· 8 min read
nFADP and your website: a practical guide for SMEs in French-speaking Switzerland
Does your website have a contact or quote form, a newsletter, Google Analytics or an embedded YouTube video? Then it processes personal data, and the new Swiss Federal Act on Data Protection (nFADP, also known as revFADP) applies to you, whatever the size of your business.
In force since 1 September 2023, the nFADP replaced the 1992 act. Here's what matters for an SME website, based on the official texts and the guidance of the Federal Data Protection and Information Commissioner (FDPIC), up to date as of September 2026. This article is general information and does not constitute legal advice.
Does the nFADP apply to my business website, and does the GDPR apply too?
Yes, as soon as your site processes personal data: any information relating to an identified or identifiable natural person, such as a name, an email address or, depending on the context, an IP address or a cookie identifier. The act covers all private companies, with no size threshold.
What's new: only data about natural persons is now protected, no longer data about companies (but the name and email address of your contact person at a client company are still personal data). Another difference from the GDPR: you don't need a “legal basis” for each processing activity, as long as you respect the principles of the act (good faith, proportionality, recognisable purpose, security); otherwise, you need a justification such as consent.
The EU GDPR may also apply if you offer goods or services to people in the EU or monitor their behaviour online (Art. 3(2) GDPR). A site that is merely accessible from France isn't enough; delivering to the EU, showing prices in euros or targeting the EU with advertising are indications. A Geneva shop that ships to France can therefore be subject to both regimes.
Does my website need a privacy policy under the nFADP?
In practice, yes. The nFADP requires you to inform people whenever you collect any personal data, not just sensitive data (Art. 19 FADP). On a website, that means a privacy policy (or data protection statement) that is concise, transparent, understandable and easily accessible (Art. 13 DPO). No hiding it away: link to it in the footer and next to every form.
At a minimum, it should include:
- Your company's identity and contact details.
- The purposes: quotes, newsletter, audience measurement, etc.
- The recipients (or categories of recipients): hosting provider, email marketing tool, CRM, Google, etc.
- If data is sent abroad: the country and the safeguards used (Art. 16 FADP) or the exception relied on (Art. 17 FADP).
- For cookies: their purpose and the option to refuse them (Art. 45c TCA).
Do you need a cookie banner in Switzerland?
This is the big difference from the EU. In Switzerland, Art. 45c of the Telecommunications Act (TCA) requires you to inform visitors about the processing and its purpose and to tell them they can refuse it; the nFADP applies on top of that as soon as personal data is involved. According to the FDPIC, neither law in itself requires consent for non-essential cookies: information and the right to object (opt-out) are sufficient in principle, whereas EU law requires prior consent.
So a banner isn't mandatory as such, but it's often the simplest way to inform visitors and let them refuse; it becomes necessary as soon as consent is required. According to the FDPIC (guidelines of October 2025, factsheet of March 2026):
- Essential cookies (session, shopping cart, language, remembering the cookie choice, security, captcha): mention them, with no need for a refuse button, as long as they are limited to what is necessary.
- Audience measurement: permissible without consent if the data is anonymised as soon as possible and the provider does not use it for its own purposes; visitors must be able to object.
- Other non-essential cookies, including “normal” personalised advertising: a clearly visible way to refuse, available in a few clicks from the first visit and, in principle, before the cookies are activated.
- Express prior consent (opt-in): required for processing that is high-risk, unexpected or involves sensitive data. For third-party advertising cookies that track visitors from site to site, the FDPIC asks you to presume high-risk profiling as long as it cannot be ruled out.
Contact forms, quote requests and newsletters: what needs to change under the nFADP?
The nFADP requires recognisable purposes and data limited to what is necessary, destroyed or anonymised as soon as it is no longer needed (Art. 6 FADP). It also requires data protection by design and by default (Art. 7 FADP): default settings must limit processing to the minimum required.
- Only ask for what's essential: for a quote, a name, an email address and a description of the project are often enough.
- Add a short note below the submit button on how the data will be used, with a link to your privacy policy.
- Newsletter: the Unfair Competition Act (Art. 3 para. 1 let. o UCA) generally requires prior consent for mass advertising by email, except towards your customers for your own similar products or services, provided they were told they can object. Every mailing must identify the sender and offer a free, easy way to unsubscribe.
- A separate, unticked newsletter checkbox: asking for a quote is not subscribing.
- Set a retention period and regularly delete requests that led nowhere.
Can I host my website or use US tools under the nFADP?
Yes, with rules. Disclosing data abroad (hosting, CDN, email marketing, CRM) is freely permitted to countries the Federal Council considers to have an adequate level of protection (Annex 1 DPO), including the EU and EEA countries and the United Kingdom.
For the United States, only companies certified under the Swiss-U.S. Data Privacy Framework (DPF) benefit from this, since 15 September 2024; that is still the case in September 2026. Check each provider's “Swiss-U.S. DPF” certification on dataprivacyframework.gov; otherwise, other safeguards are needed, such as standard contractual clauses recognised by the FDPIC.
