Switzerland
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Switzerland is easy to send data out of, as long as the destination is one the government trusts. An official list names about 44 approved places, including every European Union country and United States firms in one certification scheme. Anywhere else, you sign an approved contract first. The sting is elsewhere: getting it wrong is a crime, and the case lands on a person, not the company.
Eight questions about Switzerland
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Switzerland's rules apply to my company?
Yes. Swiss privacy law reaches any organisation whose activities have an effect in Switzerland, even one with no office, staff or company here. There is no revenue or headcount threshold to duck under, and there is no register to sign up to. You only need a named representative inside Switzerland if four things are true at once: you are selling to people here or watching what they do, you are doing it on a large scale, you are doing it regularly, and the processing is high risk for the people involved. Very few foreign companies meet all four.
Article 3 paragraph 1 of the Data Protection Act codifies the effects doctrine: the Act applies to circumstances that have an effect in Switzerland even if initiated abroad. Article 14 sets the four cumulative conditions for appointing a Swiss representative (offer of goods or services or behaviour monitoring, large scale, regular, and high risk to the personality of data subjects). The representative is a contact point for data subjects and for the Federal Data Protection and Information Commissioner, and the name and address must be published. Note the scope split in Article 2 paragraph 1: the federal Act covers private persons and FEDERAL bodies only. Cantonal and communal authorities, cantonal public hospitals and cantonal schools are governed by 26 separate cantonal data protection laws with their own cantonal commissioners. There is also a size-based relief in Article 24 of the Data Protection Ordinance: private organisations with fewer than 250 employees on 1 January of a given year are exempt from keeping a record of processing activities, unless they process a large volume of sensitive personal data or carry out high-risk profiling.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 3 (territorial scope of application)
fedlex.data.admin.ch
“This Act applies to circumstances that have an effect in Switzerland, even if they were initiated abroad.”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 14 (representative)
fedlex.data.admin.ch
“Private controllers with registered office or domicile abroad shall appoint a representative in Switzerland if they process the personal data of persons in Switzerland and the data processing meets the following requirements...”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Ordinance, Article 24 (exemption from the record of processing activities)
fedlex.data.admin.ch
“Undertakings and other private organisations employing fewer than 250 employees on 1 January of any year and natural persons are exempt from the obligation to keep a record of processing activities unless...”
Link checked 18 August 2026
Can I store my users' data outside Switzerland?
In general, yes. Switzerland publishes an official list of countries and territories it considers safe, and data can move to any of them with no extra paperwork. The list has about 44 entries. It covers all 27 European Union countries, the United Kingdom, Norway, Iceland, Liechtenstein, Canada, Israel, Argentina, Uruguay and New Zealand. It covers the United States only for companies signed up to one specific certification scheme. Japan is not on it, even though the European Union treats Japan as safe. For anywhere not on the list, you sign an approved contract first. But three industries override this completely, and one of them is an outright ban.
Headline rating: sectoral. The national baseline on its own would be 'conditional'. Sector by sector, as verified on 18 August 2026: HEALTH - electronic patient record: CLOSED. Article 12 paragraph 5 of the Electronic Patient Record Ordinance states that the data stores must be located in Switzerland and subject to Swiss law. The same applies under Article 25 paragraph 6 to issuers of the identification means used to log in. This is the only flat storage-location ban we found in Swiss federal law. HEALTH - everything else: CONDITIONAL, but with criminal exposure. Ordinary medical records outside the electronic patient record system are not location-restricted, but doctors, nurses, pharmacists and psychologists are bound by the criminal professional secrecy rule in Article 321 of the Criminal Code. BANKING: CONDITIONAL with a criminal wall. There is no rule saying bank data must stay in Switzerland. Article 47 of the Banking Act makes deliberately revealing a banking secret a criminal offence punishable by up to three years in prison, rising to five where the person makes money out of it, and up to 250,000 francs for doing it carelessly. Separately, the regulator's outsourcing circular allows offshoring only if the bank can guarantee that it, its auditor and the regulator can enforce inspection and audit rights, and only if the information needed to restructure or wind up the bank remains accessible in Switzerland at all times. That last sentence is a partial mirroring requirement. INSURANCE: same as banking on outsourcing. The regulator's outsourcing circular covers insurance companies as well as banks and certain investment firms. Insurers have no equivalent criminal secrecy article. SECURITIES AND MARKET INFRASTRUCTURE: CONDITIONAL, case by case. Under Article 11 of the Financial Market Infrastructure Act a stock exchange, central counterparty, central securities depository, trade repository or payment system must obtain the regulator's prior approval before outsourcing a material service such as risk management. Under Article 104 paragraph 4, where a derivative trade is reported to a recognised FOREIGN trade repository and the extra fields include personal data, the individual's consent must be obtained. TELECOMS: CONDITIONAL. No storage-location rule was found. Providers must retain connection metadata for six months and must grant the surveillance service immediate access to their facilities, which in practice pins the retained data to systems the Swiss authorities can reach. GOVERNMENT AND PUBLIC SECTOR: CONDITIONAL by procurement, not by statute. The Swiss Government Cloud programme, budgeted at 246.9 million francs and running from 2025 to 2032, is built in three tiers, of which one, 'Public Cloud Schweiz', is defined by data being held and processed in Switzerland, and another, 'Private Cloud Bund', keeps data in federal data centres. This is a purchasing policy, so it binds suppliers through contracts rather than through law. PROFESSIONS UNDER LEGAL SECRECY: CONDITIONAL with a criminal wall. Article 321 of the Criminal Code covers clergy, lawyers, defence counsel, notaries, patent attorneys, auditors, doctors, dentists, chiropractors, pharmacists, midwives, psychologists, nurses, physiotherapists, occupational therapists, dieticians, optometrists and osteopaths, and their auxiliaries. MAPPING AND GEOSPATIAL: no location rule found, checked 18 August 2026, confidence medium. The Geoinformation Ordinance sorts official geodata into three access tiers, publicly accessible, restricted, and not public, but says nothing about where the data may be stored. EDUCATION, GAMING, E-COMMERCE, DEFENCE: no sector-specific storage-location rule found in federal law, checked 18 August 2026, confidence medium. Cantonal law governs state schools and cantonal universities.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Ordinance, Annex 1 - states, territories and sectors guaranteeing an adequate level of data protection
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 16 (principles for disclosure abroad)
fedlex.data.admin.ch
“Personal data may be disclosed abroad if the Federal Council has decided that the legislation of the State concerned or the international body guarantees an adequate level of protection.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexOrdinance on the Electronic Patient Record (EPDV), Article 12 paragraph 5
fedlex.data.admin.ch
“Die Datenspeicher muessen sich in der Schweiz befinden und dem Schweizer Recht unterstehen.”
