[codicts-css-switcher id=”346″]

Global Law Experts Logo
is cookie consent required in switzerland

Is Cookie Consent Required in Switzerland? Nfadp, FDPIC (EDÖB) Rules & What Businesses Must Do

By Global Law Experts
– posted 2 hours ago

Whether cookie consent is required in Switzerland depends on what the cookie does, what data it collects, and who visits the website. Following the FDPIC’s (EDÖB’s) updated cookie guidelines published on 7 October 2025, Swiss businesses face a clearer, but more demanding, set of rules: functional cookies generally require only transparent notice and an opt-out mechanism, while personalised advertising, profiling, and non-essential tracking demand explicit, documented consent under the revised Federal Act on Data Protection (nFADP). This guide unpacks the legal framework, maps each cookie type to its consent requirement, and provides ready-to-use banner copy, documentation checklists, and cross-border compliance steps for websites that also serve EU residents.

Here is what this article covers:

  • When consent is required and when notice alone suffices, with a practical decision-flow table.
  • Sample cookie banner copy for Swiss-only and dual Swiss/EU audiences.
  • Record-keeping templates and retention guidance aligned with the FDPIC cookie guidelines.

Legal Basis, nFADP, FDPIC (EDÖB) Guidelines and GDPR Interplay

Switzerland’s cookie consent framework sits at the intersection of three legal instruments. Understanding how they interact is the first step toward compliance.

The revised Federal Act on Data Protection (nFADP), in force since 1 September 2023, governs the processing of personal data in Switzerland. The nFADP requires that every instance of personal-data processing rests on a recognised lawful basis, which may include consent, a prevailing private interest, or a statutory obligation. Consent, where it is the applicable basis, must be informed and given voluntarily. For sensitive personal data and high-risk profiling, the nFADP mandates express consent, meaning the individual must actively agree after receiving clear information about the processing purpose.

The FDPIC cookie guidelines (updated version, 7 October 2025) translate these statutory rules into practical instructions for website operators. The guidelines distinguish between cookies that are strictly necessary for a service the user has explicitly requested (such as shopping-cart cookies or session authentication tokens) and cookies used for non-essential purposes like behavioural advertising or cross-site tracking. For strictly necessary cookies, notice and an accessible opt-out are sufficient. For personalised advertising and profiling, explicit consent must be obtained before the cookie is set.

Finally, the EU General Data Protection Regulation (GDPR) may apply in parallel when a Swiss website targets individuals in the European Economic Area, for instance, by offering goods in euros, providing content in EU languages directed at EU audiences, or shipping to EU addresses. Where the GDPR applies, its stricter consent regime (notably Article 7 and Recital 32) governs cookie placement for those visitors, regardless of where the server is located.

What the FDPIC Says in Plain Language

The FDPIC’s October 2025 cookie guidelines can be distilled into four core positions:

  • Transparency first. Every website that sets cookies must inform visitors, in accessible, non-technical language, about which cookies are used, for what purpose, and how long they persist.
  • Functional cookies: notice + opt-out. Cookies that are strictly necessary for the requested service (login tokens, language preferences, load balancers) do not require prior consent, but the user must be told they exist and given a way to object.
  • Personalised advertising and profiling: explicit consent required. Any cookie that tracks behaviour for targeted advertising, builds user profiles, or enables real-time bidding (RTB) must receive affirmative, documented consent before it is placed.
  • No coercion. The FDPIC takes a critical view of “cookie walls” that deny access to a service unless the visitor accepts non-essential cookies. Consent obtained under such conditions may not satisfy the voluntariness requirement of the nFADP.

When the GDPR Applies to Swiss Websites

Under Article 3(2) of the GDPR, the regulation applies to the processing of personal data of individuals who are in the EU when the processing relates to offering them goods or services, or monitoring their behaviour within the EU. A Swiss e-commerce store that lists prices in euros and ships to Germany, or a Swiss SaaS provider with a French-language landing page directed at French users, falls within the GDPR’s reach for those visitors. In practice, this means applying the GDPR’s prior-consent standard for all non-essential nFADP cookies served to EU-based visitors, a higher bar than the notice-plus-opt-out model the FDPIC permits for strictly functional cookies under Swiss law alone.

