Switzerland
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Switzerland — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send data out of Switzerland easily, as long as the destination is one the government trusts. An official list names about 44 approved places. It includes every European Union country, and United States firms in one certification scheme. For anywhere else, you sign an approved contract first. The real risk is different. Getting it wrong is a crime, and the case lands on a person, not the company.
Data governance in Switzerland
The eight things that decide how you handle data about people in Switzerland. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Swiss privacy law reaches any organisation whose activities have an effect in Switzerland. That includes one with no office, staff or company here. There is no revenue or headcount limit to duck under, and there is no register to sign up to. You need a named representative inside Switzerland only if four things are true at once. You are selling to people here or watching what they do. You are doing it on a large scale. You are doing it regularly. And what you do with the data is high risk for the people involved. Very few foreign companies meet all four.
- What you have to do here:
- Appoint a representative · Keep records of how you use data
Article 3 paragraph 1 of the Data Protection Act sets the effects test. The Act applies to situations that have an effect in Switzerland, even if they start abroad. Article 14 sets four conditions for appointing a Swiss representative, and all four must be met. You offer goods or services here, or you monitor behaviour here. You do it on a large scale. You do it regularly. And what you do carries a high risk to the personality of the people involved. The representative is a contact point for those people and for the Federal Data Protection and Information Commissioner. Their name and address must be published. Watch the split in Article 2 paragraph 1. The federal Act covers private persons and FEDERAL bodies only. Cantonal and communal authorities, cantonal public hospitals and cantonal schools fall under 26 separate cantonal data protection laws, each with its own commissioner. There is also relief by size in Article 24 of the Data Protection Ordinance. Private organisations with fewer than 250 employees need not keep a record of what they do with personal data. The headcount is taken on 1 January of the year. That relief is lost if you handle a large volume of sensitive personal data, or carry out high-risk profiling.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 3 (territorial scope of application)
fedlex.data.admin.ch
“This Act applies to circumstances that have an effect in Switzerland, even if they were initiated abroad.”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 14 (representative)
fedlex.data.admin.ch
“Private controllers with registered office or domicile abroad shall appoint a representative in Switzerland if they process the personal data of persons in Switzerland and the data processing meets the following requirements...”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Ordinance, Article 24 (exemption from the record of processing activities)
fedlex.data.admin.ch
“Undertakings and other private organisations employing fewer than 250 employees on 1 January of any year and natural persons are exempt from the obligation to keep a record of processing activities unless...”
Link checked 18 August 2026
Where the data is allowed to live
Usually yes. Switzerland publishes an official list of countries and territories it considers safe. Data can move to any of them with no extra paperwork. The list has about 44 entries. It covers all 27 European Union countries, the United Kingdom, Norway, Iceland, Liechtenstein, Canada, Israel, Argentina, Uruguay and New Zealand. It covers the United States only for companies signed up to one specific certification scheme. Japan is not on it, even though the European Union treats Japan as safe. For anywhere not on the list, you sign an approved contract first. Three industries override all of this, and one of them is an outright ban.
Your industry decides the answer. On its own, the national rule would be 'conditional'. Checked industry by industry on 18 August 2026: HEALTH, electronic patient record: CLOSED. Article 12 paragraph 5 of the Electronic Patient Record Ordinance says the data stores must be in Switzerland and governed by Swiss law. Article 25 paragraph 6 says the same for the issuers of the login credentials. This is the only outright storage-location ban we found in Swiss federal law. HEALTH, everything else: CONDITIONAL, and you can be prosecuted. Ordinary medical records outside the electronic patient record system have no storage-location rule. But doctors, nurses, pharmacists and psychologists are bound by the criminal secrecy rule in Article 321 of the Criminal Code. BANKING: CONDITIONAL, backed by criminal law. No rule says bank data must stay in Switzerland. Article 47 of the Banking Act makes deliberately revealing a banking secret a crime. It carries up to three years in prison, rising to five where the person makes money from it. Careless disclosure carries a fine of up to 250,000 francs. Separately, the regulator's outsourcing circular allows offshoring on two conditions. The bank must guarantee that it, its auditor and the regulator can enforce inspection and audit rights. And the information needed to restructure or wind up the bank must stay reachable in Switzerland at all times. That second condition means keeping some data here. INSURANCE: the same outsourcing rules as banking. The regulator's outsourcing circular covers insurance companies as well as banks and certain investment firms. Insurers have no equivalent criminal secrecy article. SECURITIES AND MARKET INFRASTRUCTURE: CONDITIONAL, case by case. Article 11 of the Financial Market Infrastructure Act covers stock exchanges, central counterparties, central securities depositories, trade repositories and payment systems. They need the regulator's approval before outsourcing a material service such as risk management. Article 104 paragraph 4 covers reporting a derivative trade to a recognised FOREIGN trade repository. If the extra fields include personal data, you need the individual's consent. TELECOMS: CONDITIONAL. We found no storage-location rule. Providers must keep connection metadata for six months. They must also give the surveillance service immediate access to their facilities. That ties the kept data to systems the Swiss authorities can reach. GOVERNMENT AND PUBLIC SECTOR: CONDITIONAL through purchasing rules, not through law. The Swiss Government Cloud programme has a budget of 246.9 million francs and runs from 2025 to 2032. It has three tiers. One, 'Public Cloud Schweiz', is defined by data being held and handled in Switzerland. Another, 'Private Cloud Bund', keeps data in federal data centres. This is a purchasing policy, so it binds suppliers through contracts rather than through law. PROFESSIONS UNDER LEGAL SECRECY: CONDITIONAL, backed by criminal law. Article 321 of the Criminal Code covers a long list of jobs. Clergy, lawyers, defence counsel, notaries, patent attorneys and auditors. Doctors, dentists, chiropractors, pharmacists and midwives. Psychologists, nurses, physiotherapists, occupational therapists, dieticians, optometrists and osteopaths. It also covers their assistants. MAPPING AND GEOSPATIAL: we found no location rule, checked 18 August 2026, confidence medium. The Geoinformation Ordinance sorts official geodata into three access levels, publicly accessible, restricted, and not public. It says nothing about where the data may be stored. EDUCATION, GAMING, E-COMMERCE, DEFENCE: we found no industry storage-location rule in federal law, checked 18 August 2026, confidence medium. Cantonal law governs state schools and cantonal universities.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Ordinance, Annex 1 - states, territories and sectors guaranteeing an adequate level of data protection
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 16 (principles for disclosure abroad)
fedlex.data.admin.ch
“Personal data may be disclosed abroad if the Federal Council has decided that the legislation of the State concerned or the international body guarantees an adequate level of protection.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexOrdinance on the Electronic Patient Record (EPDV), Article 12 paragraph 5
fedlex.data.admin.ch
“Die Datenspeicher muessen sich in der Schweiz befinden und dem Schweizer Recht unterstehen.”
