Home
Web Hosting
Domains FAQ
Resources
About Contact Client Portal
Guides ยท ยท 14 min read

Dedicated Servers in Switzerland: Hardware, Privacy and Swiss Law in 2026

ยท 14 min read

Anyone shopping for dedicated servers in Switzerland is buying two things at once, and only one of them is measurable. The hardware is easy to check: real cores, real disks, nobody else on the box. The jurisdiction is where the marketing lives, and it gets sold with far more confidence than the law supports.

This guide separates the two. What dedicated hardware genuinely changes about your exposure, what our Swiss machines actually are and cost, what Swiss law does and does not do for you, and what is currently moving through Bern that could change the answer.

What a dedicated server changes that a VPS does not

On a VPS your operating system runs inside a hypervisor somebody else controls. That is not a scandal, it is how virtualisation works. But it has three consequences worth stating plainly.

The first concerns memory. Full disk encryption on a VPS protects the disk at rest, but the decryption key lives in RAM while the machine is running, and the hypervisor layer can reach that memory. On a dedicated server there is no provider-controlled hypervisor sitting underneath your operating system with routine access to guest memory. The datacentre still has physical access, and on hardware with a management controller, out-of-band access. So dedicated hardware removes one meaningful layer of exposure. It does not remove provider access.

The second is that you share nothing. No noisy neighbour, no shared IP reputation, no other customer on the same box whose behaviour draws attention to the hardware you happen to be sitting on. Fair-use terms that aggregate across services on a shared host stop applying when the host is yours alone.

The third is scope. If a machine ever has to be examined, a dedicated server contains one customer's data. A shared virtualisation node does not. In practice authorities prefer targeted requests to seizing hardware, but it remains a real difference in how entangled your environment is with strangers.

What it does not change: the provider still receives legal process, the datacentre still has hands on the metal, and the network path is still somebody else's. Dedicated hardware raises the floor. It does not put you out of reach.

Our dedicated servers in Switzerland: the full lineup

We run six dedicated servers in Switzerland, in two families that suit genuinely different workloads. Picking the wrong family is the most common and most expensive mistake on this page, so the short version first: if your workload cares how fast one core is, buy single-socket. If it cares how many cores there are, buy dual-socket.

Single-socket: modern cores, unmetered bandwidth

Fewer cores but much faster ones, DDR5 memory, NVMe throughout, software RAID-1 by default, same-day delivery. This is the right family for web applications, game servers, databases, VPNs and anything sensitive to single-thread performance.

Plan CPU Cores RAM Storage Network Price
AD1 Ryzen 7 PRO 8700GE 8C / 16T 64GB DDR5 2 x 512GB NVMe 1 Gbit/s unmetered EUR 163.90/mo
AD2 Ryzen 7 PRO 8700GE 8C / 16T 128GB DDR5 2 x 1.92TB NVMe 1 Gbit/s unmetered EUR 303.90/mo
AD3 Ryzen 9 7950X3D 16C / 32T 128GB DDR5 2 x 1.92TB NVMe 1 Gbit/s unmetered EUR 362.90/mo

A note on AD1 against AD2: identical processor, identical core count. What you are paying the difference for is memory and disk, 64GB against 128GB and half a terabyte against nearly four. If your application is CPU-bound rather than memory-bound or storage-bound, AD1 will perform the same as AD2 and the upgrade buys you nothing. AD3 is the one that adds cores, and the 7950X3D's large cache makes it the pick for databases and simulation work that thrash memory.

Dual-socket: high core count, 10G networking

Enterprise hardware built for parallel work: virtualisation, build farms, video encoding, many concurrent containers, heavy database concurrency. Five dedicated IPv4 addresses each, 10G networking with a 100TB allowance, and IPMI KVM on the upper two for out-of-band console access. Delivery is 24 to 48 hours rather than same day.

Plan CPU Cores RAM Storage Network Price
IN1 2 x Intel Xeon E5 28C / 56T 64GB DDR4 1TB SSD 1G unmetered or 10G 100TB EUR 182.90/mo
IN2 2 x Intel Xeon Gold 40C / 80T 64GB DDR4 1TB NVMe 10G, 100TB EUR 248.90/mo
EPYC 2 x AMD EPYC 7 Series 64C / 128T 64GB DDR4 1TB NVMe 10G, 100TB EUR 421.50/mo

One thing worth understanding about the dual-socket family: 128 threads against 64GB of RAM is a deliberately core-heavy ratio, half a gigabyte per thread. That is generous for encoding and build work and tight for memory-hungry databases or dense virtualisation. If your bottleneck is memory rather than parallelism, AD2 or AD3 with 128GB of DDR5 will serve you better than the EPYC box at a lower price. Buy the shape of your workload, not the largest number on the page.

Both families include full root access, dedicated IPv4, a /64 IPv6 allocation, DDoS protection and a choice of operating systems. Where a one-time setup fee applies it is passed through from our upstream rather than baked into the monthly price, and it is waived entirely on terms of six months or longer.

