Is cold email legal in Switzerland? UWG and the nDSG, explained
The short answer
The GDPR is not Swiss law, and cold email into Switzerland is regulated twice. The Federal Act on Data Protection (nDSG), in force since 1 September 2023, governs the data behind the email. Article 3 paragraph 1 letter o of the UWG makes mass advertising by telecommunication technology unfair without prior consent, a correct sender and a simple, free opt-out. A narrow existing-customer exception exists, and the text has no B2B exemption. Enforcement runs through civil claims.
The most common mistake we see teams make before their first Swiss campaign is assuming a GDPR-compliant EU setup already covers Switzerland. It does not, because Switzerland answers the question with its own statute, not an EU regulation, and the statute that matters here sits in competition law rather than data-protection law.
Note: this is general information for orientation, not legal advice, and it is not a compliance opinion on your situation. Before you send anything into Switzerland, get a written view from a qualified Swiss lawyer or data-protection adviser.

On this page
- Switzerland is not an EU member, and not GDPR
- What does UWG Article 3 paragraph 1 letter o say?
- The separate data-protection layer: the nDSG
- GDPR vs Swiss law for a cold email into Switzerland
- Who enforces this, and what does it cost?
- Per-channel risk in Switzerland, ranked
- What lower-risk Swiss outbound looks like
- Does using an agency move the legal risk?
- How we handle Switzerland
- Frequently asked
Switzerland is not an EU member, and not GDPR
Every neighbouring-market page on this site that deals with Germany, Austria or the wider EU eventually points back to the GDPR. Switzerland breaks that pattern. It is not an EU or EEA member state, so the GDPR does not apply as Swiss law. The country runs its own Federal Act on Data Protection, revised and in force since 1 September 2023, often shortened to the nDSG or revFADP, and it structures the data-protection question differently from the GDPR rather than simply restating it. To see who actually runs campaigns into Switzerland, the DACH agency comparison has a section on it.
The GDPR can still reach a Swiss sender indirectly, under its own Article 3(2), if that sender is targeting people located in the EU rather than in Switzerland. That is a separate analysis from whether Swiss law governs a message sent to a Swiss recipient, which is the question this page answers.
What does UWG Article 3 paragraph 1 letter o say?
The rule that actually restricts unsolicited cold email in Switzerland is not the data-protection act. It is Article 3 of the UWG, the federal act against unfair competition, which lists conduct that counts as unfair. Paragraph 1 letter o covers electronic advertising directly:
A person acts unfairly who sends, or causes to be sent, mass advertising by telecommunication technology with no direct connection to content the recipient requested, and in doing so fails to first obtain the customer's consent, state the correct sender, or point to a simple and free way to decline.
The same provision then carves out one exception, built the same way as the existing-customer rules in neighbouring Germany and Austria: a business that receives a customer's contact details in the course of selling that customer goods, works or services, and points out the opt-out option at that point, does not act unfairly by later sending that same customer mass advertising for its own similar goods, works or services, without further consent.
Nothing in the wording limits letter o to consumers. The UWG's general scope, set out in Article 2, covers relations between competitors and between providers and purchasers as a whole, so a business recipient gets no separate carve-out from the mass-advertising rule.
The separate data-protection layer: the nDSG
Switzerland's data-protection regulator, the Federal Data Protection and Information Commissioner (FDPIC, EDOEB in German), states directly that the data-protection act applies whenever personal data such as an email address is obtained and used to send advertising. Rather than requiring you to select one of an enumerated list of lawful bases the way GDPR Article 6 does, Swiss data-protection law works from a set of principles: processing must be lawful, proportionate, carried out in good faith, and limited to its stated purpose, and it becomes unlawful where it causes a serious violation of personality rights that is not otherwise justified.
In practice this means a Swiss cold-email programme has to satisfy the nDSG's principles on how the contact data was sourced and used, and separately satisfy UWG Article 3 paragraph 1 letter o on whether the message itself may be sent at all. The two questions do not collapse into one the way some GDPR-only jurisdictions read them.
GDPR vs Swiss law for a cold email into Switzerland
The table compares the EU position with the Swiss one on the points senders ask about most.
| Question | EU: GDPR and national law | Switzerland |
|---|---|---|
| Which data law governs? | The GDPR | The Federal Act on Data Protection (nDSG or revFADP), in force since 1 September 2023. The GDPR is not Swiss law |
| How is lawful processing decided? | One of the enumerated lawful bases in Article 6, such as legitimate interest | Principles: lawful, proportionate, in good faith and limited to the stated purpose. Unlawful where it causes a serious violation of personality rights that is not justified |
| Which rule restricts the advertising email? | National law, such as UWG Section 7 in Germany | UWG Article 3 paragraph 1 letter o: prior consent, correct sender and a simple, free way to decline |
| Is there a B2B exemption? | Varies by country | None in the statutory text; the UWG scope covers relations between providers and purchasers generally |
| Is there an existing-customer exception? | Yes in several countries | Yes, narrow: contact details received in a sale, opt-out pointed out at that point, same business's similar goods or services |
| How is it enforced? | Data protection authorities and national courts | Civil claims under Articles 9 and 10 UWG; no dedicated spam fine ladder like Austria's |
| When does the GDPR still reach a Swiss sender? | Article 3(2), when the sender targets people located in the EU | A separate analysis from the Swiss rules for a Swiss recipient |
Compare the neighbouring rules in Germany and Austria, and the commercial side in B2B lead generation in Switzerland.
