Insight
Switzerland’s revised Data Protection Act: what it means for websites, analytics and marketing
Switzerland’s revised Federal Act on Data Protection has applied since September 2023. It is close to the GDPR in spirit but not identical, and the differences matter for Swiss companies and for foreign companies serving Swiss customers. Websites, analytics and marketing systems are where most businesses meet it every day.
Why Swiss rules deserve their own look
Many companies assume that GDPR compliance automatically covers Switzerland. In practice, much GDPR work does help, because the revised Swiss Act was modernised to remain compatible with European standards. But Switzerland is not in the European Union, the Swiss Act has its own terminology and enforcement model, and some obligations are framed differently.
The revised Act applies to the processing of personal data of natural persons. Unlike the previous law, it no longer protects data about legal entities. It applies to processing that has an effect in Switzerland, even if the processing takes place abroad, which is why foreign online shops, software providers and service companies with Swiss customers need to consider it.
The Federal Data Protection and Information Commissioner supervises compliance and can open investigations and issue binding decisions. Criminal sanctions exist for certain intentional breaches of duties, and they can be imposed on responsible individuals rather than only on the company, which makes the topic a management issue rather than purely a legal one.
Transparency and privacy notices
The revised Act strengthens the duty to inform people when personal data is collected. Privacy notices should explain the identity and contact details of the controller, the purposes of processing, the recipients or categories of recipients, and, where data is disclosed abroad, the countries involved and the safeguards used.
For websites, that means the privacy notice has to reflect what the site actually does: analytics tools, advertising pixels, embedded videos, chat widgets, newsletter services, booking systems and CRM integrations. A generic template copied from another company rarely describes those tools accurately, and an inaccurate notice is a compliance problem in itself.
Notices should be written so ordinary visitors can understand them. Listing every legal article is less useful than a clear explanation of what data is collected, why, where it goes and how long it is kept.
- Who is responsible
- Controller identity and contact details.
- Why data is processed
- Purposes such as enquiries, orders, analytics and marketing.
- Who receives it
- Service providers and other recipients or categories.
- Where it goes
- Countries outside Switzerland and the safeguards applied.
Cookies and analytics
Swiss law does not contain a general cookie consent rule identical to the European ePrivacy framework. Telecommunications law requires that users are informed about cookies and similar technologies and told how they can refuse them. Consent becomes necessary in particular situations, for example where sensitive data is processed or where high-risk profiling is involved.
In practice, many Swiss websites also serve visitors from the European Union and therefore use consent banners that meet EU standards. That is often the simplest route for companies with international audiences. Companies focused only on Switzerland may choose a lighter approach, but they still need transparent information and a real way to refuse tracking.
Analytics and advertising tools should be reviewed for the data they collect, the identifiers they use and where data is processed. Profiling that combines data to assess personal characteristics can require more care, especially if it creates a high risk for the people concerned.
Data transferred abroad
Many website and marketing tools are hosted outside Switzerland. The revised Act allows disclosure abroad to countries that the Federal Council recognises as providing adequate protection. For other countries, suitable safeguards such as recognised standard contractual clauses are needed, unless a specific exception applies.
The Swiss-US Data Privacy Framework provides a route for transfers to certified US companies. Companies should still check whether a specific provider is certified and whether the tool’s configuration matches the privacy notice.
A simple data map is the practical starting point: every tool on the website, what personal data it receives, where it processes that data and which legal mechanism applies to the transfer.
Records, security and breaches
Controllers and processors generally need records of processing activities, although smaller companies with limited risk may be exempt. Even where records are not strictly required, maintaining them makes website and marketing changes easier to manage.
The Act requires appropriate technical and organisational security measures. For websites, that includes secure hosting, access controls for content management systems and CRMs, updates for plugins and dependencies, and careful handling of form submissions.
Data security breaches that are likely to result in a high risk to the personal rights or fundamental rights of the people concerned must be reported to the Commissioner as soon as possible. Affected people must be informed where necessary for their protection or where the Commissioner requires it.
Privacy by design in marketing systems
The revised Act includes privacy by design and privacy by default. For marketing systems, that means collecting only the data needed, setting sensible default privacy settings and building deletion and retention rules into CRMs and email platforms from the start.
Forms are a good example. A contact form that asks only for the information needed to answer an enquiry is easier to justify than one that collects date of birth, company size, budget and phone number by default. Optional fields and progressive profiling can collect more when the relationship develops.
High-risk processing may require a data protection impact assessment. Marketing projects that profile individuals extensively, process sensitive data or monitor behaviour at scale should be assessed before launch rather than after complaints.
A practical checklist for Swiss websites
List every tool on the website and in connected marketing systems. Confirm what data each tool collects and where it processes it. Update the privacy notice so it matches reality. Decide how visitors are informed about cookies and how they can refuse them, and use EU-grade consent where EU visitors are also served. Check transfer safeguards for foreign providers. Minimise form fields. Define retention periods. Prepare a breach response process that includes website and marketing systems.
This article is a general overview for planning websites and marketing systems. Companies should confirm their obligations with advisers familiar with Swiss data protection law.
Questions
When did Switzerland’s revised Data Protection Act apply?
The revised Federal Act on Data Protection has applied since 1 September 2023.
Does GDPR compliance cover Switzerland?
It helps a lot, but the Swiss Act has its own rules and enforcement model, so Swiss requirements should be checked separately.
Do Swiss websites need a cookie banner?
Swiss law requires information and a way to refuse cookies, while consent is needed in particular situations. Sites serving EU visitors often use EU-grade consent.
Does the Swiss Act apply to foreign companies?
It can apply to processing that has an effect in Switzerland, even when the processing takes place abroad.
Who supervises data protection in Switzerland?
The Federal Data Protection and Information Commissioner.
Must data breaches be reported in Switzerland?
Breaches likely to result in a high risk for affected people must be reported to the Commissioner as soon as possible.
Can individuals be fined under the Swiss Act?
Criminal sanctions for certain intentional breaches can be imposed on responsible individuals.
Where this sits in what we do
This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.
- Digital Growth — The ongoing programme — strategy, content, paid, organic and reporting — run as one thing that answers to pipeline rather than to channel dashboards.
- The EU AI Act: what actually applies from 2 August 2026
- Belgium's B2B e-invoicing mandate: the January 2026 big bang
- Invoicing in Switzerland: QR-bill, eBill and electronic invoices to the federal administration
- Tracking pixels on clinic websites: what health data you may be sending to advertisers
- All insight articles
Reviewing a website for Swiss data protection?
We map the tools on your website and marketing stack, fix what they collect and where it goes, and make your privacy information match reality.
Get in touch