BIG BOX Hosting Locations Switzerland № 04.02

Switzerland
— outside the EU, stronger by design.

Non-EU adequacy-decision country with the revised Federal Act on Data Protection (revFADP) in force since 1 September 2023. The strongest national privacy posture available in Europe outside the EU framework, the deepest legal-cultural commitment to resisting compelled foreign disclosure, and an infrastructure market mature enough to deliver Frankfurt-grade hosting at premium-tier pricing.

01  /  The context

Why Switzerland.

Non-EU adequacy-decision country with the revised Federal Act on Data Protection (revFADP) in force since 1 September 2023.

Privacy law in force
1 Sept 2023
revFADP — revised Federal Act on Data Protection
EU adequacy decision
14 Aug 2024
Swiss-US Data Privacy Framework recognised
Authority
FDPIC
Federal Data Protection and Information Commissioner
EU member?
No
but Convention 108 + adequacy decision

Switzerland is the cleanest privacy-first option in Europe and one of the smaller subset of countries that genuinely treat data protection as a structural matter rather than a checkbox. The revised Federal Act on Data Protection (revFADP) entered into force on 1 September 2023, modernising a 1992 law that had become inadequate for contemporary technology and aligning Swiss requirements with the EU GDPR while retaining what the FDPIC calls a "Swiss finish" — provisions that go beyond GDPR in several specific areas.

The most consequential of these provisions are the stricter sanctions for individual decision-makers. Where GDPR fines fall on the entity, the revFADP allows criminal sanctions against responsible individuals for specific violations — wilful breach of duty, processing without legal basis, refusal to provide information. The fines per individual reach CHF 250,000. For a director who has personally signed off on a non-compliant processing operation, this is a meaningfully different risk posture than what GDPR alone produces in EU jurisdictions, and it is the reason corporate decision-makers across Europe pay attention to Swiss requirements when their operations touch Swiss residents.

The other defining feature is the long Swiss tradition of resisting compelled foreign disclosure. The country's banking-secrecy regime, much weakened by international AML and tax-information-sharing reforms since 2014, remains culturally and procedurally influential. Swiss courts apply Swiss law to access requests, and the Swiss legal community has decades of experience pushing back on extraterritorial demands from foreign jurisdictions — particularly from the United States, where the political asymmetry between Swiss banks and the U.S. Department of Justice produced the practical playbook for handling cross-border legal pressure. For email infrastructure that handles sensitive personal data, this institutional muscle memory is real value even when the specific legal pathway is GDPR-aligned rather than banking-secrecy.

─────────────────────────────────────────────────────────────────────────
02b  /  The two statutes that govern

Article 47 BankG and the 2023 FADP.

Two statutes do the legal work in Switzerland. Article 47 of the Banking Act is the iconic one. The 2023 revision of the Federal Act on Data Protection is the operational one. Most marketing pages lead with the iconic statute and skip the operational one. The buyers who read both reach a more accurate picture of what Switzerland actually offers.

Article 47 of the Swiss Banking Act (Bankengesetz) is the legal anchor for Swiss banking secrecy and the most-cited statute in Swiss data sovereignty marketing. The statute is older and narrower than the marketing implies. Article 47 BankG criminalises the unauthorised disclosure of customer information by bank employees, with prison sentences up to three years and fines under the BankG enforcement schedule. The statute applies to bank employees specifically — it does not apply to non-bank service providers automatically, and it has been progressively limited by AEoI agreements (the Swiss CRS implementation), the FATCA intergovernmental agreement signed in 2013, and the OECD Multilateral Convention on Mutual Administrative Assistance.

The Federal Act on Data Protection (FADP) revised version came into force on 1 September 2023, replacing the 1992 statute. The new FADP is broadly aligned with GDPR through the Swiss-EU adequacy framework — Switzerland is recognised as providing an adequate level of data protection by the European Commission, which means EU data can flow to Switzerland without additional transfer mechanisms. The FADP applies to all data processing on Swiss soil including hosted data, with criminal penalties for serious violations and a Federal Data Protection and Information Commissioner (FDPIC) as supervisory authority. For data hosting purposes, the FADP is the operational statute. Article 47 BankG is the iconic statute that most marketing pages lead with, but the FADP is what actually governs day-to-day data handling.

