Data Protection for Invoices: What the Swiss DPA Requires
An invoice contains personal data — names, addresses, sometimes more. The Swiss Data Protection Act (revDSG) sets rules for handling it.
What invoices contain
Client names, addresses, contact details, and payment information are all personal data. You are responsible for how that data is collected, stored and protected.
An invoice routinely holds a name, address, email and payment details. Under the revised Swiss Data Protection Act all of this counts as personal data.
The definition of personal data is broad: any information relating to an identified or identifiable person. Your invoices are full of it, which is why the law applies.
Responsibility sits with you as the controller. How you collect, store, protect and eventually delete that data is your legal obligation, not an optional nicety.
- Names and addresses.
- Contact details.
- Payment information.
Your obligations
Collect only what you need, protect it against unauthorised access, and delete it when you no longer need it — subject to the 10-year retention obligation for accounting records.
The principle of data minimisation means you should hold only the personal data your invoicing genuinely requires. Extra fields are extra risk.
Protect the data with access controls, so only people who need it can see it. An unencrypted folder open to everyone is a breach waiting to happen.
Deletion is required once the data is no longer needed, but accounting law obliges you to keep invoices for 10 years. The retention obligation overrides the deletion duty during that period.
- Collect only what is necessary.
- Protect against unauthorised access.
- Delete when no longer needed (after retention periods).
Practical steps
Store invoices in a system with access control, not an unencrypted shared folder. And do not send sensitive financial documents over unsecured channels.
Use invoicing and storage systems that enforce access control and logging. Knowing who viewed a record is part of demonstrating you protect the data.
Send invoices and payment documents over secure channels rather than plain, unencrypted email where possible. Encryption or a secure client portal is the safer default.
Train anyone who handles invoices on the basic rules. Most data protection failures are human slips, not technical vulnerabilities.
- Use systems with access control.
- Send over secure channels.
- Train anyone handling invoices.
Handle requests and breaches
The revised DPA gives individuals rights over their data, and it requires you to respond. Know how to react when a client asks about their data.
A client can ask what personal data you hold about them and request its correction or deletion, subject to your legal retention duties. Have a simple process to answer these requests.
If a data breach affects invoice data, the law may require you to report it. Have a plan for who to notify and when, rather than improvising during an incident.
Keep your data protection effort proportionate to your size. A small business needs clear habits and a basic register of processing, not a full compliance department.
Related reading — AI and the Swiss Data Protection Act on strongwinds.ch: practical AI routines for Swiss freelancers and SMEs.
Create compliant Swiss QR-bills in minutes
facturio generates SIX-compliant QR-bills with every invoice — so you can focus on your work, not the paperwork.
Start free