Available only in Switzerland

Schweizerform is currently available exclusively for users in Switzerland. Account creation from your region is restricted.
Back to Blog

Which Form Data Can Legally Leave Switzerland?

Most form data may legally leave Switzerland — what changes is what you must have in place first. A practical walk through the Art. 16 and 17 nFADP test, the 44 destinations on Annex 1 of the Data Protection Ordinance, the Swiss-U.S. Data Privacy Framework, Standard Contractual Clauses, transfer impact assessments, and the sector rules that override the answer entirely.

Which Form Data Can Legally Leave Switzerland?

Most form data can legally leave Switzerland. There is no provision in the revised Federal Act on Data Protection (nFADP / nDSG, SR 235.1) that says personal data must be stored on Swiss soil. What the law regulates is not the geography but the conditions: before responses cross the border, you need either a destination the Federal Council has recognised as adequate, or a safeguard you can point to, or a derogation that fits your case — and in every scenario you must tell respondents which country their data goes to. Three sector regimes override that answer entirely, and they are where most Swiss organisations actually get caught.

The two-minute version

Step 1 — is the destination on Annex 1 of the Data Protection Ordinance (DPO / DSV, SR 235.11)? If yes, transfer on the basis of Art. 16 para. 1 nFADP. Step 2 — if not, build a safeguard under Art. 16 para. 2: Standard Contractual Clauses, binding corporate rules, an approved code of conduct or certification, plus a transfer impact assessment. Step 3 — if neither works, you are down to the case-by-case derogations in Art. 17, which are not a standing arrangement. In all three cases, Art. 19 para. 4 requires the privacy notice to name the destination country and the safeguard used.

Can Form Data Legally Leave Switzerland?

Yes, under conditions. Art. 16 para. 1 nFADP reads: personal data may be disclosed abroad if the Federal Council has determined that the legislation of the state concerned, or the international body concerned, guarantees adequate protection. That is the primary route. Anything that puts personal data within reach of a recipient outside Switzerland counts — uploading form responses to a foreign-hosted database, granting a foreign support team read access, exporting a spreadsheet to a colleague in Munich. Note the one carve-out in Art. 18 nFADP: publishing data to the general public through an automated information service is not treated as a disclosure abroad merely because the page is reachable from other countries. That covers your public form page. It does not cover the responses. This article is the operational counterpart to our positioning piece on Swiss data sovereignty: that one argues why keeping data in Switzerland is worth something, this one is about what the law actually requires when it does not stay.

The Three-Step Test: Adequacy, Safeguards, Derogations

  1. Adequacy (Art. 16 para. 1). The Federal Council maintains a list of states and bodies with adequate protection in Annex 1 DPO. If your destination is on it, no additional transfer instrument is needed — you still owe the ordinary duties: a processor contract under Art. 9, a record of processing, security measures, and the Art. 19 para. 4 disclosure.
  2. Appropriate safeguards (Art. 16 para. 2). Where there is no Federal Council determination, you may transfer if appropriate data protection is ensured by an international treaty; data protection clauses in a contract notified in advance to the FDPIC; specific guarantees of a federal body; standard data protection clauses approved, issued or recognised in advance by the FDPIC; or binding corporate rules approved in advance.
  3. Derogations (Art. 17). Six exceptions: explicit consent; direct connection with the conclusion or performance of a contract; an overriding public interest or the establishment, exercise or enforcement of legal claims before a court or foreign authority; protection of life or physical integrity; data the person has made generally accessible themselves; or data from a register provided for by law. Art. 17 para. 2 obliges you to inform the FDPIC on request about transfers based on some of these grounds.

The derogations are the weakest ground of the three, and the one most often misused. They are designed for the individual case — a one-off transfer, a specific contract, a specific emergency — not as the standing legal basis for a survey tool you use every week. If you find yourself writing “explicit consent” into a systems architecture diagram, you have probably chosen the wrong instrument.

What happens if you skip the test — Art. 61 nFADP

Art. 61 lit. a threatens a fine of up to CHF 250,000 for anyone who intentionally discloses personal data abroad in breach of Art. 16 paras. 1 and 2 without an Art. 17 exception applying. Two things distinguish this from a GDPR fine, and both matter. It is a criminal penalty aimed at the responsible natural person, not an administrative fine levied on the company. And it is an offence prosecuted on complaint — someone has to file. That combination makes it rarer than a supervisory fine but personally sharper for whoever signed off on the architecture.

