Germany, Austria, and Switzerland don’t all play by the same rules. A plain-English look at what selling online in the DACH region actually requires.
Selling into the DACH region is a good opportunity and, if you’re honest about it, a slightly nerve-wracking one. Germany, Austria, and Switzerland are wealthy markets full of online shoppers. They’re also among the strictest places on earth for data protection, and German regulators in particular have a habit of actually enforcing the rules rather than just publishing them.
The reassuring part is that none of this is a mystery. The rules are knowable, and once the shape of them clicks, staying on the right side is mostly a matter of doing a handful of things properly and not cutting the obvious corners. The mistake almost everyone makes first is assuming DACH is a single market with a single rulebook. It isn’t, and that’s the right place to start.
Three countries, two different legal worlds
DACH is a handy label for German-speaking Europe, but legally it splits down the middle.
Germany and Austria are in the EU, so the GDPR applies to them directly, sitting on top of each country’s own national law. Germany adds the BDSG, and for anything to do with cookies and tracking it adds the TDDDG (which is just the renamed, updated version of the old TTDSG). Austria has its DSG. If you already understand GDPR, you understand most of what these two markets expect.
Switzerland is the odd one out, because it isn’t in the EU at all. It runs on its own revised Federal Act on Data Protection, which came into force in September 2023. In spirit it looks a lot like GDPR, but it differs in some genuinely important ways, including how it punishes you when things go wrong. More on that shortly.
And here’s the trap that catches people: being based in Switzerland, or anywhere outside the EU, doesn’t get you off the GDPR hook. The regulation reaches across borders, so if you sell to customers in the EU, it generally applies to you regardless of where your business sits. A Swiss shop shipping to Munich usually has to care about both Swiss law and the GDPR. Not one or the other. Both.
What the GDPR actually asks of an online store
Strip out the jargon and the core of it is common sense. You’re being asked to look after people’s personal data properly and to be honest about what you’re doing with it. In practice that comes down to a few things:
- You need a valid reason for every piece of personal data you collect, usually the customer’s consent, or the simple fact that you need it to ship their order.
- You should only collect what you actually use. Hoarding data you don’t need isn’t a nice-to-have asset; it’s a liability sitting on your server.
- You have to be upfront, with a privacy policy that plainly explains what you collect, why, and what happens to it. Not buried, not written to be unreadable.
- People can ask what you hold on them, ask you to fix it, and ask you to delete it, and you need a real way to handle those requests when they come in.
- You have to keep the data reasonably secure, and report certain breaches quickly if they happen.
- The tools that touch your customers’ data, your email platform, your analytics, your apps, need proper data processing agreements in place.
None of that is exotic. It’s the kind of thing a careful business would want to do anyway. The rules just make it non-optional.
Cookies and consent, where most stores actually get caught
If you’re going to trip up somewhere, it’ll be here. Cookie and tracking consent is the single most enforced corner of this whole subject, and the bar is higher than most sellers realize.
Germany’s TDDDG is blunt about it: as a rule, you need consent before you store or read anything on a visitor’s device that isn’t strictly necessary. And across the EU, for that consent to count, it has to be freely given, specific, informed, and unambiguous, with saying no as easy as saying yes. That quietly kills a lot of the shortcuts stores still use.
Pre-ticked boxes don’t count, because the person has to actively choose. A big glowing “Accept all” button sitting next to a buried little “reject” link is exactly the kind of dark pattern regulators have been fining. Your analytics and advertising tags shouldn’t fire until the visitor has actually agreed, which means the common habit of loading them on arrival is a problem. And the banner itself shouldn’t hold your page hostage, something German guidance calls out specifically.
This is commercial, not just legal. German shoppers are about as privacy-aware as any in the world, and a pushy or shifty-looking consent banner chips away at trust with the exact people you’re trying to win over. A clean, honest consent experience isn’t only compliant. It quietly tells a cautious buyer that you’re the kind of brand that respects them.
Switzerland does a few things its own way
If Switzerland is on your map, a couple of differences are worth knowing, though the practical advice mostly rhymes with the EU.
Switzerland has no direct equivalent of the EU’s strict cookie-consent rule, and it has historically been more relaxed about some cookies, allowing an opt-out approach as long as people were told what was happening. That’s the theory. In practice, for higher-risk tracking, third-party advertising especially, the expectation has been hardening toward proper opt-in anyway, so if you simply build to the stricter EU standard you’ll almost certainly clear the Swiss bar without maintaining a separate system for it.
The penalties are where Switzerland genuinely surprises people. GDPR fines land on the company and can climb into the millions. The revised Swiss law instead reaches for the individual: criminal fines of up to CHF 250,000 can fall on the responsible person, typically a manager or decision-maker, and generally only for willful violations. It’s a different kind of pressure, pointed at a human being rather than a balance sheet, which is worth mentioning to whoever actually runs your company.
