New Data Protection Rules in Switzerland – What Companies and Organizations Need to Know Now
The new Swiss Data Protection Act (nDSG) takes effect on September 1, 2023.
The nDSG (or revDSG) aims to harmonize with the EU General Data Protection Regulation (GDPR) and is intended to better protect the data of Swiss citizens by adapting to technological developments.
In an era in which technology is advancing at a rapid pace and AI applications like ChatGPT are playing an increasingly important role in our lives, it is more important than ever to ensure privacy and data protection. The nDSG holds the promise of a modern data protection framework. 🔭
A 🧭 Alignment of the nDSG toward the GDPR is evident, even though the nDSG does not align with the GDPR in all cases. For the most part, the new Swiss law is less stringent and is only more restrictive than the European one in a few specific areas.
The European data protection law also applies to many Swiss organizations.
You can find out when and how the GDPR applies to Swiss companies and organizations in the GDPR Switzerland Checklist. 🧾

As a result, some organizations must comply with both European and Swiss data protection laws. That’s why even organizations that already meet the requirements of the GDPR need to take action. 🎬
Here you’ll learn about the key differences between the two data protection laws:
nDSG vs. GDPR: 11 Key Differences
| DSGVO | nDSG | |
|---|---|---|
| Sanktionen | Geldbussen an das verantwortliche Unternehmen bis zu 20 Mio. EUR oder 4 % des weltweiten Jahresumsatzes des Unternehmens. | Bei Verstoss gegen Regelungen strafrechtliche Bussen bis zu 250’000 CHF. Dabei ist die Strafe mit Ausnahmen an die verantwortliche natürliche Person geknüpft. |
| Melden von Datenschutzverletzungen | Pflicht, Datenschutzverletzungen mit Risiken für die betroffenen Personen der Datenschutzbehörde innerhalb von 72 Stunden zu melden. Besteht ein hohes Risiko für die Persönlichkeit, so muss die Person benachrichtigt werden. | Pflicht, sofern es zum Schutz der betroffenen Personen erforderlich ist. Das EDÖB muss vom Verantwortlichen nur bei einem hohen Risiko informiert werden, sprich, wenn es zum Schutz der betroffenen Person erforderlich ist. Dabei gilt keine Frist von 72 Stunden, sondern “möglichst schnell”. |
| Datenexporte | Die Europäische Kommission entscheidet über die Zulässigkeit. EU-Standardvertragsklauseln und verbindliche unternehmensinterne Vorschriften sind anwendbar. | Das gleiche Konzept. Der Bundesrat entscheidet über die Zulässigkeit von Datenexporten. Dieselben Standardvertragsklauseln und verbindlichen unternehmensinternen Vorschriften wie in der EU sind anwendbar. |
| Benennung eines Datenschutzbeauftragten | Pflicht, wenn das Unternehmen regelmässige und systematische Überwachung in grossem Umfang durchführt oder besondere Kategorien von Daten in grossem Umfang verarbeitet, gemäss Art. 37. | Keine Pflicht, aber ausdrücklich empfohlen. Die Benennung führt zu Erleichterung bei einer Datenverarbeitung mit einem hohen Risiko für die Persönlichkeit oder die Grundrechte der betroffenen Person. |
| Datenschutz-Folgenabschätzung | Wenn trotz ergriffener Massnahmen ein hohes Risiko besteht, dann ist eine Rücksprache mit Aufsichtsbehörden obligatorisch. | Wenn ein hohes Risiko für die Persönlichkeit oder Grundrechte der betroffenen Personen besteht, so ist eine Datenschutz-Folgeabschätzung (DSFA) durchzuführen. Wenn trotz der Massnahmen das Risiko weiter besteht, dann ist die Rücksprache mit einem Datenschutzbeauftragten oder dem EDÖB möglich. |
| Datenschutzvertretung | Unternehmen mit einem Sitz ausserhalb eines EU/EWR-Landes, die ihr Angebot an Kunden in EU/EWR-Ländern richten, Daten verarbeiten oder das Verhalten beobachten, müssen einen offiziellen Vertreter in der EU/EWR bestimmen. | Bei der Datenverarbeitung durch einen Verantwortlichen mit einem Sitz im Ausland ist eine Vertretung in der Schweiz zu benennen. Ebenso wenn die Datenverarbeitung mit einem hohen Risiko hergeht, umfassend oder regelmässig ist. |
| Profiling | Allgemeine Pflicht zur Einholung der Zustimmung. | Allgemeine Pflicht zur Einholung der Zustimmung nur bei Profiling mit hohem Risiko. |
| Informationspflicht | Pflicht, betroffene Person bei Erhebung von personenbezogenen Daten zu informieren. | Der Verantwortliche muss die betroffene Person über die Beschaffung von Personendaten informieren, auch wenn die Daten nicht bei der betroffenen Person beschafft werden (gem. Art. 18a). |
| Bearbeitung von persönlichen Daten | Die Verarbeitung von Personendaten ist grundsätzlich verboten, es sei denn, es besteht eine rechtliche Grundlage (z.B. Einwilligung, Vertrag, gesetzliche Verpflichtung). | Hier ist die Bearbeitung von Personendaten generell erlaubt, es sei denn, es liegt eine unzulässige Verletzung der Persönlichkeitsrechte vor. |
| Auskunftsrecht | Betroffene Personen haben das Recht, Informationen zu ihren verarbeiteten personenbezogenen Daten zu erhalten. Dies umfasst unter anderen Verarbeitungszwecke und Datenherkunft. | Ähnlich wie in der DSGVO, jedoch mit mehr Ausnahmen. Die Auskunft kann z.B. verweigert werden, wenn die Privatsphäre Dritter oder überwiegende Interessen betroffen sind. |
| Verzeichnis der Verarbeitungstätigkeiten | Unternehmen müssen ein Verzeichnis über ihre Verarbeitungstätigkeiten führen, gemäss Art. 37. | Verantwortliche/Auftragsbearbeiter führen ein Verzeichnis der Bearbeitungstätigkeiten mit einer Mindestinhaltsvorgabe. Eine Ausnahme ist der Fall bei Unternehmen mit weniger als 250 Mitarbeitenden und Datenbearbeitungen mit geringen Risiken für Persönlichkeitsverletzungen. Es gibt jedoch keine Ausnahme bei einem Profiling mit hohem Risiko oder Bearbeitung von besonders schützenswerten Daten in einem grossen Umfang. |

