Our Expert in Switzerland
No results available
Whether cookie consent is required in Switzerland depends on what the cookie does, what data it collects, and who visits the website. Following the FDPIC’s (EDÖB’s) updated cookie guidelines published on 7 October 2025, Swiss businesses face a clearer, but more demanding, set of rules: functional cookies generally require only transparent notice and an opt-out mechanism, while personalised advertising, profiling, and non-essential tracking demand explicit, documented consent under the revised Federal Act on Data Protection (nFADP). This guide unpacks the legal framework, maps each cookie type to its consent requirement, and provides ready-to-use banner copy, documentation checklists, and cross-border compliance steps for websites that also serve EU residents.
Here is what this article covers:
Switzerland’s cookie consent framework sits at the intersection of three legal instruments. Understanding how they interact is the first step toward compliance.
The revised Federal Act on Data Protection (nFADP), in force since 1 September 2023, governs the processing of personal data in Switzerland. The nFADP requires that every instance of personal-data processing rests on a recognised lawful basis, which may include consent, a prevailing private interest, or a statutory obligation. Consent, where it is the applicable basis, must be informed and given voluntarily. For sensitive personal data and high-risk profiling, the nFADP mandates express consent, meaning the individual must actively agree after receiving clear information about the processing purpose.
The FDPIC cookie guidelines (updated version, 7 October 2025) translate these statutory rules into practical instructions for website operators. The guidelines distinguish between cookies that are strictly necessary for a service the user has explicitly requested (such as shopping-cart cookies or session authentication tokens) and cookies used for non-essential purposes like behavioural advertising or cross-site tracking. For strictly necessary cookies, notice and an accessible opt-out are sufficient. For personalised advertising and profiling, explicit consent must be obtained before the cookie is set.
Finally, the EU General Data Protection Regulation (GDPR) may apply in parallel when a Swiss website targets individuals in the European Economic Area, for instance, by offering goods in euros, providing content in EU languages directed at EU audiences, or shipping to EU addresses. Where the GDPR applies, its stricter consent regime (notably Article 7 and Recital 32) governs cookie placement for those visitors, regardless of where the server is located.
The FDPIC’s October 2025 cookie guidelines can be distilled into four core positions:
Under Article 3(2) of the GDPR, the regulation applies to the processing of personal data of individuals who are in the EU when the processing relates to offering them goods or services, or monitoring their behaviour within the EU. A Swiss e-commerce store that lists prices in euros and ships to Germany, or a Swiss SaaS provider with a French-language landing page directed at French users, falls within the GDPR’s reach for those visitors. In practice, this means applying the GDPR’s prior-consent standard for all non-essential nFADP cookies served to EU-based visitors, a higher bar than the notice-plus-opt-out model the FDPIC permits for strictly functional cookies under Swiss law alone.
Businesses in this position should also review broader cross-border data transfer guidance for related compliance considerations.
The question of whether cookie consent is required in Switzerland ultimately turns on the cookie’s purpose and the data it processes. The decision flow below applies the nFADP and the FDPIC cookie guidelines to the most common cookie categories.
| Cookie Use | Consent Required? | Examples & Recommended Banner Action |
|---|---|---|
| Functional / strictly necessary | No, notice + opt-out sufficient | Session IDs, CSRF tokens, shopping cart, load-balancer cookies. Show a brief notice explaining these cookies; provide a link to cookie settings. |
| Preference / UX cookies | No, notice + opt-out sufficient | Language selection, dark-mode toggle, font-size preference. Include in the cookie notice; allow the user to disable via cookie settings. |
| First-party analytics (anonymised, no cross-site tracking) | Generally no, document anonymisation; offer opt-out | Matomo with IP masking; Google Analytics with IP anonymisation and no data sharing. Disclose in cookie policy; provide opt-out toggle; keep configuration records. |
| Analytics with cross-site or persistent identifiers | Yes, explicit opt-in | Google Analytics without IP masking, Adobe Analytics with cross-domain tracking. Do not set cookie until consent is given; log consent. |
| Personalised advertising / RTB | Yes, explicit opt-in + documented consent | Google Ads remarketing, Meta Pixel, programmatic ad-exchange cookies. Block all ad scripts by default; fire only after granular consent; retain consent log. |
| Social-media third-party trackers | Yes, explicit opt-in | Facebook Like button, X (Twitter) embed, LinkedIn Insight Tag. Replace with static placeholders until consent is received. |
| High-risk profiling (automated individual decisions) | Yes, express consent (nFADP) + DPIA | Credit-scoring cookies, dynamic pricing based on behavioural profiles. Require unambiguous opt-in; conduct and document DPIA; review annually. |
Do you need consent for functional cookies? Under Swiss law, the answer is no, provided you inform the user, explain the purpose, and give them a meaningful opt-out. The FDPIC cookie guidelines draw a clear line between these low-risk cookies and the non-essential categories that trigger the consent requirement.
Swiss cookie banner rules require more than a vague “this site uses cookies” notice. A compliant banner must clearly identify cookie categories, provide granular accept/reject controls, and link to a full cookie policy. Where the website also serves EU visitors, the banner must meet the higher GDPR standard of prior opt-in consent for all non-essential cookies.
Variant 1, Swiss visitors (nFADP-focused):
“We use cookies to operate this website. Some cookies are strictly necessary and are set automatically. We also use analytics cookies to improve our service, these are only set if you agree. You can manage your preferences at any time via ‘Cookie Settings’. For more information, see our Cookie Policy.”
Buttons: [Accept All] [Cookie Settings] [Reject Non-Essential]
Variant 2, EU visitors (GDPR-compliant):
“We value your privacy. This website uses cookies. Strictly necessary cookies are required for the site to function. All other cookies, including analytics and advertising cookies, will only be set with your explicit consent. Please choose your preferences below. You may withdraw consent at any time via ‘Cookie Settings’. Read our Cookie Policy.”
