# Cookie Banner Switzerland: DSG-Compliant Setup (Templates)

> Cookie banners for Swiss websites: how the TCA, FADP and UCA interact, when opt-in makes sense, three banner templates and common mistakes.

- Source: https://www.sidd.swiss/en/insights/cookie-banner-switzerland/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Cookies are treated differently in Switzerland than in the EU, a fact that regularly causes confusion in practice. While the EU enforces a strict opt-in regime through the ePrivacy directive and the GDPR, Switzerland operates an opt-out regime with transparency and objection duties under Art. 45c lit. b of the Telecommunications Act (TCA / FMG). On top of that, the DSG applies as soon as cookies process personal data, for example through IP tracking, advertising profiles or login sessions. And third, the Federal Act against Unfair Competition (UWG, in particular Art. 3 lit. o and Art. 31 lit. d) comes into play as soon as tracking cookies serve advertising purposes.

This article delivers:

- the legal layering in Switzerland: TCA, DSG, UWG;
- the distinction between strictly necessary, statistical, marketing and tracking cookies;
- when Swiss websites need de facto opt-in despite the opt-out regime (GDPR applicability);
- three concrete banner templates for pure CH, CH with EU nexus and high-risk constellations;
- the requirements of a consent management platform (CMP);
- common pitfalls such as "dark patterns" and pre-checked boxes;
- the link to the privacy policy as a consistency duty.

Anyone who copies a purely GDPR-configured banner from Germany formally satisfies Swiss law, but loses conversion performance because statistical cookies in Switzerland are not mandatorily opt-in. Conversely, a purely TCA-oriented banner for a Swiss website with a DE nexus produces a GDPR risk.

## Legal layering: TCA, DSG, UWG

**Art. 45c lit. b TCA** is the central norm. Processing of data on third-party end devices, which is exactly what cookies do, is permissible if users are informed of the processing and its purpose and are pointed to the option to object. This is an opt-out regime: active consent is not required, but transparency and an objection option are mandatory.

**FADP**: as soon as cookies concern personal data (typically IP addresses, device IDs, login sessions, personal profiles), Art. 19 DSG (duty to inform) and Art. 30 et seq. DSG (lawfulness) apply. The banner is a vehicle for the information under Art. 19 DSG, complemented by the privacy policy. With specially protected data (Art. 5 lit. c DSG) or high-risk profiling (Art. 22 DSG) the duty tightens, up to a DPIA obligation.

**UWG Art. 3 lit. o**: impermissible bulk mailing without a relationship, relevant for advertising e-mails and indirectly for tracking cookies that build a profiling basis for targeted advertising. The Federal Supreme Court has clarified in several rulings that indirect chains may fall under UWG.

The three layers in sum: *information mandatory, objection option mandatory, opt-in only mandatory in case of advertising EU nexus or specially protected data.*

## Cookie categorisation

A clean categorisation is the prerequisite for any banner configuration. The market standard is four categories:

1. **Strictly necessary cookies**: session management, shopping cart, CSRF token, security cookies (e.g. CAPTCHA state). Under TCA and DSG these cookies are permissible without consent because without them the website function is not ensured. The banner does not need to handle them as opt-in, but they should appear transparently in the cookie table of the privacy policy.
2. **Statistics / reach measurement**: anonymised or pseudonymised usage data, typically Matomo on-premise, privacy-friendly Google Analytics 4 with IP anonymisation. Under Swiss law (TCA + DSG) permissible without opt-in, but a low-barrier opt-out must be possible.
3. **Marketing / personalisation**: A/B testing, personalisation engines, CRM linking. Under Swiss law opt-out suffices; with a GDPR nexus opt-in is mandatory.
4. **Tracking / third-party advertising**: Meta Pixel, Google Ads Conversion, LinkedIn Insight, TikTok Pixel, programmatic advertising IDs. Here TCA, DSG, GDPR and UWG converge: opt-in is in practice always advisable because EU applicability can hardly be excluded.

A binary "Accept all" / "Necessary only" choice does not satisfy the transparency requirement of Art. 45c TCA, granular categorisation is the standard and FDPIC-expected.

## When does a Swiss website de facto need opt-in?

Four constellations in which a Swiss banner must de facto run opt-in:

1. **GDPR marketplace nexus under Art. 3(2) GDPR**: EU shipping, EU language variant with local pricing, targeted EU advertising. Details in [GDPR Switzerland checklist](https://www.sidd.swiss/einblicke/dsgvo-schweiz-checkliste). Tracking EU data subjects means ePrivacy applicability, which forces de facto opt-in for tracking cookies.
2. **Specially protected personal data** (Art. 5 lit. c DSG) as content of the cookies, rarely direct, but conceivable on health sites, religious communities, political platforms.
3. **High-risk profiling** under Art. 22 DSG based on cookie data, e.g. AI-supported personalisation with significant impact on users.
4. **Industry regulation**: for banks, insurers and healthcare, FINMA circulars and cantonal patient-data acts in practice require a more restrictive configuration than the TCA minimum.

