Which Form Tools Are Hosted in Switzerland — and Why It Matters
Swiss data centre, Swiss company and Swiss jurisdiction over the operator are three different claims, and vendors routinely sell them as one. What Swiss hosting actually buys you, why a Swiss-hosted US-owned provider is still reachable under the CLOUD Act, and the side channels — CDN, e-mail, fonts, analytics, error reporting, support access — that carry form data out of the country even when the database never moves.

«Our data stays in Switzerland» is one of the most frequently made and least frequently checked claims in Swiss software procurement. It is also three claims in a trench coat. A form tool can be hosted in a Swiss data centre while being operated by a company under foreign control; it can be run by an impeccably Swiss company that stores every response on Amazon in Ireland; and it can be Swiss in both respects while its support team, its e-mail notifications and its error logs quietly move submission content to four other countries.
The short version
Swiss hosting is worth having, for reasons that are narrower and more practical than the marketing suggests: it removes a cross-border transfer from your record of processing, it puts the operator's compulsion risk under Swiss procedure, and it means a foreign authority normally has to go through mutual legal assistance rather than address the provider directly. What it does not do is tell you whether the provider can read your submissions. Residency is a location claim; confidentiality is an architecture claim. Ask both questions, in that order, and be exact about which one the vendor actually answered.
This article is the why. If you want the who — the current vendor-by-vendor picture of which form and survey tools genuinely store response data in Switzerland, with the documentation each claim comes from — that is our roundup of form and survey tools hosted in Switzerland, checked in July 2026.
Three Claims That Sound Like One
Almost every «Swiss hosting» bullet point collapses three independent facts. Separating them is the single most useful thing you can do in a vendor assessment, because a provider can pass one and fail the other two without saying anything untrue.
| The claim | What it actually means | What it does not tell you |
|---|---|---|
| Swiss data centre | The servers holding response data are physically located in Switzerland | Who owns the operator, which law governs the contract, or whether the provider can read the data |
| Swiss company | You contract with a legal entity registered in Switzerland | Where the data is stored — a Swiss company may lawfully process on AWS in Ireland |
| Swiss jurisdiction over the operator | The operator is not subject to a foreign order that reaches data held abroad | Nothing about the data centre; a Swiss-hosted subsidiary of a foreign group is still reachable through the parent |
The third row is the one that gets left out, and it is the one that decides the others' value. 18 U.S.C. § 2713, added by the CLOUD Act in 2018, requires a US electronic-communication or remote-computing service provider to preserve and disclose content and records in its possession, custody or control regardless of whether the information is located within or outside of the United States. A Swiss data centre operated by a US-controlled provider therefore satisfies the residency question and leaves the compulsion question exactly where it was.
The argument to avoid, and the one that holds
«US hosting is illegal» is too strong and easy to refute — since 14 August 2024 the Federal Council has recognised the United States as providing adequate protection for companies certified under the Swiss–U.S. Data Privacy Framework, with the ordinance amendment in force from 15 September 2024, so such transfers need neither standard clauses nor a transfer impact assessment. The durable argument is narrower: adequacy is a data-protection judgement about the destination's rules, while the CLOUD Act is a jurisdictional reach over the provider. The two coexist. Which is why the strongest position is not choosing a jurisdiction but ensuring there is no readable data to hand over.
What Swiss Hosting Actually Buys You
Stripped of the flag-waving, there are four concrete benefits and they are all worth money.
- One less transfer to document. Art. 16 nFADP permits disclosure abroad where the Federal Council has found adequate protection — the list is Annex 1 to the Data Protection Ordinance — or where the transfer rests on a treaty, standard data protection clauses or binding corporate rules; Art. 17 adds narrow exceptions. None of that is prohibitive, but all of it is paperwork you must maintain and be able to produce. A purely Swiss chain removes the item rather than resolving it.
- Procedural friction for foreign authorities. A foreign authority that wants data held by a Swiss operator normally has to use mutual legal assistance, which is slow, visible and reviewable. Data held by a provider inside its own jurisdiction can be reached directly, and often confidentially. That difference is the practical core of data sovereignty.
- A simpler answer for regulated sectors. Where professional secrecy under Art. 321 StGB applies — medicine, law, dentistry, psychology, pharmacy — the duty extends to auxiliary persons, which includes the people who can access your systems. Keeping the processing chain short and Swiss makes that duty easier to honour and much easier to explain to a supervisory body. Public bodies have an additional layer: the privatim resolution of November 2025 on international cloud services treats the use of providers subject to foreign access as permissible only in narrow cases — with the notable exception where the public body itself encrypts the data and the provider holds no key.
- Latency and language, unglamorously. Swiss respondents get a faster form, and Swiss support means a contract, an invoice and an escalation path in a language and time zone you share. Nobody puts this in a data protection review; everybody notices it in operation.