Link checked 18 August 2026
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA Circular 2018/3 'Outsourcing - banks, insurance companies and selected financial institutions', section G, Outsourcing abroad
finma.ch
“Outsourcing to another country is admissible if the company can expressly guarantee that it, its audit firm and FINMA can assert and enforce their right to inspect and audit information. The possibility of restructuring or resolving the company in Switzerland must be assured. Access to the information required for this purpose must be possible in Switzerland at all times.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexFinancial Market Infrastructure Act, Articles 11 and 104
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Council / FedlexGeoinformation Ordinance, Article 21 (access authorisation levels for official geodata)
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Office of Information Technology, Systems and Telecommunication FOITTSwiss Government Cloud - three-tier design, including a Swiss-only public cloud tier
bit.admin.ch
Link checked 18 August 2026
What do I need in place before data leaves Switzerland?
The model is an approved-destinations list, and it is well populated: about 44 countries, territories and one sector-specific entry are on it right now. Send data to a listed place and you need nothing at all. Send it anywhere else and you need one of a short menu of safeguards, the most common being a standard contract. Switzerland has formally accepted the European Union's standard contract template, so most companies can reuse the paperwork they already have.
Model: allowlist, currently populated. Annex 1 of the Data Protection Ordinance lists 44 numbered entries. Entry 44 is the United States, and it is narrow: adequacy is recognised only for organisations certified under the Swiss-United States Data Privacy Framework, resting on Executive Order 14086, the Data Protection Review Court rule, Intelligence Community Directive 126, and the designation of Switzerland on 7 June 2024 as a country covered by the two-layer redress mechanism. That entry was inserted by the ordinance of 14 August 2024, in force since 15 September 2024, and was still in place in the consolidation dated 1 December 2025. Canada is qualified: adequacy applies where the federal private-sector privacy law, or a substantially similar provincial law, applies. Where the destination is not listed, Article 16 paragraph 2 gives five routes: a treaty under international law; data protection clauses in a specific agreement, notified to the Commissioner beforehand; specific guarantees drawn up by a federal body, notified beforehand; standard data protection clauses the Commissioner has approved, issued or recognised; or binding corporate rules approved by the Commissioner or by an authority in an adequate country. In a document dated 12 February 2025 the Commissioner recognised both the European Union's 2021 standard contractual clauses and the Council of Europe's model contractual clauses. Using recognised standard clauses does not have to be notified. Ad-hoc clauses in a single contract do have to be notified first. The Commissioner must respond within 90 days on standard clauses and on binding corporate rules. Article 17 adds six narrow one-off exceptions, including explicit consent, contract necessity, overriding public interest, legal claims, protecting life, and data the person has made public. These are for isolated cases, not for routine bulk flows. A divergence worth knowing: Switzerland's list is not a copy of the European Union's. Japan and South Korea have European Union adequacy decisions and do NOT appear in the Swiss annex. A company that assumes 'adequate for Europe means adequate for Switzerland' will be running an unlawful, and criminally punishable, transfer. The Commissioner's guidance adds a step that catches people out: contractual clauses only bind the parties to the contract, so where the destination country's law permits disproportionate authority access, technical measures on top of the contract may be required. And the Commissioner states plainly that a transfer failing Articles 16 and 17 may carry criminal consequences under Article 61 letter a.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Ordinance, Annex 1 (44 listed destinations, United States limited to Data Privacy Framework certified organisations)
fedlex.data.admin.ch
“For personal data processed by organisations certified under the Principles of the Swiss-US Privacy Framework, an adequate level of protection is deemed to be guaranteed...”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 16 paragraph 2 (safeguards where no adequacy decision exists)
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 17 (narrow exceptions)
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC - Cross-border transfer of personal data
edoeb.admin.ch
“If data is disclosed abroad and the conditions set out in Articles 16 and 17 FADP are not met, this may have consequences under criminal law (Art. 61 let. a FADP).”
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC recognition of the EU Standard Contractual Clauses and the Council of Europe Model Contractual Clauses, 12 February 2025
edoeb.admin.ch
Link checked 18 August 2026
Who enforces the rules in Switzerland, and what can they do?
The main regulator is the Federal Data Protection and Information Commissioner. It is real, fully staffed and busy: in the year to 31 March 2026 it ran 156 low-level interventions, 22 preliminary enquiries and 9 formal investigations, and it had 2 cases running in the Federal Administrative Court. It has issued binding orders against a bank, a debt collection firm and a fashion group, and in October 2025 the court confirmed its new way of working. The catch is that this regulator cannot fine anyone. Fines under the privacy law are criminal, they are handed out by cantonal prosecutors, and they land on individual people.
Rating: active. Commissioner: Adrian Lobsiger. Deputy Commissioner: Florence Henguely. Reported workload for 1 April 2025 to 31 March 2026: 156 low-threshold interventions, 22 preliminary enquiries, 9 investigations under Article 49 of the Data Protection Act, 2 matters pending before the Federal Administrative Court. Roughly half the office's effort goes on advisory work rather than supervision. Observable decisions: a ruling of 29 January 2025 against Cembra Money Bank on the legal deadlines for handling access requests; a ruling of 28 April 2025 against Inkasso-Team AG on publishing debtors' names online, later tested in Federal Administrative Court judgment A-3891/2025 of 22 June 2026; an instruction of 16 May 2025 to PostFinance on the use of voice biometrics; a ruling of 17 April 2026 against Cream della Cream Switzerland and Philipp Plein International, published on 4 August 2026. In February and March 2026 the Commissioner ran a preliminary investigation into Meta Platforms Ireland over an artificial intelligence feature, and on 3 March 2026 opened a formal investigation into an artificial-intelligence age-verification provider. The Federal Administrative Court judgment of 6 October 2025 upholding the ruling against Buergerforum Schweiz is described by the Commissioner as the first legally binding validation of its new decision-making practice. Other regulators that matter more than the privacy one in their own lanes: - FINMA, the financial market supervisor, which authorises outsourcing by market infrastructures, enforces the outsourcing circular and takes cyber-attack reports. - The Federal Office for Cyber Security, which receives the 24-hour critical-infrastructure incident reports and can issue enforceable orders. - The Post and Telecommunications Surveillance Service, part of the Federal Department of Justice and Police, which is plainly operational: in 2025 it handled 1,878 real-time interceptions, 6,531 retroactive surveillance measures and 650,034 simple information requests, with total measures up about 40 per cent on 2024. - The Federal Office of Public Health, which supervises the electronic patient record system. - 26 cantonal data protection authorities for cantonal and communal bodies. Why not 'aggressive': the Commissioner has no power to impose administrative fines at all. Criminal fines under Articles 60 to 63 are capped at 250,000 francs, apply only to natural persons who act wilfully, and in most cases only on complaint. We found no evidence of a criminal privacy conviction in Switzerland during the review period.
