{"id":1359,"date":"2023-07-14T08:46:48","date_gmt":"2023-07-14T06:46:48","guid":{"rendered":"https:\/\/moorlaw.digicube.dev\/rechtsgebiet\/what-should-smes-do\/"},"modified":"2023-11-18T12:27:41","modified_gmt":"2023-11-18T11:27:41","slug":"what-should-smes-do","status":"publish","type":"rechtsgebiet","link":"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/what-should-smes-do\/","title":{"rendered":"What should SMEs do?"},"content":{"rendered":"\n<p>The revised data protection law came into effect on 01.09.2023 and is immediately applicable. There are only a few transitional provisions tailored to specific circumstances. Non-compliance with data protection regulations can result in fines of up to CHF 250,000.00. Compliance should therefore be taken seriously.<\/p>\n\n<p>So, what needs to be done? Take a structured approach. This will ensure that you know where personal data is being processed, how it is protected, and whether additional measures need to be taken.<\/p>\n<div class=\"gb-container gb-container-c064a007\" id=\"bestandsaufnahme\">\n\n<h2 class=\"wp-block-heading\" id=\"h-bestandesaufnahme\">Inventory<\/h2>\n\n\n\n<p>Compliance with the obligations under the data protection law requires knowing which personal data is collected within your company, where and how it is processed, how it is already protected, and whether it is disclosed to third parties or processors or transferred abroad.<\/p>\n\n\n\n<p>The inventory is the basis for identifying the necessary measures.<\/p>\n\n\n\r\n<section id=\"digicube-block-6548bfb623e1b\"  class=\"chooseposttype-wrap\" >\r\n    <ul class=\"cpt-posts\">\r\n                   <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/what-should-smes-do\/inventory\/\">Inventory<\/a>\r\n                <\/li>\r\n                   <\/ul>\r\n<\/section> \n<\/div>\n<hr class=\"wp-block-separator has-text-color has-accent-color has-alpha-channel-opacity has-accent-background-color has-background category-separator\"\/>\n<div class=\"gb-container gb-container-af71f97a\" id=\"identifizierung\">\n\n<h2 class=\"wp-block-heading\" id=\"h-identifizierung-der-zu-treffenden-massnahmen\">Identification of Measures to be Taken<\/h2>\n\n\n\n<p>Based on the inventory, you can identify the measures necessary to comply with the new data protection law and work on their implementation. Identifying the measures to be taken requires understanding your obligations under the revised data protection law. It may be advisable to implement certain measures even if there is no legal obligation to do so.<\/p>\n\n\n\r\n<section id=\"digicube-block-6548bfb623ea2\"  class=\"chooseposttype-wrap\" >\r\n    <ul class=\"cpt-posts\">\r\n                   <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/what-should-smes-do\/identification-of-required-measures\/\">Identification of required Measures<\/a>\r\n                <\/li>\r\n                   <\/ul>\r\n<\/section> \n<\/div>\n<hr class=\"wp-block-separator has-text-color has-accent-color has-alpha-channel-opacity has-accent-background-color has-background category-separator\"\/>\n<div class=\"gb-container gb-container-d3baa72e\" id=\"umsetzung\">\n\n<h2 class=\"wp-block-heading\" id=\"h-umsetzung-der-massnahmen\">Implementation of Measures<\/h2>\n\n\n\n<p>Once you have identified the measures to be taken, you can begin implementing them. Consider the following in particular:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Privacy policy for customers, contractual partners, etc.<\/li>\n\n\n\n<li>Privacy policy for employees<\/li>\n\n\n\n<li>Application list<\/li>\n\n\n\n<li>Record of processing activities (if required)<\/li>\n\n\n\n<li>etc.<\/li>\n<\/ul>\n\n\n\r\n<section id=\"digicube-block-6548bfb623ee3\"  class=\"chooseposttype-wrap\" >\r\n    <ul class=\"cpt-posts\">\r\n                   <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/what-should-smes-do\/implementation-of-data-protection-measures\/\">Implementation of Data Protection Measures<\/a>\r\n                <\/li>\r\n                   <\/ul>\r\n<\/section> \n<\/div>\n<hr class=\"wp-block-separator has-text-color has-accent-color has-alpha-channel-opacity has-accent-background-color has-background category-separator\"\/>\n<div class=\"gb-container gb-container-1dd6bee1\" id=\"organisatorische\">\n\n<h2 class=\"wp-block-heading\" id=\"h-organisatorische-vorkehrungen\">Organisational Measures<\/h2>\n\n\n\n<p>The revised data protection law does not prescribe specific requirements for organising companies. However, organisational measures can simplify compliance with the revised data protection law and provide you with an overview. They can also facilitate your response to inquiries from affected individuals or in the event of data security breaches.