The short answer: no opt-in, but no free pass either
Swiss law does not require a cookie banner with prior consent. Neither the Data Protection Act nor the Telecommunications Act demands an opt-in before non-essential cookies may be set. That is the big difference to the EU.
It does not follow that you can do nothing. The Federal Data Protection and Information Commissioner updated its cookie guidance in October 2025 and is explicit: anyone using non-essential cookies must give visitors a way to decline, prominently placed on the website and reachable within a few clicks, on the first visit and on every visit after. In practice that means a banner or a permanently visible cookie widget.

What each law actually requires
- Data Protection Act (revFADP, in force since 1 September 2023): your privacy policy must state at minimum the controller with contact details, the processing purposes and the recipients of the data. If data goes abroad, the recipient country belongs there too. On top of that come privacy-friendly defaults: until someone can object, tracking must be limited to what is necessary.
- Telecommunications Act (Art. 45c FMG, SR 784.10): visitors must be informed about processing on their device, including its purpose, and it must be clear how they can decline. This covers not only cookies but also localStorage, SDKs and fingerprinting.
- Important: pointing at browser settings is no longer enough under current interpretation. Declining has to be possible on your website itself.
You can read the full texts at the FDPIC and in the Telecommunications Act on Fedlex.
When EU rules apply on top
As soon as you visibly address people in the EU, European law comes into play. Recognised indicators are prices in euros, delivery to Germany or Austria, EU phone numbers or paid advertising aimed at an EU audience. The mere fact that your website is reachable from the EU is not enough on its own.
Where that applies, non-essential cookies require genuine consent. Strictly speaking that duty comes not from the GDPR itself but from the ePrivacy Directive and its national implementations, in Germany section 25 TDDDG. The GDPR supplies the standard for what valid consent has to look like.
The part many miss: Google asks for more than the law
Even without an EU angle you may be obliged to run a consent banner, contractually rather than legally. Google extended its EU user consent policy to users in Switzerland on 31 July 2024. Anyone running Google Ads, AdSense or Google Analytics with advertising features while addressing a Swiss audience needs valid consent for personalised advertising.
In practice this is the most common reason Swiss websites end up needing a banner after all. Not because of Swiss law, but because of the platforms they use.
What a clean setup looks like
- A complete, understandable privacy policy, linked in the footer of every page.
- A way to decline placed prominently on the website, not buried in the privacy policy, and callable again at any time.
- Declining as easy as accepting. Hidden decline buttons annoy visitors and cost more trust than they gain in data.
- Load marketing and advertising tags only after consent, where consent is required.
- Only use tracking you actually look at. Fewer tools mean less to explain and a faster website.
How we handle it in client projects
We deliberately keep tracking lean: visitor statistics plus, where it adds value, Microsoft Clarity for heatmaps and session recordings. Both can be configured in a privacy-friendly way.
As soon as ad campaigns enter the picture, we plan the consent setup from the start instead of bolting it on afterwards. This exact interface is where the data gaps appear that nobody can explain later. Why that gets expensive is covered in More ad budget does not fix a tracking problem.
One closing note: we are a marketing agency, not a law firm. This article describes common practice and the current state of the FDPIC guidance. For a binding assessment of your specific case, there is no way around proper legal advice.
Common questions
Do I need a cookie banner for Google Analytics?
If you use Analytics purely for audience measurement, without advertising features and with early anonymisation, transparent information plus a clearly visible way to decline can be enough. As soon as advertising or remarketing features are active, both the FDPIC (because of profiling) and Google's own consent policy require active consent.
Does the GDPR apply to my Swiss website?
Only if you visibly address people in the EU or monitor their behaviour. A purely Swiss audience does not trigger the GDPR, even if some EU visitors land on your site.
Is pointing to browser settings enough?
No. Under the current FDPIC guidance, declining must be possible on the website itself within a few clicks. Pushing the responsibility onto the browser no longer suffices.

