Our Expert in Switzerland
No results available
Privacy policy Switzerland rules are catching out more businesses than ever in 2026, as the revised Federal Act on Data Protection (FADP) moves from a transition mindset into active application. If you run a website or app that touches personal data, even basic contact forms, you need to understand what the law expects you to publish and when. This guide gives a direct answer, a side-by-side FADP versus GDPR comparison, copy-paste notice snippets, and a decision framework so you can act today. It is written for Swiss SMEs, website and app owners, in-house counsel and data protection advisers who want practical compliance, not abstract theory.
What this page covers: whether Swiss businesses must publish a privacy policy under the revised FADP (in force since 1 September 2023), the minimum clauses required, copy-paste notice snippets for websites and apps, cookie and transfer disclosure, and when the EU GDPR also applies. For broader context, see our Data Privacy, Switzerland practice-area page.
The guidance below is practical compliance information, not legal advice. For complex cross-border transfers or high-risk processing, consult Swiss-qualified counsel.
Yes. The FADP is built on a transparency principle: the revised Act introduced a general duty to inform data subjects whenever personal data is collected. In practice, that means any business collecting personal data through a website, app, online shop or contact form should publish a privacy notice. The Federal Data Protection and Information Commissioner (FDPIC) expects clear, accessible information at the point of collection.
The question is not whether to publish, but how detailed the notice must be. A micro-business processing only basic administrative data needs far less than a company running analytics, profiling and international transfers. Two factors drive the length: the categories of data you process and where that data goes.
If you are a small operation collecting only names, email addresses and perhaps order details, with no tracking, no profiling and no transfers abroad, a concise notice is defensible. It still must cover the essentials: who you are (the controller’s identity and contact details), the purpose of collection, and how people can exercise their rights. Where data is transferred abroad, the destination and safeguard must also be disclosed.
Example short notice (not legal advice): “We collect your name, email and order details only to process your purchase and comply with accounting law. We do not share your data with third parties for marketing. To access, correct or delete your data, email privacy@example.ch.”
A fuller privacy policy becomes advisable the moment any of the following apply:
The FADP is less prescriptive than the GDPR in how it frames obligations, but the revised Act’s duty to inform still requires core elements of transparency. You must tell data subjects, at minimum, the controller’s identity and contact details, the purpose of processing, and, where applicable, the recipients of the data. For disclosures of personal data abroad, you must state the destination country and, where there is no adequate level of protection, the safeguard relied upon. Where you collect data from the data subject, you must inform them of the categories of recipients. The FDPIC’s guidance treats clarity and accessibility as essential.
The table below maps the Swiss minimum against the GDPR equivalent and gives a practical recommendation for Swiss SMEs.
Where the FADP is quieter than the GDPR, the gap is usually about formality rather than substance. The FADP does not require you to label a “lawful basis” for every purpose in the way the GDPR does, but it still demands that processing comply with the principles of lawfulness, good faith and proportionality. If you target EU users, you must layer the GDPR requirements on top. Build your privacy policy in Switzerland to satisfy both regimes where your audience spans the border.
| Dimension / Clause | FADP (Switzerland, 2026), Minimum required | GDPR (EU), Minimum required | Practical recommendation for Swiss SMEs |
|---|---|---|---|
| Identity / contact of controller | Required: identity and contact details of the controller. | Required: controller and (where applicable) DPO contact details. | Include company name, postal address, email, and a contact point for data requests. |
| Purpose of processing | Required: the purpose of processing. | Required: purposes plus lawful basis for each. | State purposes plainly (“to deliver orders, send marketing, prevent fraud”); add lawful basis if you target EU users. |
| Categories of personal data | Where data is not obtained from the data subject, the categories processed must be disclosed; good practice to describe categories generally. | Required: categories with specifics. | List categories with examples: name, email, IP address, cookie identifiers, payment data. |
| Recipients / onward transfers | Required: categories of recipients; and, for disclosures abroad, the destination country and safeguard where protection is not adequate. | Required: recipients and transfers, with safeguards specified. | Disclose transfers (“some data is processed by US providers under SCCs or the Swiss–US Data Privacy Framework”) and name the mechanism. |
| Data retention period | Not an explicit information-duty item, but the proportionality principle limits retention; good practice to state it. | Required: retention period or criteria. | Give concrete timeframes (e.g. ten years for accounting records; shorter for marketing data) or clear criteria. |
| Data subject rights | Rights (including access, correction, deletion) are guaranteed by law; good practice to explain how to exercise them. | Required to inform of the rights, plus the right to complain to the supervisory authority. | Set out a simple process and note the FDPIC’s role. |
| Lawful basis | Not framed as a discrete clause; FADP requires lawful, good-faith, proportionate processing. | Required: a lawful basis for each processing activity. | For EU-facing processing, state the basis (consent, contract, legitimate interest). |
| Automated decisions / profiling | Required: inform of automated individual decisions producing legal effects or significant impact; data subject may request human review. | Required: disclose, with additional safeguards for solely automated decisions. | Disclose relevant automated decisions, describe mitigations, and offer human review where decisions have major impact. |
| Cookies and tracking | Transparency on tracking; consent issues are shaped by the FADP’s transparency/proportionality rules and overlap with EU practice. | ePrivacy plus GDPR require consent for non-essential cookies. | Deploy a cookie banner, list cookie types, and obtain consent for marketing and analytics cookies. |
| Supervisory authority | No statutory duty to name it; good practice to mention the FDPIC. | Required: inform of the right to lodge a complaint with a supervisory authority. | Add FDPIC contact details and, for EU-facing processing, the relevant EU authority. |
Treat the “practical recommendation” column as your drafting checklist. Each row maps to a section of a well-structured notice, and the FDPIC guidance together with the FADP text on Fedlex supports the requirements listed.
