Scholarship and Grant Application Forms
A grant application is the densest concentration of sensitive personal data a Swiss organisation routinely collects from people who cannot refuse: household tax assessments, social-assistance attestations, medical certificates, family circumstances — usually read by volunteers on personal laptops. Encrypted in the applicant's browser, submissions stored in Switzerland, with retention you can defend against both Art. 6 al. 4 nLPD and cantonal archiving law.

A scholarship or grant application is, in data-protection terms, the densest file a Swiss organisation routinely collects from someone who has no power to refuse. A single application folder can contain the tax assessment of the applicant and of their parents, a social-assistance attestation, a debt-enforcement extract, a residence permit, a medical certificate supporting a hardship claim, a separation or guardianship document, and a two-page motivation letter in which a nineteen-year-old explains why their family situation collapsed. Then it is read by a committee — frequently volunteers, frequently on personal laptops, frequently over a shared drive folder.
Schweizerform is an end-to-end encrypted intake layer for exactly that file. Every answer and every uploaded document is encrypted in the applicant's browser before it leaves the device, and only a holder of the Vault key can decrypt it. We store encrypted submissions in Switzerland with Infomaniak, we are a Swiss company, and we cannot read submissions — not for support, not for analytics, not under any legal process, because we do not hold the key. Forms and the applicant-facing interface run in German, French, Italian and English, which for a funding call open across the language regions is not a nice-to-have.
Who this page is for
Cantonal and communal grant offices, charitable foundations running open calls, association and employer hardship funds, university and school scholarship committees, sports and cultural sponsorship bodies, and research funders running internal calls. Schools and universities face the same intake problem across enrolment and pastoral files — see the educational institution use case.
Why Scholarship and Grant Applications Carry a Bigger Data-Protection Load Than Almost Any Other Form
Scholarships and study loans in Switzerland are awarded by the cantons, not by the Confederation. The federal Act on education grants (RS 416.0, in force since 1 January 2016) governs federal contributions to cantonal spending at tertiary level and the harmonisation effort behind it; the intercantonal concordat on the harmonisation of education grants entered into force on 1 March 2013 and the majority of cantons have acceded to it. According to the STIP statistics of the Federal Statistical Office, the cantons paid out roughly CHF 369 million in education grants in 2024, some 95 % of it as non-repayable scholarships. Alongside that public system sits a large private one: the Swiss Foundation Report 2025 (CEPS Basel, SwissFoundations and the University of Zurich, June 2025) estimates the annual grant volume of Swiss charitable foundations at around CHF 6 billion, roughly double the long-quoted figure.
What is actually inside a scholarship application file
- Household finances — the tax assessment of the applicant and, in most cantonal regimes, of the parents. In Geneva the calculation runs through the revenu déterminant unifié under Art. 18 al. 2 of the cantonal grant law (rsGE C 1 20).
- Social-assistance attestations — expressly listed as sensitive personal data under Art. 5 let. c ch. 6 nLPD, which names data on social-assistance measures.
- Health data — medical certificates supporting an interruption of studies, a hardship supplement or an extended deadline. Sensitive under Art. 5 let. c ch. 2.
- Migration and residence status — permit category and nationality, which are statutory eligibility criteria in most cantonal grant laws and can reveal ethnic origin.
- Proceedings and enforcement — debt-enforcement extracts, separation agreements, guardianship measures, touching Art. 5 let. c ch. 5.
- Third-party data the applicant did not own — parents' income, referees' statements, siblings in training, a landlord's lease contract.
- A personal narrative — the motivation letter, in which applicants volunteer illness, family violence, religion or political engagement without being asked.
The applicant cannot say no — and that changes the consent analysis
An applicant for a study grant is not a customer choosing a supplier. Cantonal grant laws require them to supply everything necessary — Geneva's Art. 21 obliges the applicant to provide tous les renseignements nécessaires and to report any change immediately, with Art. 27 providing for restitution of aid wrongly received. Refusing to attach the parental tax assessment means no money. That asymmetry does not remove your legal basis, but it does remove the comfortable argument that the applicant freely chose to hand you their family's finances. Where you rely on express consent for sensitive data under Art. 6 al. 7 nLPD, be honest with yourself about how free it is, and compensate on the security side rather than the paperwork side.
