8 min read
Choosing software in Switzerland: six questions to ask
Six questions a Swiss business can put to a software provider before handing over customer data — and where the answers are usually published.

A joinery in Langenthal is moving its job management out of Excel and into a web application. Three providers make the shortlist, all three look tidy, all three promise security. What ends up in the system is names, addresses, phone numbers, quotes and invoice amounts belonging to customers — personal data the business answers for, even though it sits on somebody else’s server.
The six questions below are phrased so that the answer is usually published somewhere already: in the legal notice, in the privacy policy, in the contract, in a public register. If you know where to look, you do not have to take anyone’s word for it.
1. Who is the provider — and in which role does it process the data?
The Swiss Federal Act on Data Protection (FADP) distinguishes two roles. The controller decides on the purpose and the means of the processing; the processor handles data on the controller’s behalf. A business that uses software to keep its own customer records is, as a rule, the controller, and the provider is the processor. The Federal Data Protection and Information Commissioner (FDPIC) puts it plainly: responsibility for data protection stays with the client even when the processing is outsourced — the client has to select the processor carefully, instruct it appropriately and supervise it as far as necessary.
That includes the simple question of who the contracting party legally is: a Swiss GmbH, a foreign company with a Swiss address, or a group of several entities. A provider based abroad that regularly processes data about people in Switzerland on a large scale, with a high risk to those people, also has to designate a representative in Switzerland and publish that representative’s name and address (Art. 14 FADP).
Where the answer sits: in the legal notice (the Impressum) and the terms. A company entered in the commercial register can be looked up through the central business name index, Zefix — the register is a public source of business information and exists precisely for this kind of checking.
2. Where is the data processed — and who else is involved?
Hardly any provider runs everything itself. Behind an application there is usually a data centre, a backup service, an email sender, sometimes external support. Those are sub-processors, and the law does not treat them as a footnote: a processor may delegate processing to a third party only with the controller’s prior authorisation (Art. 9 para. 3 FADP). Where that authorisation is general, the processor has to report any intended addition or replacement, and the controller may object (Art. 7 DPO).
In its checklist on cloud services, the FDPIC accordingly asks whether the provider has an overview of its sub-processors, whether the corresponding documentation has been made available, and whether it shows in which countries the data is processed.
Where the answer sits: in the privacy policy and, with many providers, in a separately published sub-processor list giving purpose, company and country. If there is none, that is an answer in itself — and one that can be put in an email.
3. And if data goes abroad?
Personal data may be disclosed abroad where the Federal Council has established that the state in question guarantees adequate protection (Art. 16 para. 1 FADP). Which states those are is not stated in a provider’s brochure but in Annex 1 to the Data Protection Ordinance — a public list that, in the version of 1 December 2025, contains forty-four entries: the EU and EEA states, plus the United Kingdom, Canada, Israel, New Zealand and Uruguay among others.
The entry for the United States carries a condition: adequate protection applies to personal data processed by organisations certified under the principles of the Swiss-U.S. Data Privacy Framework. That addition to the list took effect on 15 September 2024. Where no such decision exists for a country, Art. 16 para. 2 FADP names the available safeguards — standard data protection clauses approved, issued or recognised by the FDPIC, data protection clauses in a specific contract, binding corporate rules.
For the business itself this has a practical consequence. Where personal data is disclosed abroad, the state — and, where applicable, the safeguard — is part of what the data subject is told (Art. 19 para. 4 FADP). The same details are mandatory entries in the record of processing activities (Art. 12 para. 2 FADP). What a provider does not supply cannot be passed on.
Where the answer sits: Annex 1 DPO is freely available on Fedlex. The countries and the safeguards a provider relies on are in its privacy policy or in its data processing agreement.
4. What does the contract say about instructions, security and incidents?
Art. 9 FADP ties outsourcing to two conditions: the data is processed the way the controller itself would be allowed to process it, and no statutory or contractual duty of confidentiality prohibits the delegation. The controller has in particular to satisfy itself that the processor is able to guarantee data security. What that means technically is set out in the Ordinance: confidentiality, availability, integrity and traceability, with logging where sensitive personal data is processed automatically on a large scale.
