6 min read
What “data in Switzerland” means — and what it does not
Storage location, applicable law, access and sub-processors are four separate questions. What a Swiss data centre answers, and what it leaves open.

“Data in Switzerland” appears on a great many websites. On ours too. The phrase sounds like a complete answer, and that is exactly what it is not: it answers one of several questions, and which one is usually left unsaid.
A physiotherapy practice in Winterthur choosing scheduling software hears the phrase in the sales conversation. A private person opening an account with a note-taking app reads it on the home page. Both come away understanding that the data does not leave the country. What is actually being promised is narrower — and what stays open can be named.
Four questions usually asked as one
“Data in Switzerland” covers four questions that can be answered independently of each other.
| Question | What it asks |
|---|---|
| Storage | In which country are the servers that hold the data? |
| Applicable law | Which law governs the processing, and where is the provider based? |
| Access | Who is allowed to see the data, and for what purpose? |
| Sub-processors | Whom does the provider bring in, and where do those contractors work? |
A data centre in Zurich answers the first question. On its own, it says little about the other three.
Storage: what a Swiss data centre does answer
Storage is the easiest of the four to check and the easiest to document. That is also why it turns up most often as an argument.
It is not unimportant. Where data rests has a bearing on which authorities are physically near it, which lines it crosses in operation, and what a practice can tell a client who asks. But it is a place, not an assurance about who may look inside.
One further distinction tends to get lost in everyday use: data at rest and data being processed are not the same thing. A backup can sit in Switzerland while support, debugging or a content delivery network happen elsewhere.
Applicable law and domicile: not the same as storage
The Swiss Data Protection Act (FADP) does not attach to the location of a server but to effect: it applies to matters that have an effect in Switzerland, even if they are initiated abroad (Art. 3 para. 1 FADP). A foreign provider serving people in Switzerland does not therefore fall outside the act automatically.
The reverse holds as well. A provider based in Switzerland is not automatically a provider that stores in Switzerland. Domicile, storage location and group ownership are three separate facts. A Swiss business can build on foreign infrastructure, and a Swiss subsidiary can belong to a foreign parent company.
The FADP leaves one visible trace here: private controllers domiciled abroad have to designate a representative in Switzerland when they process personal data of people in Switzerland extensively, regularly and with a high risk, and the processing is connected to an offering in Switzerland (Art. 14 FADP). The controller publishes that representative’s name and address.
Access and sub-processors: the chain behind the provider
Whoever uses a piece of software normally remains the controller; the provider is the processor. The act permits that delegation where the data is processed as the controller itself would be allowed to, and no duty of confidentiality stands in the way (Art. 9 para. 1 FADP). The controller has to satisfy itself that the processor is able to ensure data security (Art. 9 para. 2 FADP).
The paragraph that matters for this post is the third: a processor may delegate processing to a third party only with the controller’s prior authorisation (Art. 9 para. 3 FADP). That authorisation may be specific or general. Where it is general, the processor informs the controller of every intended change regarding the addition or replacement of other third parties, and the controller may object (Art. 7 DPO).
That is where the chain comes from. Behind one piece of software there is often a hosting provider, a delivery network, an email sender, an error log and a support tool. Each of them is a separate place and a separate answer to the question about access.
Where something does leave Switzerland, the rules on disclosure abroad apply. Disclosure is permitted where the Federal Council has determined that the state in question ensures adequate protection (Art. 16 para. 1 FADP); those states, territories and bodies are listed individually in Annex 1 DPO. Absent such a decision, safeguards such as standard data protection clauses or binding corporate rules come into play (Art. 16 para. 2 FADP), alongside the exceptions in Art. 17 FADP. The Federal Data Protection and Information Commissioner describes these routes on its page about disclosure abroad.
Where the answers are written down
The four questions can be looked up, in places that exist anyway.
With the provider. Many providers publish a list of their sub-processors. Cloudflare, for instance, keeps such a list public and states that it relies on sub-processors to deliver its services. The technical documentation is telling too: in its Regional Services documentation, Cloudflare describes that traffic is accepted at any of its data centres worldwide and that this feature confines decryption to a configured region. Pages like these say more about storage and processing than a sentence on a home page.
In the privacy statement. Anyone collecting personal data informs the data subject about the purpose, the controller’s identity and, where applicable, the recipients or categories of recipients (Art. 19 para. 2 FADP). Where data is disclosed abroad, that includes the state and, where applicable, the safeguard under Art. 16 para. 2 FADP or the exception under Art. 17 FADP (Art. 19 para. 4 FADP).
Through the right of access. Any person may request to know whether personal data about them is being processed, and receives among other things the recipients and the information under Art. 19 para. 4 FADP (Art. 25 FADP). The information is in principle free of charge and is generally provided within 30 days.
In one’s own record. Controllers and processors each keep a record of their processing activities, which for a disclosure abroad contains the state and the safeguards (Art. 12 FADP). Businesses with fewer than 250 employees on 1 January are exempt, unless sensitive personal data is processed on a large scale or high-risk profiling takes place (Art. 24 DPO). Many small businesses keep a short list of their service providers anyway, because the answer to a client’s question then follows from it.
The distinction applies to us too
We write “data in Switzerland” about our apps, and by that we mean where the data an app stores for you is held: infrastructure in Switzerland. This website is a different case. It is delivered through Cloudflare, an international provider — precisely the distinction this post is about. We consider that more honest than spreading the phrase across everything we run.
The four questions are not a test a provider passes or fails. They are four separate facts that can be found one at a time — and a sentence that appears to answer all four at once usually answers the first.
Sources
- 1.Bundesgesetz über den Datenschutz (DSG, SR 235.1) (checked on 23 September 2026)
- 2.Datenschutzverordnung (DSV, SR 235.11), Fassung in Kraft seit 15. September 2024 (checked on 23 September 2026)
- 3.EDÖB: Bekanntgabe von Personendaten ins Ausland (checked on 23 September 2026)
- 4.Cloudflare Docs: Regional Services (checked on 23 September 2026)
- 5.Cloudflare: Sub-processors (checked on 23 September 2026)
Follow our ideas
Look at our ideas and ask to be told once when one of them becomes an app. Or write to us – about an idea, about a task that deserves an app, or just to say hello.