# Cookie Banners & Tracking: DSG Obligations in Detail

> Cookies and tracking in Switzerland: the legal bases, when consent is needed and when information is enough, and what a cookie notice must contain.

- Source: https://www.sidd.swiss/en/insights/cookie-banner-tracking-ndsg/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Dr. Dominic Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

In Switzerland the cookie banner is neither a decorative element nor a one-to-one copy of GDPR obligations. Anyone deploying tracking, analytics or marketing pixels operates simultaneously under the revised Federal Act on Data Protection (DSG, in force since 1 September 2023), the Federal Telecommunications Act (Art. 45c FMG) and the Unfair Competition Act (Art. 3 para. 1 lit. s UWG). Unlike the EU ePrivacy Directive, Swiss law does not generally mandate *prior consent* for non-essential cookies, but the transparency and information requirements have sharpened considerably under the revised DSG.

This article explains in detail which Swiss law applies to which cookie type and when an **opt-in**, an **opt-out** or a simple information notice is sufficient. You will get:

- an overview of the three relevant legal bases (DSG, FMG, UWG) and where they overlap;
- the demarcation from GDPR/ePrivacy for Swiss companies with EU reach;
- a cookie taxonomy (strictly necessary, preference, statistics, marketing) with concrete examples;
- the minimum contents of a compliant cookie notice under Art. 19 DSG and following;
- the expectations of the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) including its current cookie guideline;
- typical implementation flaws and concrete pointers on consent management platforms.

The goal is a defensible compliance position that does not over-shoot what Switzerland actually demands, while covering everything it does, particularly for SMEs that often deploy off-the-shelf EU banners and miss the Swiss specificities.

## The three legal bases at a glance

Cookies in Switzerland are covered by **three** bodies of law that supplement rather than displace each other. Knowing only one of them means systematically missing risks.

**First**, the Federal Telecommunications Act: Art. 45c FMG requires *information about purpose and processing* as well as a notice about the option to refuse processing on the end device. Unlike Art. 5(3) of the ePrivacy Directive, Swiss telecoms law explicitly does *not* require an opt-in. The requirement is limited to transparent information and an opt-out option. This applies in particular to storing and reading data on the user's device, i.e. classic cookies, local storage and pixels.

**Second**, the DSG: from the moment a cookie processes personal data (IP address, device ID, profile data), the principles in Art. 6 et seq. DSG apply: lawfulness, purpose limitation, recognisability, proportionality. The information duty in Art. 19 DSG requires the data subject to actually recognise the processing and find the key information (identity of the controller, processing purpose, categories of recipients, cross-border transfers), ideally in the privacy notice linked from the cookie banner.

**Third**, Art. 3 para. 1 lit. s UWG: anyone sending mass advertising or using tracking for advertising purposes in electronic commerce must provide clear identity information and an easy, free-of-charge refusal mechanism. Violations can trigger unfair competition claims on top of data protection risks.

eIDAS and its Swiss counterpart ZertES become relevant only where cookies carry signature-relevant authentication. This constellation is rare but should appear on your asset inventory.

## When consent, when notice is enough

Combining the three legal bases produces a differentiated answer: *it depends on what the cookie does and who receives the data.*

**No consent is required** for strictly necessary cookies, session tokens, language preference, shopping cart, load balancing, security cookies (e.g. CSRF protection). A notice in the privacy policy is sufficient; a banner is not legally required, although it is often sensible from a UX perspective. Pure *first-party reach measurement* without profiling and without cross-border transfer also generally falls under the FMG notice standard in practice.

**Consent effectively becomes mandatory** as soon as tracking happens via third-party services that use data for their own purposes (Google Ads, Meta Pixel, LinkedIn Insight, TikTok Pixel), as soon as data is transferred to the United States or other countries without an adequacy decision, or as soon as profiles are formed or sensitive personal data (Art. 5 lit. c DSG) is processed. In these cases the only sustainable legal basis is typically *explicit consent* under Art. 6(7) DSG, because neither legitimate interest nor contract performance justifies the intrusive character.

In practice this means: if your website goes beyond pure first-party analytics, and most do, the legally safest path is an opt-in banner with equal-weight **Accept** and **Reject** buttons. Dark patterns (pre-ticked boxes, hidden reject buttons, an Accept button in green and Further options in grey) contradict the DSG transparency principle and the FDPIC's practice, and are prohibited under EU law in any event.

## Cookie classification in practice

A reliable banner needs a complete **cookie inventory** first. Experience shows that a technical scan on a typical SME website discovers 30 to 80 distinct cookies and storage entries, most of them unknown even to the marketing team. Four categories have become standard:

1. **Necessary:** login session, CSRF token, load-balancer sticky, the consent cookie itself. No consent, but documented in the privacy notice.
2. **Preference:** language, region, font size, dark mode. Usually no consent, with a notice.
3. **Statistics:** first-party analytics without cross-border transfer (e.g. self-hosted Matomo with IP anonymisation) is often viable on an FMG-notice basis. Google Analytics 4 with data flowing to the US has always required consent and additional safeguards, as no adequacy decision exists for CH–US.
4. **Marketing:** retargeting, conversion tracking, lookalike audiences, affiliate tracking. Always consent-based because profile-forming and typically cross-border.

