Compliance

Is cold email legal in Switzerland? UWG and the nDSG, explained

Published 26 September 2026 · Updated October 6, 2026 · 7 min read · By Ripe Leads

The short answer

The GDPR is not Swiss law, and cold email into Switzerland is regulated twice. The Federal Act on Data Protection (nDSG), in force since 1 September 2023, governs the data behind the email. Article 3 paragraph 1 letter o of the UWG makes mass advertising by telecommunication technology unfair without prior consent, a correct sender and a simple, free opt-out. A narrow existing-customer exception exists, and the text has no B2B exemption. Enforcement runs through civil claims.

The most common mistake we see teams make before their first Swiss campaign is assuming a GDPR-compliant EU setup already covers Switzerland. It does not, because Switzerland answers the question with its own statute, not an EU regulation, and the statute that matters here sits in competition law rather than data-protection law.

Note: this is general information for orientation, not legal advice, and it is not a compliance opinion on your situation. Before you send anything into Switzerland, get a written view from a qualified Swiss lawyer or data-protection adviser.

Is cold email legal in Switzerland? UWG and the nDSG, explained
On this page
  1. Switzerland is not an EU member, and not GDPR
  2. What does UWG Article 3 paragraph 1 letter o say?
  3. The separate data-protection layer: the nDSG
  4. GDPR vs Swiss law for a cold email into Switzerland
  5. Who enforces this, and what does it cost?
  6. Per-channel risk in Switzerland, ranked
  7. What lower-risk Swiss outbound looks like
  8. Does using an agency move the legal risk?
  9. How we handle Switzerland
  10. Frequently asked

Switzerland is not an EU member, and not GDPR

Every neighbouring-market page on this site that deals with Germany, Austria or the wider EU eventually points back to the GDPR. Switzerland breaks that pattern. It is not an EU or EEA member state, so the GDPR does not apply as Swiss law. The country runs its own Federal Act on Data Protection, revised and in force since 1 September 2023, often shortened to the nDSG or revFADP, and it structures the data-protection question differently from the GDPR rather than simply restating it. To see who actually runs campaigns into Switzerland, the DACH agency comparison has a section on it.

The GDPR can still reach a Swiss sender indirectly, under its own Article 3(2), if that sender is targeting people located in the EU rather than in Switzerland. That is a separate analysis from whether Swiss law governs a message sent to a Swiss recipient, which is the question this page answers.

What does UWG Article 3 paragraph 1 letter o say?

The rule that actually restricts unsolicited cold email in Switzerland is not the data-protection act. It is Article 3 of the UWG, the federal act against unfair competition, which lists conduct that counts as unfair. Paragraph 1 letter o covers electronic advertising directly:

A person acts unfairly who sends, or causes to be sent, mass advertising by telecommunication technology with no direct connection to content the recipient requested, and in doing so fails to first obtain the customer's consent, state the correct sender, or point to a simple and free way to decline.

The same provision then carves out one exception, built the same way as the existing-customer rules in neighbouring Germany and Austria: a business that receives a customer's contact details in the course of selling that customer goods, works or services, and points out the opt-out option at that point, does not act unfairly by later sending that same customer mass advertising for its own similar goods, works or services, without further consent.

Nothing in the wording limits letter o to consumers. The UWG's general scope, set out in Article 2, covers relations between competitors and between providers and purchasers as a whole, so a business recipient gets no separate carve-out from the mass-advertising rule.

The separate data-protection layer: the nDSG

Switzerland's data-protection regulator, the Federal Data Protection and Information Commissioner (FDPIC, EDOEB in German), states directly that the data-protection act applies whenever personal data such as an email address is obtained and used to send advertising. Rather than requiring you to select one of an enumerated list of lawful bases the way GDPR Article 6 does, Swiss data-protection law works from a set of principles: processing must be lawful, proportionate, carried out in good faith, and limited to its stated purpose, and it becomes unlawful where it causes a serious violation of personality rights that is not otherwise justified.

In practice this means a Swiss cold-email programme has to satisfy the nDSG's principles on how the contact data was sourced and used, and separately satisfy UWG Article 3 paragraph 1 letter o on whether the message itself may be sent at all. The two questions do not collapse into one the way some GDPR-only jurisdictions read them.

Two Swiss statutes, one messageThe nDSG governs the data behind the email. UWG Article 3(1)(o) governs the act of sending it. A Swiss campaign has to satisfy both, separately.

GDPR vs Swiss law for a cold email into Switzerland

The table compares the EU position with the Swiss one on the points senders ask about most.

QuestionEU: GDPR and national lawSwitzerland
Which data law governs?The GDPRThe Federal Act on Data Protection (nDSG or revFADP), in force since 1 September 2023. The GDPR is not Swiss law
How is lawful processing decided?One of the enumerated lawful bases in Article 6, such as legitimate interestPrinciples: lawful, proportionate, in good faith and limited to the stated purpose. Unlawful where it causes a serious violation of personality rights that is not justified
Which rule restricts the advertising email?National law, such as UWG Section 7 in GermanyUWG Article 3 paragraph 1 letter o: prior consent, correct sender and a simple, free way to decline
Is there a B2B exemption?Varies by countryNone in the statutory text; the UWG scope covers relations between providers and purchasers generally
Is there an existing-customer exception?Yes in several countriesYes, narrow: contact details received in a sale, opt-out pointed out at that point, same business's similar goods or services
How is it enforced?Data protection authorities and national courtsCivil claims under Articles 9 and 10 UWG; no dedicated spam fine ladder like Austria's
When does the GDPR still reach a Swiss sender?Article 3(2), when the sender targets people located in the EUA separate analysis from the Swiss rules for a Swiss recipient

Compare the neighbouring rules in Germany and Austria, and the commercial side in B2B lead generation in Switzerland.

