Data protection Documentation Obligations

The revised data protection law prescribes documentation obligations for companies. It may be advisable to create and maintain certain documentation even if not explicitly required. Documentation facilitates compliance and monitoring of obligations.

DocumentUp to 250 employees *Up to 250 employees **More than 250 employees *More than 250 employees **
Register of Processing Activities (Art. 12 nDSG)Generally mandatory, exception possible for SMEsmandatory, exception possible for SMEsMandatoryMandatory
Inventory of ApplicationsRecommendedRecommendedRecommendedRecommended
Internal Data Protection PoliciesRecommendedRecommendedRecommendedRecommended
Information for Employees (Art. 6 u. 19 nDSG; art. 328b CO)MandatoryMandatoryMandatoryMandatory
Privacy Policy for Website (Art. 6 u. 19 nDSG)MandatoryMandatoryMandatoryMandatory
Process for Data Subject Rights (Art. 28 nDSG; Art. 16 ff. nDSV)RecommendedMandatoryRecommendedMandatory
Documentation of Data Security Measures (Art. 8 nDSG; Art. 1 ff. nDSV)RecommendedRecommendedRecommendedRecommended
Guidelines for Data Security Breaches (Art. 24 DSG, Art. 15 nDSV)RecommendedMandatoryMandatoryMandatory
Data Protection Impact Assessment (Art. 22 nDSG)RecommendedMandatoryRecommendedMandatory
Agreements with Data ProcessorsMandatoryMandatoryMandatoryMandatory
Access Logs (Art. 8 nDSG; Art. 4 nDSV)******

Legend:

PD = Personal Data

* No processing of particularly sensitive PD

** Processing of particularly sensitive PD

*** Mandatory if processing a large volume of particularly sensitive personal data in an automated manner or conducting high-risk profiling, and data protection cannot be ensured through preventive measures.



Do you have any questions?

I will gladly assist you. Don't hesitate to contact me.