Switzerland gets named constantly in privacy hosting marketing, usually in one line about strong privacy laws, and then the page moves on to pricing. That line is doing a lot of unexamined work. This article sets out what Swiss data protection law actually says, when a Swiss hosting provider can be compelled to hand data over, and where the protection genuinely stops.
It focuses on ordinary criminal investigations, telecommunications surveillance, and foreign criminal-evidence requests. Civil proceedings, regulatory and tax investigations, and intelligence activity operate under separate rules and are noted only where relevant. None of this is legal advice. If you are making a decision with real consequences, talk to a Swiss lawyer. But you should at least know what you are buying.
Swiss data protection law: the FADP
Switzerland's data protection regime is the Federal Act on Data Protection, usually abbreviated FADP, or LPD and DSG in the other national languages. A substantially revised version came into force on 1 September 2023, often written as the nFADP or revFADP. There was no transition period. It applied from day one.
Alongside it sits the Federal Data Protection and Information Commissioner, the FDPIC, which supervises federal bodies as well as private companies and other private controllers and processors.
The revision was aimed largely at keeping Switzerland aligned enough with the GDPR to preserve its adequacy position with the EU, while remaining a separate legal system rather than adopting EU law wholesale. That distinction matters more than most marketing copy admits, and it cuts in both directions.
What changed in 2023
- Only natural persons are protected now. The old FADP also covered data about legal entities. The revised version does not. If you are a company, the FADP protects data about your people, not data about your company as such.
- Genetic and biometric data were added to the definition of sensitive personal data.
- Privacy by design and by default became explicit obligations rather than good practice.
- Data breach notification to the FDPIC became mandatory where the breach is likely to result in a high risk to the data subject. The standard is "as soon as possible" rather than the GDPR's fixed seventy two hour clock.
- A register of processing activities is required, with an exemption for smaller companies whose processing is low risk.
- Criminal penalties primarily target individuals. This is the one that surprises people. Responsible natural persons can face fines of up to CHF 250,000. In limited circumstances a legal entity may instead receive a subsidiary fine of up to CHF 50,000. The headline number is far below the GDPR's percentage-of-turnover fines, but the personal exposure changes how seriously the people making decisions take it.
The FADP applies beyond Switzerland's borders
The FADP reaches processing carried out abroad where that processing has an effect in Switzerland. So a provider does not escape it by placing a server elsewhere, and a foreign company can fall under it by targeting Swiss residents. Foreign controllers falling under the Act may need to designate a representative in Switzerland.
For a hosting customer, the practical reading is that Swiss law follows the processing rather than only the postcode of the rack.
When a Swiss hosting provider can be compelled to disclose
This is the part that marketing pages skip, and it is the only part that matters if you are being serious about a threat model.
Data protection law is not the mechanism by which authorities obtain data. The FADP governs how a provider may process your data. It does not stop a criminal investigation. Compelled disclosure runs through Swiss criminal procedure instead.
Domestic criminal proceedings. Under the Swiss Criminal Procedure Code, a public prosecutor conducting an investigation can order the production or seizure of records through a written, reasoned order. This requires an actual criminal proceeding and a legally grounded order. It does not require that a suspect has already been identified, since an investigation may be aimed partly at identifying one. What it is not is a general authority to browse a provider's customer database, and an informal request does not itself compel disclosure.
Surveillance and content. More intrusive measures, in particular real time surveillance of communications, are governed by the Federal Act on the Surveillance of Postal and Telecommunications Traffic, known as BÜPF or LSCPT. These generally require the prosecutor's order to be approved by a compulsory measures court, an independent judicial check rather than a rubber stamp inside the prosecution service.
Metadata retention. This is the honest limit. Swiss law requires telecommunications service providers to retain certain connection metadata for six months and to make it available to authorities on a lawful order. The scope of who counts as a provider, and which obligations fall on so called derived communication service providers as opposed to full telecommunications operators, is a genuinely technical question that depends on the service. A provider claiming that no logs exist anywhere in the chain is making a claim about their own systems, not a statement about Swiss law.
Requests from outside Switzerland
Historically, a foreign prosecutor could not serve a Swiss provider directly and expect compliance. Requests had to travel through mutual legal assistance, governed by the Federal Act on International Mutual Assistance in Criminal Matters. That route still exists and still matters, and two features of it are worth understanding:
- Dual criminality. Coercive assistance generally requires the conduct under investigation to be punishable in Switzerland as well as in the requesting country. Conduct that is criminal abroad and lawful in Switzerland does not travel well.
