DPIA

Data protection impact assessment

At Innovando Swiss, data protection is not a formality. It is a foundation. We design systems and processes that combine Swiss infrastructure, encryption and proactive governance, ensuring that personal information remains secure, traceable and managed with integrity.

Data protection impact assessment

Protecting data does not simply mean keeping it safe. It means knowing why it is collected, how it is processed, where it is stored, and what risks it may generate.

Every item of personal data says something about a person, a relationship, a choice, or a professional connection. Even when it appears simple, an email address, billing information, a request submitted through a form, or a browsing trace is never merely a technical element. It is a fragment of trust.

For Innovando, data protection is not a compliance item to be placed at the bottom of a website. It is part of the way we work. It concerns the structure of our processes, the choice of suppliers, system architecture, information retention, cybersecurity, access management, internal documentation, and the relationship with clients, users, partners, and providers.

The DPIA, Data Protection Impact Assessment, exists precisely for this reason: to identify processing activities, assess risks, define appropriate measures, and transparently document the choices made. Within the European framework, Article 35 of the GDPR requires a DPIA when processing is likely to result in a high risk to the rights and freedoms of natural persons. The European Data Protection Board also considers the DPIA a central tool for assessing and governing processing risks.

In the Swiss context, the Federal Act on Data Protection requires an impact assessment when processing may entail a high risk to the personality or fundamental rights of the data subjects, particularly in relation to the nature, scope, circumstances, and purpose of the processing, including when new technologies are used.

Innovando GmbH has chosen to draft and maintain its own DPIA not as a defensive document, but as a governance tool. Our objective is not only to demonstrate compliance. It is to make visible the way we protect the information that moves through our processes.

The DPIA as a method, not as bureaucracy

A well-conducted impact assessment is not meant to produce paperwork. It is meant to prevent superficiality.

It helps us ask which data is collected, for what reason, by whom it is processed, how long it is retained, which tools process it, which suppliers may access it, what risks exist, and which technical and organisational measures have been adopted to reduce them.

This distinction is decisive.

Data protection does not live inside legal formulas. It lives inside systems, behaviours, and operational decisions. A privacy policy can explain. A cookie banner can collect preferences. A contract can regulate roles and responsibilities. But the DPIA goes one step further: it observes the entire processing activity as an organism, analyses its sensitive parts, and measures the residual risk.

In our case, the DPIA covers the operational, consulting, and digital activities of Innovando GmbH: analysis, marketing, CRM, ordinary and extraordinary website maintenance, production of strategic communication documents for businesses, and administrative management of commercial relationships.

This means that data protection is not addressed only when a problem arises. It is integrated before, during, and after processing. Before, in the design phase. During, in the management of access, tools, and suppliers. After, in retention, review, and deletion when the data is no longer necessary.

Which data we process and why

Innovando processes personal data connected to its professional activity: data relating to clients, prospects, suppliers, employees, and web users. The categories include first name, last name, company name, address, email, contractual data, billing data, cookies, and browsing data.

This data is necessary to manage commercial relationships, communications, administrative activities, digital services, newsletters, traffic analysis, content personalisation, technical maintenance, consulting activities, and the continuous improvement of services.

The principle remains simple: collect what is needed, retain it for the necessary time, protect it with appropriate measures, limit access, and make the processing understandable.

The DPIA exists precisely to prevent data collection from becoming automatic. Every item of data must have a reason. Every processing activity must have a perimeter. Every risk must be assessed. Every security measure must be proportionate.

We do not treat data as indistinct raw material. We treat it as responsibility.

Technical security and infrastructure

Data security at Innovando is based on a multi-layered strategy. There is no single measure capable of guaranteeing absolute protection. There is, instead, a combination of technical, organisational, and behavioural choices that reduce risk and make the infrastructure more resilient.

The DPIA documents a strategy based on the principles of defense in depth and resilience by design. In other words: multiple layers of protection, multiple control points, and greater recovery capacity in the event of an incident, human error, failure, or external event.

One of the central elements is the backup system based on the 3-2-1 rule: three copies of the data, two different storage media, and one copy kept off-site. Company data is duplicated on a primary NAS system in RAID 5 and on a second NAS, also in RAID 5, located in a different physical unit. Backups are encrypted and subject to periodic integrity tests.

This architecture is not a secondary technical detail. It is a statement of method. It means that operational continuity, information availability, and protection against data loss or damage are not entrusted to luck, but to a redundant and verified structure.

The DPIA also documents AES-256 encryption for backups, controlled key custody, hash checks, dedicated hardware firewalls, network segmentation, regular server updates, and the application of security patches within 24 hours of their official release.

Protection, when it is serious, makes no noise. It works beneath the surface.

Suppliers, location, and responsibility

Data protection does not only concern what happens inside the company. It also concerns the technological supply chain.

For this reason, the DPIA identifies the external processors and suppliers involved in the processes, including Metanet AG for cloud and hosting, BREVO for newsletter management, Banca Popolare di Sondrio and PayPal for payments, and BEXIO for company accounting. The document also indicates certifications and infrastructure references connected to data centres compliant with ISO 27001.

Data location is an important element of our security posture: the DPIA states that data is stored and processed in Switzerland and that no transfer is carried out to countries outside the EU or not adhering to the GDPR and the FADP.

This choice should not be read as a geographical formula. It should be read as a control criterion. Knowing where the data is, through which suppliers it passes, and which measures protect it is an essential part of trust.

Security is not simply a matter of “having good tools”. It is knowing who does what, where, within which limits, and under which responsibility.

