The demand that hasn’t called yet Log in
getfishnet
Test my eligibility

Change your language and country?

You are currently viewing the Switzerland version, in English. Another version may be better suited to your situation.

Stay on this version Change version
Market reading · it cybersecurite

New Swiss DPA: evidence can open the market

How to map real processing, assign responsibility and turn Swiss DPA evidence into commercial trust without promising compliance.

getfishnetDocumented analysis20269 min read

The contract looked close. The product met the need, the price had been accepted and the sales team knew the next step. Then the buyer's questionnaire arrived: which personal data is processed, in which countries, by which processors, for how long, and who decides after a breach? The privacy notice existed, but the answers were scattered across business teams, IT, the cloud provider and management. Since 1 September 2023, Switzerland's revised Federal Act on Data Protection has required businesses to understand how processing works in practice. The issue is broader than compliance. For a B2B provider, clear evidence can reassure a buyer, shorten supplier onboarding or make a demanding market more accessible. This reading follows one customer-data process from mapping to decision. It then shows how getfishnet would assess a trust-led acquisition strategy without turning a legal duty into a sales promise.

What does the new Swiss DPA change for a business in 2026?

The new Swiss DPA requires a business to explain its data processing, assign responsibility and evidence the measures taken. It is neither just a privacy notice nor a project that ended when the law entered into force.

Parliament adopted the fully revised act on 25 September 2020. The new law and its implementing ordinances entered into force on 1 September 2023. The Federal Office of Justice describes the reform as an adaptation of data protection to digital use and growing cross-border flows.

Three years later, the date remains a reference point but says nothing about a company's current position. A new CRM, employee portal, cloud provider, prospecting system or AI feature can change the data collected, recipients and risk. The useful question is not “did we prepare for September 2023?” but “can we explain the processing running today?”

The Federal Data Protection and Information Commissioner, the FDPIC, highlights duties to provide information, access rights, data protection by design and by default, and the reporting of selected breaches. These do not apply identically to every case. They are control points to connect with the purpose, data, people, systems, suppliers, countries, retention, risks and decision.

Which processing activity should be mapped first?

Map the activity that combines a real change, a near-term decision and enough risk to mobilise the business. Starting with one defined flow avoids an abstract inventory that produces neither action nor usable evidence.

Consider a services company replacing its sales-management system. The new tool will hold prospect details, interaction histories, qualification notes and perhaps partner data. External providers will handle some hosting and support. The project has a budget, decision date and identifiable owners, making it a better starting point than a general review of every document.

How to read the diagram. Data does not belong to IT merely because it sits in software. The business defines its use, technical teams control part of the operation, providers perform governed tasks and management owns decisions that exceed one team's authority.

Mapping follows the data, not the organisation chart. It begins when information enters the process and ends when it is deleted, returned or anonymised. At each stage it links an action to an accountable person and accessible evidence.

In its cloud-computing guidance, the FDPIC states that the customer remains responsible for compliance when processing is entrusted to a cloud provider. The customer must review processor terms, disclosures abroad, security, subprocessors and support for requests or incidents. The contract is evidence within the map, not a substitute for it.

Which processing activity should be mapped first?Which processing activity should be mapped first?
  1. 1Prospect provides data
  2. 2Sales team qualifies the enquiry
  3. 3CRM stores and organises
  4. 4Approved providers host or support
  5. 5Business owner decides the use
  6. 6Security and data protection check the conditions
  7. 7Management resolves material gaps
  8. 8Retain, correct, suspend or delete

Which data and responsibilities should the map connect?

The map should connect purpose, systems, recipients, retention, security and decision-makers. An application list is inadequate if it cannot explain why processing exists and who can change it.

An actionable file answers seven questions, each tied to a decision rather than a pile of documents.

Mapping often exposes a difference between stated practice and system behaviour. A retention period may be written but not configured. A supplier may be known while its subprocessors are not. A named owner may lack authority to stop the processing.

Evidence need not be a long report. It may be a contract, setting, log, dated decision or test. Its value comes from the link between the observed fact, the decision owner and the next action.

QuestionAnswer ownerUseful evidenceDecision enabled
Why do we collect the data?Business ownerapproved purpose, journey and noticeretain or reduce collection
Which data is really present?Business and technical teamsfields, data dictionary or screenseparate what is needed from legacy data
Where does it flow?Architecture and suppliersflow map, locations and interfacescontrol access and disclosures
Who acts for whom?Management, legal or data protectionroles and processing clausesallocate obligations
How long is it retained?Business and operationsrule, configuration and deletion logclose the gap between policy and system
How are rights handled?Designated teamprocedure and example responseverify operational capability
What happens after a breach?Security, business and managementlog, escalation and decision criteriacontain, assess, report and inform

How does data protection by design change a digital project?

