Skip to content
Schweizersoftware

6 min read

A privacy policy for a small Swiss website: what goes in

What the duty to inform under Art. 19 of the Swiss FADP covers, which details typical small-business websites involve, and how the FDPIC describes the structure.

Cover on a dark background: “A privacy policy for a small website”. Below it three staggered cards — summary, full version and details — and beside them the languages DE, FR, IT and EN.

A joinery in Thun has a small website: five pages, photos of kitchens and staircases, a contact form, an embedded map to the workshop and a visitor statistics tool the web designer switched on during setup. In the footer there is a link, “Privacy”. Behind it is a long text the owner has never read in full. It came from a generator and mentions an online shop that does not exist.

A privacy policy often feels like a compulsory text you paste in once and forget. The law sees it differently: as information for the people using the website. To do that job, it has to fit your own website.

What the policy is for

The Swiss Federal Act on Data Protection (FADP, in German DSG) requires the controller to inform the person concerned appropriately about the collection of personal data (Art. 19 para. 1 FADP). The information should enable them to exercise their rights under the act and ensure transparent processing (Art. 19 para. 2 FADP).

On its page about privacy policies on the internet, the Federal Data Protection and Information Commissioner (FDPIC) describes the privacy policy as the way a website meets this duty to inform. Users should be informed well enough to decide freely whether and how they allow their data to be processed.

The law prescribes no heading and no format for this. It describes a purpose. A text nobody understands does not serve it, however complete it is.

Before writing: take stock

The FDPIC recommends clarifying what actually happens on the website before writing anything. Its questions take about half an hour:

  • Which data is collected, and where does it come from?
  • For what purposes is it used?
  • Who has access, and how long is it kept?
  • Is data disclosed to third parties or abroad?
  • Which third-party tools are embedded — statistics, maps, social media buttons, fonts, videos?

The last question is where most of the surprises lie. An embedded map, a video or an externally loaded font can mean the browser sends data to another provider during a visit. The joinery’s owner may not know her website does this. The policy can only describe it once someone has checked.

What goes in

The FADP states what the person concerned learns at a minimum (Art. 19 para. 2 FADP):

  1. the identity and contact details of the controller;
  2. the purpose of processing;
  3. where applicable, the recipients or categories of recipients.

If personal data is disclosed abroad, the country is included too and, where applicable, the safeguards under Art. 16 para. 2 FADP or the exception under Art. 17 FADP (Art. 19 para. 4 FADP). On its page, the FDPIC adds further details a clear policy typically contains: which data is collected, how long it is kept, what choices users have, and whom they contact to exercise their rights.

Applied to the parts of a typical small-business website:

Part of the website What the policy describes
Hosting Which provider runs the website, and in which country
Contact form Which details are collected, for what, where they are stored, for how long
Visitor statistics Which service, which data, whether cookies or similar technologies are used
Embedded map Which provider receives data when it loads
Newsletter Which mailing service, on what basis, how to unsubscribe
People’s rights Whom to contact for access, correction or deletion

How it is structured

The FDPIC recommends a layered structure:

  • First level: brief, easily understood information giving an overview of the essentials.
  • Second level: the full policy, linked from the first level.
  • Third level: more in-depth information where needed.

Two further points on its page are especially relevant for Swiss websites. The policy should be easy to reach from every page. And if the website is offered in several languages, the policy should be available in those languages too. A website in German and French with a policy only in German does not reach part of its visitors.

For the joinery, this means: at the top of the policy, five sentences saying who runs the website, that the contact form sends name, email and message to the workshop, which statistics tool runs, which map is embedded and where to ask. The full version follows below.

When the duty to inform does not apply

The FADP has exceptions. The duty to inform does not apply, for example, if the person concerned already has the information or the processing is provided for by law (Art. 20 para. 1 FADP). For an ordinary small-business website these exceptions rarely matter, because visitors usually see the website for the first time and do not know what happens in the background.

What the policy does not replace

A privacy policy informs. It is not consent, even if forms sometimes suggest so with a “read and accepted” tick box. Where the law requires consent, it is only valid if given voluntarily for one or more specific processing operations after adequate information (Art. 6 para. 6 FADP). A general reference to a long text does not necessarily meet that.

Conversely, not every piece of information needs confirming. The information has to be there and easy to reach; whether someone reads it is up to them. That is why a privacy policy works best where the data comes into being: as a short note right at the form, with a link to the full version.

The policy has to fit the website

What most undermines a privacy policy is not a missing paragraph but a gap between text and reality. A generator text describing a shop that does not exist informs wrongly. So does a policy that leaves out a statistics tool that is embedded.

A few occasions to read the policy again:

  • a new tool on the website, such as a booking or chat window;
  • a change of hosting or newsletter provider;
  • a new form that collects different details from the old one;
  • an additional language version of the website.

We built our own privacy policy along these lines. It explains that this website is delivered through Cloudflare, a provider based in the USA, that sign-ups and messages are stored in a data centre in Zurich, and what the website explicitly does not do. It is not short, but every section corresponds to something that actually happens.

Which details a particular website needs depends on how it is built and which services it embeds. The FDPIC’s page on privacy policies on the internet is a good basis for going through your own; for legal questions in a specific case, a professional can help.

Sources

  1. 1.Bundesgesetz über den Datenschutz (DSG, SR 235.1) (checked on 24 September 2026)
  2. 2.EDÖB: Datenschutzerklärungen im Internet (checked on 24 September 2026)
  3. 3.EDÖB: FAQ Datenschutz (checked on 24 September 2026)
  4. 4.EDÖB: Leitfaden betreffend Datenbearbeitungen mittels Cookies und ähnlichen Technologien (V. 1.1 vom 6. Oktober 2025) (checked on 24 September 2026)

Follow our ideas

Look at our ideas and ask to be told once when one of them becomes an app. Or write to us – about an idea, about a task that deserves an app, or just to say hello.

Choose a language

This page opens in the language you choose.