Skip to content

What we do

Each service starts from a concrete problem and ends with a deliverable you keep. The timeframes given are indicative, not commitments.

The regulations we cover: the Swiss Federal Act on Data Protection and the GDPR for data protection, NIS2 and DORA for sectors subject to European law, the CRA for products with digital elements, and the Swiss Information Security Act for federal mandates. We also follow the draft Swiss federal cybersecurity act, modelled on the CRA.

The timeframes below are indicative. Every organisation starts from a different situation: the actual duration is agreed together after the first conversation and set out in the written proposal. They do not constitute a commitment.

Regulated organisations

Readiness for standards

The problem
A client, an insurer or a regulator asks for a certification or a report you have never prepared.
The deliverable
Gap analysis, management system documentation, control implementation, audit preparation. We cover ISO 27001 for information security, ISO 27701 for privacy, ISO 22301 for business continuity, SOC 2 Type I and Type II readiness, the NIST CSF 2.0 framework and the CIS Controls.
Indicative timeframe
Six to twelve months depending on the standard and your starting point.

Third-party risk management

The problem
Your suppliers access your data, and you have no method for assessing what that means.
The deliverable
A map of your third parties, a proportionate assessment questionnaire, contractual clauses, and a reassessment rhythm.
Indicative timeframe
Two to four months for the framework, then ongoing.

Artificial intelligence governance

The problem
Your teams already use AI tools, and the regulatory framework is taking shape.
The deliverable
An inventory of your uses, a classification by risk level, an acceptable use policy, and the associated controls. We draw on ISO/IEC 42001, the European AI Act and the Council of Europe Framework Convention on artificial intelligence.
Indicative timeframe
Three to six months.

The partner network

For questions outside our scope, we work with lawyers specialising in data protection, technical providers and independent auditors. We say so when an engagement goes beyond what we can do alone.

SMEs and sole traders

The data protection framework

The problem
You know the law applies to you. You do not know exactly what it requires, nor in what order to tackle it.
The deliverable
Internal policies, record of processing activities, privacy notice, data breach procedure, processor agreements with your suppliers. Every document is explained: what it is for, who signs it, where to file it.
Indicative timeframe
Four to eight weeks depending on size and number of processing activities.

Impact assessment

The problem
A new processing activity, a new tool, and the question: is an impact assessment required, and how do you run one?
The deliverable
The written assessment, meeting the content required by law, with the conclusion on prior consultation of the authority and the measures to put in place.
Indicative timeframe
Two to three weeks per processing activity.

Handling a data breach

The problem
A stolen laptop, an email to the wrong recipient, unauthorised access. Decisions are made within hours.
The deliverable
A procedure prepared in advance, and our involvement at the time of the incident: risk assessment, drafting the notification if one is due, informing the people concerned.
Indicative timeframe
The procedure takes two weeks to set up. Our involvement is immediate.

Staff awareness

The problem
The rules exist, but nobody applies them because nobody has understood them.
The deliverable
A session tailored to your activity, material your teams keep, and a quiz that tells you what stuck.
Indicative timeframe
Half a day, then an annual refresher.

GRC tooling

The problem
Your compliance evidence lives in binders, inboxes and the memory of two people.
The deliverable
A tool sized for your organisation, configured with your risks, your controls and your deadlines. Not an oversized platform.
Indicative timeframe
Three to six weeks.

Sports associations

The data protection compliance kit

The problem
The law applies to every association, with no size threshold. But nobody on a volunteer committee has the time to turn it into documents.
The deliverable
A complete set: policies, charters, consent forms, processor agreements, procedures, and a record of processing activities pre-filled for your sport. The documentary core has been reviewed and validated by a law firm specialising in data protection.
Indicative timeframe
Two committee meetings for the core set, three to four months for the full rollout.

Automatic personalisation

The problem
A generic template protects nobody. Adapting twenty-four documents by hand takes two days per volunteer.
The deliverable
A software assistant that runs offline: you answer, it fills in the whole set with your name, your colours and your records. No data ever leaves your device.
Indicative timeframe
Two hours.

Training and awareness

The problem
A document signed without being understood protects nobody.
The deliverable
An online course on our training platform, with validation quizzes and tracking per club. Plain-language guides for parents, coaches and volunteers.
Indicative timeframe
One hour for the committee, ten to twenty minutes per volunteer.

Self-assessment and impact assessment

The problem
Knowing where to start, and knowing when you are done.
The deliverable
Two self-assessment tools (seventeen questions to get going, forty-four to measure) and an impact assessment tool that reaches its own conclusion on whether the authority must be consulted.
Indicative timeframe
Twenty minutes for the first assessment.

A question about your situation?

A first thirty-minute conversation, no strings attached.

Get in touch contact@rethinkmindset.ch