GDPR Switzerland, What Swiss Companies Need to Know
Introduction
For many Swiss companies the GDPR is the unwelcome topic they would prefer to leave to the DSG. The wish is understandable but legally untenable: as soon as a Swiss actor offers goods or services in the EU or monitors the behaviour of persons in the EU, the GDPR applies via Art. 3(2) regardless of the controller's seat. In practice this affects a large majority of SMEs running a webshop, a SaaS product or B2B sales with EU exposure.
This guide gives Swiss companies the essentials for GDPR applicability, the relationship with the DSG and the operational implementation. It covers:
- the extraterritorial reach of the GDPR (Art. 3) and its triggers;
- the duty to appoint an EU representative under Art. 27 GDPR and the narrow exceptions;
- the parallel application of DSG and GDPR with the key differences;
- the GDPR fines structure (Art. 83) and its effect on Swiss companies;
- cross-border transfers into Switzerland, from an EU perspective, and the 2024 adequacy decision;
- the operational steps for a GDPR-compliant Swiss company.
Targets are executive boards, sales and marketing leads, legal counsel and DPOs. The parallel Swiss-law guide is at Swiss Federal Act on Data Protection (DSG), The Complete Guide.
When the GDPR applies
Art. 3 GDPR defines three application scenarios, of which paragraph 2 matters most for Swiss companies:
Art. 3(1), establishment principle: GDPR applies as soon as processing occurs in the context of activities of an establishment in the Union. A German, French or Italian subsidiary triggers this without further ado.
Art. 3(2), market principle: GDPR applies to non-Union actors if they:
- Offer goods or services to persons in the Union, irrespective of payment;
- Monitor the behaviour of those persons insofar as that behaviour takes place in the Union (tracking, profiling, behavioural analysis).
Indicators of an offer to EU persons under Recital 23 GDPR: language (e.g. German-speaking site), currency (EUR pricing), EU delivery addresses, country-code domains (.de, .fr), explicit mention of EU customers, EU shipping costs. A purely passive English-language internet presence is not enough.
Monitoring in the EU: web tracking via cookies, analytics pixels on pages visited by EU persons, app tracking, geolocation. Once behaviour is tracked in the EU, the GDPR applies.
Art. 3(3): GDPR applies through international law, practically irrelevant for Swiss companies.
In practice this means: virtually every Swiss company with an online presence and EU customers falls under the GDPR. A solid applicability test is part of baseline compliance and should be documented in writing.
EU representative under Art. 27 GDPR
Swiss controllers and processors without an EU establishment must designate a representative in the Union under Art. 27 GDPR as soon as they fall under Art. 3(2). Three pillars:
Function: The EU representative serves as the contact point for supervisory authorities and data subjects on all matters of processing. They keep access registers, respond to authority queries, forward complaints, hold the processing register.
Exceptions: No appointment duty for occasional processing that does not include large-scale processing of special categories and presents no high risk. The threshold is narrow, most Swiss SMEs do not qualify once they systematically serve EU customers.
Appointment: In writing, with a clear mandate. The representative must sit in a Member State where most data subjects reside or where the bulk of processing takes place. For broad EU activity, Germany or Ireland are typical.
Several EU supervisors have explicitly fined Swiss companies in recent years for missing Art. 27 representation, most recently with six-figure EUR fines against online shops and coaching platforms. The appointment is not a bureaucratic formality but a compliance position with real sanction effect.
In practice specialised providers, including SIDD via our Art. 27 EU representation, take this function as a service with clear mandate, defined SLAs and transparent fees. Also available: UK Art. 27 representation, additionally required for UK exposure since Brexit.
GDPR and DSG, parallel application
Swiss companies with EU activity are subject to both regimes in parallel. The DSG does not displace the GDPR and vice versa. Both duties cumulate. In practice the concepts overlap substantially, which eases parallel compliance, but six differences matter:
- Legal bases: The DSG does not contain an exhaustive list as Art. 6 GDPR does. Instead the concept of justified processing applies (consent, contract, overriding interest, statutory duty).
- DPO duty: GDPR Art. 37 is partially mandatory, DSG Art. 10 is voluntary.
- Fines structure: GDPR up to EUR 20 million / 4 % against companies, DSG up to CHF 250,000 against natural persons.
- Breach notification: GDPR 72h from awareness, DSG as soon as possible (similar in practice).
- Access right thresholds: Both 30 days but different refusal grounds.
- EU representative / DPO: Duty under Art. 27 GDPR for Swiss actors without EU establishment; no mirror in DSG.
In practice all compliance artefacts (processing register, privacy notice, AVV, DPIA, breach playbook) are built to satisfy both regimes. Taking the stricter regime as the yardstick, usually GDPR on procedural rights and EU representative, DSG on Swiss supervisory contact, keeps both sides compliant. We treat the comparison in depth in DSG vs GDPR, differences.