Link checked 18 August 2026
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA Circular 2018/3 'Outsourcing - banks, insurance companies and selected financial institutions', section G, Outsourcing abroad
finma.ch
“Outsourcing to another country is admissible if the company can expressly guarantee that it, its audit firm and FINMA can assert and enforce their right to inspect and audit information. The possibility of restructuring or resolving the company in Switzerland must be assured. Access to the information required for this purpose must be possible in Switzerland at all times.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexFinancial Market Infrastructure Act, Articles 11 and 104
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Council / FedlexGeoinformation Ordinance, Article 21 (access authorisation levels for official geodata)
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Office of Information Technology, Systems and Telecommunication FOITTSwiss Government Cloud - three-tier design, including a Swiss-only public cloud tier
bit.admin.ch
Link checked 18 August 2026
What to do: Plan for a database inside Switzerland: this data is not allowed to leave.
Sending data out of the country
Switzerland uses an approved-destinations list, and it is well filled. About 44 countries, territories and one industry-specific entry are on it right now. Send data to a listed place and you need nothing more. Send it anywhere else and you need one of a short menu of safeguards. The most common is a standard contract. Switzerland has formally accepted the European Union's standard contract template, so most companies can reuse the paperwork they already have.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life
You can send data only to approved countries, and the list is filled in. Annex 1 of the Data Protection Ordinance lists 44 numbered entries. Entry 44 is the United States, and it is narrow. Only organisations certified under the Swiss-United States Data Privacy Framework count as safe. That rests on four things. Executive Order 14086. The Data Protection Review Court rule. Intelligence Community Directive 126. And the designation of Switzerland on 7 June 2024 as a country covered by the two-layer complaints mechanism. That entry was added by the ordinance of 14 August 2024, in force since 15 September 2024. It was still there in the consolidated text dated 1 December 2025. Canada is qualified. It counts as safe where the federal private-sector privacy law applies, or a substantially similar provincial law does. Where the destination is not on the list, Article 16 paragraph 2 gives five routes. A treaty under international law. Data protection clauses in a specific agreement, notified to the Commissioner beforehand. Specific guarantees drawn up by a federal body, notified beforehand. Standard data protection clauses the Commissioner has approved, issued or recognised. Or binding corporate rules approved by the Commissioner, or by an authority in a country on the list. A Commissioner document dated 12 February 2025 recognises two sets of clauses. The European Union's 2021 standard contractual clauses, and the Council of Europe's model contractual clauses. Using recognised standard clauses needs no notification. One-off clauses written for a single contract must be notified first. The Commissioner must respond within 90 days on standard clauses and on binding corporate rules. Article 17 adds six narrow one-off exceptions. They include explicit consent, necessity for a contract, overriding public interest, legal claims, protecting life, and data the person has made public. They are for isolated cases, not for routine bulk transfers. One difference is worth knowing. Switzerland's list is not a copy of the European Union's. Japan and South Korea are treated as safe by the European Union and do NOT appear in the Swiss annex. If you assume that safe for Europe means safe for Switzerland, you will be running an unlawful transfer, and one that is a crime. The Commissioner's guidance adds a step that catches people out. Contract clauses only bind the parties to the contract. So where the destination country's law allows disproportionate access by the authorities, you may need technical measures on top of the contract. The Commissioner also states plainly that a transfer failing Articles 16 and 17 may carry criminal consequences under Article 61 letter a.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Ordinance, Annex 1 (44 listed destinations, United States limited to Data Privacy Framework certified organisations)
fedlex.data.admin.ch
“For personal data processed by organisations certified under the Principles of the Swiss-US Privacy Framework, an adequate level of protection is deemed to be guaranteed...”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 16 paragraph 2 (safeguards where no adequacy decision exists)
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 17 (narrow exceptions)
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC - Cross-border transfer of personal data
edoeb.admin.ch
“If data is disclosed abroad and the conditions set out in Articles 16 and 17 FADP are not met, this may have consequences under criminal law (Art. 61 let. a FADP).”
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC recognition of the EU Standard Contractual Clauses and the Council of Europe Model Contractual Clauses, 12 February 2025
edoeb.admin.ch
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The main regulator is the Federal Data Protection and Information Commissioner. It is real, fully staffed and busy. In the year to 31 March 2026 it ran 156 low-level interventions, 22 preliminary enquiries and 9 formal investigations. It had 2 cases running in the Federal Administrative Court. It has issued binding orders against a bank, a debt collection firm and a fashion group. In October 2025 the court confirmed its new way of working. The catch is that this regulator cannot fine anyone. Fines under the privacy law are criminal. Cantonal prosecutors hand them out, and they land on individual people.
We rate enforcement active. Commissioner: Adrian Lobsiger. Deputy Commissioner: Florence Henguely. Reported workload for 1 April 2025 to 31 March 2026. It ran 156 low-threshold interventions and 22 preliminary enquiries. It ran 9 investigations under Article 49 of the Data Protection Act. It had 2 matters pending before the Federal Administrative Court. Roughly half the office's effort goes on advice rather than supervision. Decisions you can see. A ruling of 29 January 2025 against Cembra Money Bank, on the deadlines for handling access requests. A ruling of 28 April 2025 against Inkasso-Team AG, on publishing debtors' names online. That one was later tested in Federal Administrative Court judgment A-3891/2025 of 22 June 2026. An instruction of 16 May 2025 to PostFinance on the use of voice biometrics. And a ruling of 17 April 2026 against Cream della Cream Switzerland and Philipp Plein International, published on 4 August 2026. In February and March 2026 the Commissioner ran a preliminary investigation into Meta Platforms Ireland over an artificial intelligence feature. On 3 March 2026 it opened a formal investigation into an artificial-intelligence age-verification provider. The Federal Administrative Court judgment of 6 October 2025 upheld the ruling against Buergerforum Schweiz. The Commissioner calls it the first legally binding validation of its new way of making decisions. Other regulators that matter more than the privacy one in their own areas: - FINMA, the financial market supervisor. It authorises outsourcing by market infrastructures, enforces the outsourcing circular and takes cyber-attack reports. - The Federal Office for Cyber Security. It receives the 24-hour critical-infrastructure incident reports and can issue enforceable orders. - The Post and Telecommunications Surveillance Service, part of the Federal Department of Justice and Police. It is plainly operational. In 2025 it handled 1,878 real-time interceptions, 6,531 retroactive surveillance measures and 650,034 simple information requests. Total measures were up about 40 per cent on 2024. - The Federal Office of Public Health, which supervises the electronic patient record system. - 26 cantonal data protection authorities, for cantonal and communal bodies. Why we do not rate it aggressive. The Commissioner has no power to impose administrative fines at all. Criminal fines under Articles 60 to 63 are capped at 250,000 francs. They apply only to individual people who act deliberately, and in most cases only where someone files a complaint. We found no evidence of a criminal privacy conviction in Switzerland during the review period.
