Skip to the content
Global Data RulesData governance rules, country by country

Switzerland

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: MediumEnforcement: Active

Switzerland is easy to send data out of, as long as the destination is one the government trusts. An official list names about 44 approved places, including every European Union country and United States firms in one certification scheme. Anywhere else, you sign an approved contract first. The sting is elsewhere: getting it wrong is a crime, and the case lands on a person, not the company.

Eight questions about Switzerland

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Switzerland's rules apply to my company?

Yes. Swiss privacy law reaches any organisation whose activities have an effect in Switzerland, even one with no office, staff or company here. There is no revenue or headcount threshold to duck under, and there is no register to sign up to. You only need a named representative inside Switzerland if four things are true at once: you are selling to people here or watching what they do, you are doing it on a large scale, you are doing it regularly, and the processing is high risk for the people involved. Very few foreign companies meet all four.

High confidenceNational rulesAppoint a local representativeKeep records of processing

Can I store my users' data outside Switzerland?

In general, yes. Switzerland publishes an official list of countries and territories it considers safe, and data can move to any of them with no extra paperwork. The list has about 44 entries. It covers all 27 European Union countries, the United Kingdom, Norway, Iceland, Liechtenstein, Canada, Israel, Argentina, Uruguay and New Zealand. It covers the United States only for companies signed up to one specific certification scheme. Japan is not on it, even though the European Union treats Japan as safe. For anywhere not on the list, you sign an approved contract first. But three industries override this completely, and one of them is an outright ban.

High confidenceDepends on your industryAllowlistNo — it stays putYes, with paperwork

What do I need in place before data leaves Switzerland?

The model is an approved-destinations list, and it is well populated: about 44 countries, territories and one sector-specific entry are on it right now. Send data to a listed place and you need nothing at all. Send it anywhere else and you need one of a short menu of safeguards, the most common being a standard contract. Switzerland has formally accepted the European Union's standard contract template, so most companies can reuse the paperwork they already have.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentNeeded for a contractImportant public interestLegal claimsSomeone's life is at risk

Who enforces the rules in Switzerland, and what can they do?

The main regulator is the Federal Data Protection and Information Commissioner. It is real, fully staffed and busy: in the year to 31 March 2026 it ran 156 low-level interventions, 22 preliminary enquiries and 9 formal investigations, and it had 2 cases running in the Federal Administrative Court. It has issued binding orders against a bank, a debt collection firm and a fashion group, and in October 2025 the court confirmed its new way of working. The catch is that this regulator cannot fine anyone. Fines under the privacy law are criminal, they are handed out by cantonal prosecutors, and they land on individual people.

High confidenceActiveRegulator

How long do I have to keep the data?

Both directions apply and they pull against each other. The floor: business books, accounting records and audit reports must be kept for ten years. Financial market infrastructures keep their records ten years, trade repositories keep trade data ten years after the contract matures, electronic patient record access logs are kept ten years, and telecoms companies keep connection records for six months. The ceiling: the privacy law says personal data must be destroyed or made anonymous as soon as it is no longer needed. There is no fixed number. Where the two clash, the specific legal duty to keep wins.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Count four clocks, not one. The privacy regulator must be told 'as quickly as possible' when a breach is likely to put people at serious risk, with no number of hours attached. If you run critical infrastructure, you have a hard 24 hours to tell the national cyber security office. If you are supervised by the financial regulator, you have 24 hours to notify your supervisor and 72 hours to file the full report. Electronic patient record communities have to report security incidents to the health office. Most failures come from teams who set a single deadline and miss the others.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Switzerland?

Five things that are not in the summary. One: the penalty is a criminal fine on a named human being, not an administrative fine on the company, so your compliance lead is personally exposed. Two: sending data abroad without a valid safeguard is itself a crime. Three: banking secrecy and medical or legal secrecy are criminal laws with prison ceilings, and a standard supplier contract does not fix them. Four: cantonal authorities and cantonal hospitals are outside the federal law entirely. Five: the 24-hour cyber report has no penalty for being late, which misleads people into thinking it is optional.

