revDSG — Revised Swiss Data Protection Act

The revDSG (revised Swiss Data Protection Act, in force since 1 September 2023) sets rules for how you collect, store and use personal data — including job applicant CVs, salary records, and employee files. As an employer, you must tell people what data you collect and why, keep it secure, and honour their rights to access or delete it. Violating these rules can cost you significant fines.

Also available inDeutschFrançaisItaliano

The revDSG replaced the 1992 Data Protection Act and aligns Swiss law with international standards (including GDPR principles). It applies to any employer processing personal data — which means almost all of you, from the moment a candidate submits an application.

Unlike employment law (ArG) or collective labour agreements (GAV), the revDSG is not sector-specific. It applies equally to a Zürich bank, a Valais hotel, and a 3-person startup in Appenzell.

When revDSG Comes Up

You are processing data whenever you: review job applications, conduct background checks, store CVs, maintain salary and Quellensteuer records, use recruitment software like zenRecruiting.ai, or keep employee files with performance notes and absence records.

The revDSG applies from the moment a candidate applies — not just after you hire them. Even rejected applicants' data is protected.

  • Recruitment: collecting CVs, cover letters, test results, reference checks
  • Employment: payroll, Arbeitszeugnis, sick leave records, training notes
  • Termination: final pay, severance documentation, exit interviews
  • Third-party data: background checks via external providers, recruitment agencies
  • Data transfers: sending employee lists to payroll firms or accountants
  • Retention: how long you keep files after someone leaves (usually 5–10 years for tax/labour law compliance)

Your Core Obligations

You must be transparent. Tell applicants and employees what data you collect, why you need it, and how long you keep it. This is usually done in a privacy notice at the application stage and in your employment contract or handbook.

You must secure it. Use password protection, encryption, and restricted access. If you use a recruitment platform, your vendor must sign a data processing agreement confirming they protect data and cannot use it for their own purposes.

  • Lawful purpose: collect only data you genuinely need for hiring, payroll, or legal compliance
  • Transparency: provide a clear privacy statement before collecting CV, test scores, or references
  • Data processing agreement: if a vendor (recruitment software, payroll firm, accountant) accesses employee data, they must sign a contract confirming data protection obligations
  • Security: password-protect files, limit who can access payroll records, encrypt sensitive documents
  • Subject rights: employees and candidates can request a copy of their data or ask you to delete it (with narrow exceptions for legal/tax obligations)
  • Breach reporting: if data is compromised, notify affected people and the canton's data protection authority without undue delay

The Single Most Common Mistake

Employers forget to get a data processing agreement in place with their recruitment software, payroll provider, or accountant. You assume the vendor "just handles it," but without a signed contract, you remain liable for how they use your data.

A close second: keeping CVs and rejected-applicant records for years without a clear retention policy, then not being able to explain why you still have them when someone asks for deletion.

  • Not signing a data processing agreement with zenRecruiting.ai, your accountant, or payroll provider
  • Sharing employee lists with third parties (clients, banks, insurers) without a legal basis or notice
  • Storing sensitive data (health, references, test scores) without encryption or access controls
  • Ignoring a candidate's or employee's request to see or delete their data
  • Having no clear policy for how long you keep applicant records (revDSG assumes you delete unsuccessful applications after hiring is done)
  • Conducting background checks without explicitly telling the candidate you are doing so

Frequently asked questions

Does revDSG apply to a small team of 5 people?
Yes. revDSG applies to all employers, regardless of size. The only exception is truly personal use (e.g., a personal address book), which does not apply in a business context. A 5-person SME must still have clear privacy notices and secure storage.
Can I keep a rejected applicant's CV on file for future openings?
Only if the applicant explicitly consents, and only for a reasonable period (typically 6–12 months). Otherwise, delete it after the hiring process. If you want to re-contact them later, ask permission first. Some recruitment platforms allow you to set automatic deletion timelines.
What if my accountant or payroll firm breaches data security?
You remain liable unless you have a signed data processing agreement in place and can prove you chose a reliable vendor. Confirm in writing that they comply with revDSG. If a breach occurs, notify your data protection authority. Consult a lawyer about liability sharing.

General information for Swiss employers, not legal advice. Have a lawyer confirm anything with legal consequences.

Related