The combination matters in 2026 because Switzerland sits outside the EU regulatory frame while maintaining adequacy, which produces a different disclosure profile than EU member states. EU-internal cooperation regulations do not directly apply to Switzerland. MLAT requests go through Swiss federal channels with longer typical response times — 9 to 14 months in our experience — and the Swiss Federal Office of Justice has discretion to refuse requests that contradict Swiss public order. The FADP also includes a notification right: if data subjects' data is requested for legal or administrative proceedings outside Switzerland, the data controller must consider whether to notify the data subjects, with specific carve-outs for criminal investigation. The combination of these provisions is what produces the reputation Switzerland has — not the iconic banking secrecy alone, but the layered statutory and procedural protection.

─────────────────────────────────────────────────────────────────────────
03  /  The infrastructure

What we operate here.

Beneath the legal layer sits the operational one. The Zurich-area colocation specification, low-latency routes via SwissIX and CIXP, and the FDPIC audit cadence — documented to the level a Swiss-regulated financial-services compliance team will request.

Facility
  • Facility: Tier III, Zurich metro area
  • Power: 2N redundancy, mixed grid
  • Cooling: free cooling 8 months/year
  • Square metres: 2,400 white space
  • Floor: raised, vibration damped
  • Cabinet density: up to 15 kW per rack
  • Physical security: mantrap + biometric
  • Provisioning lead: 2-5 business days
Network
  • Carriers: Swisscom, Sunrise, Init7, Salt
  • Internet exchange: SwissIX, CIXP
  • Peering: DE-CIX FRA via direct lines
  • Transit providers: Init7, Cogent, Telia
  • IPv4 capacity: /24 PI assignments standard
  • IPv6 capacity: /29 prefix, /64 per server
  • Backbone: 10 Gbps ZRH ↔ FRA
  • Latency to FRA: 18-24 ms
Legal & operational
  • Authority: FDPIC
  • DPO requirement: per revFADP Article 10
  • Breach notification: without undue delay
  • Individual fines: up to CHF 250K
  • MLAT process: via Federal Office of Justice
  • Bank framework: Article 47 BA
  • Tax residency: non-EU
  • Currency: CHF (we invoice EUR)
─────────────────────────────────────────────────────────────────────────
04  /  The fit

Who picks Switzerland.

The customer profiles where Switzerland is the strongest fit in our portfolio. The non-EU adequacy profile plus the revFADP regime suits financial-services and high-net-worth-facing operations that need a non-EU corporate counterparty without losing transfer mechanism viability. The call ends with another jurisdiction in roughly one of five intakes — we say so when it does.

  • Senders handling sensitive personal data — health, finance, legal — where the additional revFADP protections produce meaningful additional defensibility.
  • Workloads where non-EU jurisdiction is a feature rather than a constraint — bilateral disputes, sanctions-adjacent industries, scenarios where EU mutual-recognition would expose the operation rather than protect it.
  • Operations whose threat model includes extraterritorial pressure from foreign jurisdictions and who benefit from the Swiss legal community's institutional experience pushing back on such pressure.
  • Senders whose buyers explicitly require Swiss hosting (some Swiss banks, regulated industries, and government-adjacent customers prefer or require Swiss data residency for procurement reasons).

Two of the four bullets — sensitive personal data and Swiss-required buyer profiles — overlap with wealth management and private banking workloads. The financial services vertical brief walks through the BankG Article 47 framework and the procurement scenarios where Switzerland is the structurally correct answer rather than the perceived default.

─────────────────────────────────────────────────────────────────────────
05  /  Common questions

Switzerland, specifically.

Questions specific to Switzerland — revFADP since September 2023, the non-EU adequacy position, the Swiss corporate counterparty model. The main FAQ covers the cross-jurisdiction topics.

