The key points at a glance
- Encryption is mandatory: The Swiss FADP requires appropriate data security. Without HTTPS, form data travels across the network in plain text.
- Transparency: Anyone who processes personal data must inform people about it. A linked privacy policy belongs on every page.
- Third parties count: Fonts, videos, maps and analytics tools loaded from external servers transmit your visitors’ IP address.
Our free privacy check tests all these points on your homepage. It’s a quick technical check and doesn’t replace legal advice.
SSL and HTTPS
The padlock in the address bar shows that the connection is encrypted. Three things need to be right:
- A valid certificate: If it expires, browsers show a full-page warning, and most visitors leave. Certificates from Let’s Encrypt are free and renew automatically once the host has set this up correctly.
- A redirect from http:// to https://: Anyone typing the address without https should still land on the encrypted version.
- HSTS: This header tells browsers to only ever load your site over an encrypted connection from now on.
The contact form
Names, email addresses and often confidential enquiries come in through the form. Check:
- Sent encrypted: The form must submit to an https:// address, even if the page itself is encrypted.
- Where does the data go? Third-party form services often store submissions abroad. That’s allowed, but it must be stated in the privacy policy.
- A notice on submission: A line such as “We only use your details to process your enquiry”, with a link to the privacy policy.
- Only ask for what you need: Date of birth or phone number as a required field for a simple enquiry? Leave it out.
- Sensible spam protection: Google reCAPTCHA sends data to Google. Mention it in the privacy policy, or use an alternative without a third party.
Privacy policy and legal notice
The duty to inform under Art. 19 FADP applies to every website that processes personal data, which in practice means almost all of them. The privacy policy states what data you collect, for what purpose, and which countries it goes to.
Swiss law requires a legal notice for online shops: anyone offering goods or services through electronic commerce must inform people clearly and fully about their identity and contact address, including an email address (Art. 3 para. 1 lit. s of the Unfair Competition Act, UWG). For everyone else, it’s strongly recommended anyway, if only to build trust.
Third parties and cookies
| Service | What happens when it loads | Solution |
|---|---|---|
| Google Fonts | The IP address goes to Google in the USA | local |
| Google Analytics, pixel | Tracking starts before any decision is made | consent |
| YouTube, Vimeo | The video loads along with the provider’s cookies | 2-click |
| Google Maps | The map transmits data to Google | 2-click |
| External CDNs | External servers see every visit | local |
Google Fonts is the classic case: in 2022, the Munich Regional Court ruled that loading fonts from Google’s server without consent breaches the GDPR, and awarded a visitor 100 euros in damages. The fix is simple and even makes the site faster: host the fonts on your own server.
Cookies: Technically necessary cookies, for example for the session or spam protection, are unproblematic. Analytics and advertising cookies must be disclosed, and depending on your audience, you may need to ask permission first (see below).
Security headers
Security headers are short instructions from the server to the browser, for example: “Only load scripts from my own domain” (Content-Security-Policy) or “Don’t embed me in other people’s pages” (protection against clickjacking). They cost nothing, make attacks noticeably harder, and are set up in a few minutes. If your server also reveals its exact software version, that should be switched off.
FADP or GDPR?
In Switzerland, cookies and analytics tools are generally governed by the opt-out principle: you inform people clearly and offer a way to decline (Art. 45c of the Telecommunications Act (FMG), Art. 19 FADP). Under Swiss law, an opt-in banner is usually not mandatory.
It’s different as soon as you address customers in the EU, for instance with a shop that delivers to Germany: then the GDPR applies, and tracking may only load after consent. Many Swiss companies therefore adopt the stricter standard from the outset. Read more on the basics in the article Website and data protection: what the revised FADP (revDSG) requires of you.
Check your website now
The free privacy check shows in seconds where your website has gaps. We’re happy to help you close them: book a free initial consultation.