If My Respondents Are in Switzerland, Can I Store the Data in the EU?

In the general case, yes. Annex 1 DPO — in the version in force since 15 September 2024 — lists 44 destinations, and all 27 EU member states are on it, together with Iceland, Liechtenstein and Norway. For a Swiss SME running an event sign-up, a newsletter subscription or a customer-satisfaction survey with no special-category data, an EU-hosted form tool with a proper processor contract is compliant. Anyone telling you Swiss data must never touch an EU server is either selling something or has not read Art. 16 para. 1.

The Trap: An EU Server Owned by a Non-EU Company

The place where “we host in Frankfurt” stops working is when the company operating that Frankfurt datacentre is itself subject to a third-country legal order that can compel disclosure. The FDPIC addresses this head-on in its guidance on assessing the admissibility of cross-border data transfers under Art. 16 para. 2 lit. b and d nFADP, published in June 2021 and revised for the new nFADP in May 2023.

It must be noted that a processor in a country with an adequate level of data protection may in certain circumstances be subject to a law or other binding requirement of a third country obliging it to disclose the data to the authorities of that third country … (example: servers in Switzerland, the EU or the EEA belonging to a company that is directly or indirectly subject to the legal order of a state without an adequate level of data protection).
FDPIC, guidance on assessing cross-border data transfers, step N01 (author's translation from the German original)

The consequence is explicit in the same document: in that situation you proceed as if there were no adequacy at all, and go to the Art. 16 para. 2 route with a transfer impact assessment. So the compliance question about your form tool is not only “where are the servers?” but “whose legal order does the operating entity answer to?” Those are two different questions, and only the second one is decisive when they diverge.

Which Countries Are on the Swiss Adequacy List?

Annex 1 DPO is the authoritative list, and it is short enough to read in a minute. The table below groups the destinations that matter for form tooling and states what each one actually requires of you. Read the “catch” column carefully — several entries on the list are conditional, and one of them is conditional on something you have to verify per vendor.

DestinationBasis under the nFADPWhat you must haveThe catch
EU / EEA (all 27 EU states plus Iceland, Liechtenstein, Norway)Art. 16 para. 1 — all listed in Annex 1 DPOPrivacy notice naming the country (Art. 19 para. 4); processor contract (Art. 9)Adequacy is presumed, not guaranteed: an EU server run by a company under a third-country legal order sends you back to Art. 16 para. 2 (FDPIC, step N01)
United Kingdom, Gibraltar, Guernsey, Jersey, Isle of Man, Faroe IslandsArt. 16 para. 1 — all listed in Annex 1 DPOSame as EU/EEAThe UK entry carries a footnote in Annex 1: adequacy extends to transfers under a Commission implementing decision relating to Directive (EU) 2016/680
United States — organisation certified under the Swiss-U.S. Data Privacy FrameworkArt. 16 para. 1 — Annex 1 DPO, in force since 15 September 2024Confirm the entry on the official list at dataprivacyframework.gov, and confirm it names the Swiss-U.S. framework; recheck at each annual recertificationCertification is annual self-certification and lapses on withdrawal or failed recertification. Adequacy attaches to the organisation, not to the United States
United States — organisation not certifiedArt. 16 para. 2 lit. b or dEU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with the Swiss adaptations the FDPIC required on 27 August 2021, plus a transfer impact assessmentThe FDPIC's four guarantees must be assessed against FISA 702 and Executive Order 12333; the likelihood of an access request is not an admissible argument
CanadaArt. 16 para. 1 — but conditionalConfirm that PIPEDA or a substantially similar provincial law applies to your specific recipientQuébec, British Columbia and Alberta have general equivalents; Ontario, New Brunswick, Newfoundland & Labrador and Nova Scotia only for health data
Andorra, Argentina, Israel, Monaco, New Zealand, UruguayArt. 16 para. 1 — listed in Annex 1 DPOPrivacy notice and processor contract, as for the EUAll carry the Annex 1 footnote excluding disclosures under the Directive (EU) 2016/680 cooperation framework
Japan, South KoreaNot on Annex 1 DPOArt. 16 para. 2 lit. b or d — Standard Contractual Clauses plus a transfer impact assessmentBoth hold EU adequacy decisions. EU-adequate is not Swiss-adequate, and a Swiss exporter cannot borrow the EU list
Everywhere elseArt. 16 para. 2 lit. a–e, or Art. 17 as a fallbackSCCs, binding corporate rules, an approved code of conduct or certification (Art. 12 DPO), or a documented Art. 17 derogationArt. 17 derogations are case-by-case, not a standing arrangement; the FDPIC must be told on request about transfers under several of the grounds