Sources
- Official sourceFederal Data Protection and Information Commissioner33rd Annual Report 2025/2026 of the FDPIC, key figures and supervision chapter
edoeb.admin.ch
“156 Low-threshold interventions / 22 Preliminary enquiries / 9 Investigations Art. 49 FADP / 2 pending before FAC”
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC - Findings and rulings (published rulings 2024, 2025, 2026)
edoeb.admin.ch
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC annual report page - 33rd Annual Report published 30 June 2026
edoeb.admin.ch
Link checked 18 August 2026
- Official sourceSwiss Federal Council / Post and Telecommunications Surveillance ServiceFederal Council media release, 28 April 2026 - telecommunications surveillance statistics 2025
admin.ch
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Articles 60 to 65 (criminal provisions, prosecution a matter for the cantons)
fedlex.data.admin.ch
“Die Verfolgung und die Beurteilung der strafbaren Handlungen sind Sache der Kantone.”
Link checked 18 August 2026
How long you must keep it — and when to delete it
Rules pull in both directions. On the keep-it side: business books, accounting records and audit reports must be kept for ten years. Financial market infrastructures keep their records for ten years. Trade repositories keep trade data for ten years after the contract matures. Electronic patient record access logs are kept for ten years. Telecoms companies keep connection records for six months. On the delete-it side: the privacy law says personal data must be destroyed or made anonymous as soon as you no longer need it. There is no fixed number. Where the two clash, the specific legal duty to keep wins.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
MINIMUMS, verified: - Code of Duties Article 958f: keep business books, accounting vouchers, the annual report and the audit report for ten years. The clock runs from the end of the financial year. You may store them electronically if you can make them readable again at any time. - Financial Market Infrastructure Act Article 19: financial market infrastructures record and keep all records of services, procedures and activities for ten years. - Financial Market Infrastructure Act Article 75: a trade repository keeps reported data for at least ten years after the derivative contract matures. - Financial Market Infrastructure Act Article 106: counterparties keep derivative trade vouchers under the ten-year rule in the Code of Duties. - Electronic Patient Record Act Article 10 paragraph 3: access log data must be kept for ten years. - Telecommunications Surveillance Act Article 26 paragraph 5: telecommunications providers must keep connection metadata for six months. MAXIMUMS, verified: - Data Protection Act Article 6 paragraph 4: personal data must be destroyed or anonymised as soon as you no longer need it for your purpose. No number is given. The period is tied to the purpose, so it is whatever you can justify. - Article 6 paragraph 3 limits further use to purposes compatible with the one the person could recognise when the data was collected. HOW THE CLASH RESOLVES. A specific legal duty to keep records is still a legal duty. Article 31 of the Data Protection Act lets the law justify something that would otherwise break the principles. So Swiss companies usually keep the ten-year accounting set and delete the rest on a purpose-based schedule. The trap runs the other way. Take an internal 'keep everything for ten years' policy, applied to marketing data, browsing logs or job applicant files. It has no legal basis and breaks Article 6 paragraph 4. We found no legal maximum keeping period for any general category of personal data, checked 18 August 2026.
Sources
- Official sourceFederal Council / FedlexCode of Obligations, Article 958f (ten-year retention of business books and accounting vouchers)
fedlex.data.admin.ch
“Die Geschaeftsbuecher und die Buchungsbelege sowie der Geschaeftsbericht und der Revisionsbericht sind waehrend zehn Jahren aufzubewahren.”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 6 paragraph 4 (destruction or anonymisation once no longer needed)
fedlex.data.admin.ch
“They shall be destroyed or anonymised as soon as they are no longer required for the purpose of processing.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexFinancial Market Infrastructure Act, Articles 19, 75 and 106 (ten-year record retention)
fedlex.data.admin.ch
“Das Transaktionsregister zeichnet die gemeldeten Daten auf und bewahrt sie waehrend mindestens zehn Jahren nach der Faelligkeit des Kontrakts auf.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexTelecommunications Surveillance Act, Article 26 paragraph 5 (six-month metadata retention)
fedlex.data.admin.ch
“Providers of telecommunications services must retain the secondary telecommunications data of telecommunications for 6 months.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexElectronic Patient Record Act, Article 10 paragraph 3 (ten-year log retention)
fedlex.data.admin.ch
“Die Protokolldaten sind zehn Jahre aufzubewahren.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Four clocks, not one. The privacy regulator must be told 'as quickly as possible' when a breach is likely to put people at serious risk. No number of hours is attached. If you run critical infrastructure, you have a firm 24 hours to tell the national cyber security office. If the financial regulator supervises you, you have 24 hours to notify your supervisor and 72 hours to file the full report. Electronic patient record communities must report security incidents to the health office. Most failures come from teams who set one deadline and miss the others.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
CLOCK 1: the privacy regulator. Data Protection Act Article 24. The company that decides how the data is used must tell the Commissioner about a data security breach. That applies where the breach is likely to lead to a HIGH risk to the person's personality or fundamental rights. The deadline is 'as quickly as possible'. Swiss law deliberately sets no hour count, which differs from the 72-hour rule people expect from the European Union. The notice must at least state the nature of the breach, its consequences, and the measures taken or planned. A supplier tells its customer, not the regulator. You tell the affected people only where they need to know to protect themselves, or where the Commissioner asks. Article 24 paragraph 6 gives real protection. A notice made under this article may be used against you in criminal proceedings only with your consent. Since 1 April 2025 the Commissioner may pass the notice to the national cyber security body, but only with your consent. CLOCK 2: national cyber security, 24 hours, firm. Information Security Act Article 74e paragraph 1. You must report within 24 hours of discovering the cyberattack. The duty applies to a long list of critical operators set out in Article 74b. It includes all banks, insurers and financial market infrastructures. It includes hospitals on a cantonal hospital list, licensed medical laboratories, and medicines manufacturers and importers. It includes energy companies, and water and waste utilities. It includes registered postal operators, railways, cable cars, buses and shipping under concession. It includes licensed civil aviation businesses and national airports. It includes national news agencies, the Swiss broadcaster and universities. And it includes federal, cantonal and communal authorities. Article 74d sets the trigger. The attack endangers the operation of the critical infrastructure. Or it has led to information being changed or leaked. Or it went undetected for a long period. Or it involves blackmail, threats or coercion. You report through a secure system run by the cyber security office. The duty has applied since 1 April 2025. CLOCK 3: financial regulator, 24 hours then 72 hours. FINMA Guidance 05/2020 covers the duty to report cyber attacks under Article 29 paragraph 2 of the Financial Market Supervision Act. Immediate reporting means this. The supervised firm informs FINMA through its responsible account manager within 24 hours. That runs from detecting the attack and making a first assessment of how critical it is. The actual report should follow within 72 hours through FINMA's web-based survey and application platform. A supervised firm is also responsible for reporting cyber incidents at its service providers, where they connect to the supervised business. CLOCK 4: health. Electronic Patient Record Ordinance Article 12 paragraph 3. Communities must report incidents their own data protection and security system classes as security-relevant to the Federal Office of Public Health. No deadline in hours is set. THE PENALTIES ARE THE SURPRISE. Missing the 24-hour cyber report carries no direct fine. Article 74g says the cyber security office first tells you and sets a reasonable new deadline. Only if you still fail does it issue a formal order. Article 74h then makes deliberately ignoring that order punishable by a fine of up to 100,000 francs, about 125,000 dollars. So what is punished is disobedience, not lateness.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 24 (notification of data security breaches)
fedlex.data.admin.ch
“The controller shall notify the FDPIC of any breach of data security that is likely to lead to a high risk to the data subject's personality or fundamental rights as quickly as possible.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexInformation Security Act, Articles 74b, 74d, 74e, 74g and 74h (24-hour reporting duty for critical infrastructure, in force 1 April 2025)
fedlex.data.admin.ch
“Die Meldung muss innert 24 Stunden nach der Entdeckung des Cyberangriffs erfolgen.”
