Minimize Data Loss from Consent Banners

Opt-In or Opt-Out for Tracking in Switzerland?
Data loss comes from the opt-in, not from the cookie banner. Measurement that waits for active consent drops everyone who refuses or clicks away: in practice, 40% to 60% of all measurement data. Under opt-out, measurement runs, and anyone who objects can refuse. Loss stays in the single digits.
For Swiss visitors, opt-out is therefore the goal. Swiss law provides for it — the only live dispute is whether it still suffices.
Two schools of thought on cookie rules
Whether opt-out covers standard tracking depends on the legal basis. Two readings sit side by side. Both are defensible.
The TCA school rests on Art. 45c let. b of the TCA (Telecommunications Act; FMG). The provision requires information about processing and purpose, plus notice that processing can be refused. Prior opt-in is not required.
The FDPIC school rests on the cookie guide of the FDPIC (Federal Data Protection and Information Commissioner). The guide reads the FADP (Federal Act on Data Protection) on top of the TCA and tiers the requirements by risk: information, opt-out, or opt-in.
The difference: the TCA position treats Art. 45c as a special rule for setting and reading data on the end device. The FDPIC position does not treat the TCA as exhaustive and, depending on the risk tier, demands additional measures under the FADP. Legal departments often argue only from the second reading.
The Swiss cookie rule has stood since April 1, 2007 in Art. 45c let. b TCA:
Processing of data on external equipment by means of transmission using telecommunications techniques is permitted only […] if users are informed about the processing and its purpose and are informed that they may refuse to allow processing.
Three points carry the TCA position:
- Special rule. The provision covers setting and reading data on the end device. Required: information and a way to refuse — not prior opt-in.
- No EU Cookie Directive. Switzerland is neither an EU nor an EEA (European Economic Area) member and did not adopt Directive 2009/136/EC with the revised FADP.
- No change through the FADP. Art. 6 para. 7 FADP requires express consent only for particularly sensitive personal data and for high-risk profiling. Standard reach measurement falls under neither.
In Switzerland, consent is the exception, not the rule
A system difference sits underneath this, and many legal teams underweight it. The GDPR (General Data Protection Regulation) prohibits processing of personal data in principle and permits it only exceptionally — consent is one of those legal bases. The FADP has no such prohibition: processing is lawful as long as it does not unlawfully infringe personality. Consent only justifies such an infringement (Art. 30 and 31 FADP).
For standard tracking, the overriding private interest under Art. 31 para. 2 FADP applies instead. Economic evaluation of a company's own web offering is a recognized interest — the FDPIC also relies on it for the medium risk tier.
The common claim that pseudonymous marketing IDs are anonymous does not hold. A cookie identifier is generally treated as identifiable, and Art. 45c TCA applies whether or not the data is personal. That argument loses the conversation.
What the FDPIC requires: the tier model
The second school rests on the FDPIC cookie guide of January 22, 2025, updated October 6, 2025. The guide is not legally binding and leading Swiss data protection lawyers criticize it as too close to the GDPR.
It is also often misstated: the FDPIC does not require opt-in everywhere. It classifies by risk, and Annex A even uses a points model.
| Tier | In scope | Requirement |
|---|---|---|
| 1 – Technically necessary | Session, login, shopping cart, language preference, captcha, storing the cookie choice itself. | Information in the privacy policy only. |
| 2 – Ordinary profiling | First-party reach and conversion measurement with no disclosure to third parties, convenience features, offers for own products. | Overriding interest plus an effective right to object (opt-out). |
| 3 – High risk | Cross-site tracking by embedded third parties, paid data access for third parties, location movement profiles, particularly sensitive data. | Consent before loading (opt-in). |
The core point: the duty to obtain consent does not arise from measuring. It arises from passing data to embedded third parties for their own purposes. Keep the setup free of that, and even the FDPIC accepts opt-out.
The TCA still applies — a guide does not repeal a statute
The FDPIC does not read Art. 45c TCA as exhaustive; it places the FADP alongside it. That is an interpretation, nothing more. To date there is neither a statutory amendment nor a Federal Supreme Court judgment that strips the TCA of force or establishes an opt-in duty.
The same holds for the appeal to Art. 7 para. 3 FADP (privacy by default). Data protection expert David Rosenthal argues the opposite: the provision applies only "unless the data subject specifies otherwise" — it presupposes settings and does not create a duty to introduce a banner. If legal argues from this provision, that is the reply.
Two points in the guide still matter. A mere reference to browser settings no longer counts as a way to object under the FDPIC. And continued browsing is expressly not consent.
Implementing opt-out cleanly
For opt-out to hold, the setup must stay in Tier 2. Two points decide it.
Measure in-house instead of passing data to third parties
High risk is triggered by embedding third parties that sit on many websites and collect data for their own purposes. A pure client-side setup does exactly that — and the FDPIC then assumes joint controllership of the site operator and the third party.
With Server-Side Tracking, collection runs on the first-party domain. Measurement depth and determinism remain. The legal classification shifts: measurement serves own performance control instead of giving third parties uncontrolled access to visitor data. What goes back to ad platforms stays controllable and documentable. Legal needs exactly that documentation for the balancing of interests.
A right to object that meets the requirements
The FDPIC sets four requirements, and a sentence in the privacy policy meets none of them: the opt-out must be prominent, technically effective (one click actually stops processing), granular by category, and withdrawable at any time.
In practice, that means a consent tool with a preference center. The decisive difference from an opt-in banner remains: tracking starts on page load; only someone who wants to object has to act. Measurement coverage stays near-complete.
