Can I Use Google Forms Legally in Switzerland?
Google Forms is not illegal in Switzerland — but four questions decide whether your particular form is lawful: who you are, how sensitive the data is, whether a secrecy duty sits on top, and whether you have the processor and cross-border paperwork. A practical walk through Art. 5, 9, 16, 17 and 19 nFADP, the Swiss-U.S. Data Privacy Framework, and the sectors where the honest answer is no.

Using Google Forms in Switzerland is not illegal. There is no provision in the revised Federal Act on Data Protection (nFADP / nDSG, SR 235.1) that forbids foreign software, and none that requires personal data to sit on Swiss servers. What the law does is attach conditions — and the question worth asking is not «is Google Forms allowed?» but «is this particular form, with this particular data, lawful in my particular role?». For a conference RSVP the answer is almost always yes. For a patient intake form at a Zurich practice it is almost always no, and not for the reason most people assume.
The two-minute version
Four questions decide it. One: are you a private organisation or a public body — cantonal law and the November 2025 privatim resolution make the public-sector answer much stricter. Two: does the form collect sensitive personal data under Art. 5 lit. c nFADP (health, religion, political views, ethnicity, genetic or biometric data, criminal or administrative proceedings, social assistance)? Three: does a professional secrecy duty sit on top — Art. 321 SCC for doctors, lawyers and their staff, Art. 47 Banking Act for banks? Four: have you actually done the paperwork — a processor contract under Art. 9, a lawful basis for the transfer abroad under Art. 16, and the disclosure required by Art. 19 para. 4? Most Swiss users of Google Forms fail question four without knowing it.
This article answers the legal question. Our companion post Is Google Forms secure? answers the technical one — whether responses are encrypted, and who can read them. The short version of that article matters here: Google Forms encrypts in transit and at rest, but it is not end-to-end encrypted, so Google, your Workspace administrators and anyone the linked spreadsheet reaches can read the plain text. Swiss law does not care about encryption for its own sake; it cares about who can read the data and under which contract. That is why the technical fact drives the legal answer.
Is Google Forms Legal in Switzerland?
Yes, in principle. The nFADP is technology-neutral and provider-neutral. It does not maintain a list of approved tools, it does not require Swiss hosting, and it does not treat a US provider as forbidden. A Swiss company that uses Google Forms to collect newsletter signups, event registrations or an internal lunch poll is doing nothing unlawful, provided it meets the ordinary duties every controller has: process lawfully, in good faith and proportionately (Art. 6), keep the data secure (Art. 8), inform respondents (Art. 19), and delete what is no longer needed.
The word «legally» in the question, though, usually hides a different worry — that somebody will point at the tool and say it should never have been used for this data. That is the right worry, and it has four separate sources. They stack, and each one can independently make an otherwise fine setup unlawful.
The four questions that actually decide it
- Who are you? Private organisations are governed by the federal nFADP. Cantonal and communal bodies — schools, administrations, hospitals in public ownership — are governed by cantonal data protection law, which is often stricter, and by the supervisory practice of their cantonal data protection authority.
- How sensitive is the data? Art. 5 lit. c nFADP defines sensitive personal data narrowly but consequentially. Collecting it raises the bar on consent (Art. 6 para. 7 lit. a requires explicit consent where consent is the basis) and often triggers a data protection impact assessment under Art. 22 para. 2 lit. a.
- Is there a secrecy duty on top? Professional secrecy under Art. 321 of the Swiss Criminal Code, banking secrecy under Art. 47 of the Banking Act, and official secrecy under Art. 320 SCC are not data protection rules. They are criminal provisions, they bind you personally, and they are not satisfied by a data processing agreement.
- Have you done the paperwork? A processor contract under Art. 9, a lawful basis for the disclosure abroad under Art. 16 or Art. 17, and the transparency duty in Art. 19 para. 4 — which requires you to name the destination country in your privacy notice. This is the layer almost everybody skips.