Sources
- Official sourceFederal Data Protection and Information Commissioner33rd Annual Report 2025/2026 of the FDPIC, key figures and supervision chapter
edoeb.admin.ch
“156 Low-threshold interventions / 22 Preliminary enquiries / 9 Investigations Art. 49 FADP / 2 pending before FAC”
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC - Findings and rulings (published rulings 2024, 2025, 2026)
edoeb.admin.ch
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC annual report page - 33rd Annual Report published 30 June 2026
edoeb.admin.ch
Link checked 18 August 2026
- Official sourceSwiss Federal Council / Post and Telecommunications Surveillance ServiceFederal Council media release, 28 April 2026 - telecommunications surveillance statistics 2025
admin.ch
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Articles 60 to 65 (criminal provisions, prosecution a matter for the cantons)
fedlex.data.admin.ch
“Die Verfolgung und die Beurteilung der strafbaren Handlungen sind Sache der Kantone.”
Link checked 18 August 2026
How long do I have to keep the data?
Both directions apply and they pull against each other. The floor: business books, accounting records and audit reports must be kept for ten years. Financial market infrastructures keep their records ten years, trade repositories keep trade data ten years after the contract matures, electronic patient record access logs are kept ten years, and telecoms companies keep connection records for six months. The ceiling: the privacy law says personal data must be destroyed or made anonymous as soon as it is no longer needed. There is no fixed number. Where the two clash, the specific legal duty to keep wins.
FLOOR, verified: - Code of Obligations Article 958f: business books, accounting vouchers, the annual report and the audit report must be kept for ten years, counted from the end of the financial year. Electronic storage is allowed provided the records can be made readable again at any time. - Financial Market Infrastructure Act Article 19: financial market infrastructures record and keep all records of services, procedures and activities for ten years. - Financial Market Infrastructure Act Article 75: a trade repository keeps reported data for at least ten years after the derivative contract matures. - Financial Market Infrastructure Act Article 106: counterparties keep derivative trade vouchers under the ten-year rule in the Code of Obligations. - Electronic Patient Record Act Article 10 paragraph 3: access log data must be kept for ten years. - Telecommunications Surveillance Act Article 26 paragraph 5: providers of telecommunications services must keep connection metadata for six months. CEILING, verified: - Data Protection Act Article 6 paragraph 4: personal data shall be destroyed or anonymised as soon as it is no longer required for the purpose of processing. No number is given. The duty is tied to purpose, so the retention period is whatever you can justify. - Article 6 paragraph 3 limits further use to purposes compatible with the one the person could recognise at collection. HOW THE CONFLICT RESOLVES: a specific statutory duty to retain is a legal obligation, and under Article 31 of the Data Protection Act a processing that would otherwise breach the principles can be justified by law. In practice Swiss controllers keep the ten-year accounting set and delete the rest on a purpose-based schedule. The trap is the reverse direction: an internal 'keep everything for ten years' policy applied to marketing data, browsing logs or job applicant files has no legal basis and breaches Article 6 paragraph 4. No statutory maximum retention period was found for any general category of personal data, checked 18 August 2026.
Sources
- Official sourceFederal Council / FedlexCode of Obligations, Article 958f (ten-year retention of business books and accounting vouchers)
fedlex.data.admin.ch
“Die Geschaeftsbuecher und die Buchungsbelege sowie der Geschaeftsbericht und der Revisionsbericht sind waehrend zehn Jahren aufzubewahren.”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 6 paragraph 4 (destruction or anonymisation once no longer needed)
fedlex.data.admin.ch
“They shall be destroyed or anonymised as soon as they are no longer required for the purpose of processing.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexFinancial Market Infrastructure Act, Articles 19, 75 and 106 (ten-year record retention)
fedlex.data.admin.ch
“Das Transaktionsregister zeichnet die gemeldeten Daten auf und bewahrt sie waehrend mindestens zehn Jahren nach der Faelligkeit des Kontrakts auf.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexTelecommunications Surveillance Act, Article 26 paragraph 5 (six-month metadata retention)
fedlex.data.admin.ch
“Providers of telecommunications services must retain the secondary telecommunications data of telecommunications for 6 months.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexElectronic Patient Record Act, Article 10 paragraph 3 (ten-year log retention)
fedlex.data.admin.ch
“Die Protokolldaten sind zehn Jahre aufzubewahren.”
Link checked 18 August 2026
What happens if there is a breach?
Count four clocks, not one. The privacy regulator must be told 'as quickly as possible' when a breach is likely to put people at serious risk, with no number of hours attached. If you run critical infrastructure, you have a hard 24 hours to tell the national cyber security office. If you are supervised by the financial regulator, you have 24 hours to notify your supervisor and 72 hours to file the full report. Electronic patient record communities have to report security incidents to the health office. Most failures come from teams who set a single deadline and miss the others.
CLOCK 1 - privacy regulator. Data Protection Act Article 24: the controller notifies the Commissioner of any data security breach likely to lead to a HIGH risk to the data subject's personality or fundamental rights, 'as quickly as possible'. There is deliberately no fixed hour count in Swiss law, which differs from the 72-hour rule people arriving from the European Union expect. The notification must at minimum state the nature of the breach, its consequences and the measures taken or planned. Processors notify their controller, not the regulator. Data subjects are informed only where needed for their protection or where the Commissioner asks. Article 24 paragraph 6 gives a genuine protection: a notification made under this article may be used against the notifier in criminal proceedings only with that person's consent. Since 1 April 2025 the Commissioner may, with the controller's consent, forward the notification to the national cyber security body. CLOCK 2 - national cyber security, 24 hours, hard. Information Security Act Article 74e paragraph 1: the report must be made within 24 hours of discovering the cyberattack. The duty applies to a long list of critical operators set out in Article 74b, including all banks, insurers and financial market infrastructures, hospitals on a cantonal hospital list, licensed medical laboratories, medicines manufacturers and importers, energy companies, water and waste utilities, registered postal operators, railways, cable cars, buses and shipping under concession, licensed civil aviation businesses and national airports, national news agencies, the Swiss broadcaster, universities, and federal, cantonal and communal authorities. Article 74d sets the trigger: the attack endangers the operation of the critical infrastructure, or has led to information being manipulated or leaked, or went undetected for a long period, or involves blackmail, threats or coercion. Reporting is via a secure system run by the cyber security office. Reportable in force since 1 April 2025. CLOCK 3 - financial regulator, 24 hours then 72 hours. FINMA Guidance 05/2020 on the duty to report cyber attacks under Article 29 paragraph 2 of the Financial Market Supervision Act: 'Immediate reporting to FINMA means that the affected supervised institution informs FINMA through the responsible (Key) Account Manager within 24 hours of detecting such a cyber attack and conducting an initial assessment of its criticality. The actual report should be submitted within 72 hours via the FINMA web-based survey and application platform.' A supervised firm is also responsible for reporting cyber incidents at its service providers where there is a link to the supervised business. CLOCK 4 - health. Electronic Patient Record Ordinance Article 12 paragraph 3: communities must report incidents classified as security-relevant in their data protection and data security management system to the Federal Office of Public Health. No deadline in hours is specified. PENALTY SHAPE, and this is the surprise: missing the 24-hour cyber report carries no direct fine. Article 74g says the cyber security office first tells you and sets a reasonable deadline; only if you still fail does it issue a formal order. Article 74h then makes wilfully ignoring that final order punishable by a fine of up to 100,000 francs, about 125,000 dollars. So the enforceable act is disobedience, not lateness.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 24 (notification of data security breaches)
fedlex.data.admin.ch
“The controller shall notify the FDPIC of any breach of data security that is likely to lead to a high risk to the data subject's personality or fundamental rights as quickly as possible.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexInformation Security Act, Articles 74b, 74d, 74e, 74g and 74h (24-hour reporting duty for critical infrastructure, in force 1 April 2025)
fedlex.data.admin.ch
“Die Meldung muss innert 24 Stunden nach der Entdeckung des Cyberangriffs erfolgen.”
