Flitz.ai Flitz.ai
← All articles
5 min read

Password Chaos Is a Compliance Risk: What Swiss DSG Expects From Your SME

Shared spreadsheets and sticky notes aren't just messy — under the revised Swiss DSG they're a liability. Here's what the law expects and how an encrypted team vault closes the gap.

Password Chaos Is a Compliance Risk: What Swiss DSG Expects From Your SME

Ask any Swiss SME owner where the company's passwords live, and you'll often get an uncomfortable answer: a shared Excel file, a sticky note by the printer, or a WhatsApp message from three years ago that nobody has the heart to delete. It works, more or less — until an employee leaves, a laptop gets stolen, or a data protection authority asks how customer data is actually secured.

Password hygiene isn't just an IT nicety anymore. It's a legal expectation.

What the revised Swiss DSG actually expects

The revised Federal Act on Data Protection (DSG), in force since September 2023, requires every business — not just large enterprises — to implement "appropriate technical and organizational measures" to protect personal data against unauthorized access. If your company stores customer addresses, employee records, supplier contracts, or payroll data behind a password that five people know and nobody rotates, that's precisely the kind of gap the DSG is designed to close.

The same logic applies if your business touches EU residents' data under the GDPR, or if you're bound by sector-specific confidentiality rules (fiduciaries, healthcare, legal services). Auditors and cyber-insurers are increasingly asking the same blunt question: who can access what, and can you prove it? A shared spreadsheet answers neither part of that question.

Where manual password management creates real risk

Most SMEs don't lack good intentions — they lack a practical system. The common failure points are predictable:

  • No access trail. When everyone uses the same login for a banking portal or accounting tool, you can't tell who did what, which undermines both security and bookkeeping accountability under the OR.
  • Offboarding gaps. An employee leaves, but nobody changes the shared passwords they had access to. This is one of the most common root causes of post-termination data incidents.
  • Weak or reused passwords. Without a generator and a vault, people default to memorable — and guessable — credentials, often reused across systems that hold MWST filings, salary data, or client records.
  • Authenticator app sprawl. 2FA codes live on one person's personal phone, creating a single point of failure that has nothing to do with data protection policy and everything to do with who happens to be on vacation.

None of this is negligence in the moral sense — it's what happens when security tooling feels heavier than the problem it solves. But from a compliance standpoint, "we meant to fix it" doesn't hold up well in an audit.

What an audit-ready setup actually looks like

You don't need an enterprise security team to meet the DSG's "appropriate measures" bar. You need three things: encryption that actually protects data (not just a password field), controlled sharing instead of blanket access, and a clear record of who can see what.

That's the thinking behind Flitz's encrypted team vault, built directly into the workspace your team already uses for accounting, invoicing, and HR.

Zero-knowledge encryption, by design

Passwords are encrypted in the browser before they ever leave your device. Not even a Flitz admin can read them. This is a meaningful distinction for compliance: if the provider itself cannot access the plaintext data, your exposure in the event of a provider-side incident is fundamentally limited — a point worth documenting in your own data protection file.

Controlled, auditable sharing

Instead of one shared login everyone memorizes, folders can be shared with a specific teammate in two clicks — and only the folder's creator can grant that access. This replaces "everyone has it" with "only these people have it," which is exactly the kind of access control that turns a vague policy into something you can actually demonstrate.

No more authenticator app roulette

Built-in 2FA/TOTP generation means rotating 6-digit codes live in the same encrypted vault, not on one employee's personal phone. That removes a dependency that has quietly caused more login lockouts than any actual security breach.

Offboarding without the scramble

When someone leaves the company, the Tenant Owner has emergency access to shared folders — with mandatory notification to the affected user, so nothing happens silently. This directly addresses the offboarding gap that is one of the most common and preventable sources of post-employment data risk.

No new habits to learn

There's no second master password to memorize — access is derived from the login your team already uses. Folders, items, a built-in generator, and search mean onboarding takes under a minute, which matters: a security measure only reduces risk if people actually use it.

Compliance as a byproduct, not a project

Swiss SMEs don't need a dedicated compliance officer to meet DSG expectations around data security — they need tools where the compliant behavior is also the easiest one. An encrypted vault with two-click sharing and automatic access logging doesn't just reduce your breach risk; it gives you a straightforward answer the next time a client, insurer, or auditor asks how access to sensitive data is controlled at your company.

That's a much better position than digging through an old spreadsheet to remember who still has the Wi-Fi password.

Stop Juggling Tools. Start Running Your Business.

Start your free account in 2 minutes. No credit card required.

Create Free Account