Opens in a new tab

GDPR Switzerland Checklist for Companies and Organizations

Table of contents

Start a new project with onlineKarma

Tell us about your goals, and we'll tell you how we can help.
Raphael Guldimann
Raphael Guldimann
Founder & CEO
Book a free consultation

1. What is the EU GDPR?

It is the EU’s new data protection law. Its primary purpose is to regulate the use of so-called ” personal data” and to enforce these regulations more strictly.

The full name of GDPR is Data Protection Ordinance .

The GDPR is a compilation of“digital rights”for EU citizens. The new regulation takes effect on May 25, 2018.

The GDPR also applies to companies and organizations in Switzerland as well as the substantial fines can be imposed on Swiss companies and organizations.

In English, this is known as the General Data Protection Regulation, or GDPR.

Please note that this information is provided for informational purposes only and does not constitute legal advice in any way. We accept no liability. We are happy to answer any questions you may have.

2. Are Swiss companies and organizations subject to the GDPR?

The GDPR applies not only to European companies, but also to Swiss companies and organizations —as well as to any individual who handles personal data that could potentially originate from the EU. For example, if they send newsletters to EU citizens.

If a sole proprietor uses her website to target individuals in the EU and offers them, for example, freebies such as newsletters or white papers, then the GDPR applies in this regard.

Attorney Martin SteigerWatson

Source: Watson – Attorney Martin Steiger

The GDPR therefore applies to anyone who handles data belonging to EU citizens. So it probably applies to you, too.  

A Swiss counterpart to the GDPR—a new federal data protection law —is currently being drafted. As an online marketing agency, we’ll keep you updated on any developments.

3. What is “personal information”?

Sketch of a data and marketing process on a desk

Personal data, or “Personally Identifiable Information” (PII) , can include any information that relates to individuals, regardless of whether it pertains to their private, public, or business lives.

Personal data is specifically:

  • Names,
  • Home addresses,
  • Photos,
  • Email addresses,
  • Bank account information,
  • Social media posts,
  • medical data,
  • IP addresses
  • and everything in between :)

Under the GDPR, companies must ensure that individuals have control over their personal data.

Users must now be given the ability not only to access their stored data, but also to modify, delete, or simply export it (e.g., transfer Spotify playlists to Deezer and vice versa).

4. How long may personal data be stored?

Two people shake hands during a conversation

You may store personal data only for as long as is necessary for the purposes for which you are storing the data [Art. 5(1)(e)].

Always try to keep in mind why you received the data, and be aware of the time limit.

EXAMPLE
A person applies for a job by submitting a resume and other personal data. If you, as an SME , had posted a specific job opening, you should delete the personal data as soon as possible after rejecting the applicant, since storing it is no longer necessary.

As a recruitment agency, you likely retain resumes for longer than a “typical” small or medium-sized business, since you can use the documents for multiple job openings . However, even in this case, there is little justification for retaining personnel records for several years, since the resumes become outdated after a certain amount of time anyway.

5. GDPR Checklist for Switzerland

Hand marks a yes/no checklist
  1. You must provide the option to opt out of cookies on the website or explain how this can be done.
  2. You may not use cookies ( except for those that are essential for a user to use the site) until the user has given their consent.
  3. You need an accurate/correct privacy policy on your website. Here are some privacy policy generators that might be helpful:
    1. Privacy Policy Generator for Swiss Lawyers (Switzerland)
    2. Privacy Policy Generator – Privacy Policy Partner (Switzerland)
    3. Weiss & Partner (EU) Privacy Policy Generator
    4. Dr. Schwenke Privacy Policy Generator (EU)
  4. You should enable IP address anonymization for Google Analytics . Google information on IP anonymization
  5. Do not send any personal data (e.g., via contact forms) to Google Analytics (GA) or other analytics tools and website trackers. This would violate the GDPR and could also result in the deletion of your Google Analytics account (since it also violates Google’s policies). Instructions on how to check whether personal data is stored in GA and what can be done about it.
  6. Limit contact forms to only the personal data that is truly necessary for the service.
  7. Please include a reference to your privacy policy on the contact form. In our opinion, a checkbox is not necessary, but it would of course not be detrimental from a GDPR perspective.
  8. Personal data must be encrypted and stored and transmitted securely .
  9. Keep track of who has access to which data.
  10. SSL-secured websites are a must.
  11. You need users’ active consent to send them newsletters (passive consent is no longer sufficient).
  12. You must be able to show when and where someone gave consent to receive a newsletter.
  13. Appoint a Data Protection Officer (DPO) (required only for organizations that handle large volumes of data, but also recommended for smaller companies).
  14. Document your data processing procedures .
  15. Always use the TLS (or SSL) encryption protocol when sending and receiving emails.

6. GDPR Assessment and Avoiding Fines

A laptop and a stethoscope as symbols of a GDPR assessment

To assess liability for violations and fines, take stock of all the personal data you have collected and review it based on the following 6 questions:

  1. For what purpose do you retain this data?
  2. How did you get the data?
  3. What was the original purpose of the procurement?
  4. How long do you plan to keep this data?
  5. Are they secure in terms of both encryption and accessibility ?
  6. Do you share this data with third parties, and if so, for what purpose?

Keep in mind that companies are not required to prove their compliance, but the GDPR does have the authority to conduct audits and inspections.

7. That is why the GDPR is needed

Businessman gives a thumbs-up

The GDPR is good news for all Internet users.

Users are increasingly concerned about how their personal data is used—and rightly so.

At a time when there are repeated reports of unchecked data breaches, this new directive addresses users’ concerns and grants them rights and obligations regarding data processing. This is a much-needed improvement, not only in light of the recent Facebook data scandal.