Businesses in this position should also review broader cross-border data transfer guidance for related compliance considerations.

When Is Cookie Consent Required in Switzerland? A Practical Decision Flow

The question of whether cookie consent is required in Switzerland ultimately turns on the cookie’s purpose and the data it processes. The decision flow below applies the nFADP and the FDPIC cookie guidelines to the most common cookie categories.

Quick Yes/No Rules

  • Session authentication cookies (e.g., login tokens). Consent: No. Action: provide notice.
  • Shopping-cart and form-state cookies. Consent: No. Action: provide notice.
  • Language or accessibility preference cookies. Consent: No. Action: provide notice + opt-out.
  • First-party analytics with IP anonymisation and no cross-site tracking. Consent: Generally no. Action: provide notice, document anonymisation configuration, offer opt-out.
  • Analytics with persistent identifiers or cross-site tracking. Consent: Yes. Action: obtain explicit opt-in before setting the cookie.
  • Personalised advertising / behavioural targeting cookies. Consent: Yes. Action: explicit opt-in + documented consent record.
  • Third-party tracker pixels (social media, ad networks). Consent: Yes. Action: explicit opt-in; do not load tracker script until consent is received.
  • Profiling cookies that generate automated individual decisions. Consent: Yes (express consent under nFADP for high-risk profiling). Action: explicit opt-in + Data Protection Impact Assessment (DPIA) where applicable.

Cookie Consent Comparison Table

Cookie Use Consent Required? Examples & Recommended Banner Action
Functional / strictly necessary No, notice + opt-out sufficient Session IDs, CSRF tokens, shopping cart, load-balancer cookies. Show a brief notice explaining these cookies; provide a link to cookie settings.
Preference / UX cookies No, notice + opt-out sufficient Language selection, dark-mode toggle, font-size preference. Include in the cookie notice; allow the user to disable via cookie settings.
First-party analytics (anonymised, no cross-site tracking) Generally no, document anonymisation; offer opt-out Matomo with IP masking; Google Analytics with IP anonymisation and no data sharing. Disclose in cookie policy; provide opt-out toggle; keep configuration records.
Analytics with cross-site or persistent identifiers Yes, explicit opt-in Google Analytics without IP masking, Adobe Analytics with cross-domain tracking. Do not set cookie until consent is given; log consent.
Personalised advertising / RTB Yes, explicit opt-in + documented consent Google Ads remarketing, Meta Pixel, programmatic ad-exchange cookies. Block all ad scripts by default; fire only after granular consent; retain consent log.
Social-media third-party trackers Yes, explicit opt-in Facebook Like button, X (Twitter) embed, LinkedIn Insight Tag. Replace with static placeholders until consent is received.
High-risk profiling (automated individual decisions) Yes, express consent (nFADP) + DPIA Credit-scoring cookies, dynamic pricing based on behavioural profiles. Require unambiguous opt-in; conduct and document DPIA; review annually.

Do you need consent for functional cookies? Under Swiss law, the answer is no, provided you inform the user, explain the purpose, and give them a meaningful opt-out. The FDPIC cookie guidelines draw a clear line between these low-risk cookies and the non-essential categories that trigger the consent requirement.

Building a Compliant Cookie Banner for Switzerland and EU Visitors

Swiss cookie banner rules require more than a vague “this site uses cookies” notice. A compliant banner must clearly identify cookie categories, provide granular accept/reject controls, and link to a full cookie policy. Where the website also serves EU visitors, the banner must meet the higher GDPR standard of prior opt-in consent for all non-essential cookies.

Sample Banner Copy

Variant 1, Swiss visitors (nFADP-focused):

“We use cookies to operate this website. Some cookies are strictly necessary and are set automatically. We also use analytics cookies to improve our service, these are only set if you agree. You can manage your preferences at any time via ‘Cookie Settings’. For more information, see our Cookie Policy.”

