Data protection impact assessment: when your SME needs one

The data protection impact assessment is the most thoroughly misunderstood duty in the Swiss Data Protection Act. In SMEs we meet two camps. One has never heard the term. The other fills in a template for every new tool that is longer than the contract with the provider, and never looks at it again. Both camps miss what Art. 22 FADP is meant for: thinking things through once, in a structured way, before a risky data processing activity goes live. The effort is smaller than the term sounds. The thinking behind it, however, cannot be replaced by any template.

What the data protection impact assessment requires

Art. 22 FADP is pleasantly short. If a planned processing of personal data can entail a high risk for the personality or fundamental rights of the people affected, you prepare a data protection impact assessment beforehand. It contains three things: a description of the planned processing, an assessment of the risks for the people affected, and the measures you take to keep those risks under control.

That is all. The law prescribes neither a form nor a minimum length. It requires the documented answer to a question a well-run business asks anyway: what can go wrong here for the people whose data we handle, and what do we do about it?

The term sounds like corporate counsel. The thinking behind it fits on a beer mat.

When you need one and when you do not

The law names two constellations explicitly: extensive processing of sensitive personal data, and systematic extensive monitoring of public areas. Added to that is the general formula: a high risk can also result from the use of new technologies, or from the nature, scope, circumstances and purpose of the processing.

Translated into the everyday life of a Swiss SME, it looks like this.

As a rule, no DPIA is needed for payroll, a CRM with business contacts, newsletter mailings or the usual filing in a standard cloud. These are ordinary processing activities without high risk. The law does not want to capture them at all.

Candidates for a DPIA look different. An AI tool that pre-sorts application files or analyses customer conversations. Health data at scale, for instance in medical-adjacent services or in pension provision. Video surveillance that goes beyond the front entrance. Systematic monitoring of employees or customers.

The point about new technologies is relevant right now. Many SMEs are introducing AI tools these months, often on personal data, and often nobody has asked the risk question. "Use of new technologies" is in the law verbatim. Not every use of ChatGPT triggers a DPIA because of that. But the question comes up far more often today than it did two years ago. Which data counts as sensitive in the first place is sorted in our post on data classification.

The typical case we see: a company wants to pre-sort job applications with an AI tool. The provider assures them everything is compliant and hosted in Switzerland. Both can be true and still answer the wrong question. Hosting answers no risk question when the risk is that an algorithm sorts people out without anyone being able to trace why. Exactly these points are what a DPIA brings to the table before the contract is signed: what happens to rejected files, is there automatic rejection without a human look, do applicants learn that a machine is reading along? In our experience the tool survives this check most of the time. It is only configured differently than the provider proposed.

That leaves the grey zone. Many cases are neither clearly harmless nor clearly sensitive, and the law does not take the judgement off your hands. A usable compass: switch perspective and imagine the person affected. Would they feel uncomfortable if they knew exactly what happens with their data, and would they have good reasons to? If you hesitate at this question, the hesitation is the answer. Then the closer look is worth it, if only to record cleanly why in the end no high risk exists.

The fine that does not exist

Now for the part hardly any template vendor tells you. The FADP has fines of up to CHF 250,000, and they target the responsible person. But the omission of a data protection impact assessment is not in the catalogue of fines. Art. 60 FADP penalises other things, above all violated information and access duties and false statements to the FDPIC, the Swiss data protection authority. The missing DPIA as such does not appear there.

That is no free pass. Whoever does the DPIA out of fear of a fine does it wrong: as a thick document for the filing cabinet, the main thing being that it exists. The value lies elsewhere. After an incident or a complaint, the DPIA is your evidence that you saw, assessed and treated the risk. The duty-of-care question hits managing directors personally in data protection, we took that apart in our post on FADP liability for managing directors. Standing there empty-handed at that question is more unpleasant than any fine missing from the catalogue.

Added to that: the FDPIC needs no fine to become unpleasant. It can investigate a processing activity and order measures, up to changing or stopping the processing. A project stopped after go-live costs a multiple of the assessment that would have defused it beforehand. That is the realistic risk, and it has nothing to do with the catalogue of fines.

The fear-selling around the FADP follows the same pattern as in the security market: first the fine is made big, then the product is sold that supposedly protects against it. A template protects against nothing. At most it formats the thoughts you have to produce yourself.

How much effort is appropriate

A clear case fits on a few pages in our experience: what is processed, what can go wrong for the people affected, which measures stand against it, what residual risk remains and who accepted it. Add the date and who stands behind it. The law demands no more.

The risk assessment itself needs no matrix theatre with colour codes and scores either. Two questions in plain words are enough: how plausible is it that something goes wrong, and how badly would it hit the people affected? "A rejected applicant never learns that a machine sorted him out" is a more precise risk description than any orange cell in a heat map. Whoever can phrase the risk in an understandable sentence has understood it. Whoever only enters a number, mostly not.

If a high risk remains despite the measures, Art. 23 FADP requires consulting the FDPIC. It has two months for that, one month longer for complex processing. For private companies there is a calm shortcut: whoever has appointed a data protection advisor under Art. 10 FADP and consults them can skip the consultation of the FDPIC. An administrative procedure with a waiting period becomes an internal conversation. For an SME with more sensitive data processing, that alone is often a good reason to fill the role.

The most expensive variant is over-compliance. The thick template costs you twice: when filling it in, and afterwards at every system change after which nobody updates it any more. A DPIA that no longer matches reality is decoration. Two precise pages someone maintains beat the thick binder nobody reads.

Three questions before every new project

For the duty to work in everyday business, it belongs at the start of projects and in the purchasing process. In the annual audit it is too late.

Three questions are enough for the triage:

  1. Are we using a technology whose behaviour we cannot yet assess with confidence ourselves? AI analysis, profiling and automated decisions belong here.
  2. Are we processing sensitive personal data at a notable scale? Meaning health data, biometric data, or information on religion and political views.
  3. Are we observing people systematically? Video, location tracking, analysis of work behaviour.

Three times no: record in two sentences that the question was checked and why no DPIA is needed, and carry on. This two-liner is worth more than it looks. It shows later that the question was asked.

At least one yes: do the DPIA, lean and honest. Description, risks, measures, residual risk. If you notice in the process that nobody in the company knows exactly which personal data is processed where, you have found the underlying problem. Then the overview every piece of data protection work builds on is missing, and the DPIA is a good occasion to catch up on it. Our post on the Swiss Data Protection Act gives an overview of the remaining duties.

Before the next tool goes live

The data protection impact assessment is one of the few compliance duties that delivers value when dosed correctly. Once per risky project, it forces the question nobody else asks: what can go wrong here for the people affected? Dosed wrongly, it becomes a ritual that eats time and protects nothing.

If you have a project on your desk right now and are unsure whether it is a DPIA case, we are happy to sort that out with you in an initial conversation. No template selling, and a short conversation is usually enough.

And independently of that, we are curious: when did someone in your company last ask, before a project started, what could go wrong for the people affected?