Company structure

Privacy Policy Switzerland: Duty, content and typical mistakes

When you need them, what belongs in them, and which pitfalls you should avoid.

5 Min. reading time
5 Min. reading time
5 Min. reading time
var(--variable-sqJBTWvyq)

Anyone who operates a website in Switzerland, collects customer data, sends newsletters, or uses online tools cannot avoid data protection. The privacy policy is particularly important in this context. It explains to visitors, customers, and business partners which personal data you process, why you do so, and what rights the data subjects have.

Is a privacy policy mandatory in Switzerland?

A privacy policy is always necessary in Switzerland when you obtain personal data and must inform the data subjects. This is the case for almost every business website, for example, when contact forms, newsletter registrations, web analysis, cookies, application forms, customer accounts or online shops are used.

The Swiss Federal Act on Data Protection requires that the controller informs the data subject appropriately about the collection of personal data (Art. 19 Abs. 1 DSG). The responsible party is the person or company that decides on the purpose and means of data processing (Art. 5 lit. j DSG). A privacy policy is therefore not a purely formal document, but the practical implementation of this duty to inform.

Personal data is all information relating to an identified or identifiable natural person (Art. 5 lit. a DSG). This includes not only name, address or e-mail address, but, depending on the situation, also IP addresses, customer histories, order data, application documents or tracking information. Swiss data protection law protects natural persons whose personal data is processed (Art. 1 DSG).

The form is also important. The information must be precise, transparent, easy to understand and easily accessible (Art. 13 DSV). For websites, this means in practice that the privacy policy should be easy to find, typically via a link in the footer. The EDÖB also recommends for Datenschutzerklärungen im Internet that they correspond to the data processing actually carried out and do not consist of general standard sentences.

What must a privacy policy contain?

A privacy policy in Switzerland must contain at least the information that data subjects need to exercise their rights and understand the data processing. The law explicitly names the identity and contact details of the controller, the purpose of processing, and, if applicable, the recipients or categories of recipients to whom personal data is disclosed (Art. 19 Abs. 2 DSG).

In practice, the policy should therefore first clearly state who is responsible for the data processing. This includes the company name, address and a contact option for data protection inquiries. After that, it should explain which categories of data are processed. In the case of a simple website, this can be access data, contact details and communication data. In the case of an online shop, order data, payment information and delivery details are added. In the case of applications, the resume, certificates and other application documents may be affected.

Equally important are the purposes of the processing. Personal data may only be obtained for a specific purpose that is recognizable to the data subject (Art. 6 Abs. 3 DSG). A good privacy policy therefore does not just explain that data is processed, but why. Typical purposes are answering inquiries, processing contracts, operating the website, marketing, newsletter dispatch, web analysis, security or compliance with legal obligations.

If data is passed on to third parties, this must also be transparently described. This applies, for example, to hosting providers, IT service providers, newsletter tools, payment service providers, CRM systems, accounting software or analysis and marketing services. If personal data is processed by processors, the controller remains responsible and must in particular ensure that the processor can guarantee data security (Art. 9 Abs. 2 DSG).

Retention must also not be forgotten. Personal data must be destroyed or anonymized as soon as it is no longer required for the purpose of processing (Art. 6 Abs. 4 DSG). A privacy policy does not always have to state an exact number of days for each type of data. However, it should explain the criteria used to determine the storage period, such as contract duration, statutory retention periods or legitimate documentation interests.

What applies to cookies, tracking and analysis tools?

Cookies and similar technologies are one of the most common reasons why a privacy policy in Switzerland is not properly implemented. Many websites use analysis tools, marketing pixels, embedded videos, maps, social media plugins or consent management tools. In doing so, personal data may be processed and partially passed on to third parties.

According to the Telecommunications Act, the processing of data on external devices by means of telecommunications transmission is permitted if users are informed about the processing and its purpose and are informed that they can object to the processing (Art. 45c lit. b FMG). In addition, the general rules of the Data Protection Act remain applicable, in particular the duty to inform under Art. 19 DSG and the principles under Art. 6 DSG.

For the privacy policy, this means that cookies and tracking should not be dealt with in a single flat-rate sentence. It should be explained in an understandable way which types of technologies are used, what they are used for, and how users can object or change their settings. Particularly sensitive are tools that analyze behavior across multiple websites, build marketing profiles or transfer data to providers abroad.

Consent is only valid under the DSG if it is given voluntarily for one or more specific processing operations after appropriate information (Art. 6 Abs. 6 DSG). For sensitive personal data, high-risk profiling by private individuals or profiling by federal bodies, consent must be explicit (Art. 6 Abs. 7 DSG). A privacy policy therefore does not replace every cookie banner and every consent. However, it forms the information basis for it.

What must be stated regarding cross-border data transfers?