Three implementation variants compared
| Criterion | A: Footer notice | B: Opt-out with preference center | C: Opt-in banner |
|---|---|---|---|
| Legal basis | Art. 45c let. b TCA. | Art. 45c TCA plus overriding interest (Art. 31 para. 2 FADP). | Art. 6 para. 6 and 7 FADP, Art. 6 and 7 GDPR. |
| Default | Tracking starts on page load. | Tracking starts on page load; objection takes effect at any time. | Necessary cookies only until consent. |
| Control | Link in the privacy policy. | Prominent, granular widget with withdrawal. | Banner with equally prominent "Accept" and "Reject". |
| Measurement coverage | Near-complete. | Near-complete. | 40% to 60% data loss. |
| FDPIC position | Does not meet FDPIC requirements. | Sufficient for Tier 2, not for Tier 3. | Meets all tiers. |
| Residual risk | Fine up to CHF 5,000 under Art. 53 TCA, FDPIC objection. | Objection if the FDPIC classifies the setup as Tier 3. | No supervisory risk. |
For most Swiss websites, legal certainty and measurement quality meet in variant B.
What Google requires by contract
Beside the statute sits the contract layer. Google's EU User Consent Policy has applied to Switzerland since July 31, 2024 — but only for personalized advertising to users in Switzerland, not for cookies as such. Google expressly does not require Consent Mode consent signals for Switzerland. A certified CMP (consent management platform) is mandatory only for publishers with their own ad inventory.
For Google Ads lead generation without own ad inventory, the effect stays limited.
A realistic view of the risk
Fines. The realistic exposure is Art. 53 TCA: intentional or negligent breaches of Art. 45c TCA cost up to CHF 5,000, directed at the responsible natural person. Fines under Art. 60 et seq. FADP up to CHF 250,000 require intent — for example, knowingly ignoring a final FDPIC order (Art. 63 FADP). Only if the responsible person can be identified only with disproportionate effort can the company be fined up to CHF 50,000 under Art. 64 para. 2 FADP. By comparison: under the GDPR, fines can reach 4% of worldwide annual turnover.
Supervision. The FDPIC does not impose fines; it issues orders with a remediation deadline. Under Art. 49 para. 2 FADP, it may refrain from an investigation for minor violations — it can open one of its own motion or on a complaint. After an awareness campaign, it intends to supervise in line with the guide. The likely sequence: objection, order, remediation. The cost is the work, not a payment.
In practice. Investigations against the company almost never happen. The FDPIC lacks the resources to audit websites of its own motion — as a rule, a report or complaint from a data subject comes first. Even then, a criminal proceeding under Art. 53 TCA targets the responsible natural person, not the company.
Arguments to convince legal
These problems and remedies can be shown to a Swiss legal team. The goal is to introduce variant B: opt-out with a preference center for website visitors from Switzerland.
-
Systematic data loss of 40% to 60%: An opt-in banner costs 40% to 60% of all measurement data in practice. That is not a worst-case scenario. It is the empirical standard.
-
A skewed dataset: People who refuse behave differently (different age groups, different purchase intent) and systematically distort the collected data.
-
Avoidable cost: Data-driven control of the ad budget becomes impossible. Budget cannot be shifted to the campaigns and keywords that measurably produce customers and revenue. Cost per lead can run 20% to 30% higher.
-
No opt-in mandate, including under the FDPIC: We collect via Server-Side Tracking on our own first-party domain and measure solely for our own performance control — no cross-site tracking by embedded third parties, no paid data access for third parties. The Tier 3 criteria are therefore not met, and the setup sits in the FDPIC's medium risk tier. An effective right to object suffices there, supported by the balancing of interests under Art. 31 para. 2 FADP. What goes back to ad platforms, we determine ourselves and can document.
-
Hybrid solution via geo-routing: Opt-in is served automatically in EU countries:
- EU visitors: opt-in banner (Germany § 25 TDDDG, Austria § 165 para. 3 TKG 2021).
- Swiss visitors: opt-out control under Art. 45c TCA; no banner required.
-
Over-compliance does not justify revenue loss: The FDPIC does not impose fines; where needed, it requires remediation. Its guide is not legally binding. Realistic maximum fine: CHF 5,000 under Art. 53 TCA. Negligible legal risk sits against guaranteed, recurring revenue loss.
Sources and legal bases
- Fedlex – Telecommunications Act (TCA), Art. 45c and Art. 53: Processing of data on external equipment and the related criminal provision.
- Fedlex – Federal Act on Data Protection (FADP, SR 235.1): Art. 6 principles, Art. 7 privacy by default, Art. 30 and 31 grounds of justification, Art. 49 supervision, Art. 60 et seq. criminal provisions.
- FDPIC – Guide on data processing by means of cookies and similar technologies: Version of January 22, 2025 with the supplement of October 6, 2025. Reflects the supervisory authority's view and is not legally binding.
- Martin Steiger on cyon: Cookie banners in Switzerland – who actually needs them?: The legal position from the TCA school, including Google's EU User Consent Policy.
- HÄRTING Rechtsanwälte: New Swiss FDPIC cookie guidelines: Classification of the guide and the changes in version 1.1.
- Swiss Infosec: Cookie consent banners – the current legal situation: On the extraterritorial application of the GDPR to Swiss companies.
- Datenrecht.ch – Walder Wyss: Legal analysis of the guide and FDPIC practice.
Written by
Dashflow Team