- It is procedurally heavier and generally reviewable. Swiss authorities examine whether a request meets the applicable requirements, and the process is subject to appeal depending on the measure and the procedural position of the person affected. That makes speculative or overly broad requests considerably harder than a direct domestic production order.
This is the substance behind the word offshore, and it is a procedural protection rather than a shield. It raises the cost and the bar. It does not make anyone unreachable. And as of 2026, it is no longer the only route in from Europe.
The 2026 change: EU e-Evidence
Most articles about Swiss hosting jurisdiction were written before this and are now out of date. It is the single biggest change to the picture in years, so it is worth being precise about.
Switzerland is not an EU member state, and Swiss authorities remain outside the EU's domestic criminal procedure system. But from 18 August 2026, the EU e-Evidence framework applies. It consists of Regulation (EU) 2023/1543, creating the European Production Order and European Preservation Order, and Directive (EU) 2023/1544 on designating establishments and legal representatives.
What it does is allow a judicial authority in one member state to send a production or preservation order directly to a service provider, rather than routing it through the authorities of the provider's home country. Production deadlines are short, as little as eight hours in emergency cases.
The part that matters for Swiss hosting is the scope. The framework applies to providers offering services in the EU regardless of where they are established, and the covered categories expressly include hosting and cloud services, domain name and IP numbering services, and electronic communications. Providers in scope must designate an establishment or appoint a legal representative inside an EU member state to receive and act on orders.
So a Swiss-based provider selling to customers in the EU may now be reachable through the EU system despite being incorporated outside it. Swiss jurisdiction still matters, particularly for data held only by the Swiss entity and for requests falling outside the framework's scope. But anyone still describing Switzerland as fully separated from EU production-order mechanisms is describing the position as it was before August 2026.
Note also that traffic and content data, as opposed to basic subscriber data, can only be sought where the offence under investigation carries a custodial sentence above a set threshold. The framework is not uniformly permissive across data categories.
EU adequacy still applies
Separately from all of the above, Swiss data protection law is backed by an EU adequacy recognition, reconfirmed by the European Commission in its 2024 review. Personal data can flow from the EU to Switzerland for ordinary GDPR-regulated transfers without additional safeguards, so hosting in Switzerland does not create a transfer problem for European customers.
Adequacy decisions of this kind generally concern commercial data transfers under the GDPR rather than law enforcement data exchanges, which fall under the Law Enforcement Directive and are governed separately. Adequacy is about moving data in. It says nothing about who can later ask for it back out.
Our Hosting Jurisdiction Index scores fourteen countries against criteria of this kind if you want to see how Switzerland compares.
What about the US CLOUD Act?
The CLOUD Act allows US authorities to compel covered providers subject to US jurisdiction to produce data within that provider's possession, custody or control, wherever in the world it is stored. The trigger is the provider's relationship to the United States, not the location of the server.
A Swiss datacentre therefore does not by itself remove CLOUD Act exposure. The real questions are whether a covered provider is subject to US jurisdiction, and whether the requested data is genuinely within that provider's possession, custody or control. US ownership somewhere in the group is a warning sign rather than a conclusion: a US parent may or may not legally and technically control data held by a separate Swiss subsidiary.
If jurisdiction is your reason for choosing a host, the corporate structure and the question of which entity can actually access and produce your data are fair things to ask about directly. A provider that will not answer plainly has told you something.
What Swiss law does not protect you from
A page that only lists advantages is a sales page. Here is the other side.
- It is not immunity. Switzerland cooperates internationally, prosecutes crime, and enforces court orders. Serious criminal conduct is not made safe by a Swiss IP address.
- Civil claims still exist. Defamation, intellectual property and contractual disputes proceed through Swiss courts. Switzerland has no DMCA, but that is not the same as having no takedown mechanism, a distinction we cover in our article on DMCA takedowns and hosting jurisdiction.
- Metadata exists. Retention obligations are real, and separately from the law, every provider's systems generate records.
- Jurisdiction does not encrypt anything. On a self-managed VPS or dedicated server, disk encryption, encrypted backups and key handling can be under your control, and they do work that no jurisdiction can do for you. On shared or managed hosting, those protections depend partly on the provider's infrastructure and policies rather than on you.
- Intelligence services are a separate track. Nothing above describes intelligence activity, which operates under different law with different oversight, in Switzerland as everywhere else.