What Swiss jurisdiction actually gives you

First, a myth to clear out of the way, because it appears on a great many Swiss hosting pages. Swiss banking secrecy is banking law. It governs financial intermediaries and their client relationships. It does not extend to your web server, and no hosting provider inherits it by renting rack space in Zurich. Anyone implying otherwise is selling you a feeling rather than a legal protection.

What genuinely applies is the revised Federal Act on Data Protection, in force since 1 September 2023. It governs data processing according to its own territorial scope, which reaches circumstances having an effect in Switzerland even where they were initiated abroad, and it is enforced by the Federal Data Protection and Information Commissioner rather than by an EU authority. What it does not do is cancel obligations you carry under foreign law because of who you are and who you sell to. Our guide to Swiss data protection law and hosting works through what the FADP genuinely protects.

For a foreign authority seeking data held in Switzerland, the route is mutual legal assistance. That means a formal request, Swiss review, and, where coercive measures are needed, the principle of dual criminality. It adds procedural steps and puts a Swiss decision-maker between the requesting authority and your data rather than granting direct access. That is friction and independent review. It is not a wall, and no honest provider will tell you otherwise.

Where e-Evidence really lands, and why "outside the EU" is not the whole answer

From 18 August 2026, the EU e-Evidence Regulation gives competent judicial authorities in the member states a much faster route to electronic evidence, with production deadlines of ten days and eight hours in emergencies. It is the largest change to cross-border data access in European hosting in two decades, and we cover the mechanics in our guide to the EU e-Evidence Regulation and what it means for hosting customers.

Here is the part most Swiss hosting pages get wrong. Switzerland is outside the EU, but a provider using Swiss infrastructure is not therefore outside the Regulation. The framework is built to cover service providers offering services in the Union regardless of where they are established, and hosting and cloud services fall within its contemplated scope. Providers in scope without an EU establishment are required to appoint a legal representative in the Union to receive and act on orders. Establishment and market are what matter. Server location is not the switch.

So Swiss server location remains a real jurisdictional distinction. It changes which national law governs the data and which authority reviews access to it. It should not be sold as an escape from e-Evidence. Anyone selling it that way has either not read the Regulation or is counting on you not having read it.

Switzerland is not outside surveillance law either

Swiss surveillance rests on the BÜPF and its implementing ordinance, the VÜPF. The framework splits obligated parties into telecommunications service providers and providers of derived communication services, and the supervisory body, the Dienst ÜPF, treats online storage, file hosting and cloud services as derived communication services. Its own guidance uses a company acting as a hosting provider for third parties as a worked example. Hosting sits inside the framework, not outside it.

What determines your actual exposure is which category and which tier a provider falls into. Under the current rules the heaviest obligations on a derived communication service, including six-month retention of metadata, apply only where several conditions are met together: annual turnover of CHF 100 million, a large part of the business consisting of such services, and a minimum subscriber count. The great majority of providers sit far below that and hold only the data they already generate.

The proposed revision would redraw those lines. The draft sent for consultation in January 2025 attached an identification duty, meaning storing IP addresses to identify users, from around 5,000 users, with six-month metadata retention above one million. It drew opposition across the political spectrum, from industry associations, and from Proton, Threema and NymVPN, some of whom said publicly that they would consider leaving Switzerland.

Where it stands now matters more than last year's headlines. Parliament passed motions requiring a fundamental rewrite and a fresh consultation. On 11 February 2026 the Federal Council took note of the consultation report, commissioned an external regulatory impact assessment, and announced a second consultation. A revised draft circulated privately in February 2026 and published in May raised the identification threshold from 5,000 users to 100,000, which would place small and mid-sized Swiss mail and hosting services outside it, while leaving the contested core duties intact.

None of it is law. No version has been adopted or brought into force. The honest summary is not that Switzerland has no surveillance regime. It is that Switzerland has one, hosting sits within it, thresholds decide what applies to you, and those thresholds are being actively renegotiated. We follow this file closely and will update this page when it moves.

Switzerland or Finland: a jurisdiction choice, not a hardware one

We run the same six machines in both countries, at the same specifications and the same monthly prices. AD1 costs EUR 163.90 in Zurich and EUR 163.90 in Helsinki. The EPYC box is EUR 421.50 either way. There is no performance penalty for choosing one over the other and no discount for choosing the other over the one.

We mention this because a lot of hosting comparison content is built on the assumption that the privacy-friendly jurisdiction is the expensive one, and that picking it is a trade against your budget. Here it is not. The decision is purely about which legal environment you want your data sitting in, which is how it should be.

