de en
Data Protection

Towards GDPR Compliance as a Best Practice: a Primer for Swiss SMEs

Philippe Gilliéron

Citation: Philippe Gilliéron, Towards GDPR Compliance as a Best Practice: a Primer for Swiss SMEs, in: Jusletter IT 26 September 2018

Over the last years, privacy concerns have significantly increased, and the recent adoption of the GDPR in May 2018 coupled with the Cambridge Analytica scandal now give cold sweats to most companies. SMEs are struggling to find their way in a field they have little understanding of (if any), and find it hard to know where to start from. This paper aims at providing them some basic information and checklist to start building a privacy management program without incurring significant expenditures or being a privacy expert.


Table of contents

  • I. Introduction
  • II. Footprint towards the Setting up of Privacy Management within SME
    • A. Data Mapping
      • 1. Mapping
      • 2. Privacy Impact Assessments
    • B. Privacy Policy and Notices
      • 1. Policies and Notices
      • 2. Lawful Basis for Processing
    • C. Vendor Management
      • 1. Agreements in Place
      • 2. Future Agreements
    • D. Data Breach Response Plan
    • E. Maintain Procedures for Inquiries and Complaints
    • F. Training
    • G. Need for a Data Protection Officer?
  • III. Conclusion
Please log in to read the full text.
Register for Campus? More
Login Poster
Baurechtspartner AG
Rechtsanwältin / Rechtsanwalt 100% Baurechtspartner AG
BGPartner AG (Zürich)
Anwältin / Anwalt BGPartner AG (Zürich)
Gfeller Budliger Kunz Rechtsanwälte
Rechtsanwältin / Rechtsanwalt 60-100% Gfeller Budliger Kunz Rechtsanwälte
WILD DUBACH AG Rechtsanwälte (Hergiswil)
Anwalt*in Familienrecht 80 - 100 % WILD DUBACH AG Rechtsanwälte (Hergiswil)
sozialversicherungen glarus
Direktor*in Sozialversicherungen Glarus sozialversicherungen glarus
/dam/jcr:9e9ce6db-0f4a-45c0-bb41-6f9887b960a9/zhaw.webp
Infoveranstaltung CAS Compliance [...]
/dam/jcr:ae6ea1f0-4308-4086-a761-83bc23bfba25/Swiss-Legal-Tech-Logo-267x300.png
Swiss Legal Tech Conference
/dam/jcr:d85df556-4302-43d6-aece-94d632ee9245/uni_li_logo.jpg
Intensivkurs «Internationales [...]
/dam/jcr:274399e0-95f5-417e-8939-fe54d7fbfc49/Uni_Basel_Recht_aktuell_Neues_Logo.webp
Recht aktuell-Tagung: «Aktuelle [...]
/dam/jcr:78d820ad-8ef9-4865-a1e9-bb678a9af215/Dike_logo.png
Schweizer Enforcement Tagung 2026
/dam/jcr:d85df556-4302-43d6-aece-94d632ee9245/uni_li_logo.jpg
Intensivkurs «Strafrecht und Unternehmen»
/dam/jcr:f3fc0eb9-f291-4e27-abdf-7b7a481595ef/Schulthess_Forum_rgb.svg
Strafprozessordnung 2026 Digitale [...]
/dam/jcr:8a7f3354-213a-43de-a59d-a7475e221373
Rechtssicher mit KI – Ganztageskurs [...] Begrenzte Plätze.
/dam/jcr:48e078d1-06c6-4c49-81c7-3704e8d9abf9/Uni_StGallen_irph_logo.webp
CAS Prozessführung – Civil Litigation
/dam/jcr:d85df556-4302-43d6-aece-94d632ee9245/uni_li_logo.jpg
Intensivkurs „Strafrecht und [...]
/dam/jcr:2513d656-4f19-4079-ac7b-20994bb9e76e/uzh%20logo.webp
CAS Safety in Healthcare
/dam/jcr:8a7f3354-213a-43de-a59d-a7475e221373
Rechtssicher mit KI – Ganztageskurs [...] Begrenzte Plätze.
/dam/jcr:2e9579bd-bc09-4fea-a327-9cd7e3831be2/HSLU_Logo_DE_Schwarz.webp
MAS Economic Crime Investigation
/dam/jcr:d85df556-4302-43d6-aece-94d632ee9245/uni_li_logo.jpg
Executive Master of Laws (LL.M.) in [...]
/dam/jcr:c2a09a2e-ee26-4225-a6e7-2d9825723fad
CAS Compliance in Financial Services Institut für Rechtswissenschaft und [...]
/dam/jcr:48e078d1-06c6-4c49-81c7-3704e8d9abf9/Uni_StGallen_irph_logo.webp
CAS Haftpflicht- und Versicherungsrec[...]
/dam/jcr:d85df556-4302-43d6-aece-94d632ee9245/uni_li_logo.jpg
Executive Master of Laws (LL.M.) im [...]
/dam/jcr:d85df556-4302-43d6-aece-94d632ee9245/uni_li_logo.jpg
Executive Master of Laws (LL.M.) im [...]
/dam/jcr:2e9579bd-bc09-4fea-a327-9cd7e3831be2/HSLU_Logo_DE_Schwarz.webp
MAS Information & Cyber Security
/dam/jcr:8a7f3354-213a-43de-a59d-a7475e221373
Rechtssicher mit KI – Ganztageskurs [...] Begrenzte Plätze.