The new Swiss Data Protection Act ensures that the free flow of data with the EU can continue and safeguards the competitiveness of Swiss companies. It is important to comply with the provisions to avoid heavy fines and reputational damage and to maintain customer trust. 🤝
And the cookies?🍪
“No, the new data protection law in Switzerland does not require cookie banners. Switzerland is not adopting the EU Cookie Directive.”
According to Martin Steiger, the new data protection law in Switzerland does not require the use of cookie banners. Switzerland has therefore not adopted the EU Cookie Directive.
Instead of requiring explicit consent, Swiss law emphasizes providing information to users and giving them the option to opt out. Data controllers are only required to ensure that data processing is limited to the minimum necessary.
Optional privacy settings require default restrictions only if there are actually options to choose from. 💡
So, despite the new law, the use of cookie banners in Switzerland remains voluntary. 💪
✅ In short:
- For websites hosted in Switzerland, it is sufficient to include information about the use of cookies in the privacy policy.
- Visitors from the EU continue to be protected by their own data protection laws and must therefore explicitly consent to the use of cookies.
Conclusion
The nDSG is taking the stage by storm, ready to redefine the landscape of data protection in Switzerland. In doing so, it significantly strengthens data protection for Swiss citizens and brings the country closer to the GDPR.
But as with any exciting game, there are differences to keep in mind—the nDSG and the GDPR are not identical and therefore require us to adapt our data protection practices.
With the right preparation, Swiss companies and organizations can strengthen their market position and demonstrate their reliability to their clients. Game on! 💾
Don’t waste any time getting ready for the new law! ⏰

Disclaimer
This article is for informational purposes only and does not constitute binding legal advice. Please note that the interpretation of laws may vary depending on the context and situation. We are not attorneys and recommend that you familiarize yourself thoroughly with the new law and prepare appropriately for the upcoming changes. We are happy to answer any questions you may have.
Do you have any questions or need assistance?
Sources:



