Swiss DSG vs EU GDPR, The 12 Most Important Differences for SMEs
Introduction
Swiss SMEs regularly ask me: «We comply with the GDPR, isn't that enough?» The answer is no. The revised Federal Act on Data Protection (DSG, in force since 1 September 2023) is not a Swiss copy of the GDPR. It is a stand-alone regulation that differs from the EU General Data Protection Regulation (GDPR, in force since 25 May 2018) on twelve material points. Anyone dual-regulated (Swiss companies with EU customers or EU employees) must run both regimes in parallel.
This article compares the twelve most important differences and shows what SMEs must watch out for. What you will take away:
- the structural differences between the two laws (scope, lawful bases, sanctions);
- the operational differences (breach windows, register, DPO duty);
- the substantive differences (profiling, automated individual decisions, cross-border transfers);
- a recommendation for setting up dual compliance pragmatically;
- the sources that matter for ongoing updates (EDÖB, EDPB).
Disclaimer: this article does not replace case-specific advice. It gives you the map you need to know where to look closer.
1–3: Scope, subject matter and definitions
Difference 1, territorial scope. Art. 3 DSG ties to effects in Switzerland: the DSG applies to facts that produce effects in Switzerland even if caused abroad. Art. 3 GDPR is similar (establishment principle + market location principle under Art. 3(2)), but structurally phrased differently. Practical consequence: a German company serving Swiss customers falls under both GDPR and DSG.
Difference 2, material scope. The DSG only protects personal data of natural persons under Art. 2(1), protection for legal entities was removed with the revision (previously different under the old DSG). The GDPR also only protects natural persons under Art. 1(1). Parity here now.
Difference 3, special categories of personal data. Art. 5 lit. c DSG defines a different list than Art. 9 GDPR: the DSG explicitly includes administrative or criminal sanctions and measures of social assistance, the GDPR handles criminal data separately in Art. 10. Genetic and biometric data for unique identification are specially protected in both regimes.
4–6: Lawful bases, consent and information
Difference 4, requirement of a lawful basis. The GDPR requires under Art. 6(1) one of six lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interest) for every processing. The DSG does not use this catalogue. Processing is generally permissible under the DSG, provided it respects the processing principles in Art. 6 DSG (good faith, proportionality, purpose limitation, data accuracy, data security). An explicit justification (Art. 31 DSG) is needed only where processing infringes personality, for example for special-category data or against the data subject's express will.
Difference 5, consent requirements. Art. 6(7) DSG requires «express» consent for special-category data, high-risk profiling, or profiling by federal bodies. Art. 7 GDPR is stricter: demonstrable, freely given, informed, unambiguous, with clear requirements for a «clearly affirmative act» per Recital 32.
Difference 6, duty to inform. Art. 19(2) DSG requires information at collection (identity, purpose of processing, where applicable recipients and third country). Art. 13 and 14 GDPR are more detailed (e.g. retention periods, legal basis, data source). In practice, you draft one privacy notice that satisfies both regimes.
7–9: Register, DPO and DPIA
Difference 7, register of processing activities. Art. 12 DSG requires a register, but Art. 24 DSV exempts companies with fewer than 250 employees, provided there is no extensive or high-risk processing. The GDPR regulates this similarly in Art. 30, but the Art. 30(5) GDPR exemption only applies if the processing poses no risk and is not extensive. In practice, from around 50 employees a register is mandatory anyway.
Difference 8, Data Protection Advisor (DSB) vs Data Protection Officer (DPO). Art. 10 DSG provides for a «Data Protection Advisor», voluntary for private controllers. With appointment and notification to the EDÖB, the duty to consult the EDÖB on high-risk DPIAs falls away (Art. 23(4) DSG). The GDPR makes the DPO mandatory in Art. 37 GDPR for public authorities, core activities involving extensive regular monitoring, or extensive processing of special categories.
Difference 9, Data Protection Impact Assessment. Art. 22 DSG requires a DPIA where processing brings a high risk. Art. 35 GDPR is similar in wording, though the EDPB has more detailed guidance (e.g. WP 248). Outcome-wise the two regimes converge.
