SOC Geneva — operational 24/7 Client support Remote support +41 22 740 28 29
GUIDE · COMPLIANCE · 2026-06 · 12 MIN

nLPD two years on:
what auditors actually check

The revised Swiss data protection act is no longer new. Here is what enforcement looks like in practice — and the five gaps we still find in most SMEs.

2026-06 · 12 MIN READ

When the revised Federal Act on Data Protection (nLPD) entered into force on 1 September 2023, most Swiss SMEs did the minimum: a new privacy notice, a records-of-processing spreadsheet, and a collective sigh of relief. Two years on, the FDPIC and external auditors have moved past paperwork. They now ask organisations to demonstrate that the technical and organisational measures described on paper actually operate.

What auditors actually check in 2026

Across the audits and due-diligence questionnaires we have supported this year — for foundations, trading SMEs and international organisations alike — five areas come up in almost every review.

  • Records of processing that match reality: auditors sample two or three processing activities and trace them to the systems, contracts and retention rules behind them.
  • Breach-notification readiness: can you detect, qualify and document an incident within days, not weeks? A tested playbook matters more than a policy PDF.
  • Processor contracts (art. 9): sub-processor lists, audit rights and cross-border transfer clauses — especially for US cloud services.
  • Data-subject request handling: a named owner, a tracked mailbox and evidence of response within 30 days.
  • Retention and deletion in practice: not the schedule, but proof that deletion jobs actually ran.

The five gaps we still find

The pattern is consistent: documentation exists, operation does not. Shadow SaaS holds personal data outside the records of processing. Backups retain data past its deletion date. Access reviews were done once, in 2023. Sub-processors changed and nobody updated the annex. And breach playbooks have never been exercised against a realistic scenario.

A pragmatic 90-day plan

You do not need a compliance department to close these gaps. In our experience a focused quarter is enough: month one, re-inventory processing activities and SaaS; month two, fix the contract annexes and wire deletion into the systems that matter; month three, run a tabletop breach exercise and an access review, and file the evidence. That evidence pack is what turns an audit from an interrogation into a formality.

InterHyve's consulting division runs exactly this programme for Swiss SMEs and international organisations, and our SOC provides the detection layer the breach articles assume you have. If your last nLPD review dates from 2023, it is time for a second look.

Draft article for the site mockup — technical review by the InterHyve team pending before publication.

Talk to our engineers

Let's look at your environment.

A one-hour assessment with a senior engineer. No sales script, no obligation.

GENEVA · +41 22 740 28 29 · INFO@INTERHYVE.COM
Book your assessment