# Data Protection for Swiss Associations

> Data protection in associations: member data, photos and social media, newsletters and fundraising, minimum standards and a roadmap for the board.

- Source: https://www.sidd.swiss/en/insights/data-protection-swiss-associations/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Swiss associations (Vereine) are the most common form of private self-organisation in Switzerland – sport, culture, politics, professional bodies, neighbourhood and youth associations, charities. They routinely process significant volumes of member data, organise events, run websites, send newsletters, publish photos and maintain membership lists. The revised Federal Act on Data Protection (DSG) applies to associations without any headcount threshold and without a non-profit privilege – the requirements are identical to those for businesses. At the same time most associations lack specialist staff, budget and time for data-protection compliance. This article sets out a pragmatic, association-specific path to compliance in 2026.

What this article delivers:

- How the Swiss Civil Code (CC) association framework interacts with the DSG
- Which obligations actually bite for associations (and which do not)
- Member data: collection, use, sharing with third parties
- Photos, event photography and social media
- Newsletters, fundraising, member acquisition
- A lean implementation roadmap for association boards

## Association in the CC and the DSG

A Swiss association (Art. 60 ff. CC) is a legal person with its own legal personality. It is a *controller* within the meaning of Art. 5(j) DSG for the processing of personal data of members, donors, event participants, website visitors and newsletter subscribers. The board is internally responsible for compliance; the statutes can anchor functions such as a "board data-protection lead".

Associations are smaller than companies, but the DSG knows no SME or association privilege. The following duties apply without threshold: information (Art. 19 DSG) on every collection; access right (Art. 25 DSG); rectification (Art. 32 DSG); breach notification for high-risk incidents (Art. 24 DSG). The processing register (Art. 12 DSG) is mandatory where the association regularly processes sensitive data (e.g. health association with diagnoses, patient organisation) or carries out high-risk profiling; small associations without such data are exempted under Art. 24 DPO – but should still keep a lightweight record to be able to fulfil other obligations. Fines for breach can reach CHF 250,000; they target natural persons (typically board members), not the association itself.

## Member data

Processing of member data is broadly covered by the statutes – joining the association implies consent to the processing necessary to run it (name, address, date of birth, dues management, membership status, function). This processing is justified under Art. 31 DSG by the association relationship and does not require separate consent. The picture differs for processing that goes beyond running the association:

- **Disclosure to third parties** (sponsors, other associations, advertising partners): requires explicit per-member consent.
- **Publication of the member list** (website, yearbook): only with consent; for office-holders (board, coaches) public disclosure of function is usually statutorily covered.
- **Profiling** (member retention analysis, donation behaviour analytics): requires information and – for high risk – an impact assessment.
- **Credit or security checks**: only on a legitimate association interest, with information.

The member list is a frequent friction point. An individual member has a certain right under CC association rules (Art. 67 CC, right to inspect association affairs) to view the member list, e.g. to prepare proposals for the general meeting. This right must be balanced against the privacy of other members – in practice the board does not hand over a full list but allows supervised inspection or offers a relay route. A data copy to take away is regularly not permissible.

## Events, photos and social media

Associations regularly host public and internal events (general meetings, sports days, performances, festivities). Data is collected (attendance, allergies, emergency contacts), photos are taken and published on website, social media and member magazines. The legal picture:

1. **Attendance lists**: collection to run the event is covered; sharing (e.g. with a sponsor) needs consent.
2. **Photo and video**: the right to one's own image under Art. 28 CC applies in addition to data protection. At public events with an indeterminate audience, overview shots are permissible where no individual is identifiable in the foreground; individually recognisable persons need consent.
3. **Publication**: separate consent per channel (member-internal website, public website, Instagram, Facebook, print magazine).
4. **Minors**: parental consent for children and teenagers; from 12 years onwards additional own consent is recommended.
5. **Erasure**: members, former members and event participants can request removal of "their" photos; the association must respond and – where proportionate – act on past publications.

Social-media presences should have a clear concept: who posts what, how is image material released, how are critical comments handled. Linking to member profiles is not permitted without consent; tagging persons on images must be handled cautiously.

