Back to overview
HealthcareTrackingData protectionProfessional secrecy

Who is watching when you open a hospital website?

We measured 40 Swiss hospital and clinic websites. On 25 of the 32 that were reachable, data flows to Google or Meta before anyone has clicked «Accept». On the page of a maternity ward, the full address including the page title went to Google, without any consent at all. A finding, its legal classification, and the question of where the data ends up.

Aiara Team··11 min read
Who is watching when you open a hospital website?

On 2 September 2026 we opened 40 Swiss hospital, clinic and group websites, the way any visitor does, and recorded which connections the browser establishes in the process. Nothing clicked, nothing confirmed, no banner dismissed. Just the page opened.

32 websites were reachable. On 25 of them, merely opening the page triggered at least one connection to Google or Meta. On two websites everything stayed in house.

Opening the page of a maternity ward looked like this in transmission (recipient, address, page title, consent; recorded verbatim in German):

Empfänger:   region1.analytics.google.com
Adresse:     https://www.[spital].ch/geburt
Seitentitel: «Ihre Begleitung bei Schwangerschaft und Geburt»
Einwilligung: keine

Plus the IP address, which inevitably accompanies every connection on the internet. Google thus learns: this connection opened this page of this hospital at this point in time.

We do not name the institutions examined. This is not about individual failings: the pattern is widespread, and in almost every case nobody inside the institution is likely to be aware of it.

What we measured

Finding Number
Websites in the sample (32 reachable) 40
Connection to Google or Meta on merely opening the page 25 of 32
Examined in detail: measurement points before any consent 13 of 15
Of those, Meta pixel without consent 6
Entirely without any third-party connection 2
No consent tool detectable 17 of 32

The tools in use were spread across OneTrust (5), Cookiebot (3), CookieYes (2), Usercentrics (2) plus Klaro, Complianz and Iubenda once each.

One detail deserves particular attention. At one clinic group, the request to the Google advertising server carried the parameter gcs=G111. That is the message that consent was given for analytics and advertising. Nobody had clicked. The consent tool was installed, visible, operational, and it reported agreement before anyone agreed.

That is precisely what this article is about. The banner is not the problem. Nor is it the solution.

Why a hospital is not like a furniture store

On a website for garden furniture, a tracker is a data protection question. On a hospital website it is possibly something else.

The Federal Data Protection and Information Commissioner (FDPIC) has never commented on tracking on health websites. On the structurally identical question, however, it certainly has. Its factsheet on patient forms of 30 September 2025 states (translated from the German original):

«In connection with health, the mere existence of a relationship with a therapist may already permit inferences about a person's state of health; this applies in particular to communication with medical specialists (an appointment with an oncologist, for example, suggests that she is being consulted because of a potential oncological illness). Consequently, purely administrative exchanges (e.g. the arranging of appointments) must also be classified as sensitive.»

The mental step from the appointment with the oncologist to opening the page /kliniken/onkologie is a short one. The FDPIC has not taken it, and intellectual honesty requires saying so.

Others have. On 10 June 2025 the Norwegian data protection authority decided a case concerning a health portal with a Meta pixel and held that the visit to the website may on its own suffice to constitute a special category of personal data. It is not necessary that the data be linked directly to a state of health, or that the operator combine them with other data.

In the Lindenapotheke ruling of 4 October 2024, the Court of Justice of the European Union set the threshold low: it suffices that the data allow «the state of health of the data subject to be inferred by means of mental combination or deduction». Whether the inference is correct, and whether the operator intends it at all, is irrelevant.

The Dutch supervisory authority spelled this out for hospitals as early as 2016, after examining all 85 Dutch hospitals: the point is not only the home page, but the pages behind it dealing with particular illnesses and specialist departments.

The counter-check, for the sake of fairness: no Swiss court has ever ruled on this. Across the whole of Europe there is to this day not a single supervisory decision against a hospital over Google Analytics or a Meta pixel. And the Belgian authority dismissed a comparable complaint in 2022 precisely because the link to the page visited had not been demonstrated technically. In the case of a hospital that transmits the full address itself, however, that demonstration is available, and it can be produced in any browser in two minutes.

The legal consequence if the step is taken

Anyone who classifies visit data as sensitive personal data arrives at a clear rule. The FDPIC writes in its cookie guidance (section 3.10.1), translated from the German original:

«For the use of non-necessary cookies in the context of processing with a high intensity of interference, the controller can invoke neither the predominance of its own private interest nor an optional design of the processing. Rather, it must obtain express consent from the data subjects before carrying it out.»

In the guidance's risk radar, «sensitive personal data: yes» receives the maximum value of 3, and from 2.5 upwards the rule is: opt-in mandatory. Article 6(7)(a) FADP requires express consent in any case, and Article 30(2)(c) FADP expressly calls it a breach of personality rights when sensitive personal data are disclosed to third parties.

