What we do
Each service starts from a concrete problem and ends with a deliverable you keep. The timeframes given are indicative, not commitments.
The regulations we cover: the Swiss Federal Act on Data Protection and the GDPR for data protection, NIS2 and DORA for sectors subject to European law, the CRA for products with digital elements, and the Swiss Information Security Act for federal mandates. We also follow the draft Swiss federal cybersecurity act, modelled on the CRA.
The timeframes below are indicative. Every organisation starts from a different situation: the actual duration is agreed together after the first conversation and set out in the written proposal. They do not constitute a commitment.
Regulated organisations
Readiness for standards
- The problem
- A client, an insurer or a regulator asks for a certification or a report you have never prepared.
- The deliverable
- Gap analysis, management system documentation, control implementation, audit preparation. We cover ISO 27001 for information security, ISO 27701 for privacy, ISO 22301 for business continuity, SOC 2 Type I and Type II readiness, the NIST CSF 2.0 framework and the CIS Controls.
- Indicative timeframe
- Six to twelve months depending on the standard and your starting point.
Third-party risk management
- The problem
- Your suppliers access your data, and you have no method for assessing what that means.
- The deliverable
- A map of your third parties, a proportionate assessment questionnaire, contractual clauses, and a reassessment rhythm.
- Indicative timeframe
- Two to four months for the framework, then ongoing.
Artificial intelligence governance
- The problem
- Your teams already use AI tools, and the regulatory framework is taking shape.
- The deliverable
- An inventory of your uses, a classification by risk level, an acceptable use policy, and the associated controls. We draw on ISO/IEC 42001, the European AI Act and the Council of Europe Framework Convention on artificial intelligence.
- Indicative timeframe
- Three to six months.
The partner network
For questions outside our scope, we work with lawyers specialising in data protection, technical providers and independent auditors. We say so when an engagement goes beyond what we can do alone.
SMEs and sole traders
The data protection framework
- The problem
- You know the law applies to you. You do not know exactly what it requires, nor in what order to tackle it.
- The deliverable
- Internal policies, record of processing activities, privacy notice, data breach procedure, processor agreements with your suppliers. Every document is explained: what it is for, who signs it, where to file it.
- Indicative timeframe
- Four to eight weeks depending on size and number of processing activities.
Impact assessment
- The problem
- A new processing activity, a new tool, and the question: is an impact assessment required, and how do you run one?
- The deliverable
- The written assessment, meeting the content required by law, with the conclusion on prior consultation of the authority and the measures to put in place.
- Indicative timeframe
- Two to three weeks per processing activity.
Handling a data breach
- The problem
- A stolen laptop, an email to the wrong recipient, unauthorised access. Decisions are made within hours.
- The deliverable
- A procedure prepared in advance, and our involvement at the time of the incident: risk assessment, drafting the notification if one is due, informing the people concerned.
- Indicative timeframe
- The procedure takes two weeks to set up. Our involvement is immediate.
Staff awareness
- The problem
- The rules exist, but nobody applies them because nobody has understood them.
- The deliverable
- A session tailored to your activity, material your teams keep, and a quiz that tells you what stuck.
- Indicative timeframe
- Half a day, then an annual refresher.
GRC tooling
- The problem
- Your compliance evidence lives in binders, inboxes and the memory of two people.
- The deliverable
- A tool sized for your organisation, configured with your risks, your controls and your deadlines. Not an oversized platform.
- Indicative timeframe
- Three to six weeks.
Sports associations
The data protection compliance kit
- The problem
- The law applies to every association, with no size threshold. But nobody on a volunteer committee has the time to turn it into documents.
- The deliverable
- A complete set: policies, charters, consent forms, processor agreements, procedures, and a record of processing activities pre-filled for your sport. The documentary core has been reviewed and validated by a law firm specialising in data protection.
- Indicative timeframe
- Two committee meetings for the core set, three to four months for the full rollout.
Automatic personalisation
- The problem
- A generic template protects nobody. Adapting twenty-four documents by hand takes two days per volunteer.
- The deliverable
- A software assistant that runs offline: you answer, it fills in the whole set with your name, your colours and your records. No data ever leaves your device.
- Indicative timeframe
- Two hours.
Training and awareness
- The problem
- A document signed without being understood protects nobody.
- The deliverable
- An online course on our training platform, with validation quizzes and tracking per club. Plain-language guides for parents, coaches and volunteers.
- Indicative timeframe
- One hour for the committee, ten to twenty minutes per volunteer.
Self-assessment and impact assessment
- The problem
- Knowing where to start, and knowing when you are done.
- The deliverable
- Two self-assessment tools (seventeen questions to get going, forty-four to measure) and an impact assessment tool that reaches its own conclusion on whether the authority must be consulted.
- Indicative timeframe
- Twenty minutes for the first assessment.
A question about your situation?
A first thirty-minute conversation, no strings attached.
Get in touch contact@rethinkmindset.ch