For a B2B website that matters in practice: the mechanism of company-level identification is the same, but the documents, the terms and the reference law a Swiss reviewer expects are different. This page sets out what applies here.
At a glance
- Framework
- revFADP / revDSG — Swiss law, not the GDPR
- Supervision
- FDPIC (EDÖB), the Federal Data Protection and Information Commissioner
- Usual basis
- No consent requirement by default; processing must be lawful, proportionate and transparent
- Processing location
- ISO-certified EU data centres
revFADP instead of the GDPR: what actually differs
Regulation at a glance
- FrameworkrevFADP / revDSG — Swiss law, not the GDPR
- SupervisionFDPIC (EDÖB), the Federal Data Protection and Information Commissioner
- Usual basisNo consent requirement by default; processing must be lawful, proportionate and transparent
- Processing locationISO-certified EU data centres
The revised FADP was deliberately aligned with the GDPR, but it is a separate act and the differences are not cosmetic. The most consequential one for a website operator: Swiss law does not work from a closed list of legal bases. Private processing does not require a justification such as legitimate interest in the first place — it is permitted unless it unlawfully breaches a data subject's personality rights, for example through a lack of transparency, disproportionate processing or processing against an express objection. So instead of writing a balancing test, the Swiss question is whether the processing is proportionate, recognisable and free of surprise.
The revFADP also narrowed its own scope in one respect that is directly relevant here: it protects data of natural persons only. The previous Swiss law also covered legal persons; the revised act does not. Company-level identification, which resolves an organisation rather than a person, therefore sits in a noticeably clearer position under Swiss law than it would under a regime that still protected company data as such.
Duties look familiar but are named differently. There is a register of processing activities, an obligation to inform data subjects when personal data is collected, a data protection impact assessment for high-risk processing, and breach notification to the FDPIC — with a Swiss threshold and timing that is not the GDPR's 72-hour rule. Processors are permitted with a contract; sub-processing requires authorisation.
Transfers abroad are handled through the Federal Council's list of countries with adequate protection, which includes the EEA states. Processing Swiss-related visitor data in ISO-certified EU data centres therefore rests on an adequacy decision rather than on contractual clauses — one of the reasons an EU processing location is easy to defend in a Swiss review.
One structural point often catches non-Swiss vendors: a controller abroad that processes data of people in Switzerland may need to designate a representative in Switzerland in defined cases. That is a vendor-side duty, not something a customer configures, but it is a question that gets asked.
How Swiss buyers review it
Swiss reviewers are precise about terminology. A vendor that answers a revFADP question with GDPR boilerplate signals that it has not read the local law. Expect to be asked which act you are answering under, whether legal persons are in scope, and where data physically sits.
Documentation expectations are modest but firm: a processing agreement, a named sub-processor list, a clear statement of processing location, and information text you can put into your own privacy statement. Multilingual reality matters too — German, French and Italian are all working languages, and German-language documentation covers the largest part of the B2B market.
Because Switzerland is a small, relationship-driven market, restraint in claims pays off. Describing what is resolved, what is discarded and where the customer's own responsibility begins is the version that survives a second meeting.
Start free
Install the snippet and see the first named companies on your own traffic.
What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
Where identification pays off here
Precision manufacturing, medtech, financial services suppliers and B2B software firms serving the Swiss market benefit most: high deal values, small target lists, and buying committees that research quietly before making contact. Recognising the company behind that research is often worth more than a hundred anonymous sessions.
It also suits vendors selling into Switzerland from abroad. Seeing that a Swiss company is reading your product pages is the difference between speculative outreach and a call with a reason.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
Not as Swiss domestic law. Switzerland applies the revised Federal Act on Data Protection (revFADP / revDSG), supervised by the FDPIC, and it is a separate statute from the EU regulation even though the two were deliberately aligned. The GDPR can still apply in parallel to a Swiss company through its own extraterritorial scope, for example when that company offers goods or services to people in the EU or monitors their behaviour there — which is why many Swiss B2B vendors end up documenting compliance with both frameworks rather than treating them as interchangeable. For a website serving Swiss and EU visitors together, the practical approach is to build to the stricter of the two baselines and be able to name, on request, which duty rests on which law. Swiss reviewers notice quickly when a vendor cannot tell the two apart.
