Privacy Policy Template, Mandatory Content Under DSG 2026
Introduction
A privacy policy is, at its core, mandatory information under Art. 19 DSG. While our sister articles cover the choice of a generator and the structure of a complete template, this article proceeds field by field: for every statutory disclosure we provide the legal anchor, a practical comment and a formulated example block that you can lift into your privacy policy. Anyone who does not use a generator and works with a Word template instead will find the copy-paste-ready building blocks here.
The following sections cover:
- identification of the controller (Art. 19 para. 2 lit. a DSG);
- the processing purpose with concrete wording per purpose class (Art. 19 para. 2 lit. b DSG);
- the recipients / categories of recipients (Art. 19 para. 2 lit. c DSG);
- third-country transfers with country and safeguard (Art. 19 para. 4 in conjunction with Art. 16/17 DSG);
- mandatory disclosures on indirect data collection (Art. 19 para. 3 DSG);
- automated individual decisions and profiling (Art. 21 DSG);
- data-subject rights as a de facto mandatory item (Art. 25-32 DSG).
Anyone who tests an existing privacy policy against this list typically finds at least three gaps, most often around third-country transfers, profiling and the EU representative.
Identification of the controller (Art. 19 para. 2 lit. a DSG)
The controller is the natural or legal person who alone or with others decides on the purposes and means of processing (Art. 5 lit. j DSG). The mandatory disclosure under Art. 19 para. 2 lit. a DSG requires identity and contact details. "Identity" means in practice: full company name including legal form, registered seat and ideally UID number. "Contact details" means: at least one electronic communication channel (e-mail or web form), a postal address and, where available, a phone number.
Example block:
"The controller within the meaning of the Swiss Federal Act on Data Protection (DSG) is [Full Company Name AG], [Street No.], [Postcode City], Switzerland, registered in the commercial register of the canton of [XY] under UID CHE-XXX.XXX.XXX. Please direct data-protection enquiries to privacy@[company].ch or by post to the address above."
Those who have appointed a data-protection adviser under Art. 10 DSG add their name and contact. For GDPR-bound companies established outside the EU/EEA, the EU representative under Art. 27 GDPR is added with its own address (see our service EU representative). A group constellation with several legally separate controllers requires a clear allocation; blanket wording such as "the XYZ group" is insufficient.
Processing purpose (Art. 19 para. 2 lit. b DSG)
The purpose must be specific and not too general. "Business operations" is not a permissible purpose. A sensible granularity is 5-10 purpose classes per SME. Typical purpose classes:
- Contract initiation and performance (quotes, orders, delivery, invoicing).
- Customer service (support requests, complaints, warranty cases).
- Marketing and newsletter with separation existing customer vs. new-customer outreach.
- HR management (applications, employment, payroll).
- Website operations and security (log files, DDoS defence, technical reach measurement).
- Accounting and taxes (mandatory under Art. 957 ff. of the Swiss Code of Obligations).
- Legal defence (evidence preservation, dunning, claim assignment).
Example block for purpose class 1:
"We process your contact data (name, address, e-mail, phone), order data (selected products, quantities, prices) and payment data (payment method, booking reference) in order to respond to your enquiries and to conclude and perform contracts with you. The processing is based on contract initiation or performance and on our legitimate interest in efficient business operations."
For GDPR-bound companies, add the legal basis under Art. 6(1)(b)/(f) GDPR and the specific storage period (e.g. "10 years under Art. 958f CO").
Recipients and categories of recipients (Art. 19 para. 2 lit. c DSG)
Art. 19 para. 2 lit. c DSG requires naming the recipients or categories of recipients. The recipient-category approach has proven itself in practice, it significantly reduces the update burden without sacrificing transparency, provided the categories are sufficiently specific. "Third parties" or "business partners" is not specific enough; "payment service providers", "cloud hosting", "e-mail dispatch service" satisfy the requirement.
Example block:
"We disclose your personal data to the following categories of recipients:
- cloud hosting providers (for application and data operations);
- e-mail dispatch service (for transactional e-mails and newsletters);
- payment service providers (for online payment processing);
- accounting fiduciary (for mandate processing);
- logistics providers (for shipping ordered goods);
- authorities and courts (where we are legally obliged or where necessary for legal defence)."
