Guides
Digital business cards and data protection: what Swiss companies must check
Updated on September 23, 2026
In short
A digital business card contains employees' personal data, so the company that publishes it is the controller under the revised Swiss FADP and, with contacts in the EU, the GDPR. In practice: publish only business contact data, inform employees, choose a provider with a clear contract, and deactivate cards when people leave.
Which data are involved, and who is responsible?
A digital business card shows what a paper card shows: name, role, company, phone number, email address, often a photo. These are the employee's personal data. The company that publishes the cards is the controller: it decides which data appear and for what purpose. The platform provider processes the data on the company's behalf and is the processor.
The same data are already on paper cards and in email signatures. What changes is the medium: the card page is online, reachable by anyone with the link, and stored on a provider's servers. So the questions below deserve an answer before rollout.
What do the revised FADP and the GDPR require in practice?
The revised Federal Act on Data Protection (revised FADP) has been in force in Switzerland since 1 September 2023. The GDPR applies in addition where a company has customers or contacts in the EU or EEA. For a business card project, both come down to a few practical points:
- Proportionality: publish only the data needed for business contact.
- Transparency: employees know what is published and can review their card.
- A data processing agreement with the provider that says where the data are stored.
- Rights of the persons concerned: access, rectification and deletion.
This guide is general information, not legal advice. Check the details with your data protection officer or your lawyer.
What should you check in a provider?
This checklist works for any provider; the third column shows how bizCARD answers today. Ask for the answers in writing before you sign.
| Question | Why it matters | How bizCARD answers |
|---|---|---|
| Where are the data stored? | Decides which authorities can access them. | Vercel and Neon, both in European data centres. |
| Which law governs the contract? | A Swiss contract is easier to enforce. | Swiss law, jurisdiction Lugano; dambox Sagl, a Swiss limited company. FADP and, where applicable, GDPR. |
| Who edits or deactivates cards, and what about leavers? | A card that outlives the employment is a data protection problem. | Admins, at any time. Enterprise: SCIM deactivates the card when the directory account is disabled. |
| Which statistics are collected? | Visitor tracking can itself be personal data. | Aggregated scans and visits; no tracking of the person who scans. |
| Are data sold? Who are the sub-processors? | Contact data are valuable to advertisers. | Only what the service needs, never sold. Vercel, Neon and Stripe for payments; card data never touch bizCARD servers. Plus the email service for notifications; the full list is in the privacy policy. |
| Export and deletion at contract end? | You must be able to take your data with you. | Rights of access, rectification and deletion; agree the procedure in writing. |
The card page: public by design
A card page is a web page: anyone with the link or the QR code sees it, without logging in. That is the point, but it also means the page should be treated like a page on the company website, not like a private record. Publish only business contact data: a private mobile number only if the employee agrees, a photo only with the employee's consent. Check what is shown on the page and what sits behind a tap, in the vCard download.
Joiners and leavers
Most data protection incidents with business cards are not hacks. They are cards that stay online for months after someone has left. Define who creates cards on joining and who deactivates them on leaving, and put both on the onboarding and offboarding checklists. Admins can deactivate a card at any time; in the Enterprise plan, SSO and SCIM link the card to the directory, so a disabled account deactivates the card with it.
Five rules for a compliant rollout
- Publish only business contact data: name, role, company, business phone and email.
- Tell employees what is published and let them review their card before it goes live.
- Check the provider with the checklist above and keep the answers in writing.
- Give a few admins the right to edit and deactivate cards, and name a deputy.
- Put the card on the offboarding checklist, or automate it with SSO and SCIM.
Frequently asked questions
Do we need employee consent to publish a digital business card?
A card usually shows data the company already shares on paper cards and in email signatures. Inform employees, let them review their card, and ask for their agreement for a photo or a private number. Whether formal consent is needed is a question for your data protection officer.
Does the GDPR apply to a Swiss company?
The revised FADP applies to every company in Switzerland. The GDPR applies in addition where you have customers or contacts in the EU or EEA. Check your case with your lawyer.
Where does bizCARD store the data?
The application runs on Vercel and the database on Neon, both in European data centres. bizCARD is operated by dambox Sagl, a Swiss limited company, under Swiss law with place of jurisdiction in Lugano.
What happens to the card when an employee leaves?
Admins can deactivate it at any time. In the Enterprise plan, SCIM provisioning with Microsoft Entra ID or Google Workspace deactivates the card when the account is disabled in the directory.
Do the card statistics track the people who scan?
No. Scan and visit statistics are aggregated; the person who scans is not tracked beyond what the browser sends with any web request.