On top of that comes a layer that is often overlooked in healthcare. Professional secrecy under Article 321 of the Swiss Criminal Code protects, on the reading of SAMW and FMH, not only diagnoses but also «the identity of the patient and the fact that he or she is receiving medical treatment». It is breached as soon as secrets become known to unauthorised persons, «irrespective of the manner in which this occurs».

The Data Protection Commissioner of the Canton of Zurich is very clear in her factsheet on US cloud products of February 2026 (translated from the German original):

«In the case of information and personal data subject to a special duty of secrecy, the factual possibility of access by US authorities leads to a breach of the corresponding duty of secrecy.»

And further: «Employees of US companies [are] not regarded as auxiliary persons, owing to the group structure and the international interconnection of their employers.» Metadata, too, must be protected.

Whether setting a tracker amounts to «disclosure» in criminal law has never been decided by a court. Article 321 of the Swiss Criminal Code requires intent. That is a serious hurdle, but not one that anyone taking the decision today should rely on.

Where the providers come from, and why that is the wrong question

The belief persists that the major consent providers are all non-European. That is not the case. We checked the legal entities on the basis of imprints, commercial registers and data processing agreements:

Provider Legal entity Registered office Ownership
Cookiebot Usercentrics A/S Copenhagen, DK Part of the Usercentrics group (merger with Cybot A/S, 2021)
Usercentrics Usercentrics GmbH Munich, DE Privately held, investors include Full In Partners (New York)
CookieYes CookieYes Limited Milton Keynes, UK Two private individuals; product of the Mozilor group, Kochi (India)
OneTrust OT Technology, Inc. Atlanta, USA Private, investors include Insight Partners, TCV, SoftBank

Two of the four are therefore based in the EU. Anyone arguing «they are not in Europe at all» is arguing from a false premise.

The more revealing question is: which route do the visitor data take? And that is where it becomes interesting, because the answer is set out in the providers' own documents.

Cookiebot writes in its own support documentation:

«Cookiebot uses Akamai, a US based company, as our CDN sub service provider. […] However, the way the Internet works, it cannot be avoided that Akamai will receive and log certain information about the Internet connection, including end user IP addresses

That is why a purely European variant exists, one that has to be switched on actively, by replacing consent.cookiebot.com with consent.cookiebot.eu in the script tag. Cookiebot describes the choice with remarkable openness as «a conscious choice on your part of compliance over performance». The default route runs via the USA. We measured this: consent.cookiebot.com resolves via Akamai, consent.cookiebot.eu via a node in Zurich.

For the others, the picture is as follows:

  • CookieYes lists Cloudflare in its sub-processor list, with the USA as its location and the data categories «IP address, User agent, Hostname». Its own documentation speaks of a masked IP address; how the masking works is not stated in any traceable source. Support runs through Mozilor Technologies in India. India is not on the Federal Council's country list (Annex 1 to the Data Protection Ordinance), which means that any disclosure there necessarily requires additional safeguards under Article 16(2) FADP.
  • Usercentrics keeps the chain for consent management European (hosting on Google Cloud Dublin, CDN from Slovenia), but concedes in its own privacy policy that it cannot rule out that data reach the USA and are subject there to government access under FISA 702.
  • OneTrust is the only one with a US parent company and at the same time the only one with a selectable Azure data centre in Zurich and an active certification under the Swiss-US Data Privacy Framework. Whether the visitor's IP address in the consent record is stored, truncated or hashed is not stated by OneTrust in any public source.

Put differently: the Danish provider sends IP addresses through a US corporation by default, and the American provider can host in Zurich. The registered office is not a test criterion. The data route is.

One widespread misconception should be cleared up here: it is occasionally claimed that Cookiebot was banned by the authorities. The Wiesbaden Administrative Court did indeed prohibit a university from embedding it in 2021. The Hesse Higher Administrative Court set that decision aside again in January 2022, on procedural grounds. No main proceedings on the matter are known. The statement «banned» is wrong.

Public hospitals are in a different position, a stricter one

Here is a point that is almost always lost in discussions. Public hospitals are governed not by the federal FADP but by cantonal data protection law. The FDPIC makes this clear itself: cantonal hospitals are «not directly affected» by its federal factsheets.

And some cantons are considerably stricter. The Data Protection Commissioner of the Canton of Zurich writes in her factsheet on privacy policies on the websites of public bodies (October 2025), translated from the German original:

«Public bodies shall design their web presence in compliance with data protection law and refrain from person-related analysis of user behaviour. Privacy policies, banners, pop-ups and other mechanisms are therefore not required.»

And expressly: «No mechanisms are to be used that feign a fictitious consent to users.»

The logic behind this is compelling: in public-sector data protection law, consent is not a general ground of justification. What matters is the statutory task and necessity. A cantonal hospital that deploys an off-the-shelf consent banner thereby makes two mistakes at once: it tracks without necessity, and it asks for a consent it cannot legally accept in the first place. As a permissible alternative, the authority expressly names anonymising tools such as Matomo or AWStats.