Swiss law does not require a legal basis such as consent for private processing by default; unlike the GDPR's closed list, revFADP processing is permitted unless it unlawfully breaches a data subject's personality rights — through a lack of transparency, disproportionate processing, or processing carried out against an express objection. That makes recognisability, proportionality and respecting objections the practical requirements rather than a consent form. lead.box is built around exactly those three: identification is disclosed in your privacy statement in plain language, the scope is limited to resolving the organisation behind a visit, and every visitor can object at any time through a public, independently reachable opt-out page that the FDPIC can be shown on request.
No, and this is one of the sharpest differences from the old Swiss regime. The revised act protects data of natural persons only; the previous Federal Act on Data Protection also covered legal persons such as companies, but that protection was deliberately dropped in the 2023 revision. Company-level identification resolves the organisation behind a visit — an entity entered in the commercial register, not an individual person — and therefore falls outside the revFADP's protected scope in the first place, rather than merely satisfying an exception within it. Individual employees browsing the site are never singled out, profiled or exported by name, which keeps the product's Swiss legal position noticeably clearer than a tool built around personal profiles.
Yes. The EEA states appear on the Federal Council's list of countries recognised as having an adequate level of data protection, so processing Swiss-related visitor data in ISO-certified EU data centres rests on that adequacy decision rather than on additional contractual safeguards such as standard contractual clauses. That is one of the reasons an EU processing location is straightforward to defend in a Swiss procurement review: there is no separate transfer mechanism to negotiate on top of the ordinary processing agreement. The Swiss data processing agreement, aligned with revFADP terminology, and the versioned sub-processor list are both published so a Swiss buyer's legal or compliance team can review the chain before signing.
Switzerland has no direct equivalent to the EU's ePrivacy Directive, and the Telecommunications Act (FMG) does not impose a general cookie-consent duty the way EU member states' implementations do. What governs a Swiss company's own website is still the revFADP's proportionality-and-transparency test, plus any contractual duties under the Ordinance on Telecommunication Services if the visitor uses a Swiss telecom-provided connection. lead.box does not place advertising identifiers or tracking cookies on the visitor's device and does not read information already stored there, so it sits outside the narrow set of technologies that Swiss privacy guidance treats as consent-relevant — though a site's own analytics or advertising pixels may still require attention independently of this tool.
Every company entered in a Swiss cantonal commercial register carries a unique business identification number, the UID, and Swiss B2B buyers expect vendor documentation, invoices and data processing agreements to reference it correctly rather than using a generic international format. Company-level identification resolves the organisation from network information and matches it against firmographic company data; where a Swiss visitor's organisation is registered domestically, the match can be presented with its Swiss legal name and canton of registration rather than a foreign holding entity's name, which is what a Swiss sales team actually needs to open a relevant, correctly addressed conversation instead of chasing an ambiguous international group name.
The Swiss Federal Act on Information and Consultation of Employees (Mitwirkungsgesetz) gives staff representation rights mainly around larger organisational, safety and transfer decisions in companies above a headcount threshold; it does not generally require consultation for adopting a marketing or sales tool that identifies visiting organisations rather than monitoring individual employees. Because lead.box does not track identifiable individuals, log keystrokes or evaluate staff performance, it typically falls outside the kind of employee-monitoring measure that would trigger participation rights or a works-committee consultation in Swiss companies that have one, though internal IT and data protection policies should still be checked case by case.
Most Swiss teams start by installing a small JavaScript snippet on their main marketing domain and reviewing the first identified companies within the first day, checking that Swiss cantons and language regions are represented correctly before rolling the tool out to additional properties. From there, results flow into daily or weekly digests, CSV or Excel exports for reporting in German, French or Italian as needed, and webhooks into the CRM systems common in Swiss B2B — typically HubSpot, Pipedrive or Microsoft Dynamics. Seats can be added per sales or marketing team member, and the subscription can be cancelled directly in the account without a retention call, which matters to procurement teams used to Swiss vendors requiring a notice period.
See the Swiss companies behind your traffic
Install the snippet, watch the first companies appear, and answer the revFADP questions with documents instead of promises.