Data Protection Lawyers Switzerland
Lexify offers Data Protection Officer activities conducting data protection management.

Data Protection Management
DPA requires a mapping of the processes and data managed by the company. This mapping is the basis for legal compliance and is to be carried out by means of a management tool. The specialists at Lexify, together with ‘Privacy Swiss’, support you in this obligation.

DATA PROTECTION OFFICER
The Data Protection Officer is the person who relates to the authorities and supports the entity in its data management. Do not leave your data in the hands of people who do not understand your business.

Swiss Representative
Foreign companies operating in Switzerland require a representative. Lexify acts as a representative for these entities and ensures compliance with Swiss law.

Contracts
Are you transmitting data abroad? Do you have a data processor? Your contracts must be appropriate. Lexify supports you in complying with data protection regulations.

GDPR and European Regulation
Lexify will also support you with all obligations arising from the “EU Regulation 2016/679” GDPR. Lexify will also act as a representative in the European Union for Swiss and third-country companies in order to be compliant with European legislation.
Frequently Asked Questions
What are the key changes introduced by the new Swiss Federal Act on Data Protection (nFADP)?
The revised nFADP, in force since September 2023, introduces several significant changes, including mandatory data breach notification to the Federal Data Protection and Information Commissioner (FDPIC), the right to data portability, stricter requirements for automated decision-making, and enhanced requirements for data processing agreements. Lexify helps organisations assess their current practices and implement the necessary changes.
Is a Data Protection Officer (DPO) mandatory for my company in Switzerland?
The Swiss nFADP does not mandate a DPO, but it is strongly recommended for organisations that process large volumes of sensitive personal data. Under the GDPR, a DPO is mandatory for public authorities, organisations engaged in large-scale systematic monitoring, and those processing special categories of data at scale. Lexify can help determine your obligations and provide external DPO services.
What contracts are needed when sharing data with a third-party processor?
Whenever you engage a third party to process personal data on your behalf (for example, a cloud provider or a marketing platform), you must enter into a Data Processing Agreement (DPA). This contract defines the scope of processing, the security measures to be implemented, and the obligations of the processor. Lexify drafts and reviews these agreements to ensure they meet the requirements of both the Swiss nFADP and the GDPR.