Processors (Art. 9 DSG) are not "recipients" in the strict sense because they act only as the controller's extended arm; they must nevertheless be named because they de facto receive access. Contractual binding occurs via the DPA (see Swiss DPA template).
Third-country transfers (Art. 19 para. 4 DSG)
On any export abroad, Art. 19 para. 4 DSG requires naming the recipient country and the safeguard under Art. 16 para. 2 DSG. The duty applies regardless of whether the export goes to a legally separate recipient or to a processor inside the group. The safeguards are set out in Annex 1 of the DPO (list of adequate states), Art. 16 para. 2 DSG (standard contractual clauses, binding corporate rules, codes of conduct) and Art. 17 DSG (derogations for individual cases).
Example block:
"Individual recipients are located in countries outside Switzerland and the European Economic Area. This concerns in particular:
- USA: cloud hosting providers certified under the Swiss-U.S. Data Privacy Framework (valid since 15 September 2024) or, in the absence of certification, safeguarded by the FDPIC-recognised standard contractual clauses of 27 August 2021;
- United Kingdom: adequate level of protection under Annex 1 of the DPO;
- other countries without recognised adequate protection: exclusively on the basis of standard contractual clauses and after a prior risk assessment."
Blanket formulations such as "worldwide" or "in all countries where our service providers are located" do not satisfy Art. 19 para. 4 DSG. Those who lack an overview of actual third-country transfers should build it from the records of processing (Art. 12 DSG).
Profiling and automated individual decisions (Art. 21 DSG)
Art. 21 DSG applies to every solely automated decision with legal effect or significant impact. Classic use cases: credit assessment with a score threshold, insurance pricing classification, applicant screening by an AI system, automated blocking of accounts on fraud suspicion. Anyone deploying such a system must, in the privacy policy, name the existence of an automated individual decision, point to the right to be heard and to human review, and explain the essential logic in broad terms.
Example block:
"When granting credit from CHF 5,000 upwards we deploy an automated creditworthiness check. Based on income, payment history and demographic data the system calculates a risk score and decides automatically, on crossing defined thresholds, on approval or rejection. You have the right at any time to request a human review of this decision and to present your point of view. To do so, contact credit@[company].ch."
A prior data-protection impact assessment under Art. 22 DSG is mandatory for any profiling with high risk (Art. 22 lit. f DSG), and the outcome must be documented internally. With the EU AI Act, these transparency requirements gain additional weight, in particular for high-risk systems from 2 August 2026.
Data-subject rights as a de facto mandatory item
Although Art. 19 DSG does not expressly list data-subject rights as a mandatory item, naming them is market standard and is treated by the FDPIC in practice as part of "adequate information". The content to cover is:
- Right of access under Art. 25 DSG with a 30-day response deadline (Art. 25 para. 7 DSG) and an option to extend by a maximum of 60 further days in justified cases.
- Right of rectification of inaccurate personal data (Art. 32 para. 1 DSG).
- Right of destruction or deletion (Art. 32 para. 2 DSG), with statutory retention duties (CO, tax law) taking precedence.
- Right to object to processing with an overriding legitimate interest (Art. 30 para. 2 lit. b DSG).
- Right to data hand-out and transfer under Art. 28 DSG (new in the revised act, Swiss equivalent of data portability).
- Right to lodge a complaint with the FDPIC under Art. 49 DSG.
Example block (short form):
"You have the right vis-à-vis us to access, rectification, deletion, objection and data hand-out and transfer. Please direct such requests in writing to privacy@[company].ch, we respond within 30 days. For complaints you may contact the FDPIC (www.edoeb.admin.ch)."
How SIDD supports you
SIDD provides the building blocks commented here as a compilable master template, on request via our contact form. For companies with several processors, third-country transfers or profiling systems, we recommend not maintaining the privacy policy as a static document but feeding it from the records of processing (Art. 12 DSG). This guarantees synchronicity between actual processing and published text, and reduces the risk that a privacy policy is qualified as incomplete or misleading in an FDPIC procedure.
Our central service for this is the mandate as external data-protection adviser under Swiss data-protection advisory, complemented by the Priverion platform for ongoing operational maintenance. We bundle GDPR-bound companies with GDPR DPO services and an EU representative. For a free 60-minute first assessment of your existing privacy policy use the contact form; for a concrete fixed-price mandate to fully redraft, use the quote request.