10–12: Breach reporting, transfers and sanctions
Difference 10, breach notification. Art. 24 DSG requires notification to the EDÖB «as soon as possible» where there is a high risk to the data subject, no rigid 72-hour deadline as in Art. 33 GDPR. The EDÖB's practice interprets this as «within 72 hours of the controller becoming aware». Substantively similar, formally different.
Difference 11, third-country transfers. Art. 16–18 DSG require adequate protection in the recipient country. Art. 8 DSV regulates the recognition by the Federal Council (country list). Schrems II shapes both regimes: for non-recognised countries, contractual safeguards (Swiss SCC/EU SCC), a transfer impact assessment and, where necessary, supplementary measures are required. Switzerland recognised the EU-CH Data Privacy Framework on 15 September 2024, transfers to DPF-certified US recipients are permitted since then without SCC.
Difference 12, sanctions. This is the biggest substantive difference. Art. 60–66 DSG provide for criminal sanctions against natural persons (responsible members of management), up to CHF 250,000. The GDPR provides for administrative fines against the company, up to EUR 20 million or 4% of global annual turnover (Art. 83 GDPR). Personal criminal liability in Switzerland places the executive board directly on the hook.
Practical consequences for dual-regulated SMEs
In practice the two regimes can be handled through three strategies:
- Highest common denominator: all processes are set up to GDPR standard (lawful basis required, 72h breach window, detailed information duty), because DSG compliance is then automatically met. Recommended for SMEs with material EU business.
- Per processing purpose: activities with EU nexus (e.g. webshop for DE/AT/FR) are set up GDPR-compliant, while purely internal Swiss processing (e.g. Swiss employees) is set up DSG-compliant. Advantage: less overhead for purely national operations. Disadvantage: two rule sets in parallel.
- Consolidated Privacy Information Management System with a documented mapping matrix Art. DSG ↔ Art. GDPR. Recommended from around 200 employees or when seeking ISO 27701 certification. The matrix is built once and referenced per processing activity in the ROPA.
Critical pitfalls we frequently see in practice:
- privacy notice satisfies the GDPR but not all DSG requirements (or vice versa);
- DPA template only covers GDPR sub-processors, Swiss sub-processors missing;
- the DPO is appointed internally but not notified to the EDÖB, the DSG privilege (Art. 23(4)) then does not apply;
- breach reporting paths only target the lead supervisory authority of the head office, not also the EDÖB and the Lead Supervisory Authority.
Special topics: profiling, processing, EU representative
Profiling and automated individual decisions. Art. 19(3) and Art. 21 DSG cover «high-risk profiling» and «automated individual decision-making», with a duty to inform and the data subject's right to express their view. Art. 22 GDPR is stricter: a general prohibition on fully automated decisions with legal effect, except under contract, legal authorisation or explicit consent. Anyone deploying AI-supported credit scoring, automated recruiting or dynamic pricing must assess both regimes separately, and additionally the EU AI Act (EU 2024/1689) for high-risk systems in Annex III.
Processing on behalf. Art. 9 DSG requires for outsourcing the same duties as Art. 28 GDPR: written contract (DPA), ensuring data security, sub-processor authorisation, support duties for data subject rights and data breaches. The EDÖB's Swiss template clauses closely mirror the EU SCC.
EU representative and CH representative. Art. 14 DSG requires controllers established abroad to appoint a representative in Switzerland when extensively or regularly processing data of persons in Switzerland. Art. 27 GDPR mirrors this with the EU representative duty. We offer both functions: EU representative per Art. 27 GDPR.
How SIDD supports you
SIDD specialises in dual DSG/GDPR compliance. We analyse your processing activities, identify the overlap between regimes and deliver a consolidated compliance architecture that meets both laws at once, without duplicated work. Our consultants serve both as Data Protection Advisor (DSB) under Art. 10 DSG and as Data Protection Officer (DPO) under Art. 37 GDPR.
Typical mandates: building a ROPA that mirrors both regimes; reworking the privacy notice for CH/EU websites; third-country strategy under the DPF (CH and EU); standardising DPAs across all suppliers; EU representative mandate per Art. 27 GDPR or UK representative for Swiss companies without an EU/UK establishment; awareness workshops for employees: data protection workshops.
Would you like to know where your organisation stands on dual compliance? Request a non-binding quote or contact us via the contact form. A 30-minute initial call is enough to sketch the right compliance strategy.
