[codicts-css-switcher id=”346″]

Global Law Experts Logo
privacy policy switzerland

Our Expert in Switzerland

  • GOLD

Are Privacy Policies Required in Switzerland (2026)? FADP Privacy Notice Checklist

By Global Law Experts
– posted 1 hour ago

Privacy policy Switzerland rules are catching out more businesses than ever in 2026, as the revised Federal Act on Data Protection (FADP) moves from a transition mindset into active application. If you run a website or app that touches personal data, even basic contact forms, you need to understand what the law expects you to publish and when. This guide gives a direct answer, a side-by-side FADP versus GDPR comparison, copy-paste notice snippets, and a decision framework so you can act today. It is written for Swiss SMEs, website and app owners, in-house counsel and data protection advisers who want practical compliance, not abstract theory.

What this page covers: whether Swiss businesses must publish a privacy policy under the revised FADP (in force since 1 September 2023), the minimum clauses required, copy-paste notice snippets for websites and apps, cookie and transfer disclosure, and when the EU GDPR also applies. For broader context, see our Data Privacy, Switzerland practice-area page.

The guidance below is practical compliance information, not legal advice. For complex cross-border transfers or high-risk processing, consult Swiss-qualified counsel.

TL;DR: Do Swiss businesses need a privacy policy?

Yes. The FADP is built on a transparency principle: the revised Act introduced a general duty to inform data subjects whenever personal data is collected. In practice, that means any business collecting personal data through a website, app, online shop or contact form should publish a privacy notice. The Federal Data Protection and Information Commissioner (FDPIC) expects clear, accessible information at the point of collection.

The question is not whether to publish, but how detailed the notice must be. A micro-business processing only basic administrative data needs far less than a company running analytics, profiling and international transfers. Two factors drive the length: the categories of data you process and where that data goes.

When a short notice is sufficient (SMEs, limited processing)

If you are a small operation collecting only names, email addresses and perhaps order details, with no tracking, no profiling and no transfers abroad, a concise notice is defensible. It still must cover the essentials: who you are (the controller’s identity and contact details), the purpose of collection, and how people can exercise their rights. Where data is transferred abroad, the destination and safeguard must also be disclosed.

Example short notice (not legal advice): “We collect your name, email and order details only to process your purchase and comply with accounting law. We do not share your data with third parties for marketing. To access, correct or delete your data, email privacy@example.ch.”

When a full policy is needed

A fuller privacy policy becomes advisable the moment any of the following apply:

  • Tracking or analytics. You use cookies, pixels or SDKs that profile behaviour.
  • Profiling or automated decisions. You score, segment or target users automatically.
  • International transfers. You use cloud, payment or marketing providers outside Switzerland.
  • HR processing. You handle employee data, which can be extensive and may include sensitive data.
  • EU-facing activity. You market to or monitor people in the EU, which may trigger the GDPR as well.

Minimum content required by the FADP for your privacy policy in Switzerland

The FADP is less prescriptive than the GDPR in how it frames obligations, but the revised Act’s duty to inform still requires core elements of transparency. You must tell data subjects, at minimum, the controller’s identity and contact details, the purpose of processing, and, where applicable, the recipients of the data. For disclosures of personal data abroad, you must state the destination country and, where there is no adequate level of protection, the safeguard relied upon. Where you collect data from the data subject, you must inform them of the categories of recipients. The FDPIC’s guidance treats clarity and accessibility as essential.

The table below maps the Swiss minimum against the GDPR equivalent and gives a practical recommendation for Swiss SMEs.

Where the FADP is quieter than the GDPR, the gap is usually about formality rather than substance. The FADP does not require you to label a “lawful basis” for every purpose in the way the GDPR does, but it still demands that processing comply with the principles of lawfulness, good faith and proportionality. If you target EU users, you must layer the GDPR requirements on top. Build your privacy policy in Switzerland to satisfy both regimes where your audience spans the border.

