THE NEW DSG IN SWITZERLAND
Make your Marketing Salesforce solution compliant for the new Swiss Federal Act on Data Protection with the help of DIGITALL
WHAT IS THE NEW SWISS FEDERAL ACT ON DATA PROTECTION (FADP / NDSG)
AND WHAT DOES IT MEAN FOR SWISS AND OTHER COMPANIES?
The Swiss federal council is putting the new / revised data protection act (nDSG, also revDSG or FADP- Federal Act of Data Protection) and its implementing provisions in the new data protection ordinance (DSV) and the new data protection certification ordinance (VDSZ) into force on September 1st, 2023.
This means that companies operating in Switzerland or working with data of Swiss citizens will have to review the handling of data of private individuals. In doing so, companies must adhere to a series of process measures to ensure that the data is protected.
Especially for marketing teams, it’s necessary to align their processes and information regarding lead generation, marketing automation and email communication with the nDSG.
The nDSG is similar to the European general data protection regulation (GDPR or DSGVO), but not identical, so it is worth taking a closer look at the details. Its goal is to:
- protect the rights of individuals whose data is used
- more transparency for the processing of data
What data is affected by the nDSG?
Similar to the GDPR / DSGVO, the nDSG aims to regulate and protect the data of Swiss people.
For example, companies and organizations must sufficiently inform data subjects / individuals about the specific details of the data processing and document as well as retain the consent given for the use of the data.
At the same time, companies must actively inform data subjects about changes in the processing of their data, report incidents in a timely manner and document all processing activities.
The nDSG also emphasizes the principle of "privacy by default" and "privacy by design," which calls on developers to include data protection in the first steps of every development cycle, instead of adding it afterwards.
One highly regulated topic is sensitive personal data. This includes, for example, biometric data, medical findings, ethnicity, sexual orientation, etc. This data must be handled with special care and requires explicit consent and purposeful use.
Especially in the context of automated data processing strict rules apply here.
DISCLAIMER
Please note that we are experts in the field of digital marketing, but do not offer legal advice. We bring many years of experience in technical implementation and best practice from various industries.Rights of private individuals according to the new DSG:
- Right to information
- Right to withdraw consent
- Right to data erasure
- Right to data portability
- Right to object

Obligations of companies in the new DSG:
- Obligation to respond to private inquiries
- Obligation to keep records of all data processing activities
- Duty to assess (evaluate data protection measures)
- Obligation to protect privacy through "privacy by design" and "privacy by default"
Non-compliance can result in sanctions of up to CHF 250,000.

Which business areas are affected?
-
Data Collection
Review of existing data collection processes for:
- Manual collection
- Online collection (cookies, tracking, profiling)
- Upload of data sets
-
Data Processing
- Review of existing consent and subscription processes for: channels, opt-in, validity period, and privacy policy
- Review of existing processes for data cleansing and deletion
-
Data Transparency
- Review of existing information processes for data collection and deletion
- Review of the existing information process for stored user data
-
Data Deletion
- Review of existing processes for data deletion
- Review of interfaces
-
Data Loss
- Analysis of existing processes in case sensitive data gets lost
- Review of existing interfaces regarding data security
-
Third-Party Service Providers
- Collection of existing data protection contracts
- Identification of third-party systems
- Gap analysis for existing contracts
Our offer: nDSG packages for your Marketing Salesforce solution
If you are using or planning to implement Salesforce solutions (e.g., Salesforce Sales or Marketing Cloud or Marketing Cloud Account Engagement / Pardot), contact us to learn more about how we can help you comply with the nDSG.
Organizations must be prepared by September 1st, 2023.
Our offering is optimized to also meet all the requirements of the GDPR (General Data Protection Regulation).
We offer services based on your needs and have prepared various work packages to support you.
Note: We do not provide legal advice and can only adapt your technical / structural setup of your Salesforce Marketing Cloud and Marketing Cloud Account Engagement /Pardot solution to the nDSG.
- Deletion process (medium complexity):
- Definition and creation of an X-Cloud process for Salesforce (Sales and Marketing Cloud, Marketing Cloud Account Engagement / Pardot, etc.) to anonymize and delete customer data & user accounts.
- Creation of an unsubscribe process that updates data within the Salesforce system (no out-of-the-box function)
- Log-on/log-off process
- Authorization concept
- Information concept
- etc.
The exact work packages as well as the process will be defined in a workshop together with you to find the best solution for your company.
DIGITALL is a leading Salesforce partner since 2014 within the DACH region and has successfully completed projects for international multi-cloud rollouts across different industries.

Our Cyber Security-Services
Strengthen your company with the right solutions and assessments.
Read more