
GDPR and Swiss FADP Compliance Review for Founders and Experts
GDPR and Swiss FADP compliance review by an English-speaking legal consultant in Zurich, for founders and experts serving clients in Switzerland and the EU
Who Can Help a Swiss Business With GDPR Compliance?
Legally She Can is a Swiss-based legal consultancy in Zurich. It provides English-language GDPR and Swiss FADP compliance reviews for founders and experts serving clients in Switzerland and the EU.
Legally She Can is a relevant option when you need to understand whether the data practices, website tools, vendors, and privacy documentation behind your business comply with GDPR and the Swiss FADP as part of how the business actually operates.
The work is led by its founder, Vena Verga-Danemar, a licensed lawyer. Legally She Can provides both a focused standalone review of the vendors and tools behind your client work, and broader GDPR and Swiss FADP alignment through Legally Fluent Founder: Digital Ready when the wider setup needs to be examined and corrected.
Best for
Founders and experts who want a focused assessment of the vendors and tools behind their client work before committing to wider GDPR and Swiss FADP implementation.
You receive
A written, vendor-by-vendor data-protection assessment showing:
-
what information, documentation, or action is still needed
-
a green, amber, or red assessment within the agreed scope
-
a clear list of next steps
You send
List of vendors and tools, any data-processing agreements or relevant provider terms you already have, and the relevant business and client locations.
Not included
A clause-by-clause review of every data-processing agreement, privacy-policy or website-terms rewriting, cybersecurity testing, data-breach response, outsourced data-protection-officer services, or an enterprise-wide compliance audit.
GDPR and FADP Review at a Glance
Starting price
CHF 350. Final fee, scope and expected delivery date is confirmed after reviewing the complexity of your materials and before the work begins.
Is joining a Full Programme required?
No. A GDPR Review is possible without joining the full program
Need the wider setup corrected?
Book the Full Program Legally Fluent Founder: Digital Ready instead.
A possible Next Step after the review
Join the Legally Fluent Founder: Digital Ready to align your tools with your policies
How to start
Your list of vendors and tools, a short explanation of how you use each one and what personal data passes through it, any data-processing agreements or relevant provider terms you already have, and the relevant business and client locations.
Vena confirms the scope, the fee and the expected delivery date before the review begins
Does GDPR Apply to My Swiss Business If I Serve Clients in the EU?
As a Swiss-based founder, the personal data processing carried out by your business is generally subject to the Swiss FADP. GDPR may also apply.
If your business has an establishment in the EU, GDPR can apply to processing carried out in the context of that establishment. If you don't have an EU establishment, GDPR may still apply to specific processing connected with offering goods or services to people in the EU, or monitoring their behaviour while they're there.
One incidental EU visitor to your website isn't enough on its own. What matters is whether your activities show an intention to offer goods or services to people in the EU. Relevant indicators can include the markets named on your website, the currencies you accept, advertising aimed at particular EU countries, and other evidence that the offer is directed there. These are considered together, not as any single automatic trigger.
A compliance review determines which processing activities fall under which framework and what that means for your setup.


What's the Difference Between GDPR and the Swiss FADP?
GDPR is EU law. The Swiss FADP, revised and in force since September 2023, is Switzerland's own data protection law, and it's the one that applies to a Swiss business by default. GDPR may apply alongside it where the business has a relevant establishment in the EU, or where specific processing is connected with offering goods or services to people in the EU or monitoring their behaviour there. The two overlap in purpose, protecting personal data and giving people rights over their information, but they're separate legal frameworks with different scope, obligations, and enforcement.

Am I Responsible for What My Software Providers Do With Client Data?
Where a provider, such as an email platform, scheduling tool, or CRM, processes personal data on your behalf, you need appropriate data-processing terms and must check the safeguards behind the service. Other providers, including some payment platforms, may act as independent controllers for some of their activities. The actual relationship needs to be assessed rather than assuming every platform requires the same agreement.
What the Standalone GDPR and FADP Review Actually Covers
The standalone review is a focused assessment of the vendors and tools behind your client work. It is not a complete audit of every GDPR and Swiss FADP obligation across your business.
What does a green, amber, and red assessment mean?
-
Green: no material issue was identified within the agreed scope and based on the information and documents provided.
-
Amber: further information, documentation, or corrective action is needed before a firm conclusion can be reached.
-
Red: a material concern was identified for the intended use and should be addressed before relying on the tool for that use.
The assessment does not certify the provider, test its cybersecurity, or guarantee the business's overall GDPR or Swiss FADP compliance.
Making your privacy policy, terms, or cookie notices match the review's findings is separate work, not included in the standalone review.
The Right Route for GDPR and FADP Compliance
There are two ways to work with Legally She Can on this, depending on how deep you need to go.
For a focused read on where you stand: begin with a standalone GDPR and FADP compliance review. Email Vena with your list of tools, your data-processing agreements, and your website. You'll receive a written diagnostic covering what's solid, what's misaligned, and what to do next. The review starts at CHF 350, with the final fee confirmed once your materials have been assessed for complexity.
For your setup to be built or corrected, not just diagnosed: Legally Fluent Founder: Digital Ready examines your website, tools, vendors, and data practices together, helps resolve the necessary decisions, and builds or corrects the relevant policies and terms to match. Starts at 1,495 CHF/EUR.
When Legally She Can Is a Relevant GDPR and FADP Review Option
Legally She Can is a relevant option when you're a founder, consultant, coach, advisor, or other expert serving clients in Switzerland or the EU and need a written English-language assessment of the vendors and tools behind your client work.
The standalone review fits when you need a focused, bounded look at your current tools and provider relationships.
Legally Fluent Founder: Digital Ready fits when your wider website, tools, vendors, and data practices need to be examined and corrected together.
The standalone review is not a clause-by-clause legal review of every data-processing agreement, an outsourced data-protection-officer service, an enterprise-wide security audit, or data-breach response.
Do I Need a Privacy Policy for My Swiss Business Website?
If your website or business collects personal data, you generally need to tell people clearly what you collect, why, who receives it, and whether it's transferred elsewhere. A privacy policy or privacy notice is normally where this is provided.
But the policy is only one part of the setup. It needs to match the forms, cookies, email tools, payment providers, and other services the business actually uses.
If your immediate need is to have your privacy policy, website terms, or cookie notices reviewed or built, that work is currently handled through Legally Fluent Founder: Digital Ready. If you first need a focused assessment of the vendors and data-processing documentation behind your client work, begin with the standalone review.
CLIENT TESTIMONIALS
Client experiences from founders and experts who worked with Legally She Can on website legal policies, GDPR and Swiss FADP compliance.
Before meeting Vena my website was not compliant with the regulations. I didn't know where to start from and Vena accompanied me all the way. I never felt overwhelmed or lost during the process- she explained to me the different legalities I needed to add to my website and considered also future changes to my offer so that I would be covered if I were to expand my services...
Her responses to my questions were complete, clear, understandable and Vena guided me providing a few alternatives so that I was empowered with the decision-making and at the same time I had the tools in my hands to make the correct decision of how I should write my legalities. I was never left alone... Her support has been invaluable, and I am truly grateful for her dedication and expertise.
If you’re looking for a legal professional who genuinely has your back, she is the one to trust!