Link checked 18 August 2026
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA Guidance 05/2020 - duty to report cyber attacks under Article 29 paragraph 2 FINMASA
finma.ch
“Immediate reporting to FINMA means that the affected supervised institution informs FINMA through the responsible (Key) Account Manager within 24 hours of detecting such a cyber attack and conducting an initial assessment of its criticality. The actual report should be submitted within 72 hours via the FINMA web-based survey and application platform (EHP).”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexElectronic Patient Record Ordinance, Article 12 paragraph 3 (incident reporting to the Federal Office of Public Health)
fedlex.data.admin.ch
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things. One. The penalty is a criminal fine on a named human being, not an administrative fine on the company. Your compliance lead is personally exposed. Two. Sending data abroad without a valid safeguard is itself a crime. Three. Banking secrecy and medical or legal secrecy are criminal laws that can mean prison. A standard supplier contract does not fix them. Four. Cantonal authorities and cantonal hospitals sit outside the federal law entirely. Five. The 24-hour cyber report has no penalty for being late, which leads people to treat it as optional.
- What you have to do here:
- Extra vendor secrecy terms
- What it costs if you get it wrong:
- Criminal liability · Fixed maximum fine
TRAP 1: the fine lands on a person, not the company. Articles 60 to 63 of the Data Protection Act impose fines of up to 250,000 francs, about 310,000 dollars, on 'private persons' who act deliberately. Article 64 lets the authority fine the business instead. That only works where the fine is up to 50,000 francs, about 62,000 dollars. It also only works where identifying the individual would take disproportionate effort. So the default is prosecuting a human being. Most of the offences run only where someone files a complaint. Prosecution is a cantonal matter, and the time limit is five years. The Commissioner can file a complaint itself and take part as a private claimant. One practical result: directors and officers insurance, and who you formally put in charge internally, matter more here than the size of the cap. TRAP 2: a bad transfer is a crime, not a paperwork failure. Article 61 letter a covers deliberately disclosing personal data abroad in breach of Article 16 paragraphs 1 and 2 without meeting Article 17. The fine is up to 250,000 francs. The same article makes it a crime to use a supplier without meeting the Article 9 conditions, and to fail the minimum security requirements. The Commissioner states this on its own cross-border transfer page. TRAP 3: two criminal secrecy laws sit on top of privacy law. Article 47 of the Banking Act punishes deliberately revealing a secret entrusted to you as an officer, employee, agent or liquidator of a bank. It carries up to three years in prison or a money penalty. That rises to five years where the person, or someone else, gains financially. Careless disclosure carries a fine of up to 250,000 francs. It still applies after you leave the job. Article 321 of the Criminal Code does the same for a long list of jobs. Clergy, lawyers, defence counsel, notaries, patent attorneys and auditors bound to secrecy. Doctors, dentists, chiropractors, pharmacists and midwives. Psychologists, nurses, physiotherapists, occupational therapists, dieticians, optometrists and osteopaths. It also covers their assistants. The ceiling there is three years. Under Article 321 paragraph 2 there are only two clean ways out. The consent of the person the secret belongs to, or a written authorisation from the supervisory authority. Signing a data protection contract with a cloud provider gives you neither. This is the single biggest reason Swiss law firms, hospitals and private banks buy Swiss-hosted cloud services. TRAP 4: the federal law does not cover cantonal bodies. Article 2 paragraph 1 applies the Act to private persons and federal bodies. Cantonal and communal authorities, cantonal public hospitals, cantonal police and state schools sit under 26 separate cantonal data protection laws. Each has its own commissioner, its own deadlines and its own rules on cloud use. If you sell into the Swiss public sector, you will answer to a cantonal regulator you have never heard of, not to the federal Commissioner. TRAP 5: the 24-hour cyber clock has a soft penalty and a hard public edge. Article 74g of the Information Security Act sets out what happens if you miss the deadline. The cyber security office first tells you and sets a new one. Only deliberately disobeying the formal order that follows is punishable, under Article 74h, with a fine of up to 100,000 francs. Teams read this as 'no real deadline'. Then they discover that the office's order, once issued, is public-facing and enforceable. ONE MORE: no data protection officer is required. Swiss law offers an optional data protection adviser for private companies, not a required officer. Organisations with fewer than 250 employees need not keep a record of what they do with personal data. That relief is lost if you handle a large volume of sensitive data, or do high-risk profiling. Companies that copy their European Union compliance programme wholesale usually over-build here. They then under-build on the criminal secrecy side, which is where the real Swiss risk sits.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Articles 60 to 66 (criminal fines up to 250,000 francs on private persons; 50,000 franc corporate fallback; five-year limitation)
fedlex.data.admin.ch
“On complaint, a fine not exceeding 250,000 francs shall be imposed on private persons who wilfully: a. disclose personal data abroad in violation of Article 16 paragraphs 1 and 2 without satisfying the requirements of Article 17”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexBanking Act, Article 47 (criminal banking secrecy)
fedlex.data.admin.ch
“Mit Freiheitsstrafe bis zu drei Jahren oder Geldstrafe wird bestraft, wer vorsaetzlich: a. ein Geheimnis offenbart, das ihm in seiner Eigenschaft als Organ, Angestellter, Beauftragter oder Liquidator einer Bank ... anvertraut worden ist”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexSwiss Criminal Code, Article 321 (breach of professional confidentiality)
fedlex.data.admin.ch
“Geistliche, Rechtsanwaelte, Verteidiger, Notare, ... Aerzte, Zahnaerzte, ... Psychologen, Pflegefachpersonen ... sowie ihre Hilfspersonen, die ein Geheimnis offenbaren ... werden, auf Antrag, mit Freiheitsstrafe bis zu drei Jahren oder Geldstrafe bestraft.”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 2 paragraph 1 (Act applies to private persons and federal bodies only)
fedlex.data.admin.ch
“This Act applies to the processing of personal data of natural persons by: a. private persons; b. federal bodies.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexInformation Security Act, Articles 74g and 74h (two-step enforcement of the 24-hour report, fine up to 100,000 francs for ignoring an order)
fedlex.data.admin.ch
Link checked 18 August 2026
What's changing next
Nothing in the next twelve months changes where Swiss data may be stored. The electronic identity law has passed but is not switched on yet. The financial regulator is holding a rule change until it is. A company transparency law hits banks on 1 October 2026. A rewrite of the telecoms surveillance rules has been announced for years and still has not landed. The bigger risk is not new law. The government can rewrite the approved-destinations list by itself, overnight, with no vote and no consultation.
