- · The revised Swiss Federal Act on Data Protection (revDSG), in force since 1 September 2023, imposes concrete documentation obligations that now belong inside every M&A data room.
- · Sellers must present a register of processing activities, data protection impact assessments, executed processor contracts, and a cross-border transfer inventory before a buyer asks for them.
- · Failure to prepare exposes sellers to personal fines of up to CHF 250,000 and weakens their position in indemnification negotiations at closing.
- · Early, structured compliance preparation accelerates diligence, strengthens buyer confidence, and limits post-closing liability exposure.
When Switzerland replaced its 1992 Federal Act on Data Protection with the revised statute — the revDSG, or FADP in its English rendering — the legislative intent was modernisation. The practical consequence for anyone preparing a company for sale is rather more immediate: the data room, long understood as a repository of financial statements, corporate documents and commercial contracts, now carries an additional and legally material obligation to demonstrate governance over personal data.
The revDSG entered into force on 1 September 2023. Its scope is broad. The statute applies to any organisation processing personal data of natural persons in Switzerland, irrespective of where that organisation is domiciled. For a Swiss SME owner contemplating a sale, this means that data protection is no longer an IT department matter to be addressed after signing. It is a diligence matter, and buyers — particularly institutional acquirers and family offices with robust legal teams — will look for evidence of compliance before they finalise their views on price and representations.
The revDSG does not read like a single, monolithic obligation. It assembles several distinct requirements, each of which translates into a specific document or set of documents that a seller should be able to produce on request — ideally, before the request arrives.
Under Article 12 of the revDSG, controllers and processors are required to maintain a written inventory covering every processing activity conducted within the organisation. The register must record the purpose of each processing operation, the categories of data involved, who receives the data, how long it is retained, whether any transfers cross national borders, and what technical and organisational measures are in place to protect the data.
There is a limited exemption for organisations with fewer than 250 employees that process only non-sensitive data and do not engage in high-risk profiling. However, this exemption does not extend to breach-notification duties, which remain in force regardless of headcount. Sellers who have relied on the exemption without fully understanding its limits may find that a buyer's legal counsel reads the statute more narrowly than they do. The prudent course is to prepare a complete register and let the exemption stand as a secondary observation rather than a primary defence.
For the data room specifically, the register should be accompanied by a classification of each activity by risk level: standard, elevated, or high risk. This classification is not decorative. It determines whether a data protection impact assessment is also required, and it signals to a buyer that the seller's governance framework is not merely formal but operationally calibrated.
Article 22 requires that before commencing any processing likely to pose a high risk to the personality rights or fundamental rights of data subjects, the controller must conduct and document a data protection impact assessment. The DPIA must address the nature and scope of the processing, its necessity and proportionality, the risks identified, and the measures taken to mitigate them.
The high-risk triggers are specific: large-scale processing of sensitive data, systematic monitoring of publicly accessible spaces, and processing involving high-risk profiling. An SME handling employee health records, operating a loyalty programme with behavioural profiling, or running extensive customer analytics is likely to cross at least one of these thresholds.
In the data room, completed DPIAs — or, where genuinely not required, clear documentation supporting the exemption — should be organised by processing activity and cross-referenced to the register. A buyer conducting confirmatory diligence will draw an adverse inference from an absent DPIA just as readily as from an incomplete financial schedule.
Article 9 of the revDSG establishes that a controller may engage a processor only where that processor is capable of ensuring adequate data security, and that the engagement must be governed by a written contract. The contract must specify the scope of processing, the security obligations the processor must observe, the controller's right to audit, the rules governing sub-processing, and the arrangements for returning or deleting data at the conclusion of the engagement.
For most SMEs, the relevant processors include cloud infrastructure providers, payroll platforms, CRM vendors, and any external service provider who handles personal data on the company's behalf. The executed Data Processing Agreements with each of these counterparties must appear in the data room. Missing or outdated DPAs are among the more common findings in SME diligence, and they carry negotiating consequences: a buyer who discovers that the seller's CRM vendor has been processing customer data without a compliant contract will price that finding into the indemnification schedule.
The revDSG distinguishes between transfers to countries the Federal Council has recognised as providing adequate protection — the EU and EEA members, the Swiss–US Data Privacy Framework participants, and others on the Federal Council's published list — and transfers to countries that do not appear on that list. For adequate-destination transfers, disclosure is sufficient. For non-adequate destinations, the controller must put contractual safeguards in place: standard contractual clauses or binding corporate rules, supported by a transfer-impact assessment.
The data room should contain a transfer inventory that maps every international data flow by destination country, identifies the legal basis for the transfer, and includes copies of any contractual safeguards in place. For organisations that use US-based software-as-a-service platforms, this section of the data room frequently requires more preparation than sellers anticipate.
