7 October 2026International edition
Vol. I · No.
7 October 2026
AI in Fashion
DAILY
The daily briefing on AI in the fashion business
Where fashion meets artificial intelligence.
Commerce & Marketing · Checklist

Client data and consent in clienteling: a GDPR and Swiss nFADP checklist

Client books, WhatsApp threads and AI suggestions all process personal data. This checklist covers legal bases, consent, profiling, messaging channels and records for EU and Swiss stores.

KEY TAKEAWAYS Summary by the editors

  1. Clienteling processes personal data at every step, from notes on sizes and preferences to WhatsApp messages and AI-generated suggestions, so it falls under GDPR in the EU and the revised Federal Act on Data Protection (nFADP) in Switzerland.
  2. Under GDPR, direct marketing may rely on legitimate interest where clients can reasonably expect it, but clients can object at any time, including to profiling related to direct marketing, and must then no longer be processed for that purpose.
  3. The Swiss nFADP, in force since 1 September 2023, applies only to data of natural persons, requires privacy by design and by default, and requires express consent for sensitive personal data and high-risk profiling by private persons.
  4. Under the nFADP, fines of up to CHF 250,000 can be imposed on the responsible individuals, which makes clear internal responsibilities important.
  5. Associates' personal phones and private messaging accounts are a major gap: client conversations should run through business tools that log consent and survive staff turnover.

Clienteling in the EU and Switzerland must comply with GDPR and the Swiss revised Federal Act on Data Protection (nFADP). In practice that means a documented legal basis for each use of client data, respect for objections to marketing and profiling, express consent where Swiss law requires it, transparent information at the point of capture, and business-controlled messaging channels. The checklist below turns these rules into steps for store teams, CRM owners and compliance.

This article is editorial guidance, not legal advice. Brands should confirm their set-up with qualified counsel, particularly for national rules on electronic marketing, which sit alongside data protection law.

Which laws apply to clienteling data in Europe and Switzerland?

For stores in the EU and for EU clients, GDPR governs the processing of client data. For Swiss stores and Swiss clients, the nFADP applies; it entered into force on 1 September 2023, covers only data of natural persons, introduced profiling as a legal concept and requires privacy by design and by default. Many brands with stores in both areas apply one common standard based on the stricter rule on each point.

Key differences for clienteling between GDPR and the Swiss nFADP
TopicGDPR (EU)nFADP (Switzerland)
Legal basisA legal basis is required for every processing, such as consent or legitimate interestExpress consent is required only in specific cases, listed below
Direct marketingMay rely on legitimate interest if clients can reasonably expect it; right to object at any timeAllowed within the processing principles; objections must be respected
Express consentExplicit consent is one basis allowing solely automated decisions with significant effectsExpress consent for sensitive personal data and high-risk profiling by private persons
ProfilingDefined; objections to marketing profiling must be honouredDefined since 2023; high-risk profiling subject to stricter rules
Automated decisionsRight not to be subject to solely automated decisions with legal or similarly significant effectsDuty to inform about automated individual decisions
SanctionsEnforcement by national supervisory authoritiesFines of up to CHF 250,000 against responsible individuals

When do you need consent, and when is legitimate interest enough?

Under GDPR Recital 47, processing for direct marketing may be regarded as carried out for a legitimate interest, but the assessment depends on whether clients can reasonably expect the processing at the time and in the context of collection. A client who buys in store and gives an email for receipts does not necessarily expect personalised outreach on WhatsApp. Separate electronic marketing rules often require prior consent for messages by email, text or messaging apps, with limited exceptions for existing customers. Recording explicit opt-ins per channel at capture is therefore the most robust approach.

Read also
AI in clienteling: how next-best-message works, and where privacy sets limits

What does the checklist look like?

  1. Map the data: list every field in the client book, including free-text notes, and remove anything you do not need.
  2. Define purposes: service (orders, alterations), marketing outreach, analytics and AI suggestions, each with a documented legal basis.
  3. Inform at capture: a short, clear notice at the till, in the app and online explaining what is collected, why and how to object.
  4. Record consent per channel (email, SMS, WhatsApp, phone) with date, source and wording, and make it visible in the associate app.
  5. Handle objections fast: a client who objects to marketing must be excluded from marketing and related profiling across all channels.
  6. Avoid sensitive data in notes: health information (for example, notes on pregnancy or medical needs), religion or similar details require express consent and should usually not be recorded.
  7. Assess profiling: check whether AI scoring of clients could amount to high-risk profiling under Swiss law and document the assessment.
  8. Control access: associates see their own clients; exports are restricted and logged.
  9. Set retention periods for inactive clients and delete or anonymise accordingly.
  10. Check transfers: confirm where the clienteling and messaging providers store data and which transfer safeguards apply.
  11. Keep records of processing and a breach response plan that includes notifying the Swiss supervisory authority where required.
  12. Train staff on what to note, what not to note and how to respond to client requests.

What about associates' personal phones and messaging apps?

Many associates message top clients from their own phones. This creates three problems: the brand cannot show consent or answer access requests, client relationships leave with the associate, and data may be stored in places the brand does not control. Business messaging accounts or integrated clienteling tools that log conversations solve most of this. Where personal devices are unavoidable, a clear policy on separation, retention and handover when staff leave is the minimum.

How should AI profiling be handled?

AI suggestions about which clients to contact and what to offer are a form of profiling. Under GDPR Article 21, clients may object at any time to direct marketing, including profiling related to it, and must then no longer be processed for that purpose. GDPR Article 22 adds a right not to be subject to decisions based solely on automated processing that have legal or similarly significant effects, which is relevant if a system automatically excludes clients from offers or sets individual prices. Keeping an associate as the decision maker, documenting the logic in plain language and excluding objected clients from scoring are sensible safeguards.

Read also
How is AI used in physical fashion stores?

What records should you keep?

  • A record of processing activities covering clienteling, unless an exemption for small, low-risk processing applies.
  • Consent logs per client and channel, including withdrawals.
  • Data protection impact assessments for AI profiling or large-scale processing where risks are high.
  • Contracts with clienteling, CRM and messaging providers, including transfer safeguards.
  • A log of access requests and objections and how they were handled.

Frequently asked questions

Does GDPR allow clienteling without consent?

Direct marketing can rely on legitimate interest where clients can reasonably expect it, but electronic marketing rules often require prior consent for emails, texts or messaging apps. Clients can object at any time and must then be excluded from marketing and related profiling.

What changed for clienteling with the Swiss nFADP?

Since 1 September 2023, Swiss law defines profiling, requires privacy by design and by default, and requires express consent for sensitive data and high-risk profiling. Fines of up to CHF 250,000 can be imposed on responsible individuals.

Can store staff keep client notes about health or personal life?

Notes on health, religion or similar topics are sensitive data and require express consent. In most cases such details should not be recorded at all; preferences and sizes are enough for good clienteling.

Is WhatsApp allowed for clienteling in Europe?

It can be used with the client's consent and a business set-up that logs conversations and protects data. Private accounts on personal phones make it hard to prove consent and answer client requests.

GuideThe complete guide to AI in fashion e-commerce, marketing and retailRead the complete guide
Get the Daily

One edition every weekday morning. Read in five minutes. Free for industry professionals.

Newsletter

More on Clienteling

View all