Link checked 18 August 2026
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA Guidance 05/2020 - duty to report cyber attacks under Article 29 paragraph 2 FINMASA
finma.ch
“Immediate reporting to FINMA means that the affected supervised institution informs FINMA through the responsible (Key) Account Manager within 24 hours of detecting such a cyber attack and conducting an initial assessment of its criticality. The actual report should be submitted within 72 hours via the FINMA web-based survey and application platform (EHP).”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexElectronic Patient Record Ordinance, Article 12 paragraph 3 (incident reporting to the Federal Office of Public Health)
fedlex.data.admin.ch
Link checked 18 August 2026
What trips people up in Switzerland?
Five things that are not in the summary. One: the penalty is a criminal fine on a named human being, not an administrative fine on the company, so your compliance lead is personally exposed. Two: sending data abroad without a valid safeguard is itself a crime. Three: banking secrecy and medical or legal secrecy are criminal laws with prison ceilings, and a standard supplier contract does not fix them. Four: cantonal authorities and cantonal hospitals are outside the federal law entirely. Five: the 24-hour cyber report has no penalty for being late, which misleads people into thinking it is optional.
TRAP 1 - the fine lands on a person, not the company. Articles 60 to 63 of the Data Protection Act impose fines of up to 250,000 francs, about 310,000 dollars, on 'private persons' who act wilfully. Article 64 lets the authority fine the business instead only where a fine of up to 50,000 francs, about 62,000 dollars, is in play AND identifying the individual would take disproportionate effort. So the default is prosecution of a human being. Most of the offences run 'on complaint', meaning somebody has to file. Prosecution is a cantonal matter, and the limitation period is five years. The Commissioner itself may file a complaint and take part as a private claimant. A practical consequence: directors and officers insurance and internal delegation of responsibility matter more here than the size of the cap. TRAP 2 - a bad transfer is a crime, not a paperwork failure. Article 61 letter a: wilfully disclosing personal data abroad in breach of Article 16 paragraphs 1 and 2 without meeting Article 17 attracts a fine of up to 250,000 francs. The same article criminalises using a processor without meeting the Article 9 conditions, and failing to meet the minimum security requirements. The Commissioner states this explicitly on its own cross-border transfer page. TRAP 3 - two criminal secrecy regimes sit on top of privacy law. Article 47 of the Banking Act: wilfully revealing a secret entrusted to you as an officer, employee, agent or liquidator of a bank is punishable by up to three years' imprisonment or a monetary penalty, rising to five years where the person or a third party obtains a financial advantage, with a fine of up to 250,000 francs for doing it negligently, and it stays punishable after you leave the job. Article 321 of the Criminal Code does the same for clergy, lawyers, defence counsel, notaries, patent attorneys, auditors bound to secrecy, doctors, dentists, chiropractors, pharmacists, midwives, psychologists, nurses, physiotherapists, occupational therapists, dieticians, optometrists and osteopaths, AND their auxiliaries, with a three-year ceiling. Under Article 321 paragraph 2 the only clean escapes are the consent of the person entitled to the secret, or a written authorisation from the supervisory authority. Signing a data processing agreement with a cloud provider does not by itself create either. This is the single biggest reason Swiss law firms, hospitals and private banks buy Swiss-hosted cloud services. TRAP 4 - the federal law does not cover cantonal bodies. Article 2 paragraph 1 applies the Act to private persons and federal bodies. Cantonal and communal authorities, cantonal public hospitals, cantonal police and state schools sit under 26 separate cantonal data protection statutes with their own commissioners, their own deadlines and their own rules on cloud use. A company selling into the Swiss public sector will be answering to a cantonal regulator it has never heard of, not to the federal Commissioner. TRAP 5 - the 24-hour cyber clock has a soft penalty and a hard reputational edge. Under Article 74g of the Information Security Act, if the cyber security office suspects you missed the deadline it first notifies you and sets a new one. Only wilful disobedience of the resulting formal order is punishable, under Article 74h, with a fine of up to 100,000 francs. Teams read this as 'no real deadline' and then discover that the office's order, once issued, is public-facing and enforceable. BONUS - no data protection officer is required. Swiss law offers an optional data protection adviser for private controllers, not a mandatory officer, and organisations with fewer than 250 employees are excused from keeping a record of processing activities unless they handle a large volume of sensitive data or do high-risk profiling. Companies that copy their European Union compliance programme wholesale routinely over-build here, while under-building on the criminal secrecy side, which is where the actual Swiss risk lives.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Articles 60 to 66 (criminal fines up to 250,000 francs on private persons; 50,000 franc corporate fallback; five-year limitation)
fedlex.data.admin.ch
“On complaint, a fine not exceeding 250,000 francs shall be imposed on private persons who wilfully: a. disclose personal data abroad in violation of Article 16 paragraphs 1 and 2 without satisfying the requirements of Article 17”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexBanking Act, Article 47 (criminal banking secrecy)
fedlex.data.admin.ch
“Mit Freiheitsstrafe bis zu drei Jahren oder Geldstrafe wird bestraft, wer vorsaetzlich: a. ein Geheimnis offenbart, das ihm in seiner Eigenschaft als Organ, Angestellter, Beauftragter oder Liquidator einer Bank ... anvertraut worden ist”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexSwiss Criminal Code, Article 321 (breach of professional confidentiality)
fedlex.data.admin.ch
“Geistliche, Rechtsanwaelte, Verteidiger, Notare, ... Aerzte, Zahnaerzte, ... Psychologen, Pflegefachpersonen ... sowie ihre Hilfspersonen, die ein Geheimnis offenbaren ... werden, auf Antrag, mit Freiheitsstrafe bis zu drei Jahren oder Geldstrafe bestraft.”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 2 paragraph 1 (Act applies to private persons and federal bodies only)
fedlex.data.admin.ch
“This Act applies to the processing of personal data of natural persons by: a. private persons; b. federal bodies.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexInformation Security Act, Articles 74g and 74h (two-step enforcement of the 24-hour report, fine up to 100,000 francs for ignoring an order)
fedlex.data.admin.ch
Link checked 18 August 2026
What is changing soon in Switzerland?
