Skip to content

Cold Email Laws in Switzerland: The Penalty Is Criminal

Cold email into Switzerland is governed by the Federal Act on Unfair Competition (UCA), Article 3 paragraph 1 letter o, and not by a privacy regulator. The rule asks for three things at once: prior consent, a correct sender, and a simple free of charge way to refuse. Under Article 23 UCA a wilful breach is a criminal offence carrying a custodial sentence of up to three years or a monetary penalty, and the complaint is filed by a competitor or a customer rather than by an authority.

Most teams treat Switzerland as the GDPR with a nicer flag. Switzerland is not in the EU, the GDPR is not the operative rule for your send, and the rule that is operative sits in competition law with a criminal penalty bolted to it.

In Switzerland the complaint does not come from a regulator. It comes from the competitor you just outbid.

The mistake: copying your EU sequence and swapping the footer

I have built cold email infrastructure for more than 500 businesses. Switzerland is the one country where I rebuild the list instead of reusing the European one. The Dutch and Italian rules live in telecoms and privacy statutes, enforced by a data protection authority that issues administrative fines. Switzerland files the same conduct as unfair competition. Different statute, different complainant, different penalty.

And before anyone tells me a US company is out of reach: Article 136 of the Swiss private international law act applies the law of the state in whose market the result occurred. Your message lands in a Swiss inbox, so the result occurs in the Swiss market.

The EU template read

"Switzerland is basically the GDPR, so my European sequence and footer carry over."

The GDPR is not the operative rule for the send. Article 3 of the Unfair Competition Act is, and Article 23 attaches a criminal penalty to it.

What the statute says

"Consent or a real prior sale, the correct sender named, and a simple free way to refuse."

Three duties joined by the word or. Miss any one of them and the send is unfair, whatever your privacy paperwork says.

What Article 3 paragraph 1 letter o actually requires

The provision has been in force since 1 April 2007. It covers mass advertising sent by telecommunication without a direct connection to any requested content, which puts email, SMS and MMS inside it.

It imposes three separate duties, and the statute joins them with the word or, so failing any single one is enough to make the send unfair:

  • Obtain the prior consent of the customer.
  • Indicate the correct sender.
  • Offer a simple and free of charge option of refusal.

Read the second duty again. A spoofed From name, a lookalike domain that never names your company, or a reply address routing to an inbox nobody owns, is an independent breach even when your consent record is spotless. Most senders treat consent as the whole test. It is one third of it.

The exception is narrower than the one you lean on in the EU

There is a soft opt in. It is available where you received the contact details when selling goods, works or services, you gave the option of refusal at that moment, and the advertising is for your own similar goods, works or services.

The phrase when selling does all the work. The Federal Data Protection and Information Commissioner states it plainly in its own guidance: the exception is only valid when a sale has been made or a service provided, and simply creating an online account is not enough.

So a whitepaper download is not a sale. A webinar registration is not a sale. A free trial that never billed is not a sale. Most of what your marketing team calls a warm list does not qualify here, and the fallback for everyone who never transacted is consent. If you are working from an EU legitimate interest position, note that Switzerland does not offer you that route for the send itself.

0
exemptions for business recipients in the text of letter o
3 yrs
maximum custodial sentence for a wilful breach under Article 23
500+
businesses I have built cold email infrastructure for

Article 23: the person who presses charges is your competitor

This is the part that should change how you price the risk. Article 23 paragraph 1 makes a wilful breach of Article 3 a criminal offence, prosecuted on complaint, punishable by a custodial sentence of up to three years or a monetary penalty. Paragraph 2 then says who may file that complaint, and it does it by cross reference: anyone entitled to bring civil proceedings under Articles 9 or 10.

Follow the cross reference and the risk model inverts. Article 9 gives standing to any person whose customer base, credit, professional reputation, business operations or other economic interests are threatened or damaged. That is a competitor. Article 10 adds customers, trade associations and consumer protection organisations, and Article 23 paragraph 3 gives the Confederation the rights of a private claimant.

