Swiss Privacy Policy, Everything That Belongs in It in 2026
Introduction
Since 1 September 2023, the privacy policy is no longer a goodwill gesture but a hard duty under Art. 19 and 20 DSG. Anyone collecting personal data, and practically every website or app operator does, must inform data subjects in advance about specific minimum content. Breaches can lead to fines up to CHF 250,000 against the natural person responsible under Art. 60 DSG and, where the GDPR applies in parallel, to additional fines up to 4% of global turnover or EUR 20 million under Art. 83 GDPR.
For 2026 this guide covers:
- The mandatory content under Art. 19(2) DSG
- Extensions for special constellations (third-country transfer, automated individual decision, profiling)
- Multilingual handling and linguistic clarity
- The crossover case: Swiss policy with parallel GDPR duty (Art. 13/14)
- Practical structure and maintenance
- Typical defects in FDPIC proceedings
We also show how to build the policy modularly so it stays maintainable and grows cleanly with every new processing activity or service provider.
Mandatory content under Art. 19 DSG
Art. 19(2) DSG requires at least the following:
- Identity and contact details of the controller
- Purpose of processing
- Categories of recipients (specific recipients where appropriate)
In plain language: you must at minimum say who you are, why you use the data and to whom you potentially disclose it. The scope is broad, the duty applies to any collection of personal data, which is well beyond websites: newsletter sign-ups, contact forms, app installs, logins, job applications, supplier questionnaires.
Three additional duties arise where applicable:
- Third-country disclosure under Art. 19(4) DSG: where data is transferred to a country without an adequate level of protection, you must additionally state (a) the country or international body and (b) the safeguards under Art. 16 DSG (e.g. standard contractual clauses).
- Automated individual decision under Art. 21 DSG: where decisions with legal effect or significant impact are made by automated evaluation, you must disclose that and inform the person of their right to human review.
- Special case ‘collection from a third party’: Art. 19(3) DSG additionally requires the categories of data.
The policy must be available before collection, in understandable form, in a location easily accessible to data subjects.
Recommended extended content
Beyond the legal minimum, we recommend the following content, because it is required by other DSG duties or by FDPIC supervisory practice:
- Categories of processed personal data and their sources
- Retention and deletion periods per data category (derived from the record of processing under Art. 12 DSG)
- Data security measures (in a summary that laypersons can understand)
- Data subject rights under Art. 25 et seq. DSG (access, rectification, erasure, data portability, restriction, objection) and the complaint route to the FDPIC
- Cookies and similar technologies (tracking pixels, local storage, fingerprinting), with separation of technically necessary and ‘marketing’ cookies; link to the consent manager
- Specific processing activities: newsletter (provider, tracking), web analytics (tool, IP truncation), advertising pixels (provider), chatbots (AI provider), recruitment (ATS, retention)
- Identification of the in-house data protection advisor under Art. 10 DSG if appointed
- Version and change notice with date (‘as of …’)
These items have been standard under EU practice since Art. 13/14 GDPR, anyone who already maintains a GDPR-compliant policy effortlessly meets Art. 19 DSG.
Multilingual handling and clarity
Switzerland has four official languages, but the DSG policy does not have to exist in all four. It must exist in the language in which the service is offered. Concretely:
- If your website is available in German, French and English, the policy must be in all three, each on the corresponding language version.
- If you appear only in German, German is sufficient.
- English-only policies on a German-language website do not satisfy the duty, the FDPIC has repeatedly clarified in annual reports that language clarity is mandatory.
Clarity under Art. 19(1) DSG additionally requires that the policy is written in a language the average data subject can understand. Excessively legalistic sentences with nested clauses are not compliant. We recommend a layered structure: a short version (TL;DR) at the top, then the structured detail. In B2B contexts (e.g. platforms with professional users), language can be slightly more formal; in B2C settings it must be lay-friendly, when in doubt, read-test against secondary-school readers.
Interface DSG ↔ GDPR Art. 13/14
Many Swiss companies process under both DSG and GDPR as soon as they address or monitor data subjects in the EU (Art. 3(2) GDPR). In that case both information duties must be met. Art. 13/14 GDPR is the more demanding, additionally it requires:
- Contact details of the DPO (where appointed)
- Legal bases per processing activity (Art. 6 GDPR) including the legitimate interest where applicable
- Recipients (as specific as possible, not only by category)
- Third-country transfers with concrete identification of the recipient, safeguards and means to obtain the safeguards
- Retention period or criteria
- Data subject rights under Art. 15–22 GDPR including consent withdrawal and the right to lodge a complaint with the supervisory authority
- Where profiling or automated decisions exist: meaningful information about the logic, significance and consequences (Art. 13(2)(f), Art. 22)
In practice, write one policy that satisfies both regimes. The Art. 13/14 GDPR extensions cause no harm in a pure DSG world, they are only additional. Do not artificially split ‘EU processing’ from ‘non-EU processing’; the benefit is small, maintenance is higher.
Structure and maintenance
A maintainable privacy policy emerges from a modular build. The following structure has proved itself:
- Identity of the controller and contact details
- DPO / data protection advisor (where applicable) and EU representative (if required)
- Summary of processing (TL;DR)
- Individual processing activities (one section per business process: contact form, newsletter, account, recruitment, web analytics, advertising, chatbot etc.)
- Recipients and processors with third-country tagging
- Retention period / deletion concept
- Data security (summary)
- Data subject rights and complaint route
- Automated individual decisions and profiling (if applicable)
- Changes and version date
Link the policy to your internal record of processing: every new processing entry triggers a policy update. A quarterly review covers 95% of update needs. When the vendor stack changes, new AI provider, new tracker, update immediately and mark the version.
Typical defects in FDPIC proceedings
The same weaknesses appear repeatedly in FDPIC proceedings and annual reports:
- Generic templates with no link to the actual processing stack, listing cookies and providers the company does not use, or the reverse: trackers run but are not mentioned.
- Third-country disclosure missing or incomplete: ‘we use cloud services in the US based on standard contractual clauses’, without a route to obtain the SCCs and without a transfer impact assessment in the background.
- Cookies / trackers without separation of technically necessary vs. marketing, without a consent banner offering genuine choice, without retention periods for each cookie.
- Data subject rights not mentioned or generic only (‘you have rights’), without concrete guidance on whom to contact.
- Outdated templates referencing the 1992 DSG, missing the new rights (in particular data portability under Art. 28 DSG).
- Language problems: policy only in English although the website is primarily German.
Each of these is a separate finding and compounds into an aggravated penalty. In 2024 the FDPIC explicitly addressed the criminal fines under Art. 60 DSG for the first time; the trend points to growing enforcement.
How SIDD supports you
SIDD drafts and maintains legally compliant privacy policies covering both DSG (Art. 19/20) and GDPR (Art. 13/14), linked to your record of processing. Through our Swiss data protection advisory we run the initial drafting, the mapping to your services and providers and the annual refresh. Where you also process under the GDPR, we add the GDPR DPO function and, where Art. 27 GDPR applies, the role of EU representative.
To train marketing, product and web teams so that future updates flow through cleanly, our privacy workshops are available. A first baseline check of your current policy comes via the contact form; a fixed-price proposal for a new draft or revision, including multilingual handling and a cookie audit, comes via the offer.