Assessed risks and mitigation measures

A serious DPIA does not pretend that risk does not exist. It names it.

The document identifies potential risks such as unauthorised access to data, accidental loss or damage, unauthorised automated profiling, and unlawful data transfer.

The assessment does not merely list them. It connects them to the mitigation measures adopted: redundant backups, encryption, firewalls, segmentation, updates, access limitation, internal procedures, security culture, absence of unauthorised predictive automated processing, and periodic review.

The point is not to say that nothing will ever happen. That would be naive and not very credible. The point is to demonstrate that risks have been understood, classified, and reduced through proportionate measures.

According to the DPIA, the combination of infrastructure, backups, security procedures, and absence of high-impact processing results in an extremely low residual risk.

This sentence is important, but it must be properly understood. “Low risk” does not mean absence of responsibility. It means that the processing has been analysed and that the measures adopted are considered appropriate in relation to the nature, scale, and purposes of the data processed.

Data breach: preparing before it happens

Data protection is not only about prevention. It is also about knowing how to respond.

Innovando’s DPIA provides for a procedure in the event of a suspected or confirmed data breach: immediate notification to the controller, technical analysis within 24 hours, isolation of the affected system, communication to the data subjects and competent authorities when necessary, drafting of an incident report, and annual review.

This procedure has a precise value: it reduces improvisation.

In data management, improvisation is one of the most underestimated risks. An incident becomes serious not only because of what happens technically, but also because of how it is recognised, contained, documented, and communicated.

Preparing a procedure means accepting a mature reality: no system should be based on the idea of being invulnerable. It should be based on the ability to prevent, detect, respond, and improve.

Trust does not arise from the promise that problems will never exist. It arises from the quality of the response when a problem is identified.

Privacy by design, privacy by default, accountability

The DPIA is also a tool for giving substance to three fundamental principles: privacy by design, privacy by default, and accountability.

Privacy by design means designing processes and tools with data protection in mind from the beginning, not as a later correction. Privacy by default means limiting processing to what is necessary, avoiding excessive collection or overly invasive configurations. Accountability means being able to demonstrate, through documents, processes, and concrete measures, that data protection is not merely declared, but practised.

The Italian Data Protection Authority emphasises that an impact assessment is good practice even beyond strictly mandatory cases, because it helps the controller prevent incidents and obtain useful guidance for governing processing activities.

This is exactly the perspective we adopt.

The DPIA is not a static archive. It is a living document, subject to annual review or whenever substantial changes occur in business processes, IT systems, or the applicable regulatory framework.

Serious protection is not written once and for all. It is maintained.

A culture of security

Cybersecurity is not only a matter of servers, backups, and firewalls. It is a culture.

In the DPIA document, Innovando states that it promotes a proactive security culture, in which every collaborator considers data protection not as an operational constraint, but as an ethical and reputational responsibility.

This passage is perhaps one of the most important.

Companies often speak of data protection as if it were a matter reserved for technicians or lawyers. In reality, every item of data enters a chain of behaviours: who collects it, who reads it, who saves it, who transmits it, who deletes it, who exports it, who uses it to make decisions.

Technology can protect a great deal. It cannot protect everything on its own.

For this reason, our DPIA brings together infrastructure and behaviour, tools and responsibility, technical measures and organisational awareness. Data protection works when it becomes a professional habit, not when it remains confined to a document.

The value for clients, partners, and users

A DPIA is not useful only to the company that drafts it. It is also useful to those who work with that company.

For clients, it means knowing that the data entrusted to Innovando does not enter an opaque system. It means being able to rely on documented processes, identified suppliers, declared security measures, defined retention periods, incident response procedures, and clear responsibilities.

For partners, it means collaborating with an organisation that considers the protection of information part of its professional quality.

For users, it means interacting with a digital ecosystem designed to reduce risks, avoid unnecessary processing, and maintain a more transparent relationship between technology, communication, and trust.

Data protection, when done well, does not slow work down. It makes it more serious.

It helps avoid ambiguity, reduces vulnerabilities, improves processes, strengthens reputation, and creates a more solid foundation for every commercial relationship.

Our commitment

Innovando considers the DPIA a declaration of operational maturity.

  • It is not enough to say that data is important. It must be demonstrated through coherent architectures, procedures, responsibilities, reviews, limits, criteria, and technical choices.
  • It is not enough to have a privacy policy. We must know which risks live behind processing activities.
  • It is not enough to rely on trustworthy suppliers. We must know where they sit within the chain of responsibility.
  • It is not enough to have backups. They must be tested, protected, separated, encrypted.
  • It is not enough to talk about security. It must be built.

Our Data Protection Impact Assessment exists for this reason: to transform privacy from a formal obligation into an internal discipline. A discipline made of prevention, proportionality, review, and responsibility.

Personal data is not a technical detail. It is a relationship of trust in digital form. Protecting it means protecting people, clients, processes, and the very credibility of the company.

Innovando GmbH

Legal and operational headquarters:
  • Loretto, 4
  • 9108 Gonten
  • Appenzell Innerrhoden
  • Switzerland

TAX DETAILS

  • Commercial register: Appenzell Innerrhoden
  • Registration date: 02/03/2013
  • Registration nr.: 1138488
  •  VAT number: CHE-396.086,464
  • Share capital: CHF 20,000
  • DUNS Number: 48-692-9891

QUICK CONTACTS

OFFICE HOURS

Local dateSwitzerlandChecking...

SECURITY