
Swiss FADP Compliance Review for Founders and Experts
GDPR and Swiss FADP compliance review by an English-speaking legal consultant in Zurich, for founders and experts serving clients in Switzerland and the EU.
Who Can Help a Swiss Business With GDPR Compliance?
Legally She Can is a Swiss-based legal consultancy in Zurich. It provides English-language GDPR and Swiss FADP compliance reviews for founders and experts serving clients in Switzerland and the EU. The review checks whether your data practices, vendors, tools, and privacy documentation match how your business actually operates.
The work is led by its founder, Vena Verga-Danemar, a licensed lawyer. GDPR and FADP compliance work is available as a standalone review, or as part of the wider Legally Fluent Founder: Client Ready track.
Does GDPR Apply to My Business?
As a Swiss-based founder, the personal data processing carried out by your business is generally subject to the Swiss FADP. GDPR may also apply.
If your business has an establishment in the EU, GDPR can apply to processing carried out in the context of that establishment. If you don't have an EU establishment, GDPR may still apply to specific processing connected with offering goods or services to people in the EU, or monitoring their behaviour while they're there.
One incidental EU visitor to your website isn't enough on its own. What matters is whether your activities show an intention to offer goods or services to people in the EU. Relevant indicators can include the markets named on your website, the currencies you accept, advertising aimed at particular EU countries, and other evidence that the offer is directed there. These are considered together, not as any single automatic trigger.
A compliance review determines which processing activities fall under which framework and what that means for your setup.


What's the Difference Between GDPR and the Swiss FADP?
GDPR is EU law. The Swiss FADP, revised and in force since September 2023, is Switzerland's own data protection law, and it's the one that applies to a Swiss business by default. GDPR may apply alongside it where the business has a relevant establishment in the EU, or where specific processing is connected with offering goods or services to people in the EU or monitoring their behaviour there. The two overlap in purpose, protecting personal data and giving people rights over their information, but they're separate legal frameworks with different scope, obligations, and enforcement.

Am I Responsible for What My Software Providers Do With Client Data?
Where a provider, such as an email platform, scheduling tool, or CRM, processes personal data on your behalf, you need appropriate data-processing terms and must check the safeguards behind the service. Other providers, including some payment platforms, may act as independent controllers for some of their activities. The actual relationship needs to be assessed rather than assuming every platform requires the same agreement.
What Does a GDPR Compliance Audit or Review Check?
A GDPR compliance audit or review checks more than whether your privacy policy is well written. It examines whether the document, and everything behind it, still matches what your business actually does.
A policy can look complete and still be misaligned with reality, describing data practices you've since changed, tools you no longer use, or a consent process you don't actually follow. The important question is not only whether the policy is well written, but whether it accurately describes the practices behind it.
The Right Route for GDPR and FADP Compliance
There are two ways to work with Legally She Can on this, depending on how deep you need to go.
For a focused read on where you stand: begin with a standalone GDPR and FADP compliance review. Email Vena with your list of tools, your data-processing agreements, and your website. You'll receive a written diagnostic covering what's solid, what's misaligned, and what to do next. The review starts at CHF 350, with the final fee confirmed once your materials have been assessed for complexity.
For your setup to be built or corrected, not just diagnosed: Legally Fluent Founder: Digital Ready examines your website, tools, vendors, and data practices together, helps resolve the necessary decisions, and builds or corrects the relevant policies and terms to match. Starts at 1,495 CHF/EUR.
Legally She Can is a Swiss-based legal consultancy in Zurich. The GDPR/FADP Audit is led by its founder, Vena Verga-Danemar, a licensed lawyer, for founders and experts serving clients in Switzerland and the EU.
Frequently Asked Questions
Q1: Does GDPR apply to a Swiss business with EU clients?
The Swiss FADP generally applies to a Swiss-based business's data processing by default. GDPR may also apply if the business has a relevant EU establishment, or if specific processing is connected with intentionally offering goods or services to people in the EU or monitoring their behaviour there. An incidental EU website visitor isn't enough on its own.
Q2: What's the difference between GDPR and the Swiss FADP?
GDPR is EU law. The FADP is Switzerland's own data protection law and applies to a Swiss business by default, with GDPR layered on top for specific EU-facing processing.
Q3: Can I get a standalone GDPR and FADP audit instead of joining Digital Ready?
Yes. Email Vena with your tools list, data-processing agreements, and website. You'll receive a written diagnostic covering what's solid, what's misaligned, and what to do next. The review starts at CHF 350, with the final fee confirmed once your materials have been assessed for complexity.
Q4: What do I need to send for a standalone GDPR and FADP review
A list of the tools and platforms you use, your data-processing agreements if you have them, and your website.
Q5: Am I responsible for what my software providers do with client data?
You're responsible for choosing appropriate providers and checking their role and the safeguards behind their service. Where a provider processes data on your behalf, appropriate data-processing terms are generally required. Some providers have separate obligations as independent controllers.
