# Swiss Privacy Policy – DSG-Compliant Generator 2026

> Privacy policy under the FADP: what Art. 19 FADP requires, extra duties for automated individual decisions and when the GDPR also applies.

- Source: https://www.sidd.swiss/en/insights/swiss-privacy-policy-generator/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Dr. Dominic Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

With the entry into force of the revised Federal Act on Data Protection (DSG) on 1 September 2023, the duty to inform data subjects in Switzerland changed structurally. Art. 19 DSG requires adequate, precise and intelligible information about every collection of personal data, not only about specially protected categories. A privacy policy is therefore no longer an optional add-on but mandatory information: a controller who collects personal data without one violates Art. 19 in conjunction with Art. 60 DSG and risks both private criminal complaints and a supervisory procedure of the Federal Data Protection and Information Commissioner (FDPIC / EDÖB). A generator helps Swiss SMEs cover every mandatory item, provided it correctly addresses the DSG, where applicable the GDPR, and the Swiss Telecommunications Act.

This article explains what an DSG-compliant generator in 2026 must deliver:

- the mandatory disclosures Art. 19 para. 2 DSG imposes;
- the additional duties for automated individual decisions (Art. 21 DSG);
- when GDPR mandatory items under Art. 13/14 GDPR must also be supplied;
- how recipient categories and third-country transfers (Art. 16/17 DSG) should be documented cleanly;
- which generator features add real value over a static template;
- how SIDD couples the privacy policy to the internal records of processing under Art. 12 DSG.

Treating the text as a compliance artefact, not as a marketing footer, eliminates two thirds of the typical FDPIC findings.

## What Art. 19 DSG strictly requires

Art. 19 para. 2 DSG sets out the mandatory disclosures exhaustively but tersely. At minimum the policy must contain (a) the identity and contact details of the controller, (b) the purpose of processing, and (c) where applicable the recipients or categories of recipients to whom personal data are disclosed. Where data are exported abroad, Art. 19 para. 4 DSG adds the recipient country and the safeguards under Art. 16 para. 2 DSG (Federal Council adequacy decision, standard contractual clauses, binding corporate rules) or the derogation under Art. 17 DSG. Where data are not collected directly from the data subject, the categories of data must additionally be named (Art. 19 para. 3 DSG).

Compared to Art. 13 GDPR, the DSG omits three items that a good generator should nonetheless offer as configurable blocks, because they regularly apply: the storage period or the criteria for determining it, the legal basis, and an explicit mention of data-subject rights. The latter are granted by Art. 25-29 DSG in any event; naming them in the policy nonetheless improves intelligibility and substantially reduces ambiguous access requests.

Practically relevant: the requirement of "adequate information" in Art. 19 para. 1 DSG is a substantive criterion. A twelve-page policy in dense legalese does not satisfy it, the FDPIC has clarified in its FAQ on the duty to inform that short, well-structured texts with clear headings are preferred. A generator should therefore set section headings automatically and normalise output to 1,200-2,500 words.

## Additional duties for automated individual decisions

Art. 21 DSG tightens the duty to inform for every automated individual decision that produces legal effects or significantly affects the data subject. The controller must inform the data subject of the fact of the automated decision and, on request, hear the data subject's position and provide a review by a natural person. Anyone deploying AI-supported credit-scoring, pricing or HR-scoring systems must name this explicitly in the privacy policy. A bare "we use algorithms" sentence does not suffice.

An DSG-compliant generator in 2026 must hold dedicated building blocks for such scenarios that, at minimum, describe (1) the field of application (credit, recruitment, insurance tariffs), (2) the logic in broad terms, (3) the scope and consequences, and (4) the right to challenge. With the EU AI Act, whose GPAI duties have applied since 2 August 2025 and whose high-risk regime takes effect on 2 August 2026, this transparency requirement gains additional weight, including for Swiss providers serving EU markets. The FDPIC has repeatedly pointed out in its activity reports that high-risk profiling under Art. 22 lit. f DSG triggers a prior data-protection impact assessment (DPIA) whose outcome must be documented internally.

In practice we recommend reserving a separate paragraph per profiling application in the generator, covering purpose, logic description, impact and objection channel, and mirroring the same fields in the internal [records of processing](https://www.sidd.swiss/einblicke/avv-auftragsbearbeitungsvertrag-schweiz).

## When the GDPR additionally applies

Swiss businesses fall under the GDPR in addition to the DSG as soon as they offer goods or services to data subjects in the EU/EEA or monitor their behaviour there, pursuant to Art. 3(2) GDPR. An online shop that ships to Germany; a SaaS provider with EU users; a newsletter that deliberately targets EU readers, each triggers the marketplace principle. The privacy policy must then additionally cover the mandatory items of Art. 13/14 GDPR, in particular the legal basis per processing operation (Art. 6 GDPR), the storage period, the data-subject rights (Art. 15-22 GDPR), the right to lodge a complaint with an EU supervisory authority, and the contact details of the Art. 27 GDPR EU representative.