Who enforces this, and what does it cost?
Switzerland's enforcement path runs through the civil courts rather than a dedicated administrative fine for spam, which is a real difference from Austria's telecoms-regulator model.
- Civil claims under Articles 9 and 10 UWG. Anyone threatened or harmed in their customer relationships, credit, professional reputation or economic interests by unfair competition, including the recipient as a customer, can ask a court to prohibit a threatened breach, remove an existing one, or declare it unlawful, and can claim damages and disgorgement of profit. Trade and professional associations, national consumer-protection organisations, and in defined public-interest cases the Confederation, can also bring or join a claim.
- Criminal exposure. The FDPIC's own published guidance states plainly that a sender whose email breaches Article 3 UWG is guilty of unfair competition and must expect civil or criminal sanctions. We have not independently verified a specific penalty figure from the UWG's criminal provisions, so we are not quoting one here; treat any number you encounter elsewhere with caution until you have checked it against the current statute.
- No dedicated spam fine like Austria's. Unlike the Austrian TKG, Switzerland has not built a specific administrative-fine ladder for a letter o breach. The exposure runs through the civil and criminal routes above.
Per-channel risk in Switzerland, ranked
- Mass email without consent: the channel Article 3 paragraph 1 letter o is written to restrict, with no general business exemption.
- SMS and fax: covered by the same "telecommunication technology" wording as email, and restricted the same way.
- A single, personally researched email: letter o targets mass advertising sent with no connection to requested content; a genuinely individual, relevant message to one named person sits on different ground, though this is a matter of degree rather than a bright line, and volume is the thing regulators and courts notice.
- LinkedIn and business networks: not named in the UWG's telecommunication-technology wording, and commonly used as the lower-friction first touch into the Swiss market for that reason.
- Postal mail, referrals and events: outside Article 3 paragraph 1 letter o entirely, and still the standard way serious operators build a consented Swiss list.
What lower-risk Swiss outbound looks like
None of the following makes unsolicited mass email lawful in Switzerland. It keeps volume and risk down and matches the country's own market habits.
- Write in the recipient's language and register. Switzerland runs three main language regions; a German, French or Italian message that reads as locally written performs, and reads, differently from a translated one.
- Favour small, researched lists over mass sends. Letter o is built around "Massenwerbung", mass advertising; the tighter and more individually relevant a send is, the further it sits from the conduct the statute targets.
- State the correct sender in every message, exactly as the statute requires, with no disguised or third-party-branded sending domain.
- Give a simple, free opt-out, and treat any Swiss recipient's opt-out as final and permanent across all future campaigns.
- Document how each contact's data was sourced, so the nDSG's lawfulness and transparency principles have an answer if a recipient asks.
- Sequence through LinkedIn or a phone call first where the relationship is genuinely cold, and move to email once the contact has specifically agreed to it.
Does using an agency move the legal risk?
Not away from the client whose offer is being advertised. Articles 9 and 10 UWG give standing to sue over the advertising itself, and the business benefiting from it is a natural target alongside whoever sent the message. An agency that promises to absorb all of the compliance risk on your behalf is describing something Swiss unfair-competition law does not clearly support.
What a client can reasonably expect instead: named sending domains it owns, full visibility of the copy and list before anything sends, documented data sources under the nDSG's principles, and immediate, permanent opt-out handling.
How we handle Switzerland
Ripe Leads treats Switzerland as its own plan rather than an extension of a German-language DACH send, because the governing statute, the enforcement route and the data-protection framework are all different from Germany's or Austria's. We write natively per language region, keep lists small and researched rather than mass-sent, document where contact data came from, and honour every opt-out permanently. The final call on risk belongs to the client and their counsel, not to us. Our pricing and engagement terms are public and the first call is a working session.
Frequently asked
Is cold email legal in Switzerland?
Does GDPR apply in Switzerland?
What is the difference between the GDPR and the Swiss nDSG?
Does GDPR apply to cold email sent into Switzerland?
What does UWG Article 3 paragraph 1 letter o actually say?
What happens if you send cold email into Switzerland without consent?
Is there a B2B exemption for email marketing in Switzerland?
How can I prospect into Swiss companies without breaching the UWG?
Does using an agency shift the legal risk away from my company?
Want the Swiss market handled properly?
We plan the channel mix per language region, keep lists small and researched, document our data sources and honour every opt-out. You get the accurate picture of the risk, then decide.
Book a strategy call Or get a free target list first