<\/p>\n\n\n\r\n<section id=\"digicube-block-6548bfb623f1e\"  class=\"chooseposttype-wrap\" >\r\n    <ul class=\"cpt-posts\">\r\n                   <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/what-should-smes-do\/organisational-data-protection-measures\/\">Organisational Data Protection Measures<\/a>\r\n                <\/li>\r\n                   <\/ul>\r\n<\/section> \n<\/div>\n<hr class=\"wp-block-separator has-text-color has-accent-color has-alpha-channel-opacity has-accent-background-color has-background\"\/>\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\"><div class=\"gb-container gb-container-98a7c598\">\n<div class=\"gb-container gb-container-11a0998e\">\n\n<p><strong>Services<\/strong><\/p>\n\n\n\r\n<section id=\"digicube-block-653b8880876e9\"  class=\"chooseposttype-wrap\" >\r\n    <ul class=\"cpt-posts\">\r\n                   <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/service\/legal-services-for-corporates\/\">Legal Services for Corporates<\/a>\r\n                <\/li>\r\n                   <\/ul>\r\n<\/section> \n<\/div>\n\n<div class=\"gb-container gb-container-25f5bccc\">\n\n<p><strong><strong>Further reading<\/strong><\/strong><\/p>\n\n\n\r\n<section id=\"digicube-block-653b888087772\"  class=\"chooseposttype-wrap\" >\r\n    <ul class=\"cpt-posts\">\r\n                   <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/what-should-smes-do\/organisational-data-protection-measures\/\">Organisational Data Protection Measures<\/a>\r\n                <\/li>\r\n                              <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/what-should-smes-do\/inventory\/\">Inventory<\/a>\r\n                <\/li>\r\n                              <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/what-should-smes-do\/identification-of-required-measures\/\">Identification of required Measures<\/a>\r\n                <\/li>\r\n                              <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/what-should-smes-do\/implementation-of-data-protection-measures\/\">Implementation of Data Protection Measures<\/a>\r\n                <\/li>\r\n                              <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/documentation-obligations\/\">Data protection Documentation Obligations<\/a>\r\n                <\/li>\r\n                              <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/data-protection-register-of-processing-activities\/\">Data Protection Register of Processing Activities<\/a>\r\n                <\/li>\r\n                              <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/data-protection-representation-in-switzerland\/\">Data protection representation in Switzerland<\/a>\r\n                <\/li>\r\n                   <\/ul>\r\n<\/section> \n<\/div>\n<\/div><\/div><\/div>\n\n<hr class=\"wp-block-separator has-text-color has-accent-color has-alpha-channel-opacity has-accent-background-color has-background\"\/>\n","protected":false},"excerpt":{"rendered":"<p>What needs to be done to be compliant with the new data protection act?<\/p>\n","protected":false},"featured_media":0,"parent":0,"menu_order":18,"template":"","rechtsgebiet-kategorie":[41],"class_list":["post-1359","rechtsgebiet","type-rechtsgebiet","status-publish","hentry","rechtsgebiet-kategorie-data-protection-law"],"acf":[],"_links":{"self":[{"href":"https:\/\/moor-law.ch\/en\/wp-json\/wp\/v2\/rechtsgebiet\/1359","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/moor-law.ch\/en\/wp-json\/wp\/v2\/rechtsgebiet"}],"about":[{"href":"https:\/\/moor-law.ch\/en\/wp-json\/wp\/v2\/types\/rechtsgebiet"}],"wp:attachment":[{"href":"https:\/\/moor-law.ch\/en\/wp-json\/wp\/v2\/media?parent=1359"}],"wp:term":[{"taxonomy":"rechtsgebiet-kategorie","embeddable":true,"href":"https:\/\/moor-law.ch\/en\/wp-json\/wp\/v2\/rechtsgebiet-kategorie?post=1359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}