When are customer data relevant under data protection law?
Customer data are relevant under data protection law as soon as they relate to an identified or identifiable natural person. This applies not only to sensitive information, but also to ordinary contact and contract data.
The DPA understands personal data very broadly. It covers all information relating to an identified or identifiable natural person (Art. 5 lit. a DSG). The concept of processing is equally broad. It includes, among other things, the collection, storage, retention, use, modification, disclosure, archiving, erasure or destruction of data (Art. 5 lit. d DSG).
For an SME, this means: Anyone who stores customer data in an Excel list, manages it in a CRM, transfers it to accounting software, uses it in a newsletter tool or makes it accessible to a shipping service provider is processing personal data. This does not require complex profiling or artificial intelligence. Ordinary customer administration is already sufficient.
Not all data are equally sensitive. Particularly sensitive data include, for example, health data, biometric data, data on religious or political views, data on criminal prosecutions or data on social assistance measures (Art. 5 lit. c DSG). A hair salon, a doctor's practice, a fitness studio, an insurance broker or a provider in the health and social sector must therefore carefully examine which customer data are collected and how they are protected.
What are the basic rules when handling customer data?
A Swiss SME may only process customer data lawfully, in good faith, proportionally and for a specific purpose. Furthermore, data may not be kept longer than necessary for the purpose.
The core principles are set out in Art. 6 DSG. For the everyday life of an SME, they can be easily translated.
First, every processing operation requires a factual purpose. A company may only collect customer data for a specific and recognizable purpose for the data subject (Art. 6 Abs. 3 DSG). Anyone who collects a delivery address for sending an order may not simply use this for completely different purposes. The further a new purpose deviates from the original purpose, the more likely it is that new information must be provided or a justification must be examined.
Secondly, the principle of proportionality applies. An SME should only collect those customer data that are necessary for the respective purpose (Art. 6 Abs. 2 DSG). An online shop typically requires a name, address and contact details for a delivery. Asking for date of birth, civil status or hobbies is only useful if there is a concrete, recognizable and proportionate purpose for it. Data protection therefore does not start with the privacy policy, but already with the question of which fields a form actually contains.
Thirdly, personal data must be destroyed or anonymized as soon as they are no longer required for the purpose of processing (Art. 6 Abs. 4 DSG). This does not mean that every customer file must be deleted immediately after the end of the contract. Statutory retention obligations, for example in accounting, can justify longer storage. But collecting data on stock and storing them indefinitely does not fit with the DPA.
Fourthly, customer data must be correct. Anyone who processes personal data must ensure its accuracy and take appropriate measures so that incorrect or incomplete data are corrected, deleted or destroyed (Art. 6 Abs. 5 DSG). In practice, this means, for example, that address changes should be updated in the relevant systems.
Is consent always required for customer data?
No. Under Swiss data protection law, consent is not required for every processing of customer data. However, if consent is necessary, it must be voluntary, informed and given for specific processing activities.
This is a common misconception. The DPA does not function in the same way as the EU General Data Protection Regulation (GDPR). Under Swiss law, a private company does not need separate consent for every permissible data processing operation. Rather, the decisive factor is that the processing does not unlawfully violate the personality of the data subject and that the statutory principles are observed (Art. 30 Abs. 1 DSG, Art. 30 Abs. 2 DSG).
However, consent may become necessary if processing would otherwise constitute a violation of personality or if the law requires it for specific constellations. If consent is required, it is only valid if it is given voluntarily for one or more specific processing operations after appropriate information (Art. 6 Abs. 6 DSG). For sensitive personal data or high-risk profiling, any required consent must be express (Art. 6 Abs. 7 DSG).
For SMEs, the practical consequence is clear. It is usually more important to provide transparent information, collect data sparingly and create secure processes than to install a blanket "I agree" checkbox everywhere. However, if a company relies on consent for newsletters, personalized advertising, particularly sensitive data or unusual uses, the text should be specific.
What belongs in a privacy policy?
A privacy policy must at least explain who is responsible, for what purposes customer data are processed and to whom they may be shared, if applicable. Additional information must be provided for disclosures abroad.
The duty to provide information is one of the most important obligations for Swiss SMEs. The controller must adequately inform the data subject about the collection of personal data, even if the data are not collected directly from them (Art. 19 Abs. 1 DSG). This obligation applies in principle to every collection of personal data, not only to particularly sensitive data.
At least the identity and contact details of the controller, the purpose of processing and, if applicable, the recipients or categories of recipients must be communicated (Art. 19 Abs. 2 DSG). If data are not collected from the data subject, the categories of personal data processed must also be specified (Art. 19 Abs. 3 DSG). If personal data are disclosed abroad, the country or international body must also be named, if applicable with the guarantees or exceptions (Art. 19 Abs. 4 DSG).
For an SME, the privacy policy should therefore not simply be a copied template. It must match the actual data processing. A small craft business needs different information than an online shop with tracking, newsletter tool, payment service provider and external logistics. It is important that the information is understandable, easily accessible and not unnecessarily complicated. On the web, a clearly visible privacy policy in the footer of the website is usually a sensible standard.
Anyone who willfully violates the duty to provide information risks a fine of up to CHF 250,000 (Art. 60 Abs. 1 DSG). This shows that transparency regarding Kundendaten Datenschutz Schweiz should not be treated as a mere formality.