Fines and supervisory practice
Art. 83 GDPR provides for a two-tier fines regime:
- Up to EUR 10 million or 2 % of worldwide group turnover for breaches of controller and processor duties (e.g. processing register, DPO, breach notification, DPIA).
- Up to EUR 20 million or 4 % of worldwide group turnover for breaches of core principles (legal bases, data subject rights, cross-border transfer, supervisory orders).
The higher amount is decisive. Unlike the DSG, the GDPR addresses companies directly, not the natural person. Fines are materially higher in absolute terms and more relevant for corporate liability in many constellations.
EU supervisory authorities have repeatedly sanctioned Swiss actors in recent years, in B2C (online shops), SaaS providers (CRM, marketing platforms) and group subsidiaries with central IT in Switzerland. Fines are collected via mutual assistance agreements, enforcement treaties and EU subsidiaries. Acting from Switzerland and ignoring the GDPR provides no shield.
On top come civil damages claims (Art. 82 GDPR), which have gained substantial weight since ECJ rulings on the assessment of non-material damages (particularly C-300/21 Österreichische Post and C-340/21 Natsionalna agentsia za prihodite). Swiss companies are increasingly being approached by collective action firms.
Cross-border transfer from the EU view
An often overlooked dimension: from the EU view, Switzerland is a third country. Transferring personal data from the EU to Switzerland requires a legal basis under Chap. V GDPR. Three points are central in 2026:
Adequacy decision renewed (January 2024): The European Commission renewed the adequacy decision for Switzerland in January 2024 on the basis of the DSG. Transfers from the EU to Switzerland to private recipients are thus permissible without SCC or additional safeguards. This is the most important economic relief of recent years and secures group data flows.
Switzerland–US via Swiss-US DPF (since September 2024): Transfers from Switzerland to US recipients certified under the DPF are permissible without SCC. The EU-US DPF applies in parallel for EU transfers.
SCC remain the safety belt: Where no adequacy exists (e.g. India, China, further countries without a decision), the EU SCC (Module 2 / 3) with Transfer Impact Assessment and supplementary measures are standard. The Swiss variant with FDPIC annex (FAQ of 27 August 2021) applies in parallel.
Swiss companies serving group functions in the EU (central IT, accounting, HR) benefit considerably from the adequacy decision. Caution, however, with onward transfers from Switzerland to the US or Asia, full third-country assessment remains required there, including Schrems II-compliant measures.
Operational steps for GDPR-compliant compliance
A GDPR-compliant Swiss setup consists of ten operational building blocks, integrated within a data protection management system.
- Written applicability test: Which processing operations fall under Art. 3 GDPR, which do not. Documented, board-approved.
- Appoint EU representative: With clear mandate, published in privacy notice and imprint.
- DPO / data protection advisor: Internal or external, qualified for GDPR and DSG. Notification to the FDPIC and (where mandatory) to the EU supervisor.
- Processing register (Art. 30 GDPR / Art. 12 DSG): Consolidated across all processing, annually updated.
- Dual privacy notice: DSG- and GDPR-compliant, with clear references to cross-border transfer, EU representative, remedies.
- AVV / DPA for all processors: Written, with sub-processor list, SCC where third-country.
- DPIA methodology: For high-risk processing (tracking, AI, profiling, biometrics).
- Breach playbook: 72h GDPR deadline, as soon as possible DSG, parallel notification channels.
- Training: Annually for board and staff. Special training for marketing and sales.
- Audit and review: Annually internally or externally, with update of all artefacts and risk matrix.
Experience: a mid-size SME needs 3–6 months for the build and 8–25 hours per month for ongoing operations. Without external support the setup often fails on methodology gaps and time scarcity, with support, 80–90 % of mandates reach auditable compliance in 6 months.
How SIDD supports you
SIDD is dual-qualified in Swiss and EU data protection law and runs parallel compliance under one roof. We take the function of EU Data Protection Officer under Art. 37 GDPR, the Art. 27 EU representation for Swiss companies without an EU establishment, and the function of Swiss data protection advisor under Art. 10 DSG, in an integrated mandate with a single SLA. For UK exposure we add UK Art. 27 representation.
For organisational depth we accompany the build of your data protection management system, including processing register, AVV landscape, DPIA methodology, breach playbook, training plan. On request we add privacy workshops for SMEs and the ISMS build to ISO 27001, which brings the GDPR data security requirements (Art. 32) to state of the art.
Write to us via the contact form or request a quote. We respond within one business day with a concrete proposal that maps DSG, GDPR and where relevant UK GDPR into a single compliance structure, including effort, timing and concrete deliverables.