High confidenceCriminal liabilityFixed maximum fineExtra vendor secrecy termsState or provincial rule

What is changing soon in Switzerland?

Nothing in the next twelve months changes where Swiss data may be stored. The electronic identity law has passed but is not switched on yet, and the financial regulator is holding a rule change until it is. A company transparency law hits banks on 1 October 2026. A rewrite of the telecoms surveillance rules has been announced for years and still has not landed. The bigger risk is not new legislation at all: the government can rewrite the approved-destinations list by itself, overnight, with no vote and no consultation.

Medium confidenceProposedPassed, not yet fully in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    7 rules here

  3. Layer 3

    Contract-imposed rule

    Binds you because you signed something, typically a government contract.

    1 rule here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules3 rules

Bundesgesetz ueber den Datenschutz (Datenschutzgesetz, DSG) / Federal Act on Data Protection (FADP)

Act of parliament · SR 235.1, Act of 25 September 2020

In forceYes, with paperwork

Switzerland's general privacy law. Data may leave the country freely to about 44 approved destinations and, elsewhere, once an approved safeguard such as a standard contract is in place. There is no registration, no mandatory data protection officer and a records exemption for organisations under 250 employees. Penalties are criminal fines on individuals, capped at 250,000 francs, not administrative fines on companies.

In force since 1 September 2023

Enforced by Federal Data Protection and Information Commissioner

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk

High confidence

Datenschutzverordnung (DSV), Anhang 1 - Staaten, Gebiete, spezifische Sektoren und internationale Organe mit angemessenem Datenschutz

Adequacy decision · SR 235.11, Annex 1, as amended by the Ordinance of 14 August 2024

In forceYes — store it anywhere

The approved-destinations list. About 44 entries covering the European Economic Area, the United Kingdom, Canada, Israel, Argentina, Uruguay, New Zealand, Monaco, Andorra, the Channel Islands and others. The United States is on the list only for organisations certified under the Swiss-United States Data Privacy Framework. The Federal Council can add or remove entries by ordinance alone.

In force since 15 September 2024

Enforced by Swiss Federal Council

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision

High confidence

Bundesgesetz ueber die Informationssicherheit (Informationssicherheitsgesetz, ISG), 5a. Kapitel - Meldepflicht fuer Cyberangriffe auf kritische Infrastrukturen

Act of parliament · SR 128, Articles 74a to 74h, inserted by the Federal Act of 29 September 2023

In forceYes — store it anywhere

Since 1 April 2025 operators of Swiss critical infrastructure must report a serious cyberattack to the national cyber security office within 24 hours of discovering it. The list of who counts is long and includes every bank, insurer, listed hospital, energy company and public authority. Being late is not directly punishable; ignoring the office's follow-up order is, up to 100,000 francs, about 125,000 dollars.

In force since 1 April 2025

Enforced by Federal Office for Cyber Security

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules7 rules

Verordnung ueber das elektronische Patientendossier (EPDV)

Directly binding regulation · SR 816.11, Article 12 paragraph 5 and Article 25 paragraph 6 · Health and social care

In forceNo — it stays put

The hardest storage rule in Swiss law. For the national electronic patient record system, the data stores must physically be in Switzerland and must be governed by Swiss law. The same applies to the systems of organisations that issue the login credentials patients and health professionals use.

In force since 15 April 2017

Enforced by Federal Office of Public Health

Transfer model: Not allowed

High confidence

Bundesgesetz ueber die Banken und Sparkassen (Bankengesetz, BankG), Artikel 47

Act of parliament · SR 952.0, Article 47 · Banking

In forceYes, with paperwork

Swiss banking secrecy is criminal law, not privacy law. Deliberately revealing information about a bank's client can put a named employee in prison for up to three years, or five if they profited. Careless disclosure is a fine of up to 250,000 francs, about 310,000 dollars. It keeps applying after the person leaves the bank, and cantonal prosecutors run the cases.