Buttons: [Accept All] [Reject All] [Manage Preferences]
Both variants must link to a standalone cookie policy page that lists every cookie by name, category, purpose, provider, and expiry period. The “Manage Preferences” or “Cookie Settings” layer should offer toggles for each category, functional, analytics, advertising, social media, and must not use pre-ticked boxes for non-essential categories.
Is it illegal to force users to accept cookies? Under the nFADP’s voluntariness principle, consent that is a precondition for accessing a service is unlikely to be valid unless the cookies are strictly necessary for that service. The FDPIC has signalled concern about “cookie walls”, banners that offer only an “Accept” button and no alternative. Industry observers expect the FDPIC to intensify scrutiny of such designs in future enforcement actions.
Practical rules to follow:
Obtaining consent is only half the obligation. The nFADP’s accountability principle requires data controllers to demonstrate that consent was properly collected, and the FDPIC cookie guidelines reinforce this with specific expectations around record-keeping. If cookie consent is required in Switzerland for a given processing purpose, the business must be able to prove that consent was obtained.
Each consent event should capture the following fields:
The nFADP does not prescribe a fixed retention period for consent logs. The FDPIC expects controllers to retain records for as long as the processing they authorise continues, plus any period needed to demonstrate compliance in the event of an inquiry or complaint. Best practice is to retain consent logs for at least the duration of the cookie’s maximum lifespan plus one year, refreshing the consent record whenever the cookie policy or vendor list undergoes a material change. Businesses that operate under both Swiss and EU law should align their retention with the GDPR’s accountability requirements, which similarly demand demonstrable proof of valid consent.
Organisations already navigating Swiss regulatory compliance, such as those pursuing an SRO licence in Switzerland, will recognise the pattern: regulators expect documented proof, not assertions.
Explicit consent for personalised advertising in Switzerland is the single area where the FDPIC’s October 2025 cookie guidelines are most definitive. Any cookie or pixel that enables behavioural targeting, including programmatic advertising, retargeting, lookalike-audience building, or cross-device identity resolution, falls squarely into the “consent required” category.
Analytics occupy a middle ground. First-party analytics tools configured with IP anonymisation, limited data retention, and no cross-site or cross-device linking generally do not require consent under Swiss law alone, although notice and an opt-out mechanism remain mandatory. The moment analytics data is shared with third parties, linked to advertising identifiers, or used to build individual user profiles, the processing moves into the consent-required zone.
Third-party tracker pixels, such as the Meta Pixel, Google Ads conversion tag, or LinkedIn Insight Tag, are treated as non-essential and consent-dependent under both the nFADP and GDPR. They must not load until the visitor has opted in.
Under the nFADP, a Data Protection Impact Assessment is required when processing is likely to result in a high risk to the personality or fundamental rights of the data subject. For cookie-related processing, triggers include:
Businesses that embed third-party cookies are jointly responsible for ensuring the vendor’s processing complies with the nFADP. At a minimum, contracts with ad-tech and analytics vendors should include:
For many Swiss businesses, the question is not just whether cookie consent is required in Switzerland, but whether the stricter GDPR consent requirements also apply. The answer turns on the “targeting test” under GDPR Article 3(2).
Indicators that a Swiss website is targeting EU residents include:
Where these indicators are present, practical compliance steps include:
Businesses that have already navigated Swiss cross-border administrative requirements, such as determining whether an apostille is required for Switzerland, will appreciate the importance of jurisdiction-specific documentation in a multi-regime compliance programme. Companies already operating under Swiss corporate transparency obligations, including the Swiss beneficial ownership register requirements, will find similar principles of proactive disclosure and record-keeping at work.
The FDPIC has signalled increasing attention to cookie compliance since the October 2025 guidelines. While Swiss enforcement to date has been less aggressive than in jurisdictions such as France (CNIL) or Austria (DSB), early indications suggest the following areas will attract the most scrutiny:
| Cookie Category | Enforcement Risk Level | Key Risk Factor |
|---|---|---|
| Strictly necessary / functional | Low | Risk arises only if notice is missing entirely or opt-out is non-functional. |
| Anonymised first-party analytics | Low–Medium | Risk increases if anonymisation is not properly configured or data is shared with third parties. |
| Personalised advertising / profiling | High | Consent absent, coerced, or insufficiently documented. Dark-pattern banners. |
| Third-party trackers / social pixels | High | Scripts firing before consent; lack of vendor contracts; cross-border transfer gaps. |
| Cookie walls / forced acceptance | Medium–High | FDPIC views forced acceptance as undermining voluntariness of consent. |
The likely practical effect will be that businesses running personalised advertising without documented consent face the greatest reputational and regulatory exposure. The FDPIC’s investigative powers under the nFADP include the authority to order changes to processing operations and to publish findings, making public naming a meaningful deterrent even in the absence of large financial penalties.
Whether cookie consent is required in Switzerland depends on what the cookie does. The nFADP and FDPIC cookie guidelines together create a tiered system: notice for functional cookies, explicit consent for advertising and profiling. Businesses that also serve EU visitors must layer GDPR requirements on top. The following six-point checklist summarises the core obligations:
For tailored guidance on implementing these requirements, businesses should consult a qualified Swiss data privacy specialist through the Global Law Experts lawyer directory.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Alexandros Manousakis at Privintelligent Solutions, a member of the Global Law Experts network.
posted 39 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
No results available
Find the right Advisory Expert for your business
Sign up for the latest advisor briefings and news within Global Advisory Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Advisory Experts is dedicated to providing exceptional advisory services to clients around the world. With a vast network of highly skilled and experienced advisors, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message