Privacy Policy Notice Template for Switzerland
Generate a bespoke document
What is a Privacy Policy Notice?
A Privacy Policy Notice is a legally required document under Swiss data protection law that must be provided by organizations processing personal data in Switzerland. This document has gained increased importance following the implementation of the revised Federal Act on Data Protection (revFADP) in September 2023, which introduced enhanced requirements for transparency and accountability in data processing activities. Organizations must maintain an up-to-date Privacy Policy Notice that accurately reflects their data processing activities, provides information about data subject rights, and details the measures taken to protect personal information. The document must comply with Swiss legal requirements while often also considering EU GDPR standards due to Switzerland's close economic ties with the EU and the need for maintaining adequacy status. It serves as a key transparency tool and helps organizations demonstrate compliance with data protection principles.
About the Privacy Policy Notice
A Privacy Policy Notice is a fundamental legal document that you must provide when processing personal data in Switzerland. Under the revised Federal Act on Data Protection (revFADP) effective from September 2023, this document serves as your primary transparency tool, informing data subjects about how you collect, use, and protect their personal information. Your privacy notice must be clear, accessible, and comprehensive, covering all aspects of your data processing activities while ensuring compliance with Swiss data protection principles.
When do you need this document?
You need a Privacy Policy Notice whenever you process personal data of individuals in Switzerland, regardless of your organization's location. This applies whether you're collecting customer information through your website, processing employee data, handling client records, or engaging third-party processors. The document is mandatory for all businesses operating in Switzerland, including multinational companies with Swiss subsidiaries, local SMEs handling customer data, and organizations providing digital services to Swiss residents. You must also update your privacy notice whenever you change your data processing activities, add new data categories, or modify your legal basis for processing.
Key legal considerations
Your Privacy Policy Notice must include specific mandatory elements under the revFADP, including your identity and contact details as data controller, the categories of personal data you process, and the purposes and legal basis for processing. You must clearly explain data subject rights, including access, rectification, deletion, and data portability rights, along with instructions on how individuals can exercise these rights. The document should detail any international data transfers, including the countries involved and appropriate safeguards implemented. If you share data with third parties or group companies, you must identify these recipients and explain the purposes of such sharing. Consider including information about automated decision-making processes and your data retention periods to enhance transparency.
Legal requirements in Switzerland
Swiss law requires your Privacy Policy Notice to be written in plain, understandable language and made easily accessible to data subjects before or at the time of data collection. Under Article 19 of the revFADP, you must proactively inform individuals about data processing, meaning the notice should be prominently displayed on your website and provided during data collection activities. The document must comply with Swiss Federal Constitution Article 13 regarding privacy rights and align with the principle of transparency established in the revFADP. If you process data of EU residents, your notice should also meet GDPR requirements to maintain compliance across jurisdictions. Regular updates are mandatory when processing activities change, and you must maintain records demonstrating compliance with transparency obligations for potential audits by the Swiss Federal Data Protection and Information Commissioner.
GOVERNING LAW
Applicable law
This Privacy Policy Notice is drafted to comply with Switzerland law. Key legislation includes:
Swiss Federal Constitution (Article 13): Establishes the fundamental right to privacy and protection against misuse of personal data in Switzerland.
EU General Data Protection Regulation (GDPR): While not Swiss law, it's relevant for Swiss companies processing data of EU residents or offering goods/services to the EU market. Swiss Privacy Policies often comply with GDPR to ensure broader coverage.
Swiss Civil Code: Contains provisions on personality rights protection that can affect privacy matters, particularly Article 28 on protection against violations of personality rights.
Swiss Criminal Code: Includes provisions on data theft and unauthorized data access (Article 143), which should be considered in privacy policies.
Swiss Telecommunications Act: Relevant if the organization handles telecommunications data or provides telecommunications services, containing specific privacy requirements for this sector.
Federal Act on Unfair Competition (UWG): Contains provisions relevant to data protection in the context of commercial practices and customer data handling.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it