Is Google Analytics Legal in Switzerland? The FADP, FDPIC Guidance, and the Non-EU Twist

Is Google Analytics legal in Switzerland? Yes. And not because a Swiss court or regulator blessed it, but because nobody in Switzerland has ever ruled on it at all. Switzerland isn't in the EU, the GDPR doesn't govern Swiss-only websites, and Swiss cookie law is opt-out, which means you inform visitors about tracking instead of asking their permission first. That's the short answer, and if you stop reading here, you'll be roughly right. The full picture involves a CHF 600 criminal fine against a company lawyer, a privacy regulator that can't fine anyone, and a US data deal that quietly switched on in September 2024. I'll walk you through all of it.
- Switzerland is not in the EU and the GDPR does not apply to Swiss-only websites. The revised FADP, in force since September 1, 2023, governs instead, and Swiss cookie law (Article 45c of the Telecommunications Act) is opt-out: inform visitors and let them object, no banner required.
- No Swiss authority has ever ruled on Google Analytics. Switzerland was excluded from noyb's 101 complaints by design (EU and EEA states only), so it never had its own Austria or France moment.
- FADP fines are criminal, capped at CHF 250,000, issued by cantonal prosecutors, and they target the responsible individual, not the company. The first published fine, March 2025, was CHF 600 against an in-house counsel at TX Group.
- The Swiss-US Data Privacy Framework has been in force since September 15, 2024. Swiss data can flow to certified US companies, including Google, without extra safeguards, for now.
- The FDPIC's 2025 cookie guidance allows consent-free analytics only if the tool processes data solely on your behalf, a test standard GA4 setups arguably fail. Ad blockers hide another 30.9% of Swiss visitors regardless.
Switzerland doesn't follow the GDPR. Here's what does apply
Two laws matter for a Swiss-only website, and neither of them is the GDPR. Personal data falls under the revised Federal Act on Data Protection, the FADP, in force since September 1, 2023. Cookies fall under a separate rule in the Telecommunications Act. Both ask you to be honest with visitors, not to collect consent up front.
Switzerland isn't an EU member. Swiss voters even rejected the halfway option of joining the European Economic Area back in 1992. Which means the GDPR and the ePrivacy Directive, the two EU laws behind every cookie banner you've ever clicked away, don't apply to you if you run a Swiss site for Swiss visitors.
One caveat before you celebrate. The GDPR reaches across borders: if you sell to people in the EU, or you watch their behaviour, EU rules apply to that slice of your traffic. A Zurich shop shipping to Munich answers to EU consent rules for its German visitors. Purely domestic? Then Swiss law only. And if that's not you, my cookie banner guide walks through the EU side of the question.
Now for the part I see compliance articles get wrong most often. Swiss cookie law lives in Article 45c letter b of the Telecommunications Act, and it has been in force since April 1, 2007. In practice it asks you for exactly two things. Tell visitors you're using tracking technology and why. Tell them how they can object.
That's the whole obligation. No prior consent. No banner blocking your content while people decide whether they'll tolerate you.
The FDPIC, Switzerland's federal privacy regulator (the full name is Federal Data Protection and Information Commissioner), spelled it out in a factsheet dated March 31, 2026: "While European law requires explicit prior consent for the use of cookies (with the exception of essential cookies), Swiss legislation emphasises transparent information for users and their right to object."
In plain English: the EU asks permission, Switzerland demands honesty. Two different philosophies of privacy, one border apart.
Ignore even that light-touch rule and the maximum penalty is CHF 5,000, set by Article 53 of the same act. That means CHF 5,000 in total, not per visitor. For scale, France's regulator fined one fast-fashion giant EUR 150 million over cookie violations. Put another way, the two systems aren't even playing the same sport.
The Swiss quirk nobody warns you about: fines hit people, not companies
FADP fines are criminal penalties, not administrative ones. They're capped at CHF 250,000, they're issued by cantonal prosecutors rather than the privacy regulator, and they primarily target the responsible individual: a manager, an IT lead, an in-house lawyer. As a rule, only intentional violations are punishable.
Sit with that for a second, because it inverts the GDPR model you know from the headlines. In the EU, the regulator fines the company, and the number is designed to hurt the balance sheet. In Switzerland, the FDPIC can't fine anyone. It investigates, it recommends, it orders. If someone won't cooperate, it files a criminal complaint, and the case lands with a cantonal prosecutor, the same office that handles speeding tickets. The eventual defendant isn't a company. It's a person.
That means whoever signs off on your data practices carries the risk personally. If that's you, keep reading.
