Privacy · LPD · GDPR

FADP and GDPR privacy consulting: governed and verifiable data.

We turn the requirements of the Swiss Federal Act on Data Protection (FADP) and, where applicable, the GDPR into a practical system: clear roles, updated records, proportionate measures and procedures that truly work.

An operational approach

From the initial assessment to ongoing management

Analysis, priorità, documentazione, responsabilità e controllo: senza modelli generici scollegati dai processi reali.

LPDSwitzerland
GDPRwhere applicable
DPIAhigh risk
DPOexpert support
What we put in order

Compliance becomes a way of working.

We focus on the areas that expose more organization, customers and employees, by calibrating the project of the size, industry, and risk.

01

Assessment and gap analysis

Mapping of processing, legal basis, data streams, suppliers and transfers, with a plan of adjustment ordered by priority.

02

Records and documentation

The register of treatments, notices, consents, appointments, agreements and internal regulations consistent with the operation.

03

Risks and DPIA

Assessment of the risks to people and the impact analysis for treatments that may present a high risk.

04

Data breaches and rights

Procedures and responsibility for any accident, notifications, requests for access, rectification, cancellation and opposition.

05

Measures and suppliers

Technical and organisational measures, due diligence on managers and contract clauses proportionate.

06

Training and DPO support

Awareness of the personnel, support to internal references and specialist support ongoing basis.

The DPA and GDPR

One framework, requirements applied precisely.

The LPD switzerland and the GDPR european share many of the same principles, but the scope, terminology, obligations and methods of notification are not the same. Check which rules apply really to your organization and build an integrated system, avoiding both gaps is pointless bureaucracy.

When the GDPR may apply to you

For example, when you offer goods or services to individuals in the Eu or monitor the behavior. The applicability is evaluated on the individual case, together with the international flows and roles in the supply chain.

The path

Five steps, clear results.

1

Scope

Organization, data, processes and jurisdictions.

2

Analysis

Deviations, risks and responsibilities.

3

Remediation

Documents, procedures, contracts and measures.

4

Activation

Training e integrazione nei processi.

5

Control

Audits, upgrades and support.

Privacy and ISO systems

A natural foundation for ISO/IEC 27701 and ISO/IEC 27001.

The governance of privacy can be integrated with the system of information security management. We align responsibilities, risks, controls, and the evidence to reduce duplication and to prepare the organization checks, customers, partners, and independent bodies.

Actionable results

A clear picture of conformity, available evidence, motivated decisions and improvement program that remains alive after the initial project.

Learn about the certifications ISO →
Initial consultation

Understanding where you stand is the first step towards better data protection.

Tell us about your background: we help you define the perimeter, priority, and path of adaptation.

Email info@sbgs.ch