When the revised Federal Act on Data Protection (nLPD) entered into force on 1 September 2023, most Swiss SMEs did the minimum: a new privacy notice, a records-of-processing spreadsheet, and a collective sigh of relief. Two years on, the FDPIC and external auditors have moved past paperwork. They now ask organisations to demonstrate that the technical and organisational measures described on paper actually operate.
What auditors actually check in 2026
Across the audits and due-diligence questionnaires we have supported this year — for foundations, trading SMEs and international organisations alike — five areas come up in almost every review.
- Records of processing that match reality: auditors sample two or three processing activities and trace them to the systems, contracts and retention rules behind them.
- Breach-notification readiness: can you detect, qualify and document an incident within days, not weeks? A tested playbook matters more than a policy PDF.
- Processor contracts (art. 9): sub-processor lists, audit rights and cross-border transfer clauses — especially for US cloud services.
- Data-subject request handling: a named owner, a tracked mailbox and evidence of response within 30 days.
- Retention and deletion in practice: not the schedule, but proof that deletion jobs actually ran.
The five gaps we still find
The pattern is consistent: documentation exists, operation does not. Shadow SaaS holds personal data outside the records of processing. Backups retain data past its deletion date. Access reviews were done once, in 2023. Sub-processors changed and nobody updated the annex. And breach playbooks have never been exercised against a realistic scenario.
A pragmatic 90-day plan
You do not need a compliance department to close these gaps. In our experience a focused quarter is enough: month one, re-inventory processing activities and SaaS; month two, fix the contract annexes and wire deletion into the systems that matter; month three, run a tabletop breach exercise and an access review, and file the evidence. That evidence pack is what turns an audit from an interrogation into a formality.
InterHyve's consulting division runs exactly this programme for Swiss SMEs and international organisations, and our SOC provides the detection layer the breach articles assume you have. If your last nLPD review dates from 2023, it is time for a second look.
Draft article for the site mockup — technical review by the InterHyve team pending before publication.
Talk to our engineersLet's look at your environment.
A one-hour assessment with a senior engineer. No sales script, no obligation.