Nothing in the next twelve months changes where Swiss data may be stored. The electronic identity law has passed but is not switched on yet, and the financial regulator is holding a rule change until it is. A company transparency law hits banks on 1 October 2026. A rewrite of the telecoms surveillance rules has been announced for years and still has not landed. The bigger risk is not new legislation at all: the government can rewrite the approved-destinations list by itself, overnight, with no vote and no consultation.
LANDING IN THE NEXT TWELVE MONTHS, with dates: - 1 October 2026: the Federal Act of 26 September 2025 on the transparency of legal entities and the identification of beneficial owners amends the Banking Act. This creates new identification and record duties for financial institutions. It is in the official consolidated text with that commencement date. - Q4 2026 planned: the financial regulator intends to revise its circular on video and online identification so that the new electronic identity credential can be used to identify customers. The regulator states in writing that the revision depends on the entry into force of the Federal Act on Electronic Identity Credentials and Other Electronic Credentials. As at 18 August 2026 that Act does not appear in the consolidated federal law collection, so it is not yet in force. - Q1 2027 planned: revision of the regulator's anti-money laundering ordinance following the partial revision of the Anti-Money Laundering Act. - Q2 2027 planned: revision of Article 42c of the Financial Market Supervision Act and of the circular on direct transmission, which governs when a supervised firm may send information directly to a FOREIGN authority. This is the one to watch for cross-border data flow purposes. - Ongoing, no date: a comprehensive revision of the electronic patient record law, which the Commissioner has been commenting on. If it changes the requirement that data stores sit in Switzerland, it changes the single hardest localisation rule in Swiss law. - Ongoing, no date: revision of the Ordinance on the Surveillance of Post and Telecommunications. The surveillance service's 2025 annual report lists it as a focus area. We checked the consolidated federal law collection on 18 August 2026: the ordinance has not been amended since 26 March 2024, so nothing has commenced. DORMANT SWITCHES - powers already held that could change the picture without warning: 1. The approved-destinations list. Annex 1 to the Data Protection Ordinance is amended by the Federal Council alone, by ordinance. Article 8 paragraph 6 of the Ordinance says that if a reassessment shows adequate protection is no longer guaranteed, Annex 1 SHALL be amended. Removing the United States entry, which rests on a United States executive order and a redress mechanism outside Swiss control, would instantly require every Swiss company using American cloud services to fall back to contractual clauses. No parliamentary vote is needed. 2. Extending telecoms surveillance to messaging apps. Article 27 paragraph 3 of the Telecommunications Surveillance Act empowers the Federal Council to make providers of DERIVED communications services - the category that covers messaging and email services - subject to all or some of the full obligations that apply to telecoms operators, including the six-month metadata retention duty, where they are of major economic importance or serve a large number of users. This is done by ordinance. 3. Other transfer safeguards. Article 16 paragraph 3 of the Data Protection Act lets the Federal Council create additional appropriate guarantees by ordinance. 4. Recognition of standard clauses. The Commissioner recognised the European Union's standard contractual clauses in a document, not a statute, and can revisit that recognition. 5. Cyber reporting scope. The list of critical operators subject to the 24-hour report sits in Article 74b of the Information Security Act, and the Federal Council holds delegated powers to adjust the perimeter.
Sources
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA pending regulation projects, status and outlook as of 1 June 2026
finma.ch
“It is intended that FINMA Circular 2016/7 'Video and online identification' will take account of new technological possibilities ... In particular, identification with an E-ID is to be made possible. The partial revision is dependent on the entry into force of the Federal Act on Electronic Identity Credentials and Other Electronic Credentials (E-ID Act).”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexBanking Act, consolidated text with status as at 1 October 2026, amended by the Federal Act of 26 September 2025 on the transparency of legal entities
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Ordinance, Article 8 paragraphs 4 and 6 (periodic reassessment and mandatory amendment of Annex 1)
fedlex.data.admin.ch
“If the assessment under paragraph 4 or other information show that an adequate level of data protection is no longer guaranteed, Annex 1 shall be amended; this shall have no effect on disclosures of data already carried out.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexTelecommunications Surveillance Act, Article 27 paragraph 3 (power to extend full telecoms duties to derived communications services)
fedlex.data.admin.ch
“In so far as is necessary for telecommunications surveillance, the Federal Council shall make providers of derived communications services that provide services of major economic importance or to a large number of users subject to all or some of the obligations referred to in Article 26.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexOrdinance on the Surveillance of Post and Telecommunications, consolidated status as at 26 March 2024 - no later amendment in force on 18 August 2026
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourcePost and Telecommunications Surveillance Service, Federal Department of Justice and PolicePost and Telecommunications Surveillance Service - 2025 annual report highlights the ongoing revision of the surveillance ordinance
li.admin.ch
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
3 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
7 rules here
Layer 3
Contract-imposed rule
Binds you because you signed something, typically a government contract.
1 rule here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules3 rules
Bundesgesetz ueber den Datenschutz (Datenschutzgesetz, DSG) / Federal Act on Data Protection (FADP)
Act of parliament · SR 235.1, Act of 25 September 2020
Switzerland's general privacy law. Data may leave the country freely to about 44 approved destinations and, elsewhere, once an approved safeguard such as a standard contract is in place. There is no registration, no mandatory data protection officer and a records exemption for organisations under 250 employees. Penalties are criminal fines on individuals, capped at 250,000 francs, not administrative fines on companies.
Enforced by Federal Data Protection and Information Commissioner
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk
What it makes you do
- Tell people what you do
- Get consentExplicit consent needed only for sensitive data, high-risk profiling by a private person, and any profiling by a federal body. Consent is not the default lawful basis in Switzerland.
- Let people see their data — within 720 hoursAs a rule, information must be provided within 30 days.
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Assess high-risk projectsRequired where processing is likely to lead to a high risk.
- Keep records of processing — applies at: 250 or more employees, or large volume of sensitive data, or high-risk profiling
- Report breaches to the regulator'As quickly as possible' where the breach is likely to cause a high risk. No fixed hour count in the statute.
- Tell affected people
- Appoint a local representative — applies at: Foreign controllers only, and only where large scale AND regular AND high risk
- Put a transfer safeguard in place
- Written vendor contract
- Delete data after a periodDestroy or anonymise once no longer needed for the purpose. No fixed period.
What it costs if you get it wrong
- Criminal liability: CHF 250,000 — about $310 thousandWilfully sending personal data abroad without a valid safeguard, using a processor without the required conditions, or breaching minimum security requirements. Fine imposed on the individual, on complaint.