Cantonal office or private foundation? Two completely different legal regimes
This distinction decides almost everything downstream, and it is routinely blurred. Under Art. 2 nLPD, the federal Act applies to processing by private persons and by federal bodies. A cantonal or communal scholarship office is governed by its own cantonal data-protection law, is bound by official secrecy under Art. 320 StGB, and sits under a cantonal archiving statute. A private foundation is a private controller under the nLPD, supervised as to its purpose under Art. 84 al. 2 CC — by the federal supervisory authority (ESA) if it operates nationally or internationally, otherwise cantonally — with no archiving statute over it at all. See the public-sector use case for the official-secrecy side of this.
Official secrecy is not a data-protection duty — it is a criminal one
Art. 320 StGB / art. 320 CP punishes a member of an authority or a public official who reveals a secret entrusted to them in that capacity with up to three years' custodial sentence or a monetary penalty. The duty survives the end of the official relationship. privatim, the conference of Swiss data protection commissioners, treats this as a hard limit on outsourcing: a public body may only hand processing to a provider where no statutory secrecy rule stands in the way, and it remains fully responsible after the outsourcing.
What Changes With Zero-Knowledge Intake for Grant and Scholarship Applications
Concretely: the application is encrypted on the applicant's device with a key we never receive. What reaches our servers is ciphertext. When a committee member opens the file, decryption happens in their browser with the Vault key. There is no readable copy on the server, no readable copy in a support tool, and no readable copy that a provider could be compelled to hand over.
- The intake channel stops being email attachments scattered across personal inboxes and a shared drive folder.
- The information duty under Art. 19 nLPD is discharged once, on the form itself, in the applicant's own language — including the fact that parental and referee data will be processed. Geneva's Art. 6 requires informing parents and third parties au plus tard au moment de la collecte.
- Privacy by design and by default under Art. 7 nLPD becomes something you can point at rather than describe.
- Security appropriate to the risk under Art. 8 nLPD is provided by the architecture, not only by your access policy.
- Retention under Art. 6 al. 4 nLPD is enforced per form, so a rejected file does not quietly survive in three mailboxes.
The privatim standard for sensitive data in the cloud
privatim's cloud guidance (Merkblatt Cloud-spezifische Risiken und Massnahmen, v3.01, February 2022) is unusually direct for particularly sensitive personal data: the data must be encrypted, the encryption must be performed by the public body itself, and the keys must be available only to that body. Provider-side encryption is treated as the exception requiring justification. Client-side end-to-end encryption with a Vault key the funder alone holds is a literal implementation of that sentence.
The same guidance makes the point that most procurement checklists miss: data encrypted at rest is regularly not encrypted while the service processes it, so at-rest encryption in a conventional SaaS protects storage, not processing. That is the specific gap end-to-end encryption closes, and it is worth understanding before comparing vendors — encryption at rest versus end-to-end sets out the difference.
Where Funders and Grant-Makers Use Schweizerform
Cantonal and communal study-grant applications
Mostly as an annex rather than a replacement — see the concessions below. The parts of a cantonal grant process that fit are the high-sensitivity ones the main portal routes to a human anyway: hardship supplements, medical-certificate submission, requests for an extended deadline, and applications from situations the standard form cannot model.
Foundation funding calls and open grant rounds
The natural fit. A grant-making foundation running an annual call with 40 to 300 applications, assessed by a board that meets four times a year, has no register integration to lose and every reason to keep the files unreadable to everyone but the board. Associations and NGOs running case-based support face a very similar shape — see the NGO and non-profit case management use case.
Hardship, emergency and solidarity funds
The most sensitive category we see, and often the worst-served: a fund for members, staff or parents in acute difficulty, where the application arrives by email to a single named person because nobody wanted to put it in a system. An encrypted form with a one-person Vault key is strictly better than that email, and it produces a record you can actually audit.