01 How is Switzerland different from EU jurisdictions for our purposes? +
Two ways that matter operationally. First, the revFADP imposes individual criminal sanctions for specific violations — fines up to CHF 250,000 against responsible decision-makers for wilful breach. This shifts the personal risk calculus for directors and DPOs in a way pure GDPR does not. Second, Switzerland's legal culture has a deeper institutional history of resisting compelled foreign disclosure than most EU countries, partly because of the post-2014 banking-secrecy reform process which forced Swiss courts and lawyers to develop sophisticated procedural approaches to cross-border information requests. For everyday compliance the two regimes are substantially equivalent (and the EU adequacy decision confirms this); for adversarial scenarios the Swiss approach has additional muscle memory.
02 Is the post-2018 weakening of Swiss banking secrecy relevant to our hosting? +
Less than people think. The reforms targeted the specific banking-secrecy provisions of Article 47 of the Banking Act in ways that affected how Swiss banks could resist tax-related information requests. They did not affect the broader Swiss procedural framework around lawful access — Swiss courts still apply Swiss law to access requests, the FDPIC still supervises data protection, and the Federal Office of Justice still handles MLAT processes through procedurally rigorous channels. For our hosting, the practical effect is that the secrecy framework around banking is narrower than it was, but the data-protection framework is stronger than it was (revFADP being a major modernisation). The net effect for non-banking workloads is positive.
03 Pricing — Switzerland is the most expensive of your locations. Why? +
Honestly: facility costs are higher (Swiss labour, real estate, energy), import duty applies to non-EU hardware shipments which adds to capex, and the operational overhead is meaningfully higher (Swiss compliance, FDPIC reporting, the revFADP-specific obligations). We pass these through transparently rather than absorbing them — the result is roughly 20% above our Luxembourg pricing for equivalent specifications. For workloads where Swiss jurisdiction is a feature, the premium is usually small relative to the value. For workloads where Switzerland is being chosen on inertia, we will tell you that one of our other jurisdictions is probably the better fit.
04 Does the August 2024 Swiss-US Data Privacy Framework affect anything for us? +
Marginally and as a positive. The framework simplifies the analysis when Swiss-hosted data needs to flow to U.S. recipients certified under the framework — typically vendors like analytics platforms, payment processors, or third-party tools your application uses. The framework provides an adequate-protection finding for those certified flows. For data that stays on our infrastructure and does not flow to U.S. recipients, the framework does not change anything operationally. For customers whose architecture deliberately avoids U.S. flows, neither does it apply.
05 Can we contractually require Swiss-only processing? +
Yes. The default for Switzerland-tier customers is Swiss-only processing — your data stays on Swiss hardware operated by us, and operational replication does not cross the border. Some Enterprise customers add explicit contractual clauses requiring this and forbidding even our internal management traffic from crossing borders for the workload; we accept those clauses and adjust the operational tooling accordingly. The pricing impact is small (maybe 5-10% on the overall engagement) because the technical changes are modest.
─────────────────────────────────────────────────────────────────────────
07  /  What Switzerland doesn't protect against

Three gaps in the jurisdictional posture.

The honest counterweight. Switzerland is among the strongest jurisdictions for specific exposure profiles and middling for others. The list below is what we tell prospects on the discovery call when they ask if Switzerland fits their situation.

Three things Switzerland does not protect against. The first is data outside the scope of the bank-customer relationship. Article 47 BankG protects bank-acquired customer information specifically. Hosting provider relationships fall under the FADP, which protects but does not provide the same iconic-strength carve-outs that the BankG statute does. Buyers expecting BankG-grade protection for their generic hosted data are reading the marketing copy more generously than the statute supports.

The second is high-cost basis. Switzerland is the most expensive jurisdiction in our network, with bare-metal pricing roughly 30-40 percent higher than Luxembourg or Slovenia, driven by data centre real estate costs, energy prices, and a labour market where senior infrastructure engineers earn 25 percent more than the EU baseline. Buyers selecting Switzerland purely on cost grounds end up surprised by the quote. We tell them upfront during the discovery call that Switzerland is the premium tier of our network.

The third is no constitutional press freedom carve-out. Switzerland's free expression provisions are constitutional under Article 16 of the Federal Constitution, but they follow a Continental civil-law approach without the IMMI-grade or Tryckfrihetsförordningen anchors of Iceland and Sweden. Investigative journalism gets standard protection. Buyers seeking jurisdiction-grade press freedom should pair Switzerland with Iceland or Sweden rather than select Switzerland as the press freedom answer. Switzerland is the secrecy answer, not the press freedom answer.

─────────────────────────────────────────────────────────────────────────
06  /  Other jurisdictions

Or pick another one.

Five jurisdictions in the footprint. Each fits a different threat model, audience geography and procurement constraint — the table compares Switzerland to the other four on the axes that drive most location decisions.

─────────────────────────────────────────────────────────────────────────

Pick Switzerland, or pick another.

Switzerland is the non-EU jurisdiction in our footprint with adequacy and the strongest constitutional privacy posture (Article 13 plus the revFADP that took effect September 2023). Customers who need a non-EU corporate counterparty for tax-residency, contractual or sovereignty reasons — and customers whose threat model includes hostile state actors targeting EU member states specifically — find Switzerland the most defensible answer. The trade-off is that Swiss labour and infrastructure costs sit above the EU median; the price band reflects this. We are upfront about it on the call.