[ CYBIRIT // DATA PROTECTION & AI GOVERNANCE ]
Protecting your data
wherever it goes.
We carry your FADP, GDPR and EU AI Act compliance, from everyday processing to your AI projects. On an outsourced DPO mandate or per project.
[ CERTIFICATIONS ]
[ WHAT CHANGED ]
The perimeter moved.
The function watching it did not.
Your data left your servers
SaaS, cloud, processors, and your processors' processors. The chain got longer without anyone redrawing it.
Your obligations stacked up
FADP, GDPR, EU AI Act. Then one more regime for every country where you sell, hire or host. None replaces the others.
AI arrived without going through you
AI features ship in updates, inside software you have already deployed and already approved.
[ SERVICES ]
What we take on.
[ 01 ]
Outsourced DPO
The full function, held over time, without hiring.
- Appointment and point of contact with the authorities
- Maintaining and updating the RoPA
- Impact assessments and mitigation plans
- DSRs and incident handling
- Oversight of processors and international transfers
- Regulatory monitoring and guidance for your teams
- Documented risk decisions and reporting to management
[ 02 ]
Compliance programme
A clear picture, a plan, and documentation that holds.
- Mapping of processing activities and data flows
- Applicable regimes: data protection, information security, AI governance
- Multi-jurisdictional audit, regulations and best practice
- Gap analysis and prioritised plan, starting with quick wins
- Operational documentation: records, policies, privacy notices
- Processor and transfer framework: DPAs, standard clauses and review
- Handover to your teams and training on the documentation
[ 03 ]
AI governance
Know what your AI systems do, before someone asks.
- Inventory of AI systems and how they are actually used
- Role qualification and EU AI Act classification
- Impact assessments, data protection and fundamental rights
- Interplay with the GDPR: automated decisions and transparency
- Internal use policy and staff awareness
- Governance framework aligned with ISO 42001
- Go or no-go decisions before deployment
[ DO YOU NEED A DPO? ]
A DPO is mandatory in some cases. Decisive in many others.
| Situation | Regime | Status |
|---|---|---|
You process sensitive data or you track peopleHealth, biometrics, financial data. Or scoring, profiling, behavioural analytics as a core activity. | GDPR art. 37 | Mandatory |
You deploy AI on personal dataCV screening, customer scoring, automated support, document analysis. Profiling and automated decisions trigger the same obligations, with the EU AI Act on top. | GDPR art. 22 and 35 EU AI Act art. 26 | Often mandatory |
You are a public bodyAdministration, municipality, hospital, school, or any organisation carrying out a public task. | GDPR art. 37 FADP art. 10 and cantonal laws | Mandatory |
You want to decide quickly on sensitive mattersA new tool, a data transfer, an AI feature to switch on. With a designated officer, the question gets settled instead of circulating between legal, IT and management. | Best practice ISO 27001 A.5.2 ISO 42001 A.3.2 | Strategic |
You process sensitive data or you track people
Health, biometrics, financial data. Or scoring, profiling, behavioural analytics as a core activity.
GDPR art. 37
You deploy AI on personal data
CV screening, customer scoring, automated support, document analysis. Profiling and automated decisions trigger the same obligations, with the EU AI Act on top.
GDPR art. 22 and 35
EU AI Act art. 26
You are a public body
Administration, municipality, hospital, school, or any organisation carrying out a public task.
GDPR art. 37
FADP art. 10 and cantonal laws
You want to decide quickly on sensitive matters
A new tool, a data transfer, an AI feature to switch on. With a designated officer, the question gets settled instead of circulating between legal, IT and management.
Best practice
ISO 27001 A.5.2
ISO 42001 A.3.2
Most Swiss companies already process data of people based in the European Union. The GDPR then applies alongside the FADP, and its appointment conditions are stricter.
[ WHY OUTSOURCE ]
The function, without the cost of a hire
Operational straight away.
No recruitment, no ramp-up. The mandate starts within days.
Independent by design.
An internal officer reports to the management they are meant to oversee. Outsourcing removes the conflict of duties. That is not a convenience, it is a legal condition.
Current, without effort on your side.
FADP, GDPR, EU AI Act, foreign regimes. Regulatory monitoring is included in the mandate, not billed on the side.
Without interruption.
No departure to backfill, no hiring round to run, no vacant post. The function stays covered.
[ APPROACH ]
From assessment to ongoing support
- 01
Assessment
Inventory of processing activities, systems and existing documentation. You get a clear picture, ranked priorities and the effort involved.
- 02
Framework
The blueprint for your programme: records, policies, procedures, roles and responsibilities, AI use framework.
- 03
Implementation
Drafting, processor agreements, privacy notices, impact assessments, staff training.
- 04
Ongoing support
Designated point of contact, regulatory monitoring, review of new projects, liaison with authorities.
[ MANDATE LEAD ]

Marie Mansour
MLAW · CIPP/E · ISO 27001 · ISO 42001
Big 4 consultant, then group DPO. Compliance programmes built from the ground up for multinationals and public bodies, across European, Asia-Pacific and Gulf regimes.
[ SECTOR EXPERIENCE ]
A network of specialists complements the mandate when a matter calls for it: technical security, foreign law, certification.
[ CONTACT ]
Start with a first conversation.
Describe your situation in a few lines. We come back to you within one business day.