Many digital services store or process data not only in Switzerland. Hosting, newsletter tools, cloud systems, web analysis, support tools and payment providers can transfer data abroad. As soon as personal data is disclosed abroad, the data subject must also be informed about the state or international body and, if applicable, about the guarantees or exceptions on which the transfer is based (Art. 19 Abs. 4 DSG).

The law generally permits disclosures abroad if the Federal Council has determined that the state or international body concerned guarantees adequate data protection (Art. 16 Abs. 1 DSG). In the absence of such an adequacy decision, appropriate guarantees are required, such as standard data protection clauses approved, issued or recognized by the EDÖB (Art. 16 Abs. 2 lit. d DSG). In certain cases, an exception may apply, such as in the case of explicit consent or if the disclosure is directly connected with the conclusion or performance of a contract (Art. 17 Abs. 1 DSG).

A common mistake is to name international tools but not explain where data can flow. Equally problematic is the general statement that data is processed "possibly worldwide" without concrete context. The privacy policy should name the most important recipient countries or groups of countries and explain in an understandable way how data protection is secured.

What rights must data subjects know?

A good privacy policy does not only show what a company does with data. It also explains what rights data subjects have and how they can exercise them. The right of access is particularly important. Any person can request information from the controller as to whether personal data concerning them is being processed (Art. 25 Abs. 1 DSG).

The information must contain the details required so that the data subject can assert their rights and transparent data processing is guaranteed (Art. 25 Abs. 2 DSG). This includes, among other things, the processed personal data, the purpose of processing, the storage duration or criteria for this, details on the origin of the data, recipients and, if applicable, information on automated individual decisions (Art. 25 Abs. 2 DSG).

If a decision is based exclusively on automated processing and has legal effects for the data subject or significantly affects them, they must be informed about it (Art. 21 Abs. 1 DSG). Upon request, the data subject can state their point of view and demand that a natural person reviews the decision (Art. 21 Abs. 2 DSG). This is relevant, for example, in the case of fully automated rejections, credit decisions or certain platform processes.

What typical mistakes should you avoid?

The biggest mistake is a privacy policy that does not match the actual data processing. Anyone who uses a generator and mentions all possible tools, even though they are not used at all, does not create transparency. Conversely, it is just as risky if important services are missing, such as a newsletter tool, a payment provider or an analysis service.

Another mistake is unclear language. The information must be understandable (Art. 13 DSV). Sentences like "We process data to the extent permitted by law" hardly help the data subjects. A concrete explanation of which data is used for which purpose is better.

Outdated privacy policies are also problematic. New tools, new marketing processes, a change of hosting provider or new data flows abroad can mean that the policy has to be adapted. Data protection is therefore not a one-off project, but part of the ongoing corporate organization.

Finally, the privacy policy should not be confused with consent. Many data processing activities can be based on a contract, statutory obligation or overriding interests (Art. 31 DSG). However, if consent is required, it must be given voluntarily, informatively and for specific processing operations (Art. 6 Abs. 6 DSG). A mere mention in the privacy policy is then not automatically sufficient.

How do you create a good privacy policy?

The best starting point is an honest inventory. You should first clarify which personal data you collect, through which channels it is received, which tools you use, who has access, where data is transferred to and how long it is stored. Only then should the text be formulated.

A good privacy policy in Switzerland is concrete, but not unnecessarily complicated. It names the responsible body, describes the data categories and purposes, explains recipients and processors, informs about transfers abroad, mentions cookies and tracking, describes the rights of data subjects and provides a contact address. It is easy to find, up-to-date and written in such a way that normal website visitors and customers can understand it.

Frequently asked questions about the privacy policy in Switzerland

Does every website need a privacy policy?

Almost every business website needs a privacy policy because contact forms, newsletters, web analysis, cookies or server log files can already concern personal data. The decisive factor is not the size of the company, but whether personal data is obtained and processed (Art. 19 Abs. 1 DSG).

Is a free generator enough?

A generator can help as a starting point, but does not replace checking the actual data processing operations. The privacy policy must fit your website, your tools, your data flows and your retention periods. General or incorrect standard texts do not create real transparency.

Does the privacy policy have to be in German?

The law requires understandable information (Art. 13 DSV). Which language is required therefore depends on your target audience. If your website is aimed at German-speaking customers in Switzerland, German is obvious. For multilingual offers, a multilingual privacy policy can make sense or be necessary.

Do I have to update the privacy policy regularly?

Yes, as soon as your data processing operations change significantly. New tools, new recipients, new tracking technologies, new transfers abroad or new purposes can make an adjustment necessary. A privacy policy should therefore be checked regularly and not only updated when a problem arises.

More articles

Discover more articles on this topic.

Reviews

Your satisfaction is our priority