This does not apply to private clinics, practices and hospital groups. They are subject to the FADP and hence to the route via express consent.

What an institution should check in concrete terms

  1. Measure it yourself. Right-click, «Inspect», «Network» tab, reload the page, and do so before any click on the banner. Whatever already goes to google-analytics.com, facebook.net or doubleclick.net at that point goes without consent. This takes two minutes and requires no budget.
  2. The sensitive subpages first. Oncology, psychiatry, fertility treatment, addiction medicine, obstetrics. There, the page path is itself the information.
  3. Request the sub-processor list. Not the registered office. The list, with processing locations. In the case of Cookiebot, additionally clarify whether the European variant is active. By default it is not.
  4. Check whether the tool really blocks. A banner that releases the scripts only after consent is something entirely different from one that merely asks and lets everything run.
  5. Take professional secrecy into account. It is a legal layer of its own, not a footnote to data protection law, and Article 9(1)(b) FADP expressly prohibits outsourcing wherever a duty of confidentiality stands in the way.

The benchmark already exists

For the contents of the electronic patient record, the legislature has laid down an unmistakable rule. Article 12(5) of the Ordinance on the Electronic Patient Record:

«The data stores must be located in Switzerland and be subject to Swiss law.»

For the visitor data of the same institution on its own website, that sentence does not apply. That is the law as it stands and not a loophole to be argued away. But it is a yardstick of values that the legislature itself has set. Anyone who knows the address of a hospital's oncology page may know more about the visitor than many an entry in the record reveals.


Aiara is a Swiss provider of cookie banners and legal texts. Our application runs on servers in St. Gallen; the banner script loads exclusively from aiara.ch and contacts no third parties. In the consent record we do not store the IP address in plain text, but only a salted SHA-256 hash value. That we take up this subject has to do with our business. The measurements above can nevertheless be reproduced by anyone in two minutes, and that is precisely what we would like to invite people to do.

Methodology: Accessed on 2 September 2026 from Switzerland, one page view per website with a fresh browser profile, without any interaction with the consent banner, Chromium 148, language de-CH. All outgoing network requests were recorded. Only requests to known measurement and advertising endpoints were counted as a «measurement point», not the mere loading of a library. Five addresses could not be resolved, three did not respond within 30 seconds.

Share this post

Frequently Asked Questions

Are visit data from a hospital website health data?

The question has not been conclusively settled in Switzerland. The FDPIC has not answered it for websites, but states in its factsheet of 30 September 2025 that an appointment with an oncologist already permits an inference about a possible illness, which is why even purely administrative exchanges are sensitive. The Norwegian data protection authority decided on 10 June 2025 that the mere visit to a health website may in itself constitute a special category of data. In the Lindenapotheke ruling, the CJEU requires only that the state of health can be inferred by mental combination.

What kind of consent is then required?

The FDPIC classifies the use of cookies in connection with sensitive personal data as processing with a high intensity of interference. In its cookie guidance it states that the controller can invoke neither an overriding interest of its own nor an optional design of the processing: it must obtain express consent beforehand. Article 6(7)(a) FADP requires express consent for sensitive data in any case.

Does the same law apply to a cantonal hospital as to a private clinic?

No. Public hospitals are subject to cantonal data protection law, not to the federal FADP; the FDPIC says so itself. The Data Protection Commissioner of the Canton of Zurich goes further than the federal level: public bodies should refrain entirely from person-related analysis of user behaviour, and therefore from consent banners as well, because a banner feigns a consent that is not even a valid ground of justification under public law.

Where do the widely used consent providers come from?

Cookiebot belongs to Usercentrics A/S, based in Copenhagen; Usercentrics is a GmbH in Munich. Both are therefore in the EU. CookieYes Limited is based in Milton Keynes in the United Kingdom and is owned by two private individuals; the product originates from the Indian Mozilor group in Kochi. OneTrust is domiciled in Atlanta as OT Technology, Inc. The registered office alone, however, says little about the route the visitor data takes.

What is the most important point for a hospital to check?

Not the provider's registered office, but the actual data route. Cookiebot, for instance, writes itself that in the standard setup the US service provider Akamai receives and logs visitor IP addresses, and offers a purely European variant that has to be selected actively. A hospital should request the sub-processor list, measure the data route in the browser and check whether the tool actually blocks the trackers before consent.

Is a consent banner enough to solve the problem?

No. Our measurement shows the opposite: on several websites a consent tool was installed, and the trackers fired before any consent all the same. At one clinic group the page even expressly reported to the Google server that consent had been given for analytics and advertising, although nobody had clicked. A banner is a user interface; it becomes effective only once it actually holds the scripts back.

Ready for clean cookie consent?

Aiara handles cookie banners, privacy policies and legal notices for your website — FADP and GDPR compliant.

Discover Aiara