Dimension / Clause FADP (Switzerland, 2026), Minimum required GDPR (EU), Minimum required Practical recommendation for Swiss SMEs
Identity / contact of controller Required: identity and contact details of the controller. Required: controller and (where applicable) DPO contact details. Include company name, postal address, email, and a contact point for data requests.
Purpose of processing Required: the purpose of processing. Required: purposes plus lawful basis for each. State purposes plainly (“to deliver orders, send marketing, prevent fraud”); add lawful basis if you target EU users.
Categories of personal data Where data is not obtained from the data subject, the categories processed must be disclosed; good practice to describe categories generally. Required: categories with specifics. List categories with examples: name, email, IP address, cookie identifiers, payment data.
Recipients / onward transfers Required: categories of recipients; and, for disclosures abroad, the destination country and safeguard where protection is not adequate. Required: recipients and transfers, with safeguards specified. Disclose transfers (“some data is processed by US providers under SCCs or the Swiss–US Data Privacy Framework”) and name the mechanism.
Data retention period Not an explicit information-duty item, but the proportionality principle limits retention; good practice to state it. Required: retention period or criteria. Give concrete timeframes (e.g. ten years for accounting records; shorter for marketing data) or clear criteria.
Data subject rights Rights (including access, correction, deletion) are guaranteed by law; good practice to explain how to exercise them. Required to inform of the rights, plus the right to complain to the supervisory authority. Set out a simple process and note the FDPIC’s role.
Lawful basis Not framed as a discrete clause; FADP requires lawful, good-faith, proportionate processing. Required: a lawful basis for each processing activity. For EU-facing processing, state the basis (consent, contract, legitimate interest).
Automated decisions / profiling Required: inform of automated individual decisions producing legal effects or significant impact; data subject may request human review. Required: disclose, with additional safeguards for solely automated decisions. Disclose relevant automated decisions, describe mitigations, and offer human review where decisions have major impact.
Cookies and tracking Transparency on tracking; consent issues are shaped by the FADP’s transparency/proportionality rules and overlap with EU practice. ePrivacy plus GDPR require consent for non-essential cookies. Deploy a cookie banner, list cookie types, and obtain consent for marketing and analytics cookies.
Supervisory authority No statutory duty to name it; good practice to mention the FDPIC. Required: inform of the right to lodge a complaint with a supervisory authority. Add FDPIC contact details and, for EU-facing processing, the relevant EU authority.

Treat the “practical recommendation” column as your drafting checklist. Each row maps to a section of a well-structured notice, and the FDPIC guidance together with the FADP text on Fedlex supports the requirements listed.

Cookies, trackers and consent: what to disclose in 2026

Cookie and tracking transparency attracts particular attention. The FDPIC has indicated, through its guidance and public commentary, that opaque tracking and dark-pattern consent banners raise concerns. For 2026, a prudent posture is to treat non-essential cookies as requiring informed, freely given consent, mirroring EU practice even where Swiss law is less explicit, because much Swiss web traffic overlaps with EU users and because the direction of travel is clear.

Draw a bright line between two categories. Strictly necessary cookies, session management, security, load balancing, should be labelled accordingly. Analytics, advertising and social-media tracking cookies should, as good practice, be set only after the user actively agrees. Pre-ticked boxes and “consent-or-leave” walls invite complaints.

Short cookie banner example

Example banner text (not legal advice): “We use cookies to run this site and, with your consent, to measure traffic and show relevant content. You can accept all, reject non-essential cookies, or manage your preferences.” Provide three clear buttons: Accept all, Reject non-essential, and Manage preferences, each visually equal in weight.

Analytics without consent (pseudonymisation and aggregation caveats)

Some businesses ask whether they can run analytics without a consent prompt. This is only defensible if the processing is genuinely privacy-preserving: IP addresses truncated or anonymised, no cross-site tracking, no persistent identifiers, and data aggregated so individuals cannot be singled out. The moment analytics builds a profile or feeds advertising, consent is the safer course. When in doubt, obtain consent, it is cheaper than defending a tracking complaint. A well-drafted privacy policy in Switzerland should state exactly which analytics tools you use and on what basis.

