Skip to the content
Global Data RulesData governance rules, country by country

Switzerland

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Switzerland — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Active

You can send data out of Switzerland easily, as long as the destination is one the government trusts. An official list names about 44 approved places. It includes every European Union country, and United States firms in one certification scheme. For anywhere else, you sign an approved contract first. The real risk is different. Getting it wrong is a crime, and the case lands on a person, not the company.

Data governance in Switzerland

The eight things that decide how you handle data about people in Switzerland. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Swiss privacy law reaches any organisation whose activities have an effect in Switzerland. That includes one with no office, staff or company here. There is no revenue or headcount limit to duck under, and there is no register to sign up to. You need a named representative inside Switzerland only if four things are true at once. You are selling to people here or watching what they do. You are doing it on a large scale. You are doing it regularly. And what you do with the data is high risk for the people involved. Very few foreign companies meet all four.

What you have to do here:
Appoint a representative · Keep records of how you use data

Where the data is allowed to live

Usually yes. Switzerland publishes an official list of countries and territories it considers safe. Data can move to any of them with no extra paperwork. The list has about 44 entries. It covers all 27 European Union countries, the United Kingdom, Norway, Iceland, Liechtenstein, Canada, Israel, Argentina, Uruguay and New Zealand. It covers the United States only for companies signed up to one specific certification scheme. Japan is not on it, even though the European Union treats Japan as safe. For anywhere not on the list, you sign an approved contract first. Three industries override all of this, and one of them is an outright ban.

What to do: Plan for a database inside Switzerland: this data is not allowed to leave.

Sending data out of the country

Switzerland uses an approved-destinations list, and it is well filled. About 44 countries, territories and one industry-specific entry are on it right now. Send data to a listed place and you need nothing more. Send it anywhere else and you need one of a short menu of safeguards. The most common is a standard contract. Switzerland has formally accepted the European Union's standard contract template, so most companies can reuse the paperwork they already have.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The main regulator is the Federal Data Protection and Information Commissioner. It is real, fully staffed and busy. In the year to 31 March 2026 it ran 156 low-level interventions, 22 preliminary enquiries and 9 formal investigations. It had 2 cases running in the Federal Administrative Court. It has issued binding orders against a bank, a debt collection firm and a fashion group. In October 2025 the court confirmed its new way of working. The catch is that this regulator cannot fine anyone. Fines under the privacy law are criminal. Cantonal prosecutors hand them out, and they land on individual people.

How long you must keep it — and when to delete it

Rules pull in both directions. On the keep-it side: business books, accounting records and audit reports must be kept for ten years. Financial market infrastructures keep their records for ten years. Trade repositories keep trade data for ten years after the contract matures. Electronic patient record access logs are kept for ten years. Telecoms companies keep connection records for six months. On the delete-it side: the privacy law says personal data must be destroyed or made anonymous as soon as you no longer need it. There is no fixed number. Where the two clash, the specific legal duty to keep wins.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Four clocks, not one. The privacy regulator must be told 'as quickly as possible' when a breach is likely to put people at serious risk. No number of hours is attached. If you run critical infrastructure, you have a firm 24 hours to tell the national cyber security office. If the financial regulator supervises you, you have 24 hours to notify your supervisor and 72 hours to file the full report. Electronic patient record communities must report security incidents to the health office. Most failures come from teams who set one deadline and miss the others.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. One. The penalty is a criminal fine on a named human being, not an administrative fine on the company. Your compliance lead is personally exposed. Two. Sending data abroad without a valid safeguard is itself a crime. Three. Banking secrecy and medical or legal secrecy are criminal laws that can mean prison. A standard supplier contract does not fix them. Four. Cantonal authorities and cantonal hospitals sit outside the federal law entirely. Five. The 24-hour cyber report has no penalty for being late, which leads people to treat it as optional.

