2026 Status — FADP, GDPR & FDPIC Guidelines

Do I need a cookie banner? The decision tree for your company.

Whether Switzerland, Germany or Austria — cookie rules are getting stricter. Find out in 60 seconds what your website needs: cookie banner, privacy policy, Google Consent Mode V2 — or everything together.

The Interactive Decision Tree

Answer 4 short questions and receive a clear recommendation.

1/4

Where is your company based?

The Three Levels of Cookie Obligation in Switzerland

The FDPIC distinguishes three risk levels. The higher the level, the more you need to implement.

Level 1

Essential Cookies Only

Your website only uses technically necessary cookies — e.g. session cookies, shopping cart cookies or language settings.

What you need:

  • Privacy policy with cookie listing
  • Notice of cookie usage

Not required:

  • No cookie banner
  • No consent

Legal basis: Art. 45c FMG, FDPIC Guidelines Section 3.5

Reality check: Applies to less than 5% of all Swiss websites.

Level 2

Non-Essential Cookies

You use cookies that go beyond what is technically necessary but do not enable high-risk profiling — e.g. anonymised first-party analytics.

What you need:

  • Cookie banner with opt-out right
  • Option to reject cookies
  • Privacy policy with cookie table

Legal basis: Art. 6 Para. 1 FADP, Art. 31 FADP, FDPIC Guidelines Section 3.8

Caution: The boundary to Level 3 is fluid. When in doubt, opt-in is recommended.

Level 3

High-Risk Cookies

You use third-party cookies that enable high-risk profiling — Google Analytics, Google Ads, Facebook Pixel, YouTube embeds, etc.

What you need:

  • Cookie banner with opt-in (equal buttons)
  • Granular settings per category
  • Script blocking before consent
  • Google Consent Mode V2
  • Consent log for accountability

Legal basis: Art. 6 Para. 6+7 FADP, Art. 22 FADP, FDPIC Guidelines Section 3.10

Fines: Up to CHF 5,000 (FMG) / CHF 250,000 (FADP). Affects over 90% of all SME websites.

Cookie Banner Requirements by Country

The rules differ by country. Select your country for details.

Legal basis:
FADP (since 1 Sep 2023) + Art. 45c FMG
Supervisory authority:
FDPIC (Federal Data Protection Commissioner)
Cookie banner needed?
Yes, as soon as non-essential cookies are used
Equal buttons?
Recommended for opt-in, not explicitly required for opt-out
Google Consent Mode V2:
Recommended, effectively mandatory for Google services since July 2024
Fines:
Up to CHF 5,000 (FMG) / CHF 250,000 (FADP) — against the natural person

Special feature: Three-tier system. Opt-out may suffice in certain cases (more liberal than EU). FDPIC has announced awareness campaigns and regulatory action (October 2025).

🇨🇭🇪🇺

Special Case: Swiss Companies with EU Clients

Affects virtually every Swiss website with an international audience

When does the GDPR apply to my Swiss company?

The GDPR also applies to Swiss companies when:

  • You offer goods or services to persons in the EU — identifiable by: prices in euros, delivery to EU countries, .de/.at/.eu domain
  • You monitor the behaviour of persons in the EU (tracking, profiling) — e.g. via Google Analytics with EU visitors

What else do I need to consider?

  • Cookie banner must comply with both FADP and GDPR → apply the GDPR standard (it is stricter)
  • Privacy policy must cite both FADP and GDPR legal bases
  • Appoint an EU representative (Art. 27 GDPR) if no establishment in the EU
  • Google Consent Mode V2 is mandatory (not just recommended)

Recommendation: Swiss companies that even potentially have EU visitors are safest applying the GDPR standard. Aiara automatically generates legal texts with both legal bases (FADP + GDPR).

Google Consent Mode V2 — Mandatory Since 2024

An interface between your cookie banner and Google services. It tells Google which consent the visitor has given.

ad_storage

May Google store advertising cookies?

ad_user_data

May Google use user data for advertising?

ad_personalization

May Google deliver personalized ads?

analytics_storage

May Google Analytics set cookies?

functionality_storage

May Google store functional cookies?

personalization_storage

May Google set personalization cookies?

When is GCM V2 mandatory?

  • 03/2024 In the EEA (EU + NO, IS, LI)
  • 07/2024 In Switzerland
  • Affects All websites using Google Analytics, Ads, GTM or Google advertising services

What happens without GCM V2?

  • Google Analytics delivers incomplete data
  • Google Ads conversion tracking does not work
  • Remarketing lists are not built
  • Behavioral Modeling (AI data supplementation) does not work

Google Consent Mode V2 is integrated out of the box with Aiara. Default: all parameters "denied". After consent: automatic update. Zero configuration effort.

The Most Common Google Services and Their Cookie Requirements

Google Analytics (GA4)Opt-in
Cookies:
_ga, _ga_*, _gid
Category:
Analytics
GCM V2: analytics_storage
Google AdsOpt-in
Cookies:
_gcl_au, _gcl_aw, IDE
Category:
Marketing
GCM V2: ad_storage, ad_user_data, ad_personalization
Google Tag ManagerOpt-in
Cookies:
None of its own
Category:
GCM V2: All parameters
Google reCAPTCHADisputed
Cookies:
_GRECAPTCHA, NID
Category:
Functional
GCM V2: functionality_storage
Google FontsDisputed
Cookies:
None (IP transmission)
Category:
Functional
GCM V2:
Google MapsOpt-in
Cookies:
NID, CONSENT, 1P_JAR
Category:
Marketing
GCM V2: ad_storage, personalization_storage
YouTube (Embeds)Opt-in
Cookies:
VISITOR_INFO1_LIVE, YSC
Category:
Marketing
GCM V2: ad_storage, ad_personalization
Facebook PixelOpt-in
Cookies:
_fbp, _fbc, fr
Category:
Marketing
GCM V2:
TikTok PixelOpt-in
Cookies:
_ttp, _tt_enable_cookie
Category:
Marketing
GCM V2:
HotjarOpt-in
Cookies:
_hjSessionUser_*, _hjSession_*
Category:
Analytics
GCM V2:
Matomo (self-hosted)Disputed
Cookies:
_pk_id.*, _pk_ses.*
Category:
Analytics
GCM V2:

Frequently Asked Questions

Act now — before the FDPIC comes knocking.

Aiara makes your website legally compliant in 10 minutes. Cookie banner, privacy policy, imprint and Google Consent Mode V2 — everything from one source, specifically developed for Switzerland.

Swiss MadeDSG & GDPRGCM V24 Languages