Tax-remission and fee-waiver requests
Art. 167 DBG allows full or partial remission of tax debt, interest, fines and fees where the taxpayer is in a state of hardship, and the Federal Department of Finance's remission ordinance requires a written, reasoned, signed request with the necessary supporting documents. In practice that means a full picture of income, debts and living costs arriving in a communal office inbox. Fiduciaries and tax advisers preparing these files run the same intake problem — see the accounting and tax practice use case.
Research, sports and cultural funding calls
Internal seed funding, travel grants and equipment calls inside a university or hospital, where the applicant is also an employee and the reviewers are colleagues — and peer review means grant files move between people and, in international review, across borders, which is an Art. 16–17 nLPD question about transfers abroad rather than a formality. Talent-support funds, cultural project grants and youth camp subsidies sit alongside them, with a large share of minor applicants and files that pair a parent's income declaration with a child's health information. The four-language requirement bites hardest here, because these calls are often regional and the applicants are not filtered by language.
Referee statements, appeals and reconsideration files
Two flows that are almost always improvised. A referee statement is third-party data submitted about the applicant by someone else, and it usually arrives as an unencrypted email attachment; a separate encrypted form with its own link solves that cleanly. Appeals are the other: Geneva's Art. 28 gives 30 days for a réclamation before an appeal to the administrative court, and appeal files need to be complete, dated and readable years later.
Which Data in a Grant Application Counts as Sensitive Personal Data?
Art. 5 let. c nLPD lists the categories: religious, philosophical, political or trade-union views and activities; health, the intimate sphere and racial or ethnic origin; genetic data; biometric data uniquely identifying a person; data on criminal or administrative proceedings and sanctions; and data on social-assistance measures. Grant applications hit four of those six routinely. This table maps a typical file.
| What the application file contains | Status under nLPD Art. 5 let. c | Who genuinely needs to read it | What actually drives retention |
|---|---|---|---|
| Tax assessment of the applicant and, in most cantons, of the parents | Not itself listed as sensitive, but it discloses the whole household's finances; in Geneva it feeds the revenu déterminant unifié under Art. 18 al. 2 LBPE | The one person computing eligibility — not the whole committee | Cantonal archiving schedule for a public body; the ten-year books duty of Art. 958f CO where the payment is booked |
| Social-assistance attestation | Sensitive — data on social-assistance measures, Art. 5 let. c ch. 6 | Eligibility calculation only | Deletion under Art. 6 al. 4 nLPD once the file is closed, subject to archiving law |
| Medical certificate supporting a hardship or interruption claim | Sensitive — health data, Art. 5 let. c ch. 2 | The single person assessing the hardship claim | Destroy or anonymise once the decision is final, unless archiving law says otherwise |
| Residence permit category, nationality, migration status | Sensitive where it reveals ethnic origin, Art. 5 let. c ch. 2; also a statutory eligibility criterion | Eligibility check | Cantonal archiving schedule; permit copies rarely need to survive the decision |
| Debt-enforcement extract, separation or guardianship documents | Touches Art. 5 let. c ch. 5 on proceedings and sanctions, and is highly identifying about third parties too | Eligibility calculation only | Delete after the appeal window closes; never carry forward into the next round |
| Motivation letter and personal narrative | Not formally sensitive — but routinely volunteers illness, family violence, religion or political engagement, so Art. 5 let. c data by the back door | The review committee | Delete after the appeal window closes |
| Referee statements, academic transcripts, employer confirmations | Ordinary personal data — but third-party data the referee did not submit to you directly, which engages the Art. 19 nLPD information duty | The review committee | Delete after the appeal window closes |
| The decision itself — award or refusal, amount, reasons | Ordinary data, but for a cantonal body it is an administrative act and therefore an archival record | The funder, the auditor, the supervisory authority | Under Geneva's archiving law, records must be offered to the State Archives and may not be destroyed without authorisation |
Two rows people get wrong
A social-assistance attestation is not ordinary financial data — Art. 5 let. c ch. 6 nLPD names social-assistance measures explicitly, so the moment your form asks for one you are processing sensitive data. And a medical certificate attached to a hardship claim is health data under ch. 2 whether or not you asked for a diagnosis. Both trigger the Art. 6 al. 7 express-consent requirement and, at scale, the logging and processing-regulation duties of Art. 4–6 OPDo.