Here's what that looks like when it happens. On March 4, 2025, the Zurich district criminal authority (the Statthalteramt Bezirk Zürich) issued what appears to be the first published fine under the revised FADP. Not against a company. Against an in-house counsel at TX Group, the media company behind Tamedia. The violation: someone filed an access request, the Swiss right to ask what data a company holds about you, and the first response said only two datasets existed. That answer was incomplete. The reasons for withholding the rest arrived too late to fix it.
The fine, under Article 60(1)(a) FADP: CHF 600. Put another way, Switzerland's landmark privacy fine costs about as much as a nice dinner for four in Zurich. Add a few hundred francs in procedural costs, per the practitioner newsletters that analyzed the case after lawyer Martin Steiger first surfaced it. And because the total stayed under CHF 5,000, it doesn't even enter the criminal record. In practice, the lawyer got the Swiss equivalent of a parking ticket.
The court's reasoning is the part I'd remember, though. In the decision's words: "It was enough that there was a mere risk that the recipient might form a misleading impression of completeness, without requiring a specific intent to deceive." You don't need to lie to be fined. A risk of misleading is enough.
So don't read CHF 600 as proof that Swiss privacy law is toothless. Read it as a system that has started using its teeth, and it bites individuals. The ceiling is CHF 250,000, the liability is personal, and prosecutors have now shown they'll run these cases end to end. If you're the named privacy contact at your company, that should focus you a little.
What the FDPIC's cookie guidance says about analytics
The FDPIC published dedicated cookie guidelines dated January 22, 2025, and updated them to version 1.1 on October 6, 2025. For web analytics, they describe a conditional path you can use to measure without consent: the statistics carve-out in Article 31 paragraph 2 letter e FADP. In other words, the key word is conditional.
The guidelines are the closest thing Switzerland has to formal cookie-banner rules, and they're barely a year old. The October 2025 update added three topics, and I read all three as the FDPIC watching how your visitors' data gets monetized. Sharing visitor data with third parties in exchange for payment may require consent, especially where it enables "high-risk profiling," which means building a detailed picture of a person that could seriously affect them. Cookie paywalls, the "consent or pay" pattern, got expanded treatment in the free-services section. And location data is now flagged as a high-risk profiling vector.
For analytics, the load-bearing part is section 3.8.2. It says you can justify audience measurement through "overriding private interest," a legal basis that works instead of consent, if you meet three conditions. You anonymize the data as soon as the purpose allows. You share sensitive data with third parties only in a form that can't identify anyone. And you publish results without identifying anyone either.
Then the guidelines say the sentence that matters most for your analytics choice: "These requirements can also be met when using external analysis tools, provided that the suppliers of these tools process the data only on the website operator's behalf and not for their own purposes."
Read that twice. You can run consent-free analytics in Switzerland if your tool works only for you.
This is conceptually close to France's CNIL exemption, but narrower and lonelier. France evaluated 23 tools against published criteria and now runs a self-assessment framework. Which means France gave answers, and Switzerland gives homework. You get the conditions, you make the call, and you carry the assessment if anyone ever asks. No whitelist. No pre-approved configurations.
For what it's worth, that supplier test is the one I built Clickport around: it processes data only on the site owner's behalf, anonymizes at ingestion, and never touches your visitors' data for its own purposes. But you should hold whatever tool you use to the same test, including mine.
Where Google Analytics stands: official silence
No Swiss ruling, no guidance, and no enforcement action has ever ruled on Google Analytics. The only place the name appears in the FDPIC's roughly 20-page cookie guidelines is a footnote citing Austria's ruling as a comparative reference. Switzerland never had its Austria or France moment, and you can trace that silence to a single scoping decision made in 2020.
Remember the 2022 wave? In January 2022, the Austrian data protection authority ruled that using Google Analytics violated the GDPR, the story I covered in the Austria edition of this series. France's CNIL followed in February 2022, and Italy joined that summer. Put another way, that wave wasn't spontaneous. Those decisions all grew from one seed: the 101 complaints that the privacy group noyb filed on August 17, 2020, after the EU's top court struck down the Privacy Shield transfer deal.
Here's the detail that explains the Swiss silence. noyb's campaign was explicitly scoped to "30 EU and EEA member states." Which means Switzerland was never even in the queue. No complaint was filed here, so no Swiss ruling was triggered. The silence isn't a verdict. It's an accident of geography.
The FDPIC knows about those rulings, of course. Its own cookie guidelines cite the Austrian Google Analytics decisions in a footnote, as a comparative reference for when visitor data counts as identifiable. That's a citation for context, not a Swiss ruling. And it's as close as Switzerland has ever come to an official position on GA.
