Data Protection in Swiss Online Shops

7 min readLast updated By Marc Grob

Introduction

A Swiss online shop is a hybrid construct in data-protection terms: it is mandatorily subject to the revised Federal Act on Data Protection (DSG), often additionally to the EU GDPR (as soon as it offers goods or services to persons in the EU under the "marketplace principle" of Art. 3(2) GDPR), to the obligations of the Federal Act against Unfair Competition (UWG, in particular Art. 3(1)(o) and (u) on e-mail marketing and spam), and to sector-specific duties for card and payment data (PCI DSS). In the background, distance-selling rules (Art. 40 OR), telecommunications law and the cookie provision in Art. 45c lit. b FMG also apply.

This article bundles what owners, managing directors and online marketing managers of a Swiss shop need to know in practice:

  • mandatory information in the footer, checkout and newsletter opt-in;
  • cookies, tracking pixels and retargeting (DSG vs. ePrivacy/TTDSG);
  • payment processing and tokenisation (Datatrans, Stripe, PostFinance, TWINT);
  • processors in the shop stack (hosting, fulfilment, logistics, CRM and review platforms);
  • anti-spam duties under the UWG;
  • data breaches and the 72-hour notification under Art. 24 DSG.

We take a pragmatic angle and show which minimum standards the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) actually expects and where additional GDPR requirements bite.

Legal framework for Swiss online shops

Any shop established in Switzerland or directing offers there is a controller within the meaning of Art. 5 lit. j DSG. As soon as the shop is presented in EU languages, delivers to the EU or shows euro pricing, the GDPR additionally applies via Art. 3(2). In that case, the appointment of an EU representative under Art. 27 GDPR is mandatory unless an exception applies; SIDD offers this EU representative service as a standard product. For sales to the UK, UK GDPR and a UK representative come into play (UK representative).

The threshold for "commercial mass communication" under Art. 3(1)(o) UWG is crossed by even a single unsolicited newsletter sent to a person without an existing business relationship. Infringements are sanctioned both civilly (injunction) and criminally (fine up to CHF 100,000) and are actively pursued by SECO.

Particular attention should be paid to the DSG duty to inform on data collection (Art. 19 DSG). The old Swiss practice of publishing a three-paragraph "privacy statement" is no longer enough. The information must cover at least: identity and contact of the controller, processing purpose, categories of recipients, transfers abroad with the corresponding safeguard, data-subject rights and, in case of automated individual decisions, a notice under Art. 21 DSG.

Privacy notice and checkout information

The checkout collects an unusually large set of data categories: first and last name, delivery and billing address, e-mail, phone, possibly date of birth (for age verification), payment instrument and credit indicators. A two-tier approach works well: a layer-1 short notice in the checkout itself (two or three sentences plus a link) and a full privacy notice in the footer.

The privacy notice must contain at least:

  1. controller with full company address, business identifier (UID) and contact e-mail;
  2. EU or UK representative (where applicable) with address;
  3. categories of data processed and processing purposes;
  4. legal bases (contract, legitimate interest, consent); for GDPR addressees additionally Art. 6(1) GDPR;
  5. categories of recipients (hosting, payment service provider, logistics, marketing, authorities);
  6. third-country transfers and safeguards (adequacy decision, SCCs, BCRs);
  7. retention periods per category;
  8. rights under Art. 25 et seq. DSG and Art. 15-22 GDPR;
  9. reference to the FDPIC as supervisory authority;
  10. date of last update.

Internally, the shop must maintain a record of processing activities under Art. 12 DSG. The exception for SMEs with fewer than 250 employees and low risk practically never applies in profiling-heavy e-commerce.

Cookies, tracking and retargeting

In contrast to the EU, Switzerland currently does not impose a strict cookie consent regime: Art. 45c lit. b FMG requires only information and a right to object ("opt-out"). Technically a transparent cookie notice with opt-out is therefore sufficient for purely Swiss target markets. As soon as the shop addresses persons in the EU, however, the ePrivacy Directive and national transpositions apply (Germany: TTDSG/TDDDG, Austria: TKG): explicit, informed and freely given consent must be obtained before setting non-essential cookies, pixels and fingerprinting.

In a typical online shop this means: technically necessary cookies (cart, session, CSRF) without consent; statistics cookies (Google Analytics 4, Plausible, Matomo server-side) with consent where personal; marketing and retargeting pixels (Meta Pixel, Google Ads Conversion, TikTok Pixel, LinkedIn Insight, Pinterest Tag) only after active consent. Consent must be granular (purposes individually de-selectable), free of dark patterns and as easy to withdraw as to give.

We treat Swiss cookie practice in depth in Cookie Banner Switzerland and tracking requirements under the DSG in Cookie Banner & Tracking DSG. Anyone running Google Analytics must additionally assess the transfer to the US: since the EU-US Data Privacy Framework adequacy decision of 2023, the transfer is again possible for DPF-certified providers, and the DSG accepts this by analogy for "recognised countries" under Art. 16(1) DSG.