The consumer-account trap
If you are using Google Forms from a personal @gmail.com account for organisational purposes, you have no processor contract at all. The Cloud Data Processing Addendum that turns Google into a contractual processor is part of the Google Workspace and Cloud Identity agreements — not of the consumer terms. Without it, you cannot demonstrate compliance with Art. 9 nFADP for any respondent data, however harmless. This single point disqualifies a large share of Swiss associations, small practices and one-person companies that reach for the free tool.
Do You Need a Data Processing Agreement With Google?
Yes. When you collect responses through Google Forms, you are the controller and Google is your processor: it processes personal data on your behalf, on your instructions, for your purposes. Art. 9 para. 1 nFADP allows that delegation by contract or by legislation, on two conditions — the processor may only do what you yourself would be permitted to do, and no statutory or contractual duty of confidentiality may prohibit the delegation in the first place. Art. 9 para. 2 adds that you must satisfy yourself, specifically, that the processor is able to guarantee data security.
In practice that means opting in to (or confirming that your agreement already incorporates) Google's Cloud Data Processing Addendum, which is offered for Google Workspace and Cloud Identity and expressly references the Swiss FADP alongside the GDPR and UK law. Google's own guidance notes that customers billed outside Europe, the Middle East and Africa whose use becomes subject to the Swiss FADP need to certify as such — which is exactly the situation of a Swiss customer on a non-EMEA billing arrangement. Check it; do not assume it.
Subprocessors need your prior approval
Art. 9 para. 3 nFADP says a processor may only delegate processing to a third party with the controller's prior authorisation. Google, like every hyperscaler, runs on a long subprocessor list that changes over time. The compliant pattern is general authorisation plus notification — you accept the published list and the change process in the addendum, and you keep a copy of the list you accepted. The non-compliant pattern is never having looked at it.
What a processor contract does not buy you
A signed addendum makes the processing relationship lawful. It does not change who can technically read the data, it does not release you from a secrecy duty, and it does not stop a lawful order in the provider's home jurisdiction. Contract terms allocate responsibility; they do not remove capability. That distinction is the whole substance of the Swiss debate about international cloud services, and it is why the technical question and the legal question refuse to stay separate.
Does Google Forms Data Leaving Switzerland Break the Law?
Not by itself. Art. 16 para. 1 nFADP permits disclosure abroad where the Federal Council has determined that the destination guarantees adequate protection — the list lives in Annex 1 of the Data Protection Ordinance (DPO / DSV, SR 235.11). All EU and EEA states are on it. The United States is on it too, but conditionally: by ordinance of 14 August 2024, in force since 15 September 2024, the Federal Council recognised US recipients that are certified under the Swiss-U.S. Data Privacy Framework as providing adequate protection. Google LLC certifies under the Swiss-U.S. DPF, alongside the EU-U.S. DPF and the UK extension.
So the transfer route itself is available. What people get wrong is that adequacy is not automatic and not permanent: it depends on the recipient staying certified for the relevant data categories, and a Federal Council determination can be revised. If you cannot rely on Art. 16 para. 1, you fall back to the safeguards in Art. 16 para. 2 — standard data protection clauses recognised by the FDPIC, binding corporate rules, and so on — or, in individual cases only, to the derogations in Art. 17. Our cross-border transfer guide walks through that test in full.
Art. 61 nFADP is a criminal provision
Disclosing personal data abroad in breach of Art. 16 paras. 1 and 2, where none of the Art. 17 exceptions applies, is punishable on complaint with a fine of up to CHF 250,000 under Art. 61 lit. a nFADP. Handing processing to a processor without meeting the Art. 9 conditions is punishable under Art. 61 lit. b. The fines target private individuals — the responsible natural person, not an abstract company. Swiss data protection enforcement is not purely administrative, and this is the article that surprises people.
Is EU hosting enough for Swiss form data?
For the adequacy question, yes: every EU/EEA state is on Annex 1, so storing Swiss respondents' answers in an EU datacentre needs no additional transfer instrument. Google Workspace offers a data regions setting that lets an administrator pin primary data at rest to the EU or the US, and Google's documentation lists Forms among the services covered for data at rest. Two caveats matter. First, the coverage for processing location is narrower than for storage, so transient processing may still occur elsewhere. Second — and this is the point Swiss buyers keep missing — Switzerland is not one of the choices. The EU multi-region explicitly excludes non-EU geographies including Switzerland and the UK. «EU hosting» is a lawful answer to Art. 16; it is not a Swiss-hosting answer.