Buttons: [Accept All] [Cookie Settings] [Reject Non-Essential]

Variant 2, EU visitors (GDPR-compliant):

“We value your privacy. This website uses cookies. Strictly necessary cookies are required for the site to function. All other cookies, including analytics and advertising cookies, will only be set with your explicit consent. Please choose your preferences below. You may withdraw consent at any time via ‘Cookie Settings’. Read our Cookie Policy.”

Buttons: [Accept All] [Reject All] [Manage Preferences]

Both variants must link to a standalone cookie policy page that lists every cookie by name, category, purpose, provider, and expiry period. The “Manage Preferences” or “Cookie Settings” layer should offer toggles for each category, functional, analytics, advertising, social media, and must not use pre-ticked boxes for non-essential categories.

UX Best Practices and Dark-Pattern Pitfalls

Is it illegal to force users to accept cookies? Under the nFADP’s voluntariness principle, consent that is a precondition for accessing a service is unlikely to be valid unless the cookies are strictly necessary for that service. The FDPIC has signalled concern about “cookie walls”, banners that offer only an “Accept” button and no alternative. Industry observers expect the FDPIC to intensify scrutiny of such designs in future enforcement actions.

Practical rules to follow:

  • Equal prominence. The “Reject” or “Reject Non-Essential” button must be as visible and easy to click as the “Accept All” button. Hiding the reject option behind a secondary settings layer is a risk factor.
  • No pre-ticked boxes. Every non-essential cookie category must default to “off.”
  • No deceptive colour contrast. Avoid greying out the reject button while using a bright colour for accept.
  • Easy withdrawal. The user must be able to revisit and change their preferences at any time, typically via a persistent “Cookie Settings” link in the website footer.
  • No scripts before consent. Non-essential cookie scripts must not fire until the user has given consent. Implement this through tag-management rules that gate script loading on the consent signal.

Documentation, Logging, Retention and Record-Keeping Under nFADP

Obtaining consent is only half the obligation. The nFADP’s accountability principle requires data controllers to demonstrate that consent was properly collected, and the FDPIC cookie guidelines reinforce this with specific expectations around record-keeping. If cookie consent is required in Switzerland for a given processing purpose, the business must be able to prove that consent was obtained.

Template Checklist, What to Record

Each consent event should capture the following fields:

  • User identifier (hashed or pseudonymised). A unique reference that links the consent record to the individual without storing plain-text personal data unnecessarily.
  • Timestamp (UTC). The exact date and time the user gave, modified, or withdrew consent.
  • Consent string or ID. The machine-readable consent signal (e.g., TCF consent string or custom consent ID) recording which categories were accepted and which were rejected.
  • Granular category choices. A breakdown of whether the user accepted or rejected each cookie category (functional, analytics, advertising, social media).
  • Banner/policy version. The version number or hash of the cookie banner text and cookie policy that the user saw at the time of consent.
  • Vendor list version. The version of the third-party vendor list active at the time of consent, essential for advertising technology consent frameworks.
  • Revocation record. If the user later withdraws consent, a separate timestamped entry documenting the revocation.

Retention Recommendations and FDPIC Expectations

The nFADP does not prescribe a fixed retention period for consent logs. The FDPIC expects controllers to retain records for as long as the processing they authorise continues, plus any period needed to demonstrate compliance in the event of an inquiry or complaint. Best practice is to retain consent logs for at least the duration of the cookie’s maximum lifespan plus one year, refreshing the consent record whenever the cookie policy or vendor list undergoes a material change. Businesses that operate under both Swiss and EU law should align their retention with the GDPR’s accountability requirements, which similarly demand demonstrable proof of valid consent.

Organisations already navigating Swiss regulatory compliance, such as those pursuing an SRO licence in Switzerland, will recognise the pattern: regulators expect documented proof, not assertions.

Special Cases, Personalised Advertising, Profiling, Analytics and Third-Party Trackers

Explicit consent for personalised advertising in Switzerland is the single area where the FDPIC’s October 2025 cookie guidelines are most definitive. Any cookie or pixel that enables behavioural targeting, including programmatic advertising, retargeting, lookalike-audience building, or cross-device identity resolution, falls squarely into the “consent required” category.

