Data protection workshop · GDPR + revised FADP · 1 day

Data-protection workshop for SMEs (1 day, on-site or remote)

You want to know where your company stands on data protection, without immediately committing to a multi-month advisory mandate. In a single day, the SIDD data protection workshop delivers a clear picture: assessment, gap list, prioritisation, next steps. Including a concrete report.

CHF 2'500 – 5'000 1 day GDPR + revised FADP
Data Protection Workshop for SMEs - GDPR and revised FADP
Workshop under Professional secrecy

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide
Dr. Dominic Staiger

Responsible for this workshop

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

Leads data protection workshops for SMEs, from the IT setup review through privacy notices and data processing agreements to the technical quick check of technical and organisational measures.

LinkedIn profile

How the data protection workshop helps your SME

A day that creates clarity, operationally and for the next 12 months.

  • Understanding GDPR/revised FADP requirements and the risk of fines
  • Identification of data collection points with missing or incomplete data protection notices
  • Identification of unknown data protection incidents and unclear processes
  • Feedback on the data protection compliance of planned new business models
  • Determination of the data processing agreements (DPAs) required
  • Status of the legal requirements (data protection notices, ROPA, TOMs)
  • Strengthening customer trust through a documented status

Workshop agenda (hour by hour)

Format: 1 day (3 h workshop + 2 h preparation + 3 h follow-up). The workshop itself via Teams or on site.

– 2 weeks: preliminary briefing

Questionnaire on the company, IT setup, industry and critical data processing activities.

– 1 day: preparation

2 h of SIDD preparation, analysis of your information, identification of focus points.

0:00 – 0:30: introduction & company profile

Business model, customers, data categories, critical processing activities.

0:30 – 1:30: data protection fundamentals & ROPA

Status of GDPR/revised FADP compliance, records of processing activities, data protection notices.

1:30 – 2:30: DPAs, TOMs & third-country transfers

Data processing agreements, technical and organisational measures, transfers.

2:30 – 3:00: prioritisation & Q&A

Prioritise top risks, open questions, next steps.

+ 5 days: report

3 h of SIDD follow-up, list of gaps with prioritisation and recommended actions.

Package & price

The workshop is a flat-rate package. Complexity surcharges depending on the industry (e.g. medical technology).

What are the next steps after the workshop?

You decide afterwards, there is no obligation to engage us further.

Type of findingRecommended follow-up service
Missing data protection notices / ROPA gapsDPO Switzerland oder DPO EU
No designated DPO / executive management riskExternal DPO (EU) / DPO Switzerland
Selling in the EEA without an EU representativeEU representative from CHF 600/year
Selling in the UK without a UK representativeUK representative
TOM weaknesses / vendor review pendingVulnerability Scan oder ISO 27001 consulting
Complex processing (health, HR)Trusted Third Party

What happens after the engagement is awarded?

Engagement

By email. You receive a preparation checklist with all the information required in advance.

Preparation

We analyse your information and prepare the workshop.

Workshop

3 hours via Teams or on site. All key data protection topics are covered.

Report

You receive the report with gaps ranked by priority. Optionally, we support you as DPO Switzerland oder DPO EU further.

Why SIDD?

Why you should assess your SME's data protection status with SIDD: in a single day, without a lengthy mandate, yet with the depth of a law firm that has its own technical team.

Getting started without a lengthy mandate

The workshop is intended as an entry-level product and not as a disguised consulting contract. In a single day you gain a clear picture and then decide freely whether and how to proceed, for example with an external DPO or a gap audit.

Law and technology in a single session

At least two advisors take part in the workshop, one from data protection law and one from information security, supplemented if needed by a subject-matter expert. This allows us to assess privacy notices, data processing agreements and your TOMs in the same session rather than in separate mandates.

Led by senior experts, not a junior team

The workshop is led by experienced specialists around Dr. iur. Dominic Staiger (LL.M., CIPP/E). You speak directly with the people who assess the gaps, not with a downstream research team.

A concrete report instead of slides

Instead of a presentation, you subsequently receive a written report with a prioritised list of gaps and next steps. This gives your executive management a solid basis for decisions on budget and measures.

GDPR and revised FADP at the same time

We assess your status against both frameworks relevant to SMEs, the Swiss revised FADP and the GDPR. Where needed, we draw on our experience from mandates in CH, the EU, the UK and the US, for example regarding international data flows and suppliers.

Speak openly, stay protected

During the workshop you disclose openly where things are going wrong, including data protection incidents not yet identified. To the extent that Dr. Staiger acts as a lawyer, what is disclosed is subject to Swiss professional secrecy under Art. 321 SCC.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For the SME workshop, concretely, LexCommand checks your status against the revFADP and the GDPR in parallel and lines up overlapping duties, so every entry in the report's prioritised gap list, from privacy notices to processor agreements to the Art. 30 register, traces to the exact provision behind it.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions before engaging us

On site or remote?

Both are possible. The standard is via Microsoft Teams. On-site workshops are billed according to effort and travel costs, gladly in the Zug area.

Who should take part?

Executive management, IT managers and, where applicable, marketing/sales (for data collection points). The ideal number of participants is 2–5.

What does the workshop cost?

CHF 2'500 – 5'000 as a flat fee. Complex sectors (medical technology, health, FINMA) are at the upper end.

What does the report contain?

A list of gaps with prioritisation (critical / high / medium), concrete recommendations for action, a cost estimate for the next steps and references to templates or external resources.

Can we extend the workshop afterwards?

Yes. Many clients engage us after the workshop as DPO Switzerland, DPO EU or for a follow-up mandate.

Are the workshop contents subject to confidentiality?

Yes, Art. 321 SCC. All information and the report are shared exclusively with the persons you designate.

Workshop in one day, a clear picture for the next 12 months.

First download our self-check, or request a workshop date directly.