LANDING IN THE NEXT TWELVE MONTHS, with dates: - 1 October 2026: the Banking Act is amended. The amending law is the Federal Act of 26 September 2025 on the transparency of legal entities and the identification of beneficial owners. It creates new identification and record duties for financial institutions. It is in the official consolidated text with that start date. - Fourth quarter of 2026, planned: the financial regulator intends to revise its circular on video and online identification, so the new electronic identity credential can be used to identify customers. The regulator says in writing that this depends on the Federal Act on Electronic Identity Credentials and Other Electronic Credentials coming into force. As at 18 August 2026 that Act does not appear in the consolidated federal law collection, so it is not yet in force. - First quarter of 2027, planned: revision of the regulator's anti-money laundering ordinance, following the partial revision of the Anti-Money Laundering Act. - Second quarter of 2027, planned: revision of Article 42c of the Financial Market Supervision Act, and of the circular on direct transmission. That governs when a supervised firm may send information straight to a FOREIGN authority. This is the one to watch for cross-border data flows. - Ongoing, no date: a full revision of the electronic patient record law, which the Commissioner has been commenting on. If it changes the requirement that data stores sit in Switzerland, it changes the strictest storage rule in Swiss law. - Ongoing, no date: revision of the Ordinance on the Surveillance of Post and Telecommunications. The surveillance service's 2025 annual report lists it as a focus area. We checked the consolidated federal law collection on 18 August 2026. The ordinance has not been amended since 26 March 2024, so nothing has started. POWERS ALREADY HELD THAT COULD CHANGE THE ANSWER WITHOUT WARNING: 1. The approved-destinations list. Annex 1 to the Data Protection Ordinance is amended by the Federal Council alone, by ordinance. Article 8 paragraph 6 of the Ordinance says that if a review shows protection is no longer good enough, Annex 1 SHALL be amended. Removing the United States entry would instantly force every Swiss company using American cloud services back onto contract clauses. That entry rests on a United States executive order and a complaints mechanism outside Swiss control. No parliamentary vote is needed. 2. Extending telecoms surveillance to messaging apps. Article 27 paragraph 3 of the Telecommunications Surveillance Act gives the Federal Council a power. It can apply all or some of the telecoms operators' duties to providers of DERIVED communications services. That category covers messaging and email services. It includes the six-month metadata keeping duty. It applies where the provider is of major economic importance or serves a large number of users. This is done by ordinance. 3. Other transfer safeguards. Article 16 paragraph 3 of the Data Protection Act lets the Federal Council create extra appropriate guarantees by ordinance. 4. Recognition of standard clauses. The Commissioner recognised the European Union's standard contractual clauses in a document, not a statute, and can revisit that recognition. 5. Cyber reporting scope. The list of critical operators that must report within 24 hours sits in Article 74b of the Information Security Act. The Federal Council holds delegated powers to change who is on it.
Sources
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA pending regulation projects, status and outlook as of 1 June 2026
finma.ch
“It is intended that FINMA Circular 2016/7 'Video and online identification' will take account of new technological possibilities ... In particular, identification with an E-ID is to be made possible. The partial revision is dependent on the entry into force of the Federal Act on Electronic Identity Credentials and Other Electronic Credentials (E-ID Act).”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexBanking Act, consolidated text with status as at 1 October 2026, amended by the Federal Act of 26 September 2025 on the transparency of legal entities
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Ordinance, Article 8 paragraphs 4 and 6 (periodic reassessment and mandatory amendment of Annex 1)
fedlex.data.admin.ch
“If the assessment under paragraph 4 or other information show that an adequate level of data protection is no longer guaranteed, Annex 1 shall be amended; this shall have no effect on disclosures of data already carried out.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexTelecommunications Surveillance Act, Article 27 paragraph 3 (power to extend full telecoms duties to derived communications services)
fedlex.data.admin.ch
“In so far as is necessary for telecommunications surveillance, the Federal Council shall make providers of derived communications services that provide services of major economic importance or to a large number of users subject to all or some of the obligations referred to in Article 26.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexOrdinance on the Surveillance of Post and Telecommunications, consolidated status as at 26 March 2024 - no later amendment in force on 18 August 2026
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourcePost and Telecommunications Surveillance Service, Federal Department of Justice and PolicePost and Telecommunications Surveillance Service - 2025 annual report highlights the ongoing revision of the surveillance ordinance
li.admin.ch
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries7 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Health and social care data must stay in the country
Official name: Verordnung ueber das elektronische Patientendossier (EPDV) · SR 816.11, Article 12 paragraph 5 and Article 25 paragraph 6 · Directly binding regulation
The hardest storage rule in Swiss law. For the national electronic patient record system, the data stores must physically be in Switzerland and must be governed by Swiss law. The same applies to the systems of organisations that issue the login credentials patients and health professionals use.
Enforced by Federal Office of Public Health
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryData stores must be located in Switzerland AND subject to Swiss law. Both limbs must be met, so a Swiss data centre run under a foreign governing law does not satisfy it.
- Keep logs — 10 yearsAccess log data kept ten years under Article 10 paragraph 3 of the Electronic Patient Record Act.
- Hold a security certificateCommunities, parent communities, access portals and issuers of identification means must all be certified by a recognised body.
- Appoint a data protection officerCommunities must name a person responsible for data protection and data security.
- Report breaches to the regulatorSecurity-relevant incidents reported to the Federal Office of Public Health.
What it costs if you get it wrong
- Loss of your licence: n/aLoss of certification, which removes the ability to operate in the electronic patient record system
Sources
- Official sourceFederal Council / FedlexOrdinance on the Electronic Patient Record (EPDV), SR 816.11, Article 12 paragraph 5
fedlex.data.admin.ch
“Die Datenspeicher muessen sich in der Schweiz befinden und dem Schweizer Recht unterstehen.”