Data protection by design brings minimisation, access, retention and security into the project before launch. Default settings should restrict processing to what is necessary for the stated purpose.

Article 7 DPA places data protection within service design. The FDPIC's cloud guidance makes the consequence clear: if the standard service cannot control the risks, the business must find suitable safeguards, choose another solution or avoid that outsourcing arrangement.

For the CRM, ask practical questions. Are all free-text notes necessary? Should a salesperson see another region's records? Should inactive contacts remain accessible indefinitely? Can a full export be downloaded without an alert? What happens to an employee account when its user leaves?

The project gains a decision sequence: remove unnecessary data, restrict access, set retention, document suppliers, test sensitive operations and prepare for incidents. Compliance becomes visible because it changes the product and its operation.

When is a processing register or impact assessment required?

A processing register or impact assessment is required when the DPA's conditions are met. Its operational value begins earlier, as soon as important processing can no longer be explained, documented or decided reliably.

A record of processing activities organises purposes, categories of people and data, recipients, retention and security measures. Exceptions for selected private companies mean it is not a universal requirement without a case review. Even where an exemption may apply, proportionate mapping helps manage a project, answer a customer or handle an access request.

A data protection impact assessment applies where planned processing is likely to create a high risk to personality or fundamental rights. It describes the project, assesses risk and examines measures. The FDPIC also notes that appointing a data protection adviser is optional for private companies, subject to specific conditions where they seek the DPA's impact-assessment facilitations.

Commercially, a provider should not sell a heavy assessment merely because a keyword appears. It first identifies the processing, risk, existing work and required decision. A short assignment may reveal a deeper need or avoid a disproportionate audit.

Who decides after a data security breach?

The controller decides after a data security breach, using technical facts, the context of affected people and a risk assessment. The processor must notify the controller promptly and provide available information; it does not replace the controller's decision.

Under Article 24 DPA, a breach likely to result in a high risk to personality or fundamental rights must be reported to the FDPIC as soon as possible. Affected people must also be informed where necessary for their protection. FDPIC guidance published on 23 April 2025 distinguishes the high risk that triggers reporting from the protective need that can justify informing individuals.

How to read the diagram. Urgency does not justify a fact-free decision. Technical teams document the event, the business explains the use of the data, the competent function prepares the assessment, and the controller records the decision and reasons.

The FDPIC's 33rd activity report for 2025/2026 records more than 2,000 reports of potential data protection breaches, 156 interventions with controllers, 22 preliminary examinations and 9 investigations during the reporting year. These categories are not a sales funnel and do not measure every Swiss incident. They do show a functioning supervisory practice.

Who decides after a data security breach?Who decides after a data security breach?
  1. 1Technical team
  2. 2Business owner
  3. 3Data protection
  4. 4Accountable management
  5. 5FDPIC / affected people

How can processing be prioritised without auditing everything at once?

Prioritisation combines potential impact with the evidence gap. Important but well-controlled processing does not require the same urgency as a sensitive, poorly documented flow tied to an imminent decision. The method selects the next effort; it does not deliver a legal verdict.

The indicative matrix below can support a first workshop. Each organisation must justify its criteria; a point's position cannot determine legal status.

Consider sensitivity, volume, affected people, recipient count, foreign disclosures, operational dependency, approaching changes and evidence quality. The score makes judgement explicit; it does not replace it. “Act now” needs an owner, deadline and decision. “Improve the evidence” may need limited documentary or technical work. “Review and monitor” needs a targeted check. “Maintain simply” does not justify a heavy assignment.

How can processing be prioritised without auditing everything at once?How can processing be prioritised without auditing everything at once?
  1. 10.78, 0.82
  2. 20.58, 0.90
  3. 30.28, 0.30
  4. 40.72, 0.45

Why can DPA evidence support access to a new market?

DPA evidence can support market access when a buyer, partner or contracting authority must assess a supplier before entrusting it with data. Evidence reduces documentable uncertainty but never guarantees onboarding or a sale.

In B2B relationships, trust often becomes verifiable material: flow map, supplier list, security measures, retention rule, incident procedure, roles and request handling. The law promises no contract in return. Missing answers can, however, prolong evaluation, generate further questions or prevent approval.

The National Cyber Security Centre's 2025 annual report stresses secure supply chains. That is a broader cybersecurity finding, not proof that every DPA control is a purchasing requirement. It nevertheless reflects a shift: suppliers are assessed not only on their product but on the dependencies and risks they introduce.

