# General Data Protection Regulation

> The EU General Data Protection Regulation (Regulation (EU) 2016/679) has applied since 25 May 2018 and governs the processing of personal data in the EU. Under the market-location principle in Article 3(2), it also covers Swiss companies that offer goods or services to people in the EU or monitor their behaviour - regardless of their own registered seat. Anyone covered generally has to appoint a representative in the EU under Article 27.

- Type: Regulation, Statutory
- Scope: EU
- As of: 24 September 2026
- Page: https://sacosi.ch/en/norms/dsgvo
- Regulatory Check: https://sacosi.ch/en/regulation#normencheck

## When does GDPR apply to you?

- Markets: EU (only together with industry or activity) (Recommend individual review): You state that you are active in the EU market - under Art. 3 GDPR, either an EU establishment is sufficient (Art. 3(1)) or, without an EU establishment, that you specifically offer goods or services to people in the EU or monitor their behaviour (Art. 3(2)). Whether there is deliberate targeting of the market or an occasional one-off sale without any GDPR relevance cannot be conclusively assessed from the market information alone and needs to be checked case by case.
- Activity: Customers’ personal data (applies if additionally: Markets: EU) (Recommend individual review): You process personal data of customers and are active in the EU market - if this includes people in the EU to whom you specifically offer goods or services, or whose behaviour you monitor, the GDPR applies in addition to the FADP (Art. 3(2)). Without any EU market relevance, only the FADP obligations remain.
- Activity: Special category personal data (applies if additionally: Markets: EU) (Recommend individual review): You process special categories of personal data, for instance health data, and are active in the EU market - if this also concerns people in the EU, the GDPR's stricter requirements for precisely these data categories apply in addition to the FADP. Without any EU market relevance, only the FADP obligations remain.

## Exceptions

- The obligation to appoint a representative under Art. 27 does not apply if the processing is only occasional, does not include special categories of data (Art. 9) or data relating to criminal convictions (Art. 10) to any significant extent, and, taking into account the nature, scope and purpose of the processing, is unlikely to result in a risk to the rights and freedoms of data subjects (Art. 27(2)(a) GDPR).
- The obligation to appoint a representative does not apply to public authorities and bodies (Art. 27(2)(b) GDPR).
- Purely B2B offerings with no connection to natural persons in the EU do not trigger Art. 3(2) GDPR, as long as no personal data of people in the EU is processed.

## Obligations

- Be able to demonstrate a legal basis for every processing of personal data (Art. 6 GDPR).
- Maintain a record of processing activities, unless an exemption applies (Art. 30 GDPR).
- Be able to fulfil data subject rights: access, rectification, erasure, objection, data portability (Art. 12-22 GDPR).
- Carry out a data protection impact assessment where processing is likely to result in a high risk (Art. 35 GDPR).
- Report personal data breaches to the supervisory authority within 72 hours, and notify data subjects where required (Art. 33-34 GDPR).
- Where Art. 3(2) applies: appoint in writing a representative in the EU, established in a member state where data subjects are located (Art. 27(1) and (3) GDPR).

## Evidence

- Record of processing activities (Art. 30).
- Documented legal bases and consents.
- Data processing agreements with providers (Art. 28).
- Evidence of the representative's appointment under Art. 27 (contact details, written appointment), where applicable.
- Data protection impact assessments, where carried out.

## Deadlines

- 25 May 2018: The GDPR becomes applicable across the entire EU.

## Penalties

Fines under Art. 83 GDPR: up to EUR 10 million or 2% of total worldwide annual turnover of the preceding financial year for breaches under Art. 83(4) (e.g. against obligations on data processing or representative appointment), and up to EUR 20 million or 4% of total worldwide annual turnover for more serious breaches under Art. 83(5) (e.g. against basic processing principles, data subject rights, international data transfers) - whichever amount is higher.

## Frequently asked questions

**Does a Swiss company without an EU establishment always need an EU representative?**
No. The obligation under Art. 27 GDPR does not apply if the processing concerned is only occasional, does not concern special categories of data to any significant extent, and is unlikely to result in a risk to the rights and freedoms of data subjects, or if it concerns a public authority (Art. 27(2) GDPR).

**Does the GDPR apply to a Swiss company that only occasionally sells goods to Germany?**
What matters is not the individual export sale, but whether you specifically offer goods or services to people in the EU or monitor their behaviour (Art. 3(2) GDPR). An occasional sale without deliberate market targeting generally does not suffice for this.

**How does the GDPR differ from the revised Swiss Federal Act on Data Protection (FADP)?**
Both frameworks are structurally similar but differ in the level of fines, competent authorities and detailed requirements. Swiss companies with EU relevance under Art. 3(2) GDPR generally have to comply with both frameworks in parallel; see the separate norm file revdsg.

## Open points of the research

- The EUR-Lex primary text (eur-lex.europa.eu/eli/reg/2016/679/oj, also in the form legal-content/DE/TXT/... and .../PDF/...) was not retrievable in this session (empty or blocked response); the article wording was instead verified via the mirror dejure.org, not via the EDPB or EUR-Lex itself.
- Whether and under what conditions individual Swiss bodies count as a 'public authority' within the meaning of Art. 27(2)(b) GDPR was not examined in depth.

## Sources

- [Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel)](https://dejure.org/gesetze/DSGVO/27.html), dejure.org, retrieved 24 September 2026
- [Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel)](https://dejure.org/gesetze/DSGVO/3.html), dejure.org, retrieved 24 September 2026
- [Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel)](https://dejure.org/gesetze/DSGVO/83.html), dejure.org, retrieved 24 September 2026

---
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
Source: SACOSI, Situational Awareness Consulting by Ivo Schönberner (https://sacosi.ch).