Analytics occupy a middle ground. First-party analytics tools configured with IP anonymisation, limited data retention, and no cross-site or cross-device linking generally do not require consent under Swiss law alone, although notice and an opt-out mechanism remain mandatory. The moment analytics data is shared with third parties, linked to advertising identifiers, or used to build individual user profiles, the processing moves into the consent-required zone.

Third-party tracker pixels, such as the Meta Pixel, Google Ads conversion tag, or LinkedIn Insight Tag, are treated as non-essential and consent-dependent under both the nFADP and GDPR. They must not load until the visitor has opted in.

When to Run a DPIA

Under the nFADP, a Data Protection Impact Assessment is required when processing is likely to result in a high risk to the personality or fundamental rights of the data subject. For cookie-related processing, triggers include:

  • Large-scale profiling that produces legal or similarly significant effects on individuals.
  • Systematic monitoring of user behaviour across multiple websites or apps.
  • Combining cookie-derived data with other personal data sets to generate detailed individual profiles.

Vendor Management and Contractual Clauses

Businesses that embed third-party cookies are jointly responsible for ensuring the vendor’s processing complies with the nFADP. At a minimum, contracts with ad-tech and analytics vendors should include:

  • A clause confirming the vendor will not process data beyond the purposes consented to by the user.
  • Obligations on the vendor to respect consent revocations promptly.
  • Audit rights allowing the controller to verify the vendor’s data-handling practices.
  • Clear provisions on data transfers outside Switzerland, consistent with the nFADP’s adequacy and safeguard requirements. Cross-border data flows are a separate but related compliance layer, businesses that also process data in jurisdictions with distinct transfer rules should consider broader cross-border data transfer obligations.

Cross-Border Nuance, When to Apply GDPR and Practical Cookie Consent Compliance Steps

For many Swiss businesses, the question is not just whether cookie consent is required in Switzerland, but whether the stricter GDPR consent requirements also apply. The answer turns on the “targeting test” under GDPR Article 3(2).

Indicators that a Swiss website is targeting EU residents include:

  • Displaying prices in euros or other EU-member-state currencies.
  • Offering shipping or delivery to EU addresses.
  • Publishing content in EU languages specifically directed at EU audiences (as opposed to, for example, French content aimed at Swiss Romande users).
  • Using EU-specific top-level domains (e.g., .de, .fr, .it sub-pages).
  • Running advertising campaigns geo-targeted to EU countries.

Where these indicators are present, practical compliance steps include:

  • Geolocation-based banner logic. Serve the GDPR-compliant explicit-consent banner (Variant 2 above) to visitors whose IP address resolves to an EU/EEA country, and the Swiss nFADP notice (Variant 1) to Swiss-located visitors.
  • Jurisdiction-segmented consent logs. Tag each consent record with the applicable legal regime (nFADP, GDPR, or both) to support jurisdiction-specific accountability.
  • Dual cookie-policy sections. Maintain a single cookie policy document with clearly labelled sections explaining the Swiss and EU legal bases, respectively.

Businesses that have already navigated Swiss cross-border administrative requirements, such as determining whether an apostille is required for Switzerland, will appreciate the importance of jurisdiction-specific documentation in a multi-regime compliance programme. Companies already operating under Swiss corporate transparency obligations, including the Swiss beneficial ownership register requirements, will find similar principles of proactive disclosure and record-keeping at work.

Enforcement Risk and Likely Regulator Focus

The FDPIC has signalled increasing attention to cookie compliance since the October 2025 guidelines. While Swiss enforcement to date has been less aggressive than in jurisdictions such as France (CNIL) or Austria (DSB), early indications suggest the following areas will attract the most scrutiny:

Cookie Category Enforcement Risk Level Key Risk Factor
Strictly necessary / functional Low Risk arises only if notice is missing entirely or opt-out is non-functional.
Anonymised first-party analytics Low–Medium Risk increases if anonymisation is not properly configured or data is shared with third parties.
Personalised advertising / profiling High Consent absent, coerced, or insufficiently documented. Dark-pattern banners.
Third-party trackers / social pixels High Scripts firing before consent; lack of vendor contracts; cross-border transfer gaps.
Cookie walls / forced acceptance Medium–High FDPIC views forced acceptance as undermining voluntariness of consent.

