Data Protection Law
Data protection is rarely a project and usually an operating state. We bring your processing to a standard that withstands scrutiny — without mountains of paper nobody reads.

What we do for you.
Privacy Notice and Website
Review and drafting of privacy notices, cookie banners and consents — matched to your actual processing, not to a template.Inventory and Impact Assessment
Building the register of processing activities and, where the risk requires it, the data protection impact assessment.Processors and Cloud
Agreements with IT service providers, cloud and marketing vendors, and assessment of disclosure abroad.GDPR and Representation
Clarifying whether the GDPR applies to your business and setting up an EU representative where one is required.Data Breach
Immediate assistance after data loss, a cyberattack or misdirected information: reporting duties, informing data subjects and follow-up.Access Requests and Personality Rights
Handling access requests — and enforcing your own rights to information, rectification and deletion.The Revised Swiss Data Protection Act in Practice
The revised Data Protection Act has applied since 1 September 2023. It has brought Swiss data protection closer to the European regime but differs in several respects: it protects only the data of natural persons, contains no general duty to appoint a data protection adviser, and sanctions not the company but the responsible individual personally.
For a business this means above all transparency and traceability. Anyone collecting personal data must inform the person concerned — who is processing, for what purpose, and to whom the data goes. That information is the core of any privacy notice, and it is only accurate if you first know what actually happens inside your own organisation.
Starting Point: A Stocktake, Not a Template
A privacy notice copied from the internet does more harm than good: it describes processing that does not exist and omits processing that does. We therefore start with a stocktake — which data sits where, who has access, which external providers are involved, where the data flows. From this come the register of processing activities (Art. 12 Data Protection Act), the privacy notice and, where the risk is high, the data protection impact assessment (Art. 22).
Smaller businesses are exempt from the register where processing involves only a low risk. It is useful nonetheless: without an overview you can neither answer an access request nor assess an incident.
Providers, Cloud and Transfers Abroad
Outsourcing processing does not outsource responsibility. The agreement with the processor must set out what it may do, what security it guarantees and whether it may engage sub-processors (Art. 9 Data Protection Act). If the server is abroad, the question of adequacy arises: for states without an adequacy decision, safeguards are required, as a rule the standard contractual clauses. With marketing tools, newsletter services and cloud storage in particular, this point is regularly overlooked.
When Something Goes Wrong
Data incidents rarely start spectacularly: a misaddressed email, a lost laptop, a compromised account. The first hours are decisive. What must be clarified is which data is affected, whether there is a high risk to those concerned and whether a report to the Federal Data Protection Commissioner is required (Art. 24 Data Protection Act). Under the GDPR the 72-hour deadline runs in parallel. We handle the report, the information of data subjects and the follow-up — and record what is needed to defend against later claims.
Data Protection for Companies in Eastern Switzerland
We advise SMEs, associations, practices and municipalities from Wil SG, Teufen AR and Zurich. Where software and cloud contracts are involved we work together with our IT law practice; for data processing in employment relationships with employment law.
Your contact persons.
Raphael Fisch
Frequently asked questions.
Does Swiss or EU data protection law apply to my business?
Do I need a register of processing activities?
What must I do after a data breach?
May I store data with a provider in the United States?
What does an access request under Swiss law cost?
Who is liable for a breach of Swiss data protection law?
Other practice areas.

IP and IT Law
Protecting trade marks, copyright and trade secrets — and IT contracts that hold up in a project.
Administrative Law
When the state issues a decision: objection, appeal and complaint — including public procurement law.


