Swiss Data Protection Law in the International Context
Switzerland in the Global Data Protection Landscape
The Swiss DSG (Federal Act on Data Protection / FADP) has applied in its fully revised form since 1 September 2023 and positions itself deliberately between European GDPR stringency and global interoperability. The act follows the Council of Europe's Convention 108+ and aligns substantively with the GDPR but retains specificities on sanctions (Art. 60 et seq. DSG), on the Data Protection Advisor role (Art. 10 DSG) and in the FDPIC procedural law. This constellation makes Switzerland attractive for international companies: high protection level, clear supervision, yet a different sanctions dynamic than the EU. The DSG pillar guide (German-language pillar) develops the domestic system in depth.
International interconnection operates at several levels: at international law through the Council of Europe's Convention 108+ and the OECD Privacy Guidelines, supranationally through EU adequacy, bilaterally through the Swiss-US Data Privacy Framework (DPF) and sectorally through arrangements in the banking, insurance and healthcare areas. Swiss controllers therefore operate in a multi-layered compliance model in which the DSG forms the base and additional regimes are added depending on the business relationship. This article positions the most important building blocks, their relationships and the operational consequences for practice.
Switzerland-EU Adequacy: Mutual Recognition
The European Commission's adequacy decision in respect of Switzerland of 15 January 2024 formally confirms that Switzerland under the revised DSG offers a level of protection essentially equivalent to the GDPR. Data transfers from the EEA to Switzerland therefore no longer require the additional safeguards of Art. 46 GDPR. Conversely, the EU is listed in Annex 1 of the DSV as a state with adequate data protection for disclosures under Art. 16(1) DSG. This mutual recognition materially reduces the documentary burden on Swiss companies with EU exposure but does not replace the domestic GDPR obligations where there is an establishment or market activity in the EU.
Adequacy is conditional and is reviewed by the European Commission every four years (Art. 45(3) GDPR). An amendment to the DSG that lowered the substantive level of protection could jeopardise adequacy. Conversely, Switzerland is de facto bound by the ongoing development of the GDPR if it wishes to retain adequacy. This quiet convergence operates as a constant modernisation pressure, for instance on the interpretation of DPIA thresholds, on the handling of cookie consent or on the assessment of cross-border transfers. The DSG remains autonomous, yet its interpretive corridor is co-drawn from Brussels.
Swiss-US Data Privacy Framework: Practical Reach
The Swiss-US Data Privacy Framework (DPF) was recognised by the Federal Council in summer 2024 as an adequacy decision for the United States and has applied since 15 September 2024. It allows data transfers to US recipients that have certified to the Swiss-US DPF with the US Department of Commerce, without additional safeguards under Art. 16(2) DSG being required. The list of certified recipients is available daily at the Department of Commerce. Uncertified recipients or processing outside the DPF scope (for example, the HR area is not covered by default) still require SCCs plus a Transfer Impact Assessment. A repeat of the Schrems saga cannot be excluded; the DPF is based on an Executive Order whose persistence is politically conditioned.
From a risk perspective, a two-step approach is therefore advisable: first, primary reliance on the DPF for certified recipients; second, a prepared fallback architecture with SCCs plus supplementary measures in case the DPF is suspended or annulled. The same logic applies to the parallel EU-US Data Privacy Framework. A periodic review of the DPF certification of US recipients, a careful assessment of the processing scope (HR data, for example, are only covered upon adherence to the HR annex of the DPF) and a clear escalation chain are part of the standard approach for Swiss controllers with US suppliers.
SCCs, BCRs and Transfer Impact Assessment
Standard contractual clauses (SCCs) are the workhorse of international data transfers. The FDPIC has published its own SCCs and also accepts the EU SCCs provided a Swiss annex supplements the cantonal and national specifics (in particular FDPIC as supervisor, jurisdiction, applicable law). Binding corporate rules (BCRs) under Art. 16(2)(b) DSG are an alternative for groups with a global footprint; they must be approved by the FDPIC. Both instruments require a documented Transfer Impact Assessment that concretely analyses risks in the destination state (state-authority access rights, legal protection) and defines supplementary measures (encryption, pseudonymisation, contractual commitments).
EDPB Recommendation 01/2020 on supplementary measures should also be used in Switzerland as methodological guidance. It distinguishes four levels of protection: technical (encryption, pseudonymisation), contractual (transparency, push-back against authority requests), organisational (internal policies, training) and procedural measures (audit rights, escalation mechanisms). For sensitive data or large-scale processing, contractual guarantees alone are insufficient; the Schrems II judgment demands demonstrable technical effectiveness. The SIDD practice shows that, particularly for e-mail, collaboration and CRM solutions in US clouds, additional encryption layers are often the only legally sound solution.