## Newsletters and fundraising

In 2026 newsletters, fundraising and event invitations are subject to four legal layers: DSG (information, consent), telecoms/unfair competition law (Art. 3(o) UCA Swiss anti-spam), newsletter specifics, and – for recipients in the EU – GDPR and ePrivacy.

Practically: **members** can receive association-related communications (assembly invitations, dues invoices, member-internal news) without separate consent – this is part of the association relationship, but every communication must contain an easy unsubscribe option for non-mandatory mailings. **Non-members** (donors, interested persons) require explicit opt-in with double opt-in via confirmation link, documented consent with timestamp and IP, and easy unsubscribe at any time. **Fundraising** to former donors is defensible on legitimate interest, with a clearly visible opt-out. Address rentals or purchases without recipient consent are not permissible.

For tools: Swiss and EU vendors (Mailingwork, CleverReach EU, Brevo EU, Newsletter2Go EU) are typically easier to justify than US-only solutions without a TIA. Anyone using Mailchimp, ActiveCampaign or HubSpot needs a documented transfer assessment and EU residency configuration.

## Minimum technical and organisational measures

Small associations do not need corporate-grade TOMs, but a baseline is in the association's own interest:

- **Member database**: centralised in a suitable tool (ClubDesk, Webling, Hitobito, Verein2.0, fasciaPro, Bexio for associations, properly configured Office 365) instead of scattered Excel files on individual board members' machines.
- **Access management**: personal logins, roles by function (president, treasurer, secretariat, coaches), MFA on all logins, access reconciliation on board changes.
- **Backup**: daily backup, one off-site copy, annual recovery test.
- **E-mail hygiene**: no personal mass mailings in open To/Cc fields – always Bcc or newsletter tool. Phishing awareness on the board.
- **Devices**: encryption on board laptops, strong passwords, separate devices or profiles for association and personal use.
- **Retention**: member data after departure only as long as necessary (typically 2-3 years for possible bookkeeping), then erasure; board minutes and accounting in line with Swiss Code of Obligations retention (10 years).
- **Board commitment**: written confidentiality and data-protection commitment, surviving departure from the board.
- **DPAs with providers**: every external provider processing member data (accountant, IT support, newsletter tool, donation platform) signs a DPA under Art. 9 DSG.

## Implementation roadmap for the board

Associations new to data protection can reach a solid compliance level in around 8-12 weeks. A proven plan:

1. **Weeks 1-2: inventory**. Which data is processed where, for what purpose, by whom? List of tools, accounts, external providers.
2. **Weeks 3-4: privacy notice and member information**. A short, clear privacy notice on the website and a flyer for new members.
3. **Weeks 5-6: DPA collection**. Obtain or sign DPAs with every relevant provider.
4. **Weeks 7-8: TOM update**. Centralise the member tool, enable MFA, establish Bcc discipline on newsletters, erase old data.
5. **Weeks 9-10: consent setup**. Obtain photo consents, clean up newsletter opt-in, extend event registrations.
6. **Weeks 11-12: board training and incident plan**. 90-minute workshop, breach playbook, set annual review date.

Statute amendments are rarely strictly required but useful: an article on board data-protection responsibility, a reference to the privacy notice, optionally a statutory "board data-protection lead" function.

## How SIDD supports you

SIDD offers Swiss associations a deliberately lean data-protection package: an association-specific privacy notice, DPA templates for the most common tools, photo-consent templates, an incident playbook and a short board training. Larger associations and federations take up our [data-protection adviser mandate](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland), with annual review and availability during incidents. For associations with active IT platforms we additionally recommend a [vulnerability scan](https://www.sidd.swiss/en/services/vulnerability-scan). Our [data-protection workshops](https://www.sidd.swiss/en/services/data-protection-workshop-sme) are designed for boards too and cover the essentials in 90-120 minutes. If your association has members or activities in the EU, we evaluate the need for an [EU representative under Art. 27 GDPR](https://www.sidd.swiss/en/services/eu-representative). Speak with us via our [contact form](https://www.sidd.swiss/en/contact) or request an association-friendly [quote](https://www.sidd.swiss/en/quote).

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
