Switzerland's revFADP: Cookie Consent & Privacy Rules for App Publishers

What revFADP Is & Why App Publishers Should Care

Switzerland is not in the EU, so the GDPR does not apply there directly. Instead the country runs its own regime: the revised Federal Act on Data Protection, or revFADP (in German, revDSG), fully in force since September 1, 2023. The revision pulled Swiss law much closer to GDPR while keeping some distinctly Swiss quirks.

For mobile app and game publishers, Switzerland matters more than its size suggests: a wealthy market with high ad eCPMs and a meaningful slice of many install bases. Treating it as "basically GDPR" — or ignoring it — risks both compliance gaps and lost monetization.

How revFADP Differs From GDPR

The two laws rhyme, but they are not identical. Knowing the differences keeps you from over- or under-engineering your consent flow.

Consent & Transparency Requirements

The heart of revFADP is informed transparency. Even where consent is not strictly mandatory, you must tell users clearly what you collect and why. In practice, ad-funded apps still need a genuine consent mechanism because the advertising supply chain — Google, IAB vendors, measurement partners — demands signals to operate. Publishers should provide:

Because Google requires a certified CMP to serve personalized ads to users in the EEA, UK, and Switzerland, a compliant consent layer is effectively a monetization requirement. Google Consent Mode v2 signals (ad_storage, ad_user_data, ad_personalization) should reflect Swiss users' choices just as they do for EU users.

Extraterritorial Scope

Like GDPR, revFADP reaches beyond Swiss borders. It applies to any processing that has an effect in Switzerland, regardless of where your company is incorporated or where your servers sit. A game studio in Singapore, Turkey, or the US with Swiss players is squarely in scope.

Crucially, foreign businesses without a Swiss establishment may have to appoint a representative in Switzerland if they process Swiss residents' data on a large scale, regularly, while offering goods or services. Many ad-supported apps cross that threshold without realizing it.

Penalties & Personal Liability

Here is the surprise that catches many publishers off guard: revFADP penalties are not corporate fines — they target individuals. Responsible persons (often executives or whoever made the decision) can be fined up to CHF 250,000 for breaches such as failing to provide required information, violating transparency or disclosure duties, ignoring minimum data-security requirements, or failing to appoint a representative.

Because liability is personal and criminal in nature, "we'll pay the fine if it comes" is a far weaker strategy than under GDPR. It creates direct exposure for founders and managers — raising the stakes for getting consent and disclosure right the first time.

A Practical Checklist for Publishers Serving Swiss Users

This is where a multi-region CMP earns its keep. FlexyConsent is a Google-certified Consent Management Platform supporting IAB TCF 2.3 and Consent Mode v2, and it handles Swiss and EU coverage from a single integration — detecting region, showing the right notice, capturing granular choices, and storing consent records you can produce on demand. You stay compliant across revFADP and GDPR without separate flows or lost ad revenue.

This article is for general information and is not legal advice; consult qualified counsel for your specific situation.

Key Takeaways

← Blog Read All →