There is an administrative route as well, and the FDPIC points recipients to the State Secretariat for Economic Affairs. But the criminal trigger does not wait for a regulator to open a file. It needs one irritated Swiss firm in your category.

Non compliant send
Competitor has standing, Article 9
Files criminal complaint, Article 23
Up to three years

Your dialer sits inside the same statute

Three more letters were added to Article 3 with effect from 1 January 2021, and they decide whether your outbound calling or AI voice agent can run into Switzerland at all.

Letter u prohibits ignoring the note in the telephone directory recording that a customer does not want advertising from firms they have no business relationship with. Then comes the clause that ends the scraped mobile list: customers without a directory entry are treated in the same way as customers with a directory entry and note. An unlisted Swiss number is a do not call by default. Calls inside an existing business relationship are exempt.

Letter v requires advertising calls to display a telephone number that is entered in the telephone directory and that you are entitled to use, so a US caller ID or a rented VoIP number breaches the statute before the call is answered. Letter w closes the loop: you may not use information that came to you through a breach of letter u or v. A meeting booked off a non compliant call is tainted at the source.

Four moves to make this week

01
Split Switzerland out of your EU segment
Not a sub segment of DACH and not a row in your GDPR sheet. Its own country rule, its own suppression logic, its own sending policy. It is the first thing I set up on any European cold email infrastructure build.
02
Re run your soft opt in against the sale test
Query your list for Swiss contacts and check each source against one question: did money change hands for goods, works or a service. Downloads, registrations and free accounts fail, and everyone who fails goes back to a consent record or comes off the Swiss send.
03
Audit the sender line and the unsubscribe as separate line items
Your From name must identify the real sender and the refusal option must be simple and free. Test the unsubscribe end to end from a cold inbox rather than trusting your platform preview. Two of the three duties are set by your infrastructure, not your copy.
04
If you dial Switzerland, gate on the directory
Suppress every number that is not listed, respect the star marker set through Swisscom Directories, and make sure your caller ID is a Swiss directory number you are entitled to use. If you cannot satisfy all three, run email only and keep the phone for existing clients.

The bottom line

Switzerland is a small market with a high average contract value and it is worth sending into. It is not worth sending into on autopilot with an EU template.

The rule is short, it is public, and it is enforceable by the competitor sitting across the table from you in a pitch. Read Article 3 paragraph 1 letters o, u and v once, fix the three things they ask for, and you can prospect there with a clear head.

Fix the three duties, gate the dialer on the directory, and Switzerland becomes a normal market to sell into. If you want a second pair of eyes on your setup, book a 30 minute call at cal.com/zeeshanwaheed/30min or email [email protected].

Frequently Asked Questions

Not as the operative rule. Switzerland is not an EU member state, and Swiss e-mail advertising is governed by Article 3 paragraph 1 letter o of the Federal Act on Unfair Competition. The Swiss Federal Act on Data Protection governs the handling of the addresses themselves, and the GDPR can still reach you separately if you are also processing EU residents data. For the send itself, the UCA is the rule to satisfy.

It is legal where you satisfy the statute. Article 3 paragraph 1 letter o is written around the customer and carves out no exemption for business recipients, so the safe operating assumption is that B2B sends are covered. You need prior consent or a qualifying prior sale, a correct sender identity, and a simple free of charge way to refuse.

There are two routes. A recipient can complain to the State Secretariat for Economic Affairs, which the Federal Data Protection and Information Commissioner points to on its own guidance page. Separately, Article 23 makes a wilful breach a criminal offence prosecuted on complaint, and Article 23 paragraph 2 lets anyone with civil standing under Articles 9 or 10 file that complaint, which includes competitors and customers.

Article 136 of the Swiss Private International Law Act applies the law of the state in whose market the result occurred to unfair competition claims. Messages delivered to Swiss inboxes produce their result in the Swiss market, so being incorporated in the United States or the United Kingdom does not by itself put a sender outside the rule.

Not sure whether your Swiss list is legal to send to

I have built cold email infrastructure for 500+ businesses and I check the country rules before a single message goes out. Bring me your list and your sending setup and I will tell you what has to change.

Book a 30-Minute Call

Or email [email protected].