Datenschutz Compliance Check
Risiken erkennen, Compliance-Anforderungen erfuellen und Best Practices umsetzen — zugeschnitten auf euer Business.
"Whether you are an innovative startup or a successful SME, we offer an industry-specific data protection package that uses our pragmatic, best-practice approach to help your business comply with data protection regulations — book a call with me and my team."
Thomas Kuster · Partner @ LEXR · Book your free call →
Trusted by startups, SMEs and enterprise legal teams
Tapping into LEXR’s expertise and leveraging their advice was a great experience – as great as it can be when dealing with such an uncharming topic like data privacy. We kicked it off with an overall assessment. After that, a clear action plan with specific sub-task ownership and a pragmatic, hands-on approach were the key ingredients for successfully revamping our data privacy setup in view of the revised Data Protection Act.
The data privacy experts at LEXR provided us with a tailor-made compliance package and were very responsive to all of our questions.
How we solve your challenges
From initial risk profiling to actionable policies and ongoing support — full data protection coverage in one team.
Quickly identify risk areas and receive actionable recommendations tailored to your business. We always take into account the specific risk position, industry and company size, and provide tailor-made implementation proposals.
Meet first essential compliance requirements for national and international data protection laws (the EU's GDPR, the Swiss FADP). Gain peace of mind, avoid fines, and increase customer confidence with comprehensive data protection risk analysis.
As additional deliverables to our compliance check, our experts create easy-to-understand and user-friendly processes, policies, and templates that are efficient to use in day-to-day operations.
For other outstanding tasks identified in the assessment, LEXR has a team of legal experts that can assist you on an hourly or monthly basis — from filling in your record of processing activities, retention and deletion concepts, to any other tasks specific to your operations.
How we deliver Data Protection, AI-amplified
Matter in
Brief us in plain language — we scope it and route it to the right specialist.
Intake < 4hAI does the heavy lifting
Our own AI stack drafts, reviews and cross-checks — inside privilege.
60% fewer draft cyclesSenior lawyer signs off
The specialist who built the strategy reviews and signs every output.
Output delivered
On scope, on the quoted price — delivered into your workflow.
Scope and price are fixed in writing before we start — AI absorbs the lift, not your budget.
Our expert data protection services
One team across the whole compliance journey — from initial assessment to ongoing expert support.
Find your perfect flat fee plan
Starter Package
Quick initial overview of the current state of data protection in your company, including simple best practice guidelines. Kick-off workshop, summary of results and to-dos, and a 30-minute debrief. From CHF 2'800 excl. VAT.
Book your free call →Advanced Package
Comprehensive GAP analysis and extensive PDF report of current data protection status — suitable for external documentation (audits, due diligence). Includes roadmap, customised best practice guidelines, and reviewed policies. From CHF 5'600 excl. VAT.
Book your free call →Data Protection Expert Subscription
A data protection expert on a monthly retainer, guiding your daily operations and solving ad hoc problems as they arise. Upon request, LEXR experts can also fulfil the role of data protection officer/advisor.
Learn more →Tailored Expert Support
For more complex and specific projects — filling in your record of processing activities, retention and deletion concepts, and any other tasks identified in your assessment.
See our pricing →Why LEXR
Pragmatic, industry-specific approach
We don't deliver generic checklists. Our compliance checks are tailored to your specific risk position, industry and company size — so you get actionable, proportionate guidance that actually fits your business.
Transparent, predictable costs
Flat-fee packages mean you know the price before we start. No surprise billable hours — just clear deliverables, clear costs, and peace of mind from day one.
Full coverage — GDPR and Swiss FADP
Our data protection experts cover both EU GDPR and the revised Swiss Federal Act on Data Protection (FADP), with practical knowledge of how regulators apply the rules to tech companies, startups and SMEs.
Data protection FAQ
The questions founders and compliance leads ask us most before starting their data protection journey.
A DPA is needed whenever you transfer personal data to a service provider that acts under your instructions for the specific purposes you have defined — what is called a processor. The same need appears if your company acts as a service provider for another company.
Under the EU GDPR, there are certain topics that need to be covered (Art. 28 EU-GDPR): the purpose, duration and nature of the processing; confidentiality obligations for the processor's staff; the processor's obligation to act only under the controller's instructions; assistance with data subjects' rights; data security; and general GDPR compliance. Under Swiss law, the controller must ensure the processor guarantees data security and integrity, can only engage sub-processors with prior authorisation, and notifies the controller of data breaches.
It can, but it needs to obtain authorisation from the controller as defined in the DPA. This can be done on a case-by-case basis — where the processor requests authorisation for each new sub-processor — or via a general authorisation included in the DPA that allows the processor to engage new sub-processors in the future.
In certain cases, personal data is transferred not to a processor but to another company that jointly determines the purposes and means of the processing. Under EU GDPR, this joint-controller relationship also needs to be governed by a contract that determines their respective responsibilities — in particular how they will comply with data subjects' rights and provide appropriate privacy notices.
The Starter Package gives you a quick initial overview — a 90-minute kick-off workshop, a summary of results by email, and a 30-minute debrief — plus first implementation steps such as a privacy policy and breach-handling policy. The Advanced Package adds a comprehensive GAP analysis in PDF format (suitable for external audits or due diligence), a risk-based roadmap with a time horizon, and a broader set of tailored templates including a record of processing activities and DPA template.
Even companies operating solely in Switzerland are subject to the revised Swiss FADP. And as soon as your product or service reaches users in the EU — even indirectly — the GDPR also applies. Our compliance check covers both frameworks and helps you understand which obligations are relevant to your specific situation.
Meet your data protection team
Let's get started
Book your free call and become one of our 1'000+ happy clients.
