The related reading on reporting cyberattacks against critical infrastructure also distributes facts across technical teams, the business and management, but follows a different trigger and authority.

How would getfishnet build trust-led acquisition?

getfishnet would begin with target markets, the evidence buyers actually request and the partner's ability to deliver a useful first output. The strategy would remain a test, never an executed campaign or assured result.

First, identify a specific commercial moment: tender, supplier onboarding, entry into a regulated sector or major-account request. A legal duty without a buyer, deadline or deliverable is not yet an acquisition opportunity.

Then separate three offer levels: a short blocker diagnostic; implementation of priority evidence; and follow-up only where new projects or suppliers regularly create decisions. Finally, test the proposition with a partner who can promptly define scope, timing, exclusions and capacity.

Which channels should be tested without reducing the strategy to SEO?

Channel choice follows the moment when evidence becomes decisive. Search, account prospecting, phone, email, professional networks, partners, events and content can play complementary roles. No channel is retained by habit or judged on contact volume alone.

Search may reveal an existing request. Targeted outreach reaches suppliers pursuing demanding buyers. Legal, cyber, cloud, insurance and software partners may detect change earlier. Events and content make observed objections easier to understand.

How to read the diagram. Every channel feeds the same qualification. The first useful measure is not a click or meeting but the share of cases where real processing, missing evidence and a commercial decision coincide.

Acquisition cost includes media, data, tools, production and human time. Compare it with attributable margin, collection time and delivery capacity. Without those measures, getfishnet proposes a test, not a return.

Which channels should be tested without reducing the strategy to SEO?Which channels should be tested without reducing the strategy to SEO?
  1. 1Signals project, onboarding, tender
  2. 2Search and content
  3. 3Target accounts phone, email, networks
  4. 4Partners legal, cyber, cloud, software
  5. 5Events and business communities
  6. 6Qualify the real processing
  7. 7Inform or stop
  8. 8Bounded diagnostic
  9. 9Revise offer or targeting
  10. 10Deploy, then measure
  11. 11Missing evidence and near-term decision?
  12. 12Value and capacity confirmed?

Which results can be modelled before the campaign runs?

Before execution, only decision thresholds can be modelled: accessible account pool, genuinely qualified cases, initial-deliverable value, maximum acquisition cost, monthly capacity and collection time. These are assumptions to replace with measurements, not observed performance.

A cautious, central and maximum-capacity scenario can each start with accessible accounts and end with assignments the partner can deliver. Response and close rates remain unknown until testing.

This prevents two errors: treating the FDPIC's 2,000-plus reports as leads, and presenting the total value of an expected contract as acquisition revenue. Only signed, collected and attributable revenue can validate the model after execution.

VariableQuestion to resolvePosition before testing
Addressable poolHow many new accounts face the selected trigger?must be measured
Qualified casesHow many combine processing, a gap and a decision?must be measured
Initial revenueWhich deliverable can be invoiced and collected quickly?must be validated
Gross marginWhat remains after expert time and tools?must be validated
Maximum acquisition costWhat effort is acceptable against that margin?must be modelled
CapacityHow many cases can the partner start without delay?must be confirmed

When is recurring revenue genuinely justified?

Recurring revenue is justified when new projects, suppliers, processing activities or buyer requirements create regular decisions for the partner to prepare and follow. Automatic updates without useful work do not form a durable offer.

Follow-up may cover changes, subprocessors, buyer questionnaires, incident exercises or impact assessments. Its scope states what is reviewed, who decides and what is delivered. The client must name owners, report changes and make decisions; an external partner cannot sustain governance alone.

The Swiss IT and cybersecurity market page separates data protection, operational security and reporting duties.

What decision should be taken on the new DPA and acquisition?

Map one real processing activity before discussing compliance or acquisition. If the map exposes missing evidence that blocks a commercial decision, getfishnet can then assess a market-development strategy with a competent partner.

The new DPA provides a demanding framework. Commercial trust adds a growth issue only where a buyer genuinely expects evidence and the business can produce it. This reading certifies no organisation and promises no sale. It shows how to turn a broad concern into a verifiable case, then decide whether that case merits a multichannel acquisition test.

Does your market present a comparable window?

The eligibility report dates and quantifies it, then tests whether it deserves action.

Test my eligibility
Strategic development · non-exhaustive demonstration

Reading the diagram. A disease contact only progresses after proof of origin, qualification of the relationship and control of the product concerned.

Text alternative. Telephone, prescriber or incoming request follow different proofs; missing consent causes documented exit.

How can the testing cycle reach a stable operating rhythm?