What you have to do here:
Extra vendor secrecy terms
What it costs if you get it wrong:
Criminal liability · Fixed maximum fine

What's changing next

Nothing in the next twelve months changes where Swiss data may be stored. The electronic identity law has passed but is not switched on yet. The financial regulator is holding a rule change until it is. A company transparency law hits banks on 1 October 2026. A rewrite of the telecoms surveillance rules has been announced for years and still has not landed. The bigger risk is not new law. The government can rewrite the approved-destinations list by itself, overnight, with no vote and no consultation.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries7 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Health and social care data must stay in the country

Official name: Verordnung ueber das elektronische Patientendossier (EPDV) · SR 816.11, Article 12 paragraph 5 and Article 25 paragraph 6 · Directly binding regulation

In forceNo — it stays put

The hardest storage rule in Swiss law. For the national electronic patient record system, the data stores must physically be in Switzerland and must be governed by Swiss law. The same applies to the systems of organisations that issue the login credentials patients and health professionals use.

In force since 15 April 2017

Enforced by Federal Office of Public Health

How this country controls where data goes: Not allowed

Banking

Banking rules

Official name: Bundesgesetz ueber die Banken und Sparkassen (Bankengesetz, BankG), Artikel 47 · SR 952.0, Article 47 · Act of parliament

In forceYes, with paperwork

Swiss banking secrecy is criminal law, not privacy law. Deliberately revealing information about a bank's client can put a named employee in prison for up to three years, or five if they profited. Careless disclosure is a fine of up to 250,000 francs, about 310,000 dollars. It keeps applying after the person leaves the bank, and cantonal prosecutors run the cases.

In force since 1 January 2009Enforced from 1 July 2015

Enforced by Swiss Financial Market Supervisory Authority

How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, Legal claims

Finance

Finance data needs a copy kept in the country

Official name: FINMA-Rundschreiben 2018/3 'Outsourcing - Banken, Versicherungsunternehmen und ausgewaehlte Finanzinstitute nach FINIG' · FINMA Circular 18/3, of 21 September 2017, last amended 4 November 2020 · Regulator directive

In forceA copy must stay

Banks, insurance companies and certain investment firms may outsource abroad. But two conditions apply. The firm, its auditor and the regulator must be able to enforce inspection and audit rights against the foreign provider. And the data needed to restructure or wind up the firm must stay reachable inside Switzerland at all times. That is a partial keep-a-copy-here duty rather than a ban.

In force since 1 April 2018Enforced from 1 April 2023

Enforced by Swiss Financial Market Supervisory Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Bundesgesetz ueber den Datenschutz (Datenschutzgesetz, DSG) / Federal Act on Data Protection (FADP) · SR 235.1, Act of 25 September 2020 · Act of parliament

In forceYes, with paperwork

Switzerland's general privacy law. Data may leave freely to about 44 approved destinations. Elsewhere it may leave once an approved safeguard, such as a standard contract, is in place. There is no registration and no required data protection officer. Organisations under 250 employees are excused from keeping records of what they do with data. Penalties are criminal fines on individuals, capped at 250,000 francs. They are not administrative fines on companies.

In force since 1 September 2023

Enforced by Federal Data Protection and Information Commissioner

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life

General data protection law (2024)

Official name: Datenschutzverordnung (DSV), Anhang 1 - Staaten, Gebiete, spezifische Sektoren und internationale Organe mit angemessenem Datenschutz · SR 235.11, Annex 1, as amended by the Ordinance of 14 August 2024 · Official “this country is safe” decision

In forceYes — store it anywhere

The approved-destinations list. About 44 entries covering the European Economic Area, the United Kingdom, Canada, Israel, Argentina, Uruguay, New Zealand, Monaco, Andorra, the Channel Islands and others. The United States is on the list only for organisations certified under the Swiss-United States Data Privacy Framework. The Federal Council can add or remove entries by ordinance alone.

In force since 15 September 2024

Enforced by Swiss Federal Council

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision

Cyber security rules

Official name: Bundesgesetz ueber die Informationssicherheit (Informationssicherheitsgesetz, ISG), 5a. Kapitel - Meldepflicht fuer Cyberangriffe auf kritische Infrastrukturen · SR 128, Articles 74a to 74h, inserted by the Federal Act of 29 September 2023 · Act of parliament

In forceYes — store it anywhere

Since 1 April 2025 operators of Swiss critical infrastructure must report a serious cyberattack within 24 hours of discovering it. The report goes to the national cyber security office. The list of who counts is long and includes every bank, insurer, listed hospital, energy company and public authority. Being late is not directly punishable; ignoring the office's follow-up order is, up to 100,000 francs, about 125,000 dollars.