The GDPR is intended to offer Internet users greater protection and security and make browsing the Internet easier, which is also good news for website operators, as it helps build trust.

8. Key Rights and Obligations Under the New Data Protection Act of 2018

Illustration on data protection featuring the letters GDPR

1. Right of Access

The right of access is a right of the data subject. This gives EU citizens the right to access their stored personal data and to obtain information about the processing of their personal data.

2. Right to Erasure

The right to erasure means that the data subject has the right to request the erasure of their personal data for one of several reasons, including non-compliance with Article 6.1 (lawfulness).

3. Right to Data Portability (Art. 20 of the GDPR)

Everyone has the right to have their personal data transferred from one electronic processing system to another without being hindered by the data controllers. Data that has been sufficiently anonymized is an exception. GDPR Art. 20 https://dsgvo-gesetz.de/art-20-dsgvo/

4. Requirement: Data Protection by Design—Strictdata protection settings at every step (Art. 25 of the GDPR)

Privacy settings on every part of a website—whether through forms, analytics, or anywhere else where user data is managed or stored— must be set to a high level by default. This means that users do not have to take any additional steps to ensure that their data remains private by default.

The data controller shall implement technical and organizational measures to ensure that the entire processing lifecycle complies with the Regulation. Encryption can remove personal data from the scope of the GDPR. This means that when data is fully encrypted, it is no longer identifiable and therefore no longer falls within the scope of the GDPR.

Encryption and decryption operations must be performed locally to ensure that both the keys and the data remain under the control of the data owner, thereby safeguarding privacy.

Some encryption techniques may not be sufficient to remove personal data from the scope of the GDPR. Data controllers should carefully review the encrypted data and assess whether there is a risk that the data could be decrypted, taking into account potential future technologies.

5. Requirement to Maintain Records of Activities

This means that records must be kept of data processing activities that describe in great detail the purpose of the processing, the categories of data subjects, and the anticipated time limits.

6. Requirement to report violations within 72 hours

The GDPR imposes a new requirement: Data controllers must report any personal data breach to their country’s supervisory authority within 72 hours of becoming aware of it, unless the data has been anonymized or encrypted. Breaches that pose a risk to an individual (identity theft, breach of confidentiality, etc.) must also be reported directly to the affected individuals.

9. Who is your data protection officer?

Several people touch their fists together as a symbol of cooperation

The GDPR requires every company or organization that stores or processes large amounts of personal data—whether for employees, individuals outside the organization, or both—to appoint a DPO (Data Protection Officer).

Data processing is managed by a person appointed by the data controllers whose primary responsibilities involve data processing. The DPO requires a regular and systematic overview of the data in question. The DPO is a qualified individual who should be familiar with data protection regulations and practices and who can support and monitor the data controllers to ensure their compliance with the GDPR.

The data protection officer must be able to demonstrate that “consent” (opt-in) has been obtained and ensure that consent can be withdrawn. The identity and contact information of the data controller(s) in your company must be provided.

Even though it is not mandatory for every organization, most companies are advised to appoint a data protection officer.

10. GDPR: Amount of Possible Fines

The judge's gavel as a symbol of GDPR fines

The fines have been increased. Depending on the offense, there are two levels of fines.

The maximum penalty for noncompliance with the GDPR is 20,000,000 euros or up to 4% of your global annual revenue (based on figures from the previous fiscal year), whichever is higher.

11. Recent ECJ Ruling, September 2019

The European Court of Justice has ruled on four very important issues:

  • In addition to Facebook, website operators are always jointly responsible for data protection violations.
  • The unsolicited transfer of user data via the Facebook “Like” button on websites violates data protection laws.
  • Competition authorities can issue formal warningssubject to a fee—to websites that have incorporated Facebook’s “Like” button without providing an option to opt out.
  • For cookies set for tracking or advertising purposes, genuine consent from website visitors is required. A cookie notice banner is not sufficient.

12. Conclusion

A hand holds a compass, looking down a path

The GDPR is good news for individuals and the public. It is another step toward strengthening Internet security and, above all, promoting fairness and respect in the use of personal data.

As a Swiss company or association, it is important that youare aware ofyour obligations and comply with them. You can consult a lawyer to be on the safe side, and you can review the above GDPR-Switzerland checklist in advance and go through it carefully.

Raphael Guldimann
About the author

Raphael Guldimann

Managing Director

Raphael Guldimann is Managing Director at onlineKarma.

Profile and more articles

You might also be interested in

Three members of the onlineKarma executive team chatting outdoors
June 30, 2026

LinkedIn Statistics & Usage in Switzerland, 2026

LinkedIn now reports 5.7 million active users. LinkedIn continues to grow. Most users are between the ages of 28 and 35.
Read more
Two onlineKarma employees are working together on a flip chart
June 30, 2026

Facebook Usage in Switzerland in 2026

Who are Facebook users in Switzerland? Updated data from onlineKarma.
Read more
View all items

Now you know what's possible. Let's make it happen together.

We don’t just write about it – we implement it every day for our customers.

Get in touch with no obligation

Get in touch for a no-obligation conversation. We usually reply within a few hours.

By submitting this form, you agree to our privacy policy.

Talk to us directly

Call us for a free initial consultation: 061 551 02 02.

Phone Hours
  • Mon–Thu: 8:00 a.m.–12:00 p.m. and 1:00 p.m.–5:30 p.m.
  • Fri: 8:00 a.m.–12:00 p.m. and 1:00 p.m.–5:00 p.m.
  • Sat–Sun: Closed
Call now