What Reviewers, Committees and Auditors Actually See
The default in most funding bodies is that everyone on the committee sees everything, because the file was circulated as one PDF. Almost nothing in the law requires that. The person computing eligibility from the tax assessment does not need the medical certificate; the board voting on merit rarely needs the debt-enforcement extract. Proportionality under Art. 6 nLPD is not satisfied by the fact that all readers are bound by confidentiality — it asks whether each reader needed the data at all.
Foundation supervision under Art. 84 al. 2 CC checks that assets are used in line with the foundation's purpose; the federal supervisory authority has run its digital supervision through the eESA system since May 2022. Auditors verify that the money went where the minutes say it went. Both need the decision, the amount and the reasoning — neither needs the medical certificate of a rejected applicant from four rounds ago. Structuring your forms so the audit trail and the sensitive annexes are separable is the whole game.
How Do You Give a Volunteer Committee Access Without Broadcasting the File?
This is the operational question that decides whether a funding body's data protection is real or theoretical, and it has a boring answer: split the intake, do not split the encryption.
- Use more than one form per round. An eligibility form holding the financial annexes with a Vault key held by one or two administrators, and a merit form holding the project description and motivation letter that the committee actually reads. Two links, two keys, one applicant journey.
- Keep the sensitive annexes out of the circulated pack. Committees should receive the assessment, not the raw certificates. If the pack has to travel, it should travel as a summary, not the file.
- Name key custodians in writing. Two people, an offline copy in the safe, handover on committee rotation. Under Art. 5–6 OPDo a private controller processing sensitive data on a large scale needs a processing regulation anyway — key custody belongs in it.
- Log who read what. Art. 4 OPDo requires logging of recording, modification, reading, communication, erasure and destruction for private actors processing sensitive data on a large scale, kept for at least one year. Reading is on that list and is the one most systems omit.
- Retire access when the mandate ends. Committee members rotate; their access should end with the mandate, not with the next audit.
How Do You Handle Document Uploads Without Creating a Second Copy Everywhere?
Uploads are where grant intake usually leaks. The applicant photographs a tax assessment on a phone, emails it, then emails a corrected version, then the office forwards both to two reviewers — and now six copies of a household's finances exist across four mail servers. Schweizerform encrypts attachments in the applicant's browser alongside the answers, so the file and its context stay in one encrypted record rather than fanning out as mail attachments. Vaud's grant service explicitly allows applicants to submit the form first and add documents afterwards; a form that accepts a late upload against the same encrypted record is the same convenience without the mail trail. The mechanics are set out in secure file uploads in online forms.
How Long Do You Have to Keep a Rejected Scholarship Application?
If you are a cantonal or communal body
You cannot simply purge rejected applications, however tidy that would be. Geneva's archiving law (rsGE B 2 15) forbids public institutions from destroying administrative records of potential archival value without the authorisation of the State Archives, requires them to offer records they no longer permanently need, and provides that documents classified by personal name containing sensitive personal data may not be consulted until ten years after the death of the person concerned. Destruction itself has to happen under archival control so that confidentiality is preserved. Art. 6 al. 4 nLPD's instinct — destroy when no longer necessary — is subordinated to that.
If you are a private foundation or association
No archiving statute sits over you. What remains is the duty to destroy or anonymise once the purpose is exhausted, plus Art. 958f CO, which requires business books and accounting records to be kept for ten years from the end of the financial year — that catches the payment and the award decision, not the rejected applicant's medical certificate. The practical schedule most foundations land on: keep the decision and the accounting trail for ten years, delete the sensitive annexes of unsuccessful applications once the appeal window has closed. Our form data retention guide covers how to set that per form.
For public bodies: an unreadable file is a destroyed file
If the Vault key is lost, the submissions are unrecoverable — that is the same property that keeps us out of the data. For a cantonal or communal body this is not merely inconvenient: where archiving law forbids destroying records of potential archival value without authorisation, a file nobody can open is functionally destroyed. Any public body adopting end-to-end encryption needs a documented key-custody arrangement — two named custodians, an offline copy, handover on rotation — written into its processing regulation before the first form goes live.