Why Japan and South Korea Are on the EU List but Not the Swiss One

This is the single most useful fact in the article, and the one most often got wrong in vendor documentation. The European Commission adopted an adequacy decision for Japan, and one for the Republic of Korea on 17 December 2021. Neither state appears in Annex 1 DPO. Switzerland runs its own assessment under Art. 8 DPO — international obligations, the rule of law and human rights, the applicable legislation and its enforcement, effective data-subject rights and remedies, and a functioning independent supervisory authority — with the FDPIC consulted each time. The two lists overlap heavily, but they are not the same list. A Swiss exporter transferring to Tokyo needs SCCs and a transfer impact assessment even though an exporter in Munich sending the same data does not.

Adequacy Is a Rebuttable Presumption, Not a Permit

The FDPIC's guidance is blunt about what appearing on Annex 1 buys you: it gives the exporter the benefit of good faith under Art. 3 para. 1 of the Civil Code — and good faith is rebuttable under Art. 3 para. 2. You cannot invoke it when you know that adequacy does not in fact hold in your specific case. The exporter, the guidance says, remains responsible for the export in every case and must inform itself periodically about whether adequacy still applies. That is a standing obligation on you, not a one-time box tick at vendor selection.

Adequacy can be withdrawn — plan for it

Art. 8 para. 6 DPO provides that where a state no longer guarantees adequate protection, Annex 1 is amended accordingly — with no retroactive effect on transfers already made. Read that as a design constraint rather than a risk footnote: past transfers are not retroactively unlawful, but the pipe closes going forward. If a single adequacy entry is the only thing standing between your form tool and an Art. 16 para. 2 exercise, write down now what you would do the week it changed.

Can a Swiss Company Use a US-Based Survey Provider?

Yes, and the route is not a workaround. On 14 August 2024 the Federal Council decided to add the United States to Annex 1 DPO, with effect from 15 September 2024. The adequacy is narrow: it covers personal data processed by organisations certified under the principles of the Swiss-U.S. Data Privacy Framework. It rests on Executive Order 14086 of 7 October 2022, the Attorney General's regulation establishing the Data Protection Review Court, Intelligence Community Directive 126, and Switzerland's designation on 7 June 2024 as a qualifying state for the two-tier redress mechanism. The FDPIC's own statement is that from 15 September 2024 this ensures adequate data protection in exchanges between Switzerland and certified US companies.

How to Check Whether Your Vendor Is Actually Certified

  • Look the legal entity up on the official Data Privacy Framework List at dataprivacyframework.gov — not on the vendor's own marketing page, and not on a comparison blog.
  • Check that the record covers the Swiss-U.S. framework specifically. A great many organisations certified for the EU-U.S. framework alone. That certification does you no good under Annex 1 DPO.
  • Check the entity name matches the one on your contract. Certifications attach to a named legal entity; a subsidiary or a differently-named billing entity is not covered by the parent's listing.
  • Certification is self-certification to the US International Trade Administration and must be renewed annually. Organisations are removed on withdrawal, failure to recertify, or persistent non-compliance — so diarise a recheck rather than screenshotting it once.

What the DPF Does Not Cover

It does not switch off the US CLOUD Act, in force since spring 2018, which reaches data held by US-controlled providers wherever in the world it is stored. A provider may contest an order where the subject is not a US person or resident and disclosure would breach foreign law — Art. 271 and Art. 273 of the Swiss Criminal Code are exactly the kind of conflict contemplated — but that is a contest, not an immunity, and Switzerland has no CLOUD Act executive agreement with the United States. The Federal Office of Justice published a report on the US CLOUD Act on 17 September 2021 for readers who want the official Swiss treatment. On the EU side, Art. 48 GDPR provides that a third-country judgment or administrative decision requiring disclosure is recognisable only on the basis of an international agreement in force such as a mutual legal assistance treaty, and the EDPB's Guidelines 02/2024, finalised in June 2025, stress that Art. 48 is not itself a transfer ground. Our post on subpoenas, warrants and form data covers what an order looks like in practice and what a provider can and cannot hand over.

