The new Swiss Data Protection Act (DSG), in effect since September 2023, places heightened requirements on the processing of personal data. Microsoft 365 offers extensive tools to meet these requirements – provided they are correctly configured and deployed across the organization.
DSG Requirements
Data Subject Rights
The DSG significantly strengthens the rights of data subjects. Companies must fulfill information requests within 30 days, process deletion requests, and ensure data portability. Every data processing activity must be transparently documented. Violations can result in fines of up to CHF 250,000 – and unlike the GDPR, the DSG can hold natural persons (responsible individuals) personally liable.
Documentation Obligations
The DSG requires a register of processing activities that systematically records all data processing operations. Data protection impact assessments are required for processing activities that pose a high risk to personal rights. Companies must also document technical and organizational measures (TOMs) and review them regularly to ensure ongoing compliance.
Data Localization
The disclosure of personal data abroad is only permitted under certain conditions. Microsoft offers the option to store data entirely in Switzerland through its data centers in Zurich and Geneva. Configuring Data Residency is a central building block of DSG compliance and should be prioritized during Microsoft 365 setup, especially for organizations handling sensitive Swiss citizen data.
Microsoft 365 Features
Compliance Manager
Microsoft Purview Compliance Manager provides a comprehensive overview of your organization's compliance status. The tool includes pre-configured assessments for various data protection frameworks and delivers a compliance score along with specific action recommendations. Custom assessments can be created for the Swiss DSG that address its specific requirements and local regulatory nuances.
Data Subject Requests
The Data Subject Request (DSR) function in Microsoft Purview enables systematic handling of access, deletion, and correction requests. The tool searches Exchange, SharePoint, OneDrive, and Teams for personal data and generates reports for information disclosure. Automated workflows accelerate processing and ensure compliance with the 30-day response deadline.
Retention Policies
Retention policies in Microsoft Purview automate the data lifecycle. They define how long data must be retained (e.g., statutory retention periods) and when it should be deleted (data minimization per DSG). Audit logs record all access and changes for complete traceability, providing the evidence trail regulators may require during investigations.
Conclusion
Microsoft 365 comprehensively supports DSG compliance – but configuration is key. Swiss companies should activate data localization in Swiss data centers, set up compliance assessments, and establish processes for data subject requests. Professional guidance during setup ensures that all DSG requirements are correctly implemented from day one.