Why it’s worth taking seriously
The numbers are what grab attention. In the EU, a GDPR fine can reach 20 million euros or 4% of your global annual turnover, whichever is larger, and Germany’s cookie law can stack its own penalty on top. Regulators in Germany and Austria have shown, repeatedly, that they’ll use those powers.
But honestly, the fine is rarely the worst of it. The bigger everyday cost is trust. In markets this privacy-conscious, being visibly careful with data is a real edge, and being sloppy with it is the sort of thing that lands in the press and lingers in customers’ minds long after the penalty is paid. Handled well, compliance is quietly one of the better marketing decisions you can make in DACH.
What all this does to your marketing
Here’s the bit the pure compliance guides skip, and it’s the one that actually touches your growth. Strict consent doesn’t just shape your legal paperwork. It changes what marketing is even possible, because so much of modern marketing quietly runs on tracking people.
When a big share of your visitors decline tracking, and in these markets plenty do, your analytics see less, your ad pixels fire less, and your retargeting pools shrink. That’s not a disaster, but it does move the smart money. The channels that never depended on following people around the web start to look a lot more attractive.
Email and other owned audiences, built on consent, keep working no matter who rejects cookies. Getting recommended by AI tools or found in search doesn’t rely on surveillance, which makes it a naturally privacy-friendly way to grow. And your measurement has to grow up a little, leaning on blended, first-party signals instead of pretending you can still track every click. Put simply, as invasive tracking gets harder in DACH, the things that were never built on it quietly become your most dependable engines.
Where CommerceV3 fits
Let’s be clear about our lane. CommerceV3 is a growth partner, not a law firm, so the compliance itself belongs with your data protection professional. What we do is help you grow within these rules instead of fighting them, by leaning into the channels that hold up in a privacy-first market. That means GEO and AI search that earns visibility without invasive tracking, plus consent-friendly email and retention, all run by one senior team. We work with ecommerce brands across verticals, including ones selling into privacy-strict markets like DACH.
Grow in DACH without leaning on tracking
If tighter consent rules are shrinking what your analytics and ads can see, the answer is to lean on channels that don’t need them. Request CommerceV3’s free AI Visibility Assessment to see how visible your brand is in AI answers today, a growth channel that works with the privacy rules rather than around them. Request your assessment to get started.
Frequently Asked Questions
Does the GDPR apply to my store if I’m based outside the EU?
Often, yes. The GDPR reaches beyond EU borders and applies to any business that targets or sells to people in the EU. So a Swiss, UK, or US store shipping to German or Austrian customers generally has to comply with it for that data, on top of its own country’s rules. It’s exactly why a Swiss seller usually has to weigh both Swiss law and the GDPR. Since the details hinge on your situation, confirm your obligations with a qualified professional rather than assuming you’re exempt.
Is Switzerland covered by the GDPR?
Not directly, since it isn’t in the EU. Switzerland runs on its own revised Federal Act on Data Protection, in force since September 2023, which is similar in spirit but differs in practice, including a penalty structure that can fine the responsible individual rather than the company. The catch is that the GDPR can still apply to a Swiss business if it serves EU customers. Building to the stricter EU standard is usually the simplest way to stay clear on both sides.
What’s the biggest GDPR mistake ecommerce stores make?
Cookie and tracking consent, by a distance. The usual culprits are firing analytics and ad tags before the visitor agrees, using pre-ticked boxes, making “accept” far easier than “reject,” and banners that block the page. Regulators actively fine this. The fix is a properly set-up consent flow that keeps non-essential tracking switched off until the visitor makes a genuine, freely given choice, with refusing as easy as accepting.
How big can the fines get?
In the EU, up to 20 million euros or 4% of global annual turnover, whichever is higher, with national cookie laws like Germany’s able to add penalties on top. Switzerland works differently, with criminal fines of up to CHF 250,000 aimed at the responsible individual for willful breaches. And beyond the money, the hit to trust in privacy-conscious markets can outlast the fine itself, which is really why this is worth doing properly.
Does strict consent hurt my marketing in DACH?
It changes it rather than kills it. When many visitors decline tracking, your analytics and ad pixels see less and retargeting shrinks. The move isn’t to fight the rules, it’s to lean on channels that don’t depend on invasive tracking: consent-based email and owned audiences, and earned visibility in AI and search. Those keep working whoever accepts cookies, which makes them more valuable in strict markets, not less. Measurement should shift toward blended, first-party signals.
Do I need a Data Protection Officer to sell in DACH?
It depends on things like the scale and nature of your data processing, and the rules vary by country, so this is genuinely a question for a professional rather than a blog. Some businesses are required to appoint one; others aren’t but choose to anyway. Rather than guess, get advice for your specific case. The underlying point stands either way: someone competent should clearly own data protection in your business.




