Opens in a new tab

Swiss nDSG vs. EU GDPR

Table of contents

Start a new project with onlineKarma

Tell us about your goals, and we'll tell you how we can help.
Raphael Guldimann
Raphael Guldimann
Founder & CEO
Book a free consultation

New Data Protection Rules in Switzerland – What Companies and Organizations Need to Know Now

The new Swiss Data Protection Act (nDSG) takes effect on September 1, 2023.

The nDSG (or revDSG) aims to harmonize with the EU General Data Protection Regulation (GDPR) and is intended to better protect the data of Swiss citizens by adapting to technological developments.

In an era in which technology is advancing at a rapid pace and AI applications like ChatGPT are playing an increasingly important role in our lives, it is more important than ever to ensure privacy and data protection. The nDSG holds the promise of a modern data protection framework. 🔭

A 🧭 Alignment of the nDSG toward the GDPR is evident, even though the nDSG does not align with the GDPR in all cases. For the most part, the new Swiss law is less stringent and is only more restrictive than the European one in a few specific areas.

The European data protection law also applies to many Swiss organizations.

You can find out when and how the GDPR applies to Swiss companies and organizations in the GDPR Switzerland Checklist. 🧾

Animation featuring the text “Talk nerdy to me”

via GIPHY

As a result, some organizations must comply with both European and Swiss data protection laws. That’s why even organizations that already meet the requirements of the GDPR need to take action. 🎬

Here you’ll learn about the key differences between the two data protection laws:

nDSG vs. GDPR: 11 Key Differences

DSGVOnDSG
SanktionenGeldbussen an das verantwortliche Unternehmen bis zu 20 Mio. EUR oder 4 % des weltweiten Jahresumsatzes des Unternehmens.Bei Verstoss gegen Regelungen strafrechtliche Bussen bis zu 250’000 CHF. Dabei ist die Strafe mit Ausnahmen an die verantwortliche natürliche Person geknüpft.
Melden von DatenschutzverletzungenPflicht, Datenschutzverletzungen mit Risiken für die betroffenen Personen der Datenschutzbehörde innerhalb von 72 Stunden zu melden. Besteht ein hohes Risiko für die Persönlichkeit, so muss die Person benachrichtigt werden.Pflicht, sofern es zum Schutz der betroffenen Personen erforderlich ist. Das EDÖB muss vom Verantwortlichen nur bei einem hohen Risiko informiert werden, sprich, wenn es zum Schutz der betroffenen Person erforderlich ist. Dabei gilt keine Frist von 72 Stunden, sondern “möglichst schnell”.
DatenexporteDie Europäische Kommission entscheidet über die Zulässigkeit. EU-Standardvertragsklauseln und verbindliche unternehmensinterne Vorschriften sind anwendbar.Das gleiche Konzept. Der Bundesrat entscheidet über die Zulässigkeit von Datenexporten. Dieselben Standardvertragsklauseln und verbindlichen unternehmensinternen Vorschriften wie in der EU sind anwendbar.
Benennung eines DatenschutzbeauftragtenPflicht, wenn das Unternehmen regelmässige und systematische Überwachung in grossem Umfang durchführt oder besondere Kategorien von Daten in grossem Umfang verarbeitet, gemäss Art. 37.Keine Pflicht, aber ausdrücklich empfohlen. Die Benennung führt zu Erleichterung bei einer Datenverarbeitung mit einem hohen Risiko für die Persönlichkeit oder die Grundrechte der betroffenen Person.
Datenschutz-FolgenabschätzungWenn trotz ergriffener Massnahmen ein hohes Risiko besteht, dann ist eine Rücksprache mit Aufsichtsbehörden obligatorisch.Wenn ein hohes Risiko für die Persönlichkeit oder Grundrechte der betroffenen Personen besteht, so ist eine Datenschutz-Folgeabschätzung (DSFA) durchzuführen. Wenn trotz der Massnahmen das Risiko weiter besteht, dann ist die Rücksprache mit einem Datenschutzbeauftragten oder dem EDÖB möglich.
DatenschutzvertretungUnternehmen mit einem Sitz ausserhalb eines EU/EWR-Landes, die ihr Angebot an Kunden in EU/EWR-Ländern richten, Daten verarbeiten oder das Verhalten beobachten, müssen einen offiziellen Vertreter in der EU/EWR bestimmen.Bei der Datenverarbeitung durch einen Verantwortlichen mit einem Sitz im Ausland ist eine Vertretung in der Schweiz zu benennen. Ebenso wenn die Datenverarbeitung mit einem hohen Risiko hergeht, umfassend oder regelmässig ist.
ProfilingAllgemeine Pflicht zur Einholung der Zustimmung.Allgemeine Pflicht zur Einholung der Zustimmung nur bei Profiling mit hohem Risiko.
InformationspflichtPflicht, betroffene Person bei Erhebung von personenbezogenen Daten zu informieren.Der Verantwortliche muss die betroffene Person über die Beschaffung von Personendaten informieren, auch wenn die Daten nicht bei der betroffenen Person beschafft werden (gem. Art. 18a).
Bearbeitung von persönlichen DatenDie Verarbeitung von Personendaten ist grundsätzlich verboten, es sei denn, es besteht eine rechtliche Grundlage (z.B. Einwilligung, Vertrag, gesetzliche Verpflichtung).Hier ist die Bearbeitung von Personendaten generell erlaubt, es sei denn, es liegt eine unzulässige Verletzung der Persönlichkeitsrechte vor.
AuskunftsrechtBetroffene Personen haben das Recht, Informationen zu ihren verarbeiteten personenbezogenen Daten zu erhalten. Dies umfasst unter anderen Verarbeitungszwecke und Datenherkunft.Ähnlich wie in der DSGVO, jedoch mit mehr Ausnahmen. Die Auskunft kann z.B. verweigert werden, wenn die Privatsphäre Dritter oder überwiegende Interessen betroffen sind.
Verzeichnis der VerarbeitungstätigkeitenUnternehmen müssen ein Verzeichnis über ihre Verarbeitungstätigkeiten führen, gemäss Art. 37.Verantwortliche/Auftragsbearbeiter führen ein Verzeichnis der Bearbeitungstätigkeiten mit einer Mindestinhaltsvorgabe. Eine Ausnahme ist der Fall bei Unternehmen mit weniger als 250 Mitarbeitenden und Datenbearbeitungen mit geringen Risiken für Persönlichkeitsverletzungen. Es gibt jedoch keine Ausnahme bei einem Profiling mit hohem Risiko oder Bearbeitung von besonders schützenswerten Daten in einem grossen Umfang.
Swiss nDSG vs. EU GDPR - onlineKarma

