{"id":916,"date":"2026-01-10T09:00:00","date_gmt":"2026-01-10T09:00:00","guid":{"rendered":"https:\/\/exposiq.ch\/ndsg-and-it-security-what-swiss-smes-really-need-to-do\/"},"modified":"2026-02-22T18:02:13","modified_gmt":"2026-02-22T18:02:13","slug":"ndsg-and-it-security-what-swiss-smes-really-need-to-do","status":"publish","type":"post","link":"https:\/\/exposiq.ch\/en\/ndsg-and-it-security-what-swiss-smes-really-need-to-do\/","title":{"rendered":"nDSG and IT Security: What Swiss SMEs Really Need to Do"},"content":{"rendered":"<p>Since September 2023, the new Swiss Data Protection Act (nDSG) has been in force. Many SMEs are uncertain: what do we actually need to implement on the technical side? Is a privacy policy enough? Do we need a data protection consultant?<\/p>\n<p>This article explains the technical requirements of the nDSG \u2014 without legal jargon, with concrete measures.<\/p>\n<h2>What the nDSG Requires Technically<\/h2>\n<p>Article 8 of the nDSG calls for &#8220;appropriate technical and organisational measures&#8221; to protect personal data. The Federal Council has specified these in the Data Protection Ordinance (DSV):<\/p>\n<ul>\n<li><strong>Access control:<\/strong> Who has access to which data?<\/li>\n<li><strong>Encryption:<\/strong> Is data protected during transmission and storage?<\/li>\n<li><strong>Logging:<\/strong> Are access and changes logged in a traceable manner?<\/li>\n<li><strong>Availability:<\/strong> Are there backups and recovery plans?<\/li>\n<li><strong>Regular review:<\/strong> Are measures reviewed periodically?<\/li>\n<\/ul>\n<p>The last point is crucial \u2014 and the one most often neglected.<\/p>\n<h2>&#8220;Appropriate&#8221; \u2014 What Does That Actually Mean?<\/h2>\n<p>The law does not require specific products or certifications. &#8220;Appropriate&#8221; means: proportionate to the risk and the size of the company.<\/p>\n<p>A 20-person SME is held to different standards than a bank. But &#8220;we are too small, this does not apply to us&#8221; does not hold up. The nDSG applies to every company that processes personal data \u2014 and virtually every SME does (customer data, employee data, email addresses).<\/p>\n<h2>7 Concrete Measures Every SME Should Implement<\/h2>\n<p><strong>1. Enforce encryption<\/strong><br \/>\nAll externally accessible services must use TLS 1.2 or higher. TLS 1.0 and 1.1 are outdated and considered insecure.<\/p>\n<p><strong>2. Review access rights<\/strong><br \/>\nWho has admin access? Who can access personal data? Apply the principle of least privilege.<\/p>\n<p><strong>3. Keep software up to date<\/strong><br \/>\nOutdated software with known vulnerabilities is a risk that is hard to justify in the event of an incident.<\/p>\n<p><strong>4. Regular vulnerability scans<\/strong><br \/>\nThe DSV requires &#8220;regular review&#8221; of protective measures. An automated vulnerability scan is the most efficient way to meet this requirement.<\/p>\n<p><strong>5. Document your backup strategy<\/strong><br \/>\nRegular backups with tested recovery. Ransomware protection: at least one backup offline or immutable.<\/p>\n<p><strong>6. Plan your incident response<\/strong><br \/>\nThe nDSG requires notification to the FDPIC within 72 hours in the event of a data breach. A documented process is mandatory.<\/p>\n<p><strong>7. Update your privacy policy<\/strong><br \/>\nObligation to inform data subjects. Must be accessible on your website and when collecting data.<\/p>\n<h2>What Happens in Case of Violations?<\/h2>\n<p>The nDSG provides for fines of up to CHF 250&#8217;000 \u2014 and these are levied against the responsible individual, not the company. This means: managing directors and IT managers are personally liable.<\/p>\n<p>In practice, the FDPIC (Federal Data Protection and Information Commissioner) will likely focus on cooperation and improvement first. But: in the event of an incident, it will be examined whether appropriate protective measures were in place. Those who cannot demonstrate any will have a problem.<\/p>\n<h2>Documentation Is Key<\/h2>\n<p>The nDSG does not require certification. But it does require that you can demonstrate you have taken appropriate measures.<\/p>\n<p>Concretely, this means:<\/p>\n<ul>\n<li>Documented IT security measures<\/li>\n<li>Regular assessment reports (e.g. vulnerability scan reports)<\/li>\n<li>Documented improvements<\/li>\n<li>Traceable access rights<\/li>\n<\/ul>\n<p>A professional scan report in your language is exactly the kind of evidence an auditor or the FDPIC wants to see.<\/p>\n<h2>Conclusion<\/h2>\n<p>The nDSG is not an IT security law in the strict sense. But it requires technical measures that align with IT security standards. Those who regularly assess their systems and document the results fulfil the majority of the technical requirements.<\/p>\n<p>ExposIQ automatically generates nDSG-compliant assessment reports in German, French, Italian and English. The reports document assessed systems, identified vulnerabilities and recommended measures \u2014 exactly what auditors and regulators want to see.<\/p>\n<p><a href=\"https:\/\/app.exposiq.ch\">Try it free for 14 days.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since September 2023, the new Swiss Data Protection Act (nDSG) has been in force. Many SMEs are uncertain: what do we actually need to implement on the technical side? Is a privacy policy enough? Do we need a data protection consultant? This article explains the technical requirements of the nDSG \u2014 without legal jargon, with &#8230; <a title=\"nDSG and IT Security: What Swiss SMEs Really Need to Do\" class=\"read-more\" href=\"https:\/\/exposiq.ch\/en\/ndsg-and-it-security-what-swiss-smes-really-need-to-do\/\" aria-label=\"Read more about nDSG and IT Security: What Swiss SMEs Really Need to Do\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_focus_keyword":"nDSG IT security SME","rank_math_title":"nDSG and IT Security: What Swiss SMEs Really Need to Do","rank_math_description":"The new Swiss Data Protection Act requires technical measures. 7 concrete steps every SME should implement \u2014 explained without legal jargon.","rank_math_robots":"","rank_math_canonical_url":"","rank_math_primary_category":"","footnotes":""},"categories":[8],"tags":[],"class_list":["post-916","post","type-post","status-publish","format-standard","hentry","category-it-sicherheit","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-33"],"_links":{"self":[{"href":"https:\/\/exposiq.ch\/en\/wp-json\/wp\/v2\/posts\/916","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/exposiq.ch\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/exposiq.ch\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/exposiq.ch\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/exposiq.ch\/en\/wp-json\/wp\/v2\/comments?post=916"}],"version-history":[{"count":1,"href":"https:\/\/exposiq.ch\/en\/wp-json\/wp\/v2\/posts\/916\/revisions"}],"predecessor-version":[{"id":926,"href":"https:\/\/exposiq.ch\/en\/wp-json\/wp\/v2\/posts\/916\/revisions\/926"}],"wp:attachment":[{"href":"https:\/\/exposiq.ch\/en\/wp-json\/wp\/v2\/media?parent=916"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/exposiq.ch\/en\/wp-json\/wp\/v2\/categories?post=916"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/exposiq.ch\/en\/wp-json\/wp\/v2\/tags?post=916"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}