GDPR Switzerland Checklist – What Applies Beyond the DSG

7 min readLast updated By Dominic Staiger

Introduction

A Swiss company without an EU subsidiary, without an EU establishment and without EU employees can nevertheless fall under the GDPR, and does so more often than its own management assumes. The trigger is Art. 3(2) GDPR: the marketplace principle. Anyone who actively offers goods or services to EU data subjects (letter a) or monitors their behaviour in the EU (letter b) becomes GDPR-bound, in addition to the DSG duty that already applies in Switzerland. This dual qualification is, in 2026, the normal case for any SME with an online business.

This checklist covers:

  • the trigger test of Art. 3(2) GDPR with concrete indicators;
  • the GDPR additional duties versus the DSG;
  • the duty to appoint an EU representative under Art. 27 GDPR and the exceptions;
  • the GDPR breach-notification duties (72 hours Art. 33 GDPR, communication to data subjects Art. 34 GDPR);
  • the sanction thresholds (Art. 83 GDPR) and their practical meaning for Swiss companies;
  • the parallel handling in DSG and GDPR documents (one privacy policy or two?).

If you end the checklist with clear "yes" answers on GDPR applicability but operate no EU representative mandate, no GDPR extension of the privacy policy and no 72-hour GDPR notification process, you have a documented compliance failure, typically the first thing an EU supervisory authority pins down.

When does the GDPR apply to a Swiss company?

Art. 3(2) GDPR applies on two triggers:

  1. Lit. a, offering goods/services: you actively address EU data subjects. Indicators: EU language versions with local prices (EUR pricing on the DE website), shipping-address entry for EU countries in checkout, EU phone number as contact, targeted advertising in EU markets (Google Ads with EU geo-targeting, Meta campaigns for the DACH market).
  2. Lit. b, behaviour monitoring in the EU: tracking cookies of a third-party provider on your website capture EU users. The classic constellation: Google Analytics, Meta Pixel, HubSpot tracking, Hotjar, all build behavioural profiles that, under CJEU case law, qualify as "monitoring" once they fasten on EU data subjects.

EDPB Guidelines 3/2018 on the GDPR's territorial scope interpret both letters broadly. The mere fact that a Swiss website is available in German is not enough, what matters is targeting the EU market. Practical indicator: anyone who accepts DE shipping addresses in checkout and has more than two DE orders per quarter is "actively offering".

The de minimis hint in recital 23 GDPR is to be read narrowly: incidental, occasional reachability for EU persons is insufficient, intended, regular reach suffices.

GDPR additional duties versus the DSG

Becoming GDPR-bound preserves all DSG duties and adds the following GDPR duties:

  • Legal basis per processing under Art. 6 GDPR (contract, legal duty, vital interest, public interest, legitimate interest, consent). The DSG has no comparable "legal-basis catalogue".
  • Mandatory disclosures under Art. 13/14 GDPR: in addition to the DSG information, you must state the storage period, the data-subject rights with a GDPR anchor (in particular Art. 20 portability, which has no direct DSG counterpart), and the right to lodge a complaint with an EU supervisory authority.
  • Processor management under Art. 28 GDPR: stricter than Art. 9 DSG, in particular on sub-processing (prior authorisation) and audit rights.
  • Data-protection impact assessment under Art. 35 GDPR: a hard duty on systematic, large-scale processing of special categories (Art. 9 GDPR) or systematic monitoring of publicly accessible areas.
  • DPO under Art. 37 GDPR: for Swiss companies without an EU establishment not strictly mandatory, but where the core activity is systematic monitoring or large-scale processing of sensitive categories, a DPO is effectively recommended, see GDPR DPO.
  • EU representative under Art. 27 GDPR with its own address in the EU (see next block).

The sanction threshold under Art. 83 GDPR is EUR 20 million or 4 % of global group turnover, significantly higher than the DSG penalty under Art. 60 DSG, which caps at CHF 250,000 for natural persons and therefore often hits Swiss companies only indirectly.

EU representative under Art. 27 GDPR

Art. 27 GDPR obliges every controller or processor not established in the EU to appoint in writing a representative in the EU. The representative is the contact point for data subjects and EU supervisory authorities and must be able to evidence its mandate in writing. The representative's address and identity belong in the privacy policy (Art. 13(1)(a) GDPR).

Exceptions under Art. 27(2) GDPR are narrow:

  1. occasional processing that is not large-scale and does not concern special categories. "Occasional" under EDPB guidance is not structurally recurring, an online shop that ships into the EU monthly does not qualify.
  2. public bodies.

For the majority of Swiss SMEs with an EU nexus, the exception does not apply. The representative appointment is therefore practically mandatory. Violations have been consistently pursued in EU supervisory practice, known examples in recent years have produced fines in the EUR 100,000 range for SMEs, and significantly more for larger breaches.

