Data Protection

Privacy for company websites

Complete website data protection compliance — fast, flat-fee and done right.

Switzerland's largest law firm focused on tech companies
30+ legal experts — CH and DE data protection specialists
Complete website privacy package implemented within 72 hours
Transparent flat-fee pricing — no hidden costs
Compliant with GDPR & Swiss nFADP
Trusted by 1000+ clients
Trusted by 1'500+ tech companies & investors
Thomas Kuster
"Your website is your most visible figurehead — and one of the most scrutinised assets for data protection compliance. Book a call with me and my team and we'll take care of everything."

Thomas Kuster · Partner @ LEXR  ·  Book your free call →

Trusted by companies who take privacy seriously

Yoko Spirig
The data privacy experts at LEXR provided us with a tailor-made compliance package and were very responsive to all of our questions.
Yoko Spirig
CEO, Ledgy
Sandro Matter
Tapping into LEXR’s expertise and leveraging their advice was a great experience – as great as it can be when dealing with such an uncharming topic like data privacy. We kicked it off with an overall assessment. After that, a clear action plan with specific sub-task ownership and a pragmatic, hands-on approach were the key ingredients for successfully revamping our data privacy setup in view of the revised Data Protection Act.
Sandro Matter
Co-Founder & CFO, vlot

How we solve your challenges

From privacy policy to cookie banner to imprint — everything your website needs to comply with GDPR and the Swiss nFADP, in one package.

We draft or update your website privacy policy to comply with both GDPR and the Swiss Data Protection Act (nFADP). Our policy covers all required disclosures: purpose, legal basis, duration of processing, third-party transfers and user rights — written in plain, precise language.

We create or adapt your cookie policy and draft the text for your cookie consent banner where required. We assess which cookies and tracking technologies (analytics, pixels, social plug-ins) require opt-in consent and which are exempt — matching the rules applicable to your specific audience.

We prepare a legally compliant imprint for your website covering the disclosure requirements under Swiss law, and where relevant German law, including company details, registration numbers and any profession-specific additions.

Beyond the website package, our team offers comprehensive ad-hoc privacy consulting, full data protection compliance checks, data processing agreements, EU Representative services (GDPR Art. 27) and preparation of all internal and external policies your business requires.

The LEXR approach

How we deliver Website Privacy, AI-amplified

Step 01

Matter in

Brief us in plain language — we scope it and route it to the right specialist.

Intake < 4h
Step 02 AI · Privileged

AI does the heavy lifting

Our own AI stack drafts, reviews and cross-checks — inside privilege.

60% fewer draft cycles
Step 03

Senior lawyer signs off

The specialist who built the strategy reviews and signs every output.

Lars Fidan Stephan Meyer Nadine Saalbach
Step 04

Output delivered

On scope, on the quoted price — delivered into your workflow.

Scope and price are fixed in writing before we start — AI absorbs the lift, not your budget.

Our website privacy services

One team handles everything your website needs — from first analysis to completed, integration-ready documents.

Website privacy policyCookie policy & banner textImprint draftingGDPR compliance checkSwiss nFADP complianceData processing agreementsPrivacy consulting

Why LEXR

01

Expert CH & DE data protection lawyers

Our team includes specialists in both Swiss nFADP and EU GDPR. We know the regulatory nuances — from cookie consent requirements to cross-border data transfers — so your website stays compliant across all relevant jurisdictions.

02

Complete package, fast delivery

One mandate covers everything your website needs: privacy policy, cookie policy, banner text and imprint. We deliver within 72 hours of your kick-off call, at a fixed all-inclusive price — no surprise invoices.

03

Pragmatic, business-first advice

We don't bury you in legal complexity. Our experts explain what you actually need, why it matters and exactly how to integrate the documents into your website — so you can get on with running your business.

Website Privacy FAQ

The questions companies ask us most before getting started.

The requirements for a privacy policy are specified by the GDPR and Swiss data protection law. General information about data processing must be provided — such as the purpose, legal basis, duration of data processing and any data transfers to third parties — as well as an indication of the rights of website users. The information must be precise, transparent and in plain language.

