Swiss Privacy Policy Generator: Free Online Builder

6 min readLast updated By Marc Grob

Introduction

Anyone who needs a privacy policy in Switzerland in 2026, for a website or app, has two structurally different routes: a free online builder that produces a PDF from multiple-choice answers, or an integrated generator that feeds the privacy policy from the internal records of processing (Art. 12 DSG). The first route suits micro-businesses with a single processing context; the second is standard for SMEs with several processors, multiple languages and a shifting tool landscape. This article addresses managing directors, marketing leads and internal data-protection coordinators who need to choose between these options.

We cover in this article:

  • the mandatory items of an DSG-compliant privacy policy as input fields for any generator;
  • the typical functional gaps of free builders compared with paid solutions;
  • when the GDPR additionally applies and which generator configuration that requires;
  • how generator output is kept in sync with the records of processing under Art. 12 DSG;
  • the audit trail: why a versioned privacy policy is evidentially relevant in FDPIC procedures;
  • a concrete checklist that lets you assess any generator in 15 minutes.

The core thesis: the "generator" is not the product. The product is the versioned compliance artefact linked to the records of processing, the generator is merely the tool that produces it.

What a 2026 privacy policy must contain

The mandatory items derive from Art. 19 para. 2 DSG: identity and contact details of the controller, purpose of processing, and where applicable the recipients or categories of recipients. Where data are exported abroad, Art. 19 para. 4 DSG adds the recipient country and the safeguards under Art. 16 para. 2 DSG. Where data are not collected directly from the data subject, Art. 19 para. 3 DSG additionally requires naming the categories of data. A full list of the mandatory items with practical examples is in our article on Swiss privacy policy contents.

Anyone who addresses persons in the EU/EEA or monitors their behaviour (Art. 3(2) GDPR) additionally needs the mandatory items from Art. 13/14 GDPR: legal basis, storage period, data-subject rights under Art. 15-22 GDPR, the right to lodge a complaint with an EU supervisory authority, and the contact details of the Art. 27 GDPR EU representative. A good generator switches these building blocks on automatically when required.

Industry-specific additions are not covered by Art. 19 DSG but are mandatory in practice: banks need references to banking secrecy and the FINMA reporting duty under Art. 29 FINMASA, hospitals to the cantonal patient-data acts, law firms to Art. 13 BGFA. A generic builder cannot supply these specifics and delivers incomplete text in regulated industries.

What free builders typically cannot do

A free generator-builder produces a draft text in five minutes, and this is precisely its limit. From more than 200 SIDD audits in 2024-2025 we see recurring gaps: (1) no versioning with an effective date, (2) no synchronisation with records of processing, (3) no multilingualism that guarantees identical content across DE/FR/IT/EN, (4) no industry switches for regulated sectors, (5) no automatic updates when legal requirements change, and (6) no audit trail evidencing which text was in force at the time of a data collection.

There is a subtler problem too: many free builders monetise through affiliate links to hosting, cookie or analytics providers. This leads to texts that recommend or pre-install these tools in the privacy policy, even where the customer is not actually using them. The result: a policy that lists more tools than the business actually deploys is factually incorrect and may, in a damage case, support an accusation of misleading practice under Art. 3 lit. b UWG (Federal Act against Unfair Competition).

Our recommendation: a free builder is fine for a purely informational first draft. As soon as a website carries more than three processors, a second language or regulatorily sensitive content (credit, health, recruitment), it is worth switching to an integrated solution.

When a GDPR-capable generator is necessary

The marketplace principle under Art. 3(2) GDPR catches Swiss providers as soon as they actively address EU data subjects, for example through DE/FR language versions with EU pricing, shipping to Germany, or targeted search-engine advertising in the EU. Monitoring is enough too: advertising cookies of a third-country provider that track EU users on a Swiss website also trigger GDPR application. Anyone who fails to model this in the generator risks proceedings by the competent EU supervisory authority, typically the one in the country of the principal target market.

A GDPR-capable generator must additionally provide four modules: (1) the legal basis per processing operation with reference to Art. 6 or Art. 9 GDPR; (2) the reference to the Art. 27 GDPR EU representative (identity, contact, mandate basis); (3) the data-subject rights with a GDPR anchor, in particular the right to data portability under Art. 20 GDPR which has no direct DSG equivalent; (4) the right to lodge a complaint with an EU supervisory authority, naming the typically competent authority of the customer's country of residence. For UK customers in parallel: Art. 27 UK GDPR via our UK representative.

