Swiss Privacy Policy Template (DSG 2026, Free)

7 min readLast updated By Dominic Staiger

Introduction

Anyone creating a privacy policy in Switzerland is, in practice, looking for a template that covers every mandatory item of the revised Federal Act on Data Protection (DSG, in force since 1 September 2023) and is usable with minimal adaptation. A good template is more than a sparse Word document: it walks through the mandatory disclosures of Art. 19 DSG, flags industry- and canton-specific additions, and makes clear where GDPR contents must be added. This article walks section by section through a free, complete template, and names the legal anchor for every block.

What you will find here:

  • the twelve sections of a complete privacy policy under Art. 19 paras. 2-4 DSG;
  • a clear marking of which sections are mandatory (DSG), which are de facto mandatory (GDPR with marketplace reach) and which are best practice;
  • notes on adaptation for cantonal information and data-protection acts (IDG/IDAG/LIPAD/LPrD) for public bodies;
  • industry-specific additions for law firms, hospitals, fiduciaries and banks;
  • maintenance notes: when does the template have to be updated?
  • a recommendation on when a template is enough, and when an integrated generator is more economical.

The template does not replace a case-by-case legal review; it does, however, provide a reliable base for 80 % of Swiss SMEs.

Sections 1-3: controller, scope, terminology

The first three sections of a template cover the formal anchor data. Section 1, controller: identity (full company name, legal form, UID number), registered seat, contact details (general e-mail, optionally a dedicated privacy address such as [email protected]). Mandatory under Art. 19 para. 2 lit. a DSG. Companies that have appointed a data-protection adviser (DSB, Art. 10 DSG) name them here too. For GDPR-bound companies established outside the EU/EEA, the EU representative under Art. 27 GDPR is added with its own address.

On request you will find our EU representative service at EU representative Art. 27 GDPR and our DSB service at Swiss data-protection advisory.

Section 2, scope: which domains, apps or channels does the policy cover? With multiple brands or subsidiaries the boundary is critical, without a clear boundary the policy is exposed in an FDPIC procedure.

Section 3, terminology: a short, own explanation of "personal data" (Art. 5 lit. a DSG), "processing" (Art. 5 lit. d DSG), "controller" (Art. 5 lit. j DSG) and, where applicable, "specially protected personal data" (Art. 5 lit. c DSG). Companies under the GDPR add "profiling" (Art. 4(4) GDPR) and "pseudonymised" (Art. 4(5) GDPR).

Sections 4-5: processing purposes and recipients

Section 4, processing purposes: the core section. A tabular or structured presentation per main purpose is recommended: contract performance, customer support, newsletter, recruitment, website analytics, security monitoring. Document per purpose: data categories concerned, storage period (e.g. 10 years under Art. 958f CO for business correspondence, 5 years for applicant records, 6 months after contract end for newsletter profiles), legal basis (for GDPR-bound companies with an Art. 6 anchor). The template provides placeholder text for each purpose; the selection is made by the individual company.

Section 5, recipients and processors: mandatory under Art. 19 para. 2 lit. c DSG. The template recommends the recipient-category approach with examples: "cloud hosting providers (e.g. Microsoft Azure Switzerland, AWS Frankfurt)", "payment service providers (e.g. Stripe, PostFinance)", "CRM providers", "accounting fiduciary". Important: processors are not a separate recipient category but legally remain the controller's "extended arm" (Art. 9 DSG); naming them serves transparency, while contractual binding occurs via the DPA (see our Swiss DPA template).

The template explicitly warns against blanket wording such as "third parties" or "business partners", they do not satisfy the "adequate information" requirement of Art. 19 para. 1 DSG.

Sections 6-7: third-country transfers and cookies/tracking

Section 6, third-country transfers: Art. 19 para. 4 DSG requires, on export abroad, naming the recipient country and the safeguard under Art. 16 para. 2 DSG. The template provides a list with examples: recipients in EU/EEA (adequacy decision, no additional safeguard needed), recipients in the USA with Swiss-U.S. DPF certification since 15 September 2024 (no SCCs needed, certification link recommended), other third countries (Swiss SCCs in the version recognised by the FDPIC on 27 August 2021).

Section 7, cookies and tracking: Switzerland follows, in contrast to GDPR/ePrivacy, an opt-out regime regulated by Art. 45c lit. b of the Telecommunications Act (TCA / FMG). Reach measurement and security-relevant cookies are generally permissible without active consent, provided there is transparent information and an objection option. Advertising and tracking cookies that build personal profiles, however, engage Art. 31 lit. d UWG (Federal Act against Unfair Competition) and, with an EU nexus, fall under the GDPR opt-in regime. The template therefore contains two cookie-section variants: purely Swiss configuration and "Switzerland with EU nexus". Detailed guidance is in our article Cookie banners in Switzerland.

