Data Privacy & Data Protection Services

We support your Risk, Compliance and Legal departments and help you comply with data protection regulations.

Privacy and Data Protection are the essential foundations for digital trust and confidence in an interconnected environment and enabler for secure, data-driven products especially when using AI. Understanding your organization’s data and how to handle it to ensure compliance with changing regulations and requirements is the key to compliant operations.

As our world becomes more interconnected and complex, robust data protection mechanisms are indispensable for fostering and preserving trust.

Our multidisciplinary team has extensive knowledge of the regulatory landscape, technology, risk and compliances and combines this with expertise in the optimization of processes and procedures relating to data protection practices. The complexity of todays and the evolving regulatory landscape, and thus securing data protection possesses many challenges.

We not only assess your compliance with the law, but also support you with the necessary compliance framework, including governance, processes, directives, technical and organizational measures, secure cross-border transfers, training and awareness-raising around data protection regulations.

Benefit from our expertise and experience in all practical privacy and data protection related matters.

Thomas Bolliger

Director, Information Management & Compliance

KPMG Switzerland

Alberto Job

Director, Information Management & Compliance

KPMG Switzerland


Why KPMG services?

  1. Expertise in global, regional (EU) and national data protection

    KPMG specializes in data protection, information security and data management and provides comprehensive data security measures.

  1. Cross-industry and sector references

    The references we provide offer insights into digitalization and data trends, empowering early risk mitigation with tailored measures.

  1. Interdisciplinary approach

    We combine technical, organizational and legal expertise in an interdisciplinary approach to provide practicable privacy solutions and ensure risk-based end-to-end client support.

  1. Practical compliance solutions

    Our compliance solutions integrate a wide range of regulatory requirements effectively and simply through automation to facilitate compliance. We offer predefined modules for the rapid and effective implementation of data protection and AI measures.


Our services help you generate innovation by providing value far beyond just data privacy

Safeguard privacy rights

Upholding stringent data protection measures ensures individuals' privacy rights, aligning with fundamental values and legal frameworks.

We help you develop and execute strategies, we provide expert guidance on frameworks and ongoing monitoring for a sustainable implementation of effective measures to keep up with privacy rights and laws.

Enable innovation and responsible data use

Promoting a secure environment encourages responsible data use and fosters innovation in emerging technologies, such as artificial intelligence, blockchain, and the Internet of Things (IoT).

We support you create secure environments where you can innovate and ensure data integrity while maximizing the potential of new technologies.

Foster trust and stability

Strong data protection practices foster trust among citizens, businesses, and international partners, contributing to sustainable relationships and economic stability.

We help you with plan and implement robust data protection strategies in order to enhance transparency, accountability and security.

Ensure regulatory compliance

Adhering to robust data protection regulations, such as the General Data Protection Regulation (GDPR), ensures legal compliance and mitigates regulatory risks for entities operating globally.

We help you implement tailored compliance frameworks, strategic advice and to develop incident response plans to mitigate risks.

Strengthen cybersecurity resilience

Effective data protection measures help mitigate cybersecurity threats, reducing the potential for data breaches, cyberattacks, and financial losses.

We help your organization be more resilient and have to right plans in place to minimize risks and impacts.

Strengthen your Governance on AI

Our services enable you to build relevant building blocks for an effective AI Management System and constantly monitor your compliance with applicable laws and regulations, such as the EU AI Act or the expectations of FINMA towards the financial industry.

We help you to build a good start in your AI journey and minimize AI risks whilst you strive to unlock the potential of AI.