- Criminal liability: CHF 250,000 — about $310 thousandWilfully giving false or incomplete information to data subjects, or failing to cooperate with the Commissioner's investigation
- Fixed maximum fine: CHF 50,000 — about $62 thousandFallback fine on the business where identifying the responsible individual would take disproportionate effort
- Order to stop: n/aThe Commissioner may order processing to be modified, suspended or stopped and data to be deleted
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawFederal Act on Data Protection (FADP), SR 235.1, consolidated text last amended 7 July 2025
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC - Cross-border transfer of personal data
edoeb.admin.ch
Link checked 18 August 2026
Datenschutzverordnung (DSV), Anhang 1 - Staaten, Gebiete, spezifische Sektoren und internationale Organe mit angemessenem Datenschutz
Adequacy decision · SR 235.11, Annex 1, as amended by the Ordinance of 14 August 2024
The approved-destinations list. About 44 entries covering the European Economic Area, the United Kingdom, Canada, Israel, Argentina, Uruguay, New Zealand, Monaco, Andorra, the Channel Islands and others. The United States is on the list only for organisations certified under the Swiss-United States Data Privacy Framework. The Federal Council can add or remove entries by ordinance alone.
Enforced by Swiss Federal Council
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision
What it makes you do
- Put a transfer safeguard in placeNothing extra is needed for a listed destination, but the recipient country still has to actually be covered by the entry.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Ordinance, Annex 1 (44 listed destinations), consolidated text status 1 December 2025
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC - list of countries (Annex 1 DPO)
edoeb.admin.ch
Link checked 18 August 2026
Bundesgesetz ueber die Informationssicherheit (Informationssicherheitsgesetz, ISG), 5a. Kapitel - Meldepflicht fuer Cyberangriffe auf kritische Infrastrukturen
Act of parliament · SR 128, Articles 74a to 74h, inserted by the Federal Act of 29 September 2023
Since 1 April 2025 operators of Swiss critical infrastructure must report a serious cyberattack to the national cyber security office within 24 hours of discovering it. The list of who counts is long and includes every bank, insurer, listed hospital, energy company and public authority. Being late is not directly punishable; ignoring the office's follow-up order is, up to 100,000 francs, about 125,000 dollars.
Enforced by Federal Office for Cyber Security
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — applies at: Operators of critical infrastructure listed in Article 74b, including all banks, insurers and financial market infrastructures, listed hospitals, licensed medical laboratories, medicines makers and importers, energy companies, water and waste utilities, registered postal operators, railways and licensed bus, cable car and shipping operators, civil aviation businesses and national airports, universities, the national broadcaster, national news agencies, and federal, cantonal and communal authorities, within 24 hours, from 1 April 2025Report within 24 hours of discovering the attack. Reportable if it endangers operations, has led to manipulated or leaked information, went undetected for a long time, or involves blackmail, threats or coercion.
What it costs if you get it wrong
- Fixed maximum fine: CHF 100,000 — about $125 thousandWilfully ignoring a final enforceable order of the Federal Office for Cyber Security. Being late with the report itself carries no direct fine.
- Fixed maximum fine: CHF 20,000 — about $25 thousandFallback fine on the business where identifying the responsible individual would be disproportionate
Sources
- Official sourceFederal Council / FedlexInformation Security Act, SR 128, Articles 74b, 74d, 74e, 74g and 74h
fedlex.data.admin.ch
“Die Meldung muss innert 24 Stunden nach der Entdeckung des Cyberangriffs erfolgen.”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 24 paragraph 5bis, inserted by the same reform, in force since 1 April 2025
fedlex.data.admin.ch
Link checked 18 August 2026
Industry rules7 rules
Verordnung ueber das elektronische Patientendossier (EPDV)
Directly binding regulation · SR 816.11, Article 12 paragraph 5 and Article 25 paragraph 6 · Health and social care
The hardest storage rule in Swiss law. For the national electronic patient record system, the data stores must physically be in Switzerland and must be governed by Swiss law. The same applies to the systems of organisations that issue the login credentials patients and health professionals use.
Enforced by Federal Office of Public Health
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryData stores must be located in Switzerland AND subject to Swiss law. Both limbs must be met, so a Swiss data centre run under a foreign governing law does not satisfy it.
- Keep logs — 10 yearsAccess log data kept ten years under Article 10 paragraph 3 of the Electronic Patient Record Act.
- Hold a security certificateCommunities, parent communities, access portals and issuers of identification means must all be certified by a recognised body.
- Appoint a data protection officerCommunities must name a person responsible for data protection and data security.
- Report breaches to the regulatorSecurity-relevant incidents reported to the Federal Office of Public Health.
What it costs if you get it wrong
- Loss of your licence: n/aLoss of certification, which removes the ability to operate in the electronic patient record system
Sources
- Official sourceFederal Council / FedlexOrdinance on the Electronic Patient Record (EPDV), SR 816.11, Article 12 paragraph 5
fedlex.data.admin.ch
“Die Datenspeicher muessen sich in der Schweiz befinden und dem Schweizer Recht unterstehen.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexFederal Act on the Electronic Patient Record (EPDG), SR 816.1, Articles 10 to 12
fedlex.data.admin.ch
Link checked 18 August 2026
Bundesgesetz ueber die Banken und Sparkassen (Bankengesetz, BankG), Artikel 47
Act of parliament · SR 952.0, Article 47 · Banking
Swiss banking secrecy is criminal law, not privacy law. Deliberately revealing information about a bank's client can put a named employee in prison for up to three years, or five if they profited. Careless disclosure is a fine of up to 250,000 francs, about 310,000 dollars. It keeps applying after the person leaves the bank, and cantonal prosecutors run the cases.
Enforced by Swiss Financial Market Supervisory Authority
Transfer model: Approval each time · Accepted routes: Explicit consent, Legal claims
What it makes you do
- Extra vendor secrecy termsEvery person who will touch client-identifying data, including staff of an offshore supplier, must be brought inside the secrecy perimeter. A standard data processing agreement is not enough.
- Do not hand data to foreign authorities on demandComplying with a foreign authority's demand for client data can itself be the criminal act, unless a Swiss legal route applies.
What it costs if you get it wrong
- Criminal liability: Custodial sentence up to 3 years or a monetary penaltyWilfully revealing a secret entrusted to a person as an officer, employee, agent or liquidator of a bank
- Criminal liability: Custodial sentence up to 5 years or a monetary penaltyDoing so to obtain a financial advantage for oneself or another
- Criminal liability: CHF 250,000 — about $310 thousandActing negligently
Sources
- Official sourceFederal Council / FedlexBanking Act, SR 952.0, Article 47
fedlex.data.admin.ch
“Mit Freiheitsstrafe bis zu drei Jahren oder Geldstrafe wird bestraft, wer vorsaetzlich ... ein Geheimnis offenbart, das ihm in seiner Eigenschaft als Organ, Angestellter, Beauftragter oder Liquidator einer Bank ... anvertraut worden ist”
Link checked 18 August 2026
FINMA-Rundschreiben 2018/3 'Outsourcing - Banken, Versicherungsunternehmen und ausgewaehlte Finanzinstitute nach FINIG'
Regulator directive · FINMA Circular 18/3, of 21 September 2017, last amended 4 November 2020 · Finance
Banks, insurance companies and certain investment firms may outsource abroad, but only if the firm, its auditor and the regulator can enforce inspection and audit rights against the foreign provider, and only if the data needed to restructure or wind up the firm stays reachable inside Switzerland at all times. In effect a partial mirroring duty rather than a ban.
