Is Typeform Compliant for Swiss Businesses?
For marketing and non-sensitive collection, yes — Typeform is an EU company with a proper processing agreement, and EU storage is adequate under Swiss law without standard clauses. The complications are narrower and more interesting: US cloud sub-processors underneath a Barcelona company, regional hosting gated to higher tiers, third-party scripts running on the respondent's side, and the fact that Typeform can read every answer. Where the line falls for a Swiss business.

Typeform is the form tool people actually enjoy filling in, which is why it ends up carrying far more than the marketing survey it was bought for. The compliance question usually arrives late — after the lead-generation form has quietly become a client onboarding form, or after somebody points out that the HR team is collecting exit-interview answers in it. The answer is more nuanced than either side of the usual argument, and the nuances are not the ones most often cited.
The short version
Yes for marketing and non-sensitive collection. Typeform SL is headquartered in Barcelona, so the corporate entity is in the EU and the CLOUD Act does not apply to it by corporate structure. EU and EEA states are on the Swiss adequacy list, so EU storage needs no standard clauses and no transfer impact assessment. Sign the processing agreement, name Typeform in your privacy notice, keep the field list proportionate, and you are compliant. The four things to actually check: the infrastructure underneath is US cloud, so sub-processor-level exposure is real; regional data hosting is a plan feature, not a default; the form page itself may load third-party scripts on the respondent's side; and Typeform can read every submission, which is the property that decides whether it belongs anywhere near confidential data.
For the head-to-head feature and pricing view, see Schweizerform vs Typeform. This article is the compliance question on its own.
What Swiss Law Actually Asks of You
The structure first, because it makes the rest easy to check. You are the controller; Typeform is a processor within the meaning of Art. 9 nFADP; you remain responsible for the processing regardless of how good the vendor is. Five obligations follow, and none of them requires Swiss hosting.
- A processing agreement. Typeform publishes a data processing agreement as part of its terms. Locate it, save a dated copy, and record it — see do you need a data processing agreement for your form tool for what it must contain.
- A documented basis for the disclosure abroad. EU/EEA states are covered by the Federal Council's adequacy list in Annex 1 to the Data Protection Ordinance, so an EU-hosted form is a lawful cross-border disclosure without further instruments. Where the chain reaches the United States, check whether the sub-processor is certified under the Swiss–U.S. Data Privacy Framework, recognised as adequate since 15 September 2024, or whether you need standard clauses. Detail in which form data can legally leave Switzerland.
- Transparency under Art. 19 — the controller, the purpose, the recipients and the countries. «We use Typeform, which processes responses in the EU/United States» is the sentence most Swiss privacy notices are missing.
- Proportionality under Art. 6 — the fields, again. This is the requirement that is failed most often and has nothing to do with the vendor.
- Security appropriate to the risk under Art. 8, which for a marketing form is satisfied comfortably and for a whistleblowing form is not, for reasons set out below.
The Four Things Worth Checking Before You Scale Up
1. An EU company on US infrastructure
Typeform SL sits in Barcelona, which is a genuine advantage over a US-headquartered vendor: the company itself is not a US electronic-communication provider, so 18 U.S.C. § 2713 does not reach it by corporate structure. In practice, however, Typeform's infrastructure relies on US-based cloud providers and sub-processors, with its main servers historically in Virginia and an EU data centre offered alongside. That puts the CLOUD Act question at the sub-processor layer rather than removing it — a different, narrower exposure than a US vendor, and not zero. Read the sub-processor list rather than the imprint.
2. Regional hosting is a paid feature, not a default
EU data hosting is described in Typeform's documentation as part of its higher, custom tiers, and it comes with separate EU API endpoints. Two consequences follow. First, if you assumed EU residency because you are a European customer, verify it — the assumption is common and often wrong. Second, there is no Swiss option at all; the best available answer is the EU, which is lawful but is not what a procurement checklist asking for Swiss data residency is asking for. The full market picture is in our roundup of form and survey tools hosted in Switzerland.
3. The respondent side of the page
This is the part that is almost never in the compliance review, and it applies to any embedded or hosted form. When the form loads, what else loads with it — analytics, tracking, fonts, session tooling — and what does that place on the respondent's device before they submit anything? Cookie and tracking obligations attach to that layer, and in Switzerland the transparency duty covers it too. Run the browser's network inspector on your live form and list the hosts it contacts; it takes two minutes and it is the fastest way to find a disclosure you did not document. The wider version of this check is in which form tools are hosted in Switzerland.
4. Typeform can read every submission
Like nearly every mainstream form platform, Typeform encrypts data in transit and at rest with keys it manages. That is a real and sensible control against stolen hardware and misconfigured storage. It is not a barrier to the provider itself, its support tooling or its sub-processors. So the honest answer to «who can read this response» includes your team, Typeform's staff with production access, and its sub-processors. For a lead form, irrelevant. For a legal intake form, it is the whole question — and it is the one distinction that no contract changes, which we explain in encryption at rest vs end-to-end.
