ArticlesData and security

Swiss FADP: what your website must show

The revised Federal Act on Data Protection has been in force since 1 September 2023. For a company website, it comes down to a few concrete obligations. Here they are, without the jargon.

Topic
Data and security
Published on
Reading time
3 min

The duty to inform

As soon as your website collects personal data, you must inform the person concerned (Art. 19 FADP). A contact form, a newsletter sign-up, audience measurement or even the server logs are enough to trigger this duty.

The information is usually given in a privacy policy that can be reached from every page. At the very least, it must state:

  • the identity and contact details of the controller;
  • the purpose of the processing: why you collect each piece of data;
  • the recipients or categories of recipients, such as your hosting provider or your email service;
  • where applicable, the foreign countries the data is sent to, with the safeguards in place.

A privacy policy copied from another website is almost always wrong. It has to describe your actual tools and data flows: that’s the first thing checked when a complaint comes in.

Cookies

Swiss law does not require an EU-style prior consent banner. The Telecommunications Act does require that visitors be informed of the cookies stored on their device and of their purpose. They must also know that they can refuse them (Art. 45c TCA).

If your website also targets visitors from the European Union, the GDPR may apply and prior consent along with it. That’s why many Swiss websites show a banner that stores nothing until the visitor agrees: it’s the easiest choice to defend.

Data sent abroad

An analytics tool, a font hosted by a third party or an email service can transfer data outside Switzerland. This is allowed to countries whose level of protection the Federal Council considers adequate. They are listed in Annex 1 of the Data Protection Ordinance. For all other countries, you need safeguards such as standard contractual clauses (Art. 16 FADP).

If there is a breach

A data security breach that is likely to result in a high risk for the people concerned must be reported to the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible (Art. 24 FADP). A hacked website whose contact database has leaked is one such case.

Penalties

The Act provides for fines of up to CHF 250,000. When the breach is intentional, they target the responsible individuals, not just the company. Deliberately false or incomplete information is one such breach (Art. 60 FADP).

The checklist

  1. 01List everything your website collects: forms, audience measurement, server logs, newsletter.
  2. 02For each tool, note who provides it and where it stores the data.
  3. 03Write or update your privacy policy based on that list. Then date it.
  4. 04Check that the website stores no non-essential cookies before the visitor agrees.
  5. 05Decide who to call and what to do on the day a breach happens.

On our own websites, audience measurement is anonymous and sets no cookies. Our legal pages describe every data flow, one by one.

Read next

A question about your project?

Write to us: we answer in writing, with a scope and an estimate.

Write to us