steurifischlaw firm and notary office
Call us

Data Protection Law

Data protection is rarely a project and usually an operating state. We bring your processing to a standard that withstands scrutiny — without mountains of paper nobody reads.

Owner and employee working together on a laptop in a small office

What we do for you.

Privacy Notice and Website

Review and drafting of privacy notices, cookie banners and consents — matched to your actual processing, not to a template.

Inventory and Impact Assessment

Building the register of processing activities and, where the risk requires it, the data protection impact assessment.

Processors and Cloud

Agreements with IT service providers, cloud and marketing vendors, and assessment of disclosure abroad.

GDPR and Representation

Clarifying whether the GDPR applies to your business and setting up an EU representative where one is required.

Data Breach

Immediate assistance after data loss, a cyberattack or misdirected information: reporting duties, informing data subjects and follow-up.

Access Requests and Personality Rights

Handling access requests — and enforcing your own rights to information, rectification and deletion.

The Revised Swiss Data Protection Act in Practice

The revised Data Protection Act has applied since 1 September 2023. It has brought Swiss data protection closer to the European regime but differs in several respects: it protects only the data of natural persons, contains no general duty to appoint a data protection adviser, and sanctions not the company but the responsible individual personally.

For a business this means above all transparency and traceability. Anyone collecting personal data must inform the person concerned — who is processing, for what purpose, and to whom the data goes. That information is the core of any privacy notice, and it is only accurate if you first know what actually happens inside your own organisation.

Starting Point: A Stocktake, Not a Template

A privacy notice copied from the internet does more harm than good: it describes processing that does not exist and omits processing that does. We therefore start with a stocktake — which data sits where, who has access, which external providers are involved, where the data flows. From this come the register of processing activities (Art. 12 Data Protection Act), the privacy notice and, where the risk is high, the data protection impact assessment (Art. 22).

Smaller businesses are exempt from the register where processing involves only a low risk. It is useful nonetheless: without an overview you can neither answer an access request nor assess an incident.

Providers, Cloud and Transfers Abroad

Outsourcing processing does not outsource responsibility. The agreement with the processor must set out what it may do, what security it guarantees and whether it may engage sub-processors (Art. 9 Data Protection Act). If the server is abroad, the question of adequacy arises: for states without an adequacy decision, safeguards are required, as a rule the standard contractual clauses. With marketing tools, newsletter services and cloud storage in particular, this point is regularly overlooked.

When Something Goes Wrong

Data incidents rarely start spectacularly: a misaddressed email, a lost laptop, a compromised account. The first hours are decisive. What must be clarified is which data is affected, whether there is a high risk to those concerned and whether a report to the Federal Data Protection Commissioner is required (Art. 24 Data Protection Act). Under the GDPR the 72-hour deadline runs in parallel. We handle the report, the information of data subjects and the follow-up — and record what is needed to defend against later claims.

Data Protection for Companies in Eastern Switzerland

We advise SMEs, associations, practices and municipalities from Wil SG, Teufen AR and Zurich. Where software and cloud contracts are involved we work together with our IT law practice; for data processing in employment relationships with employment law.

Your contact persons.

Portrait of Wayne Hess

Wayne Hess

MLaw UZH — Attorney at Law and Public Notary
Portrait of Raphael Fisch

Raphael Fisch

Partner · MLaw & BA phil. — Attorney at Law and Public Notary

Frequently asked questions.

Does Swiss or EU data protection law apply to my business?
The revised Swiss Data Protection Act has applied to all processing in Switzerland since 1 September 2023. The GDPR applies in addition where you deliberately offer goods or services in the EU or monitor people's behaviour there. An online shop delivering to Germany falls within it; a purely local service generally does not.
Do I need a register of processing activities?
In principle yes. Companies with fewer than 250 employees are exempt, provided the processing involves only a low risk to the personality of those concerned. Anyone processing sensitive data on a large scale or carrying out high-risk profiling must nevertheless keep the register.
What must I do after a data breach?
A breach of data security must be reported to the Federal Data Protection Commissioner as soon as possible where it is likely to result in a high risk to those affected (Art. 24 Data Protection Act). Data subjects must be informed where necessary for their protection or where the Commissioner so requires. Under the GDPR a 72-hour deadline applies in addition. Document the incident from the first minute.
May I store data with a provider in the United States?
Disclosure abroad is permitted where the Federal Council has recognised the destination country's data protection as adequate. For the United States this holds only for companies certified under the Swiss-U.S. Data Privacy Framework. Otherwise safeguards are required, in practice the standard contractual clauses — plus an assessment of whether they suffice in the specific case.
What does an access request under Swiss law cost?
For the data subject, access is in principle free of charge and must be provided within thirty days. A contribution of at most 300 francs is permitted only exceptionally, where providing access causes disproportionate effort. Leaving an access request unanswered is not an option — it is subject to criminal sanction.
Who is liable for a breach of Swiss data protection law?
Unlike the GDPR, Swiss law sanctions not the company but the responsible natural person: anyone who intentionally breaches information duties, refuses access or disregards minimum data security requirements can be fined up to 250,000 francs (Art. 60 et seq. Data Protection Act). This makes clear internal responsibilities important.

Other practice areas.