In force since 1 April 2025

Enforced by Federal Office for Cyber Security

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies only if you signed a contract1 rule

Usually a government or enterprise contract that adds rules of its own.

Government

Cloud and outsourcing rules (Government)

Official name: Swiss Government Cloud (SGC) und Cloud-Strategie der Bundesverwaltung · Federal Council cloud strategy of 11 December 2020; Swiss Government Cloud programme, commitment credit CHF 246.9 million, 2025 to 2032 · Government policy document

Partly in forceDepends on your industry

The Swiss federal government is building its own three-tier cloud between 2025 and 2032 for about 247 million francs, roughly 305 million dollars. One tier requires data to be held and processed in Switzerland and one keeps it in federal data centres. This binds suppliers through procurement contracts, not through law, and it is being built rather than finished.

In force since 1 January 2025

Enforced by Federal Office of Information Technology, Systems and Telecommunication

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Eidgenoessischer Datenschutz- und Oeffentlichkeitsbeauftragter (EDOEB) / Prepose federal a la protection des donnees et a la transparence (PFPDT)

    General data protection law over private organisations and federal bodies, plus freedom of information

    Fully operational and long-established. Commissioner Adrian Lobsiger, Deputy Commissioner Florence Henguely. In the year to 31 March 2026 it recorded 156 low-threshold interventions and 22 preliminary enquiries. It also recorded 9 formal investigations under Article 49 of the Data Protection Act, and 2 matters pending before the Federal Administrative Court. Published binding rulings in 2024, 2025 and 2026, the most recent dated 17 April 2026 and published on 4 August 2026. Its practice was validated by the Federal Administrative Court on 6 October 2025. Important limitation: it cannot impose fines. It issues binding orders and may file criminal complaints.

  • Schweizerischer Bundesrat / Conseil federal suisse

    Decides which countries are on the approved-destinations list, and holds most of the dormant ordinance-making powers

    Amends Annex 1 to the Data Protection Ordinance by ordinance alone. Last amendment 14 August 2024, in force 15 September 2024, adding the United States for Data Privacy Framework certified organisations.

  • Eidgenoessische Finanzmarktaufsicht FINMA

    Banks, insurers, investment firms, fund managers, financial market infrastructures. Outsourcing rules, cyber incident reporting, prior approval for outsourcing by market infrastructures

    Operational and publishing continuously. Its pending-regulation table was updated on 1 June 2026 and lists projects through to 2028. It can attach conditions to authorisations, order unwinding of outsourcing arrangements and withdraw licences.

  • Bundesamt fuer Cybersicherheit (BACS) / Office federal de la cybersecurite

    Receives the mandatory 24-hour cyberattack reports from critical infrastructure operators and can issue enforceable orders

    The reporting duty commenced on 1 April 2025 and the office runs the secure reporting system required by Article 74f of the Information Security Act. It can issue formal orders whose breach is punishable by a fine of up to 100,000 francs.

  • Dienst Ueberwachung Post- und Fernmeldeverkehr (Dienst UEPF)

    Telecoms metadata retention and interception; runs administrative criminal proceedings against non-cooperating providers

    Plainly operational. In 2025 it processed 1,878 real-time interceptions and 6,531 retroactive surveillance measures. It also processed 1,287 emergency traces and 650,034 simple information requests. Total measures were up about 40 per cent on 2024. Its 2025 annual report was published on 30 June 2026.

  • Bundesamt fuer Gesundheit (BAG)

    Electronic patient record system, including the requirement that data stores be in Switzerland

    Operational. It receives security incident reports from electronic patient record communities and oversees the certification system. A full revision of the electronic patient record law is in progress.