A good generator detects this configuration and switches on the GDPR-specific building blocks automatically, producing a single combined document rather than two parallel versions. Important: the identity and contact details of the EU representative must come from an active mandate, not a placeholder address. Anyone who has not yet appointed a representative will find a packaged mandate at SIDD under [EU representative under Art. 27 GDPR](https://www.sidd.swiss/en/services/eu-representative). For the UK market Art. 27 UK GDPR applies in parallel; see our service [UK representative](https://www.sidd.swiss/en/services/uk-representative).

Without this multi-jurisdictional awareness, a GDPR-blind generator produces a policy that counts as incomplete in the EU, with fines of up to EUR 20 million or 4 % of global group turnover.

## Recipients, processors and third-country transfers

Art. 19 para. 2 lit. c DSG requires naming the recipients or categories of recipients. In practice the category approach has prevailed, e.g. "cloud hosting providers", "payment service providers", "newsletter dispatch", "accounting fiduciary". The FDPIC accepts categories as long as they are sufficiently specific. "Third parties" or "business partners" without further delimitation is not enough.

For third-country transfers under Art. 16 DSG, the generator must distinguish: is the recipient country on the list of adequate states (Annex 1 of the DPO, including the EU/EEA, the UK, Canada and Israel)? If yes, naming the country suffices. If no (typically the USA without active certification under the Swiss-U.S. Data Privacy Framework, India, many APAC countries), the safeguard under Art. 16 para. 2 DSG must be specified, usually the Swiss standard contractual clauses (FDPIC-recognised version of 27 August 2021 in combination with the EU SCCs). For the USA, transfers to recipients certified under the Swiss-U.S. DPF have been permissible without SCCs since 15 September 2024, the generator must check this per recipient.

Processors are not a separate recipient category but legally remain the controller's "extended arm" (Art. 9 DSG). They must nonetheless be named transparently because they de facto receive access. Sub-processing, audit rights and deletion duties belong in the data-processing agreement, not in the privacy policy, see our article on [Swiss DPA templates](https://www.sidd.swiss/einblicke/avv-auftragsbearbeitungsvertrag-schweiz).

## What a good generator delivers beyond a template

A static Word template ages from the day it is downloaded. A generator can translate structured inputs into a versioned HTML output that is coupled to the internal records of processing (Art. 12 DSG). Concretely, four features form what we consider the 2026 minimum standard:

1. **Modules instead of flowing prose.** One module per recipient, purpose and third-country transfer, importable from the records of processing.
2. **Versioning with effective date.** Every change produces a new version with an effective date, essential for access requests under Art. 25 DSG.
3. **Synchronised multilingualism.** German, French, Italian and English versions must carry identical content. In disputes the contract-language version prevails.
4. **Canton / industry switches.** Banks (FINMA banking secrecy), hospitals (cantonal patient-data acts), law firms (BGFA) and cantonal authorities (IDG/IDAG) require additional clauses that a generic generator cannot supply.

The extra cost over a template pays off at the first access request: a versioned document evidentially shows which information the data subject received at the time of collection, a key piece of evidence in any FDPIC procedure.

## Typical mistakes and how to avoid them

From more than 200 SIDD audits in 2024-2025, six recurring mistakes stand out:

- **Copy-paste from German GDPR templates**, references to "Art. 6(1) GDPR" look misplaced in a purely Swiss context and create confusion about the applicable legal order.
- **Cookie banner and privacy policy inconsistent**, the banner lists tools missing from the policy, or vice versa. See our article on [Cookie banners in Switzerland](https://www.sidd.swiss/einblicke/cookie-banner-schweiz).
- **Third-country transfers worded too vaguely**, "worldwide" or "in all countries of the world" is not a permissible disclosure.
- **No EU representative named** although the online shop demonstrably ships into the EU.
- **Outdated references to the old DSG** with article numbering predating 1 September 2023.
- **Profiling / AI not mentioned** although an automated scoring tool runs in the background.

Anyone using a generator should perform a plausibility check against the current records of processing at least once a year, and mandatorily on each new processor, third-country transfer or newly introduced profiling system.

## How SIDD supports you

SIDD operates a web-based generator that merges the DSG mandatory items from Art. 19, 21 and 22 with, where required, the GDPR contents of Art. 13/14 into a single, versioned document. The generator pulls recipients, purposes and processors directly from the records of processing maintained in the [Priverion platform](https://www.sidd.swiss/en/priverion-platform), eliminating inconsistencies between register and policy. Multilingual outputs (DE/FR/IT/EN) are kept in sync; every change produces a new version with an effective date.

For SMEs without an in-house data protection officer we bundle the generator with an external DPO mandate under [Swiss data-protection advisory](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland). Companies that are additionally GDPR-bound add [GDPR DPO services](https://www.sidd.swiss/en/services/data-protection-officer-eu) and an [EU representative](https://www.sidd.swiss/en/services/eu-representative). A free first assessment of your existing privacy policy is available via [our contact form](https://www.sidd.swiss/en/contact); for a concrete quote on drafting or migration, use the [quote request](https://www.sidd.swiss/en/quote). We typically deliver a first draft aligned with your records of processing within 10 business days.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