Who enforces this, and what does it cost?

Switzerland's enforcement path runs through the civil courts rather than a dedicated administrative fine for spam, which is a real difference from Austria's telecoms-regulator model.

Per-channel risk in Switzerland, ranked

What lower-risk Swiss outbound looks like

None of the following makes unsolicited mass email lawful in Switzerland. It keeps volume and risk down and matches the country's own market habits.

Not away from the client whose offer is being advertised. Articles 9 and 10 UWG give standing to sue over the advertising itself, and the business benefiting from it is a natural target alongside whoever sent the message. An agency that promises to absorb all of the compliance risk on your behalf is describing something Swiss unfair-competition law does not clearly support.

What a client can reasonably expect instead: named sending domains it owns, full visibility of the copy and list before anything sends, documented data sources under the nDSG's principles, and immediate, permanent opt-out handling.

How we handle Switzerland

Ripe Leads treats Switzerland as its own plan rather than an extension of a German-language DACH send, because the governing statute, the enforcement route and the data-protection framework are all different from Germany's or Austria's. We write natively per language region, keep lists small and researched rather than mass-sent, document where contact data came from, and honour every opt-out permanently. The final call on risk belongs to the client and their counsel, not to us. Our pricing and engagement terms are public and the first call is a working session.

Frequently asked

Is cold email legal in Switzerland?
Not without consent, in most cases, and Swiss law does not run on the GDPR to answer that question. Article 3 paragraph 1 letter o of the Bundesgesetz gegen den unlauteren Wettbewerb (UWG), Switzerland's unfair-competition act, treats mass advertising sent by telecommunication technology as unfair unless the sender first obtained the recipient's consent, states the correct sender, and offers a simple, free way to decline. A narrow existing-customer exception applies. Outside it, unsolicited B2B cold email into Switzerland carries real exposure under the UWG, separate from the country's own data-protection act. This is general information, not legal advice.
Does GDPR apply in Switzerland?
Not as Swiss law. Switzerland is not an EU or EEA member, so the GDPR does not govern a message to a Swiss recipient. The revised Federal Act on Data Protection, in force since 1 September 2023, governs the personal data, and UWG Article 3 paragraph 1 letter o governs the sending. The GDPR can still apply under its Article 3(2) if you target people located in the EU.
What is the difference between the GDPR and the Swiss nDSG?
The GDPR asks you to pick an enumerated lawful basis under Article 6. The nDSG works from principles: processing must be lawful, proportionate, carried out in good faith and limited to its purpose, and it becomes unlawful where it causes a serious violation of personality rights that is not justified. Neither one clears the separate UWG rule on sending the email.
Does GDPR apply to cold email sent into Switzerland?
Not automatically. Switzerland is not an EU or EEA member, so the GDPR is not Swiss law. Its own Federal Act on Data Protection, revised and in force since 1 September 2023, governs the collection and use of personal data such as email addresses on Swiss soil. The GDPR can still apply separately and extraterritorially under its own Article 3(2) if a sender is targeting people located in the EU, but that is a different question from whether Swiss law applies to a Swiss recipient.
What does UWG Article 3 paragraph 1 letter o actually say?
It provides that a person acts unfairly if they send, or cause to be sent, mass advertising by telecommunication technology with no direct connection to content the recipient requested, and fail to first obtain the customer's consent, state the correct sender, or point to a simple and free way to decline. It then carves out one exception: a business that receives a customer's contact details in the course of selling that customer goods or services, and points out the opt-out option, does not act unfairly by sending that same customer mass advertising for its own similar goods or services without further consent.
What happens if you send cold email into Switzerland without consent?
The Federal Data Protection and Information Commissioner, the FDPIC, states plainly that a sender whose email breaches UWG Article 3 is guilty of unfair competition and must expect civil or criminal consequences. On the civil side, Articles 9 and 10 UWG let a harmed customer, a competitor, a trade association or, in defined public-interest cases, the Confederation itself seek an injunction, a declaration of unlawfulness, and damages. We have not found a published, verified figure for a typical fine or settlement, so none is stated here; treat any number you see elsewhere with caution.
Is there a B2B exemption for email marketing in Switzerland?
No express one. Article 3 paragraph 1 letter o is written around Kunden, customers, and the UWG's own scope covers relations between competitors and between providers and purchasers generally, without limiting the mass-advertising rule to consumers. A business email address gets no separate carve-out in the statutory text.
How can I prospect into Swiss companies without breaching the UWG?
Treat the data-protection question and the unfair-competition question as separate, because Swiss law does not merge them the way GDPR analysis sometimes does. On the data side, the Federal Act on Data Protection asks you to process personal data lawfully, proportionately and transparently rather than checking it against an enumerated legal-basis list. That does not clear UWG Article 3 paragraph 1 letter o, which separately requires the recipient's prior consent before you send mass email advertising. Most operators sequence Swiss outreach through a call or a personalised LinkedIn message first, and move to email once a specific, documented consent exists.
Does using an agency shift the legal risk away from my company?
Not away from the client whose offer is being advertised. UWG claims under Articles 9 and 10 can be brought against the business benefiting from the advertising, and an agency that promises to absorb all compliance risk on your behalf is describing something Swiss unfair-competition law does not clearly support. What you can reasonably expect instead is full visibility of the copy and list before anything sends, documented data sources, and immediate opt-out handling.

Want the Swiss market handled properly?

We plan the channel mix per language region, keep lists small and researched, document our data sources and honour every opt-out. You get the accurate picture of the risk, then decide.

Book a strategy call Or get a free target list first