Data Protection

Data protection compliance check

Identify risks, meet compliance requirements, and implement best practices — tailored to your business.

Industry-specific data protection packages for startups & SMEs
Covers EU GDPR and Swiss FADP compliance
Pragmatic, best-practice approach — not generic checklists
Transparent flat-fee pricing — Starter from CHF 2'800
Risk identification, GAP analysis and actionable implementation steps
Trusted by 1000+ clients
Trusted by 1'500+ tech companies & investors
Thomas Kuster
"Whether you are an innovative startup or a successful SME, we offer an industry-specific data protection package that uses our pragmatic, best-practice approach to help your business comply with data protection regulations — book a call with me and my team."

Thomas Kuster · Partner @ LEXR  ·  Book your free call →

Trusted by startups, SMEs and enterprise legal teams

Sandro Matter
Tapping into LEXR’s expertise and leveraging their advice was a great experience – as great as it can be when dealing with such an uncharming topic like data privacy. We kicked it off with an overall assessment. After that, a clear action plan with specific sub-task ownership and a pragmatic, hands-on approach were the key ingredients for successfully revamping our data privacy setup in view of the revised Data Protection Act.
Sandro Matter
Co-Founder & CFO, vlot
Yoko Spirig
The data privacy experts at LEXR provided us with a tailor-made compliance package and were very responsive to all of our questions.
Yoko Spirig
CEO, Ledgy

How we solve your challenges

From initial risk profiling to actionable policies and ongoing support — full data protection coverage in one team.

Quickly identify risk areas and receive actionable recommendations tailored to your business. We always take into account the specific risk position, industry and company size, and provide tailor-made implementation proposals.

Meet first essential compliance requirements for national and international data protection laws (the EU's GDPR, the Swiss FADP). Gain peace of mind, avoid fines, and increase customer confidence with comprehensive data protection risk analysis.

As additional deliverables to our compliance check, our experts create easy-to-understand and user-friendly processes, policies, and templates that are efficient to use in day-to-day operations.

For other outstanding tasks identified in the assessment, LEXR has a team of legal experts that can assist you on an hourly or monthly basis — from filling in your record of processing activities, retention and deletion concepts, to any other tasks specific to your operations.

The LEXR approach

How we deliver Data Protection, AI-amplified

Step 01

Matter in

Brief us in plain language — we scope it and route it to the right specialist.

Intake < 4h
Step 02 AI · Privileged

AI does the heavy lifting

Our own AI stack drafts, reviews and cross-checks — inside privilege.

60% fewer draft cycles
Step 03

Senior lawyer signs off

The specialist who built the strategy reviews and signs every output.

Lars Fidan Maximilian Krähenbühl Christian Meisser
Step 04

Output delivered

On scope, on the quoted price — delivered into your workflow.

Scope and price are fixed in writing before we start — AI absorbs the lift, not your budget.

Our expert data protection services

One team across the whole compliance journey — from initial assessment to ongoing expert support.

Data protection compliance checkGAP analysis & risk reportPrivacy policy & cookie policyData breach policyData subject rights policyRecord of processing activitiesData processing agreement (DPA)Marketing compliance guidelinesData protection officer/advisorEU GDPR complianceSwiss FADP compliance

Why LEXR

01

Pragmatic, industry-specific approach

We don't deliver generic checklists. Our compliance checks are tailored to your specific risk position, industry and company size — so you get actionable, proportionate guidance that actually fits your business.

02

Transparent, predictable costs

Flat-fee packages mean you know the price before we start. No surprise billable hours — just clear deliverables, clear costs, and peace of mind from day one.

03

Full coverage — GDPR and Swiss FADP

Our data protection experts cover both EU GDPR and the revised Swiss Federal Act on Data Protection (FADP), with practical knowledge of how regulators apply the rules to tech companies, startups and SMEs.

Data protection FAQ

The questions founders and compliance leads ask us most before starting their data protection journey.

A DPA is needed whenever you transfer personal data to a service provider that acts under your instructions for the specific purposes you have defined — what is called a processor. The same need appears if your company acts as a service provider for another company.

Under the EU GDPR, there are certain topics that need to be covered (Art. 28 EU-GDPR): the purpose, duration and nature of the processing; confidentiality obligations for the processor's staff; the processor's obligation to act only under the controller's instructions; assistance with data subjects' rights; data security; and general GDPR compliance. Under Swiss law, the controller must ensure the processor guarantees data security and integrity, can only engage sub-processors with prior authorisation, and notifies the controller of data breaches.