Finland is in the EU. That means GDPR applies directly, and it means Finland is inside the e-Evidence system as both an issuing and an executing state, with the ten-day and eight-hour deadlines running against Finnish-held data from 18 August 2026. It also means strong constitutional protection for privacy and expression, consistently high press-freedom rankings, and datacentres running on renewable power with natural cooling. If your users are in the EU and your compliance story is easier when your infrastructure is too, Finland is the straightforward answer.

Switzerland is outside the EU and outside NATO. Data sits under the FADP with a Swiss regulator, and foreign requests run through mutual legal assistance with Swiss review and, for coercive measures, dual criminality. As set out above, that is a distinction rather than an exemption, and it comes with an open question that Finland does not have: the VÜPF revision is unresolved, and where the thresholds finally land will decide what Swiss providers are obliged to retain. If you want a foreign authority's request to pass through an independent non-EU review, Switzerland is the answer, with that caveat attached honestly.

We compare the two legal environments in depth in Finland vs Switzerland hosting in 2026, and score fourteen countries against each other in the Hosting Jurisdiction Index.

Ordering without identity documents

Signup takes an email address and a password. We do not ask for identity documents, at signup or afterwards, on any product including dedicated servers. There is no verification step that appears once the order value crosses some threshold, which is the usual place this promise quietly breaks elsewhere.

Payment can be made in Bitcoin or Monero through our own BTCPay Server instance, which we run ourselves rather than routing through a third-party processor. That matters more than it sounds, because a hosted payment gateway sees your transaction data whatever your host's privacy policy says. We explain the reasoning in why we run our own BTCPay Server, and cover the Monero side in Monero hosting in Switzerland. Fiat options are available for anyone who prefers them.

Practical setup on a Swiss dedicated box

Encrypt the disks yourself. LUKS full disk encryption is meaningfully stronger on dedicated hardware than on a VPS, because there is no hypervisor with a routine view of your memory. On IN2 and the EPYC box you have IPMI KVM, so you can unlock the volume from the console after a reboot. On the single-socket AD plans there is no management controller listed, so configure Dropbear in the initramfs and unlock over SSH instead. Either way, test the unlock path before you put anything on the machine you cannot afford to lose access to.

Decide your logging policy deliberately. Legal process reaches what exists. A dedicated server means you control what exists. Shorten retention to what you actually need to operate, and be honest with yourself about which logs you have never once read.

Use the RAID-1 you are given. The single-socket plans ship with software RAID-1 across two NVMe drives by default. That is redundancy against drive failure, not a backup. Keep an off-server copy regardless, encrypted before it leaves the box.

Check the AUP before you build, not after. Tor exit nodes are not permitted in either location. Running a VPN is explicitly allowed and needs no separate approval. Confirm your plans against the policy before you provision rather than after.

Frequently asked questions

Does GDPR apply to a server in Switzerland?

Not because of where the server is. GDPR can still apply depending on the controller's or processor's establishment and activities, including where a business outside the EU offers goods or services to people in the Union or monitors their behaviour. Server location is not the test.

Does the EU e-Evidence Regulation apply to Swiss hosting?

It can. The Regulation is aimed at service providers offering services in the Union regardless of where they are established, and hosting and cloud services fall within its contemplated scope. Swiss location changes which law governs the data and which authority reviews access to it, but it is not an automatic exemption from the framework.

Does Switzerland require data retention from hosting providers?

Hosting is treated as a derived communication service under the Swiss surveillance framework, but the heaviest duties, including six-month metadata retention, currently attach only where high turnover, business composition and subscriber thresholds are all met together. The pending VÜPF revision would redraw those lines. It has not been adopted, it is undergoing a regulatory impact assessment, and a second consultation is planned.

Do dedicated servers in Switzerland require KYC?

Not with us. Email and password at signup, no identity documents at any point, on any product. Bitcoin and Monero accepted through our self-hosted BTCPay Server. If you are weighing providers on this specifically, we compare the Swiss options in the best privacy hosting providers in Switzerland.

Is Swiss hosting protected by banking secrecy?

No. Banking secrecy is financial law and applies to financial intermediaries. It confers nothing on a hosting provider or its customers. What actually applies to your data is the Federal Act on Data Protection, and what actually governs access requests is Swiss criminal procedure and mutual legal assistance.

Should I get a dedicated server or a VPS?

If your reason is performance, the answer is whatever your benchmarks say. If your reason is privacy, the question is narrower: does hypervisor-level exposure matter to your threat model? If it does, dedicated is the answer. If it does not, a Swiss VPS gives you the same jurisdiction for a fraction of the cost.

Getting started

All six dedicated servers in Switzerland come with full root access, dedicated IPv4, a /64 IPv6 allocation, DDoS protection and a choice of operating systems, and the dual-socket machines add five IPv4 addresses and 10G networking. Specifications and ordering are on the Switzerland dedicated server page. If you are unsure whether you need cores or clock speed, contact us first and describe the workload. It is a cheaper conversation than a month on the wrong box.

Need Reliable Hosting?

Privacy-focused, anonymous, and built for people who value their data.