Where Typeform Is the Right Call — and Where It Is Not
| Use | Typeform? | Why |
|---|---|---|
| Lead generation, waitlists, newsletter signup | Yes | Low-sensitivity contact data; the conversational format genuinely converts better |
| Marketing surveys, NPS, event feedback | Yes | Aggregate opinion data; provider readability is not a meaningful risk |
| Job applications | Careful | CVs carry far more than you asked for; set retention for rejected candidates and restrict who can view |
| Customer onboarding with financial or identity data | Weigh it | Lawful, but the reader list now includes the provider — decide whether that is acceptable and write down why |
| Health, therapy, legal or client-matter intake | No | Sensitive data under Art. 5 lit. c, and Art. 321 StGB secrecy reaches anyone who can read it |
| Whistleblowing and HR grievances | No | The value of the channel depends on the reporter believing nobody else can read it |
| Anything a supervisory authority may later ask about | Document first | Fine to use, but the transfer basis, sub-processors and retention need to exist on paper beforehand |
The pattern in that table is worth stating directly: the constraint is almost never the law, it is the reader list. Typeform's compliance posture is solid enough that a Swiss company can use it lawfully for the top half of the table without doing anything clever. The bottom half fails for a reason that is architectural rather than contractual, and no amount of paperwork moves it.
If You Are Staying on Typeform, Do These Five Things
Confirm where your responses are stored, in writing
Not the company's country: the data centre region for response data, whether the regional option applies to your plan, and where backups live. Save the answer with a date.
File the DPA and read the sub-processor list line by line
Every entry with access to response data belongs in your record of processing, along with the country. This is where the US layer becomes visible.
Name the processor in your privacy notice
Art. 19 wants recipients and countries. One sentence, in the notice on the form itself rather than only in a website footer.
Inspect what the form page loads
Open the live form with the network inspector running. Anything third-party is a disclosure and, if it profiles the respondent, likely needs consent and certainly needs disclosure.
Set retention and turn off answer-bearing notifications
Responses that arrive by e-mail become permanent unencrypted copies in several mailboxes. Alert without content, read in the tool, and put a deletion date on both the responses and any export. See form data retention.
The scope-creep pattern
Almost nobody chooses Typeform for sensitive data. They choose it for a marketing survey, and eighteen months later the same account holds an intake form, a job application form and a complaints form — because it was already there and it looked good. Do the review at the point the form changes, not at the point the tool changes; the compliance question follows the content, not the contract.
What Changes If You Move the Sensitive Forms
If the reader list is the problem, the only fix that works is architectural: end-to-end encryption, where the response is encrypted in the respondent's browser and only the key holder can decrypt it. The provider then holds ciphertext, its staff see ciphertext, a legal order to it produces ciphertext. Add Swiss hosting and the cross-border paragraph in your record gets shorter too.
The honest trade-offs: you lose provider-side features that require reading content, the conversational one-question-at-a-time experience Typeform is famous for is not the same, and a lost key means unreadable submissions with no recovery path. Most organisations end up splitting — keep the polished tool for the public-facing marketing forms where presentation drives conversion, and move the small number of forms that carry confidential content. That is scoping, not a migration project.
Bottom Line
Is Typeform compliant for Swiss businesses? For marketing and non-sensitive collection, yes — an EU company, an available processing agreement, and EU storage that is adequate under Swiss law without extra instruments. Do the paperwork once: DPA on file, sub-processors listed, Typeform named in the privacy notice, retention set, notifications stripped of answers.
The two things that are actually easy to get wrong are assuming EU residency you have not verified, and letting the tool drift from marketing into confidential intake. The second is where the answer changes — not because Typeform is careless, but because a provider that can read your submissions is inside your trust perimeter, and for some forms that is a property you need to remove rather than manage.
Schweizerform is built for exactly the forms in the bottom half of that table: responses encrypted in the respondent's browser, Swiss hosting on every plan including Free, and no provider-side access to content. It is not a Typeform replacement for a beautifully designed marketing quiz, and we would not pretend otherwise. Feature-by-feature: Schweizerform vs Typeform.
Disclaimer: This article is general information and marketing content, not legal, regulatory or procurement advice. Details about Typeform — corporate structure, hosting arrangements, regional data-hosting availability, plan gating, sub-processors and the processing agreement — reflect publicly available vendor documentation as checked in July 2026 and may change; verify current details directly with the vendor before making procurement or compliance decisions. References to the nFADP (Art. 5 lit. c, 6, 8, 9, 16, 19), the Data Protection Ordinance, Art. 321 StGB, the Swiss–U.S. Data Privacy Framework and 18 U.S.C. § 2713 are simplified summaries. All product and company names are trademarks of their respective owners, used here for factual comparison only. Competitive details were last verified on 25 July 2026.