Data Protection for Swiss Trustees, FINMA, Banking Secrecy, DSG
Introduction
Swiss trustees (Treuhänder) handle data protected under several regimes simultaneously: tax and accounting records, account statements from Swiss and foreign banks, ownership structures, beneficial-ownership data, payroll and HR data, and client correspondence with substantial trade-secret content. They operate at the intersection of the revised Federal Act on Data Protection (DSG), banking secrecy (Art. 47 BankA) where bank data is involved, AMLA due diligence duties, FINMA outsourcing rules (Circular 2018/3), international tax exchange (AEOI/CRS, FATCA, group requests), and – for engagements with FINMA-supervised clients – indirect resilience and cyber requirements. Running this poorly in 2026 risks DSG fines up to CHF 250,000, AMLA proceedings, FINMA interventions at the client level and reputational damage in the strictest sense.
What this article delivers:
- Where banking secrecy (Art. 47 BankA) meets the DSG
- FINMA outsourcing expectations and their effect on trustees as IT-engaged providers
- International tax data flows (AEOI, FATCA, mutual assistance, group requests)
- AMLA due diligence duties and their data-protection implications
- Concrete TOMs and a prioritised implementation plan
Legal framework
A Swiss trustee operates under at least six overlapping bodies of law:
- FADP: processing of personal data (clients, their beneficial owners, their employees), with information, access, rectification and notification duties.
- Banking secrecy (Art. 47 BankA): primarily binds the bank, but trustees who receive bank data – e.g. account statements for bookkeeping – must preserve the secrecy. Breach is a criminal offence, also when committed by auxiliaries.
- AMLA, FINMA Anti-Money-Laundering Ordinance: due diligence to identify contracting parties and beneficial owners (KYC), reporting suspicions to MROS.
- Professional secrecy under Art. 321 SCC: does not bind trustees directly but does bind affiliated tax advisers and auditors in certain constellations; contractually agreed confidentiality complements this.
- Tax mutual assistance: TAAA, AEOI Act, FATCA Switzerland-US agreement, bilateral DTAs with information clauses.
- FINMA Circular 2018/3 "Outsourcing": relevant when the trustee acts as outsourcing provider for a FINMA-supervised bank, insurer or asset manager – the requirements pass from the client to the trustee.
Banking secrecy meets DSG
When the trustee processes account data and bank correspondence on behalf of the client, the trustee becomes an indirect bearer of secrecy under Art. 47 BankA. Practically, this means: disclosure of this information to third parties – including to internal trustee staff outside the need-to-know – is criminal. Bank data must therefore be processed in a documented separation from other client data, with need-to-know access and logged inquiries.
The Art. 25 DSG right of access can collide with banking secrecy: a person asks for everything the trustee holds about them; that may include data on third parties (e.g. an account holder). In such cases access must be restricted under Art. 26(2)(b) DSG where overriding third-party interests or statutory secrecy prevail. The refusal must be reasoned without disclosing the secret. A documented internal "access request" playbook with decision logic, templates and four-eyes approval is recommended. Equally sensitive: requests from foreign tax authorities sent directly to the trustee. These must be routed through the Federal Tax Administration (mutual assistance under TAAA); direct disclosure to foreign authorities is criminal under Art. 271 SCC.
FINMA outsourcing requirements
When a trustee provides accounting, payroll, VAT and tax-return services to FINMA-supervised clients (banks, insurers, asset managers, securities firms), the trustee is regularly classified as an outsourcing provider under FINMA Circular 2018/3. FINMA expectations are passed contractually to the trustee with material effect:
- Selection and oversight: the client must document selection and periodic review; the trustee must cooperate (audits, questionnaires, ISAE 3402 Type II or ISAE 3000 reports).
- Outsourcing contract: must contain concrete duties on data security, sub-contracting, business continuity, exit and audit rights.
- FINMA access rights: FINMA must be able to access the outsourced function – this includes the trustee's premises, files and personnel.
- Materiality and concentration: the client must assess whether the outsourcing is material, which triggers stricter requirements.
- Operational resilience under FINMA Circular 2023/1: recovery times, critical functions, concentration risk – even where the trustee is not itself supervised, this shapes operational reality.
