Data protection for Swiss companies: Prepare for the new law
Data protection & data processing on the Internet

Data protection for Swiss companies: Prepare for the new law

06/02/2023

In the run-up to the entry into force of the Swiss Federal Data Protection Act (FADP), every company needs to rethink its data protection measures. Among other things, this concerns the company website and its cookie management. In this article, you will learn more about cookies, data protection and steps that can help you stay on the safe side with the upcoming law.

What are cookies?

Cookies are text files that are stored when visiting a website in order to determine the visitor's activities on this website. 

Cookies are used, among other things, so that the website can offer a better user experience (e.g. saving settings selected once for future visits) or so that user behavior is further used for web analytic purposes.

There are four types of cookies:

  • Essential: Necessary for the basic functionality of the website. Through them, only information about the current session is stored and deleted after its termination.
  • Functional or preference cookies enable additional functionality such as linking external media (Youtube, social media, Google Fonts, etc.) or user selection such as language setting.
  • Statistics cookies contain behavioral data for geo- and demographic analysis. They are anonymized, i.e. they are not linked to personal data.
  • Marketing cookies contain user data for marketing purposes (personalized ads).

Privacy, cookies and data misuse

Why are cookies a privacy concern?

Valuable information in cookies

What data is collected?

Cookies can contain a variety of personal information, such as name, email address, phone number, location, and other data that the visitor provides himself when using them. In addition, his activities such as clicks, search history, purchases and more can be evidenced.

Cookie tracking gives you the opportunity to get valuable information about who is searching for your products, where your visitors are coming from, and how likely they are to visit your website again.

Specifically, cookies do not contain data about the particular personality of the website visitor. However, when combined with other relevant cookies, they can be used to create an online persona and thus retarget the user across websites. 

Datenschutz und Datenmissbrauch

Welche Gefahren bestehen?

According to data protection, everyone has the right to determine for themselves what personal data is made available, when, to whom and for what purpose. Since personal data is stored and transmitted through cookies, it is the responsibility of website operators to ensure transparency regarding cookie use as well as the possibility of choice.

The biggest problem with cookies is the risk of data misuse via their use, either through cookie theft or non-consented, cross-site tracking for marketing purposes.

In addition, European privacy activists have concerns about the Internet giant Google, which provides all collected data, including personal data of its users, to the U.S. government. Many privacy experts recommend avoiding Google services unless the US legal requirements are changed to bypass the transfer of personal data to US intelligence agencies.

The new Swiss Data Protection Act

What will be changed?

The revised Swiss Data Protection Act will enter into force without transition periods on September 1, 2023. The revision is due to rapid technological developments as well as the required equivalence of the level of protection with the EU (DSGVO).

The changes in the law largely relate to:

  • greater transparency with regard to data processing,
  • a higher degree of self-determination and 
  • stronger data protection authority.

The visitor may request details about which of his or her data is used, how it is used, and to whom it is disclosed. Companies have a duty to provide information regarding the purpose of the data processing, the contact details of the person responsible, the recipient and the recipient country in the case of data export abroad.

In contrast to the GDPR, consent is still not required for the processing of personal data, provided that no particularly sensitive personal data is involved. However, the visitor must be able to control the settings about the processing of his data himself (e.g. by using the "Cookie settings" option on the cookie banner).

An implicit consent request in the cookie banner (e.g. "By continuing to use the website, you consent to the use of cookies") is not permitted with the new law.

Important:

This article contains general information and relates to data protection on the Internet. For complete advice on the implementation of data protection in the company, please consult with a lawyer.

Steps for website owners: what can you do?

Find out exactly about processes on your website that collect personal data.

Which cookies are used on your website and for what purpose?
Is data transferred to external order processors?
Is personal data processed abroad? If so, is it handled there in compliance with data protection laws?

Update your privacy policy.

According to the new law, every website must contain an up-to-date privacy statement. Among other things, this must contain transparent information about the nature, scope and purpose of any data processing as well as the rights of the data subjects.

Check your cookie banner.

Companies operating only in Switzerland are still not required to obtain tracking consent from visitors when they access the website. According to the new Swiss DPA, the cookie banner only requires information about cookie use with a link to the privacy policy and with the option of cookie settings. However, if visitors from the EU also access the website, no data may be transmitted without consent.

Make sure that no form can be sent on the website without consent.

A checkbox as a mandatory field with the reference to the privacy policy ensures that the visitor gives consent to the appropriate processing of his data before sending the message.

Consider your web analytics solution.

Web analytics tools (Google Analytics, Matomo, etc.) are important for website operators to understand the behavior of their visitors. However, their use requires data collection. You should make an informed decision about which tool to use.

Embed the Google fonts locally.

If the Google font on your website is not pulled from the Google server, but is embedded locally on your website's server, no contact with the Google server is initiated when you visit your website.

We support you

On the way to a data protection-compliant website, we can provide you with consulting and technical support. For any questions on the subject, write to us or call us (+41 43 255 68 68). Our team of experts will be happy to assist you.

Contact now