Marketing in Switzerland: what the revised Data Protection Act requires

Switzerland's revised Data Protection Act has applied since 1 September 2023. It resembles the GDPR in much, but differs clearly in three places — and most Swiss companies are subject to both at the same time anyway.

Two translucent frames overlap, the shared area glowing considerably brighter
Note This piece gives an overview and does not replace legal advice. Whether and to what extent these obligations apply to you depends on your offering, company size and markets, and should be assessed case by case — particularly for sensitive personal data, profiling, or transfers to third countries.

In short

  • The revised Act has applied since 1 September 2023 and has no transition period.
  • Three substantial differences from the GDPR: consent is not the default requirement, penalties fall on individuals rather than companies, and small businesses are generally exempt from the processing record.
  • Anyone with EU customers, or addressing people in the EU, is additionally subject to the GDPR — in practice the stricter standard then applies.
  • Six points have to be settled on a Swiss business website; the privacy notice is only one of them.

The three substantial differences from the GDPR

1. Processing is permitted in principle

The GDPR prohibits processing personal data unless a lawful basis exists. The revised Swiss Act reverses the starting point: processing is permissible as long as it does not unlawfully infringe personality rights.

In practice: the difference is smaller than it sounds. Transparency, purpose limitation, proportionality and data security apply here too. For sensitive personal data and for high-risk profiling, explicit consent is likewise required.

2. Penalties fall on individuals, not companies

The GDPR provides for fines against companies, calculated against turnover. The revised Swiss Act provides for fines of up to CHF 250,000 — against the responsible natural person, meaning management or the responsible manager.

In practice: the lower figure is often read as an all-clear. That is a misunderstanding: personal liability changes the accountability picture inside a business, and it applies to wilful omission too.

3. No processing record for small companies

Companies with fewer than 250 employees are exempt from the record of processing activities — provided the processing carries no high risk and no sensitive personal data is processed at scale.

In practice: the exemption falls away quickly. Anyone processing health data or running extensive profiling still needs the record — and it is in any case the most useful overview a business can have in-house.

Worth knowing

Most Swiss companies with a website are in practice subject to both regimes at once. The GDPR bites as soon as people in the EU are deliberately addressed — through prices in euros, a language version aimed at EU customers, or shipping into the EU.

That has a practical consequence: if you have to meet both, it makes sense to work to the stricter one. Running two separate processes for two regimes costs more than simply working to the higher standard.

Six points that have to be settled

PointWhat is requiredCommon mistake
Privacy noticeunderstandable, complete, naming every service provider in usenaming providers no longer used — or the reverse
Processing agreementsa contract with every provider processing data for youmissing for hosting, email sending and analytics
Transfers abroadcheck adequacy, otherwise standard contractual clausesUS services in use with no documented basis
Right of accessreply within 30 days, generally free of chargeno process defined — the deadline runs anyway
Data securityappropriate technical and organisational measuresno documentation of what was done
Breach notificationnotify the FDPIC where there is a high risknobody knows who notifies in an emergency

Email marketing: a separate regime

Email marketing in Switzerland is not governed by the Data Protection Act but by the Unfair Competition Act. Three conditions have to be met together:

  1. The recipient's consent, or an existing customer relationship for your own comparable products.
  2. Correct sender details with an address that is genuinely reachable.
  3. A reference to how to unsubscribe in every message, free of charge and without needing to log in.

A breach here carries criminal liability — and that too falls on the responsible person. Anyone also writing to EU recipients is additionally subject to the stricter requirements for demonstrable consent; the Swiss exception for existing customer relationships is drawn more narrowly there.

From practice

The most common finding in a review is always the same: the privacy notice names services the company no longer uses — and fails to name others that have long been in place. An analytics tool was swapped, an email provider changed, a delivery network introduced.

This is not a formality: a notice naming an unused service is just as wrong as one concealing a used one. A fixed annual date to check the list of providers against the notice removes by far the most common defect.

Services from the US and other third countries

The point that snags most often in practice — because nearly every marketing tool is affected.

Switzerland maintains a list of states with an adequate level of protection. For the US, a framework has existed since 2024 permitting transfers to certified recipients. Two things have to be checked:

  • Is this particular provider certified? The framework does not apply blanket to all US companies, only to those that have obtained certification. That is verifiable in the public register.
  • If not: standard contractual clauses plus your own risk assessment. The clauses alone are not sufficient; an assessment is needed of whether equivalent protection is actually achievable in the destination country.
Tip Keep a simple list of every service that processes personal data: provider, purpose, server location, basis for the transfer, date last reviewed. That list answers most questions in an audit within minutes — and it is the foundation for the processing record, should you need one.
Prompt
Help me check our data protection documentation for gaps.
We are a Swiss company.

Our situation:
- Employees: [number]
- Do we have EU customers or address people in the EU? [yes/no]
- Services that process personal data: [list with purpose and
  server location, where known]
- What we already have: [privacy notice / processing agreements /
  processing record / none of these]

Tasks:
1. For each service, name the basis the transfer abroad requires
   and what we must have on file for it.
2. Based on my details, check whether we have to keep a record of
   processing activities. Justify it.
3. Name the details likely missing from our privacy notice.
4. List the points where the GDPR additionally applies, and what
   is stricter there.
5. Mark everything that must be assessed by a legal professional.

Do not invent statutory articles or deadlines. Where you are not
certain of a detail, mark it as to be checked.

In closing

The revised Act is less strict than the GDPR and still no reason to relax — mainly because liability is personal and because most Swiss companies are subject to both regimes anyway.

In practice that leads to a simple recommendation: work to the stricter standard, keep a maintained list of all service providers, and check once a year whether the privacy notice still describes what is actually in use. That covers most of what an audit actually turns up.

Common questions

Does the GDPR apply to Swiss companies?

Yes, as soon as people in the EU are deliberately addressed — through prices in euros, shipping into the EU, or a language version aimed at EU customers — or where their behaviour is monitored. Both regimes then apply at once, and in practice it is simpler to work to the stricter standard.

What is the most important difference between the revised Swiss Act and the GDPR?

The starting point: the GDPR prohibits processing unless a lawful basis exists; the revised Swiss Act permits it as long as personality rights are not unlawfully infringed. More relevant in practice are two other differences — fines of up to CHF 250,000 fall on the responsible natural person, and small companies are conditionally exempt from the processing record.

Does a small Swiss company need a processing record?

Companies with fewer than 250 employees are exempt, provided the processing carries no high risk and no sensitive personal data is processed at scale. The exemption falls away quickly — with extensive profiling, for instance. Regardless of that, a list of the services in use is the most useful overview a business can have.

Can a Swiss company use US services?

Yes, under conditions. What has to be checked is whether the particular provider is certified under the framework in place since 2024 — this does not apply blanket to all US companies. If not, standard contractual clauses are needed plus your own assessment of whether equivalent protection is actually achievable in the destination country.

What rules apply to email marketing in Switzerland?

Not the Data Protection Act but the Unfair Competition Act. Three things are required together: consent or an existing customer relationship for your own comparable products, correct and reachable sender details, and a free unsubscribe reference in every message. For EU recipients, the stricter requirements for demonstrable consent apply as well.

Marketing that sets itself up

The Studio Engine beta is live. Claim your spot and help shape it from the start.

Join the beta →
← Back to overview