The new Swiss Data Protection Act ensures that the free flow of data with the EU can continue and safeguards the competitiveness of Swiss companies. It is important to comply with the provisions to avoid heavy fines and reputational damage and to maintain customer trust. 🤝

And the cookies?🍪

“No, the new data protection law in Switzerland does not require cookie banners. Switzerland is not adopting the EU Cookie Directive.”

— Martin SteigerSteiger Legal

According to Martin Steiger, the new data protection law in Switzerland does not require the use of cookie banners. Switzerland has therefore not adopted the EU Cookie Directive.

Instead of requiring explicit consent, Swiss law emphasizes providing information to users and giving them the option to opt out. Data controllers are only required to ensure that data processing is limited to the minimum necessary.

Optional privacy settings require default restrictions only if there are actually options to choose from. 💡

So, despite the new law, the use of cookie banners in Switzerland remains voluntary. 💪

✅ In short:

  • For websites hosted in Switzerland, it is sufficient to include information about the use of cookies in the privacy policy.
  • Visitors from the EU continue to be protected by their own data protection laws and must therefore explicitly consent to the use of cookies.

Conclusion

The nDSG is taking the stage by storm, ready to redefine the landscape of data protection in Switzerland. In doing so, it significantly strengthens data protection for Swiss citizens and brings the country closer to the GDPR.

But as with any exciting game, there are differences to keep in mind—the nDSG and the GDPR are not identical and therefore require us to adapt our data protection practices.

With the right preparation, Swiss companies and organizations can strengthen their market position and demonstrate their reliability to their clients. Game on! 💾

Don’t waste any time getting ready for the new law! ⏰

Animated UFC scene on the theme of time pressure

via GIPHY

Disclaimer

This article is for informational purposes only and does not constitute binding legal advice. Please note that the interpretation of laws may vary depending on the context and situation. We are not attorneys and recommend that you familiarize yourself thoroughly with the new law and prepare appropriately for the upcoming changes. We are happy to answer any questions you may have.

Do you have any questions or need assistance?

Please feel free to contact us for a no-obligation consultation.
Get in touch with no obligation

Sources:

Raphael Guldimann
About the author

Raphael Guldimann

Managing Director

Raphael Guldimann is Managing Director at onlineKarma.

Profile and more articles

You might also be interested in

An onlineKarma employee explains technical content on a laptop
July 9, 2026

How to protect your website

Cybercriminals are becoming increasingly targeted. The Federal Office for Cybersecurity (BACS) states in its latest semi-annual report that attacks are increasingly individualized, with artificial intelligence being used more and more frequently.
Read more
A person is working on building a website on a laptop
September 30, 2025

9 Tips for Creating a Strong Homepage

New visitors should be able to understand within 2–3 seconds what you offer and why they should stay.
Read more
View all items

Now you know what's possible. Let's make it happen together.

We don’t just write about it – we implement it every day for our customers.

Get in touch with no obligation

Get in touch for a no-obligation conversation. We usually reply within a few hours.

By submitting this form, you agree to our privacy policy.

Talk to us directly

Call us for a free initial consultation: 061 551 02 02.

Phone Hours
  • Mon–Thu: 8:00 a.m.–12:00 p.m. and 1:00 p.m.–5:30 p.m.
  • Fri: 8:00 a.m.–12:00 p.m. and 1:00 p.m.–5:00 p.m.
  • Sat–Sun: Closed
Call now