Skip to content

Law

FADP for websites: what SMEs really have to implement

The revised Data Protection Act has applied since September 2023. What is mandatory for your website, what merely looks good – and the checklist for the next meeting.

Online3 minUpdated
FADP for websites: what SMEs really have to implement

The revised Data Protection Act has applied since 1 September 2023. In consultations we have heard the same question almost weekly since: "Do we need one of those cookie banners now too?" The answer is shorter than many expect – and the real work lies elsewhere.

What the FADP demands of a website

The revised Federal Act on Data Protection makes three demands: transparency, purpose limitation and security. Translated to a website, that means: you say comprehensibly which personal data you collect, what you use it for and to whom it is passed on. Unlike the European GDPR, the FADP does not require prior consent for ordinary audience measurement, but clear information. Anyone who addresses customers in the EU, however, additionally falls under the GDPR – and then the stricter regime applies.

A banner is not generally prescribed in Switzerland. You need genuine consent where data flows to third parties for advertising purposes – with remarketing pixels, conversion tracking by advertising networks or embedded services that build profiles. For technical cookies such as basket, login or language choice no consent is needed. Important: if you use a banner, "Decline" must be as easy to reach as "Accept", and the scripts may only load after consent. A banner that blocks nothing is decoration and creates liability rather than protection.

Analytics, fonts and maps

Three classics from our audit practice:

  • Analytics belongs in the privacy policy, including a note on transfer to the USA.
  • Google Fonts from Google's server transmit the IP address of every visitor. Embedding the fonts locally takes half an hour and speeds up the page as well.
  • An embedded map immediately sends data to Google. Better is a preview with a click to load. The same applies to embedded videos.

Contact forms and newsletters

For the form: collect only what you really need. Every additional mandatory field lowers the completion rate and increases the duty to justify. A note under the send button stating where the data goes and how long it stays is enough. For the newsletter we recommend double opt-in: confirmation e-mail, logged timestamp, unsubscribe link in every mailing. That is not only clean under data protection law; it also protects against complaints under the Unfair Competition Act.

Who is responsible

The company is always responsible – not the agency and not the host. Anyone who processes data on your behalf, i.e. hosting, newsletter tool, shop system or accounting, belongs on a list with purpose, data type and server location. From 250 employees a record of processing activities is mandatory; we advise everyone else to keep one too, because the overview saves time with every enquiry.

Checklist for the next website meeting

  • Privacy policy current, comprehensible and reachable from every page
  • List of all embedded services including server location
  • Fonts local, maps and videos only on click
  • Banner only if it really blocks – with an equivalent "Decline"
  • Form fields reduced to what is necessary, deletion periods defined
  • Data processing agreements with host and tools

Conclusion

The FADP is not a threat but a call to order. Anyone who knows which services run on their own site has done the largest part. We go through this list with clients from Solothurn and Bern in one meeting and record what stays and what goes.

Data protectionndsgcookie bannerprivacy policylawSMEwebsiteGDPR

More articles

News

Let's talk about your project.