So where does that leave you? With the supplier test from the previous section. The statistics carve-out requires your analytics tool to process data "only on the website operator's behalf and not for their own purposes." I'll be straight with you here: what follows is my reading, not an FDPIC finding. A standard GA4 setup arguably fails that test, because Google also processes analytics data for its own purposes. You won't find a Swiss ruling that says so. You won't find one that says otherwise either. For the EU-wide legal history behind the 2022 rulings, I keep a full timeline of Google Analytics' legal status updated separately.
The US transfer question, solved the Swiss way (for now)
Sending visitor data to US servers is exactly what made Google Analytics unlawful in Austria and France in 2022. Switzerland closed that gap on its own schedule: the Swiss-US Data Privacy Framework has been in force since September 15, 2024. Certified US companies, Google included, can receive Swiss personal data without extra safeguards.
A quick plain-words detour, because "adequacy" is doing a lot of work here. Countries keep lists of other countries whose data protection they trust. If the destination is on the list, your data can flow freely. If it isn't, you need extra contracts and risk assessments for every transfer. In Switzerland, the Federal Council, the government's executive, decides who's on that list. Not the FDPIC.
The Swiss-US Data Privacy Framework was announced on August 15, 2024, and the FDPIC took note of it in exactly these words: "From 15 September 2024, this will ensure adequate data protection in the exchange of personal data between Switzerland and certified US companies."
The mechanism is self-certification. In plain English: a US company promises to follow the framework's principles, registers itself, and the door opens, with no extra clauses and no transfer impact assessments. Google is certified, according to the US Department of Commerce's framework list. So the transfer leg of using Google Analytics is currently covered in Switzerland.
Currently is the load-bearing word. The EU's parallel framework, in place since July 2023, is being challenged before the EU's highest court right now. Switzerland sits outside that court's jurisdiction, and the Swiss-US framework is a separate instrument, so a Luxembourg judgment wouldn't strike it down directly. But both frameworks stand on the same US legal foundations, and US transfer deals have already collapsed twice, Safe Harbor in 2015 and Privacy Shield in 2020. In other words, these deals have averaged about a five-year lifespan. I wouldn't anchor your long-term analytics setup on the third attempt surviving.
What the FDPIC actually enforces
The FDPIC's public record on web tracking is short, and it contains zero fines against companies, because the FDPIC can't issue any. I went through every public FDPIC case that touches tracking or marketing data, and I found four. The pattern: investigations, recommendations, binding orders, and once, a criminal complaint handed to prosecutors.
The closest the FDPIC ever came to a Google-Analytics-style case was Oracle. It opened an inquiry on September 27, 2022, after a US class action alleged Oracle tracked billions of people through cookies, pixels, and JavaScript. The FDPIC's first checks found similar tracking "widely used in Switzerland." Then, on October 6, 2023, it closed the case without formal proceedings, after Oracle assured it doesn't use Swiss individuals' data for advertising and had ended its Swiss data-broker contracts. In practice, the biggest Swiss web-tracking investigation ended in a handshake.
The other cases follow the same shape:
- Digitec Galaxus, Switzerland's biggest online retailer. The FDPIC concluded in April 2024 that forcing account creation and tying orders to behavioural personalisation violated proportionality, the principle that you only use as much data as the purpose needs. The remedy wasn't a penalty. It was a recommendation. The company added a one-click opt-out, and the FDPIC published the case as closed on February 12, 2026. No fine.
- Add Conti GmbH, a Swiss firm that collected and shared German residents' data for advertising and ignored deletion and access requests. The FDPIC opened an investigation on June 4, 2025. The company simply didn't respond. So on August 14, 2025, the FDPIC filed a criminal complaint with cantonal law enforcement, citing the CHF 250,000 maximum for breaching the duty to cooperate. That case now sits with prosecutors.
- Cream della Cream and Philipp Plein, the fashion group. A ruling dated April 17, 2026 found they kept using customers' emails and phone numbers for ads after explicit objections, and even after confirming deletion. The FDPIC ordered them to stop on objection and delete on request. Again: an order, no money.
So if you run a Swiss site, the realistic enforcement path is a complaint, then an FDPIC letter, then orders, with personal criminal liability as the escalation for whoever stonewalls. You aren't getting a nine-figure cookie fine here. But a published FDPIC ruling with your name in it is its own kind of expensive, and Add Conti shows you what happens when you ignore the regulator's mail.
Your analytics still miss a third of your Swiss traffic
Legal permission isn't the same as good data. Around 30.9% of Swiss internet users run an ad blocker, which stops the Google Analytics script before any legal question even arises. Safari holds 29.78% of the Swiss browser market and restricts tracking on its own. And if you show an EU-style consent banner anyway, most people decline it.