Adequacy is a political instrument

The EU-U.S. framework was adopted on 10 July 2023 and survived its first challenge when the EU General Court dismissed the Latombe case in September 2025 — a ruling limited, the Court noted, to the framework's validity at the time of adoption, with the Commission's ongoing review duty stressed. An appeal to the Court of Justice was lodged in October 2025. Both the EU and Swiss frameworks remain valid law as of mid-2026. The structural point stands regardless of how any single case resolves: adequacy is a determination that can be revisited, and an architecture whose lawfulness depends entirely on one is an architecture with a political dependency in it.

What Contractual Safeguards Are Needed for US Cloud Providers?

Where the recipient is not DPF-certified, the workhorse instrument is the EU Standard Contractual Clauses. On 27 August 2021 the FDPIC recognised the SCCs under Commission Implementing Decision (EU) 2021/914 as a basis for transfers to countries without adequate protection — provided the adaptations and additions necessary for use under Swiss law are made. The older instruments (the 2010 processor SCCs, the 2013 Swiss transborder data-flow contract, the Council of Europe model contract) were usable only until 31 December 2022. Art. 9 DPO sets out the ten mandatory contents of contractual data protection clauses, from purpose limitation and the categories of data and data subjects through to destination states, retention, recipients, security measures, breach notification and data-subject rights. Art. 10 para. 2 DPO obliges the FDPIC to publish the clauses it has approved, issued or recognised and to communicate the outcome of a review within 90 days.

The Transfer Impact Assessment: the FDPIC's Four Guarantees

Signing SCCs is the easy half. The FDPIC's guidance requires you to assess whether four guarantees are ensured analogously in the destination country, and it says explicitly that the exporter must carry out those enquiries itself and may not rely solely on the importer's statements.

  1. Legality — state access must have a proper statutory basis (Art. 5 and Art. 164 of the Federal Constitution as the Swiss reference point).
  2. Proportionality — Art. 5 para. 2 of the Constitution and Art. 6 para. 2 nFADP.
  3. Effective legal remedies — Art. 13 para. 2 of the Constitution, Art. 32 nFADP, and Art. 8 and 13 of the European Convention on Human Rights.
  4. Access to an independent court — Art. 29 ff. of the Constitution, Art. 32 nFADP, Art. 6 para. 1 ECHR.

Two operational points from the same guidance. First, the analysis covers applicable law, administrative and judicial practice and case law — and subjective factors such as the likelihood of an access request generally cannot be taken into account. “Nobody would ever ask for our event sign-up data” is not an argument the assessment recognises. Second, the guidance annexes a US-specific questionnaire, adapted for Switzerland from the noyb questionnaire and referencing the Schrems II judgment, covering 50 U.S.C. § 1881a (FISA 702), Executive Order 12333, and control by a US parent or shareholder. Every question offers the provider the answer option that it is legally obliged not to answer — which tells you something about how the exercise usually goes. And if the assessment finds gaps that cannot be compensated by supplementary measures, the guidance is unambiguous: the transfer must be suspended or terminated immediately. That is the sentence to keep in front of you when a vendor offers to “add a clause” to close a statutory access power — a contract between two private parties cannot bind a foreign authority, and the FDPIC says so directly.

Our Company Is Swiss but Has EU Employees — What Rules Apply?

Usually both laws, in parallel. The nFADP applies under Art. 3 para. 1 to circumstances that have an effect in Switzerland, even if they are initiated abroad — so a Swiss employer processing HR form data has the nFADP regardless of where the server sits. The GDPR applies on its own territorial terms where you have an establishment in the EU or are offering goods and services to, or monitoring, people there. The two regimes are close enough that one well-built form process satisfies both; we walk through the practical overlap in GDPR vs nFADP for form data.

We Have Customers in Germany, France and Switzerland — Which Law Do We Follow?