SIDD takes on EU representation as a fixed-price mandate at EU representative Art. 27 GDPR. Those who serve UK data subjects need a parallel UK representative under Art. 27 UK GDPR, see UK representative. Further background in our article Article 27 GDPR.

Breach notification: 72 hours under Art. 33 GDPR too

The 72-hour deadline is anchored in both the DSG (Art. 24) and the GDPR (Art. 33), with differences:

  • DSG Art. 24: notification to the FDPIC for any breach with high risk to data subjects. Communication to data subjects is optional, dependent on risk.
  • GDPR Art. 33: notification to the competent EU supervisory authority for any breach, unless it is "unlikely to result in a risk". The threshold is therefore lower than under the DSG.
  • GDPR Art. 34: communication to data subjects where the breach is "likely to result in a high risk". A narrower condition than the DSG's discretionary information duty.

A dually qualified controller must, on a relevant breach, typically serve two authorities: the FDPIC and the competent EU supervisory authority (typically the one in the country of the representative's EU establishment or, under the one-stop-shop in Art. 56 GDPR, the lead authority of the main establishment, which does not apply to Swiss companies without an EU establishment, hence the authority in the country of the affected data subjects). Templates for both notifications must be on hand, we recommend them as part of an incident-response plan exercised annually in a tabletop. Details in our article Reporting a data breach to the FDPIC.

One privacy policy or two?

The most common question for dually qualified Swiss companies: a combined privacy policy or two separate ones (one DSG, one GDPR)? The clear recommendation is one combined policy. Reasons:

  1. Practicality: two parallel policies double the maintenance burden and create drift risk.
  2. User comprehensibility: a single, clearly structured policy is more user-friendly.
  3. Legal certainty: all mandatory items of both regimes are covered without case-by-case allocation.

The combined policy contains the DSG mandatory items (Art. 19 DSG) as a base layer and adds the GDPR-specific blocks (legal basis per processing, storage period, the right to data portability under Art. 20 GDPR, right to lodge a complaint with an EU supervisory authority, EU representative). Where it is unclear which regime applies, the higher protection standard prevails (typically GDPR).

A well-configured generator switches on the GDPR blocks automatically as soon as the triggers (EU shipping, EU language variant with prices, tracking with EU nexus) are met. Detailed discussion in our articles Swiss privacy policy generator and generator comparison.

Practical checklist: 12-point GDPR self-test

Answer the following 12 questions yes/no:

  1. Do you actively deliver goods or services to at least one EU member state?
  2. Do you offer EUR pricing or DE/FR/IT language variants with EU reach?
  3. Do you use tracking tools (analytics, pixel, heatmaps) with data flow to US/EU providers?
  4. Do you run targeted advertising in EU markets (Google Ads geo, Meta campaigns)?
  5. Do you have an EU establishment, EU subsidiary or EU employees?
  6. Is an EU representative under Art. 27 GDPR appointed and published in the privacy policy?
  7. Are the mandatory disclosures under Art. 13/14 GDPR contained in the privacy policy?
  8. Is a legal basis under Art. 6 GDPR documented per processing operation?
  9. Is a DPIA process under Art. 35 GDPR in place with activated triggers?
  10. Have you appointed a DPO or documented the basis for non-appointment?
  11. Is a GDPR-compliant 72-hour notification process in place with templates for Art. 33 and Art. 34 GDPR?
  12. Are your DPAs drafted under Art. 28 GDPR (sub-authorisation, audit rights)?

Anyone answering questions 1-5 with at least one "yes" and questions 6-12 predominantly "no" has acute remediation needs. The next step is a 60-minute call with a GDPR specialist and a GDPR onboarding with EU representative, DPO and privacy-policy extension.

How SIDD supports you

SIDD is positioned as a dually qualified advisory for both DSG and GDPR. For dually qualified Swiss companies we typically bundle three mandates: Swiss data-protection advisory (DSG compliance), GDPR DPO (Art. 37 GDPR), and EU representative (Art. 27 GDPR). With a UK nexus we add the UK representative. Operationally maintenance runs through the Priverion platform with a combined records register under Art. 12 DSG and Art. 30 GDPR.

For a first baseline, in particular on whether the GDPR truly applies to your company, we are happy to schedule a 30-minute call via our contact form. For a concrete fixed-price mandate for GDPR onboarding (EU representative, privacy-policy extension, DPO mandate, incident-response templates) use the quote request. A GDPR onboarding is typically completed in 4-6 weeks.

Need help putting this into practice? SIDD operates the matching service.
See service →

GDPR Switzerland Checklist – What Applies Beyond the DSG

INSIGHT

Data Protection
24 May 2026
Dr. Dominic Staiger
When the GDPR applies to Swiss companies and what it requires on top of the FADP: EU representative, breach deadlines, privacy notice, checklist.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.