Enforced by Swiss Financial Market Supervisory Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryNot a full localisation duty. The information needed to restructure or wind up the firm in Switzerland must be accessible IN Switzerland at all times, even where the rest of the function sits abroad.
- Independent auditThe firm, its audit firm and FINMA must be able to assert and enforce inspection and audit rights against the offshore provider.
- Written vendor contractWritten or text-form agreement, with early notice of subcontractor changes and the ability to terminate in an orderly way. Subcontractors must be bound by the same guarantees.
- Assess high-risk projectsRisk analysis before outsourcing a significant function.
What it costs if you get it wrong
- Order to stop: n/aFINMA supervisory measures, conditions attached to the authorisation, or an order to unwind the outsourcing
- Loss of your licence: n/aSerious or repeated breach of supervisory law
Sources
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA Circular 2018/3 'Outsourcing', section G
finma.ch
“Outsourcing to another country is admissible if the company can expressly guarantee that it, its audit firm and FINMA can assert and enforce their right to inspect and audit information. The possibility of restructuring or resolving the company in Switzerland must be assured. Access to the information required for this purpose must be possible in Switzerland at all times.”
Link checked 18 August 2026
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA pending regulation projects as of 1 June 2026 - no revision of Circular 2018/3 listed, so it remains current
finma.ch
Link checked 18 August 2026
Bundesgesetz ueber die Finanzmarktinfrastrukturen und das Marktverhalten im Effekten- und Derivatehandel (Finanzmarktinfrastrukturgesetz, FinfraG)
Act of parliament · SR 958.1, Articles 11, 19, 75, 104 and 106 · Securities
Stock exchanges, central counterparties, central securities depositories, trade repositories and payment systems need the financial regulator's permission in advance before outsourcing anything material, wherever the supplier sits. Separately, sending extra personal data to a foreign trade repository needs the individual's consent.
Enforced by Swiss Financial Market Supervisory Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent
What it makes you do
- Register or notifyPrior FINMA approval required before a financial market infrastructure outsources a material service such as risk management. Where the infrastructure is systemically important, the national bank must be consulted first.
- Get consentReporting extra fields to a recognised FOREIGN trade repository requires the individual's consent where those fields are personal data.
- Keep data for a minimum period — 10 yearsTen years for all records of services, procedures and activities; trade repositories keep reported data ten years after the contract matures.
What it costs if you get it wrong
- Order to stop: n/aRefusal or withdrawal of approval for the outsourcing
Sources
- Official sourceFederal Council / FedlexFinancial Market Infrastructure Act, SR 958.1, Articles 11, 19, 75 and 104
fedlex.data.admin.ch
“Will die Finanzmarktinfrastruktur wesentliche Dienstleistungen wie das Risikomanagement auslagern, so bedarf dies der vorgaengigen Genehmigung der FINMA.”
Link checked 18 August 2026
Schweizerisches Strafgesetzbuch, Artikel 321 (Verletzung des Berufsgeheimnisses)
Act of parliament · SR 311.0, Article 321 · Professional secrecy trades
Doctors, dentists, pharmacists, midwives, psychologists, nurses, physiotherapists, lawyers, defence counsel, notaries, patent attorneys, auditors and clergy, plus anyone assisting them, commit a criminal offence if they reveal a client's or patient's secret. Up to three years in prison. Putting the records into a cloud service is a disclosure unless the client consents or the supervisory authority authorises it in writing.
Enforced by Cantonal public prosecution authorities
Transfer model: Approval each time · Accepted routes: Explicit consent, Government sign-off needed
What it makes you do
- Extra vendor secrecy termsThe only clean routes out are the consent of the person the secret belongs to, or a written authorisation from the supervisory authority. A data processing agreement is not one of them.
- Get consent
What it costs if you get it wrong
- Criminal liability: Custodial sentence up to 3 years or a monetary penaltyA professional listed in Article 321, or their auxiliary, wilfully revealing a secret learned through the profession. Prosecuted on complaint, and still punishable after the person stops practising.
Sources
- Official sourceFederal Council / FedlexSwiss Criminal Code, SR 311.0, Article 321
fedlex.data.admin.ch
“Der Taeter ist nicht strafbar, wenn er das Geheimnis auf Grund einer Einwilligung des Berechtigten oder einer auf Gesuch des Taeters erteilten schriftlichen Bewilligung der vorgesetzten Behoerde oder Aufsichtsbehoerde offenbart hat.”
Link checked 18 August 2026
Bundesgesetz betreffend die Ueberwachung des Post- und Fernmeldeverkehrs (BUEPF)
Act of parliament · SR 780.1, Articles 26 to 29 · Telecoms
Telecoms providers must keep connection records for six months and hand them over on order, and must let the surveillance service into their systems immediately. No rule says where the data must be stored, but the access duty makes purely offshore architectures hard to run. Messaging and email services are only partly caught today; the government can extend the full duties to them by ordinance.
Enforced by Post and Telecommunications Surveillance Service
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 6 monthsSix months of secondary telecommunications data, that is who contacted whom, when, from where and for how long.
- Keep logs — 6 months
- Secure the dataProviders must grant the surveillance service immediate access to their facilities and must remove any encryption they themselves applied.
What it costs if you get it wrong
- Criminal liability: Administrative criminal proceedings run by the surveillance serviceFailure to cooperate with a surveillance order
Sources
- Official sourceFederal Council / FedlexTelecommunications Surveillance Act, SR 780.1, Articles 26 and 27
fedlex.data.admin.ch
“Providers of telecommunications services must retain the secondary telecommunications data of telecommunications for 6 months.”
Link checked 18 August 2026
- Official sourcePost and Telecommunications Surveillance ServiceFederal Council media release, 28 April 2026 - 2025 surveillance statistics
admin.ch
Link checked 18 August 2026
FINMA-Aufsichtsmitteilung 05/2020 - Meldepflicht von Cyberattacken nach Art. 29 Abs. 2 FINMAG
Regulator guideline · FINMA Guidance 05/2020 of 7 May 2020 · Finance
A second, separate cyber clock for anyone the financial regulator supervises: tell your supervisor within 24 hours of spotting the attack, then file the full report within 72 hours. It runs alongside, not instead of, the national 24-hour report and the privacy notification.
Enforced by Swiss Financial Market Supervisory Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hoursInitial notification to the FINMA account manager within 24 hours of detection and an initial criticality assessment. The full report follows within 72 hours through the regulator's online platform. The supervised firm is also on the hook for incidents at its own suppliers where they connect to the supervised business.
