FROM THE LGS JOURNAL / Compliance

FADP and GDPR for Outbound: A Practical Reading

A practical guide to fadp outbound compliance for Swiss B2B teams, covering contact sourcing, channel rules, privacy notices, objections and useful campaign controls.

RESEARCH → SEQUENCE → CONVERSATIONIllustrative workflow · example data
01 / DISCOVER

Find the person.
Understand the account.

Emailcontact@example.com

Phone+41 •• ••• •• ••

LinkedInDecision-maker identified

ICP → research → enrichment → review
02 / ENGAGE

One conversation.
Connected channels.

  1. 01✉ Personalised introduction
  2. 02in LinkedIn connection
  3. 03✉ Relevant follow-up
  4. 04☎ Prepared sales call
A reply changes the next step.
03 / LEARN

Read the signals.
Qualify the interest.

Open rate42%
Click rate6%
Meetings booked04
Example only. Opens and clicks are directional signals.
Human review at every commercial decision.Explore the process

Start with permission to use the channel

For a Swiss founder, outbound compliance starts before the first message. You need to know whom you intend to contact, where their details came from, whether you may use the chosen channel and what happens if they object. A relevant offer does not, by itself, answer those questions. Neither does the fact that a work email address appears on a company website.

A practical approach to fadp outbound compliance separates two decisions. First, may you collect and process this person's information for your stated purpose? Second, may you send this particular communication through email, LinkedIn or telephone? Passing the first test does not automatically satisfy the second.

Build these decisions into campaign approval rather than leaving them to individual sales representatives. Record the target geography, audience, source, channel justification, notice and objection process. If a required answer is missing, hold that segment until the responsible person has reviewed it.

Understand the Swiss legal frame

The revised Federal Act on Data Protection, commonly called revDSG or nLPD, governs processing of personal data. A named employee's work address or direct telephone number can be personal data, even when used professionally. Core duties include transparency, proportionality, purpose limitation, accuracy and appropriate security. Swiss private sector processing does not use exactly the same lawful basis framework as GDPR.

The Swiss Unfair Competition Act, UWG or LCD, adds rules about marketing conduct. For mass advertising through telecommunications, prior consent is generally required, alongside correct sender identification and an easy, free refusal mechanism. A narrow existing customer exception can apply to advertising for your own similar offerings when the statutory conditions are met. B2B status is not a general exemption.

GDPR must also be assessed where EU contacts are involved, together with applicable national electronic marketing rules. These regimes overlap rather than replace each other. This article provides an operational framework, not a legal determination. Specific cases need legal advice.

Define a narrow audience and document provenance

Begin with an ideal customer profile based on business facts: sector, company size, operating location, relevant function and a specific commercial need. For example, a provider of production scheduling software might target operations leaders at manufacturers with multiple sites. That is more defensible and useful than gathering every senior contact in Zurich and hoping a message resonates.

For each record, retain the company, role, necessary contact details, source and collection date. Record whether the source is the company's website, a directory, an event registration or a supplier. If someone claims consent exists, retain evidence of its wording, date, scope and the organisations or channels it covers. A supplier's assurance that a list is compliant is not enough.

Avoid collecting private mobile numbers, sensitive personal details or unrelated social information simply because they are available. Verify current employment and business relevance before approval. Email verification can reduce delivery errors, but it does not establish permission to contact the person.

Make an explicit decision for every channel

Treat email, LinkedIn and telephone as separate decisions. For email, assess whether the proposed activity is mass advertising and whether valid consent or the existing customer exception supports it. Personalised fields and small batches do not necessarily change the legal character of a coordinated campaign. Do not build a programme around the assumption that manual sending creates an exemption.

For telephone outreach, check Swiss directory restrictions, including starred entries and protections for unlisted numbers, as well as any applicable relationship or consent exception. Keep evidence of the check. Use an identifiable business number and make your identity and purpose clear. A published switchboard number is not blanket authorisation for every marketing call.

LinkedIn also requires review of privacy rules, marketing restrictions and platform terms. A connection acceptance should not be treated as consent to an email sequence. Where a channel cannot be justified, use permission gathering through suitable inbound forms, events or introductions instead of transferring the same list to another tool.

Assess EU outreach separately

An EU address should trigger a jurisdiction review, not a copied Swiss campaign. GDPR applicability depends on factors such as an EU establishment or activities within its territorial scope. Where it applies, identify and document a lawful basis for personal data processing. Legitimate interests may be relevant to direct marketing, but require a genuine assessment of purpose, necessity and the individual's interests and reasonable expectations.

That assessment does not override national rules implementing the ePrivacy framework. Requirements for unsolicited B2B email differ across EU countries. Segment your audience by relevant jurisdiction and approve each channel accordingly. If you cannot identify which rules apply, do not launch the segment until that uncertainty is resolved.

Where GDPR Article 14 applies to indirectly collected data, provide the required information within the applicable timeframe, generally no later than the first communication if that occurs before one month. Make the right to object to direct marketing explicit and prominent. An objection requires stopping that processing, including related profiling.

Use transparent wording without treating it as permission

Clear wording helps people understand the contact, but cannot make an otherwise prohibited message lawful. Use the following email only after approving the channel and legal conditions. Replace each bracketed field with verified information, and provide an accessible privacy notice covering the controller, purpose, source, recipients, relevant transfers and rights as required.

“Hello [Name], I am [Sender] from [Company]. You requested information about [service] at [event]. We help [specific type of business] address [specific operational issue]. Would a short discussion about [relevant topic] be useful? We received your details through [registration source]. Our privacy notice is available at [privacy notice location]. If you prefer no further marketing contact, reply stop and we will record that preference.”

