Many Swiss companies fall under both rule sets at the same time. The revised Swiss data protection act has applied since 1 September 2023 to processing with a Swiss connection. The GDPR applies on top as soon as you address people in the EU. What decides this is not where your company sits but who you are speaking to.
When each law applies
The revDSG attaches to a Swiss connection. The GDPR follows the marketplace principle: it applies when you deliberately offer goods or services to people in the EU or monitor their behaviour. Indicators include pricing in euros, shipping into the EU, or running your website in a language and tone clearly aimed at an EU audience. A website merely being reachable from abroad is not enough on its own.
Where the two diverge in practice
- Who gets sanctioned. The GDPR provides for fines against companies, measured partly against worldwide annual turnover. The revDSG instead aims its penalty provisions primarily at responsible private individuals, with fines up to 250,000 francs. That shifts the question of responsibility inside the business noticeably.
- Record of processing activities. Both know the concept. In Switzerland, companies with fewer than 250 employees are exempt as long as the processing carries low risk. That exemption relieves many smaller firms.
- Reporting breaches. The GDPR names a 72-hour deadline. The revDSG requires a report to the Swiss commissioner as quickly as possible, with no fixed hour count, but with its own threshold for when a report is needed at all.
- Consent. The GDPR requires active consent for many kinds of processing. The revDSG leans more on transparency and recognisable purposes, and requires explicit consent above all for particularly sensitive data.
What this means day to day
Companies serving both markets usually end up following the stricter standard. Keeping two parallel processes for consent, deletion and information requests cleanly apart costs more in operation than it saves. Companies serving only Swiss customers can make life simpler in places, but should record that assessment in writing rather than assuming it quietly.
Where a closer look pays off
It gets delicate where data leaves the country, where particularly sensitive data is involved, and where the tools in use come from providers subject to US law. Those three points justify a legal review, while everyday website practice usually manages with a clean baseline. What that baseline looks like for a company website is in the revDSG checklist for websites.
This text is an orientation and not legal advice. Which rules apply to your specific situation belongs, in case of doubt, with a specialised lawyer.
Want to put this to work for your business? We review your website for free in classic and AI search and show the biggest levers.