Link checked 18 August 2026
- Official sourceFederal Council / FedlexFederal Act on the Electronic Patient Record (EPDG), SR 816.1, Articles 10 to 12
fedlex.data.admin.ch
Link checked 18 August 2026
Banking rules
Official name: Bundesgesetz ueber die Banken und Sparkassen (Bankengesetz, BankG), Artikel 47 · SR 952.0, Article 47 · Act of parliament
Swiss banking secrecy is criminal law, not privacy law. Deliberately revealing information about a bank's client can put a named employee in prison for up to three years, or five if they profited. Careless disclosure is a fine of up to 250,000 francs, about 310,000 dollars. It keeps applying after the person leaves the bank, and cantonal prosecutors run the cases.
Enforced by Swiss Financial Market Supervisory Authority
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, Legal claims
What you have to do
- Extra vendor secrecy termsEvery person who will touch client-identifying data must be brought inside the secrecy perimeter, including staff of an offshore supplier. A standard data protection contract is not enough.
- Do not hand data to foreign authorities on demandComplying with a foreign authority's demand for client data can itself be the criminal act, unless a Swiss legal route applies.
What it costs if you get it wrong
- Criminal liability: Custodial sentence up to 3 years or a monetary penaltyWilfully revealing a secret entrusted to a person as an officer, employee, agent or liquidator of a bank
- Criminal liability: Custodial sentence up to 5 years or a monetary penaltyDoing so to obtain a financial advantage for oneself or another
- Criminal liability: CHF 250,000 — about $310 thousandActing negligently
Sources
- Official sourceFederal Council / FedlexBanking Act, SR 952.0, Article 47
fedlex.data.admin.ch
“Mit Freiheitsstrafe bis zu drei Jahren oder Geldstrafe wird bestraft, wer vorsaetzlich ... ein Geheimnis offenbart, das ihm in seiner Eigenschaft als Organ, Angestellter, Beauftragter oder Liquidator einer Bank ... anvertraut worden ist”
Link checked 18 August 2026
Finance data needs a copy kept in the country
Official name: FINMA-Rundschreiben 2018/3 'Outsourcing - Banken, Versicherungsunternehmen und ausgewaehlte Finanzinstitute nach FINIG' · FINMA Circular 18/3, of 21 September 2017, last amended 4 November 2020 · Regulator directive
Banks, insurance companies and certain investment firms may outsource abroad. But two conditions apply. The firm, its auditor and the regulator must be able to enforce inspection and audit rights against the foreign provider. And the data needed to restructure or wind up the firm must stay reachable inside Switzerland at all times. That is a partial keep-a-copy-here duty rather than a ban.
Enforced by Swiss Financial Market Supervisory Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThis is not a full keep-it-here duty. But some data must stay reachable IN Switzerland at all times. That is the information needed to restructure or wind up the firm in Switzerland. It applies even where the rest of the function sits abroad.
- Independent auditThe firm, its audit firm and FINMA must be able to assert and enforce inspection and audit rights against the offshore provider.
- Written vendor contractWritten or text-form agreement, with early notice of subcontractor changes and the ability to terminate in an orderly way. Subcontractors must be bound by the same guarantees.
- Assess high-risk projectsRisk analysis before outsourcing a significant function.
What it costs if you get it wrong
- Order to stop: n/aFINMA supervisory measures, conditions attached to the authorisation, or an order to unwind the outsourcing
- Loss of your licence: n/aSerious or repeated breach of supervisory law
Sources
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA Circular 2018/3 'Outsourcing', section G
finma.ch
“Outsourcing to another country is admissible if the company can expressly guarantee that it, its audit firm and FINMA can assert and enforce their right to inspect and audit information. The possibility of restructuring or resolving the company in Switzerland must be assured. Access to the information required for this purpose must be possible in Switzerland at all times.”
Link checked 18 August 2026
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA pending regulation projects as of 1 June 2026 - no revision of Circular 2018/3 listed, so it remains current
finma.ch
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Bundesgesetz ueber die Finanzmarktinfrastrukturen und das Marktverhalten im Effekten- und Derivatehandel (Finanzmarktinfrastrukturgesetz, FinfraG) · SR 958.1, Articles 11, 19, 75, 104 and 106 · Act of parliament
Stock exchanges, central counterparties, central securities depositories, trade repositories and payment systems need the financial regulator's permission in advance. That applies before outsourcing anything material, wherever the supplier sits. Separately, sending extra personal data to a foreign trade repository needs the individual's consent.
Enforced by Swiss Financial Market Supervisory Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Explicit consent
What you have to do
- Register or notifyPrior FINMA approval required before a financial market infrastructure outsources a material service such as risk management. Where the infrastructure is systemically important, the national bank must be consulted first.
- Get consentReporting extra fields to a recognised FOREIGN trade repository requires the individual's consent where those fields are personal data.
- Keep data for a minimum period — 10 yearsTen years for all records of services, procedures and activities; trade repositories keep reported data ten years after the contract matures.
What it costs if you get it wrong
- Order to stop: n/aRefusal or withdrawal of approval for the outsourcing
Sources
- Official sourceFederal Council / FedlexFinancial Market Infrastructure Act, SR 958.1, Articles 11, 19, 75 and 104
fedlex.data.admin.ch
“Will die Finanzmarktinfrastruktur wesentliche Dienstleistungen wie das Risikomanagement auslagern, so bedarf dies der vorgaengigen Genehmigung der FINMA.”
Link checked 18 August 2026
Cloud and outsourcing rules (Professional secrecy trades)
Official name: Schweizerisches Strafgesetzbuch, Artikel 321 (Verletzung des Berufsgeheimnisses) · SR 311.0, Article 321 · Act of parliament
A long list of professionals commits a crime by revealing a client's or patient's secret. It covers doctors, dentists, pharmacists, midwives, psychologists, nurses and physiotherapists. It also covers lawyers, defence counsel, notaries, patent attorneys, auditors and clergy. Anyone assisting them is covered too. The penalty is up to three years in prison. Putting the records into a cloud service counts as revealing them. The only ways round that are the client's consent, or written authorisation from the supervisory authority.
Enforced by Cantonal public prosecution authorities
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, Government sign-off needed
What you have to do
- Extra vendor secrecy termsThe only clean routes out are the consent of the person the secret belongs to, or a written authorisation from the supervisory authority. A data protection contract is not one of them.
- Get consent
What it costs if you get it wrong
- Criminal liability: Custodial sentence up to 3 years or a monetary penaltyA professional listed in Article 321, or their auxiliary, wilfully revealing a secret learned through the profession. Prosecuted on complaint, and still punishable after the person stops practising.