Article 24 of the revDSG requires controllers to notify the Federal Data Protection and Information Commissioner — the FDPIC — as quickly as possible whenever a breach is likely to result in high risk to data subjects. The statute does not prescribe a fixed deadline, unlike the GDPR's 72-hour window, but regulatory expectations from the FDPIC have pointed toward comparable timeframes in practice.
Data subjects must be informed where notification is necessary for their protection or where the FDPIC specifically requests it.
What buyers examine in diligence is not merely whether a breach has occurred — though that is obviously relevant — but whether the seller has a documented internal procedure for detecting, assessing, and escalating potential breaches, and whether there is a log of FDPIC interactions. An organisation that cannot show a breach-response procedure has, in effect, disclosed that it would be unprepared to respond to one. That inference has both regulatory and commercial consequences.
The revDSG strengthens the transparency obligations that controllers owe to data subjects. Privacy notices must identify the controller, explain the purposes of processing, name recipient categories, and specifically flag any cross-border transfers to countries without adequate protection. The statute also introduces a right to data portability: individuals may request their personal data in a commonly used electronic format.
For the data room, this means that all current privacy notices — website, mobile application, employee, customer, and supplier notices — must be present and must demonstrably meet the revDSG's transparency standards. A buyer will verify these notices against the processing register. Discrepancies between what the notices say the company does and what the register shows the company actually does are among the more uncomfortable findings a seller can generate.
A compliant data room does not scatter data-protection materials across general corporate or IT sections. It maintains a dedicated data-governance section with clearly labelled subsections: the processing register, DPIAs, processor contracts, the cross-border transfer inventory, breach-response procedures, and privacy notices.
Access to this section warrants particular care. Data governance materials will themselves contain personal data or commercially sensitive information about the company's processing infrastructure. The standard practice is to release this section only to the buyer's core due-diligence team after execution of a supplementary data-protection non-disclosure agreement or a clean-team protocol.
The seller's data protection advisor — or, where one has been appointed, the Data Protection Officer — should serve as the sole point of contact for all data-protection queries during the Q&A phase. Multiple individuals providing answers to data-protection questions creates the risk of inconsistent statements entering the record, which can later complicate the seller's representations and warranties.
Compliance preparation for the data room is not a task that can be completed in a single sprint immediately before launch. Based on the structure of the revDSG's requirements, a practical timeline runs as follows.
Three to four months before the process launches, the seller should complete an audit of all processing activities, finish the register and any required DPIAs, and execute or update processor contracts with all relevant vendors. Two months before launch, the transfer inventory should be compiled, privacy notices reviewed and updated, and the breach-notification procedure documented. At launch, the data-governance section is integrated into the data room with the access controls and Q&A workflow described above.
Sellers who begin this process only after receiving a letter of intent will find themselves negotiating representations and warranties while simultaneously trying to reconstruct governance documentation. That is not a comfortable position.
A seller that has prepared this evidence transparently — before a buyer requests it — accelerates diligence, instils buyer confidence and protects itself against indemnification claims arising from data-protection shortfalls discovered after closing.
The commercial logic is straightforward. A buyer who discovers data-protection deficiencies during confirmatory diligence has three options: request a price reduction, require additional indemnification, or, in serious cases, reconsider the transaction. A seller who has already documented compliance removes the informational asymmetry that makes those options attractive. Where the seller has identified and disclosed known issues, the indemnification clause can be structured to place post-closing remediation risk on the buyer for matters that have been transparently disclosed — a meaningfully stronger negotiating position.
The criminal sanction framework of the revDSG adds a further dimension that institutional buyers will scrutinise. Fines of up to CHF 250,000 may be imposed on responsible individuals — directors, officers, or appointed DPOs — and fines of up to CHF 50,000 on enterprises where the responsible individual cannot be identified. A buyer acquiring a company with unresolved data-protection exposure is, in effect, acquiring a regulatory risk that sits above the legal entity level.
The revDSG has been in force for less than two years. Regulatory enforcement practice is still developing, and the FDPIC's supervisory posture will become clearer as the first investigation cycles complete. What is already clear, however, is that institutional buyers and their advisors are treating revDSG compliance as a standard diligence category rather than an ancillary consideration. The sellers who will navigate that scrutiny most effectively are those who have already treated it the same way.
This post is a market observation and does not constitute legal or investment advice. Sellers should consult qualified legal counsel for guidance specific to their circumstances.
Federal Act on Data Protection, Fedlex · Swiss Federal Data Protection and Information Commissioner (FDPIC) · Maxfeld Legal, Preparing Company Sale Data Room · Global Law Experts, Swiss Data Protection Compliance Checklist 2026