Opens in a new tab

Checklist: 7 Steps to Compliance with the New Swiss Data Protection Act

Table of contents

Start a new project with onlineKarma

Tell us about your goals, and we'll tell you how we can help.
Raphael Guldimann
Raphael Guldimann
Founder & CEO
Book a free consultation

On September 1, 2023, the new Swiss Data Protection Act (nDSG) took effect. It followed the European Union’s General Data Protection Regulation (GDPR), which was introduced in 2018.

This article explains the changes introduced at that time and their short- and long-term impacts on SMEs. The checklist provides an overview to help companies plan their transition so they can avoid fines and reputational damage, strengthen their customers’ trust, and ensure the free flow of data with the EU.

Note on the Legal Status: This article was published on August 16, 2023, and reflects the information available at that time, shortly before the nDSG took effect. It is intended for informational purposes only and does not constitute legal advice. Please check the current requirements with the EDÖB, on Fedlex, or by consulting a qualified legal advisor.

Animated illustration of the new Swiss Data Protection Act

1/ A Brief Summary of the nDSG

  • Effective as of: September 1, 2023
  • Goal: Better protection of personal rights and fundamental rights in the processing of personal data
  • Model: The European Union’s General Data Protection Regulation (GDPR) of 2018
  • Subject: Primarily businesses and organizations
  • Benefits for SMEs: Stay competitive, avoid fines, and strengthen customer trust
  • nDSG vs. GDPR: An Overview of the 11 Key Differences
  • Practical Help: Privacy Policy Generator; the code onlineKarma10 offers a discount.

2/ nDSG: The 5 Key Changes

1. Protection of Natural Persons

The nDSG fully protects the data of natural persons. The data of legal entities is no longer protected by the law to the same extent. The personal rights of a company’s employees remain protected.

2. Genetic and biometric data

Genetic and biometric personal data are considered particularly sensitive personal data and require special care.

Personal data includes, for example, master data such as name, date of birth, or IBAN; activity data from physical and digital tracking; and profiling data used for the automatic analysis of interests, preferences, or performance.

Data that warrants special protection includes, among other things, data related to health, genetic or biometric characteristics, religious, political, or union-related views, as well as data regarding criminal or social measures.

3. Privacy by Design and Privacy by Default

These two principles protect personal data through appropriate technical and organizational measures, as well as through privacy-friendly default settings.

4. Data Protection Impact Assessment

The Data Protection Impact Assessment (DPIA) describes the planned data processing, evaluates risks to the privacy and fundamental rights of data subjects, and sets forth appropriate safeguards.

5. Expanded Disclosure Requirements

The obligation to provide information applies to any collection of personal data, not just to data requiring special protection. Data subjects must be informed in an understandable manner about the scope and purpose of the processing—for example, in a privacy policy. Further information is available from the EDÖB.

3/ Checklist: 7 Steps to Get Ready

Animated Checklist for Preparing for the nDSG

1. What personal data do I process?

Identify what personal data you process and which of these categories require special protection. Provide transparent and easy-to-understand information, such as:

  • Privacy Policy
  • Terms and Conditions or a separate letter
  • Consent Form
  • Informative cookie banners

Whether consent is required depends on the category of data, the purpose, the technology used, and the applicable law.

2. Does my website comply with Privacy by Design?

The technical design of a product or service must respect privacy. Appropriate measures include:

  • Data minimization: Collect only the data that is truly necessary for the purpose.
  • Selective password and access protection: Access is limited to employees who need it for their work.
  • Data Deletion Policy: Delete personal data after a specified period of time, in compliance with statutory retention requirements.

3. Does my website comply with "Privacy by Default"?

Privacy-friendly default settings are active without any action required by users and limit data processing to the absolute minimum. Examples include IP anonymization in analytics systems, minimalist contact forms, restricted access to profiles, and app permissions.

Current Note on Cookies: Switzerland does not have a blanket requirement for cookie banners like the one in the EU. However, depending on the technologies used, data categories, target audience, and the applicability of the GDPR, consent may still be required. Please review the specific circumstances of your case.