You must name the destination in your privacy notice
Art. 19 para. 4 nFADP is short and widely ignored: where personal data is disclosed abroad, the controller must also inform the data subject of the state or international body concerned and, where applicable, of the safeguards under Art. 16 para. 2 or the use of a derogation under Art. 17. A privacy notice that says «we use third-party services» does not satisfy it. Naming «Google LLC, United States, on the basis of the Swiss-U.S. Data Privacy Framework» does. Failure to inform is itself punishable under Art. 60 nFADP, again with fines up to CHF 250,000.
When Google Forms Is Perfectly Fine in Switzerland
It is worth saying plainly, because compliance content tends to imply that every tool is a liability. Google Forms is a good product, it is free, it is familiar to everyone, and for a large class of Swiss use cases it raises no serious legal question at all. If your form fits the following description, use it and spend your compliance energy elsewhere:
- You run it from a Google Workspace account with the Cloud Data Processing Addendum in place — not a personal Gmail account.
- The data is ordinary personal data: name, email, company, meal preference, session choice, satisfaction rating.
- No sensitive category under Art. 5 lit. c is collected — no health details, no religious or political affiliation, no criminal proceedings, no social assistance.
- No professional secrecy binds you in respect of the respondents.
- Your privacy notice names Google and the destination country, and your record of processing activities (Art. 12) lists the tool.
- Retention is deliberate: the responses and the linked spreadsheet get deleted when the purpose ends, not «whenever».
Event registrations, newsletter signups, internal polls, feedback on a public talk, volunteer availability, non-sensitive customer surveys — for these, Google Forms with a Workspace account and a correct privacy notice is a defensible choice, and any consultant who tells you otherwise is selling something.
When Google Forms Is Not the Right Choice
The line is not «Swiss versus foreign». It is «who is allowed to be able to read this». Once the answer to that question is «only me and the respondent», a tool whose provider holds the keys stops being suitable — regardless of adequacy decisions, contracts or the quality of Google's security engineering, which is genuinely excellent. The table below is the practical version of the four questions.
| Form / data type | Google Forms on Workspace | What actually decides it |
|---|---|---|
| Event registration, RSVPs, internal polls | Fine | Ordinary personal data; processor contract and privacy notice suffice |
| Customer satisfaction, non-sensitive market research | Fine | Keep free-text fields from turning into sensitive data by accident |
| Job applications, CV intake | Borderline | Health, religion or criminal-record questions push it into Art. 5 lit. c; retention of rejected applicants is the real exposure |
| Employee surveys, feedback on management | Borderline | Art. 328b CO limits what an employer may process; employees rarely believe a tool the employer administers is anonymous |
| Event forms asking about allergies, medication, disability | No | Dietary and accessibility answers are health data under Art. 5 lit. c |
| Patient intake, medical history, therapy questionnaires | No | Art. 321 SCC professional secrecy plus sensitive data; Art. 9 para. 1 lit. b blocks the delegation itself |
| Lawyer or notary client intake | No | Art. 321 SCC and professional conduct rules; privilege does not survive a readable copy at a third party |
| Whistleblowing and grievance reports | No | Reporter identity is the protected asset; admin-readable storage defeats the purpose and the EU directive's confidentiality requirement |
| School forms on special needs, welfare, guardianship | No | Cantonal school data protection law plus sensitive data on minors |
| Public-body forms with sensitive or secrecy-bound data | No | Cantonal law and the November 2025 privatim resolution on international cloud services |
The Sectors Where the Answer Is Effectively No
In four Swiss contexts the analysis short-circuits: a rule outside data protection law decides the question before the nFADP test even begins.
