A privacy notice (data protection declaration) is mandatory under Switzerland's revised FADP. It must inform data subjects what personal data you collect, why you process it, who receives it, and how they can exercise their rights. This template covers the required elements with explanatory notes.
What the FADP Requires
Under FADP Article 19, controllers must provide data subjects with certain minimum information at the time of data collection (or as soon as practicable for indirectly collected data). The privacy notice must include:
- Identity and contact details of the controller
- Purpose of processing
- Recipients or categories of recipients
- Countries to which data is transferred and the safeguards applied
- Right to request information and the procedure to do so
- Right to rectification and other applicable rights
The notice must be written in a way that data subjects can understand it — clear, plain language, not legal jargon.
Privacy Notice Template
Below is a template for a Swiss FADP-compliant privacy notice for a SaaS company. Replace the bracketed placeholders with your own information. The template also covers GDPR requirements for companies with EU customers.
Data Protection Declaration
Last updated: [date]
1. Controller
[Company name] ("we", "us", "our") is the controller responsible for processing your personal data.
Contact: [Company name] [Address, Switzerland / or registered address] [Email: privacy@yourcompany.com]
2. Data We Collect and Why
a) Account Data When you register an account, we collect: your name, email address, job title, and company name. We use this data to create and manage your account and to provide you with access to our service.
Legal basis (GDPR): Performance of contract (Article 6(1)(b)). FADP basis: Necessary for the purpose of providing the service.
b) Service Usage Data As you use the service, we collect data about how you interact with our product: features accessed, actions taken, session duration, and error logs. We use this data to operate and improve the service and to provide customer support.
Legal basis (GDPR): Legitimate interests (Article 6(1)(f)) — improving the service for all users. FADP basis: Proportionate and in line with our stated purpose.
c) Communications When you contact us by email or through our support system, we collect your name, email address, and the content of your communications. We use this data to respond to your enquiry and resolve support requests.
Legal basis (GDPR): Legitimate interests (Article 6(1)(f)) — responding to communications. FADP basis: Proportionate and in line with our stated purpose.
d) Billing Data When you subscribe to a paid plan, we collect billing contact details (name, address, VAT number if applicable). Payment card data is processed directly by our payment provider — we do not store card numbers.
Legal basis (GDPR): Performance of contract (Article 6(1)(b)) and legal obligation (tax records). FADP basis: Necessary to fulfil the contract and meet legal obligations.
e) Marketing Communications If you subscribe to our newsletter or marketing communications, we will send you product updates, compliance guides, and relevant information about our services.
Legal basis (GDPR): Consent (Article 6(1)(a)) — you can withdraw at any time. FADP basis: Your consent.
You can unsubscribe at any time by clicking the unsubscribe link in any marketing email or by emailing [privacy@yourcompany.com].
f) Website and Cookies When you visit our website, we collect standard technical information: IP address, browser type, pages visited, and referral source. We use this data for security and to understand how our website is used.
For non-essential cookies (analytics, preferences), we obtain your consent via our cookie banner. See our [Cookie Policy] for details.
Legal basis (GDPR): Legitimate interests (security, technical operation); consent (analytics cookies). FADP basis: Proportionate to purpose; consent for non-essential cookies.
3. Who Receives Your Data
We share personal data with the following categories of recipients:
| Recipient | Purpose | Location |
|---|---|---|
| [Cloud provider, e.g. AWS] | Infrastructure and data hosting | [e.g. EU (Frankfurt)] |
| [Email provider, e.g. Postmark] | Transactional email delivery | [e.g. US — DPF certified] |
| [Analytics tool, e.g. Mixpanel] | Product usage analytics | [e.g. US — SCCs executed] |
| [Support tool, e.g. Intercom] | Customer support | [e.g. US — SCCs executed] |
| [Payment provider, e.g. Stripe] | Payment processing | [e.g. US — DPF / independent controller] |
We do not sell personal data to third parties.
4. International Data Transfers
Some of the recipients listed above are located outside Switzerland and the EU/EEA. Where we transfer personal data internationally, we ensure appropriate safeguards are in place:
- Transfers to EU/EEA: Switzerland has been granted adequacy status by the EU. Transfers between Switzerland and EU/EEA countries are lawful.
- Transfers to the US: Where vendors are certified under the EU-US Data Privacy Framework (DPF), we rely on the adequacy decision. Where DPF certification does not apply, we execute Standard Contractual Clauses (SCCs) approved by the Federal Council / European Commission.
- Other countries: We only transfer to countries on the Federal Council's adequacy list or where we have executed approved Standard Data Protection Clauses.
For information about specific transfer mechanisms for a particular recipient, contact [privacy@yourcompany.com].
5. Retention Periods
| Data category | Retention period |
|---|---|
| Account data | Duration of account + 30 days after deletion |
| Usage data and logs | 24 months |
| Support communications | 3 years from last interaction |
| Billing records | 10 years (legal obligation under Swiss accounting law) |
| Marketing list | Until unsubscribe + suppression record retained |
| Security and access logs | 12 months |
6. Your Rights
Under the Swiss FADP and (where applicable) GDPR, you have the following rights:
- Right of access: Request confirmation of whether we process your data and obtain a copy
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your data in certain circumstances
- Right to restriction: Request that we limit processing in certain circumstances
- Right to data portability: Receive your data in a structured, machine-readable format (GDPR)
- Right to object: Object to processing based on legitimate interests
- Right regarding automated decisions: Request explanation and human review of automated decisions with significant effects on you
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time
To exercise your rights, contact us at [privacy@yourcompany.com]. We will respond within 30 days.
If you believe we have violated your data protection rights, you have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch (Switzerland) or the supervisory authority in your EU member state.
7. Automated Decision-Making
[If applicable:] We use [describe AI/automated feature]. This may produce [describe output]. Where this has a significant effect on you, you have the right to request a human review and an explanation of the decision. Contact [privacy@yourcompany.com] to exercise this right.
[If not applicable:] We do not make automated decisions that produce legal or similarly significant effects on individuals without human review.
8. Security
We implement technical and organisational security measures appropriate to the risk, including [encryption at rest and in transit, access controls, regular security testing]. We hold [ISO 27001 / SOC 2 certification — specify if applicable].
9. Changes to This Notice
We update this notice when our processing activities change. We will notify you of significant changes by email or by displaying a notice within the product. The date at the top of this notice indicates when it was last updated.
10. Contact
For any questions about this notice or how we process your personal data:
[privacy@yourcompany.com] [Company name], [Address]
Notes for Customisation:
- Complete Section 3 with your actual sub-processors and their locations
- Verify transfer mechanisms for each US vendor — confirm DPF certification or executed SCCs
- Add or remove data categories in Section 2 to match your actual processing
- Section 7 (automated decisions) must be completed if you use AI features that produce individual-level outputs