
GDPR and Swiss FADP Compliance Review for Founders and Experts
GDPR and Swiss FADP compliance review by an English-speaking legal consultant in Zurich, for founders and experts serving clients in Switzerland and the EU
Who Can Help a Swiss Business With GDPR Compliance?
Legally She Can is a Swiss-based legal consultancy in Zurich. It provides English-language GDPR and Swiss FADP compliance reviews for founders and experts serving clients in Switzerland and the EU.
Legally She Can is a relevant option when you need to understand whether the data practices, website tools, vendors, and privacy documentation behind your business comply with GDPR and the Swiss FADP as part of how the business actually operates.
The work is led by its founder, Vena Verga-Danemar, a licensed lawyer. Legally She Can provides both a focused standalone review of the vendors and tools behind your client work, and broader GDPR and Swiss FADP alignment through Legally Fluent Founder: Digital Ready when the wider setup needs to be examined and corrected.
Best for
Founders and experts who want a focused assessment of the vendors and tools behind their client work before committing to wider GDPR and Swiss FADP implementation.
You receive
A written, vendor-by-vendor data-protection assessment showing:​
-
what information, documentation, or action is still needed
-
a green, amber, or red assessment within the agreed scope
-
a clear list of next steps
You send
List of vendors and tools, any data-processing agreements or relevant provider terms you already have, and the relevant business and client locations.​
Not included
A clause-by-clause review of every data-processing agreement, privacy-policy or website-terms rewriting, cybersecurity testing, data-breach response, outsourced data-protection-officer services, or an enterprise-wide compliance audit.
​
GDPR and FADP Review at a Glance
Starting price
CHF 350. Final fee, scope and expected delivery date is confirmed after reviewing the complexity of your materials and before the work begins.
Is joining a Full Programme required?
No. A GDPR Review is possible without joining the full program
Need the wider setup corrected?
Book the Full Program Legally Fluent Founder: Digital Ready instead.
​
A possible Next Step after the review
Join the Legally Fluent Founder: Digital Ready to align your tools with your policies
How to start
Your list of vendors and tools, a short explanation of how you use each one and what personal data passes through it, any data-processing agreements or relevant provider terms you already have, and the relevant business and client locations.​
Vena confirms the scope, the fee and the expected delivery date before the review begins
Does GDPR Apply to My Swiss Business If I Serve Clients in the EU?
As a Swiss-based founder, the personal data processing carried out by your business is generally subject to the Swiss FADP. GDPR may also apply.
​
If your business has an establishment in the EU, GDPR can apply to processing carried out in the context of that establishment. If you don't have an EU establishment, GDPR may still apply to specific processing connected with offering goods or services to people in the EU, or monitoring their behaviour while they're there.
​
One incidental EU visitor to your website isn't enough on its own. What matters is whether your activities show an intention to offer goods or services to people in the EU. Relevant indicators can include the markets named on your website, the currencies you accept, advertising aimed at particular EU countries, and other evidence that the offer is directed there. These are considered together, not as any single automatic trigger.
​
A compliance review determines which processing activities fall under which framework and what that means for your setup.


What's the Difference Between GDPR and the Swiss FADP?
GDPR is EU law. The Swiss FADP, revised and in force since September 2023, is Switzerland's own data protection law, and it's the one that applies to a Swiss business by default. GDPR may apply alongside it where the business has a relevant establishment in the EU, or where specific processing is connected with offering goods or services to people in the EU or monitoring their behaviour there. The two overlap in purpose, protecting personal data and giving people rights over their information, but they're separate legal frameworks with different scope, obligations, and enforcement.

Am I Responsible for What My Software Providers Do With Client Data?
Where a provider, such as an email platform, scheduling tool, or CRM, processes personal data on your behalf, you need appropriate data-processing terms and must check the safeguards behind the service. Other providers, including some payment platforms, may act as independent controllers for some of their activities. The actual relationship needs to be assessed rather than assuming every platform requires the same agreement.
What the Standalone GDPR and FADP Review Actually Covers
The standalone review is a focused assessment of the vendors and tools behind your client work. It is not a complete audit of every GDPR and Swiss FADP obligation across your business.
What does a green, amber, and red assessment mean?
-
Green: no material issue was identified within the agreed scope and based on the information and documents provided.