In force since 1 January 2009But only enforceable from 1 July 2015

Enforced by Swiss Financial Market Supervisory Authority

Transfer model: Approval each time · Accepted routes: Explicit consent, Legal claims

High confidence

FINMA-Rundschreiben 2018/3 'Outsourcing - Banken, Versicherungsunternehmen und ausgewaehlte Finanzinstitute nach FINIG'

Regulator directive · FINMA Circular 18/3, of 21 September 2017, last amended 4 November 2020 · Finance

In forceA copy must stay

Banks, insurance companies and certain investment firms may outsource abroad, but only if the firm, its auditor and the regulator can enforce inspection and audit rights against the foreign provider, and only if the data needed to restructure or wind up the firm stays reachable inside Switzerland at all times. In effect a partial mirroring duty rather than a ban.

In force since 1 April 2018But only enforceable from 1 April 2023

Enforced by Swiss Financial Market Supervisory Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Contract-imposed rule1 rule

Swiss Government Cloud (SGC) und Cloud-Strategie der Bundesverwaltung

Government policy document · Federal Council cloud strategy of 11 December 2020; Swiss Government Cloud programme, commitment credit CHF 246.9 million, 2025 to 2032 · Government

Partly in forceDepends on your industry

The Swiss federal government is building its own three-tier cloud between 2025 and 2032 for about 247 million francs, roughly 305 million dollars. One tier requires data to be held and processed in Switzerland and one keeps it in federal data centres. This binds suppliers through procurement contracts, not through law, and it is being built rather than finished.

In force since 1 January 2025

Enforced by Federal Office of Information Technology, Systems and Telecommunication

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

Who you would hear from

  • Eidgenoessischer Datenschutz- und Oeffentlichkeitsbeauftragter (EDOEB) / Prepose federal a la protection des donnees et a la transparence (PFPDT)

    General data protection law over private organisations and federal bodies, plus freedom of information

    Fully operational and long-established. Commissioner Adrian Lobsiger, Deputy Commissioner Florence Henguely. In the year to 31 March 2026 it recorded 156 low-threshold interventions, 22 preliminary enquiries, 9 formal investigations under Article 49 of the Data Protection Act and 2 matters pending before the Federal Administrative Court. Published binding rulings in 2024, 2025 and 2026, the most recent dated 17 April 2026 and published on 4 August 2026. Its practice was validated by the Federal Administrative Court on 6 October 2025. Important limitation: it cannot impose fines. It issues binding orders and may file criminal complaints.

  • Schweizerischer Bundesrat / Conseil federal suisse

    Decides which countries are on the approved-destinations list, and holds most of the dormant ordinance-making powers

    Amends Annex 1 to the Data Protection Ordinance by ordinance alone. Last amendment 14 August 2024, in force 15 September 2024, adding the United States for Data Privacy Framework certified organisations.

  • Eidgenoessische Finanzmarktaufsicht FINMA

    Banks, insurers, investment firms, fund managers, financial market infrastructures. Outsourcing rules, cyber incident reporting, prior approval for outsourcing by market infrastructures

    Operational and publishing continuously. Its pending-regulation table was updated on 1 June 2026 and lists projects through to 2028. It can attach conditions to authorisations, order unwinding of outsourcing arrangements and withdraw licences.

  • Bundesamt fuer Cybersicherheit (BACS) / Office federal de la cybersecurite

    Receives the mandatory 24-hour cyberattack reports from critical infrastructure operators and can issue enforceable orders

    The reporting duty commenced on 1 April 2025 and the office runs the secure reporting system required by Article 74f of the Information Security Act. It can issue formal orders whose breach is punishable by a fine of up to 100,000 francs.

  • Dienst Ueberwachung Post- und Fernmeldeverkehr (Dienst UEPF)

    Telecoms metadata retention and interception; runs administrative criminal proceedings against non-cooperating providers

    Plainly operational. In 2025 it processed 1,878 real-time interceptions, 6,531 retroactive surveillance measures, 1,287 emergency traces and 650,034 simple information requests, with total measures up about 40 per cent on 2024. Its 2025 annual report was published on 30 June 2026.

  • Bundesamt fuer Gesundheit (BAG)

    Electronic patient record system, including the requirement that data stores be in Switzerland

    Operational. Receives security incident reports from electronic patient record communities and oversees the certification regime. A comprehensive revision of the electronic patient record law is in progress.