Build to the stricter requirement per topic rather than picking a single regime. In practice that means GDPR-grade legal-basis documentation and data-subject-request handling, plus the Swiss specifics that have no GDPR twin — the Art. 19 para. 4 duty to name the destination country and the safeguard being the clearest example. The provision-by-provision comparison lives in nFADP vs GDPR: the key provisions. Note also Art. 14 nFADP: a foreign private controller must appoint a Swiss representative only where four conditions are met cumulatively — offering goods or services in Switzerland or monitoring behaviour there, on a large scale, regularly, and with a high risk to the personality of the persons concerned. Many foreign vendors assume they need one and do not; a few assume they do not and do.

The other direction is easy

Data flowing from the EU or EEA into Switzerland needs no additional safeguards. Switzerland has held an EU adequacy decision since Commission Decision 2000/518/EC, and on 15 January 2024 the European Commission confirmed it in its report on the first review of the eleven pre-GDPR adequacy decisions — no amendment required. So an EU-based respondent submitting to a Swiss-hosted form is the legally simplest configuration in this entire article, and it is strictly simpler than the reverse.

When Sector Rules Override the Adequacy Answer

This is the part most cross-border checklists skip. Art. 9 para. 1 lit. b nFADP permits delegating processing to a processor only where no statutory or contractual duty of confidentiality prohibits the transfer — and Art. 9 para. 3 requires the controller's prior approval for sub-processors. That clause is the hook by which a professional secrecy duty, a supervisory circular or a research statute can defeat an adequacy finding entirely. Annex 1 says yes; the sector rule still says no.

Art. 321 SCC — Professional Secrecy

Lawyers, doctors, dentists, psychologists, pharmacists and their auxiliaries are bound by Art. 321 of the Swiss Criminal Code. Under the prevailing doctrine a cloud provider qualifies as an auxiliary within the meaning of Art. 321 no. 1 para. 1, so outsourcing is not per se a breach — but the engagement must be necessary for delivering the service and foreseeable for the client, with instruction rights, data security and control over sub-processors. Whether the auxiliary sits in Switzerland or abroad is not, on this reading, decisive in itself. Treat that as doctrine and a defensible position rather than a statutory safe harbour, and get advice before relying on it. Alongside it, Art. 62 nFADP creates its own criminal provision — a fine of up to CHF 250,000, again on complaint — for intentionally disclosing secret personal data learned in the exercise of a profession requiring such knowledge.

FINMA-Supervised Firms and Outsourcing Abroad

FINMA Circular 2018/3 on outsourcing for banks and insurers, in the version of 1 January 2021, sets a bar that has nothing to do with adequacy. Section G on outsourcing abroad requires the firm to be able to give an express assurance that it, its audit firm and FINMA can exercise and enforce their inspection and audit rights, and that the firm's restructuring or resolution in Switzerland remains possible with access to the necessary information available in Switzerland at all times. Section F requires a contractual right of inspection and audit that is unrestricted, complete and available at any time. A form vendor with a Swiss datacentre helps you meet that; it does not discharge it, because the obligation is contractual and organisational, not geographic.

Research Data, and Accounting Records

For human research, the Human Research Act (HRA / HFG, SR 810.30) adds a consent and ethics layer on top of everything above: Art. 32 requires explicit consent tied to the specific project for the identifying further use of genetic data and biological material, while Art. 33 allows general consent for research purposes for other identifying health data — and ethics committee approval is required in addition. What the HRA does not do is create its own destination-country rule: the cross-border question is still governed by Art. 16 and 17 nFADP, with the special-category status of health, genetic and biometric data under Art. 5 lit. c raising the stakes on the assessment rather than changing the test. Accounting records are the mirror-image case, and worth stating plainly because the folklore runs the other way. Art. 958f CO and the Ordinance on the Keeping and Preservation of Business Records (GeBüV, SR 221.431) require books and accounting vouchers to be kept for ten years from the end of the financial year, require electronic retention to make changes detectable, and require the records to be readable at any time. Those are availability and integrity duties, not a location rule — GeBüV does not say your ledgers must sit on Swiss soil. If your form collects expense claims or invoice data, the retention clock is what to plan around, and our post on how long to keep form data works through the overlapping periods.

When Hosting Abroad Is Perfectly Fine

We sell end-to-end encrypted forms whose submissions are stored in Switzerland, so take this section as the part where we argue against our own funnel. There is a large category of Swiss form data for which a foreign-hosted tool is the correct, compliant and cheaper answer, and pretending otherwise would make everything above less credible.