What this means when choosing a host
If Swiss jurisdiction is genuinely part of why you are buying, these are the questions that separate a real answer from a slogan:
- Is the infrastructure the provider's own, or resold capacity from a third party in another country? A jurisdiction claim built on someone else's rack is only as good as that contract.
- Who owns the operating company, and where? This determines CLOUD Act exposure regardless of where the hardware sits.
- What does the provider collect at signup? Law that restricts disclosure protects data that exists. Data never collected cannot be produced.
- What is the actual process when an order arrives, and does the provider now have an EU legal representative under the e-Evidence framework? Both are reasonable questions in 2026.
- Which payment processors sit between you and them? A third party processor may hold identity data the host itself never had, under a jurisdiction you did not choose.
Frequently asked questions
Is Switzerland good for privacy hosting?
Yes, for specific and identifiable reasons rather than reputation, though Swiss data protection law is only half the picture. Compelled access to stored records in a criminal investigation generally requires an actual proceeding and a written, reasoned production or seizure order, more intrusive surveillance needs approval from a compulsory measures court, and coercive foreign assistance generally requires dual criminality. Switzerland also holds EU adequacy without being an EU member state. It is not immunity from law, and since August 2026 it no longer places a provider fully outside EU production orders either.
What is the nFADP?
The revised Swiss Federal Act on Data Protection, in force since 1 September 2023. It modernised the 1992 Act, extended protection to genetic and biometric data, introduced privacy by design and by default, and made breach notification mandatory for breaches likely to create a high risk. Criminal fines of up to CHF 250,000 fall primarily on responsible individuals, with a subsidiary fine of up to CHF 50,000 available against a legal entity in limited circumstances. It also narrowed protection to natural persons, dropping the coverage of legal entities that existed under the old Act.
Can Swiss authorities access my hosting data?
In a criminal proceeding, yes, through a written and reasoned production or seizure order, with judicial approval required for more intrusive measures such as real time surveillance. An informal request does not itself compel a provider to disclose data. Separately, retention obligations mean certain connection metadata may be held for six months and produced on a lawful order.
Does the EU e-Evidence Regulation apply to Swiss hosting providers?
It can. From 18 August 2026, Regulation (EU) 2023/1543 applies to service providers offering services in the EU regardless of where they are established, and hosting and cloud services are within scope. Providers in scope must designate an establishment or legal representative in an EU member state to receive European Production and Preservation Orders. Being incorporated in Switzerland does not by itself put a provider outside that framework where it serves EU customers.
Does hosting in Switzerland protect me from the US CLOUD Act?
Only where the provider and the data are genuinely outside the relevant reach of US jurisdiction. The CLOUD Act follows covered providers and data within their possession, custody or control, not merely the physical server. Check the ownership structure, the contractual arrangements, and which entity can actually access or produce the data.
Is Swiss hosting GDPR compliant?
Switzerland holds an EU adequacy recognition, so personal data can move from the EU to Switzerland for ordinary GDPR-regulated transfers without additional safeguards. Your own obligations as a controller do not disappear, but the location of the server does not create a transfer problem.
Is Switzerland better than Finland or Iceland for privacy hosting?
They are different trade-offs rather than a ranking. Switzerland offers non-EU jurisdiction with EU adequacy and a mutual assistance barrier for coercive foreign requests outside the e-Evidence framework. Finland offers full EU membership, strong constitutional privacy protection and consistently top-three global press freedom rankings, inside the EU legal system rather than outside it. Which is better depends on who you expect to be dealing with. We compare the two directly in Finland vs Switzerland Hosting.
The short version
For ordinary compulsory access to stored records in a criminal investigation, Swiss authorities generally need a legally grounded proceeding and a written, reasoned production or seizure order. More intrusive surveillance carries additional approval requirements. Coercive foreign assistance through mutual legal assistance generally requires dual criminality. Civil, regulatory, intelligence and emergency procedures follow separate rules, and since 18 August 2026 the EU e-Evidence framework provides a further route for providers serving EU customers.
What Swiss jurisdiction is not is a shield, an absence of logs, or a substitute for encrypting your own data. Any provider selling it as those things is selling you the reputation rather than the law.
Packetra runs its own infrastructure in Switzerland and Finland, requires only an email address and a password to open an account, and never requests identity documents at any stage. If you want the practical side, our writeups on VPS hosting in Switzerland and Monero hosting in Switzerland go further.
Shared Hosting
WordPress Hosting
Cloud VPS Hosting
Dedicated Servers