For an approved call, keep the opening equally direct: “Hello, this is [Name] from [Company]. This is a business development call about [topic]. Is it a suitable time for a brief explanation?” If the answer is no, distinguish an inconvenient moment from an objection without pressuring the person to continue.

Make notices and objections work in practice

Your privacy notice should describe the outbound activity you actually run. Explain who is responsible, what information is used, why it is processed and which recipients receive it. Address foreign disclosures and safeguards where required. A generic website notice covering only contact forms may leave prospecting activities unexplained. Check that the notice is readable without creating an account.

Assign ownership for objections before launching. Replies such as “remove me”, “not interested, do not contact again” and “stop calling” must reach a person or workflow that can prevent further activity. Do not force recipients to log in, provide additional marketing information or speak to a salesperson to unsubscribe.

Maintain a minimal suppression record so deleted prospects are not accidentally imported again. Record the identifier, scope of objection and date, with access limited to those who need it. Apply a broad marketing objection across channels rather than interpreting it as an invitation to switch from email to telephone. Test the entire process with an internal record.

Control tools partners and retention

Map where prospect information travels: research spreadsheets, enrichment providers, sending platforms, CRM systems, calendars and reporting tools. Establish the actual roles of the client, agency and suppliers. Contract labels alone do not determine whether an organisation acts as a controller or processor. Put appropriate processing agreements and instructions in place where required.

Check hosting locations, remote access and onward transfers, not just the vendor's headquarters. Where data leaves Switzerland or the EEA, assess applicable transfer requirements and safeguards. Restrict exports, use multifactor authentication and remove access when a staff member or contractor leaves. Prepare an incident escalation route with someone responsible for assessing notification duties.

Set retention periods according to purpose rather than storing every prospect indefinitely. Review inactive records at a documented interval and delete or anonymise information no longer needed. Keep justified suppression information separately. Ask vendors how deletion propagates into connected systems and backups, and record any limitations before making promises in your notice.

Measure outcomes alongside compliance controls

A weekly report should show whether the programme is commercially useful and operating within its approved boundaries. Track delivered messages, genuine replies, positive replies, qualified meetings and opportunities accepted by sales. Define a qualified meeting before launch, using criteria such as company fit, relevant responsibility and an agreed reason to speak. Calendar bookings alone are an incomplete measure.

Alongside those outcomes, report objections, complaints, invalid addresses, records missing provenance and the time taken to apply suppression. Review samples of live messages against approved wording. A campaign can generate meetings and still expose weaknesses in sourcing or objection handling. Investigate those weaknesses rather than averaging them into an overall conversion figure.

Do not treat open rates as proof of interest. Mail systems, privacy features and security scanners can inflate opens; some also generate automated clicks. Use replies and confirmed conversations as stronger evidence. Set internal pause criteria before launch, including any repeat contact after a recorded objection or discovery of unsupported consent claims.

Book a strategy call with Lead Generation Switzerland

Before scaling outbound, bring together the commercial objective and the compliance decisions. A useful starting brief contains your ideal customer profile, target locations, proposed channels, current data sources and definition of a qualified meeting. Include any existing customer consent records and the objections your team already holds. This makes gaps visible before more contacts enter the system.

Lead Generation Switzerland is a founder led Swiss B2B outbound agency based in Geneva, founded by Philip Allsopp. It operates across Geneva, Lausanne, Zurich, Basel, Zug and Bern in English, French and German. Its work covers ICP definition, verified Swiss target lists, multichannel outreach, qualified meetings booked into the client's calendar and weekly reporting. Verified contact details remain distinct from permission to use a channel.

Book a strategy call to discuss your audience, approval process and operational requirements, then consider whether Starter, Growth or Premium fits the scope. Bring specific legal uncertainties to qualified counsel. The aim is to establish a workable programme with clear responsibilities, not to substitute campaign delivery for legal advice.

Questions and answers

Does the FADP allow cold email to Swiss businesses

The FADP is only part of the assessment. Processing a business contact's personal data and sending advertising are separate questions. The Swiss Unfair Competition Act also restricts mass advertising through telecommunications. B2B relevance or a publicly available address does not establish consent. Review the campaign format, applicable exceptions and specific circumstances with legal counsel.

Can we rely on legitimate interests for EU prospecting

Where GDPR applies, legitimate interests may support some direct marketing data processing after a documented assessment. It does not automatically authorise unsolicited email or override national electronic marketing rules. Assess the recipient jurisdiction, channel, transparency requirements and objection process separately. Stop direct marketing processing when the person exercises their right to object.

What should we ask a Swiss contact list supplier

Ask for original sources, collection dates, verification methods and evidence behind any consent claims. Establish what the consent actually covers, including sender and channel. Check processing roles, transfer arrangements, retention and how corrections or objections are communicated. A verified email address indicates a technical check, not legal permission to send advertising.

Should we delete every record after an unsubscribe

Remove the person from active marketing and stop the relevant processing. Keeping a minimal suppression record may be necessary to prevent accidental recontact, subject to applicable requirements. Limit that record to what serves the suppression purpose, restrict access and document retention. Deleting everything without a suppression mechanism can allow the same contact to enter another campaign.

THE NEXT MOVE IS YOURS.

Your next Swiss client
is already out there.

Let’s find the right companies, start the right conversations and build your Swiss pipeline.

01 / MARKET02 / TARGET03 / ENGAGE04 / QUALIFY05 / MEETING ↗
BOOK A STRATEGY CALL ↗