  • Bundesamt fuer Informatik und Telekommunikation (BIT)

    Builds and runs the Swiss Government Cloud, including its Swiss-only tiers

    Operational. The Swiss Government Cloud programme runs 2025 to 2032 with a commitment credit of 246.9 million francs and total costs of 319.4 million francs. It serves federal bodies, and optionally cantons and communes, but not the private sector.

  • Kantonale Staatsanwaltschaften

    Prosecute the criminal offences in the Data Protection Act, banking secrecy under the Banking Act and professional secrecy under the Criminal Code

    Operational as general criminal authorities, but data protection prosecutions are rare. Article 65 of the Data Protection Act gives prosecution and judgment to the cantons. Most offences run only where someone complains, and the time limit is five years. We found no evidence of a published criminal conviction under the new Data Protection Act during the review period.

  • Bundesverwaltungsgericht (BVGer)

    Hears appeals against the Commissioner's rulings and against decisions of federal regulators

    Operational. The judgment of 6 October 2025 upheld the Commissioner's ruling against Buergerforum Schweiz. The Commissioner calls it the first legally binding validation of its post-2023 way of making decisions. Judgment A-3891/2025 of 22 June 2026 dealt with the Inkasso-Team ruling.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether the European Union's official “this country is safe” decision for Switzerland has been renewed or reviewed since January 2024

    We could not confirm this. It governs data moving from the European Union INTO Switzerland, which is the direction most companies care about. For this record we cite only Swiss government sources, and no Swiss federal page we read states the current status of the European Commission's decision. Treat the inbound direction as unverified here, and check with the European Commission.

  • Whether any criminal fine has actually been imposed under Articles 60 to 63 of the Data Protection Act since 1 September 2023

    We could not confirm whether anyone has been convicted. Prosecution is a cantonal matter under Article 65, and there is no central federal register of cantonal data protection convictions we could search. The Commissioner's 33rd annual report describes investigations and rulings, but we found no reported conviction. We can show that no cases have been published, not that no cases exist.

  • Whether an offshore cloud provider can lawfully be treated as an 'auxiliary' under Article 321 of the Criminal Code

    We could not confirm how far the secrecy duty reaches. The article punishes the listed professionals 'and their auxiliaries'. On its wording, that extends the duty to helpers rather than excusing them. Swiss practice on whether an outsourced foreign supplier falls inside that word is disputed. We found no federal court ruling or regulator guidance settling it. That is why we rate the professional-secrecy area as conditional and backed by criminal law, rather than closed.

  • The exact status of the revision of the Ordinance on the Surveillance of Post and Telecommunications

    We can show one thing. On 18 August 2026 the official federal law collection still showed 26 March 2024 as the ordinance's latest version. So no revision has started. One thing we could not establish from a government source. Whether a revised text has been formally adopted with a future start date, or is still a draft.

  • The commencement date of the Federal Act on Electronic Identity Credentials and Other Electronic Credentials

    The Act does not appear in the consolidated federal law collection as at 18 August 2026. The financial regulator's own pending-projects table of 1 June 2026 says its circular revision depends on the Act coming into force. That revision is planned for the fourth quarter of 2026. That is strong evidence the Act is not yet in force. But we did not find a Federal Council decree fixing the date.

  • Whether any Swiss federal rule restricts where mapping or geospatial data may be stored

    We found no rule about where this data must be stored, checked 18 August 2026, confidence medium. The Geoinformation Ordinance sorts official geodata into three access levels but says nothing about storage location. Limits on imagery of military installations sit in defence law we did not fully review. Check before you rely on this.

  • Whether cantonal data protection laws impose their own storage-location rules on cantonal hospitals, schools and authorities

    There are 26 cantonal systems, each with its own law and its own commissioner. Several cantons are known to apply stricter cloud rules to cantonal hospitals than federal law requires. Reviewing all 26 was outside the scope of this pass. Treat any Swiss public-sector deal as needing a separate cantonal check.

  • The precise number of entries in Annex 1 of the Data Protection Ordinance

    We counted 44 numbered entries in the consolidated English text dated 1 December 2025. The annex mixes states, territories and one industry-specific entry, and the English translation has no legal force. Use the German, French or Italian text for anything binding.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.