Cross-border transfers and transfer wording

Under the FADP, you may disclose personal data abroad only where the destination state is recognised by the Federal Council as providing adequate protection, or where appropriate safeguards are in place. For countries without a recognised adequate level of protection, you must rely on a mechanism such as the Standard Contractual Clauses recognised by the FDPIC, binding corporate rules, or another lawful safeguard. For US recipients that are certified under the Swiss–US Data Privacy Framework (recognised by the Federal Council as providing adequate protection), transfers may rely on that framework. Your privacy policy in Switzerland should disclose that transfers occur, name the destination, and identify the safeguard where protection is not adequate.

Most SMEs transfer data without realising it, the moment you use a US-based cloud host, email platform, payment processor or analytics tool, data leaves Switzerland. Map these providers first, then document the safeguard for each.

Template transfer wording, US processors and cloud providers

Example clause (not legal advice): “Some of your personal data is processed by service providers located in the United States and other countries, including our hosting, email and payment partners. Where these countries do not provide a level of data protection recognised as adequate, we rely on Standard Contractual Clauses and, where applicable, the Swiss–US Data Privacy Framework to safeguard your data. You may request a copy of the relevant safeguards by contacting privacy@example.ch.”

When to include a transfer impact assessment note

For transfers to higher-risk jurisdictions, or where the recipient is subject to broad government access laws, a transfer impact assessment can strengthen your position. You do not need to publish it, but you should note internally that one has been completed and be ready to provide safeguard details on request. Keep the assessment on file in case the FDPIC asks.

When GDPR also applies to your privacy policy in Switzerland

Switzerland is not an EU member and is not automatically subject to the GDPR. But the GDPR can reach across the border in two situations: when you offer goods or services to people in the EU, or when you monitor the behaviour of people in the EU. Either test, met, can pull your processing into GDPR scope alongside the FADP. Regulation (EU) 2016/679 sets out these triggers in its territorial-scope provisions (Article 3).

When both regimes apply, build your notice to the higher standard. That means explicit lawful bases, GDPR data-subject rights including the right to lodge a complaint with an EU supervisory authority, and, in many cases, an EU representative under Article 27.

Example: a Swiss online shop selling to EU consumers

A Zurich-based shop that ships to Germany and France, prices in euros and advertises to EU audiences is likely offering goods to EU residents. Its notice should therefore state the lawful basis for each purpose (contract for order fulfilment, consent for marketing, legitimate interest for fraud prevention), list the full set of GDPR rights, and reference both the FDPIC and the relevant EU supervisory authority. The same shop selling only within Switzerland would generally not need the GDPR layer.

Practical checklist and templates

Use this checklist to build or audit your privacy policy in Switzerland. Work top to bottom; each item maps to a row in the comparison table above.

  • Publish a notice that is easy to find, linked in your website footer and shown at data collection.
  • Name the controller with company name, address, email and a contact point for data requests.
  • State every purpose in plain language; add lawful basis if you target EU users.
  • List data categories with concrete examples.
  • Disclose recipients and transfers, naming destination countries and safeguards.
  • Set retention periods or the criteria that determine them.
  • Explain rights and the step-by-step process to exercise them.
  • Deploy a cookie banner with genuine accept/reject/manage options.
  • Name the FDPIC and, for EU-facing processing, the relevant EU authority.
  • Date the policy and review it whenever your processing changes.

Full privacy policy skeleton (example outline):

  1. Who we are (controller identity and contact)
  2. What data we collect and why (purposes and categories)
  3. Legal basis (for EU-facing processing)
  4. Cookies and tracking
  5. Who we share data with (recipients and international transfers)
  6. How long we keep data (retention)
  7. Your rights and how to exercise them
  8. Complaints (FDPIC and, if relevant, EU authority)
  9. Changes to this notice and last updated date

For a ready-to-adapt document, see our privacy policy template (Switzerland) in the data privacy cluster.

Decision framework: full policy or short notice?

Do not agonise over this choice, the answer follows directly from what you process. Take a position using the paired lists below.