The FDPIC names audits and certifications as ways of checking whether the measures taken are appropriate to the risk, effective and current; the FADP expressly provides for the certification of systems, products and services by recognised independent bodies (Art. 13 FADP). A second point concerns the bad day: the processor has to report a breach of data security to the controller as quickly as possible, so that the controller can meet its own duty to notify the FDPIC (Art. 24 FADP).
Where the answer sits: in the data processing agreement, which many providers offer as a standard document to download, and on a security page linking audit reports and certificates.
5. Export, deletion — and what happens when the contract ends
Two questions that are rarely asked while everything is running smoothly. First: in what format does the data come back out, without the provider having to do anything by hand? Second: what happens to it when the contract ends? The FDPIC lists both in its cloud checklist and asks explicitly whether it is agreed, or can be determined, that the provider deletes or returns the personal data once the contract is over.
Two provisions of the FADP sit behind this. Personal data is destroyed or anonymised as soon as it is no longer required for the purpose of processing (Art. 6 para. 4). And any person may request from the controller the release of the personal data they have disclosed to it, in a commonly used electronic format — provided the processing is automated and rests on consent or on a contract (Art. 28 FADP). A business that can only get its data out of a piece of software as a PDF printout will struggle to meet that.
Where the answer sits: in the terms, under termination and end of contract, and in the product’s help pages under “export” — which is also where it becomes clear what formats actually exist.
6. Who answers when someone requests access?
Anyone may ask a controller whether personal data about them is being processed, and receives among other things the data itself, the purpose, the retention period and the recipients (Art. 25 FADP). The information is in principle free of charge and is provided within 30 days as a rule; the Ordinance sets the same deadline and allows a contribution to costs of at most CHF 300, and only where the effort would be disproportionate (Art. 18 and 19 DPO).
The request is addressed to the business, not to the provider: where a controller has personal data processed by a processor, the duty to provide information stays with the controller (Art. 25 para. 4 FADP). The processor supports it in doing so, unless it answers the request on the controller’s behalf (Art. 17 para. 2 DPO). In practice that means the software has to make one individual’s data findable — and somebody at the provider has to be reachable when it does not.
Where the answer sits: in the privacy policy, which has to name a contact point, and in the data processing agreement under the duty to cooperate.
The six questions at a glance
| Question | Where the answer usually sits |
|---|---|
| Who is the contracting party? | Legal notice, terms, commercial register (Zefix) |
| Who else processes the data? | Privacy policy, sub-processor list |
| Does data go abroad? | Privacy policy, contract; Annex 1 DPO on Fedlex |
| What applies to security and incidents? | Data processing agreement, security page |
| How does the data come back out? | Terms on end of contract, product help on export |
| Who helps with an access request? | Privacy policy, data processing agreement |
The pleasant thing about these six questions is that none of them calls for expertise. They only call for somebody to look — and for the answers to exist in writing rather than in a sales conversation. Whoever gathers them once for a provider has, along the way, most of what a privacy policy or a record of processing activities will need anyway. And when a customer asks where her data is kept, the answer fits in a sentence.
Sources
- 1.Bundesgesetz über den Datenschutz (DSG, SR 235.1) (checked on 23 September 2026)
- 2.Datenschutzverordnung (DSV, SR 235.11), Stand 1. Dezember 2025 (checked on 23 September 2026)
- 3.EDÖB: Outsourcing (Auftragsbearbeitung) (checked on 23 September 2026)
- 4.EDÖB: Datenbearbeitungen in der Cloud (checked on 23 September 2026)
- 5.EDÖB: Bekanntgabe von Personendaten ins Ausland (checked on 23 September 2026)
- 6.Bundesamt für Justiz: Handelsregister, Zefix und Regix (checked on 23 September 2026)
Follow our ideas
Look at our ideas and ask to be told once when one of them becomes an app. Or write to us – about an idea, about a task that deserves an app, or just to say hello.