The new data protection act (LPD) in Switzerland comes into force on 1 September 2025. This reform considerably strengthens the protection of Swiss residents’ personal data and aligns with the European GDPR you have surely heard of. But what does this Swiss LPD mean for your website?
The 4 key obligations of the Swiss LPD for your website
Here is what you absolutely need to know if you run a website:
- You must obtain users’ consent before collecting their personal data. Under the new law, this covers names, emails, IP addresses and payment information. You must clearly explain why you are collecting this data and how you intend to use it.
For instance, if you collect emails for your newsletter, say so clearly! Also specify how your subscribers can unsubscribe. If you log IP addresses, explain why you track activity on your site. Transparency is your best ally in the face of these new requirements!
- You must inform users of their rights over their data. Under the Swiss Data Protection Act, these rights include access, rectification, erasure, restriction of processing, portability and objection to processing. Offer a simple way to exercise these rights.
A good practice? Create a dedicated page where your users can view, change or delete their data. At Smart Impact, we always set up an easily accessible form so users can exercise their rights in a few clicks.
Security and documentation: obligations you cannot ignore
- You must take the security of your users’ personal data seriously. The new legislation requires strong passwords, encryption of sensitive data and adequate physical protection.
In practical terms? Protect your site and your client database with complex passwords. Encrypt sensitive data such as bank card numbers. Do not forget physical security measures such as cameras or alarm systems to protect your premises and servers.
- You must keep a detailed record of your processing activities. The law requires this document to specify what data you collect, why you process it, who has access to it and how long you keep it.
For instance, keep the list of people with access to your client database up to date. Document every collection or processing of personal data. I know, it sounds tedious, but it is essential for compliance!

The concrete benefits of the new Swiss LPD
Despite the constraints, this new law brings real benefits:
- It strengthens users' rights. With this reform, your clients now have more control over their personal data. They can access, correct, delete, restrict the processing of, transfer or object to the processing of their information. That is an excellent thing for digital trust!
- It sets deterrent penalties. Companies that fail to comply face fines of up to 20 million Swiss francs or 4% of worldwide turnover. Those penalties are a strong incentive to respect personal data.
- It enhances Switzerland's image. The legislation shows that the country takes data protection seriously. A genuine asset for Swiss companies working with the European Union or other countries with similar laws.
How do you comply with the new legislation?
I am not going to lie to you: the penalties for non-compliance with the Swiss LPD are frightening! Up to CHF 20 million or 4% of global revenue. Suffice to say it is worth preparing seriously.
Here is my advice to help you get compliant:
- Analyse your current data protection practices in depth
- Update your privacy policies and procedures in line with the new requirements
- Raise awareness and train your teams on these regulatory changes
- Invest in compliant security measures
- Create and keep your record of processing activities up to date
By following these recommendations, you not only protect your users’ data, but you also reduce your exposure to the heavy penalties provided for by law. Everyone wins!
Practical solutions for WordPress and PrestaShop
Good news for WordPress and PrestaShop users! Many plugins can make your compliance with the new LPD easier. These tools help you collect consent, manage user rights and protect their personal data effectively.
Here are two particularly effective plugins that we recommend:
- GDPR Cookie Consent for WordPress – simple to configure and compatible with Swiss requirements
- GDPR for PrestaShop – an official solution that can be adapted to the Swiss context
These plugins are easy to install and let you comply quickly with the requirements of the new legislation. Within a few hours, you can already have the essentials in place!
Need help with the new LPD? We are here!
Feeling overwhelmed by all these new requirements? No need to worry! At Smart Impact, we support companies every day in their compliance with the Swiss LPD. Our team knows the subtleties of this reform inside out and can propose solutions suited to your specific situation.
Do not wait until the last minute to prepare for this important deadline. Contact us today to discuss your needs and build a tailor-made compliance strategy together. Data protection is not only a legal obligation: it is also an argument for trust with your customers!