What it does not buy: immunity. Swiss criminal procedure allows Swiss authorities to order the production or seizure of data held in Switzerland, and a Swiss provider that can read your submissions can be made to produce them. We work through that scenario, and what encryption changes about it, in subpoenas, warrants and your form data.
The Side Channels That Leave Switzerland While the Database Stays
This is the part almost no vendor page addresses, and it is where most real-world data leaves the country. A form is not just a database row. It is a page loaded from somewhere, delivered through something, with notifications, logs and support tooling attached. Each of those is a potential disclosure abroad in its own right.
- The CDN in front of the form. If the form page is served through a foreign content delivery network that terminates TLS, that network sees the request — and, depending on configuration, the submitted payload. A Swiss database behind a US edge network is not a Swiss data path.
- E-mail notifications. The most common leak by a wide margin. A notification that includes the answers creates a plaintext copy of the submission in every recipient's mailbox and in every mail server along the way. If your inbox is on a foreign cloud, your Swiss-hosted form is now also stored there.
- Fonts, scripts and CAPTCHAs. A web font, an analytics snippet or a third-party CAPTCHA loaded from a foreign host discloses the respondent's IP address and page context to that host on every form view — before anyone submits anything.
- Error and performance monitoring. Crash reporters and session-replay tools routinely capture form field contents in their payloads. A monitoring backend in another country is a processor with access to submission data, whether or not anyone intended that.
- Support and administration access. Where does the provider's support team sit, and what can they see? Remote administration of a Swiss data centre from abroad puts a human with access outside the jurisdiction, even though the disks never move.
- Backups, and the second provider you did not notice. Backups sometimes live in a different region than production; payment providers, e-signature services, SMS gateways and AI features often live in a different country entirely. Every one of them belongs in the sub-processor list, and the sub-processor list is where residency claims usually break.
The test that finds all six at once
Open the public form page with the browser's network inspector running, and look at which hosts it contacts. Then submit a test response and read the notification e-mail. Two minutes of that tells you more about where your data goes than any vendor questionnaire — and it is the check that reveals the CDN, the fonts, the CAPTCHA, the analytics and the plaintext e-mail copy in one pass.
Is EU Hosting Good Enough?
Legally, usually yes — and that is the honest answer. EU and EEA states are on the Swiss adequacy list, so storing Swiss respondents' data in Frankfurt or Dublin is a lawful disclosure abroad that requires no standard clauses and no transfer impact assessment. If your only concern is nFADP compliance, EU hosting is a defensible choice and there is no reason to pretend otherwise.
Three situations change the calculus. First, a sector overlay that is stricter than data protection law: professional secrecy, cantonal rules for schools and hospitals, FINMA outsourcing expectations, research governance. Second, the ownership question — a great deal of EU-region hosting is provided by US-controlled groups, which puts you back at the CLOUD Act paragraph above. Third, the perception question, which is not legal but is real: an employee filling in a whistleblowing form, or a patient filling in an intake form, is making a trust decision, and «stored in Ireland by a US company» is a harder sentence to say than «stored in Switzerland». Where the whole point of the form is that people answer honestly, that matters. The full legal test, country by country, is in which form data can legally leave Switzerland.
What the «swiss hosting» Label Certifies — and What It Does Not
The «swiss hosting» label, launched by Swiss Made Software in August 2020, is the closest thing to a checkable shorthand. It requires that the company is Swiss-owned and headquartered in Switzerland, that applications and personal or business data are hosted in a data centre in Switzerland, that data protection and security are subject to Swiss law, and that only the customer and Swiss authorities may access the data. That covers all three of the claims we separated above, which is exactly why it is more useful than a flag icon.
Note what it still does not certify: whether the provider can technically read your content. Schweizerform is hosted at Infomaniak — an independent Swiss company founded in Geneva in 1994, majority-owned by its employees, with sites in Geneva and Zurich, certified to ISO 27001:2022 among others. That is a strong residency story, and on its own it would still leave the provider inside the trust perimeter. The reason it does not is architectural rather than geographic, and it is described on our security page.
A related trap: Google has operated a Google Cloud region in Zurich since 2019, which is Google Cloud Platform infrastructure — not Google Workspace. It gives Google Forms no Swiss residency option whatsoever. Data-region controls for Workspace offer «United States» or «Europe»; Switzerland is not on the list. The equivalent Microsoft nuance is that Switzerland is an Advanced Data Residency geography, but Forms is among the services carrying no data-residency commitment, so a Swiss tenant's Forms data lands in the EU/EFTA macro region regardless. Details in can I use Google Forms legally in Switzerland and the Microsoft Forms comparison.