Sources
- Official sourceFederal Council / FedlexSwiss Criminal Code, SR 311.0, Article 321
fedlex.data.admin.ch
“Der Taeter ist nicht strafbar, wenn er das Geheimnis auf Grund einer Einwilligung des Berechtigten oder einer auf Gesuch des Taeters erteilten schriftlichen Bewilligung der vorgesetzten Behoerde oder Aufsichtsbehoerde offenbart hat.”
Link checked 18 August 2026
Telecoms rules
Official name: Bundesgesetz betreffend die Ueberwachung des Post- und Fernmeldeverkehrs (BUEPF) · SR 780.1, Articles 26 to 29 · Act of parliament
Telecoms providers must keep connection records for six months and hand them over on order, and must let the surveillance service into their systems immediately. No rule says where the data must be stored, but the access duty makes purely offshore architectures hard to run. Messaging and email services are only partly caught today; the government can extend the full duties to them by ordinance.
Enforced by Post and Telecommunications Surveillance Service
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 6 monthsSix months of secondary telecommunications data, that is who contacted whom, when, from where and for how long.
- Keep logs — 6 months
- Secure the dataProviders must grant the surveillance service immediate access to their facilities and must remove any encryption they themselves applied.
What it costs if you get it wrong
- Criminal liability: Administrative criminal proceedings run by the surveillance serviceFailure to cooperate with a surveillance order
Sources
- Official sourceFederal Council / FedlexTelecommunications Surveillance Act, SR 780.1, Articles 26 and 27
fedlex.data.admin.ch
“Providers of telecommunications services must retain the secondary telecommunications data of telecommunications for 6 months.”
Link checked 18 August 2026
- Official sourcePost and Telecommunications Surveillance ServiceFederal Council media release, 28 April 2026 - 2025 surveillance statistics
admin.ch
Link checked 18 August 2026
General data protection law (Finance)
Official name: FINMA-Aufsichtsmitteilung 05/2020 - Meldepflicht von Cyberattacken nach Art. 29 Abs. 2 FINMAG · FINMA Guidance 05/2020 of 7 May 2020 · Regulator guideline
There is a second, separate cyber clock for anyone the financial regulator supervises. Tell your supervisor within 24 hours of spotting the attack. Then file the full report within 72 hours. It runs alongside, not instead of, the national 24-hour report and the privacy notification.
Enforced by Swiss Financial Market Supervisory Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hoursInitial notification to the FINMA account manager within 24 hours of detection and an initial criticality assessment. The full report follows within 72 hours through the regulator's online platform. The supervised firm is also on the hook for incidents at its own suppliers where they connect to the supervised business.
What it costs if you get it wrong
- Order to stop: n/aSupervisory measures for breach of the duty to report matters of substantial importance
Sources
- Official sourceSwiss Financial Market Supervisory Authority FINMAFINMA Guidance 05/2020, section 3 - immediate reporting to FINMA
finma.ch
“Immediate reporting to FINMA means that the affected supervised institution informs FINMA through the responsible (Key) Account Manager within 24 hours of detecting such a cyber attack ... The actual report should be submitted within 72 hours via the FINMA web-based survey and application platform (EHP).”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Bundesgesetz ueber den Datenschutz (Datenschutzgesetz, DSG) / Federal Act on Data Protection (FADP) · SR 235.1, Act of 25 September 2020 · Act of parliament
Switzerland's general privacy law. Data may leave freely to about 44 approved destinations. Elsewhere it may leave once an approved safeguard, such as a standard contract, is in place. There is no registration and no required data protection officer. Organisations under 250 employees are excused from keeping records of what they do with data. Penalties are criminal fines on individuals, capped at 250,000 francs. They are not administrative fines on companies.
Enforced by Federal Data Protection and Information Commissioner
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life
What you have to do
- Tell people what you do
- Get consentExplicit consent needed only for sensitive data, high-risk profiling by a private person, and any profiling by a federal body. Consent is not the default lawful basis in Switzerland.
- Let people see their data — within 720 hoursAs a rule, information must be provided within 30 days.
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Assess high-risk projectsRequired where what you do with the data is likely to lead to a high risk.
- Keep records of how you use data — applies at: 250 or more employees, or large volume of sensitive data, or high-risk profiling
- Report breaches to the regulator'As quickly as possible' where the breach is likely to cause a high risk. No fixed hour count in the statute.
- Tell affected people
- Appoint a representative — applies at: Foreign controllers only, and only where large scale AND regular AND high risk
- Put a transfer safeguard in place
- Written vendor contract
- Delete data after a periodDestroy or anonymise once no longer needed for the purpose. No fixed period.
What it costs if you get it wrong
- Criminal liability: CHF 250,000 — about $310 thousandWilfully sending personal data abroad without a valid safeguard, using a processor without the required conditions, or breaching minimum security requirements. Fine imposed on the individual, on complaint.
- Criminal liability: CHF 250,000 — about $310 thousandWilfully giving false or incomplete information to data subjects, or failing to cooperate with the Commissioner's investigation
- Fixed maximum fine: CHF 50,000 — about $62 thousandFallback fine on the business where identifying the responsible individual would take disproportionate effort
- Order to stop: n/aThe Commissioner may order processing to be modified, suspended or stopped and data to be deleted
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawFederal Act on Data Protection (FADP), SR 235.1, consolidated text last amended 7 July 2025
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC - Cross-border transfer of personal data
edoeb.admin.ch
Link checked 18 August 2026
General data protection law (2024)
Official name: Datenschutzverordnung (DSV), Anhang 1 - Staaten, Gebiete, spezifische Sektoren und internationale Organe mit angemessenem Datenschutz · SR 235.11, Annex 1, as amended by the Ordinance of 14 August 2024 · Official “this country is safe” decision
The approved-destinations list. About 44 entries covering the European Economic Area, the United Kingdom, Canada, Israel, Argentina, Uruguay, New Zealand, Monaco, Andorra, the Channel Islands and others. The United States is on the list only for organisations certified under the Swiss-United States Data Privacy Framework. The Federal Council can add or remove entries by ordinance alone.
Enforced by Swiss Federal Council
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision
What you have to do
- Put a transfer safeguard in placeNothing extra is needed for a listed destination, but the recipient country still has to actually be covered by the entry.
Sources
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Ordinance, Annex 1 (44 listed destinations), consolidated text status 1 December 2025
fedlex.data.admin.ch
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC - list of countries (Annex 1 DPO)
edoeb.admin.ch
Link checked 18 August 2026
Cyber security rules
Official name: Bundesgesetz ueber die Informationssicherheit (Informationssicherheitsgesetz, ISG), 5a. Kapitel - Meldepflicht fuer Cyberangriffe auf kritische Infrastrukturen · SR 128, Articles 74a to 74h, inserted by the Federal Act of 29 September 2023 · Act of parliament
Since 1 April 2025 operators of Swiss critical infrastructure must report a serious cyberattack within 24 hours of discovering it. The report goes to the national cyber security office. The list of who counts is long and includes every bank, insurer, listed hospital, energy company and public authority. Being late is not directly punishable; ignoring the office's follow-up order is, up to 100,000 francs, about 125,000 dollars.