FDPIC in Relation to EDPB, ICO and FTC
The FDPIC (seated in Bern) is the sole Swiss supervisory authority for data protection and is not a member of the European Data Protection Board (EDPB) but attends its plenary meetings in observer status. Established cooperation channels exist with the UK Information Commissioner's Office (ICO) and with the Irish DPC, also formalised through the Global Privacy Assembly. The US Federal Trade Commission (FTC) pursues a sectoral approach under Sec. 5 FTC Act ("unfair or deceptive acts") without a horizontal federal data protection statute; this produces enforcement gaps that continuously generate friction with the GDPR and the DSG. The fines under the GDPR regularly reach three-digit million amounts, while FTC settlements remain structurally below this level.
Leadership in the EDPB rotates; the Irish DPC is, owing to the European headquarters of the US tech groups, de facto the most influential supervisor. Swiss companies with an Irish EU establishment should be aware of this supervisory dynamic. In the area of cyber and security regulation, ENISA is growing in importance as the EU's technical centre of competence; in Switzerland this function is performed by the Federal Office for Cybersecurity (BACS). At the US-state level, new data protection acts are emerging (California CPRA, Virginia CDPA, Colorado CPA, Connecticut, Utah, Texas, Florida); for Swiss companies with US clientele a multi-state compliance strategy is required.
Tension between DSG, GDPR and the US CLOUD Act
The US Clarifying Lawful Overseas Use of Data Act (CLOUD Act, 2018) obliges US companies to hand over data to US authorities irrespective of the storage location. This creates a direct collision with Art. 271 Swiss Criminal Code (StGB) (acts on behalf of a foreign state), with Art. 16 DSG (cross-border disclosure) and with Art. 48 GDPR. Swiss controllers using US cloud providers must address the risk through encryption with customer-managed key management (Hold Your Own Key), through data localisation in Swiss regions and through contractual transparency duties. EU boutique providers and Swiss sovereignty offerings such as confidential compute from the hyperscalers reduce the residual risk but do not eliminate it entirely.
The Federal Supreme Court and the FDPIC have clarified in several decisions that Art. 271 StGB prohibits disclosure to foreign authorities outside the mutual-legal-assistance channel even where the cloud provider itself performs the disclosure. Contractual commitments of the provider to challenge authority requests and to inform the customer are therefore indispensable. A complementary data classification with clear processing prohibitions for sensitive data categories in US clouds (for example health data, lawyer-client privilege, banking secrecy under Art. 47 BankG) is current practice. For regulated financial institutions, FINMA additionally requires an outsourcing concept in line with FINMA Circular 2018/3.
Convention 108+, OECD and Global Standards
The modernised Council of Europe Convention 108+ (Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data) is the only legally binding multilateral data protection treaty open to global accession. Switzerland has ratified Convention 108+; it is substantively largely congruent with the DSG core principles. The OECD Privacy Guidelines (revised 2013) are not binding but shape international practice for cross-border data flows. Added to this are the APEC Cross-Border Privacy Rules System and increasingly bilateral adequacy decisions (Japan, South Korea, United Kingdom). For Swiss companies this entails a multi-layered compliance model: DSG as base, GDPR where there is EU exposure, sectoral requirements (FINMA, HIPAA for US health data) as overlay.
New international conventions continue to evolve in parallel. The Federal Council signed the Council of Europe AI Convention on 5 September 2024, the first internationally binding framework on AI, which defines requirements on transparency, oversight and legal remedy. Domestic implementation will shape the interface between AI regulation and the DSG processing principles. Added to this are the modernisation efforts around Convention 108+ and possible new adequacy decisions of the EU for further states, which will gradually broaden the circle of low-documentation transfers.
Operationalisation for Swiss Companies
Operationalisation requires three building blocks: first a complete records of processing activities (ROPA) under Art. 12 DSG that flags cross-border transfers; second a transfer matrix that documents per recipient the legal basis (adequacy, DPF, SCCs, BCRs) and the supplementary measures; third a clear responsibility structure between the Swiss Data Protection Advisor and the EU Representative. SIDD assumes mandates as Swiss DSG Data Protection Advisor, as External DPO under GDPR Art. 37 and as EU Representative under Art. 27 GDPR; the ISMS under ISO/IEC 27001 delivers the security evidence. The DSG pillar guide (German-language pillar) bundles the domestic perspective; the GDPR pillar guide the European one.
Complementarily, an annual transfer audit is advisable to verify the currency of DPF certifications, SCC versions, BCR approvals and supplementary technical measures. Supplier changes, group restructurings and new regulatory developments (for example new adequacy decisions or Schrems III) should be reflected through change management. A clear escalation chain between the Swiss Data Protection Advisor, the EU Representative and senior management secures the response capability. In international business, increasingly it is not the level of protection alone that determines business success, but the demonstrable robustness of the compliance architecture.
