Independent comparison · no paid rankings
Home / Blog / Swiss hosting: privacy does not remove the need for a clear contract
Guide

Swiss hosting: privacy does not remove the need for a clear contract

Outside the EU but close, Switzerland attracts with discretion and vendors like Infomaniak. Yet nLPD, transfers and host scope require the same contractual rigour as elsewhere.

4 min read Updated Jul 19, 2026

A Geneva firm promises clients "everything is in Switzerland." The audit finds backups listed in Germany, a US CDN and transactional email routed via a California SaaS. The white cross flag held for the WordPress site — not the full chain.

Switzerland remains attractive: stability, discretion, transparent vendors like Infomaniak, documented datacenters, and the nLPD framework (new Swiss data protection law). But privacy ≠ no contract. Outside the EU, transfers and subcontracting need the same discipline as Paris or Frankfurt.

Switzerland and the EU: adequacy, not fusion

The European Commission recognises adequate protection for transfers to Switzerland — provided you meet GDPR duties on the EU side: legal basis, informing data subjects, data processing agreement with host, register.

Watch points: nLPD is not GDPR word-for-word — align contractual clauses. Third-party services (analytics, payment) may sit outside CH. French HDS: Switzerland does not replace an HDS host for a French health record.

Reading a Swiss host: Infomaniak and beyond

Infomaniak illustrates the documented model: Swiss datacenters, public impact report, clear residency. Before generalising to "Switzerland":

QuestionWhy
Where are prod, staging, backups?A DE backup region changes the story
CDN included or third party?Edge outside CH possible
Support: data access?Admin from abroad to frame
Email, DNS, paymentOften outside web host

Ask for a diagram — not a "100% Swiss" sentence.

Marketing privacy vs operational reality

Switzerland sells institutional trust. It does not guarantee an unpatched WordPress, weak passwords, a vendor without ISO or data processing agreement, or absence of Cloud Act if a US third party reads your logs.

For Infomaniak documented ecology, see Infomaniak and ecology. For general compliance, cross GDPR, HDS, SecNumCloud.

When to choose Switzerland — and when to avoid

Good fit: Romandy or Swiss clients requiring CH residency; project where Infomaniak or documented Swiss cloud covers the full stack; wish to leave "US hyperscaler" talk without HDS.

Avoid: HDS or SecNumCloud France obligation; 100% metropolitan France audience without CH constraint; need for ANSSI-qualified cloud ecosystem.

For a Romandy SME selling in Switzerland and France, Switzerland can be a credible compromise: EU adequacy, low latency to Geneva and Lausanne, privacy narrative understood by local clients. Still verify your French-side duties — register, informing data subjects, DPO — remain covered.

Contract: clauses to reread

Demand an up-to-date subprocessor annex, not a "we respect privacy" page. Verify transfers outside Switzerland for backups, support and monitoring. Align nLPD clauses with your GDPR duties if you are an EU controller — the Swiss DPA model is not always identical to the French one. A serious Swiss host provides these documents without delay; a generic reseller promises them "after signing". Archive them: an EU client may request them during audit.

The climax: digital banking secrecy does not exist

Decide and move forward without blind spots

Map production, backups, CDN, email and analytics before signing — a diagram beats an oral promise. Sign a data processing agreement aligned nLPD/GDPR. Verify adequacy and EU data subject information. Test latency from your main market. Compare Infomaniak and alternatives via the directory.

Frequently asked questions

Is Switzerland GDPR-equivalent for EU clients?

EU adequacy for transfers, under conditions. Data processing agreement and documentation remain mandatory — adequacy does not replace contract.

Is Infomaniak enough for "Swiss data"?

Yes if full scope is Infomaniak in Switzerland. Verify CDN, backups and third parties — one out-of-scope flow changes the story.

Does Swiss hosting avoid Cloud Act?

Not if US third parties touch data. Audit full stack, not only web server.

When is Switzerland the right choice?

CH residency required, documented vendor — not to replace French HDS.


Next time a quote says "Swiss privacy", ask for the list of subcontractors outside Switzerland. That is where the promise is won or lost.

Compare European hosts

Filter by compliance, location and use case — then open the sheets to verify the real scope.

Browse the directory
Blog

Related reading

All articles →