Enforced by Federal Office for Cyber Security
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — applies at: Operators of critical infrastructure listed in Article 74b, including all banks, insurers and financial market infrastructures, listed hospitals, licensed medical laboratories, medicines makers and importers, energy companies, water and waste utilities, registered postal operators, railways and licensed bus, cable car and shipping operators, civil aviation businesses and national airports, universities, the national broadcaster, national news agencies, and federal, cantonal and communal authorities, within 24 hours, from 1 April 2025Report within 24 hours of discovering the attack. Reportable if it endangers operations, has led to manipulated or leaked information, went undetected for a long time, or involves blackmail, threats or coercion.
What it costs if you get it wrong
- Fixed maximum fine: CHF 100,000 — about $125 thousandWilfully ignoring a final enforceable order of the Federal Office for Cyber Security. Being late with the report itself carries no direct fine.
- Fixed maximum fine: CHF 20,000 — about $25 thousandFallback fine on the business where identifying the responsible individual would be disproportionate
Sources
- Official sourceFederal Council / FedlexInformation Security Act, SR 128, Articles 74b, 74d, 74e, 74g and 74h
fedlex.data.admin.ch
“Die Meldung muss innert 24 Stunden nach der Entdeckung des Cyberangriffs erfolgen.”
Link checked 18 August 2026
- Official sourceFederal Council / Fedlex, official consolidated lawData Protection Act, Article 24 paragraph 5bis, inserted by the same reform, in force since 1 April 2025
fedlex.data.admin.ch
Link checked 18 August 2026
Applies only if you signed a contract1 rule
Usually a government or enterprise contract that adds rules of its own.
Cloud and outsourcing rules (Government)
Official name: Swiss Government Cloud (SGC) und Cloud-Strategie der Bundesverwaltung · Federal Council cloud strategy of 11 December 2020; Swiss Government Cloud programme, commitment credit CHF 246.9 million, 2025 to 2032 · Government policy document
The Swiss federal government is building its own three-tier cloud between 2025 and 2032 for about 247 million francs, roughly 305 million dollars. One tier requires data to be held and processed in Switzerland and one keeps it in federal data centres. This binds suppliers through procurement contracts, not through law, and it is being built rather than finished.
Enforced by Federal Office of Information Technology, Systems and Telecommunication
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Prove the data stays under local controlThree tiers. 'Public Cloud' uses established global providers who must meet extra legal and technical conditions. 'Public Cloud Schweiz' requires the data to be held and processed in Switzerland. 'Private Cloud Bund' keeps data inside federal data centres.
- Hold a security certificate
- Keep the data in the countryApplies only to the two Swiss tiers, and by contract rather than by statute.
What it costs if you get it wrong
- Order to stop: n/aExclusion from federal procurement or termination of the framework contract
Sources
- Official sourceFederal Office of Information Technology, Systems and Telecommunication FOITTSwiss Government Cloud - Federal Office of Information Technology, Systems and Telecommunication
bit.admin.ch
“Auf Stufe 'Public Cloud Schweiz' bietet die SGC Public-Cloud-Services von etablierten Public-Cloud-Anbietern mit Datenhaltung und Datenbearbeitung in der Schweiz - auch um erhoehte Anforderungen an die Souveraenitaet zu erfuellen.”
Link checked 18 August 2026
- Official sourceFederal Data Protection and Information CommissionerFDPIC 33rd Annual Report 2025/2026 - oversight of the Cloud Enabling Office and the federal Microsoft 365 roll-out
edoeb.admin.ch
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the European Union's official “this country is safe” decision for Switzerland has been renewed or reviewed since January 2024
We could not confirm this. It governs data moving from the European Union INTO Switzerland, which is the direction most companies care about. For this record we cite only Swiss government sources, and no Swiss federal page we read states the current status of the European Commission's decision. Treat the inbound direction as unverified here, and check with the European Commission.
Whether any criminal fine has actually been imposed under Articles 60 to 63 of the Data Protection Act since 1 September 2023
We could not confirm whether anyone has been convicted. Prosecution is a cantonal matter under Article 65, and there is no central federal register of cantonal data protection convictions we could search. The Commissioner's 33rd annual report describes investigations and rulings, but we found no reported conviction. We can show that no cases have been published, not that no cases exist.
Whether an offshore cloud provider can lawfully be treated as an 'auxiliary' under Article 321 of the Criminal Code
We could not confirm how far the secrecy duty reaches. The article punishes the listed professionals 'and their auxiliaries'. On its wording, that extends the duty to helpers rather than excusing them. Swiss practice on whether an outsourced foreign supplier falls inside that word is disputed. We found no federal court ruling or regulator guidance settling it. That is why we rate the professional-secrecy area as conditional and backed by criminal law, rather than closed.
The exact status of the revision of the Ordinance on the Surveillance of Post and Telecommunications
We can show one thing. On 18 August 2026 the official federal law collection still showed 26 March 2024 as the ordinance's latest version. So no revision has started. One thing we could not establish from a government source. Whether a revised text has been formally adopted with a future start date, or is still a draft.
The commencement date of the Federal Act on Electronic Identity Credentials and Other Electronic Credentials
The Act does not appear in the consolidated federal law collection as at 18 August 2026. The financial regulator's own pending-projects table of 1 June 2026 says its circular revision depends on the Act coming into force. That revision is planned for the fourth quarter of 2026. That is strong evidence the Act is not yet in force. But we did not find a Federal Council decree fixing the date.
Whether any Swiss federal rule restricts where mapping or geospatial data may be stored
We found no rule about where this data must be stored, checked 18 August 2026, confidence medium. The Geoinformation Ordinance sorts official geodata into three access levels but says nothing about storage location. Limits on imagery of military installations sit in defence law we did not fully review. Check before you rely on this.
Whether cantonal data protection laws impose their own storage-location rules on cantonal hospitals, schools and authorities
There are 26 cantonal systems, each with its own law and its own commissioner. Several cantons are known to apply stricter cloud rules to cantonal hospitals than federal law requires. Reviewing all 26 was outside the scope of this pass. Treat any Swiss public-sector deal as needing a separate cantonal check.
The precise number of entries in Annex 1 of the Data Protection Ordinance
We counted 44 numbered entries in the consolidated English text dated 1 December 2025. The annex mixes states, territories and one industry-specific entry, and the English translation has no legal force. Use the German, French or Italian text for anything binding.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.