Skip to content
UK GDPR

UK GDPR for Swiss Businesses Selling into the UK

4 min readUpdated 2 September 2026

Swiss companies selling products or services to UK customers face UK GDPR obligations in addition to their Swiss FADP requirements. Switzerland is not in the EU, was never subject to EU GDPR, and is not subject to UK GDPR directly — but UK GDPR's extraterritorial scope means that processing UK residents' personal data triggers UK compliance obligations regardless of where the company is based.


Does UK GDPR Apply to Swiss Companies?

UK GDPR applies to controllers not established in the UK when they:

  • Offer goods or services to UK individuals (whether free or paid), or
  • Monitor the behaviour of UK individuals

For Swiss companies: If your business serves UK customers, accepts UK orders, or markets to UK individuals, UK GDPR applies to your processing of their personal data. The fact that you are based in Switzerland (outside the EU and UK) does not exempt you.

Practical triggers:

  • UK pricing on your website (GBP)
  • UK-targeted marketing or advertising
  • UK customer support
  • Accepting UK payment methods
  • A significant proportion of your customers are UK-based

The UK-Switzerland Data Transfer Position

Swiss companies need to understand data flows between Switzerland and the UK:

UK → Switzerland: The UK has made adequacy regulations for Switzerland. Personal data can be transferred from the UK to Switzerland without additional mechanisms. The UK considers Switzerland adequate.

Switzerland → UK: Swiss FADP also recognises the UK as adequate for Swiss data transfer purposes. Personal data can flow from Switzerland to the UK without Swiss SCCs.

Result: For direct Switzerland ↔ UK data flows, mutual adequacy means no additional transfer mechanisms are needed in either direction. This is a material simplification compared to many other cross-border relationships.


What Swiss Companies Need for UK GDPR Compliance

1. UK GDPR Representative

Swiss companies without a UK establishment that process UK residents' data must appoint a UK GDPR representative (Article 27 UK GDPR). This is the same requirement that applies to EU companies.

The representative must be:

  • Established in the UK
  • Named in writing by the Swiss company
  • Identified in the UK privacy notice

Several specialist UK GDPR representative service companies can be engaged for a relatively modest annual fee.

2. UK Privacy Notice

Your privacy notice must include UK-specific content:

  • The ICO as the supervisory authority for UK data subjects
  • Your UK representative's contact details
  • UK-specific rights under UK GDPR (same as EU GDPR in substance, but referencing UK law)
  • Transfer information (UK → Switzerland covered by adequacy)

The simplest approach: add a "UK Users" section to your existing Swiss FADP privacy notice, or maintain a separate UK privacy notice page.

3. UK Transfer Mechanisms (for Swiss → US and Beyond)

Switzerland has its own transfer mechanisms (Swiss SCCs, Swiss DPF). But when Swiss personal data flows to the US on behalf of UK customers, the UK transfer position may also be relevant:

If UK customer data flows through Swiss infrastructure to a US cloud provider, you need:

  • Swiss DPF or Swiss SCCs for the Switzerland → US transfer
  • UK Bridge or UK IDTA for the UK → US transfer (if the data originated as UK personal data processed under UK GDPR)

In practice, most Swiss companies handle this by ensuring their US vendors are both Swiss DPF and UK Bridge certified, covering both obligations with one vendor certification.

4. ICO Breach Reporting

If a breach affects UK individuals, report to the ICO within 72 hours. This is separate from any FDPIC notification obligation under Swiss FADP. Both may be required for a breach affecting both Swiss and UK individuals.


Running Dual Compliance: Swiss FADP + UK GDPR

The practical compliance approach for Swiss companies with UK customers:

Combined privacy notice with UK and Swiss sections:

  • Core requirements (same under FADP and UK GDPR)
  • Swiss section: FDPIC as supervisory authority, Swiss rights
  • UK section: ICO as supervisory authority, UK representative contact

Single DSAR process: The right to access, rectification, erasure, and portability is substantively the same under both frameworks. One process can handle requests from both Swiss and UK individuals, with appropriate identification of which law governs the specific request.

Breach procedure covering both timelines: FADP says "as soon as possible" (treated as ~72 hours in practice); UK GDPR says 72 hours explicitly. One procedure with a 72-hour target covers both.

DPA / processing agreements: For B2B sales to UK businesses, UK customers may request UK GDPR-compliant DPAs. These are substantively equivalent to FADP processing agreements but should reference UK law.

ComplyOne covers UK GDPR and EU GDPR in one platform — identifying the specific gaps between the two frameworks.

Check your UK GDPR compliance →