  • Ordinary data to an EU/EEA destination. Event registrations, newsletter sign-ups, satisfaction surveys, contact forms with a name and an email address. Annex 1 covers the destination; a processor contract and a correct privacy notice cover the rest. There is no “data must stay in Switzerland” rule to breach.
  • A DPF-certified US vendor for the same class of data. A current Swiss-U.S. listing is a lawful basis under Art. 16 para. 1, not a loophole. Verify it, diarise the recheck, and move on.
  • A shop already standardised on a large platform. Microsoft's EU Data Boundary is a real engineering commitment rather than a marketing page, and it explicitly includes Switzerland as an EFTA state, with datacentres in Switzerland among those used or announced. Microsoft's own documentation is also honest about the limits — “limited circumstances” in which data still moves outside the boundary, system-generated logs that are pseudonymised rather than eliminated, remote DevOps access, boundary scope determined by the tenant's sign-up country, and Multi-Geo customers falling out of scope. Which individual services are in scope is set by the Product Terms, so check yours rather than assuming. We go through the encryption side of that stack in Is Microsoft Forms encrypted?

Where Schweizerform Is Not the Right Answer

  • We do not remove the paperwork. Even when responses can only be decrypted by the holder of the Vault key, you still owe the Art. 19 para. 4 disclosure, a record of processing, a processor contract and a retention decision. End-to-end encryption removes a confidentiality risk; it does not remove an obligation.
  • If your workflow needs the provider to act on plaintext, our shape is wrong. Server-side scoring, server-side rendering into a foreign document management system, routing based on answer content, or a vendor-run helpdesk that reads submissions — zero-knowledge intake fights all of these. A tool with a strong processor contract and a documented transfer impact assessment is the better fit.
  • FINMA-supervised firms should not treat us as the outsourcing answer on our own. Circular 2018/3 requires enforceable inspection rights for the firm, its audit firm and FINMA, plus guaranteed Swiss access for resolution purposes. Swiss hosting helps; the rest is a contract-and-governance exercise.
  • We are an intake layer. Cross-border compliance for a clinical trial, a group-wide HR system or a KYC file mostly lives downstream of the form. Encrypting intake does not fix an export that happens later in your CRM.

Why End-to-End Encryption Changes the Transfer Analysis

Where E2EE does real work is in the middle of the three-step test: it changes what a party abroad actually holds. Schweizerform encrypts responses in the respondent's browser; the ciphertext is stored in Switzerland at Infomaniak, which states publicly that it hosts and processes data exclusively in Switzerland, is an independent Swiss company, runs Swiss-based support, and holds ISO/IEC 27001:2022 among other certifications. Only the holder of the Vault key can decrypt a submission. We cannot read them, which means we have nothing readable to hand over — to anyone. The difference between that and provider-managed encryption is the whole subject of encryption at rest vs end-to-end.

What the FDPIC Says About BYOK and BYOE

The FDPIC's guidance is explicit that contractual add-ons are barely workable against state access because they cannot bind third-country authorities, and that technical and organisational measures must be such that authority access is factually prevented. It then names the shape those measures take: for pure cloud storage by a provider in a state without adequate protection, an encryption implemented on “bring your own key” and additionally “bring your own encryption” principles is conceivable, so that no plaintext exists in the cloud and no decryption or encryption happens there. That is a description of a zero-knowledge architecture. The EDPB reaches a compatible conclusion in Recommendations 01/2020 on supplementary measures, version 2.0 of 18 June 2021: encryption is an effective supplementary measure for storage without access in the clear where it is state of the art, flawlessly implemented, and the keys stay solely under the control of the exporter or an entity in the EEA or an adequate country.

What Encryption Does Not Get You Out Of

Three honest limits. The FDPIC itself adds that such technical measures become demanding as soon as the service in the destination country goes beyond pure data storage — which is the same constraint we describe above. Second, the argument that ciphertext held by a party with no key is a different matter from plaintext is supported by Switzerland's relative approach to identifiability, which the Federal Supreme Court set out in the Logistep decision (BGE 136 II 508, 8 September 2010): identifiability is assessed on the concrete circumstances of the individual case, not in the abstract. That is an argument in your favour, not a holding that encrypted data is not personal data — the Court never said that, and you should not write it in a data protection impact assessment as though it had. Third, and most practically, none of it touches the disclosure duty.