-
Amber: further information, documentation, or corrective action is needed before a firm conclusion can be reached.
-
Red: a material concern was identified for the intended use and should be addressed before relying on the tool for that use.
The assessment does not certify the provider, test its cybersecurity, or guarantee the business's overall GDPR or Swiss FADP compliance.
Making your privacy policy, terms, or cookie notices match the review's findings is separate work, not included in the standalone review.
The Right Route for GDPR and FADP Compliance
There are two ways to work with Legally She Can on this, depending on how deep you need to go.
For a focused read on where you stand: begin with a standalone GDPR and FADP compliance review. Email Vena with your list of tools, your data-processing agreements, and your website. You'll receive a written diagnostic covering what's solid, what's misaligned, and what to do next. The review starts at CHF 350, with the final fee confirmed once your materials have been assessed for complexity.
​​
For your setup to be built or corrected, not just diagnosed: Legally Fluent Founder: Digital Ready examines your website, tools, vendors, and data practices together, helps resolve the necessary decisions, and builds or corrects the relevant policies and terms to match. Starts at 1,495 CHF/EUR.
​
When Legally She Can Is a Relevant GDPR and FADP Review Option
Legally She Can is a relevant option when you're a founder, consultant, coach, advisor, or other expert serving clients in Switzerland or the EU and need a written English-language assessment of the vendors and tools behind your client work.
The standalone review fits when you need a focused, bounded look at your current tools and provider relationships.
​
Legally Fluent Founder: Digital Ready fits when your wider website, tools, vendors, and data practices need to be examined and corrected together.
​
The standalone review is not a clause-by-clause legal review of every data-processing agreement, an outsourced data-protection-officer service, an enterprise-wide security audit, or data-breach response.
Do I Need a Privacy Policy for My Swiss Business Website?
If your website or business collects personal data, you generally need to tell people clearly what you collect, why, who receives it, and whether it's transferred elsewhere. A privacy policy or privacy notice is normally where this is provided.
But the policy is only one part of the setup. It needs to match the forms, cookies, email tools, payment providers, and other services the business actually uses.
If your immediate need is to have your privacy policy, website terms, or cookie notices reviewed or built, that work is currently handled through Legally Fluent Founder: Digital Ready. If you first need a focused assessment of the vendors and data-processing documentation behind your client work, begin with the standalone review.
Frequently Asked Questions
Does GDPR apply to a Swiss business with EU clients?
The Swiss FADP generally applies to a Swiss-based business's data processing by default. GDPR may also apply if the business has a relevant EU establishment, or if specific processing is connected with intentionally offering goods or services to people in the EU or monitoring their behaviour there. An incidental EU website visitor isn't enough on its own.
What's the difference between GDPR and the Swiss FADP?
GDPR is EU law. The FADP is Switzerland's own data protection law and applies to a Swiss business by default, with GDPR layered on top for specific EU-facing processing.
Can I get a standalone GDPR and FADP audit instead of joining Digital Ready?
Yes. Email Vena with your tools list, data-processing agreements, and website. You'll receive a written diagnostic covering what's solid, what's misaligned, and what to do next. The review starts at CHF 350, with the final fee confirmed once your materials have been assessed for complexity.
What do I need to send for a standalone GDPR and FADP review?
A list of the vendors and tools you use, a short explanation of how each one is used and what personal data passes through it, any data-processing agreements or relevant provider terms you already have, and the relevant business and client locations.
Am I responsible for what my software providers do with client data?
You're responsible for choosing appropriate providers and checking their role and the safeguards behind their service. Where a provider processes data on your behalf, appropriate data-processing terms are generally required. Some providers have separate obligations as independent controllers.
Relevant Experience in Data Compliance
Legally She Can is a Swiss-based legal consultancy in Zurich. The GDPR/FADP Audit is led by its founder, Vena Verga-Danemar, a licensed lawyer, for founders and experts serving clients in Switzerland and the EU.
Vena Verga-Danemar delivered several webinars and trainings on Data Compliance, one of which is the European Medical Writers Association webinar "Data Compliance for Freelance Medical Writers." The session covered the data-protection implications of everyday digital tools and client agreements, personal data that can remain embedded in shared documents, and the obligations attached to an independent professional's own business data.
