The Federal Act against Unfair Competition (UCA) requires Swiss websites offering goods or services to clearly identify the operator. Since September 1, 2023, the new Federal Act on Data Protection (nFADP) adds a layer of requirements regarding visitor information. Together, these two texts make legal notices a legal foundation that should not be taken lightly.
nFADP and Legal Notices: What the 2023 Revision Changes Practically
Most articles on legal notices in Switzerland focus on the UCA without detailing the impact of the nFADP. This is an analytical error. Since September 1, 2023, the obligation to inform applies to all personal data, not just sensitive data. A simple contact form or a traffic analysis tool triggers this obligation.
The nFADP requires the data controller to communicate at a minimum: their identity and contact details, the purpose of the processing, the recipients or categories of recipients of the data, as well as the destination countries in case of communication abroad, along with the guarantees used.
In practice, we recommend not merging this information into a single legal notice page. The privacy policy constitutes a separate document, linked in the footer just like the legal notices. Both are now equally central for the compliance of a website in Switzerland.
To observe how this structuring works on a professional site, the legal notices of Tous Éco illustrate well the separation between the identification of the operator and information related to personal data.

Mandatory Content of Legal Notices under the Swiss UCA
The UCA targets e-commerce sites and, more broadly, any site offering goods, works, or services. The goal is to enable potential customers to identify the company and contact it. The information to be included is specific:
- Name or company name, complete postal address (not just a PO box)
- Functional email address and, ideally, phone number
- For companies registered in the commercial register: company identification number (UID)
- For e-commerce: clear presentation of the steps in the ordering process, the possibility to correct entries before validation, and sending an order confirmation
A point often overlooked: the UCA requires transparency about the ordering process, not just about identity. The customer must know at what stage they are, be able to verify their input, and receive a summary. A merchant site that omits these elements exposes itself to lawsuits for unfair competition.
Data Communication Abroad: The Trap of Third-Party Tools
The nFADP requires documentation of any transfer of personal data outside Switzerland. We observe that the majority of Swiss sites use services hosted in the United States or the EU without mentioning it in their privacy policy. Google Analytics, a foreign host, a payment provider based outside Switzerland: each of these tools constitutes a communication abroad under the law.
Each third-party tool processing personal data must be declared with its destination country. It is also necessary to specify the guarantees in place: standard contractual clauses, adequacy decision by the Federal Council, or explicit consent from the user. Omitting this information is not a minor oversight. It is a direct breach of the nFADP’s information obligation.
We recommend regular technical audits of active scripts and cookies on the site. A plugin added by a developer may include a third-party tracker without the operator being aware. The privacy policy page must reflect the technical reality of the site, not a static version written at the time of launch.

Sanctions and Concrete Risks for Swiss Companies
Under the UCA, a competitor or a customer can take legal action against a site that does not comply with transparency obligations. The consequences range from compliance injunctions to damages.
The nFADP has introduced a criminal aspect. Intentional violations of information obligations can lead to fines targeting the responsible individual, not just the company. This mechanism changes the game compared to the previous regime, where sanctions were primarily civil.
The reputational risk also deserves mention. A site without legal notices or with a lacking privacy policy sends a negative signal to business partners and customers. In a Swiss B2B context, the legal compliance of the website is part of the due diligence before any collaboration.
Technical Structure of a Compliant Legal Notice Page
We find that many sites group legal notices, general terms and conditions, and privacy policy on a single page. This approach harms readability and complicates updates.
The structure we recommend is based on three distinct pages, all accessible from the footer:
- A legal notice page with the identification of the operator (company name, address, UID, contact)
- A privacy policy detailing data processing, third-party tools, transfers abroad, and the rights of data subjects
- Separate general terms of sale or use, tailored to the activity (e-commerce, SaaS, service)
Each page must display a visible last updated date. This allows proving that the content reflects the current state of the law and the technical configuration of the site. A document dated 2019 on a site revamped in 2024 poses a legal credibility issue.
The compliance of a website in Switzerland is not just about ticking a box at launch. The nFADP has transformed the privacy policy into a living document, to be revised whenever a new tool is integrated or a provider changes hosting country. The legal notices, on the other hand, remain stable as long as the legal structure of the company does not change, but their absence exposes to concrete and measurable risks.