Name the country and the safeguard in your privacy notice

Art. 19 para. 4 nFADP: where personal data is disclosed abroad, the controller must also inform the data subject of the state or international body concerned and, where applicable, of the guarantees under Art. 16 para. 2 or the application of an exception under Art. 17. This is the single most operational obligation attached to a form, and the one most often missing. “We may transfer data to third countries” is not compliant — the country and the instrument have to be named. Our walkthrough of nFADP compliance for online forms covers the rest of the notice.

How to Document a Cross-Border Transfer in Six Steps

1

Map where the data actually goes

For each form: the hosting entity, the datacentre country, every sub-processor and its country, and the legal order the operating entity answers to. The FDPIC's inventory questions ask precisely this, including whether the data is processed by companies subject to third-country legal orders — for example US cloud providers with servers in Switzerland or the EEA.

2

Classify what the form collects

Flag special-category data under Art. 5 lit. c nFADP: religious, philosophical, political or trade-union views; health, intimate sphere, race or ethnicity; genetic data; biometric data uniquely identifying a person; administrative or criminal proceedings and sanctions; social assistance measures. Flag anything covered by professional secrecy separately — that is a different override.

3

Test the destination against Annex 1 DPO

Check the current Annex 1 rather than a summary. For the United States, check the vendor's entry on the Data Privacy Framework List and confirm it names the Swiss-U.S. framework. For Canada, confirm which provincial law applies to your recipient.

4

Build the safeguard where adequacy does not apply

Standard Contractual Clauses with the Swiss adaptations, binding corporate rules, or a code of conduct or certification under Art. 12 DPO. Check the FDPIC's published list of recognised clauses, and remember Art. 9 para. 3 DPO on when notification is treated as already discharged.

5

Run and file a transfer impact assessment

The four guarantees, assessed against the destination's actual law and practice, with your own enquiries rather than the importer's assurances alone, and without leaning on how unlikely an access request seems. If the gaps cannot be compensated, the transfer must be suspended or terminated.

6

Write it into the privacy notice and the record of processing

Name the destination country and the safeguard or derogation, per Art. 19 para. 4. Then set a review date — adequacy findings change, certifications lapse annually, and sub-processor lists change without asking you. Our security page sets out our own hosting and key model if you need a worked example of what a vendor answer to steps 1 and 4 looks like.

Bottom Line: Which Form Data Can Legally Leave Switzerland?

Ordinary form data can go to any of the 44 destinations on Annex 1 DPO with a processor contract and an accurate privacy notice — including the whole EU and EEA, the UK, and DPF-certified US organisations. Data going anywhere else needs Standard Contractual Clauses with the Swiss adaptations plus a transfer impact assessment, and the Art. 17 derogations are for individual cases, not for architectures. Data caught by professional secrecy, FINMA outsourcing rules or human research law is subject to a second test that adequacy does not settle. And an EU datacentre operated by a company under a third-country legal order does not get you the benefit of Annex 1 at all. The practical takeaway is that “where are the servers?” is the second question, not the first. The first is who controls the entity, and the third is whether anyone in the chain holds a readable copy. Keeping the data in Switzerland and keeping the decryption key with you shortens all three answers at once — but it does not shorten the documentation, and any vendor telling you it does is selling you the wrong thing. If you are now picking a provider on this basis, our roundup of form and survey tools hosted in Switzerland works through each vendor's actual data residency, one by one.


Disclaimer: This article is general information and marketing content, not legal, regulatory or security advice. References to the nFADP (SR 235.1), the Data Protection Ordinance (SR 235.11) and its Annex 1, FDPIC guidance, FINMA Circular 2018/3, the Human Research Act, GeBüV, the GDPR and the Swiss-U.S. Data Privacy Framework reflect publicly available sources as of July 2026 and are summarised at a conceptual level; adequacy findings, certifications, circular versions and vendor arrangements change, and you should verify the current text of any instrument before relying on it. Whether a specific transfer is lawful depends on your data, your recipients and your sector, and several points above are matters of doctrine rather than settled law. Consult qualified data protection counsel before making compliance or purchasing decisions. All product and company names are trademarks of their respective owners and are used here for factual comparison only.