Privacy notice under the revised Federal Act on Data Protection (Datenschutzgesetz "DSG" 2023, in force since 1 September 2023, internationally referred to as the revFADP/nLPD) — the DSG is lighter than the GDPR for small businesses but imposes fines of up to CHF 250,000 directly on the responsible individual (not the company); a business also serving EU customers online needs a parallel GDPR layer.
⚠️ Это шаблон-болванка, а не юридическая консультация: перед использованием проверьте текст у юриста и адаптируйте под своё законодательство и конкретную ситуацию.
У этого шаблона опциональных разделов нет: текст одинаковый для всех. Поля показаны подписями: на сайте шаблон только для чтения, значения подставляются в системе.
PRIVACY NOTICE (DATENSCHUTZERKLÄRUNG)
Business name (responsible party), Business address Effective date: Effective date
This notice explains how Business name (responsible party) (the "Company", the responsible party / data controller) collects, uses and protects personal data, in accordance with the revised Swiss Federal Act on Data Protection (Datenschutzgesetz "DSG"), in force since 1 September 2023 — internationally also referred to as the revFADP / nLPD.
1. RESPONSIBLE PARTY 1.1. Business name (responsible party) is responsible for the processing described in this notice (art. 5 let. j DSG).
2. WHAT DATA WE COLLECT AND WHY 2.1. What data is collected and why
3. PURPOSES AND INFORMATION DUTY 3.1. Purposes of processing 3.2. Under articles 19 et seq. DSG, we must inform data subjects, in an appropriate and adequate form, at the time personal data is collected — this notice fulfils that duty.
4. RECIPIENTS AND TRANSFERS ABROAD 4.1. Recipients & transfers abroad 4.2. Transfers of personal data outside Switzerland require either a country with an adequate level of protection (per the FDPIC's list) or appropriate safeguards (e.g. standard contractual clauses).
5. RETENTION 5.1. Retention period
6. YOUR RIGHTS 6.1. Data subject rights 6.2. You may also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC / EDÖB), edoeb.admin.ch, if you believe your data has been mishandled.
7. GDPR (EUROPEAN UNION) 7.1. GDPR applicability 7.2. EU representative (if applicable, art. 27 GDPR): EU representative, if applicable
8. DSG VS. GDPR — WHAT IS DIFFERENT 8.1. Unlike the GDPR, the DSG does not impose turnover-based fines on the company; instead, individual liability of up to CHF 250,000 can be imposed directly on the responsible manager/officer for intentional violations. A register of processing activities (Verzeichnis der Bearbeitungstätigkeiten) is mandatory only for organisations with 250 or more employees, unless the processing carries a higher risk. Data-breach notification to the FDPIC must happen "as quickly as possible" (so rasch als möglich) rather than the GDPR's strict 72-hour deadline, but only where the breach carries a high risk to the data subject.
9. CONTACT US 9.1. Questions about this notice, or requests to exercise your rights, may be sent to Privacy contact email.
⚠️ If CCTV, guest Wi-Fi logging, or staff monitoring is used, see the separate Video Surveillance Notice template — surveillance of employees' work performance/behaviour is prohibited by art. 26 ArGV 3 and cameras may only serve a genuine safety/security purpose.
— — — ⚠️ This is a boilerplate template, not legal advice. Swiss employment, consumer-protection, data-protection, and food-safety law (Code of Obligations "OR"/"CO", L-GAV/CCNT für das Gastgewerbe, Arbeitsgesetz "ArG"/ArGV 1, Datenschutzgesetz "DSG" 2023, LMG/LGV) includes significant cantonal variation (minimum wages, Meldeschein/guest-registration forms, Kurtaxe rates, Spesenreglement approval, hygiene guidance, alcohol age limits) and the L-GAV minimum-wage figures are re-indexed every year — have this document reviewed and adapted by a Swiss employment/legal advisor and verified against your canton before use. Where a German-, French- or Italian-language version of this document is also used, that version prevails in case of conflict.
Поля выключенных разделов приглушены — их не спрашивают.
e.g. bookings, orders, CCTV, guest Wi-Fi, loyalty/marketing data
Processors, and any transfer outside Switzerland/EEA
Access, rectification, erasure, objection, and the right to complain to the FDPIC/EDÖB
Required only if GDPR applies and the business has no EU establishment
2 из 11 полей берутся из карточки компании, сотрудника или контрагента, опросник можно надиктовать ИИ, а готовый документ выдаётся с номером, PDF и подтверждением ознакомления.