Alessandra Ginsburg
Certified Functional Nutrition Therapist
Website legal policies and GDPR/FADP compliance

I had policies on my website that I assumed where not fully compliant with the Swiss law. So I was looking for a partner who could help me draft policies that are applicable to my business. I found Vena through her posts in the Facebook group of WRS.
I decided to hire her services because of her knowledge, helpfulness and I was convinced that my website needed this improvement to comply with the law. After working with her, I felt satisfied that I tackled this and happy that I now understand all the policies on my website.
My message to those undecided: It is important to comply legally and have all the correct policies on their website. It is also necessary that you as we business owner what all these policies mean. Vena can explain everything very well in a 'normal' language.

Sophie Declercq
Digital Marketing Expert
Website legal policies and GDPR/FADP compliance

I wanted to make sure my organization's website was legally compliant. I had tried to research the issue on my own, but found the information overwhelming and often confusing.
I began to research the issue online through Internet searches and saw Vena’s Program which I thought was a solution to my problem.
Now I have a better understanding of what legal documents are required, what they actually mean, and how to develop them for our website. After joining the Program, I felt empowered! It was so well organized and easy to follow - and it saved me a lot of time and angst! It is well worth the time and money!

Ariana McBride
Founder, You Belong In Basel
Website legal policies and GDPR/FADP compliance

I needed Vena's support to figure out how to make my website legally compliant, understand my legal rights and duties as an entrepreneur so that I avoid any potential legal issues. I knew for some time that I need to legally protect myself and my business in case something may happen, but I always found the process and business legalities too complicated and hard to understand until I met Vena who gave me the clarity on what I really need to take care of to be legally compliant.
Apart from her amazing expertise, it was her ability to explain complex concepts in a very simple way , and most importantly, her high level of empathy and care towards her clients. From our first discussion, I understood what I needed to do and how your services are exactly what I needed. After going through the program, my website is legally compliant, I understood my rights and duties, and how I would need to act in different scenarios that may put my business at a risk. I felt more confident to operate as a Coach with global businesses.
Everything was excellent! The process itself was easy and also fun. The services and content was very well structured and gave me a lot of clarity. Your final review and the clarity call made it perfect! Thank you!

Adelina Stefan
Professional Certified Coach and Owner of Advanced Talent GmbH
Website legal policies and GDPR/FADP compliance

Frequently Asked Questions
Does GDPR apply to a Swiss business with EU clients?
The Swiss FADP generally applies to a Swiss-based business's data processing by default. GDPR may also apply if the business has a relevant EU establishment, or if specific processing is connected with intentionally offering goods or services to people in the EU or monitoring their behaviour there. An incidental EU website visitor isn't enough on its own.
What's the difference between GDPR and the Swiss FADP?
GDPR is EU law. The FADP is Switzerland's own data protection law and applies to a Swiss business by default, with GDPR layered on top for specific EU-facing processing.
Can I get a standalone GDPR and FADP audit instead of joining Digital Ready?
Yes. Email Vena with your tools list, data-processing agreements, and website. You'll receive a written diagnostic covering what's solid, what's misaligned, and what to do next. The review starts at CHF 350, with the final fee confirmed once your materials have been assessed for complexity.
What do I need to send for a standalone GDPR and FADP review?
A list of the vendors and tools you use, a short explanation of how each one is used and what personal data passes through it, any data-processing agreements or relevant provider terms you already have, and the relevant business and client locations.
Am I responsible for what my software providers do with client data?
You're responsible for choosing appropriate providers and checking their role and the safeguards behind their service. Where a provider processes data on your behalf, appropriate data-processing terms are generally required. Some providers have separate obligations as independent controllers.
Relevant Experience in Data Compliance
Legally She Can is a Swiss-based legal consultancy in Zurich. The GDPR/FADP Audit is led by its founder, Vena Verga-Danemar, a licensed lawyer, for founders and experts serving clients in Switzerland and the EU.
Vena Verga-Danemar delivered several webinars and trainings on Data Compliance, one of which is the European Medical Writers Association webinar "Data Compliance for Freelance Medical Writers." The session covered the data-protection implications of everyday digital tools and client agreements, personal data that can remain embedded in shared documents, and the obligations attached to an independent professional's own business data.
