Skip to content
Swiss FADP

Swiss FADP for E-Commerce Businesses

7 min readUpdated 22 July 2026

E-commerce companies operating in Switzerland — whether Swiss-based or foreign businesses selling to Swiss customers — must comply with the revised Swiss FADP. The regulation came into force on 1 September 2023, and its requirements for online retailers are more demanding than the old Swiss data protection law.

This guide covers what e-commerce companies need to address.


Does FADP Apply to Your E-Commerce Business?

The revised FADP applies to any processing of personal data that has effects in Switzerland. For e-commerce businesses, this typically means:

  • Swiss-based e-commerce companies: Clearly covered
  • EU companies selling to Swiss customers: Covered for processing of Swiss customers' data
  • US or other companies with Swiss customers: Covered for the same reason

If you take orders from Swiss customers, process Swiss payment data, or run marketing to Swiss residents, FADP applies to you.


The Data You Process (and Why It Matters)

A typical e-commerce business processes:

Data categoryFADP sensitivityRelevant obligations
Customer names and contact detailsStandardPrivacy notice, retention limits
Purchase history and order dataStandardRetention, access rights
Payment dataStandard (financial — processed under strict conditions)Secure handling, limited retention
Delivery addressesStandardRetention, security
Browsing and behavioural dataStandard — but note if used for profilingConsent for tracking cookies
Email marketing listStandardConsent, opt-out
Customer service recordsStandardRetention, access rights
Health or dietary data (food/pharmacy)SensitiveHeightened requirements
Biometric data (face for verification)SensitiveHeightened requirements, DPIA

Cookie and Tracking Compliance

E-commerce sites rely heavily on cookies and tracking — analytics, retargeting, cart abandonment, and personalisation. Under FADP, combined with the Swiss Telecommunications Act (FMG) and its successor provisions:

  • Strictly necessary cookies (session, cart, authentication): No consent required
  • Analytics cookies (traffic analysis, conversion tracking): Consent required in Switzerland — this aligns with Germany's strict approach
  • Retargeting and advertising cookies (Google Ads, Meta Pixel, affiliate tracking): Consent required
  • Personalisation cookies (recommended products, saved preferences): Consent required unless strictly necessary to the service

Practical requirement: You need a cookie consent banner that:

  • Blocks non-essential scripts until consent is given
  • Offers a genuine, equally prominent reject option
  • Records what consent was given and when

Google Analytics 4, Meta Pixel, and similar tools must not load until the user consents. This is often not what default e-commerce platform installations do — review and configure accordingly.


Privacy Notice Requirements

Your website privacy notice must include (under FADP Article 19):

  • Your identity and contact details as the controller
  • Purpose of each processing activity (orders, marketing, analytics, reviews)
  • Categories of recipients (payment processors, shipping partners, marketing tools)
  • Countries to which data is transferred and the safeguards
  • Retention periods or criteria
  • Rights of data subjects and how to exercise them

Cross-border transfers in the e-commerce context: If you use US-based tools (Shopify, Google Analytics, Meta Pixel, Klaviyo, Stripe), these are all transfers out of Switzerland. Each must have a valid mechanism:

  • DPF certification: check at dataprivacyframework.gov
  • Swiss SCCs: if DPF does not apply

Disclose each transfer in your privacy notice.


Marketing and Email Consent

Swiss law — including FADP and the Unfair Competition Act (UWG) — requires opt-in consent for direct marketing emails to natural persons.

Requirements for valid email marketing consent:

  • Prior, express consent before the first marketing email
  • Consent must be specific — "I agree to receive marketing emails from [company]"
  • Double opt-in (confirmation email) is best practice and frequently required by email service providers
  • Clear and easy unsubscribe in every marketing email

Soft opt-in (existing customers): Switzerland's rules are less developed than the EU's ePrivacy rules on existing customer exemptions, but the general principle is: if a customer purchased from you and you wish to market similar products, you may have a legitimate interest — but this must be assessed and documented, and an opt-out must always be provided.


Customer Data Retention

Retail and e-commerce data has specific retention tensions:

Data typeRetention driverRecommended limit
Order recordsSwiss accounting law requires 10-year retention10 years for financial records
Customer account dataDuration of account + reasonable periodAccount lifetime + 2 years
Marketing dataUntil opt-outSuppression list retained indefinitely
Browsing/analytics dataNo legal requirementMaximum 24 months
Payment card dataPCI DSS rules — minimise retentionDo not store card numbers; limited transaction data

Data Subject Rights for Customers

E-commerce customers are entitled to:

  • Access: Request a copy of their data — purchase history, account details, marketing preferences, behavioural data
  • Erasure: Request deletion of their account and associated data — but financial records may need to be retained under accounting law
  • Portability: Receive their data in a structured format (order history export)
  • Object: Opt out of marketing and profiling

Build a self-service portal where customers can:

  • Download their order history and personal data
  • Update or correct their details
  • Delete their account (with explanation of what is retained for legal reasons)
  • Manage marketing preferences

This satisfies most DSAR requirements without manual processing.


Profiling and Personalisation

Many e-commerce platforms use behavioural data to personalise product recommendations, target abandoned cart emails, or segment customers for dynamic pricing. Where this constitutes profiling:

  • Disclose it in the privacy notice
  • If it results in decisions with significant effects on individuals (differential pricing affecting access, for example), ensure a human review pathway exists
  • Obtain consent where the personalisation relies on tracking cookies

Breach Response

If customer data is exposed in a breach:

  • Assess risk to customers — payment data, contact details, purchase history
  • E-commerce breaches involving payment data typically meet the "high risk" threshold
  • Notify the FDPIC as soon as possible
  • Notify affected customers if the breach poses high risk to them
  • Coordinate with your payment processor — they have their own PCI DSS incident obligations

ComplyOne assesses your FADP compliance alongside GDPR and identifies the gaps specific to Swiss law.

Check your Swiss FADP obligations →