What it costs if you get it wrong
- Order to stop: n/aSupervisory measures for breach of the duty to report matters of substantial importance
Sources
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA Guidance 05/2020, section 3 - immediate reporting to FINMA
finma.ch
“Immediate reporting to FINMA means that the affected supervised institution informs FINMA through the responsible (Key) Account Manager within 24 hours of detecting such a cyber attack ... The actual report should be submitted within 72 hours via the FINMA web-based survey and application platform (EHP).”
Link checked 18 August 2026
Contract-imposed rule1 rule
Swiss Government Cloud (SGC) und Cloud-Strategie der Bundesverwaltung
Government policy document · Federal Council cloud strategy of 11 December 2020; Swiss Government Cloud programme, commitment credit CHF 246.9 million, 2025 to 2032 · Government
The Swiss federal government is building its own three-tier cloud between 2025 and 2032 for about 247 million francs, roughly 305 million dollars. One tier requires data to be held and processed in Switzerland and one keeps it in federal data centres. This binds suppliers through procurement contracts, not through law, and it is being built rather than finished.
Enforced by Federal Office of Information Technology, Systems and Telecommunication
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Prove the data stays under local controlThree tiers. 'Public Cloud' uses established global providers who must meet extra legal and technical conditions. 'Public Cloud Schweiz' requires the data to be held and processed in Switzerland. 'Private Cloud Bund' keeps data inside federal data centres.
- Hold a security certificate
- Keep the data in the countryApplies only to the two Swiss tiers, and by contract rather than by statute.
What it costs if you get it wrong
- Order to stop: n/aExclusion from federal procurement or termination of the framework contract
Sources
- Official sourceFederal Office of Information Technology, Systems and Telecommunication FOITTSwiss Government Cloud - Federal Office of Information Technology, Systems and Telecommunication
bit.admin.ch
“Auf Stufe 'Public Cloud Schweiz' bietet die SGC Public-Cloud-Services von etablierten Public-Cloud-Anbietern mit Datenhaltung und Datenbearbeitung in der Schweiz - auch um erhoehte Anforderungen an die Souveraenitaet zu erfuellen.”
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC 33rd Annual Report 2025/2026 - oversight of the Cloud Enabling Office and the federal Microsoft 365 roll-out
edoeb.admin.ch
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the European Union's adequacy decision for Switzerland has been renewed or reviewed since January 2024
This governs data moving from the European Union INTO Switzerland, which is the direction most companies care about. We deliberately restricted citations to Swiss government sources for this record, and no Swiss federal page we fetched states the current status of the European Commission's decision. Treat the inbound direction as unverified here and check the European Commission directly.
Whether any criminal fine has actually been imposed under Articles 60 to 63 of the Data Protection Act since 1 September 2023
Prosecution is a cantonal matter under Article 65, and there is no central federal register of cantonal data protection convictions that we could query. The Commissioner's 33rd annual report describes investigations and rulings but we found no reported conviction. We can evidence the absence of published cases, not the absence of cases.
Whether an offshore cloud provider can lawfully be treated as an 'auxiliary' under Article 321 of the Criminal Code
The article punishes listed professionals 'and their auxiliaries', which by its wording extends the secrecy duty to helpers rather than creating an exemption for them. Swiss practice on whether an outsourced foreign processor falls inside that word is contested and we found no federal court ruling or regulator guidance settling it. This is why we rate the professional-secrecy sector as conditional with a criminal wall rather than closed.
The exact status of the revision of the Ordinance on the Surveillance of Post and Telecommunications
We can prove a negative in one respect: the consolidated ordinance in the official federal law collection still shows 26 March 2024 as its latest version on 18 August 2026, so no revision has commenced. What we could not establish from a government source is whether a revised text has been formally adopted with a future commencement date, or is still at draft stage.
The commencement date of the Federal Act on Electronic Identity Credentials and Other Electronic Credentials
The Act does not appear in the consolidated federal law collection as at 18 August 2026, and the financial regulator's own pending-projects table of 1 June 2026 states that its circular revision depends on the Act entering into force, with the revision planned for the fourth quarter of 2026. That is strong evidence it is not yet in force, but we did not locate a Federal Council decree fixing the date.
Whether any Swiss federal rule restricts where mapping or geospatial data may be stored
No rule found, checked 18 August 2026, confidence medium. The Geoinformation Ordinance sorts official geodata into three access tiers but is silent on storage location. Restrictions on imagery of military installations sit in defence legislation we did not fully review.
Whether cantonal data protection laws impose their own storage-location rules on cantonal hospitals, schools and authorities
There are 26 cantonal regimes and each has its own statute and commissioner. Several cantons are known to apply stricter cloud rules to cantonal hospitals than federal law requires. Reviewing all 26 was outside the scope of this pass, so treat any Swiss public-sector deal as needing a separate cantonal check.
The precise number of entries in Annex 1 of the Data Protection Ordinance
We counted 44 numbered entries in the consolidated English text dated 1 December 2025, but the annex mixes states, territories and one sector-specific entry, and the English translation has no legal force. Use the German, French or Italian text for anything binding.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Switzerland versus Argentina
- Switzerland versus Armenia
- Switzerland versus Australia
- Switzerland versus Austria
- Switzerland versus Azerbaijan
- Switzerland versus Brazil
- Switzerland versus Bulgaria
- Switzerland versus Cambodia
- Switzerland versus Canada
- Switzerland versus China
- Switzerland versus Croatia
- Switzerland versus Cyprus
- Switzerland versus Estonia
- Switzerland versus France
- Switzerland versus Georgia
- Switzerland versus Germany
- Switzerland versus Greece
- Switzerland versus Hong Kong SAR
- Switzerland versus Hungary
- Switzerland versus Iceland
- Switzerland versus India
- Switzerland versus Indonesia
- Switzerland versus Ireland
- Switzerland versus Israel
- Switzerland versus Italy
- Switzerland versus Japan
- Switzerland versus Latvia
- Switzerland versus Lithuania
- Switzerland versus Luxembourg
- Switzerland versus Malta
- Switzerland versus Mexico
- Switzerland versus Mongolia
- Switzerland versus Nepal
- Switzerland versus Netherlands
- Switzerland versus Poland
- Switzerland versus Russia
- Switzerland versus Saudi Arabia
- Switzerland versus Serbia
- Switzerland versus Singapore
- Switzerland versus Slovakia
- Switzerland versus Slovenia
- Switzerland versus South Korea
- Switzerland versus Spain
- Switzerland versus Sri Lanka
- Switzerland versus Sweden
- Switzerland versus Taiwan
- Switzerland versus Thailand
- Switzerland versus Turkey
- Switzerland versus Ukraine
- Switzerland versus United Arab Emirates
- Switzerland versus United Kingdom
- Switzerland versus United States
- Switzerland versus Uzbekistan