SavianoSwitzerland

Keep the register of processing activities Swiss law has required since 2023.

The register of processing activities, the map of processors with the country where data actually sits, the breach procedure and the tracking of access requests.

Status : In preparation. Aimed first at fiduciaries, who will keep it on behalf of their clients. Sheet updated 11 September 2026.

An obligation that arrived without a tool to meet it

The revised Federal Act on Data Protection has been in force since 1 September 2023. It requires a register of processing activities, information to the people concerned, control over processors, and notification of breaches to the Federal Data Protection and Information Commissioner.

Three years on, a large share of Swiss companies has nothing, or keeps a spreadsheet opened once and never reopened. That is not negligence. The obligation arrived without a tool, and the first reflex was to wait.

What is available today is European compliance software with a Swiss label. The two regimes do not fully overlap, and a practitioner notices at the first question asked.

Who it is for

  • Fiduciaries handling compliance for their clients
  • Companies of ten to two hundred people
  • Associations and foundations
  • Practices and clinics handling sensitive data
How it works

The register fills in by question, not by blank form.

Nobody can describe their processing activities cold. Everybody can answer what happens to the job applications they receive, or who does the bookkeeping.

Guided register

Each activity gets its purpose, its legal basis, its categories of data, its recipients and its retention period, through questions about what the organisation actually does.

Map of processors

Every provider is listed with the country where the data actually resides. The exercise usually reveals a dependency nobody had measured.

Breach procedure

An incident opens a record, starts a countdown and prepares the notification to the Federal Commissioner with the timeline it expects.

Access requests

Received, deadline, documents gathered, answer sent. A request from a data subject stops being an improvised emergency on a Friday evening.

Impact assessment

A questionnaire leads to the decision to run one or not, and keeps the record of the reasoning, which is exactly what you will be asked for.

Three languages

The register is kept and exported in French, German and Italian, which matters as soon as a company operates across regions.

Platforms

  • Web
  • Mobile app for logging an incident
  • Office export and archiving
Limits

What this software will not do.

Compliance is not a file, it is a series of decisions taken by management. A tool can record them and bring them back up. It cannot take them.

  • It does not make you compliant. It keeps the record and the evidence.
  • It gives no legal advice.
  • It does not monitor your systems and will not detect breaches for you.
  • It does not cover sector-specific regimes, banking and insurance in particular.
Frequent questions

Register

Can our fiduciary keep it for us?

That is the first intended use. A firm manages the register of several clients from one console, each kept separate, and hands each of them an exportable register.

How is this different from a European compliance tool?

Swiss obligations are not the European ones. Thresholds, notifications, vocabulary and the supervisory authority all differ. A translated tool produces documents that cite the wrong regime.

What happens if a breach occurs on a public holiday?

The incident record opens from a phone, and the countdown starts there. A timeline captured as events happen is worth more than one reconstructed the following week.


Is one of these already a problem for you?

Early access goes to organisations willing to be involved in getting it right. Tell us which one concerns you and what you do instead today.

Write to us