Illustration on Data Protection, Cybersecurity, and Technical Safeguards

4. Do I need to conduct a data protection impact assessment?

A data protection impact assessment (DPIA) is required if processing is likely to pose a high risk to personal rights or fundamental rights. The risk may arise, in particular, from new technologies, the nature and scope of the processing, the circumstances, or the purpose of the processing. Examples include the extensive processing of data requiring special protection or the systematic monitoring of publicly accessible areas.

5. Is my privacy policy in compliance with the law?

The privacy policy must clearly describe all relevant data processing activities and be easy to find—for example, in the footer. Contact forms should also include a reference to the privacy policy. Important information includes:

  • Identity and Contact Information of the Data Controller
  • Purpose of Processing
  • Recipients of Data Disclosures
  • Data Categories for Third-Party Data Collection
  • Country Specification for Data Exports

The generator from Datenschutzpartner helps with the creation process. With the code onlineKarma10, customers can save up to 10 percent.

6. Do I need a record of all data processing activities?

Data controllers and data processors must generally maintain a record of processing activities. An exception may apply to organizations with fewer than 250 employees if the processing poses only a low risk. The record documents the minimum information required by law and should also include the retention period as well as a general description of data security measures.

7. When do I need to report to the EDÖB?

Data security breaches must be reported to the FDPIC as soon as possible if they are likely to pose a high risk to privacy or fundamental rights. Data subjects must be informed if this is necessary for their protection or if the FDPIC requires it.

Current Note: The former NCSC is now known as the Federal Office for Cybersecurity. Information and reporting options are available from the BACS.

4/ Criminal Liability: What Are the Possible Penalties?

The judge's gavel as a symbol of penalties for data protection violations

The nDSG provides for criminal sanctions against responsible individuals in the case of certain intentional violations. Depending on the circumstances of the offense, fines of up to CHF 250,000, supervisory investigations by the EDÖB, and civil claims may be imposed.

In particular, breaches of obligations regarding information, disclosure, or data security; inadequate safeguards for cross-border data transfers; and a lack of contractual safeguards with data processors may be relevant.

The specific sanctions that may apply in individual cases and the question of liability depend on the specific circumstances. This overview does not constitute a legal assessment.

5/ For SMEs: What measures make sense?

The following steps are recommended for a structured implementation:

  • Inventory of All Processing of Personal Data
  • Risk Assessment in the Company
  • Organization of internal processes, clear responsibilities, and minimal access rights
  • Review and amendment of privacy policies and contracts with data processors, including the record of processing activities
  • Designation of a contact person for data protection matters

6/ The Best Tools for Data Protection

These two services can assist you with the practical implementation. Before using them, check whether their features and terms are a good fit for your situation.

Data Protection in 30 Minutes

Datenschutzpartner logo

You can use the questionnaire from Datenschutzpartner to create a customized privacy policy.

Quick and Easy Cookie Banners

Cookiebot logo for cookie banners

If the website requires a consent banner, Cookiebot can help with setup and management.

Sources and Related Links

Implementing Data Protection and Tracking Properly

We help you integrate data protection, analytics, and marketing in a way that’s both easy to understand and effective.
Get in touch with no obligation
Raphael Guldimann
About the author

Raphael Guldimann

Managing Director

Raphael Guldimann is Managing Director at onlineKarma.

Profile and more articles

You might also be interested in

Three members of the onlineKarma executive team chatting outdoors
June 30, 2026

LinkedIn Statistics & Usage in Switzerland, 2026

LinkedIn now reports 5.7 million active users. LinkedIn continues to grow. Most users are between the ages of 28 and 35.
Read more
Two onlineKarma employees are working together on a flip chart
June 30, 2026

Facebook Usage in Switzerland in 2026

Who are Facebook users in Switzerland? Updated data from onlineKarma.
Read more
View all items

Now you know what's possible. Let's make it happen together.

We don’t just write about it – we implement it every day for our customers.

Get in touch with no obligation

Get in touch for a no-obligation conversation. We usually reply within a few hours.

By submitting this form, you agree to our privacy policy.

Talk to us directly

Call us for a free initial consultation: 061 551 02 02.

Phone Hours
  • Mon–Thu: 8:00 a.m.–12:00 p.m. and 1:00 p.m.–5:30 p.m.
  • Fri: 8:00 a.m.–12:00 p.m. and 1:00 p.m.–5:00 p.m.
  • Sat–Sun: Closed
Call now