Newsletters, text message discounts and event invitations are indispensable marketing tools for many businesses. However, any business that continues to send marketing messages to customers despite them having unsubscribed, or ignores requests to have their data deleted, risks more than just upsetting recipients. A new decision by the FDPIC makes it clear: Opt-out means opt-out — and data protection in marketing must work in practice.
The ruling also makes it clear that it is not merely a question of whether companies formulate their marketing rules correctly on paper. Objections and requests for deletion must actually be implemented across all systems and communication channels.
FDPIC ruling against Philipp Plein: What is it about?
In a decision dated 17 April 2026, the Federal Data Protection and Information Commissioner (FDPIC) concluded proceedings against Cream della Cream Switzerland GmbH and Philipp Plein International AG. The proceedings were triggered by several complaints from data subjects who claimed to have continued to receive marketing messages by email or text message despite having objected. The FDPIC published a statement on the matter; the decision became final once the appeal period had expired.
According to the EDÖB’s findings, customers had received marketing messages – including information on discounts and events – following purchases in physical or online shops. According to the data subjects, in some cases consent for this data processing had never been given. However, the order does not conclusively determine whether the initial marketing contact was therefore unlawful. Rather, the decisive factor in the decision was that the marketing continued despite subsequent explicit objections. In some cases, the deletion was confirmed without the marketing contact actually ceasing.
The case therefore concerns more than just traditional newsletter compliance. Rather, it demonstrates that companies must set up their marketing databases, CRM systems, newsletter tools and deletion processes – both organisationally and technically – in such a way that objections and requests for deletion are reliably implemented.
Two legal questions must be distinguished: Is advertising permitted – and is it permissible to continue advertising?
In practice, it is important to make a distinction that is often lost in the discussion about newsletters. On the one hand, the question arises as to the conditions under which a person may be sent advertising via email or text message in the first place. On the other hand, it must be examined what happens after that person has expressly objected to the use of their data. The FDPIC’s decision focuses on the second question.
In addition, the Federal Act against Unfair Competition (UWG, SR 241) must be taken into account for mass electronic advertising. According to the legal position outlined by the EDÖB, email advertising generally requires prior explicit consent. An exception applies, in particular, within the context of an existing customer relationship for the advertising of the company’s own similar products or services. Even in such cases, however, there must be a simple and free-of-charge option to opt out of further advertising. The requirements of the UWG and those of the Data Protection Act (DSG, SR 235.1) must therefore be assessed in conjunction with one another.
The fact that, in this specific case, some text messages did not include a straightforward option to unsubscribe and that, according to the data subjects’ documentation, the email unsubscribe links did not work is therefore not merely a technical detail. An opt-out option that appears on the screen but has no effect in the backend does not fulfil its function.
Advertising constitutes data processing
The FDPIC makes it clear: anyone who uses email addresses or telephone numbers to send advertising to identifiable customers via email or SMS is processing personal data. Under Article 5(a) of the Data Protection Act (DSG), personal data is defined as any information relating to an identified or identifiable natural person; under Article 5(d) of the DSG, processing is defined in particular as the collection, storage, use, disclosure, erasure or destruction of such data.
This has practical implications for businesses. Marketing data is not ‘merely’ contact details. As soon as it is used for direct marketing, it is subject to the principles of data protection law. These include, in particular, purpose limitation, proportionality, transparency, data minimisation and good faith. Anyone who originally collects data in the context of a sale may not use it arbitrarily and without restriction for marketing purposes.
The right to object under the Swiss Data Protection Act (DSG)
At the heart of the decision is Article 30(2)(b) of the Swiss Data Protection Act (DSG). According to this provision, an infringement of personal rights occurs, in particular, when personal data is processed contrary to the express wishes of the data subject. The FDPIC concludes from this that anyone who objects to advertising does not need to provide any further justification as to why they no longer wish to receive it. An explicit statement is sufficient. In this specific case, the data subjects had objected via various channels: by email, by telephone or via contact forms.