Residency Answers «Who Can Compel», Not «Who Can Read»
Here is the sentence worth taking away: the location of the server tells you which state can compel access; the architecture tells you what there is to give. Almost every provider in this market encrypts data in transit and at rest with keys it holds itself. That is a sensible, real control against stolen hardware and misconfigured storage. It is not a barrier to the provider, its support tooling, its sub-processors, or an order addressed to it — because the provider holds the key. The distinction is set out in encryption at rest vs end-to-end.
End-to-end encryption changes the object of the question. When responses are encrypted in the respondent's browser and only the holder of the key can decrypt them, an order to the provider produces ciphertext, a compromised backup produces ciphertext, and a support engineer with production access sees ciphertext. Residency then becomes a useful second-order property rather than the load-bearing one — which is why we do both, and why we say plainly that doing only the first would be the weaker product.
The honest cost of that choice
If the provider cannot decrypt your data, the provider cannot recover it. A lost Vault key means unreadable submissions, with no reset path. Swiss hosting has no such trade-off, which is part of why it is the easier claim to make — and a reason to be suspicious when a vendor presents residency as if it solved the confidentiality problem too.
How to Verify a Hosting Claim in Fifteen Minutes
Ask where response data is stored, in writing
Not where the website is, not where the company is: where submission data and its backups sit. Accept only a named country and a named infrastructure provider. «In Europe» is not an answer; «Frankfurt, Google Cloud» is.
Identify the contracting entity, its ownership and the governing law
Which legal person do you contract with, who controls it, and which law and place of jurisdiction does the contract name? A Swiss GmbH with a foreign parent is a different risk picture from an independent Swiss entity under Swiss law.
Read the sub-processor list line by line
This is where residency claims break. Hosting, backups, e-mail delivery, error monitoring, support tooling, payments, AI features. Every entry with access to response data belongs in your own record of processing.
Run the network inspector on the live form
Load the public form and list every host it contacts. Fonts, CDNs, analytics and CAPTCHAs show up immediately, and each foreign host is a disclosure you did not put in the register.
Send yourself a test submission
Read the notification e-mail. If it contains the answers, the answers now live wherever your mail does. Turn the notification down to an alert without content if you can.
Ask the confidentiality question separately
«Can your staff, your support tooling or your sub-processors read a submission in plaintext? Where does the decryption key live?» A vendor that answers this crisply is telling you something residency never could.
Date the answer and diarise a re-check
Hosting regions, ownership and sub-processor lists change, sometimes quietly. Note the date you verified and re-verify at renewal — including against our own comparison page, which carries a verification date for exactly this reason.
When Swiss Hosting Genuinely Does Not Matter
Worth saying, because treating every form as a sovereignty question wastes the credibility you need for the forms that are. A lunch poll, an internal room booking, a public event signup with a name and an e-mail address, a satisfaction rating with no identifiers: for these, an EU-hosted tool your organisation already pays for is a perfectly reasonable answer, and insisting otherwise makes the conversation harder the day a genuinely sensitive form comes along.
The line is usually drawn by content rather than volume. Sensitive data under Art. 5 lit. c nFADP, anything under a secrecy duty, anything where the respondent's honesty depends on believing the channel, and anything a supervisory authority might one day ask about — those are the forms where residency and architecture both earn their keep. Our roundup of online form tools for Swiss companies takes the same both-feet-on-the-ground view of the market.
Bottom Line
Ask three questions instead of one. Where does the response data physically sit? Who owns and controls the operator, and under which law? And can anyone other than you read a submission? The first is a fact you can verify in writing. The second is a fact you can verify in a commercial register. The third is the one that determines how much the first two are worth — and it is the one most vendor pages never mention.
Swiss hosting is a real advantage, honestly stated: fewer transfers to document, procedural friction for foreign authorities, an easier story for regulated sectors. It is not a confidentiality guarantee, and any page that presents it as one — including a competitor's, including ours — should be read with that in mind.
Schweizerform stores encrypted submissions in Switzerland at Infomaniak on every plan, including Free, with no other region to choose. On top of that, responses are encrypted in the respondent's browser, so the list of parties who can read a submission is you and whoever you share the Vault key with. For the current vendor-by-vendor picture, see form and survey tools hosted in Switzerland; for the wider sovereignty argument, Swiss data sovereignty.
Disclaimer: This article is general information and marketing content, not legal advice. References to the nFADP (Art. 5 lit. c, 8, 16, 17, 24), the Data Protection Ordinance, Art. 321 StGB, 18 U.S.C. § 2713, the Swiss–U.S. Data Privacy Framework, the privatim resolution of November 2025 and the «swiss hosting» label are simplified summaries reflecting the position in July 2026. Vendor hosting locations and ownership change — verify current details directly with the provider before making procurement or compliance decisions, and consult qualified Swiss counsel on your specific processing. All product and company names are trademarks of their respective owners and are used here for factual comparison only. Competitive details were last verified on 25 July 2026.