Switzerland is one of the most connected countries on earth. DataReportal's Digital 2026 report counts 8.89 million internet users out of 8.98 million people, which is 99.0% penetration. In practice, your entire Swiss market is online. You can't blame an offline remainder for weak numbers.
Now subtract the invisible part. Per Backlinko's compilation of DataReportal's 2026 data, 30.9% of Swiss internet users block ads, slightly above the global average of 29.5% and in the same band as Germany's 31.5%. Put another way: nearly 1 Swiss visitor in 3 never appears in Google Analytics, no matter what the law allows you to do. Ad blockers kill the script itself. Consent never enters into it.
Browsers take another cut. StatCounter puts Safari at 29.78% of Swiss browsing as of July 2026, against Chrome's 44.79%. In practice, Safari's built-in tracking prevention caps cookie lifetimes and blocks known trackers, which quietly degrades any cookie-based tool you run.
And then there's the banner problem, which many Swiss sites volunteer for. Swiss law doesn't require a consent banner, but plenty of Swiss businesses serve EU visitors and show one anyway, sometimes to everyone, even where they don't have to. The numbers on fair banners are brutal, and I mean brutal. A 2019 study by Utz and colleagues analyzed about 3 million real consent interactions across roughly 2,000 sites (an international dataset, not a Swiss one), and found that when nothing was pre-ticked, only 5.59% of people accepted. That means about 19 in 20 visitors decline when you ask them fairly. With everything pre-ticked, acceptance jumped to 98.84%. Which means the pre-tick was doing all the work, and that's exactly why the EU banned it.
This is the quiet advantage of the Swiss model. Because the law is opt-out, a cookie-banner-free analytics setup isn't a workaround here. It's the default the law was written for. Tools that need no cookies and no banner, several of them built and hosted in Europe, show you every visitor an ad blocker doesn't eat. Cookie-based tools start every day a third down.
What's coming in 2026 and beyond
The Swiss framework itself is stable, but three moving pieces around it aren't: the EU is weighing consent-free audience measurement through the Digital Omnibus, the EU-US data transfer framework is being challenged in court, and the FDPIC has tightened its cookie guidance twice within a year. Here's what I'm watching on each.
The EU may be drifting toward the Swiss model. The Digital Omnibus, proposed in November 2025, would allow consent-free audience measurement across all 27 EU member states. In plain English, Brussels wants what Bern already has. It's still a proposal, not law. But I find the direction telling: after a decade of banner fatigue, the EU is inching toward the inform-and-object philosophy Switzerland has run since 2007. If it passes, the gap between your Swiss traffic and your EU traffic narrows a lot.
The EU-US transfer framework is in court. The challenge to the EU's Data Privacy Framework is pending at the EU's highest court. You aren't directly bound by the outcome if you're Swiss-only. Still, if the EU framework falls, I'd expect pressure on the parallel Swiss-US framework, because both rest on the same US surveillance-law foundations. That's my expectation, not a legal prediction.
The FDPIC is warming up on cookies. It updated its cookie guidance twice within a year, adding consent-or-pay walls, third-party data sharing, and location profiling. And the Add Conti criminal complaint is the first live test of the CHF 250,000 penalty for refusing to cooperate. In practice, that means the era of the FDPIC politely watching from the sidelines is probably ending.
What this means for your website
If your site serves Swiss visitors only: you can run Google Analytics legally today. No Swiss law forces a cookie banner on you; you'll still need to disclose your tracking in a privacy notice and give visitors a way to object. Your open questions are quieter ones. Does Google process your visitors' data only on your behalf? I doubt it, and that's the condition Swiss law attaches to consent-free analytics. And 30.9% of your visitors block the script anyway. Which means your numbers start a third short before you've measured anything.
If your Swiss site also serves EU visitors: the GDPR travels with them. For that part of your traffic you're back to opt-in consent, equal-prominence reject buttons, and the data loss that follows, the same maths as everywhere in the EU. You can run two regimes on one site, but most companies just apply the stricter one everywhere and quietly lose most of their data to it.
If you want full data and no open questions: use an analytics tool that passes the Swiss test by design. One that processes data only on your behalf, anonymizes immediately, needs no cookies and no banner, and keeps the data in Europe so the whole US transfer question disappears for you. Here's how that works in practice.
A closing note, because this is a legal topic: I'm not a lawyer and this article isn't legal advice. It's a founder's map of the Swiss terrain, with every ruling linked to its primary source where one is public. If your setup is complicated, show this to your DPO or your lawyer. And if you're weighing a Swiss analytics decision and something here doesn't match what you're seeing, email me.
If you'd rather be done with the question altogether, you can try Clickport free for 30 days. Switching from Google Analytics takes one snippet, and the banner conversation never comes up again.

Comments
Loading comments...
Leave a comment