E-commerce companies operating in Switzerland — whether Swiss-based or foreign businesses selling to Swiss customers — must comply with the revised Swiss FADP. The regulation came into force on 1 September 2023, and its requirements for online retailers are more demanding than the old Swiss data protection law.
This guide covers what e-commerce companies need to address.
Does FADP Apply to Your E-Commerce Business?
The revised FADP applies to any processing of personal data that has effects in Switzerland. For e-commerce businesses, this typically means:
- Swiss-based e-commerce companies: Clearly covered
- EU companies selling to Swiss customers: Covered for processing of Swiss customers' data
- US or other companies with Swiss customers: Covered for the same reason
If you take orders from Swiss customers, process Swiss payment data, or run marketing to Swiss residents, FADP applies to you.
The Data You Process (and Why It Matters)
A typical e-commerce business processes:
| Data category | FADP sensitivity | Relevant obligations |
|---|---|---|
| Customer names and contact details | Standard | Privacy notice, retention limits |
| Purchase history and order data | Standard | Retention, access rights |
| Payment data | Standard (financial — processed under strict conditions) | Secure handling, limited retention |
| Delivery addresses | Standard | Retention, security |
| Browsing and behavioural data | Standard — but note if used for profiling | Consent for tracking cookies |
| Email marketing list | Standard | Consent, opt-out |
| Customer service records | Standard | Retention, access rights |
| Health or dietary data (food/pharmacy) | Sensitive | Heightened requirements |
| Biometric data (face for verification) | Sensitive | Heightened requirements, DPIA |
Cookie and Tracking Compliance
E-commerce sites rely heavily on cookies and tracking — analytics, retargeting, cart abandonment, and personalisation. Under FADP, combined with the Swiss Telecommunications Act (FMG) and its successor provisions:
- Strictly necessary cookies (session, cart, authentication): No consent required
- Analytics cookies (traffic analysis, conversion tracking): Consent required in Switzerland — this aligns with Germany's strict approach
- Retargeting and advertising cookies (Google Ads, Meta Pixel, affiliate tracking): Consent required
- Personalisation cookies (recommended products, saved preferences): Consent required unless strictly necessary to the service
Practical requirement: You need a cookie consent banner that:
- Blocks non-essential scripts until consent is given
- Offers a genuine, equally prominent reject option
- Records what consent was given and when
Google Analytics 4, Meta Pixel, and similar tools must not load until the user consents. This is often not what default e-commerce platform installations do — review and configure accordingly.
Privacy Notice Requirements
Your website privacy notice must include (under FADP Article 19):
- Your identity and contact details as the controller
- Purpose of each processing activity (orders, marketing, analytics, reviews)
- Categories of recipients (payment processors, shipping partners, marketing tools)
- Countries to which data is transferred and the safeguards
- Retention periods or criteria
- Rights of data subjects and how to exercise them
Cross-border transfers in the e-commerce context: If you use US-based tools (Shopify, Google Analytics, Meta Pixel, Klaviyo, Stripe), these are all transfers out of Switzerland. Each must have a valid mechanism:
- DPF certification: check at dataprivacyframework.gov
- Swiss SCCs: if DPF does not apply
Disclose each transfer in your privacy notice.
Marketing and Email Consent
Swiss law — including FADP and the Unfair Competition Act (UWG) — requires opt-in consent for direct marketing emails to natural persons.
Requirements for valid email marketing consent:
- Prior, express consent before the first marketing email
- Consent must be specific — "I agree to receive marketing emails from [company]"
- Double opt-in (confirmation email) is best practice and frequently required by email service providers
- Clear and easy unsubscribe in every marketing email
Soft opt-in (existing customers): Switzerland's rules are less developed than the EU's ePrivacy rules on existing customer exemptions, but the general principle is: if a customer purchased from you and you wish to market similar products, you may have a legitimate interest — but this must be assessed and documented, and an opt-out must always be provided.
Customer Data Retention
Retail and e-commerce data has specific retention tensions:
| Data type | Retention driver | Recommended limit |
|---|---|---|
| Order records | Swiss accounting law requires 10-year retention | 10 years for financial records |
| Customer account data | Duration of account + reasonable period | Account lifetime + 2 years |
| Marketing data | Until opt-out | Suppression list retained indefinitely |
| Browsing/analytics data | No legal requirement | Maximum 24 months |
| Payment card data | PCI DSS rules — minimise retention | Do not store card numbers; limited transaction data |
Data Subject Rights for Customers
E-commerce customers are entitled to:
- Access: Request a copy of their data — purchase history, account details, marketing preferences, behavioural data
- Erasure: Request deletion of their account and associated data — but financial records may need to be retained under accounting law
- Portability: Receive their data in a structured format (order history export)
- Object: Opt out of marketing and profiling
Build a self-service portal where customers can:
- Download their order history and personal data
- Update or correct their details
- Delete their account (with explanation of what is retained for legal reasons)
- Manage marketing preferences
This satisfies most DSAR requirements without manual processing.
Profiling and Personalisation
Many e-commerce platforms use behavioural data to personalise product recommendations, target abandoned cart emails, or segment customers for dynamic pricing. Where this constitutes profiling:
- Disclose it in the privacy notice
- If it results in decisions with significant effects on individuals (differential pricing affecting access, for example), ensure a human review pathway exists
- Obtain consent where the personalisation relies on tracking cookies
Breach Response
If customer data is exposed in a breach:
- Assess risk to customers — payment data, contact details, purchase history
- E-commerce breaches involving payment data typically meet the "high risk" threshold
- Notify the FDPIC as soon as possible
- Notify affected customers if the breach poses high risk to them
- Coordinate with your payment processor — they have their own PCI DSS incident obligations