Payment processing and PCI DSS

Card and payment data are not "sensitive" within the technical meaning of Art. 5 lit. c DSG, but they are among the most sensitive data in a shop and sit at the heart of PCI DSS (version 4.0.1 has been mandatory since 31 March 2024). The central recommendation has been the same for years: never store card numbers in your own systems; instead use tokenisation at the payment service provider (Datatrans, Wallee, SIX Payment, Stripe, PostFinance Checkout, TWINT).

This typically reduces the own PCI DSS scope to SAQ A (for fully redirected or iframe-based payment flows): manageable effort and significantly lower audit burden. Anyone collecting card data in their own frontend (Direct Post) ends up in SAQ A-EP or SAQ D with much higher requirements, including quarterly ASV scans.

Invoice purchase and "buy now pay later" (Klarna, Cembra, byjuno, Riverty) also create specific data flows: these providers conduct credit checks and are typically to be classified either as joint controllers or as independent controllers. The checkout must transparently inform users before the credit check that data flows to the payment partner and possibly to credit bureaus (CRIF, Intrum), and the customer must have the choice of a payment route without a credit check (prepayment, TWINT).

Processors in the e-commerce stack

A typical Swiss online shop processes data through ten to thirty processors: shop platform (Shopify, WooCommerce host, Magento host, Shopware Cloud), CDN, e-mail sender (Mailchimp, Brevo, ActiveCampaign), CRM (HubSpot, Salesforce), helpdesk (Zendesk, Intercom), reviews (Trustpilot, Trusted Shops, Bazaarvoice), logistics (Swiss Post, DHL, DPD), returns tools, analytics, tag manager, live chat. Each one needs a data-processing agreement under Art. 9 DSG or Art. 28 GDPR.

For each processor the following must be verified: (a) primary processing location and sub-processors, (b) transfer mechanism for third-country links, (c) security measures aligned with Art. 8 DSG / Art. 32 GDPR, (d) deletion and return arrangements at the end of the contract. A central processor list, updated quarterly and ready to be shown in any audit, is highly recommended.

Trusted Shops, Trustpilot and similar platforms are a special case: they send automated review invitations on the shop's instruction. Under Art. 3(1)(o) UWG, this is only permissible if the recipient has consented in advance or if, in the framework of an existing business relationship, "similar goods or services" are being advertised and a free unsubscribe option is provided at order placement and in every follow-up e-mail.

Newsletters, the UWG and marketing automation

Newsletters and marketing e-mails are the area with the highest sanction risk in Swiss practice, not via the DSG but via the UWG. Art. 3(1)(o) UWG requires double opt-in with a confirmation e-mail, verifiable consent and, in every advertising e-mail, a working, free and one-click unsubscribe link. Infringements can be pursued by SECO, by competitors (Art. 9, 23 UWG) and by consumer associations through injunctions and damages.

For EU-addressed newsletters, the GDPR adds the requirement of a legal basis under Art. 6(1)(a) or (f) GDPR and the burden of proof under Art. 7(1) GDPR. Comprehensive logging of every opt-in with timestamp, IP address, the form used and the wording of the consent text is the practical answer. Marketing automation platforms (HubSpot, ActiveCampaign, Klaviyo, Salesforce Marketing Cloud) typically offer this logging, but it has to be activated and the export drilled for breach and access-request scenarios.

Profiling, lead scoring and "predictive segmentation" fall under Art. 21 DSG and Art. 22 GDPR. As soon as automated decisions about discounts, shipping conditions or creditworthiness flow from the score, information, the right to state one's position, and possibly a data-protection impact assessment (Art. 22 DSG / Art. 35 GDPR) are required.

How SIDD supports you

SIDD looks after Swiss online shops from the sneaker drop store to the institutional B2B marketplace. We review your privacy notice, checkout flow and cookie solution in the light of the DSG, GDPR and UWG, close the regularly missing data-processing agreements with your e-commerce tools and support you in handling data breaches or access requests.

For our online-shop clients we typically combine an external Swiss data-protection adviser under Art. 10 DSG with, where required, a GDPR data protection officer and an EU representative under Art. 27 GDPR. We carry out pragmatic webshop audits (legal plus technical), advise on tag-manager configuration and train your marketing team in the UWG boundaries. Write to us via the contact form or request a tailored quote for your shop.

Need help putting this into practice? SIDD operates the matching service.
See service →

Data Protection in Swiss Online Shops

INSIGHT

Data Protection
24 May 2026
Marc Grob
Data protection in Swiss online shops: privacy notice at checkout, cookies and retargeting, payment data, service providers, newsletters and the UCA.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.