GDPR for Swiss Employers

The GDPR (General Data Protection Regulation) applies to your Swiss company if you process personal data of EU residents—including job candidates and employees. You must comply even if your business is based in Switzerland. Swiss law recognises GDPR compliance as meeting the revDSG standard. A privacy lawyer should review your hiring practices and data retention.

Also available inDeutschFrançaisItaliano

The GDPR is EU law that regulates how organisations handle personal data of people in the European Economic Area. If you recruit across borders or employ EU citizens, GDPR applies to you—your Swiss location doesn't exempt you.

Switzerland has its own Federal Data Protection Act (revDSG), which is roughly equivalent to GDPR. Swiss regulators accept GDPR compliance as satisfying Swiss data-protection requirements. However, the two laws differ in detail, so a lawyer should confirm your approach covers both.

When GDPR Matters in Hiring

You trigger GDPR obligations the moment you collect a CV, LinkedIn profile, or application from an EU candidate. This includes applicants who never take the job. You must have a legal basis (consent, contract, or legitimate interest) and be transparent about what you collect and why.

If you use recruiting software or store data on servers outside Switzerland, check where data physically lives. Cloud services like Google Workspace or Microsoft 365 may process EU data, activating GDPR compliance requirements for your company.

  • Collect only data relevant to the role (no birthplace, religion, or photo unless job-specific)
  • Tell every candidate upfront how long you keep their data and who can access it
  • Delete applications from rejected candidates within 6–12 months unless you have a retention reason
  • If using an applicant-tracking system, ensure the vendor signs a data-processing agreement (DPA)
  • Give candidates the right to request their data, correct it, or ask you to delete it
  • Report data breaches to the EU authority (if the person is in the EU) within 72 hours

Your Obligations as an Employer

Document your hiring process: write down why you collect each data point and how long you keep it. This 'privacy notice' must be given to candidates before or at application. Regulators look for this documentation first in any audit.

If you outsource recruiting to an agency or use background-check services, they become 'data processors' under GDPR. You must have a written contract (DPA) specifying what they can do with data and requiring them to delete it on request.

  • Appoint a data-protection officer if you're a public authority or process data at scale
  • Train hiring managers: never ask about marital status, health, or union membership on application forms
  • Keep encrypted passwords on any recruiting platform; use two-factor authentication
  • Conduct a privacy impact assessment (DPIA) if you use AI screening tools or automated decision-making
  • Review your Arbeitszeugnis and personnel-file practices; GDPR restricts how long you keep performance records
  • Respond to candidate data-access requests within 30 days

The Most Common Mistake

Employers assume GDPR doesn't apply because they're Swiss. Wrong. If you advertise a role on an EU job board or accept applications from the EU, you are bound by GDPR. Ignorance is not a defence; fines can reach EUR 20 million or 4% of global revenue.

The second mistake: keeping candidate data 'just in case' without a stated reason. GDPR requires you to delete data once the hiring process ends, unless you have legitimate grounds (legal dispute, background-check appeal). Hoarding CVs violates the retention principle.

  • Don't rely on consent alone; document legitimate business reasons for each data point
  • Don't store passwords or sensitive data in plain text in email or spreadsheets
  • Don't assume a DPA with your software vendor exists; request it in writing
  • Don't forget that candidates have more rights under GDPR than under revDSG alone
  • Don't skip privacy notices; they're your proof of transparency if challenged
  • Confirm your approach with a Swiss data-protection or employment lawyer before scaling hiring

Frequently asked questions

Do I need GDPR if I only hire in Switzerland?
No—if all your candidates and employees are Swiss residents and you process no EU personal data. But if you advertise on EU job boards, accept applications from EU citizens, or have employees in the EU, GDPR applies. When in doubt, consult a lawyer.
What's the difference between GDPR and the Swiss revDSG?
Both protect personal data, but GDPR is stricter on consent, data-subject rights, and fines. If you comply with GDPR, you typically also comply with revDSG. However, revDSG has some unique rules (e.g., around employee monitoring). A lawyer should review both.
How long can I keep a rejected candidate's CV?
GDPR requires you to delete it once the hiring decision is final, unless you have written consent to keep it for future roles (must be opt-in) or a legal reason (e.g., defence against discrimination claims, typically up to 6 months). Safest approach: delete after 3 months unless candidate consents to longer storage.

General information for Swiss employers, not legal advice. Have a lawyer confirm anything with legal consequences.

Related