Legally, however, the assessment is carried out in two stages: continued processing in defiance of an explicit objection initially constitutes an infringement of personal rights under Article 30(2)(b) of the Data Protection Act. The infringement of personal rights is unlawful if there is no justification under Article 31 of the Data Protection Act – such as consent, an overriding private or public interest, or a legal basis. Following the decision, it was incumbent on the responsible companies to demonstrate such a justification. However, they failed to do so; nor did any such justification arise from the facts established by the FDPIC. Consequently, the continued processing for marketing purposes was unlawful.
It is important to note in practice that the right to object must not merely exist in law; it must also function in practice. A newsletter link that is formally present but does not effectively allow users to unsubscribe is not sufficient. The same applies to SMS advertising without a simple opt-out option. During the proceedings, the FDPIC expressly emphasised that an effective and swift unsubscribe procedure must be available.
Companies should therefore be able to recognise objections regardless of the channel through which they are received. For example, anyone who informs customer services by email that they no longer wish to receive advertising must not, as a matter of principle, be told to first use a specific newsletter link. What is decisive is the clearly expressed statement of intent – not the technical channel preferred by the company.
Deletion does not mean: continue advertising
In addition to objections to advertising, the issue concerned requests for erasure. In the opinion of the FDPIC, the FADP establishes a right to the erasure, destruction or anonymisation of data if it is no longer required for the original purpose and there is no justification for its continued retention. The law also obliges data controllers to retain data only for as long as is necessary for the purpose of processing.
However, the right to erasure is not absolute. A statutory retention obligation or an overriding private interest may justify the continued storage of certain data. The EDÖB therefore expressly states that erasure may be demanded provided there is no justification for continued retention. Such permissible retention does not, however, mean that the data may continue to be used for marketing purposes. The purpose of retention and the marketing purpose must be assessed separately.
The assessment is particularly stringent in cases where a company confirms deletion but the data subject continues to receive advertising. The FDPIC regarded this not only as processing contrary to the data subject’s expressed wishes, but also as a breach of the principle of good faith. Anyone who promises to delete data must ensure internally that this promise is implemented in all relevant systems.
In this specific case, two separate data protection considerations therefore converge: continued processing following an objection infringes Article 30(2)(b) of the Data Protection Act (DSG). If, in addition, deletion has been confirmed and the data is nevertheless processed further, this constitutes, in the opinion of the EDÖB, a breach of good faith under Article 6(2) of the DSG and thus also an infringement of personal rights under Article 30(2)(a) of the DSG.
In practice, this is often the weak point. Customer data is not stored in just one system. It is held in shop systems, CRM solutions, newsletter tools, event databases, customer service systems, backups or with external marketing service providers. Deletion from one system is not sufficient if the same address continues to be used in another list.
Companies should therefore make a technical distinction between deletion and marketing blocking. Data which, for example, must still be retained for legal reasons must, in any case, be blocked for marketing purposes. If data is deleted in its entirety, it must also be checked whether, and in what form, a restriction notice – reduced to the necessary minimum – is required and justified under data protection law, in order to prevent the same address from subsequently being re-included in a marketing campaign from a legacy system or an external list. Such a solution should be purpose-limited, subject to restricted access and documented. The FDPIC points out in general that, where there are existing grounds for justification, blocking the data may also be considered as an alternative to complete deletion.
International companies: An objection must not be thwarted by corporate or system boundaries
The decision contains a further point relevant to international e-commerce groups. The FDPIC regarded both Cream della Cream Switzerland GmbH and Philipp Plein International AG as data controllers; according to the privacy policy examined, both companies were responsible for personal data, whilst Cream della Cream was specifically responsible for the website. Furthermore, the advertisements concerned individuals in several European countries. The FDPIC noted that, where data is processed in Switzerland, the data subject’s place of residence or nationality is not decisive for the applicability of the Data Protection Act (DSG).
For corporate groups, this raises a practical governance issue: it must be clear which company receives an objection, which systems are affected, and how the signal is passed on group-wide to CRM, shop, loyalty, event and dispatch solutions. An organisational issue regarding responsibility must not result in a person being targeted with advertising again via a different system or through another group company.