Medical, dental, psychological and pharmacy practices
Art. 321 of the Swiss Criminal Code makes it an offence — punishable by up to three years' imprisonment or a monetary penalty — for doctors, dentists, chiropractors, pharmacists, midwives, psychologists and their auxiliary persons to disclose a secret confided to them in their professional capacity. Software vendors with technical access to plain-text patient data sit uncomfortably close to that perimeter, and the practitioner carries the criminal risk personally. Art. 9 para. 1 lit. b nFADP closes the circle from the data protection side: processing may not be delegated where a statutory or contractual duty of confidentiality prohibits it. This is why a data processing agreement is not the answer for a practice — the agreement is a data protection instrument, and the obstacle is criminal law. See our healthcare forms use case for how zero-knowledge intake resolves it.
Law firms and notaries
The same Art. 321 applies to lawyers, defence counsel and notaries, reinforced by the professional conduct rules of the cantonal bar associations. Client intake forms routinely capture the facts of a dispute before an engagement even exists — precisely the material privilege is designed to protect. A provider that can read the intake form is a party who holds privileged information without being bound by the privilege. Our legal intake use case covers the practical setup.
Schools, cantonal administrations and other public bodies
Public bodies are the strictest case, and the position hardened recently. In a resolution published in November 2025, privatim — the conference of Swiss cantonal data protection commissioners — held that outsourcing sensitive personal data, or data subject to a statutory duty of secrecy, to international cloud providers is in most cases inadmissible for public bodies, because most SaaS offerings do not provide genuine end-to-end encryption that would exclude provider access to plain text, and because global vendors offer too little transparency for authorities to verify contractual compliance. The exception the resolution leaves open is narrow and specific: the responsible body encrypts the data itself and the provider has no access to the key.
For schools specifically, Switzerland has built a workable middle path for the general platform: educa has negotiated a framework agreement for Google Workspace for Education under which Swiss law and a Swiss place of jurisdiction apply to the relationship with Google Ireland, storage locations in the EU can be selected, and advertising profiling of pupils is contractually excluded. The cantonal guidance that accompanies it, however, is consistent — sensitive data does not belong in the platform, and surveys collecting it need additional protection. Using the classroom Workspace for a schedule poll is fine; using it for a welfare questionnaire is not. Our educational institution use case is written around that split.
Banks, insurers and regulated financial firms
Client identifying data is protected by Art. 47 of the Banking Act, and FINMA's outsourcing expectations require regulated institutions to keep control, auditability and access rights over outsourced processing — including the ability of the regulator and the internal audit function to inspect. A free consumer-grade form tool is not going to satisfy an outsourcing inventory, and «we used Google Forms for the onboarding questionnaire» is not a sentence anyone wants in an audit report.
A Decision Tree for Swiss Organisations
Work through these in order. The first «no» decides the matter — there is no averaging.
- Are you a public body? If yes, apply cantonal law and your cantonal authority's guidance first, and read the privatim resolution before anything else. For sensitive or secrecy-bound data, assume no unless you hold the keys yourself.
- Does a secrecy duty bind you under Art. 321 SCC, Art. 320 SCC or Art. 47 Banking Act? If yes, stop. No processor contract cures a criminal-law duty; you need a tool the provider cannot read.
- Does the form collect sensitive data under Art. 5 lit. c nFADP — health, religious, philosophical, political or trade-union views, intimate life, ethnicity, genetic or biometric data, criminal or administrative proceedings, social assistance? If yes, treat Google Forms as unsuitable and document why.
- Could free text turn into sensitive data? A field labelled «anything else we should know?» on a registration form reliably collects health information. If you cannot prevent that, treat the form as sensitive.
- Are you on Workspace with the Cloud Data Processing Addendum, and can you produce it? If not, fix that before collecting anything.
- Does your privacy notice name Google and the destination country, and does your Art. 12 record of processing list the tool? If not, you have an Art. 19 and Art. 60 problem independent of everything above.
- If all six are clear, use it. Then set a retention rule for the responses and the linked spreadsheet, and review the sharing settings on both.
What to Do If You Are Already Using Google Forms for the Wrong Data
This is the common situation, and panic is not the right response. A clinic that has been collecting anamnesis forms through Google Forms for two years has a problem to remediate, not a scandal to conceal. The order matters, because stopping the intake without cleaning up the archive leaves the exposure in place.
Stop the intake first
Close the form to new responses today. Every additional submission enlarges the set of data you will have to justify, migrate and delete.
