Where the cookie rule lives
The revised Federal Act on Data Protection came into force on 1 September 2023 and modernised Swiss data protection: a duty to inform on collection, records of processing, data protection impact assessments, breach notification to the FDPIC, and privacy by design and by default. Unlike the GDPR it does not require a legal basis for every processing operation; lawful processing is the default and consent is needed for specific situations, including profiling with a high risk by private persons.
The cookie-specific rule is elsewhere. Article 45c of the Telecommunications Act permits processing of data on third-party equipment where users are informed about the processing and its purpose and are told that they may refuse it. That is an inform-and-allow-refusal standard, not prior consent.
The engine is stricter than this, on purpose
CH sits in the opt-in set alongside the EEA and the UK, so a Swiss visitor sees a prior-consent experience under every profile that shows a banner. This is a defensible default rather than a statement that Swiss law demands it, and many Swiss businesses do run an EEA-grade banner because they are also caught by the GDPR.
What each region profile resolves to
| Region profile | Resolved model | What the visitor sees |
|---|---|---|
| Regional defaults | opt-in | Nothing optional loads until a choice is made |
| Global strict | opt-in | Nothing optional loads until a choice is made, everywhere |
| Global balanced | opt-in | Nothing optional loads until a choice is made |
| EU and UK opt-in | opt-in | Nothing optional loads until a choice is made |
Switzerland is one of the three territories the "EU and UK opt-in" profile covers, alongside the EEA and the United Kingdom.
If you want the lighter Article 45c experience for Swiss visitors specifically, add a region rule for CH with the opt-out model. Optional technologies will then load with a visible way to refuse, and the decision will be recorded as matched by country.
What else the FADP asks for
- Inform on collection, in a form that is genuinely accessible: the privacy notice the banner links to
- Keep a record of processing activities, unless the small-business exemption applies
- Notify the FDPIC of breaches likely to result in a high risk
- Apply privacy by design and by default, which is where a default-off configuration helps
- Name the countries data is exported to, which for a website means naming the vendors behind the trackers
Swiss enforcement is unusual in that penalties are criminal fines of up to CHF 250,000 directed at responsible individuals rather than administrative fines against the company. That changes who inside a business cares about getting this right.
This is a product reference, not legal advice
It describes how StrongPrivacy behaves and summarises published law so you can configure the product deliberately. Whether a particular configuration satisfies your obligations is a question for your own counsel, who knows your data flows and your risk position.
Common questions
Does Switzerland require prior consent for cookies?
Article 45c of the Telecommunications Act sets an information-and-refusal standard rather than prior consent. Where the GDPR also applies to you (which is common for Swiss businesses serving the EU), the stricter European rule governs that audience.
Why does StrongPrivacy default Switzerland to opt-in?
Because a single configuration usually serves EEA visitors too, and because failing closed costs nothing you cannot undo. A CH region rule with the opt-out model is the supported way to apply the lighter standard deliberately.
Is a Swiss representative required?
Controllers outside Switzerland may need to designate a representative in Switzerland in defined circumstances under the revised FADP. That is an organisational obligation rather than a runtime one, and it is worth checking with counsel if you process Swiss data at scale from abroad.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Swiss Federal Act on Data Protection
Legislation
Checked
- Swiss Telecommunications Act
Legislation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.