The likely practical effect will be that businesses running personalised advertising without documented consent face the greatest reputational and regulatory exposure. The FDPIC’s investigative powers under the nFADP include the authority to order changes to processing operations and to publish findings, making public naming a meaningful deterrent even in the absence of large financial penalties.

Conclusion, Cookie Consent Compliance Checklist and Next Steps

Whether cookie consent is required in Switzerland depends on what the cookie does. The nFADP and FDPIC cookie guidelines together create a tiered system: notice for functional cookies, explicit consent for advertising and profiling. Businesses that also serve EU visitors must layer GDPR requirements on top. The following six-point checklist summarises the core obligations:

  1. Audit your cookies. Catalogue every cookie and tracker by name, purpose, provider, and expiry.
  2. Classify each cookie. Map it to the correct category (functional, analytics, advertising, profiling) using the decision-flow table above.
  3. Implement a compliant banner. Use granular accept/reject controls, no pre-ticked boxes, and equal-prominence buttons.
  4. Block non-essential scripts. Ensure advertising and tracker scripts do not fire until consent is received.
  5. Document everything. Log consent events with timestamps, category choices, banner version, and vendor list version.
  6. Review regularly. Refresh consent records when your cookie policy or vendor list changes, and reassess annually.

For tailored guidance on implementing these requirements, businesses should consult a qualified Swiss data privacy specialist through the Global Law Experts lawyer directory.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Alexandros Manousakis at Privintelligent Solutions, a member of the Global Law Experts network.

Sources

  1. Swiss Federal Data Protection and Information Commissioner (FDPIC / EDÖB), Official Website
  2. Swiss Federal Act on Data Protection (nFADP), Consolidated Text (Fedlex)
  3. EU General Data Protection Regulation (GDPR), Regulation 2016/679 (EUR-Lex)
  4. European Data Protection Board (EDPB), Guidelines on Consent and Cookies
  5. OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data

FAQs

What are the requirements for cookie consent in Switzerland?
Under the nFADP and FDPIC cookie guidelines, businesses must provide clear notice about all cookies, obtain explicit consent before setting non-essential cookies used for personalised advertising or profiling, and maintain documented records of each consent event including timestamps and category choices.
No. Strictly necessary cookies, those required for core service functions such as session authentication or shopping-cart persistence, do not require prior consent under Swiss law. However, the website must still inform visitors that these cookies are used and provide an accessible opt-out mechanism.
The GDPR applies when a Swiss website targets individuals in the EU or EEA, for example, by offering products in euros, shipping to EU addresses, or running EU-targeted advertising. In these cases, the website must apply the GDPR’s stricter prior-consent requirements for all non-essential cookies served to those visitors, alongside its nFADP obligations.
Each consent event should be logged with a hashed user identifier, UTC timestamp, granular category choices (accepted/rejected), the banner and cookie-policy version the user saw, the active vendor list version, and any subsequent revocation records.
The FDPIC takes a critical view of “cookie walls” that deny service access unless visitors accept non-essential cookies. Consent obtained under such conditions is unlikely to satisfy the nFADP’s requirement that consent be given voluntarily and without coercion.
The nFADP does not specify a fixed validity period for consent. Best practice is to refresh consent whenever the cookie policy or vendor list undergoes a material change, or at least annually, and to document each version change in the consent log.
Third-party trackers, such as ad-network pixels or social-media embeds, are classified as non-essential. You must disclose them, obtain explicit consent before they load, and ensure your contracts with tracker vendors include obligations on purpose limitation, revocation compliance, and data-transfer safeguards.
mas dpt licence singapore
By Jonathon Richards

posted 20 minutes ago

sfc vasp licence hong kong
By Jonathon Richards

posted 4 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Is Cookie Consent Required in Switzerland? Nfadp, FDPIC (EDÖB) Rules & What Businesses Must Do

Send welcome message

Custom Message