A privacy policy is required whenever personal data is collected or processed. This includes not only names and email addresses collected through a contact form, but also the IP address, which is often found in server log files. This means that a website almost always needs a privacy policy.

The requirements in Switzerland are less strict than in the EU. However, if data of EU citizens are processed, it is quite possible that the requirements of the GDPR also apply to Swiss companies. In addition, there are other legal requirements within the EU, such as the e-Privacy Directive. A cookie banner with opt-in functionality is required whenever cookies and other technologies (e.g. pixels) used are not essential to the operation of the website — this includes tracking and analytics tools and social media plug-ins. In any case, information about the use of cookies must always be provided, whether in a banner, a privacy policy or a cookie policy.

In Switzerland, contact information including the company's full address is sufficient. In Germany, the disclosure requirements are more extensive — for example, a registration number, if available, must also be provided. Depending on the professional group, additional requirements may apply.

Let's get your website compliant

Book your free call — we'll have your privacy policy, cookie policy and imprint ready within 72 hours.

Dive deeper into data protection

Data ProtectionAI Features in Your SaaS? What the EU AI Act Means for YouTeam LEXR · Mar 2026Read more →Data ProtectionYou Need to Fix These 5 Points in Your SaaS Agreements Now!Nadine Saalbach · Sep 2025Read more →Data ProtectionNavigating the EU AI Act: A Comprehensive Analysis and Compliance GuideTeam LEXR · May 2024Read more →Data ProtectionNew EU Regulations: A Blueprint for Growth in the Digital SectorTeam LEXR · May 2024Read more →Data ProtectionCybersecurity and data protection: keeping your company's data safeTeam LEXR · Apr 2024Read more →Data ProtectionFrom concept to compliance: Legal Bases for AI training explainedTeam LEXR · Mar 2024Read more →Data ProtectionData Processing Agreements: Navigating the Essentials for Data Protection Compliance (Part 2)Team LEXR · Feb 2024Read more →Data ProtectionData Processing Agreements: Navigating the Essentials for Data Protection Compliance (Part 1)Team LEXR · Jan 2024Read more →Data ProtectionPseudonymisation versus anonymisation: a practical privacy guideTeam LEXR · Dec 2023Read more →Data ProtectionHow to handle data breaches – a privacy best practice guideTeam LEXR · Sep 2023Read more →Data ProtectionNavigating AI tools and data protection: A guide for compliant company practicesTeam LEXR · Jul 2023Read more →Data ProtectionThe new Swiss Data Protection Act comes into force: What tech companies need to do nowTeam LEXR · Jun 2023Read more →Data ProtectionNavigating Privacy Rules for App Developers: App Store Compliance and Privacy RequirementsTeam LEXR · Apr 2023Read more →Data ProtectionKYC for FinTech companies: Data protection guide part 3 - Manage the dataTeam LEXR · Mar 2023Read more →Data ProtectionKYC for FinTech companies: Data protection guide part 2 - Follow the dataTeam LEXR · Feb 2023Read more →Data ProtectionKYC for FinTech companies - Guide to a data protection compliant implementationTeam LEXR · Feb 2023Read more →Data ProtectionChecklist: How to write a privacy policy for the new FADP and GDPR?Team LEXR · Jun 2021Read more →Data ProtectionData Processing Agreement I: Determine whether you are a Controller or a ProcessorTeam LEXR · Apr 2021Read more →Data ProtectionSchrems II impact on privacy shield & SCCsTeam LEXR · Jul 2020Read more →Data ProtectionGDPR impact on AdTech and Real-Time Bidding (RTB)Team LEXR · May 2020Read more →Data ProtectionConfidential Computing and GDPRTeam LEXR · Mar 2020Read more →Data ProtectionThe License to Kill and the right to be forgotten - Gaming in the Age of GDPRTeam LEXR · Mar 2020Read more →Data ProtectionEmployee awareness as the key to security and data privacyTeam LEXR · Feb 2020Read more →Data ProtectionThe Internet of Things in the GDPR eraTeam LEXR · Jan 2020Read more →Data ProtectionGDPR in Switzerland - What it means for businessesTeam LEXR · Dec 2018Read more →