Sections 8-9: data-subject rights and profiling

Section 8, rights of the data subjects: even though Art. 19 DSG does not explicitly require naming them, this section is standard. The template covers: right of access (Art. 25 DSG, 30-day deadline under Art. 25 para. 7 DSG), right of rectification (Art. 32 para. 1 DSG), right to deletion and destruction (Art. 32 para. 2 DSG), objection to processing (Art. 30 para. 2 lit. b DSG), data hand-out and transfer (Art. 28 DSG, newly introduced in the revision). For GDPR-bound companies the template adds the right to data portability under Art. 20 GDPR and the right to lodge a complaint with an EU supervisory authority.

Section 9, automated individual decisions and profiling: mandatory under Art. 21 DSG as soon as a solely automated decision has legal effects or significantly affects the data subject. The template contains three prepared scenarios (credit, recruitment, insurance pricing) and an empty placeholder for the controller's own AI or scoring systems. Whoever deploys such a tool must additionally check whether a data-protection impact assessment under Art. 22 DSG is required, and document the outcome internally. With the EU AI Act (high-risk regime from 2 August 2026), these duties gain additional weight for providers with EU reach.

Sections 10-12: security, changes, contact

Section 10, data security: a reference to the technical and organisational measures (TOMs) under Art. 8 DSG and Art. 1-3 of the Data Protection Ordinance (DPO). The template warns against listing concrete security controls here, overly detailed disclosure can give attackers valuable hints. A generic formulation is recommended ("measures appropriate to the state of the art, regular review, encryption in transit and at rest for sensitive data").

Section 11, changes to this privacy policy: the template formulates a clause that reserves the right to unilateral adaptation in line with the legal situation and actively notifies material changes (e.g. by e-mail to registered customers). With reference to versioning and effective date.

Section 12, contact for data-protection requests: a separate section with precise contact details, in larger organisations with separate addresses for DPO, EU representative and right to complain. A central e-mail such as [email protected] has proven effective.

These three closing sections are not strictly mandatory but are read by the FDPIC in practice as an indicator of the maturity of a compliance programme.

Adaptation for cantonal authorities and regulated industries

Public bodies are not subject to the DSG but to cantonal information and data-protection law, IDG (ZH, BS, etc.), IDAG (AG, SO), LIPAD (GE), LPrD (VD). These acts have a different mandatory content structure, in particular for the legal basis of processing (cantons typically require a "statutory basis" with concrete reference to the substantive act) and for supervision (cantonal data-protection commissioners instead of the FDPIC). The template provides an adaptation variant for the five largest cantons; for other cantons a mapping via the table in our article Data protection Aargau, or comparable cantonal overviews, is recommended.

Regulated industries need additional clauses:

  • Banks / securities dealers: reference to banking secrecy (Art. 47 BankA) and FINMA reporting duty (Art. 29 FINMASA, FINMA Circ. 2023/01).
  • Law firms: lawyer secrecy (Art. 13 BGFA) as a colliding confidentiality duty that prevails over the right of access.
  • Hospitals / medical practices: cantonal patient-data acts, Art. 321 of the Swiss Criminal Code.
  • Fiduciaries / audit: professional secrecy and retention periods under the Code of Obligations.

A regulated-industry actor using a generic template without adaptation signals lack of due care to the FDPIC in any procedure.

How SIDD supports you

SIDD provides the template described here free of charge to interested SMEs, request via our contact form. For companies with multiple languages, processors or regulatory sensitivity, the template is only the entry point: a versioned privacy policy linked to the records of processing under Art. 12 DSG is produced as part of our DSB mandate or as a modular service on the Priverion platform.

GDPR-bound companies get additional GDPR DPO services, an EU representative and, where there is a UK nexus, a UK representative. A first review of your existing text against Art. 19 DSG gaps typically takes 60 minutes and can be requested as a fixed-price mandate via the quote request. We then deliver a concrete gap analysis with a remediation plan that you can implement internally or hand over to us as a full mandate.

Need help putting this into practice? SIDD operates the matching service.
See service →

Swiss Privacy Policy Template (DSG 2026, Free)

INSIGHT

Data Protection
24 May 2026
Dr. Dominic Staiger
Free privacy policy template under the FADP: explained section by section, with notes for public authorities and regulated industries.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.