Skip to content
Scheidegger Webpublishing Webpublishing, Bern

Web regulation / European Union

When European law reaches a Swiss website

Many Swiss businesses believe European law has no bearing on them because their server sits in Switzerland. The test has never been the server. It is the audience addressed.

File verified on 27 July 2026.

Does the GDPR apply to a Swiss website?

Its art. 3(2) says so plainly. The regulation applies to the processing of the data of people located in the Union by a controller established outside the Union, in two cases: where it offers them goods or services, and where it monitors their behaviour.

What triggers application is therefore neither the registered office, nor the server, nor the domain. It is targeting a European audience. A German version aimed at Germany, prices in euros, delivery advertised into the Union: all are indications the case law accepts. A French-language Swiss site, with no soliciting across the border, that a European happens to consult, does not fall in for that reason alone.

The second limb is the broader and the less noticed. Monitoring the behaviour of a European visitor is enough, quite apart from any sale. An audience measurement tool tracking a German visitor’s path brings a Swiss website within the regulation.

Cookies, on the European side

The regime inverts compared with Switzerland. The ePrivacy directive requires prior, informed and freely given consent before any information is stored on or read from the user’s device, except where strictly necessary to deliver the service requested.

Three consequences follow, and they are what gets sites penalised. Refusing must be as easy as accepting, so at the same level and in one gesture. Continuing to browse is not acceptance. And nothing is stored before the choice is made, which rules out banners that load their trackers while you read them.

A site with no non-essential cookies has nothing to ask and nothing to display. It is the only known way of making this question permanently harmless, and it is the one we apply.

Is an EU representative required?

Art. 27 of the regulation imposes one on any controller established outside the Union that falls under art. 3(2). The representative is a person or entity established in a member state where the data subjects are located, designated in writing, and addressable by authorities and individuals alike.

An exception exists, and it covers most small structures. It applies to occasional processing that does not involve special categories of data or criminal conviction data on a large scale, and is unlikely to result in a risk to people’s rights. It still has to be examined rather than assumed.

Accessibility, mandatory since 28 June 2025

The directive on accessibility requirements for products and services became applicable on 28 June 2025. It covers among other things e-commerce, consumer banking, e-books and passenger transport services, and it addresses any operator offering those services to consumers in the Union, wherever it is established.

The timetable distinguishes two situations. Services placed on the market after that date are compliant from launch. Those existing beforehand benefit from a transitional period running until 28 June 2030.

The directive exempts microenterprises providing services, meaning fewer than ten people and an annual turnover or balance sheet not exceeding two million euros. The exemption covers services, not products, and member states have transposed it with variations that have to be checked country by country.

Where may the data be hosted?

Between Switzerland and the Union, data moves freely in both directions, and it is an advantage people forget to count. The European Commission recognises Switzerland as providing an adequate level of protection, a decision reviewed and maintained in January 2024. Symmetrically, the Federal Council lists the member states on its own register of states with adequate protection.

Swiss, German or Irish hosting therefore raises no transfer question at all. What does raise one are services established outside that space, and in particular the measurement, web font or video tools that ship an IP address on every page view without anyone having decided it.

Continue

The three parts

What Swiss law asks of a website

Switzerland is more permissive than the European Union on cookies, and stricter than people assume on personal liability. The four points below cover almost every case of a presentation site or an editorial site.

Read this part

The rest of the world, and the principle behind all of it

Around a hundred states now have personal data legislation. Listing them would serve no purpose. Understanding what they share does, because it lets you decide without seeking advice every time.

Read this part