Inventory what exists
The form itself, the linked Google Sheet, downloaded exports, email notifications containing answers, copies in shared drives, and any spreadsheet a colleague duplicated. Responses proliferate faster than anyone expects.
Assess and document
Note which data categories were collected, over what period, who had access, and where it was stored. If the exposure is significant and involves sensitive data, assess whether Art. 24 nFADP notification to the FDPIC is triggered. Write it down — the record of your assessment is what an auditor asks for.
Rebuild the form on a suitable platform
Recreate the questions on an end-to-end encrypted, Swiss-hosted tool, and take the opportunity to cut fields you never actually used. Data you do not collect is data you never have to defend.
Migrate what you must keep, then delete the rest
Some records carry retention duties — medical documentation, accounting records under GeBüV. Export those, store them where they belong, and then delete the Google Forms responses, the linked sheet, the exports and the email copies.
Update the paper trail
Amend the record of processing activities, the privacy notice and the list of processors, and note the change and its date. A remediated setup with documentation beats a clean-looking setup with none.
The Swiss-Hosted, Zero-Knowledge Alternative
Schweizerform exists for exactly the forms in the «no» column. Responses are encrypted in the respondent's browser with AES-256-GCM before transmission; the per-submission key is wrapped with the form's public key, and the private key chain is protected by the owner's Vault key, which never reaches our servers. We store encrypted submissions on Swiss infrastructure and, structurally, cannot read a single submission.
The legal consequence is what matters here, and it is precise rather than promotional. There is no disclosure of readable personal data abroad, because there is no readable data anywhere outside the two browsers. The Art. 9 lit. b obstacle — a confidentiality duty prohibiting delegation — falls away when the provider has no technical access to the secret. And the narrow exception in the privatim resolution, where the responsible body encrypts and the provider holds no key, describes the architecture rather than an add-on. If you want the vendor landscape rather than our own pitch, the roundup of form tools hosted in Switzerland compares the Swiss options honestly, and the Schweizerform vs Google Forms comparison is the feature-level view.
To be fair to Google: none of this says Google Forms is badly built or that Google is careless with data. Its infrastructure security is better than almost any organisation could achieve alone, which is the point our Is Google Forms secure? article makes at length. The mismatch is about access, jurisdiction and secrecy duties — not about engineering quality.
Bottom Line: Can I Use Google Forms Legally in Switzerland?
For ordinary personal data, from a Google Workspace account, with the Cloud Data Processing Addendum in place and a privacy notice that names Google and the destination country: yes. The Swiss-U.S. Data Privacy Framework has been part of Annex 1 to the Data Protection Ordinance since 15 September 2024, Google LLC certifies under it, and the transfer route is available. Nothing about the tool is inherently unlawful in Switzerland.
For sensitive data under Art. 5 lit. c nFADP, for anyone bound by Art. 321 SCC, for public bodies handling secrecy-bound information, and for whistleblowing or welfare intake: no — and the reason is not the server location but the fact that the provider can read the plain text. The honest test is the one from the beginning of this article. Ask who is able to read the responses, list them, and decide whether every name on that list belongs there. When the list has to be «only me», the tool has to be one that cannot read your data at all.
Schweizerform is that tool: end-to-end encrypted forms, Swiss hosting, EN / DE / FR / IT throughout, and a free plan with no credit card required. If you are migrating away from Google Forms for a specific category of form, that is the fastest place to start.
Disclaimer: This article is general information and marketing content, not legal advice. References to the nFADP, the Data Protection Ordinance, the Swiss Criminal Code, the Banking Act, cantonal data protection law and the Swiss-U.S. Data Privacy Framework are simplified and reflect the position at the time of writing (July 2026); adequacy determinations, vendor certifications, contractual terms and hosting options change. Statements about Google Forms and Google Workspace summarise publicly available vendor documentation and should be verified directly with the vendor for your plan and configuration. Whether a specific form is lawful depends on your role, your sector and your data — consult qualified data protection counsel before relying on any single article, including this one. All product and company names are trademarks of their respective owners and are used here for factual reference only. Competitive details were last verified on 25 July 2026.