Choose A, publish a full FADP-compliant privacy policy now, when any of these are true:

  • You process personal data beyond basic contact and payment details (profiling, analytics, marketing).
  • You operate cookies, pixels or tracking SDKs.
  • You transfer data to providers outside Switzerland.
  • You target or monitor EU customers.
  • You process employee or sensitive personal data.

Choose B, a short notice with minimal disclosure, only when all of these are true:

  • You are a micro-business processing only basic administrative data.
  • You run no tracking, profiling or analytics.
  • You make no international transfers.
  • You maintain a working contact point for data-subject requests.

Our recommendation: most businesses fall into Option A. If you are unsure which column you sit in, default to the fuller policy, the incremental effort is small and the exposure of under-disclosure is real. Two implementation quick wins settle most edge cases: if any tracking is present, publish a fuller policy plus cookie consent; if any transfers to US processors exist, add a transfer clause referencing your SCC or Data Privacy Framework safeguards.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Alexandros Manousakis at Privintelligent Solutions, a member of the Global Law Experts network.

Next steps, risk focus and recommended resources

Work in priority order to close your biggest gaps first:

  1. Inventory the personal data you hold and the systems that touch it.
  2. Map transfers, list every provider and where it sits.
  3. Fix cookie tech, install a consent manager that blocks non-essential cookies until consent.
  4. Publish the notice, align it to the checklist above.
  5. Train staff, ensure your team can handle access and deletion requests.

Compliance risk is concentrated in tracking and transfer transparency, so prioritise those. If you need specialist support, browse the Global Law Experts, Switzerland data privacy lawyers directory. For official guidance and the complaint process, consult the FDPIC directly.

Sources

  1. Swiss Federal Data Protection and Information Commissioner (FDPIC)
  2. Fedlex, Swiss law portal (official)
  3. Federal Act on Data Protection (FADP), Fedlex
  4. EUR-Lex, GDPR text (Regulation (EU) 2016/679)
  5. European Data Protection Board (EDPB), guidance

FAQs

Is it a legal requirement to have a privacy policy in Switzerland?
Effectively, yes, for most organisations. The revised FADP introduced a general duty to inform people when their personal data is collected. Publishing a clear privacy notice is the standard way to meet this duty on a website or app. The level of detail depends on your processing, more data, tracking or transfers means a fuller policy.
Not automatically. The GDPR applies where you offer goods or services to people in the EU or monitor their behaviour. In those cases you must comply with both the GDPR and the FADP, and build your notice to the higher standard.
At minimum: the controller’s identity and contact details, the purpose of processing, and the categories of recipients. For disclosures abroad, state the destination country and the safeguard where protection is not adequate. As good practice, also cover data categories, retention, data-subject rights, cookie and tracking information, and how to contact the FDPIC. Use the checklist above as your drafting guide.
Swiss law does not contain a cookie-consent rule identical to the EU’s, but transparency is required and, for non-essential cookies, obtaining informed consent is the recommended and increasingly expected practice, particularly where your audience overlaps with the EU. Strictly necessary cookies generally do not require consent. Use a banner that genuinely lets users reject non-essential cookies.
The FADP does not mandate a statutory qualification. The Act allows (but does not generally require) private controllers to appoint a data protection adviser; where appointed, they should have the necessary expertise and sufficient independence. Recognised training and certifications such as CIPM, CIPP/E or other IAPP credentials are useful evidence of competence.
The FADP’s proportionality principle requires you to limit retention to what is necessary for the stated purpose. State retention periods or the criteria that set them in your notice, and follow sectoral rules, for example, business records are generally kept for ten years under Swiss commercial law.
The Federal Data Protection and Information Commissioner (FDPIC). Including its contact details and a note on how to raise concerns is good practice in your privacy policy in Switzerland.
Data Privacy Day, known in Europe as Data Protection Day, falls on 28 January each year, including in 2026. It marks the anniversary of the opening of Convention 108 for signature and is a useful annual prompt to review your notice.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Are Privacy Policies Required in Switzerland (2026)? FADP Privacy Notice Checklist

Send welcome message

Custom Message