All our articles

Data protection in Switzerland: our nFADP strategy

Vincent Prou
· 8 min

The Federal Council has set the deadline for the nFADP — the new Swiss data protection act, the Swiss equivalent of the GDPR — to come into application.

Swipe left to read

The Federal Council has set the deadline for the nFADP — the new Swiss data protection act, the Swiss equivalent of the GDPR — to come into application.

The act was passed on 18 December 2020 and will come into force on 1 September 2023. That leaves less than a year to come into line with the FADP/GDPR in Switzerland. And a year passes quickly.

Update, September 2026: the nFADP has been in force since 1 September 2023.

The starting point of the nFADP: the scope of the GDPR

As a reminder, the GDPR coming into application in Europe shook the whole industry when it arrived in May 2018, because it implied a whole series of measures to protect users’ data better. The hardest for the digital industry was classifying the cookie as personal data, since it sits at the centre of every measurement tool on the market. The whole industry has been working since to find alternatives for continuing to measure what marketing achieves.

The end of tracking in digital marketing?

For many, it signalled the end of data collection and a return to the stone age: data collection in digital marketing means measuring actions on one side and building audiences on the other, so as to deploy communication targeted at each of them, and to be able to improve it through measurement. Yet classifying cookies and other identifiers as personal data forces a systematic request for consent, which reduces the possible use of cookies. The industry has nonetheless put CMPs (consent management platforms) in place to comply.

In Switzerland, consent is so far little used, or used incorrectly. Many Swiss companies will have to come into line. The nFADP resembles the GDPR in its broad lines. The good practices applied to respect the GDPR therefore apply to respecting the nFADP, the Swiss data protection act. Below is a comparison of the two laws, with their broad similarities and a few differences.

The real stake of the GDPR: attributing campaign performance

Attributing performance is what lets investment be steered and the business be grown. It is essential to put solutions in place that show which marketing effort has an impact on the business.

The loss of a far from negligible share of the data will mean the loss of certain measures as we know them today.

Advertisers who implemented consent correctly, for instance, saw their CPA rise. The reason follows from the fact that only 40% of users consent to cookies on average. For a given marketing budget, that means the number of conversions passed back by cookies falls by 60% on average, which mechanically sends CPAs soaring.

That is exactly what will happen in Switzerland if campaigns go on being analysed through “traditional” methods and tools.

The adservers now measure only about one event in four

Share of events measured by tool, in %, before the FADP / GDPR (without cookie consent) and after (with consent). The second button translates that loss into the cost per acquisition shown.

Source: Bright, the table published in this article (October 2022); “est.”: a value estimated in that table · Chart: bright.swiss

Table comparing, before and after the nFADP, the share of events measured by Google Analytics, Google Ads, Meta Ads and the adserver.

The chart above shows that:

  1. Putting consent in place degrades data collection across the various platforms.
  2. The loss on classic adservers such as Google Campaign Manager or Xandr is greater, because those tools suffer both from the loss tied to consent and from the third-party cookie blocking many browsers now apply.
  3. Google and Meta hold a higher level of measurement, because they moved years ago to first-party tracking, which partly limits browser blocking. That solution is not perfect, however, since browsers such as Safari have begun blocking first-party cookies older than 24 hours.

Note that this also signals the loss of a large share of post-view conversions.

The solutions

There are nonetheless other ways of measuring what marketing achieves — solutions with the advantage of being little or not at all disturbed by the nFADP.

Those solutions turn on four pillars:

  1. A clear data collection plan, in line with the nFADP. That collection happens at different levels (see the table below).
  2. Change the prism through data science: analyse the collected data at three levels — third party, first party and zero party.
  3. Build cross-channel reattribution models covering offline and online activity, including MMM (media mix modeling).
  4. Build algorithms that make the data better understood, through machine learning.
1 – Ad centric 2 – Site / app centric 3 – Customer centric
Collection through the tools tied to measuring the performance of the ad-buying platforms, such as Google Ads, Meta Ads and others. Collection through the analysis tools tied to the site and the app. For the web that means web analytics such as Google Analytics; for mobile, an MMP such as Appsflyer or Adjust. Collection through the tools tied to customers. The CRM of course, but also every tool collecting business data, the marketing automation tools and other databases (first party and zero party).
The aim is to create a systemic connection between the tools, so that the data can be enriched and explored afterwards

The solutions in detail

Data collection

The biggest question for companies is not so much compliance as having a data collection strategy that measures business activity, so that marketing can go on being developed. For Vilebrequin, present in 53 countries, the data collection strategy was strengthened while taking cookie regulation into account.