It can, but it needs to obtain authorisation from the controller as defined in the DPA. This can be done on a case-by-case basis — where the processor requests authorisation for each new sub-processor — or via a general authorisation included in the DPA that allows the processor to engage new sub-processors in the future.

In certain cases, personal data is transferred not to a processor but to another company that jointly determines the purposes and means of the processing. Under EU GDPR, this joint-controller relationship also needs to be governed by a contract that determines their respective responsibilities — in particular how they will comply with data subjects' rights and provide appropriate privacy notices.

The Starter Package gives you a quick initial overview — a 90-minute kick-off workshop, a summary of results by email, and a 30-minute debrief — plus first implementation steps such as a privacy policy and breach-handling policy. The Advanced Package adds a comprehensive GAP analysis in PDF format (suitable for external audits or due diligence), a risk-based roadmap with a time horizon, and a broader set of tailored templates including a record of processing activities and DPA template.

Even companies operating solely in Switzerland are subject to the revised Swiss FADP. And as soon as your product or service reaches users in the EU — even indirectly — the GDPR also applies. Our compliance check covers both frameworks and helps you understand which obligations are relevant to your specific situation.

Let's get started

Book your free call and become one of our 1'000+ happy clients.

Dive deeper into data protection

Data ProtectionAI Features in Your SaaS? What the EU AI Act Means for YouTeam LEXR · Mar 2026Read more →Data ProtectionYou Need to Fix These 5 Points in Your SaaS Agreements Now!Nadine Saalbach · Sep 2025Read more →Data ProtectionNavigating the EU AI Act: A Comprehensive Analysis and Compliance GuideTeam LEXR · May 2024Read more →Data ProtectionNew EU Regulations: A Blueprint for Growth in the Digital SectorTeam LEXR · May 2024Read more →Data ProtectionCybersecurity and data protection: keeping your company's data safeTeam LEXR · Apr 2024Read more →Data ProtectionFrom concept to compliance: Legal Bases for AI training explainedTeam LEXR · Mar 2024Read more →Data ProtectionData Processing Agreements: Navigating the Essentials for Data Protection Compliance (Part 2)Team LEXR · Feb 2024Read more →Data ProtectionData Processing Agreements: Navigating the Essentials for Data Protection Compliance (Part 1)Team LEXR · Jan 2024Read more →Data ProtectionPseudonymisation versus anonymisation: a practical privacy guideTeam LEXR · Dec 2023Read more →Data ProtectionHow to handle data breaches – a privacy best practice guideTeam LEXR · Sep 2023Read more →Data ProtectionNavigating AI tools and data protection: A guide for compliant company practicesTeam LEXR · Jul 2023Read more →Data ProtectionThe new Swiss Data Protection Act comes into force: What tech companies need to do nowTeam LEXR · Jun 2023Read more →Data ProtectionNavigating Privacy Rules for App Developers: App Store Compliance and Privacy RequirementsTeam LEXR · Apr 2023Read more →Data ProtectionKYC for FinTech companies: Data protection guide part 3 - Manage the dataTeam LEXR · Mar 2023Read more →Data ProtectionKYC for FinTech companies: Data protection guide part 2 - Follow the dataTeam LEXR · Feb 2023Read more →Data ProtectionKYC for FinTech companies - Guide to a data protection compliant implementationTeam LEXR · Feb 2023Read more →Data ProtectionChecklist: How to write a privacy policy for the new FADP and GDPR?Team LEXR · Jun 2021Read more →Data ProtectionData Processing Agreement I: Determine whether you are a Controller or a ProcessorTeam LEXR · Apr 2021Read more →Data ProtectionSchrems II impact on privacy shield & SCCsTeam LEXR · Jul 2020Read more →Data ProtectionGDPR impact on AdTech and Real-Time Bidding (RTB)Team LEXR · May 2020Read more →Data ProtectionConfidential Computing and GDPRTeam LEXR · Mar 2020Read more →Data ProtectionThe License to Kill and the right to be forgotten - Gaming in the Age of GDPRTeam LEXR · Mar 2020Read more →Data ProtectionEmployee awareness as the key to security and data privacyTeam LEXR · Feb 2020Read more →Data ProtectionThe Internet of Things in the GDPR eraTeam LEXR · Jan 2020Read more →Data ProtectionGDPR in Switzerland - What it means for businessesTeam LEXR · Dec 2018Read more →