For every cookie, document name, provider, purpose, retention period, data categories, recipients, cross-border transfer and legal basis in the inventory. This table becomes part of your privacy notice and must be reviewed regularly (at least every six months), because marketing and analytics tools continuously set new cookies. Operationally we recommend a consent management platform (CMP) that drives a server-side tag manager and loads cookies only after consent is granted, not one that retroactively blocks them.

## Mandatory contents of the cookie notice

A compliant Swiss cookie banner differs from the EU standard mainly on two points: it does *not* always need a prior opt-in, but its content must be precise. Combining Art. 19 DSG, Art. 45c FMG and the FDPIC cookie guidelines yields the following essential elements:

- **Identity of the controller** including contact details (linked from the banner to the privacy notice).
- **Processing purposes** per cookie category, not in the abstract (Improving the user experience is not enough).
- **Recipients and categories of recipients**, naming third parties such as Google, Meta, HubSpot.
- **Cross-border transfers** with country and safeguards (FDPIC adequacy decision, Standard Contractual Clauses, Swiss-US Data Privacy Framework).
- **Retention period** per cookie, concretely in days/months, not as long as necessary.
- **Withdrawal mechanism** as low-friction as the original consent (Art. 6(7) DSG, as easy as giving consent). In practice: a permanently accessible settings icon.
- **Notice of data subject rights** per Art. 25 et seq. DSG including access, rectification and erasure rights.

If you want the same banner to satisfy GDPR and DSG, take the stricter EU requirements as the yardstick: active, granular consent with a real refusal option at the first layer, documented consent records with timestamp, banner version and cookie list. These logs serve as evidence in access requests and complaint proceedings.

## FDPIC expectations and typical failure modes

In its cookie guidelines and annual activity reports, the FDPIC has signalled that it regards cookie banners as a visible test case for an organisation's overall DSG compliance. A failure here flags broader gaps. The most frequent issues from our advisory practice:

- **Cookies set before consent:** the tag manager fires all marketing pixels at page load; later CMP blocking is too late. Fix: server-side or consent-aware tag management.
- **Unequal Accept and Reject:** visually, in colour, in position. This is a dark pattern that undermines the voluntariness of consent.
- **No genuine withdrawal:** once accepted, the banner disappears and the user can no longer reach the settings.
- **Cross-border transfer omitted:** US-hosted tools (Google Analytics, Meta, Hotjar US region) are not disclosed as such.
- **Outdated cookie table:** the privacy notice still lists Universal Analytics while the site has long run GA4 with a different cookie set.
- **Missing legal basis per purpose:** a generic consent reference does not survive an access request, the mapping purpose to legal basis is required.

Closing these six items typically yields a banner that holds up under both Swiss and EU law and does not collapse at the first complaint.

## US Framework and cross-border transfers

Since the Swiss-U.S. Data Privacy Framework entered into force and the FDPIC recognised it on 15 September 2024, data transfers to the United States to certified recipients are again possible without Standard Contractual Clauses, but *only* to companies that have actively certified on the US Department of Commerce list. Anyone skipping this check is still transferring blind and unconditionally needs SCCs plus a Transfer Impact Assessment (TIA).

For cookies and tracking this means concretely: before activating a US tool, verify (1) whether the provider is Swiss-US DPF certified, (2) what data categories it receives, (3) whether it re-uses the data for its own purposes, (4) how the certification is reflected in the cookie notice. With cloud vendors that re-transfer intra-group (e.g. to Indian or Israeli group entities), DPF certification in the US is insufficient, you additionally need SCCs for the onward transfer.

Also note: cookie law within the EU itself is anything but harmonised. France's CNIL, Italy's Garante and Austria's DSB have repeatedly held Google Analytics in default configuration non-compliant in recent years. Anyone maintaining a unified presence across DACH and the EU must know these decisions and ideally fall back on EU-hosted alternatives (Matomo, Plausible, Fathom) or server-side tagging with data minimisation.

## How SIDD supports you

SIDD guides Swiss companies from the initial cookie audit through compliant banner implementation and ongoing maintenance. Our approach combines legal analysis (DSG, FMG, UWG, GDPR where EU reach applies) with a technical scan of deployed trackers, a recommendation on the right consent management platform and an update of your [privacy notice](https://www.sidd.swiss/einblicke/datenschutzerklaerung-website-schweiz). The output is a documented cookie catalogue, a compliant banner and a recurring review process.

Through our mandates as [Swiss data protection advisor](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) and as [EU Data Protection Officer](https://www.sidd.swiss/en/services/data-protection-officer-eu), we support companies that must meet DSG and GDPR requirements in parallel. Workshops with the marketing and web teams via our format [privacy workshop for SMEs](https://www.sidd.swiss/en/services/data-protection-workshop-sme) ensure that new campaigns and tools are designed consent-aware from the outset.

Write to us via the [contact form](https://www.sidd.swiss/en/contact) or request a tailored [quote](https://www.sidd.swiss/en/quote), we respond within one business day with a concrete proposal that transparently quantifies scope, timing and deliverables for your banner project.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