Deadlines, Late Files and Incomplete Applications
Grant rounds are deadline-driven in a way most form use cases are not. Cantonal regimes set statutory windows — Geneva requires the application within six months of the start of the academic year; Valais publishes fixed dates per semester for its online eBourse portal. A form that closes cleanly at the deadline, timestamps every submission, and lets an applicant complete a partially documented file afterwards without restarting is doing real work: it removes the argument about when something arrived, and it prevents the classic failure where a stressed applicant sends the missing attestation to a personal address after the portal closed.
Getting Started With Scholarship and Grant Forms
Decide which regime you are in
Cantonal or communal body, or private foundation or association. It determines whether cantonal data-protection law or the nLPD applies to you, whether Art. 320 StGB official secrecy binds your staff, and whether an archiving statute overrides your deletion schedule.
Split the round into an eligibility form and a merit form
Financial annexes on one, project and motivation on the other, with separate Vault keys. This single decision does more for proportionality under Art. 6 nLPD than any policy document.
Set up Vault key custody before the call opens
Two named custodians, an offline copy stored securely, a written handover step for committee rotation. Read how the Vault key works first — the recovery properties are the point, and they are not negotiable afterwards.
Write the Art. 19 information text into the form itself
Identity of the controller, purpose, categories of recipients, and — the one everyone forgets — that parental and referee data will be processed, with those third parties informed at the latest at the point of collection.
Set retention per form
Different windows for the decision, the accounting trail and the sensitive annexes. Public bodies check the cantonal archiving schedule before choosing any of them.
Pick a plan and open the call
A single funding round fits comfortably on one of the paid plans — Pro at CHF 19 and Business at CHF 49 per month, with a free tier for a first round. The plan comparison has the limits.
Running One Funding Round End to End
Publish the call in all the languages it is open in
One form, four language versions — German, French, Italian and English. A cantonal or national call published only in one language filters applicants by language rather than by merit. Starting from a form template shortens this considerably.
Collect applications and late annexes against the same record
Applicants submit before the deadline and attach the documents they are still chasing afterwards, without a second submission and without email.
Run the eligibility pass
One or two administrators decrypt the financial form, compute eligibility, and record a yes or no with a short reason. The tax assessments never reach the committee.
Circulate the merit pack to the committee
Committee members decrypt the merit form in their own browser with their Vault key. Nothing is emailed, nothing lands in a shared drive folder, and the sensitive annexes stay where they were.
Notify decisions and open the appeal window
Award and refusal notices go out with the reasoning and the deadline for a reconsideration request. Keep a separate encrypted form for appeals so that appeal files are complete and dated.
Close the round and run the deletion schedule
Once the appeal window has closed, delete the annexes of unsuccessful applications on the schedule you set. Keep the decisions and the accounting record; if you are a public body, offer the archival records rather than destroying them.
Common Objections — and Realistic Answers
The canton already runs a portal wired into the tax office — why would we need this?
For a canton in that position, you probably do not, and we would rather say so. Geneva's grant law gives the scholarship service direct statutory access to the databases of educational institutions, the population and migration office and the cantonal tax administration; Vaud and Valais run integrated online portals. That integration is the entire value: it removes documents a stressed nineteen-year-old would otherwise have to chase. A zero-knowledge form cannot query the cantonal tax register — by construction, not by omission. Where we fit inside a cantonal setup is the narrow annex: hardship supplements, medical certificates, appeal files, and the cases the main portal routes to a human anyway.
Our committee is made up of volunteers. Someone will lose the Vault key.
This is the most legitimate objection on the page and we will not soften it. If the key is lost, the data is gone — that is the same property that keeps us out of it. The mitigation is organisational, not technical: two named custodians, an offline copy in a safe, a handover written into the committee's rules of procedure, and a rehearsed recovery before the first real round. If your body cannot commit to that, end-to-end encryption is the wrong architecture for you and a conventional platform with a proper processing contract is the honest alternative.