Relative benchmarks: D00 sets the rules of origin and termination of contact, D14 closes the preparation, W03 to W06 tests the scripts, consents, relationships of more than thirty-six months and ceilings per product, W07 to W08 arbitrator, then M03 stabilizes documented paths. Variances are recorded before any budget extension.

Gantt chart for the testing cycle — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. The foundation secures the right to contact; exploration then measures the quality of requests before any channel stabilization.

Textual alternative. D00 sets consent, D14 audits scripts, W03–W06 tests provenance, W07–W08 cuts discrepancies, M03 maintains compliance.

What financial potential does the model make visible?

Model: 132 qualified conversations, 44 reviews and 26 new customers. Weighted average: 1 527 CHF; monthly total: 39 700 CHF. The projection concerns acquisitions agreed and allocated, without using the ceilings as margin or portfolio value. No national denominator is applied.

Breakdown of acquisitions — NON-EXHAUSTIVE DEMONSTRATION

The chart counts customers, not percentage points.

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. 26 acquisitions represent subscriptions preceded by a controlled origin and relationship; the size of a share does not prejudge either the documentary quality or the maintained value.

Text alternative. The circle distributes customers obtained after verifiable consent, never people simply called. Total: 26 customers, reread with the value specific to each channel.

How do customers, average monthly revenue, and recurring revenue correlate by channel?

Channel exploredCustomersAverage monthly revenue per customerMonthly Recurring Channel Revenue
Natural and paid referencing41 300 CHF5 200 CHF
Telephone outreach31 600 CHF4 800 CHF
Voicemails2900 CHF1 800 CHF
Email Campaigns41 200 CHF4 800 CHF
Social networks31 400 CHF4 200 CHF
Partners and prescribers32 000 CHF6 000 CHF
Events and webinars21 700 CHF3 400 CHF
Advertising retargeting11 100 CHF1 100 CHF
Strategic accounts and outbound outreach22 300 CHF4 600 CHF
Content and press relations21 900 CHF3 800 CHF
Total / weighted average261 527 CHF39 700 CHF

The value is read again with the product, the applicable ceiling and the cost of controlling the provenance. The product customers × average income totals 39 700 CHF without promising performance.

Monthly recurring revenue by channel — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. Compliant disease contacts, their converted volumes and the corresponding monthly income recompose 39 700 CHF without a value outside the table.

Alternative text. Each height associates an authorized channel, actual assigned customers, and the value specific to their product. Their addition exactly equals monthly 39 700 CHF.

How should acquisition cost be assessed before recurring revenue is scaled?

Arbitration adds proof of consent, script control, relationship data, call supervision and refusal handling and reports the charge to assigned customers. It compares legal origin, product concerned, ceiling, full cost, expected termination and service capacity then reduces any channel that weakens the proof.

Funnel to Retained Monthly Recurring Revenue — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. disease contacts whose origin is demonstrated produce raw 39 700 CHF, then 34 142 CHF after maintaining at 86 %.

Text alternative. 132 conversations become 44 journals and 26 clients for disease contacts whose provenance is demonstrated. 39 700 CHF weighted to 86 % gives 34 142 CHF.

Financial limit. The 70 francs and the sixteen bonuses limit the remuneration; they give neither margin, nor number of contracts, nor maintenance. The 34 142 CHF remains a hypothesis, without reference value or forecast.

Text references: Federal Office of Public Health, decision and rules applicable to intermediaries; monitoring activity report. The federal office describes ceilings and outreach, while consent and history remain evidence specific to the file. The addresses remain in the internal source register. Each topic retains a clear documentary boundary.

The ISA 2024 processes the status. The ICA 2022 processes the contract trace. The nLPD 2023 shows another prequalification of the contact and data.

CORRELATED READINGS — DYNAMIC MODULE

The thematic map will link rules 2024 of health insurance intermediaries to ISA for status, ICA for contract and nLPD for legality of contact data. The links remain governed without implying equivalence.

The September deadline has passed; each origin of contact must always be able to be explained The report isolates the proof and the next action without reopening the 2024 rules of health insurance intermediaries.

g
getfishnet editorial team

The topic is broken down into entities, attributes, evidence, channels, costs and decision points. Institutions are cited in the text; no external resource interrupts the reading path.

documented

All market readings.

Could your next contract already depend on missing evidence?

Our 100% free eligibility test examines your acquisition challenge, potential fit and whether a tailored strategy could open new opportunities.

Test my eligibility at no cost
Test d'éligibilité

Vérifions votre marché.

Dossier reçu.

Nous étudions votre marché et rendons le verdict sous 48 heures.

Fermer

Deux minutes. Verdict sous 48 heures, sans engagement.

Vérifier mon éligibilité