Picture of OSAM FORMATIONS

OSAM FORMATIONS

Christina Borges

Data protection: a strategic tool for SMEs

After 38 years’ professional experience in Uruguay, Italy and Switzerland, I have learnt one thing that applies to virtually all areas of business management: organisations that treat compliance as a burden end up suffering as a result. Those that treat it as a tool master it and derive real benefit from it.

Data protection is no exception. And yet it is one of the areas where I still most often see SMEs reacting rather than planning ahead.

 

A reality from day one

There is a persistent misconception: that data protection is only a concern for large companies – those that handle millions of customer records or operate large-scale digital platforms.

That’s not what I’m seeing on the ground.

Every SME processes personal data right from the start of its operations: its customers’ contact details, its employees’ files, job applications received by email, forms completed on its website, contact lists for its newsletter, and the tools it uses on a daily basis. It is not a question of size, sector or turnover. It is an operational reality that affects every business, right from its very first customer.

In Switzerland, the nLPD, which came into force in September 2023, imposes specific obligations on all organisations that process personal data within the country. And the European GDPR applies as soon as a Swiss SME processes the data of individuals based in the European Union: a French customer, a German supplier or a Belgian newsletter subscriber is sufficient.

Two distinct legal frameworks, obligations that sometimes overlap, and a reality that many managers realise only too late.

It’s always cheaper to plan ahead than to put things right.

 

What I see most often in the field

In my day-to-day work with SMEs in French-speaking Switzerland and my Italian clients, whom I visit every month, I regularly come across the same weaknesses. This is not down to negligence, but because nobody has taken the time to lay the foundations properly.

The reference databases are either missing or out of date. A data processing register that has not been updated for two years. Legal notices that have been copied and pasted onto the website but do not reflect the reality of the business. Contracts with service providers that make no mention of data protection. These are the foundations, and they are often lacking.

Suppliers are undervalued. Every cloud-based tool, every piece of SaaS software and every external service provider that accesses personal data poses a potential risk. Yet it is often this link in the chain that is the least closely monitored. Who hosts the data? In which country? What are the terms of the contract? These questions must be answered.

Compliance is gathering dust in a filing cabinet. This is perhaps the most common shortcoming: producing compliance documents without ensuring that internal practices are aligned with them. A privacy policy published on a website does not protect anyone if staff do not know how to handle a request for access or recognise a security incident.

Compliance must be dynamic, consistent and embedded in the organisation’s actual processes.

 

Integrate without adding bulk

The question that almost all the executives I work with ask me is this: How can we integrate all of this without adding an extra layer to an organisation that is already operating on a just-in-time basis?

My answer is always the same: by not adding any extra layers, but by building on what already exists.

Data protection does not need a dedicated department to function within an SME. It needs to be integrated into the key stages that already punctuate the life of the business.

Introducing a new digital tool? Now is the time to ask three simple questions about data and hosting. Hiring a new employee? Now is the time to provide clear information on the data being processed and internal policies. Signing a contract with a new supplier? Now is the time to check the data protection clauses in the contract.

My practical recommendation is this: a short checklist, tailored to each typical situation, which teams can go through in a matter of minutes. A few good questions asked at the right time are better than forty-page procedures that nobody reads.

It is also useful to appoint an in-house point of contact – without necessarily creating a new post – who can centralise enquiries, keep track of regulatory updates and know when to seek external support. Not a lawyer. A liaison.

The aim is to make compliance a professional habit, rather than an administrative burden.

 

AI is a game-changer and raises new questions

With the rise of artificial intelligence tools in businesses, a new area of risk is emerging, and one that has yet to be fully mapped out in SMEs.

Editorial assistants, data analytics tools, AI-enhanced CRM systems, automated recruitment platforms: SMEs are adopting these tools rapidly, often without having asked the right questions first.

The first question is simple: what data do we feed into these systems, and what happens to it afterwards? Is it used to train the models? In which country is it hosted? Who has access to it?

The quality and legitimacy of data also play a key role. Data that has been collected incorrectly, is incomplete or is used for purposes other than those for which it was originally intended can create significant legal and operational risks, even in a tool that appears perfectly innocuous.

The European AI Act, which has been gradually coming into force since 2024, also introduces obligations that vary according to the risk level of the systems used. Some SMEs are already affected without realising it.

Before adopting a new AI tool, I recommend three steps : take stock of the tools already in place, assess the data involved and the associated risks, and then establish a simple set of internal governance rules. The aim is not to stifle innovation — it is to enable businesses to use AI in an informed, secure and responsible manner.

 

What I’ve noticed about SMEs that have got ahead of the game

SMEs that have structured their approach to data protection – even on a modest scale, and even without a permanent consultant – share several characteristics that I regularly observe.

They know their data: where it is, who has access to it, and how long it is retained. They are more responsive when an incident occurs, because they have a procedure in place, however simple it may be. They inspire greater confidence in their customers and business partners. And they find it easier to meet the growing demands of tenders, audits and B2B relationships, particularly with European companies, which now systematically vet their service providers.

A well-designed compliance framework does not place a burden on the organisation. It makes it stronger.

 

Turning a constraint into an opportunity

I often conclude my consultancy engagements with this point: an SME that has its data under control has part of its risk, its reputation and its relationship with its stakeholders under control.

It is not an ideal. It is a reality that I see, week in, week out, in companies of all sizes and across all sectors.

Data protection is not an end in itself. It is a means of enhancing professionalism, credibility and, ultimately, performance.

Turning an obligation into an opportunity: that is precisely where strategic advice begins.

 

Cristina Borges supports SMEs in French-speaking Switzerland and Italy with their compliance with the nLPD, GDPR and AI Act, as well as with their organisational structure and quality management (ISO 9001, ISO 22000 / HACCP). She also advises on issues relating to governance, management control and internal organisation.

 

www.cristinaborges.com · gestione@cristinaborges.com · +41 77 513 45 57

Share

Recommended items