What applies to Cloud, CRM, newsletter tools and other service providers?
Anyone who has customer data processed by external service providers remains responsible. The SME must check whether the service provider only processes the data as permitted and can ensure adequate data security.
Many SMEs outsource parts of their data processing. Typical examples are hosting, cloud storage, accounting software, CRM systems, newsletter tools, external IT support, payment service providers or shipping partners. Under data protection law, this often constitutes processor processing. According to Art. 9 DSG, this is permissible if the data are processed in the same way as the controller themselves would be allowed to do, and no statutory or contractual obligation of secrecy prevents it (Art. 9 Abs. 1 DSG).
In particular, the controller must ensure that the processor is able to guarantee data security (Art. 9 Abs. 2 DSG). In practice, a written processing agreement is recommended. This should regulate, among other things, the purpose and scope of processing, rights of direction, technical and organizational measures, sub-processors, notification obligations in the event of security incidents and deletion or return after the end of the contract.
Special attention is required when service providers process data abroad. Personal data may be disclosed abroad if adequate protection is guaranteed there (Art. 16 Abs. 1 DSG). In the absence of such a decision, appropriate safeguards are required, such as recognized standard data protection clauses (Art. 16 Abs. 2 DSG). For SMEs, this means that with international cloud or marketing tools, it is worth taking a close look at the provider's contractual documents and privacy notices.
How must customer data be protected?
Customer data must be protected through appropriate technical and organizational measures. The measures depend on the risk, the nature of the data, the purpose, scope and circumstances of the processing.
Data security is not just an IT matter, but a legal obligation. Controllers and processors must ensure data security appropriate to the risk (Art. 8 Abs. 1 DSG). The measures must contribute to preventing data security breaches (Art. 8 Abs. 2 DSG).
The Data Protection Ordinance specifies this risk-based approach. Controllers and processors must determine the protection requirements of the personal data and define suitable technical and organizational measures (Art. 1 Abs. 1 DSV). In doing so, the nature of the data, the purpose, type, scope and circumstances of processing, among other things, are taken into account (Art. 1 Abs. 2 DSV). The state of the art and implementation costs may also be considered (Art. 1 Abs. 4 DSV).
For an SME, the measures do not have to look the same as for a large corporation. But certain basics should be in place. These include strong passwords, two-factor authentication for important systems, role-based access, regular updates, backups, encrypted devices, clear responsibilities, staff training and a simple emergency process for data breaches.
If a data security breach occurs, the controller must report the breach to the FDPIC as quickly as possible if the breach is likely to result in a high risk to the personality or fundamental rights of the data subject (Art. 24 Abs. 1 DSG). The processor must report a breach to the controller as quickly as possible (Art. 24 Abs. 3 DSG). The report to the FDPIC must include, as far as possible, the nature, timing, affected data, affected persons, consequences, risks and measures (Art. 15 Abs. 1 DSV).
Do SMEs have to keep a record of processing activities?
Not every SME has to keep a record of processing activities. Companies with fewer than 250 employees are exempt from this requirement, provided they do not process sensitive personal data on a large scale and do not carry out high-risk profiling.
In principle, the DPA provides that controllers and processors must keep a record of their processing activities (Art. 12 Abs. 1 DSG). This record contains, among other things, identity, purpose of processing, categories of data subjects, categories of personal data, recipients, retention period, data security measures and details of disclosures abroad (Art. 12 Abs. 2 DSG).
For many SMEs, however, there is an important relief. Companies and other private-law organizations with fewer than 250 employees are exempt from the obligation if they do not process sensitive personal data on a large scale and do not carry out high-risk profiling (Art. 24 DSV).
Nevertheless, a simple internal data inventory is often useful. It does not necessarily have to be a major legal document. Even an overview of which customer data are located where, who has access, which service providers are involved, how long data are kept and what to do in the event of an incident helps enormously. Data protection thereby becomes less abstract and more manageable in everyday life.
Frequently asked questions on data protection for customer data
Does the Swiss Data Protection Act also apply to small businesses?
Yes. The DPA also applies to small businesses as soon as they process personal data. The size of the company does not determine whether data protection obligations exist. However, it can play a role in individual obligations and the scope of required measures, such as the record of processing activities (Art. 24 DSV).
Is a privacy policy on the website sufficient?
A privacy policy on the website is often an important component, but is only sufficient if it correctly reflects the actual data processing operations and is easily accessible. If customer data are also collected offline, by telephone, via paper forms or at events, information must also be provided appropriately there (Art. 19 Abs. 1 DSG).
May an SME use customer data for newsletters?
This can be permissible if clients and customers have been adequately informed and the other legal requirements are met. Depending on the nature of the newsletter and the recipient group, additional requirements from unfair competition law may be relevant. Under data protection law, it is important that the purpose is clearly recognizable and that no unexpected or disproportionate use occurs (Art. 6 Abs. 2 DSG, Art. 6 Abs. 3 DSG).
What is the most important first step for SMEs?
The most important first step is an honest assessment. An SME should know what customer data it collects, what it uses it for, where it is stored, who has access, which service providers are involved and how long the data are kept. Only then can the privacy policy, contracts, deletion periods and security measures be sensibly adjusted.