List the countries concerned in your privacy policy and sign a data processing agreement (often the provider's “DPA”) with every provider that processes data on your behalf (Art. 9 FADP). One to watch: the equivalent EU–US framework is the subject of an appeal before the Court of Justice of the EU.
Records of processing, security, data breaches: what must an SME do?
Records of processing activities: companies with fewer than 250 employees on 1 January are exempt, unless they process sensitive data on a large scale or carry out high-risk profiling (Art. 24 DPO).
Security: the act requires technical and organisational measures appropriate to the risk (Art. 8 FADP), including keeping software up to date and fixing known critical vulnerabilities (Art. 3 DPO). For a website, that means HTTPS, CMS and plugin updates, strong passwords, limited access and backups.
Data breaches: a breach that is likely to result in a high risk for the people concerned must be reported to the FDPIC as soon as possible (Art. 24 FADP), via its DataBreach portal, with no fixed 72-hour deadline as under the GDPR. Also inform the people concerned if their protection requires it, and document breaches for at least two years (Art. 15 DPO).
What are the fines under the nFADP, and who is liable?
The nFADP provides for criminal fines of up to CHF 250,000. Three particularities: they are aimed in principle at the responsible individual (for example, a member of management), not the company; only intent is punishable; and most offences are only prosecuted on complaint. The exception: if the fine does not exceed CHF 50,000 and identifying the responsible person would require disproportionate measures, the company can be convicted instead (Art. 64 FADP).
For a website, the offences include intentionally failing to inform or giving false information (Art. 60 FADP), transferring data abroad without safeguards, using a processor without a compliant contract, or ignoring the minimum data security requirements (Art. 61 FADP). The cantons prosecute; the FDPIC, for its part, can investigate and order that processing be changed or stopped. Art. 53 TCA also provides for a fine of up to CHF 5,000 for cookies.
Is my website nFADP compliant? A checklist
The priorities for an SME website (for a complex case, such as health data, consult a lawyer):
- Take stock of your forms, cookies and third-party tools (analytics, pixels, videos, maps, chat), and of the countries the data goes to.
- Publish an up-to-date privacy policy, linked from the footer and from every form.
- Inform visitors about cookies and let them refuse; get consent for high-risk profiling and, if you target the EU, for any non-essential cookie.
- Cut forms down to what is necessary, with a separate, unticked newsletter checkbox.
- Check the DPF certification or safeguards of providers outside the EU and sign their data processing agreements.
- Keep the site up to date (HTTPS, CMS, plugins, backups) and know what to do in the event of a breach.
nFADP vs. Quebec's Law 25: what's the difference?
If you have clients in Quebec, Law 25 goes further: a designated person in charge of the protection of personal information, named on the website; profiling technologies turned off by default; and administrative monetary penalties against the company of up to CAD 10 million or 2% of worldwide turnover. The nFADP favours information and opt-out for cookies, makes the data protection advisor optional and primarily sanctions individuals. See our article on Law 25.
At Situs Digital, based in Lausanne and Montréal, we build fast, bilingual websites with data protection built in from the design stage. If you'd like us to take a look at your current site, just write to us.
Frequently asked questions
Does the nFADP apply to self-employed people and small businesses?
Yes. There is no size threshold: a simple contact form is enough. Only the record of processing activities comes with an exemption, for companies with fewer than 250 employees.
Can I use Google Analytics in Switzerland?
Yes, with conditions: mention it in your privacy policy (including the transfer to the United States), let visitors object, and turn off the advertising features and data sharing with Google. If you target visitors in the EU, ask for their consent before activating it.
Do I need to appoint a data protection officer (DPO)?
No: for a private company, the data protection advisor is optional (Art. 10 FADP). Designating an internal contact person and publishing a dedicated email address is still useful.
Is a “By continuing to browse, you accept cookies” banner enough?
Not if it offers no way to refuse: Art. 45c TCA requires you to tell visitors that they can refuse the processing. And where consent is required, the FDPIC requires an active step, such as a click: simply continuing to browse is not enough.
Sources
- Fedlex – Federal Act on Data Protection (FADP, SR 235.1), English version
- Fedlex – Data Protection Ordinance (DPO, SR 235.11), including Annex 1 (states with an adequate level of data protection), English version
- Fedlex – Telecommunications Act (TCA, SR 784.10), Art. 45c and 53, English version
- Fedlex – Federal Act on Unfair Competition (UCA, SR 241), Art. 3 para. 1 let. o, English version
- FDPIC – Guidelines on data processing using cookies and similar technologies (version 1.1 of 6 October 2025)
- FDPIC – Factsheet: use of cookies and other similar technologies in the context of online tracking (March 2026)
- FDPIC – Guidelines on data breaches
- Federal Council – Swiss-US Data Privacy Framework: certified US companies offer adequate protection for personal data (14 August 2024)
- Data Privacy Framework – List of certified organisations
- KMU.admin.ch – New Federal Act on Data Protection (nFADP)
- KMU.admin.ch – Business site and data protection
- Sylvain Métille, attorney – Cookies under Swiss law (in French)
- EUR-Lex – General Data Protection Regulation (GDPR), Art. 3
- EDPB – Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)
- Court of Justice of the EU – Case C-703/25 P, Latombe v Commission