Navigating success: our proven approach

Assess

  • As part of our services, we will perform in-depth gap and maturity assessments, provide a detailed mitigation plan that addresses any gaps identified and assist with implementing the mitigation strategy applying data protection best practices that are tailored to your situation.
  • We focus on assessing the organization's compliance with national and international data protection regulations, such as the European General Data Protection Regulation (EU-GDPR), the Swiss Federal Act on Data Protection (CH-FADP) and the EU Artificial Intelligence Act (EU AI Act). 
  • We assess your Data Protection Management System (DPMS), including the organizational structure, governance and operational model and define appropriate best practice solutions. 
  • We assist you in determining data flows, design data maps and support the Record of Processing Activities (ROPA) for greater insight of your data-driven products and identify potential compliance challenges.
  • We review and design policies, procedures and control mechanisms.

  • Data Protection Impact Assessment (DPIA): we help you to identify, assess and evaluate risks in data processing activities. Our services cover advising, managing the entire DPIA process, assisting DPOs or business units, defining state-of-the-art technical and organizational measures, structuring actions as well as establishing review processes for compliance and accountability.
  • Transfer Impact Assessment: compliance with data transfer regulations to third countries is crucial. We assist in evaluating the data protection level of adequacy of the recipient state and defining additional safeguards.

  • Producers of data processing systems or programs as well as controllers and processors are entitled to undergo an assessment of their systems, products and services by a recognized independent certification body (Art. 13 para. 1 FADP).
  • KPMG, accredited by the Swiss Accreditation Body (SCESm 0071), is authorized to audit and certify data protection management systems (DPMS) as per Article 13 of the Swiss Federal Act on Data Protection (FADP). Our thorough certification program allows you to showcase ongoing compliance.

Transform

We support your organizations in evaluating technological, social and political trends and forecasts for the digital market. We take global and national regulatory developments into account and derive a customized data protection strategy for your business area and your needs.

We support businesses in establishing a robust data protection program, which involves creating policies and processes to be followed across all stages of the privacy program life cycle. Additionally, we integrate main processes to ensure accountability, uphold data subject rights, handle data protection incidents and manage third parties. Our approach includes defining key performance indicators (KPIs) to measure performance and facilitate continuous improvement throughout the program's operational life cycle. 

We support organizations by introducing privacy tools to automate data protection management and streamline business processes. Leveraging resources such as the OneTrust Alliance, eGRC tools, vendor evaluation solutions and AI for privacy, businesses efficiently manage compliance, assess risks and enhance privacy practices.

Operate

Supporting the company's operational business unit in implementing data protection and internal requirements (e.g. advising on handling data subject rights, fulfilling information requirements, conducting data protection impact assessments (business case assessment and enabling)).

Providing subject matter expertise in applicable legal and regulatory compliance obligations, our specialists are experienced in the areas of IT, law and organization, holding internationally recognized certifications.

Providing assistance in readiness for and responding to data breaches, ensuring compliance with regulatory requirements including notification to supervisory authorities and data subjects, while also establishing project task forces and facilitating coordination efforts among affected stakeholders from business, legal, IT, data protection and information security units.

Data protection requires regular or ad-hoc deletion of personal data when the processing purpose no longer applies or in response to legitimate requests. We assist in defining deletion rules aligned with business and legal requirements, ensuring compliance with commercial, tax and archiving laws. Our support includes determining retention, archiving and deletion needs for data categories, and developing practical deletion concepts with your business units.

Defining and assessing appropriate technical and organizational measures to ensure adequate security of processing according to national and international data protection requirements on a risk-based approach, considering international standards for information security (e.g. Guidelines of the Supervisory Authorities, Industry standard ISO/IEC 27001, NIST).

When outsourcing to service providers for activities such as cloud services, marketing campaigns, data center storage or affiliated company processing, data protection and contractual compliance are crucial. Service providers must ensure data security, grant audit rights, and comply with specific requirements for data transfer. We assist in identifying suitable providers, guide you through contract negotiation, and offer advice on data protection considerations.


Partnering for success: submit your interests and open questions

Secure your digital assets. We support your compliance and digitization strategies with our expertise in data protection, information security and data management.

Meet our expert

Thomas Bolliger

Director, Information Management & Compliance

KPMG Switzerland

Alberto Job

Director, Information Management & Compliance

KPMG Switzerland