The FDPIC can issue binding orders and threaten sanctions
The decision is also noteworthy because the EDÖB did not stop at an informal intervention. After receiving no response to initial notifications and a subsequent letter, the EDÖB opened a formal investigation under Article 49(1) of the Data Protection Act (DSG). The Data Protection Act (DSG) allows the EDÖB to launch investigations where there are sufficient indications that data processing may contravene data protection regulations.
The order requires the companies concerned to immediately cease processing personal data for advertising purposes where a data subject has objected, to comply with requests for erasure, and to take into account any objections or requests for erasure that have already been made. Compliance must take place no later than 30 days after the decision becomes final. In addition, fees of CHF 5,500 have been imposed.
However, this 30-day period must not be understood as a general ‘processing period’ for future newsletter unsubscriptions. Rather, the order requires that data processing for advertising purposes be ceased immediately upon receipt of an objection; the 30 days referred to the implementation of the ordered measures once the specific order has become final.
The threat of a penalty is particularly relevant in practice: Anyone who wilfully fails to comply with a decision by the FDPIC may be fined up to CHF 250,000 under Article 63 of the Data Protection Act (DSG). In the case of legal entities, the decision, based on Article 29 of the Swiss Criminal Code (StGB), expressly identifies the natural persons within the company who are responsible for compliance. This is to be distinguished from the CHF 5,500: these are fees for the supervisory proceedings or the measures ordered, not a fine for the original data protection breach.
Checklist: What companies should review now
For e-commerce providers, retailers, event organisers, platform operators and companies with centralised CRM or loyalty systems, the following practical checklist can be derived from the decision:
- Check the legal basis for advertising: Is there valid consent for email and SMS campaigns, or are the conditions for permissible marketing to existing customers met? Are the sender and a simple, free opt-out option clearly identifiable?
- Record all opt-out channels: Can customer service, the data protection officer, marketing and sales identify opt-outs via email, telephone, web form or other channels and forward them immediately?
- Implement a centralised advertising block: Is an opt-out transmitted, where possible in real time, to the CRM, newsletter system, SMS service provider, online shop, loyalty system and events database?
- Test unsubscribe links regularly: Does the link actually work technically right through to the blocking mechanism in the mailing backend? Are faulty or out-of-sync systems also detected?
- Define the deletion process across all systems: Is it known in which production systems, archives and with which service providers customer data is stored? Is a distinction made between data to be deleted and data that must be retained for a legitimate reason?
- Prevent reactivation via data imports: Is it ensured that a blocked address cannot be reactivated via a CRM import, an old event list, an external service provider or another group company?
- Document evidence and responsibilities: Is it possible to trace when an objection was received, when it was implemented and which systems were affected? Is it clearly defined internally who is responsible for this?
- Establish an escalation process: Complaints about advertising despite unsubscription should not be treated as ordinary customer service tickets. Repeated complaints are a compliance red flag and should be escalated to data protection or legal officers.
Conclusion: Marketing compliance is not a form, but a process
The FDPIC ruling shows that data protection-compliant marketing does not end with the consent text or the unsubscribe link. What matters is whether objections and requests for erasure are effectively implemented in practice. Companies that continue to send advertising to individuals who have unsubscribed or requested erasure risk binding orders, fees, reputational damage and, in the event of non-compliance with a decision, substantial fines.
For companies, the key lesson therefore lies less in the front end than in the back end: a functioning unsubscribe link is only the beginning. What is crucial is a robust process, a centralised and cross-system blocking mechanism, clear responsibilities, and the distinction between necessary data retention and unauthorised further use for marketing purposes.
Our specialists in e-commerce and advertising are happy to assist companies, where required, with the legal and technical assessment of such marketing and opt-out processes.
Sources
- FDPIC announcement: FDPIC decision against Cream della Cream Switzerland GmbH and Philipp Plein International AG
- FDPIC: Decision of 17 April 2026, Investigation pursuant to Article 49 of the Data Protection Act (LPD) against Cream della Cream Switzerland GmbH and Philipp Plein International AG
- Federal Act on Data Protection, DSG
- Federal Act against Unfair Competition (UWG)