The good news is that there are ways of continuing to follow marketing activity without being too affected by consent: a good GA4 configuration, or collecting first-party and zero-party data, are among them. Hence the need for a good data collection strategy.

One of the major questions of the nFADP is respecting consent properly, on setting cookies and on sharing data. For the web, a CMP — a consent management platform — has to be put in place. It will gather the consent and pass the information to the other tools.

Data collection – ad centric

Most tools resting on cookies will suffer from the nFADP’s arrival. A certain amount of data will be lost and the algorithms will be the poorer for it.

The solutions follow from several actions:

  1. Define the funnel and the events to collect properly, and distinguish macro events from micro events clearly. The aim is to collect usable data. It is often pointless to collect data whose use is unclear.
  2. Shorten the funnels: the shorter the time between the click and the action, the better performance will be followed.
  3. Put performance measurement in place through APIs such as Google’s and Facebook’s; and to make deploying that kind of solution easier, we recommend putting server-side GTM in place, so that the data integration has to be done only once.
  4. Use server-to-server tracking: so that the measurement no longer passes through a cookie in the browser, but through storing a tracking value in the URL, which the advertiser records and passes back to the third party through a server call. That solution can also be implemented in server-side Google Tag Manager.
  5. Pass conversion IDs to the ad-centric tools wherever possible.

Data collection – site / app centric

With GA4 in place, here is the difference in how performance is measured.

GA4 fills in the 60% of events Universal Analytics loses, to within 10%

Share of events measured, in %, once cookie consent is in place. GA4 counts cookieless events and estimates by machine learning what it cannot measure; the black line shows its margin of error, 10%.

The margin of error is the one in the original table; it is drawn on either side of 100%, since year estimate can overshoot reality as well as fall short of it.

Source: Bright, the table published in this article (October 2022) · Chart: bright.swiss

Table of the share of events measured: 40% for Google Analytics UA, 100% for GA4 within a 10% margin of error.

Google’s answer with GA4 lets users’ consent be respected while measurement continues. Google manages that in two ways:

  • The tool counts every event independently of cookies
  • GA4 uses machine learning to extrapolate performance for the users it cannot measure. By crossing the counting events with the user data of those who consented to cookies, it reaches a level of measurement close to reality. A sample of 40% is amply enough for the algorithm to deliver data with a small margin of error.

Data collection – customer centric

There are two steps to take on the advertiser’s side. The first is to send the IDs tied to conversions to the site-centric and ad-centric tools, where they will be reconciled in the system. The second is to bring in a tool that connects the various platforms through a Customer Data Platform (CDP).

The first solution lets the data be explored with a data scientist and the customer journey be reconstructed.

The second automates the connection of the data, so as to automate the triggering of actions.

And finally, getting round the question through data science and machine learning.

Build cross-channel reattribution models covering offline and online activity.

Since tracking and data collection are not perfect — by their nature as much as through the new limits on collection — it is essential to analyse the return on advertising investment through a reattribution model other than simple analytics data.

Sophisticated algorithms can estimate each marketing channel’s impact. They use the same method for every channel and give information that greatly helps allocate the marketing budget better.

Through structuring the media plan, the data and data science, it is possible to analyse how the various channels contribute to the business’s revenue. That is what building a Media Mix Modeling, or MMM, is for: to indicate mathematically the ideal investment against defined objectives.

In summary, here is the approach we recommend:

  1. Rebuild the data collection strategy, with a clear roadmap of what data to collect and where.
  2. Put GDPR/nFADP-compliant tooling in place: a CMP (consent management platform), a fitting TMS (tag management system), and an analytics tool in line with the law. Putting GA4 (Google Analytics 4) in place, for instance, is a good way to make up for a CMP.
  3. Update the measurement of the ad-centric tools, by changing the tagging plan and putting API connections in place with Google, Facebook and other sources. To do that effectively, deploying server-side Google Tag Manager is a good practice to prioritise, so as to simplify putting server-side tracking in place and maintaining it in future.
  4. Explore the back-end data with a scientific and business intelligence method, so as to cross online, offline and BI data.
  5. Put algorithmic models in place to make better use of the data — a reattribution or scoring model — so as to adjust media investment, and the marketing aimed at your audience and your customers, more finely.

A pragmatic first step: take stock

Before embarking on a project as important and time-consuming as data, it matters to have a clear view of what to do. Speed should not be confused with haste. We therefore recommend carrying out an audit of the company’s whole information system, so as to document the data collection strategy in place, propose a new vision and, above all, identify the short-, medium- and long-term actions that can be taken.

That will bring technical changes, so it is essential to anticipate now, in order to be compliant in September 2023. Get in touch to learn more about the solutions we offer.

  • Data protection
  • Tracking and data collection

Privacy Preference Center