  • Bundesamt fuer Informatik und Telekommunikation (BIT)

    Builds and runs the Swiss Government Cloud, including its Swiss-only tiers

    Operational. The Swiss Government Cloud programme runs 2025 to 2032 with a commitment credit of 246.9 million francs and total costs of 319.4 million francs. It serves federal bodies, and optionally cantons and communes, but not the private sector.

  • Kantonale Staatsanwaltschaften

    Prosecute the criminal offences in the Data Protection Act, banking secrecy under the Banking Act and professional secrecy under the Criminal Code

    Operational as general criminal authorities, but data protection prosecutions are rare. Article 65 of the Data Protection Act assigns prosecution and adjudication to the cantons, and most offences run only on complaint, with a five-year limitation period. We found no evidence of a published criminal conviction under the new Data Protection Act during the review period.

  • Bundesverwaltungsgericht (BVGer)

    Hears appeals against the Commissioner's rulings and against decisions of federal regulators

    Operational. Judgment of 6 October 2025 upheld the Commissioner's ruling against Buergerforum Schweiz and is described by the Commissioner as the first legally binding validation of its post-2023 decision-making practice. Judgment A-3891/2025 of 22 June 2026 dealt with the Inkasso-Team ruling.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether the European Union's adequacy decision for Switzerland has been renewed or reviewed since January 2024

    This governs data moving from the European Union INTO Switzerland, which is the direction most companies care about. We deliberately restricted citations to Swiss government sources for this record, and no Swiss federal page we fetched states the current status of the European Commission's decision. Treat the inbound direction as unverified here and check the European Commission directly.

  • Whether any criminal fine has actually been imposed under Articles 60 to 63 of the Data Protection Act since 1 September 2023

    Prosecution is a cantonal matter under Article 65, and there is no central federal register of cantonal data protection convictions that we could query. The Commissioner's 33rd annual report describes investigations and rulings but we found no reported conviction. We can evidence the absence of published cases, not the absence of cases.

  • Whether an offshore cloud provider can lawfully be treated as an 'auxiliary' under Article 321 of the Criminal Code

    The article punishes listed professionals 'and their auxiliaries', which by its wording extends the secrecy duty to helpers rather than creating an exemption for them. Swiss practice on whether an outsourced foreign processor falls inside that word is contested and we found no federal court ruling or regulator guidance settling it. This is why we rate the professional-secrecy sector as conditional with a criminal wall rather than closed.

  • The exact status of the revision of the Ordinance on the Surveillance of Post and Telecommunications

    We can prove a negative in one respect: the consolidated ordinance in the official federal law collection still shows 26 March 2024 as its latest version on 18 August 2026, so no revision has commenced. What we could not establish from a government source is whether a revised text has been formally adopted with a future commencement date, or is still at draft stage.

  • The commencement date of the Federal Act on Electronic Identity Credentials and Other Electronic Credentials

    The Act does not appear in the consolidated federal law collection as at 18 August 2026, and the financial regulator's own pending-projects table of 1 June 2026 states that its circular revision depends on the Act entering into force, with the revision planned for the fourth quarter of 2026. That is strong evidence it is not yet in force, but we did not locate a Federal Council decree fixing the date.

  • Whether any Swiss federal rule restricts where mapping or geospatial data may be stored

    No rule found, checked 18 August 2026, confidence medium. The Geoinformation Ordinance sorts official geodata into three access tiers but is silent on storage location. Restrictions on imagery of military installations sit in defence legislation we did not fully review.

  • Whether cantonal data protection laws impose their own storage-location rules on cantonal hospitals, schools and authorities

    There are 26 cantonal regimes and each has its own statute and commissioner. Several cantons are known to apply stricter cloud rules to cantonal hospitals than federal law requires. Reviewing all 26 was outside the scope of this pass, so treat any Swiss public-sector deal as needing a separate cantonal check.

  • The precise number of entries in Annex 1 of the Data Protection Ordinance

    We counted 44 numbered entries in the consolidated English text dated 1 December 2025, but the annex mixes states, territories and one sector-specific entry, and the English translation has no legal force. Use the German, French or Italian text for anything binding.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.