Switzerland's revFADP: Cookie Consent & Privacy Rules for App Publishers
What revFADP Is & Why App Publishers Should Care
Switzerland is not in the EU, so the GDPR does not apply there directly. Instead the country runs its own regime: the revised Federal Act on Data Protection, or revFADP (in German, revDSG), fully in force since September 1, 2023. The revision pulled Swiss law much closer to GDPR while keeping some distinctly Swiss quirks.
For mobile app and game publishers, Switzerland matters more than its size suggests: a wealthy market with high ad eCPMs and a meaningful slice of many install bases. Treating it as "basically GDPR" — or ignoring it — risks both compliance gaps and lost monetization.
How revFADP Differs From GDPR
The two laws rhyme, but they are not identical. Knowing the differences keeps you from over- or under-engineering your consent flow.
- Opt-out as the default baseline. Unlike GDPR's strict opt-in for most processing, revFADP generally permits processing unless the law restricts it — transparency is the central duty rather than universal prior consent.
- Narrower consent triggers. Explicit consent is required mainly for high-risk profiling and sensitive data (health, religion, biometrics, genetic data, and similar).
- No mandatory DPO, though Swiss law encourages appointing a data-protection adviser.
- The supervisory body is the FDPIC (Federal Data Protection and Information Commissioner), not an EU-style DPA network.
Consent & Transparency Requirements
The heart of revFADP is informed transparency. Even where consent is not strictly mandatory, you must tell users clearly what you collect and why. In practice, ad-funded apps still need a genuine consent mechanism because the advertising supply chain — Google, IAB vendors, measurement partners — demands signals to operate. Publishers should provide:
- A clear privacy notice describing data categories, purposes, retention, and cross-border transfers.
- A consent prompt before non-essential tracking, advertising IDs, or profiling SDKs fire.
- Granular controls so users can accept or reject advertising and analytics separately.
- Disclosure of automated decision-making and high-risk profiling where it occurs.
Because Google requires a certified CMP to serve personalized ads to users in the EEA, UK, and Switzerland, a compliant consent layer is effectively a monetization requirement. Google Consent Mode v2 signals (ad_storage, ad_user_data, ad_personalization) should reflect Swiss users' choices just as they do for EU users.
Extraterritorial Scope
Like GDPR, revFADP reaches beyond Swiss borders. It applies to any processing that has an effect in Switzerland, regardless of where your company is incorporated or where your servers sit. A game studio in Singapore, Turkey, or the US with Swiss players is squarely in scope.
Crucially, foreign businesses without a Swiss establishment may have to appoint a representative in Switzerland if they process Swiss residents' data on a large scale, regularly, while offering goods or services. Many ad-supported apps cross that threshold without realizing it.
Penalties & Personal Liability
Here is the surprise that catches many publishers off guard: revFADP penalties are not corporate fines — they target individuals. Responsible persons (often executives or whoever made the decision) can be fined up to CHF 250,000 for breaches such as failing to provide required information, violating transparency or disclosure duties, ignoring minimum data-security requirements, or failing to appoint a representative.
Because liability is personal and criminal in nature, "we'll pay the fine if it comes" is a far weaker strategy than under GDPR. It creates direct exposure for founders and managers — raising the stakes for getting consent and disclosure right the first time.
A Practical Checklist for Publishers Serving Swiss Users
- Detect Swiss traffic and apply a GDPR-grade consent experience — don't carve Switzerland out of your EU flow.
- Publish a transparent privacy notice covering purposes, retention, and cross-border transfers.
- Gate advertising and analytics SDKs behind consent and wire choices into Consent Mode v2.
- Assess whether you need a Swiss representative and a record of processing activities.
- Keep audit logs of consent to demonstrate compliance to the FDPIC.
This is where a multi-region CMP earns its keep. FlexyConsent is a Google-certified Consent Management Platform supporting IAB TCF 2.3 and Consent Mode v2, and it handles Swiss and EU coverage from a single integration — detecting region, showing the right notice, capturing granular choices, and storing consent records you can produce on demand. You stay compliant across revFADP and GDPR without separate flows or lost ad revenue.
This article is for general information and is not legal advice; consult qualified counsel for your specific situation.
Key Takeaways
- revFADP has applied since September 2023 and reaches any app whose processing affects Swiss users, wherever the publisher is based.
- It leans on transparency rather than universal opt-in, but ad-funded apps still need a real consent layer to monetize.
- Penalties are personal — individuals face fines up to CHF 250,000 — so compliance is a leadership-level concern.
- A multi-region CMP like FlexyConsent covers Swiss and EU rules together via TCF 2.3 and Consent Mode v2.