The GDPR in Switzerland
When it applies to your company, and what to do then
Swiss companies can fall under the EU GDPR too, especially in recruiting. Here is when it applies to you, what duties follow from it, and how it relates to the revised Swiss Data Protection Act.
Data privacy | Vanessa Hunkeler-Bolliger
The GDPR in Switzerland

First, the distinction. In Switzerland the revised Federal Act on Data Protection (FADP) has applied since 1 September 2023. The GDPR comes into play on top of that, when your company processes data of people in the EU and your offering is aimed at that market. The two frameworks do not exclude each other; they can apply side by side. What that means in recruiting is covered in a separate article. In the other direction the situation is relaxed: in its report of 15 January 2024 the European Commission confirmed that Swiss data protection law continues to meet the European standard. Data may therefore be transferred from the EU to Switzerland without additional safeguards.

The GDPR explained in brief

The General Data Protection Regulation (GDPR) is the central framework governing the handling of personal data in the EU. It sets the rules for how data must be processed, stored, and deleted, with the aim of protecting the privacy of natural persons. Especially in recruiting, where sensitive information is processed daily, this is a crucial issue.

Key principles of the GDPR:

  • Right to access, rectification, and erasure
  • Privacy by Design: Data protection is integrated into the system architecture from the outset.
  • Privacy by Default: Data protection is enabled by default, without users having to take action.
  • Purpose limitation and storage limitation: Application data may only be stored as long as it is truly needed.

Personal Data

But what exactly are personal data? And how long can they be stored? Personal data refers to any information that relates to an identified or identifiable natural person. In other words, any data that can be (even indirectly) assigned to a person, such as their name, phone number, or bank details. A distinction is made between general and special categories of personal data: Special personal data such as genetic, biometric, or ethnic information enjoy a higher level of protection. Personal data may only be stored as long as they serve a specific purpose. This is prescribed by the principle of storage limitation. This also applies, for example, to job applications: when storing an application from a natural person from the EU, personal data are being processed.

The GDPR in Switzerland: Who is affected?

In principle, the Swiss Federal Act on Data Protection (FADP) applies in Switzerland. However, Swiss companies must also engage with the GDPR, especially if they maintain business relationships with the EU based on the marketplace principle. Internal processes, contracts, policies, and privacy notices should therefore be thoroughly reviewed. The consequence: As soon as Swiss companies receive and process personal data from natural persons in the EU, they must comply with the EU GDPR. This is particularly relevant in the context of goods and/or services, or when tracking the behavior of individuals. Does the company have a branch in the EU? Is there a client in the EU involved? Or does a Swiss company process personal data on behalf of an EU-based business? In these cases too, the GDPR rules apply to your company.

Is the company in Switzerland affected by the GDPR because there is a clear intent to engage in trade? Then the following obligations apply:

  • Informing the data subject and obtaining their consent to data processing
  • Guaranteeing “Privacy by Design” and “Privacy by Default”
  • Appointing a data protection representative in the EU
  • Reporting data breaches to the supervisory authority
  • Conducting a Data Protection Impact Assessment (DPIA)

Data protection officers in Switzerland for the GDPR

Whether internal or external: A competent person who manages data protection is worth their weight in gold, especially in recruiting. They can define, review, and coordinate the necessary processes. If your company is subject to the GDPR, you will also need an official representative based in an EU member state as a point of contact for supervisory authorities and data subjects.

GDPR violations: severe penalties possible

The GDPR provides for substantial sanctions. In the case of serious breaches, fines of up to 4% of global annual turnover or up to 20 million euros can be imposed, whichever amount is higher.

And this is no mere theory. What has actually been decided in a recruiting context, however, has been less about large fines from supervisory authorities and more about damages claimed by individual candidates.

Two examples from Germany. In the first, a bank sent a message about a candidate’s ongoing application through a career network and, because of a processing error, also transmitted it to an unrelated person from the same industry. The Federal Court of Justice held that the candidate was entitled to non-material damages in principle.[1]

In the second, a university googled a candidate before the interview, found information about criminal proceedings and let it influence the decision without telling him. The Federal Labour Court awarded him 1,000 euros. The research on candidates itself was lawful; what was breached was the duty to inform him about the data obtained that way.[2]

Both are German rulings on the GDPR and are not directly applicable law for Swiss companies. They are still a useful signal: in both cases it was not the privacy notice that failed, but a piece of information that was never given.

This article explains the main duties and does not replace legal advice. How the rules apply in your company depends on the individual case.

Conclusion: the GDPR also affects Swiss companies

Whether the GDPR applies to your company is not decided by where you are registered, but by whose data you process and where your offering is aimed. That is not a question to settle in passing.

What to take away: have a data protection expert check whether your company falls within the scope. If it does, look first at the processes where candidate data is created and left lying around. That is where the mistakes happen, not in the privacy notice.

Our e-recruiting solution covers every process from application to deletion in line with the GDPR, including consent management, transparent communication and automated deletion periods.

Try it now and see how simple data-secure recruiting can be!

[1] Damages after a candidate’s application was mistakenly transmitted to a third party: judgment of the German Federal Court of Justice of 23 June 2026, VI ZR 97/22.

[2] Internet research on candidates is permitted, but informing them about it is mandatory: judgment of the German Federal Labour Court of 5 June 2025, 8 AZR 117/24.