Trustees serving multiple FINMA clients benefit greatly from their own ISO 27001 certification and an ISAE 3402 report – both substitute for a substantial portion of recurring audit questionnaires.
International tax data flows
In 2026 trustees are regularly drawn into international tax information flows. Four mechanisms stand out:
- Automatic Exchange of Information (AEOI/CRS): Switzerland exchanges account data with 100+ partner states. Trustees managing trusts and ownership structures identify beneficial owners and deliver data to the Federal Tax Administration (ESTV), which forwards it. Data-protection communication to data subjects is mandatory.
- FATCA: US persons are reported separately; Swiss financial institutions, in some constellations trustees as sponsoring entities, report under the Switzerland-US FATCA agreement.
- Mutual assistance on request (TAAA): individual or group requests from foreign authorities via ESTV with notice to data subjects and judicial review at the Federal Administrative Court.
- Comparable channels (DAC7, Pillar 2 reporting): EU directives reach Swiss group structures and indirectly affect trustees supporting their reporting.
From a data-protection perspective: cross-border disclosure under Art. 16 DSG is directly permitted only to states with adequate data-protection levels (Federal Council adequacy list); other states require safeguards (Standard Contractual Clauses, recognised mechanisms). Swiss obligations toward ESTV are statutorily covered, but processing upstream at the trustee is fully DSG-governed.
AMLA due diligence and data protection
Trustees performing financially intermediated business (asset management, trust administration, domiciliary companies) are subject to AMLA as financial intermediaries under Art. 2(3) AMLA and require either SRO membership or a FINMA licence. This entails KYC identification of contracting party and beneficial owner, periodic monitoring and suspicious activity reports to the Money Laundering Reporting Office Switzerland (MROS) under Art. 9 AMLA.
The data-protection implications are subtle. Processing of KYC data is statutorily grounded (Art. 31(1)(c) DSG), but retention periods (at least 10 years after the end of the business relationship under Art. 7 AMLA) collide with DSG erasure rights – the statutory retention prevails. MROS suspicious activity reports carry a non-disclosure obligation toward the customer (Art. 10a(1) AMLA) – the Art. 25 DSG right of access is correspondingly restricted (Art. 26(2)(a) DSG). Anyone processing KYC data in the trustee organisation needs a tightly documented separation between compliance and client data, technically and organisationally, and a defined procedure to handle access requests that may touch KYC/MROS content.
Technical and organisational measures
A Swiss trustee in 2026 should have at minimum the following TOMs in place:
- Identity and access management: phishing-resistant MFA (FIDO2), role-based access per client cluster, privileged-access management for administrators, quarterly access reviews.
- Endpoint and network security: EDR on every endpoint, vulnerability management with monthly patching, segmented networks for KYC/bank data.
- E-mail and data transfer: enforced TLS, S/MIME for sensitive correspondence, secure file exchange via a Swiss- or EU-hosted platform – no pure US tools without a TIA.
- Backup and recovery: daily backups, immutable off-site copies, quarterly recovery tests, ransomware playbook.
- Logging and monitoring: central SIEM or MDR with use cases for unauthorised access to KYC data, anomalous mass downloads, privilege escalations.
- Contract management: DPAs under Art. 9 DSG with every cloud and IT provider, sub-processor inventory with transfer assessments, four-eyes approval for new sub-processors.
- People: documented confidentiality obligations referring to banking secrecy and AMLA, annual awareness training, onboarding/offboarding processes with access removal within 4 hours.
- Audit readiness: ISAE 3402 Type II or ISO 27001 certification as market standard for trustees serving FINMA-supervised clients.
How SIDD supports you
SIDD supports Swiss trustees from sole practitioners to mid-sized trustee networks on data protection, banking-secrecy compliance and information security. Our interdisciplinary team (Swiss and international lawyers, ISO 27001 Lead Auditors, former FINMA practitioners) delivers the processing register, the client privacy notice, FINMA outsourcing contract annexes, AEOI/FATCA data-protection communication, a KYC/MROS-compliant access playbook and an incident handbook. Our data-protection adviser mandate for trustees is tailored to this complexity. For the security organisation we frequently combine the adviser mandate with an external CISO mandate, an ISO 27001 certification and an annual penetration test. For trustees with EU clients we add the GDPR DPO function. Speak with us via our contact form or request a confidential quote.