We need to compute eligibility against income thresholds. Doesn't encryption block that?
It blocks the server-side version of it, yes. We cannot score applications, cannot run a rules engine on income thresholds, cannot auto-extract a figure from an uploaded tax assessment, cannot deduplicate applicants across rounds server-side, and cannot pre-fill from last year's file. Everything happens after decryption, in a browser, in front of a person. For a funder running two thousand formula-driven applications a year, a conventional grants-management system with a solid processing contract will hurt less. For a foundation running forty to three hundred applications that humans read anyway, the trade is trivially worth it.
Can't we just use a Google Form and a shared Drive folder?
You can, and it is worth being fair about why so many funders do: those tools are encrypted in transit and at rest, they are free or already paid for, and they are operationally frictionless. The objection is specific, not a smear. First, at-rest encryption leaves data unprotected while the service processes it. Second, privatim warns that providers subject to the US CLOUD Act must give US authorities access to stored data even when storage is in the EU or Switzerland, and treats such access as an unlawful disclosure to third parties because it lacks a legal basis recognised in Switzerland. For a public body bound by Art. 320 StGB that is a hard problem. We have written up both sides at length in is Google Forms secure? and Swiss data sovereignty.
We hand out CHF 40,000 a year. Is any of this proportionate?
The obligations under Art. 5 and Art. 6 nLPD attach to the data, not to the size of the grant. A small association fund handling twenty applications is still processing social-assistance attestations and medical certificates. What is proportionate is the effort: for a fund that size, this is one form, one Vault key, two custodians and a written deletion rule — an afternoon, not a project. A data protection impact assessment under Art. 22 nLPD is a separate question and depends on whether the processing presents a high risk; at that scale it usually does not, but the answer is yours to document.
Where Schweizerform Is Not the Right Answer
- A canton with an integrated portal should keep it. Register integration is the thing applicants value most, and we cannot provide it. Use us for the sensitive annex, not the main flow.
- No server-side automation. No scoring, no eligibility engine, no cross-round deduplication, no pre-fill from last year. If your process depends on those, choose a conventional grants platform with a proper processing contract.
- Key loss is unrecoverable, and for public bodies bound by archiving law that is a compliance risk, not just an operational one. Custody arrangements are a precondition, not a footnote.
- We are the intake layer, not a grants-management suite. No committee voting workflow, no budget tracking, no disbursement, no payment execution, no accounting. Money movement stays exactly where it is today.
The Bottom Line for Scholarship and Grant Application Forms
A grant application concentrates household finances, social-assistance attestations, health data and migration status into one file, submitted by someone who cannot decline to supply it, and read by people who are usually volunteers. Art. 5 let. c nLPD makes at least four of those categories sensitive; Art. 6, 7 and 8 set the handling standard; OPDo Art. 4–6 add logging and a processing regulation once you are doing it at scale; and for a public body, Art. 320 StGB and cantonal archiving law pull in opposite directions on what you may keep and what you may delete.
The intake layer is the part of that chain most easily fixed. Encrypt in the applicant's browser, hold the Vault key yourself, split the sensitive annexes from the merit pack, and set a deletion date per form. As of July 2026, Infomaniak's trust centre states that all of its data centres and software are located in Switzerland, which is where your submissions sit. What we do not do — scoring, disbursement, register lookups — we would rather you know before you sign up than after.
Start with one form for your next funding round on the free plan — encrypted in the applicant's browser, hosted in Switzerland, published in German, French, Italian and English — and keep the tax assessments out of the committee's inbox.
Disclaimer: this page is general information and marketing content, not legal, tax or compliance advice. References to the nLPD/nDSG and OPDo/VDSG, Art. 84 al. 2 CC, Art. 958f CO, Art. 167 DBG, Art. 320 StGB, the federal Act on education grants (RS 416.0), cantonal grant and archiving legislation and privatim guidance are summarised at a conceptual level, reflect the position as of July 2026, and are subject to cantonal variation and judicial interpretation. Responsibility for the lawful processing of applicant data remains with the funding body. Consult a qualified Swiss data-protection or administrative-law adviser before relying on any summary here for a compliance or procurement decision.