For all other pure-CH configurations without special risk factors, opt-out with clear information and granular categorisation is the appropriate measure. A Swiss SME based in Zurich, selling in the DACH region only through Swiss sales channels, without EU advertising and without EU shipping, may exploit the lower Swiss protection level in the banner configuration, many do not and unnecessarily lose conversion.

## Three banner templates

**Template A, pure CH, low risk density**:

*"We use cookies and similar technologies to operate our website and to capture access statistically. Strictly necessary cookies are set without your consent; statistical cookies you can reject at any time or adjust under 'Settings'. Details in our privacy policy."* Buttons: "Confirm selection", "Settings", "Accept all".

**Template B, CH with EU nexus (GDPR marketplace)**:

*"We use cookies to operate our website, to capture access statistically and to personalise marketing and advertising. Strictly necessary cookies are set without your consent. For statistical, marketing and tracking cookies we require your active consent. You can withdraw it at any time under 'Cookie settings'."* Buttons: "Reject all", "Settings", "Accept all", all three equally visible.

**Template C, high risk (banks / hospitals / profiling-based advertising)**:

*"We use cookies and tracking technologies to operate our services, meet security requirements and improve our offer. Certain processing, in particular personalisation and tracking by third parties, requires your active consent. A detailed list of all cookies used, providers and third-country transfers is in our privacy policy. You can withdraw your consent at any time."* Buttons as in Template B; complemented by prominent linking to the privacy policy and the DSB.

All three templates follow four principles: equal visibility of all buttons (no dark patterns), default "not enabled" for non-necessary categories (even in Template A), low-barrier withdrawal via footer link, consistency with the cookie table in the privacy policy.

## CMP requirements and consistency with the privacy policy

A consent management platform automates the banner logic and maintains a versioned consent log. DACH market leaders are Cookiebot, Usercentrics, OneTrust and Iubenda. Eight requirements against which every CMP should be tested:

1. **Automatic cookie scan** of the website, identifying every cookie set and its provider.
2. **Granular categories** with individual opt-in/opt-out logic per category and per provider.
3. **Versioned consent log** with user ID / browser signature, timestamp, choice and banner version, evidence in a dispute.
4. **Banner versioning**: every change to the text or categories triggers a new banner version; on material changes with re-confirmation.
5. **Multilingualism** DE/FR/IT/EN synchronous with identical logic.
6. **Geo-targeting**: different banner configuration for CH and EU visitors via IP- or cookie-based detection.
7. **Low-barrier withdrawal** via a footer link "Cookie settings", reachable from every page.
8. **Cookie-table export** as an embed in the privacy policy, automatically synchronous.

The last requirement is the most common source of gaps: banner and privacy policy list different cookies. In FDPIC procedures this is one of the first findings. A CMP that establishes this synchronicity automatically eliminates the error source systemically.

## Common pitfalls and dark patterns

From SIDD audits in 2024-2025 we see recurring banner mistakes:

- **Pre-checked boxes** for non-necessary categories, the CJEU (Planet49 decision C-673/17, 1 October 2019) clarified that this does not amount to valid consent under GDPR/ePrivacy. Under Swiss law it is also problematic because it undermines the objection option of Art. 45c TCA.
- **"Accept" button prominent, "Reject" hidden**, a dark pattern that has produced fines in EU supervisory practice. Swiss supervision has caught up, the FDPIC qualifies such configurations as a breach of "adequate information" under Art. 19 para. 1 DSG.
- **Cookie wall ("you can use the website only if you accept all cookies")**, EDPB guideline 03/2022 rejects this; the FDPIC follows the assessment by analogy.
- **Banner disappears on scroll** without a choice, does not count as consent or objection.
- **Banner text in 8 px grey-on-white**, violates transparency.
- **No low-barrier re-invocation** of the choice.
- **Inconsistency banner ↔ privacy policy**: tools in the banner that are missing from the policy, or vice versa.

Note also that Swiss law does not provide explicit damages for ineffective cookie banners, but Art. 28 of the Civil Code (personality violation) and Art. 3 lit. b UWG (misleading practice) are levers in practice that can establish civil-law consequences.

## How SIDD supports you

SIDD takes on banner design and CMP setup typically as part of a [DSB mandate](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland), from the cookie scan through categorisation and banner configuration to the interlocking with the privacy policy and the records under Art. 12 DSG. With a GDPR nexus we add [GDPR DPO](https://www.sidd.swiss/en/services/data-protection-officer-eu) and [EU representative](https://www.sidd.swiss/en/services/eu-representative). Operational synchronisation between banner, privacy policy and records runs through the [Priverion platform](https://www.sidd.swiss/en/priverion-platform).

For a technical cookie scan of your website with a banner-configuration recommendation, book a free appointment via [our contact form](https://www.sidd.swiss/en/contact), the deliverable is a list of all cookies set, their providers, third-country transfers and the recommended categorisation. For a concrete fixed-price mandate covering banner setup including CMP selection and configuration, use the [quote request](https://www.sidd.swiss/en/quote). Typical project duration: 2-3 weeks for initial configuration, then monthly maintenance as part of the ongoing mandate.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