Cookie and tracking transparency attracts particular attention. The FDPIC has indicated, through its guidance and public commentary, that opaque tracking and dark-pattern consent banners raise concerns. For 2026, a prudent posture is to treat non-essential cookies as requiring informed, freely given consent, mirroring EU practice even where Swiss law is less explicit, because much Swiss web traffic overlaps with EU users and because the direction of travel is clear.
Draw a bright line between two categories. Strictly necessary cookies, session management, security, load balancing, should be labelled accordingly. Analytics, advertising and social-media tracking cookies should, as good practice, be set only after the user actively agrees. Pre-ticked boxes and “consent-or-leave” walls invite complaints.
Example banner text (not legal advice): “We use cookies to run this site and, with your consent, to measure traffic and show relevant content. You can accept all, reject non-essential cookies, or manage your preferences.” Provide three clear buttons: Accept all, Reject non-essential, and Manage preferences, each visually equal in weight.
Some businesses ask whether they can run analytics without a consent prompt. This is only defensible if the processing is genuinely privacy-preserving: IP addresses truncated or anonymised, no cross-site tracking, no persistent identifiers, and data aggregated so individuals cannot be singled out. The moment analytics builds a profile or feeds advertising, consent is the safer course. When in doubt, obtain consent, it is cheaper than defending a tracking complaint. A well-drafted privacy policy in Switzerland should state exactly which analytics tools you use and on what basis.
Under the FADP, you may disclose personal data abroad only where the destination state is recognised by the Federal Council as providing adequate protection, or where appropriate safeguards are in place. For countries without a recognised adequate level of protection, you must rely on a mechanism such as the Standard Contractual Clauses recognised by the FDPIC, binding corporate rules, or another lawful safeguard. For US recipients that are certified under the Swiss–US Data Privacy Framework (recognised by the Federal Council as providing adequate protection), transfers may rely on that framework. Your privacy policy in Switzerland should disclose that transfers occur, name the destination, and identify the safeguard where protection is not adequate.
Most SMEs transfer data without realising it, the moment you use a US-based cloud host, email platform, payment processor or analytics tool, data leaves Switzerland. Map these providers first, then document the safeguard for each.
Example clause (not legal advice): “Some of your personal data is processed by service providers located in the United States and other countries, including our hosting, email and payment partners. Where these countries do not provide a level of data protection recognised as adequate, we rely on Standard Contractual Clauses and, where applicable, the Swiss–US Data Privacy Framework to safeguard your data. You may request a copy of the relevant safeguards by contacting privacy@example.ch.”
For transfers to higher-risk jurisdictions, or where the recipient is subject to broad government access laws, a transfer impact assessment can strengthen your position. You do not need to publish it, but you should note internally that one has been completed and be ready to provide safeguard details on request. Keep the assessment on file in case the FDPIC asks.
Switzerland is not an EU member and is not automatically subject to the GDPR. But the GDPR can reach across the border in two situations: when you offer goods or services to people in the EU, or when you monitor the behaviour of people in the EU. Either test, met, can pull your processing into GDPR scope alongside the FADP. Regulation (EU) 2016/679 sets out these triggers in its territorial-scope provisions (Article 3).
When both regimes apply, build your notice to the higher standard. That means explicit lawful bases, GDPR data-subject rights including the right to lodge a complaint with an EU supervisory authority, and, in many cases, an EU representative under Article 27.
A Zurich-based shop that ships to Germany and France, prices in euros and advertises to EU audiences is likely offering goods to EU residents. Its notice should therefore state the lawful basis for each purpose (contract for order fulfilment, consent for marketing, legitimate interest for fraud prevention), list the full set of GDPR rights, and reference both the FDPIC and the relevant EU supervisory authority. The same shop selling only within Switzerland would generally not need the GDPR layer.
Use this checklist to build or audit your privacy policy in Switzerland. Work top to bottom; each item maps to a row in the comparison table above.
Full privacy policy skeleton (example outline):
For a ready-to-adapt document, see our privacy policy template (Switzerland) in the data privacy cluster.
Do not agonise over this choice, the answer follows directly from what you process. Take a position using the paired lists below.
Choose A, publish a full FADP-compliant privacy policy now, when any of these are true:
Choose B, a short notice with minimal disclosure, only when all of these are true:
Our recommendation: most businesses fall into Option A. If you are unsure which column you sit in, default to the fuller policy, the incremental effort is small and the exposure of under-disclosure is real. Two implementation quick wins settle most edge cases: if any tracking is present, publish a fuller policy plus cookie consent; if any transfers to US processors exist, add a transfer clause referencing your SCC or Data Privacy Framework safeguards.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Alexandros Manousakis at Privintelligent Solutions, a member of the Global Law Experts network.
Work in priority order to close your biggest gaps first:
Compliance risk is concentrated in tracking and transfer transparency, so prioritise those. If you need specialist support, browse the Global Law Experts, Switzerland data privacy lawyers directory. For official guidance and the complaint process, consult the FDPIC directly.
posted 52 seconds ago
posted 21 minutes ago
posted 43 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message