Anyone who has not appointed an EU representative cannot complete the privacy policy. We package that mandate under EU representative under Art. 27 GDPR.

Synchronisation with the records of processing

Art. 12 DSG (in conjunction with Art. 24 ff. of the DPO) requires every controller to maintain records of processing that document, per processing activity, the purpose, data categories, recipients, retention and where applicable third-country transfers. These same fields form the input grid of a good privacy policy. An integrated generator therefore applies a simple principle: the single source of truth is the records; the privacy policy is a curated view of them.

Concretely, introducing a new processor, for example a newsletter service, triggers three steps in one workflow: (1) entry in the records (Art. 12 DSG), (2) conclusion of a data-processing agreement under Art. 9 DSG, (3) automatic extension of the privacy policy by the recipient category "newsletter dispatch". Anyone running these three steps manually loses synchronicity in 9 out of 10 cases within 12 months.

The SIDD solution treats the records and the privacy policy as two views of the same data model. Details on the DPA component are in our article on Swiss DPA / data-processing agreements.

Audit trail and versioning as proof of compliance

The privacy policy is a compliance artefact, not a marketing text. On an access request under Art. 25 DSG, in an FDPIC procedure, or in a civil damage claim for inadequate information, the controller must evidence which information the data subject received at the time of data collection. A versioned privacy policy with an effective date, diff against the previous version and traceable change history is central here.

A good generator therefore maintains:

  1. Version number and effective date on every publication.
  2. Diff against the previous version for internal reviews and approval workflows.
  3. Archived PDF snapshots of all historical versions, at least 10 years.
  4. Synchronised multilingual publication, with a documented consistency check.
  5. Approval workflow with a four-eyes principle before publication.

These five features lift an integrated generator above any free builder. In an FDPIC procedure under Art. 49-53 DSG they are the difference between a quickly rebutted assertion and an evidenced compliance programme.

Checklist: assess any generator in 15 minutes

When choosing among generator offers, check the following 12 points. A serious provider satisfies at least 10:

  • Full coverage of Art. 19 paras. 2-4 DSG (identity, purpose, recipients, third country).
  • Module for profiling and automated individual decisions (Art. 21 DSG).
  • Optionally enabled GDPR building blocks (Art. 13/14 GDPR).
  • Records-of-processing synchronisation, or at minimum import/export to Art. 12 DSG records.
  • Multilingual output DE/FR/IT/EN with documented consistency check.
  • Versioning with effective date and PDF archiving.
  • Industry switches for banks, hospitals, lawyers, authorities.
  • EU representative block tied to an active mandate, not a placeholder.
  • Third-country logic distinguishing adequacy list vs. SCCs vs. DPF certification.
  • Cookie-banner integration for consistency between banner and policy.
  • Four-eyes approval before publication.
  • Clear separation between editorial text and mandatory legal information.

A provider that meets all 12 points offers an integrated compliance product. One that meets 4 or fewer offers a pure text builder.

How SIDD supports you

As part of the Priverion platform, SIDD offers an integrated privacy-policy generator that covers all 12 checklist points. The privacy policy is fed from the records of processing under Art. 12 DSG, automatically versioned, delivered in synchronised multilingual versions and linked to the concluded data-processing agreements. Changes to a processor propagate in a single workflow through records, DPA inventory and privacy policy.

For SMEs without an in-house data protection officer we combine the generator with an external DPO mandate under Swiss data-protection advisory. Where the GDPR additionally applies we add GDPR DPO services and an EU representative. If you are unsure which solution fits your need, book a 30-minute first call via our contact form. For a concrete fixed-price proposal, including an initial inventory of your records and migration of an existing privacy policy, use our quote request. We typically deliver the first production-ready version within 10 business days.

Need help putting this into practice? SIDD operates the matching service.
See service →

Swiss Privacy Policy Generator: Free Online Builder

INSIGHT

Data Protection
24 May 2026
Marc Grob
Privacy policy generators for Swiss websites: what free builders deliver, when you need more and how a record of processing activities helps.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.