data protection impact assessment (DPIA) under Article 35 GDPR — integrated rather than duplicated, as one audit-ready assessment with a clear approval decision.
More regions
Data protection consulting for Geneva
Geneva's NGOs and foundations handle some of the most sensitive personal data there is: beneficiaries in vulnerable situations, donors, staff in many countries. As private entities they fall under the Swiss revFADP, often alongside the GDPR. We implement data protection in their processes and systems and document it in English. We do not work in French.
Data protection consulting in Zug
International companies in Zug frequently need data protection work in English: group policies reconciled with Swiss law, transfers to entities abroad, and the question of whether an EU representative is required. We handle this from our office in Zug, in person, and implement the results in your systems.
Software development for Geneva
Geneva is home to many international organisations, NGOs, foundations and trading companies whose working language is English. We build custom software for them — secure portals, case and grant management tools, internal applications — in English, with data held in Switzerland or the EU. To be clear from the start: we work in English and German, not in French.
Web development for Geneva
Many organisations in Geneva communicate primarily in English with a global audience of donors, partners, member states or clients. We build English-first websites for them that are accessible, fast, well structured for search and ready to be cited by AI assistants. We do not produce French content; where a French version is needed, it comes from professional translators or your own team.
FAQ
Does the GDPR apply to our Zurich company?
If you offer goods or services to people in the EU or monitor their behaviour, it can apply in addition to the Swiss act. We clarify this at the start.
Can our documentation be in English?
Yes for internal documentation. Information addressed to Swiss staff or customers should be in a language they understand, which often means German as well.
Are you a law firm?
No. We implement data protection in organisation and technology. For legal assessments of individual cases we recommend specialised counsel.
