Compliance · FADP

Data protection audit for Swiss SMEs

The revised Swiss Data Protection Act applies to your SME, whether you are ready or not. AlpenData maps your data, builds your record of processing activities and hands you a clear action plan to improve your compliance, without unnecessary legal jargon.

The problem

The revised Swiss Data Protection Act is in force, and most SMEs are not ready

Since September 2023, the revised Swiss Data Protection Act has imposed concrete obligations on almost every company. Many SMEs know it, but don't know where to start.

You don't know what data you hold

Client, HR, supplier, prospect data, video surveillance… It is scattered across tools that no one has a complete list of.

You have no record of processing activities

The Swiss Data Protection Act requires one for most companies. Without it, you cannot respond to an inspection or a client request.

Your sub-processors are not under contract

Your cloud tools, your payroll software, your IT provider process personal data, often without a compliant data-processing agreement.

Your data leaves the country without your knowing

Many SaaS tools host data outside Switzerland. The Swiss Data Protection Act strictly governs these transfers, and you are responsible for them.

Our method

From inventory to action plan, in four steps

No generic copy-paste checklist. We start from your actual situation, your tools and your data, to give you a concrete, prioritised path to improvement.

01

Data mapping

We identify all the personal data you process (clients, employees, prospects, suppliers) and where it is stored.

02

Record of processing activities

We build (or update) your record of processing activities, the central document required by the Swiss Data Protection Act.

03

Gap analysis

We compare your actual situation with the requirements of the Act: legal bases, retention periods, security, cross-border transfers, sub-processors.

04

Documented action plan

You receive a clear report with non-compliance issues sorted by priority and risk, and the concrete actions needed to fix them.

What you get

Ready-to-use documents, not theory

  • A mapping of personal-data processing activities.
  • A record of processing activities compliant with the Swiss Data Protection Act, ready to present.
  • A gap report sorted by level of legal risk.
  • A prioritised action plan, both technical and organisational.
  • Templates: privacy policy, data-processing clauses, information notices.

How it's billed

The data protection audit is an IT Project: a one-off engagement at a fixed fee, defined on request after a short scoping based on the size of your organisation. Typically expect between CHF 1,500 and CHF 3,500. You know the amount before we start, with no fixed-term commitment.

To maintain compliance over time (security, backups, Swiss hosting), it also fits into AlpenCare managed IT.

Request a data protection quote

Service area

Local data protection support, in French-speaking Switzerland

We support SMEs in Lausanne and throughout the canton of Vaud, and remotely in the rest of French-speaking Switzerland. A contact who speaks your language and knows the Swiss context.

Lausanne Renens Morges Nyon Yverdon-les-Bains Vevey Canton of Vaud French-speaking Switzerland

Data Protection FAQ

Frequently asked questions about the data protection audit

Can’t find your answer?

Ask us your question →

First step

Move forward on your data protection compliance with peace of mind

David Cunha, cofondateur et directeur technique d'AlpenData

A clear audit, a ready-to-use record of processing and a prioritised action plan. Request your quote, with no commitment.