Regulation Statutory · EU
General Data Protection Regulation.
The EU General Data Protection Regulation (Regulation (EU) 2016/679) has applied since 25 May 2018 and governs the processing of personal data in the EU. Under the market-location principle in Article 3(2), it also covers Swiss companies that offer goods or services to people in the EU or monitor their behaviour - regardless of their own registered seat. Anyone covered generally has to appoint a representative in the EU under Article 27.
01 Triggers
When does GDPR apply to you?
GDPR may apply to you if one of these triggers applies. The Regulatory Check tests them against your details. Triggers marked “only together with industry or activity” only count if a trigger on industry or activity applies at the same time.
- Markets: EU (only together with industry or activity) (Recommend individual review): You state that you are active in the EU market - under Art. 3 GDPR, either an EU establishment is sufficient (Art. 3(1)) or, without an EU establishment, that you specifically offer goods or services to people in the EU or monitor their behaviour (Art. 3(2)). Whether there is deliberate targeting of the market or an occasional one-off sale without any GDPR relevance cannot be conclusively assessed from the market information alone and needs to be checked case by case.
- Activity: Customers’ personal data (applies if additionally: Markets: EU) (Recommend individual review): You process personal data of customers and are active in the EU market - if this includes people in the EU to whom you specifically offer goods or services, or whose behaviour you monitor, the GDPR applies in addition to the FADP (Art. 3(2)). Without any EU market relevance, only the FADP obligations remain.
- Activity: Special category personal data (applies if additionally: Markets: EU) (Recommend individual review): You process special categories of personal data, for instance health data, and are active in the EU market - if this also concerns people in the EU, the GDPR's stricter requirements for precisely these data categories apply in addition to the FADP. Without any EU market relevance, only the FADP obligations remain.
Exceptions
- The obligation to appoint a representative under Art. 27 does not apply if the processing is only occasional, does not include special categories of data (Art. 9) or data relating to criminal convictions (Art. 10) to any significant extent, and, taking into account the nature, scope and purpose of the processing, is unlikely to result in a risk to the rights and freedoms of data subjects (Art. 27(2)(a) GDPR).
- The obligation to appoint a representative does not apply to public authorities and bodies (Art. 27(2)(b) GDPR).
- Purely B2B offerings with no connection to natural persons in the EU do not trigger Art. 3(2) GDPR, as long as no personal data of people in the EU is processed.
02 Obligations
What does GDPR require?
- Be able to demonstrate a legal basis for every processing of personal data (Art. 6 GDPR).
- Maintain a record of processing activities, unless an exemption applies (Art. 30 GDPR).
- Be able to fulfil data subject rights: access, rectification, erasure, objection, data portability (Art. 12-22 GDPR).
- Carry out a data protection impact assessment where processing is likely to result in a high risk (Art. 35 GDPR).
- Report personal data breaches to the supervisory authority within 72 hours, and notify data subjects where required (Art. 33-34 GDPR).
- Where Art. 3(2) applies: appoint in writing a representative in the EU, established in a member state where data subjects are located (Art. 27(1) and (3) GDPR).
03 Evidence
What evidence is needed?
- Record of processing activities (Art. 30).
- Documented legal bases and consents.
- Data processing agreements with providers (Art. 28).
- Evidence of the representative's appointment under Art. 27 (contact details, written appointment), where applicable.
- Data protection impact assessments, where carried out.
04 Deadlines
Which deadlines apply?
- The GDPR becomes applicable across the entire EU.
Information as of: 24 September 2026. Past dates are grey, upcoming ones highlighted (as of when the page was built).
05 Penalties
What are the consequences of violations?
Fines under Art. 83 GDPR: up to EUR 10 million or 2% of total worldwide annual turnover of the preceding financial year for breaches under Art. 83(4) (e.g. against obligations on data processing or representative appointment), and up to EUR 20 million or 4% of total worldwide annual turnover for more serious breaches under Art. 83(5) (e.g. against basic processing principles, data subject rights, international data transfers) - whichever amount is higher.
06 Related
What is connected with it?
- Federal Act on Data Protection (Data Protection Act, FADP): The revised Federal Act on Data Protection (FADP, SR 235.1) has, since 1 September 2023, governed the processing of personal data of natural persons by private companies and federal bodies in Switzerland.
07 Open
What is still uncertain?
- The EUR-Lex primary text (eur-lex.europa.eu/eli/reg/2016/679/oj, also in the form legal-content/DE/TXT/... and .../PDF/...) was not retrievable in this session (empty or blocked response); the article wording was instead verified via the mirror dejure.org, not via the EDPB or EUR-Lex itself.
- Whether and under what conditions individual Swiss bodies count as a 'public authority' within the meaning of Art. 27(2)(b) GDPR was not examined in depth.
08 Sources
Sources
Information as of: 24 September 2026.
- Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel), dejure.org, retrieved on 24 September 2026
- Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel), dejure.org, retrieved on 24 September 2026
- Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel), dejure.org, retrieved on 24 September 2026
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
FAQ Answers
Questions about GDPR.
Does a Swiss company without an EU establishment always need an EU representative?
No. The obligation under Art. 27 GDPR does not apply if the processing concerned is only occasional, does not concern special categories of data to any significant extent, and is unlikely to result in a risk to the rights and freedoms of data subjects, or if it concerns a public authority (Art. 27(2) GDPR).
Does the GDPR apply to a Swiss company that only occasionally sells goods to Germany?
What matters is not the individual export sale, but whether you specifically offer goods or services to people in the EU or monitor their behaviour (Art. 3(2) GDPR). An occasional sale without deliberate market targeting generally does not suffice for this.
How does the GDPR differ from the revised Swiss Federal Act on Data Protection (FADP)?
Both frameworks are structurally similar but differ in the level of fines, competent authorities and detailed requirements. Swiss companies with EU relevance under Art. 3(2) GDPR generally have to comply with both frameworks in parallel; see the separate norm file revdsg.
Does GDPR apply to you?
The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.
