Independent comparison · no paid rankings
Home / Blog / Compliance / Swiss host and GDPR: when must an EU transfer be governed?

Swiss host and GDPR: when must an EU transfer be governed?

Switzerland eases transfers through an adequacy decision, but hosting with Infomaniak or Hostpoint does not remove the duty to document every flow outside the EEA.

Hébergeurs.eu Editorial Team 3 min read Updated Nov 2, 2026

A French SME picks Swiss hosting for proximity, perceived neutrality, and documented datacenters. The DPO then reminds them Switzerland is not in the EU — and "friendly country" does not mean "no transfer to document."

Swiss providers such as Infomaniak or Hostpoint are credible for many francophone sites. GDPR compliance then rests on explicit transfer governance, not on border absence.

Transfer or not: reading GDPR correctly

For a controller established in the EU, entrusting personal data to a Swiss provider is a transfer to a third country (GDPR Chapter V).

Two myths persist:

  • "Switzerland has similar law, so no formalities." Wrong: lighter formalities ≠ no obligation.
  • "My visitors are French, so no transfer." Wrong: it is the processing location by the processor that counts.

The European Commission's adequacy decision (Switzerland) allows transfer without standard clauses to Switzerland, while the framework stays valid and the flow is identified.

SituationTypical framework
Prod hosting in CH, no other countryAdequacy + DPA + register
Backup copied to EU or USAdditional governed transfer
Third-party CDN / analyticsOther sub-processor, other analysis
Support from non-adequate countryClauses or supplementary measures

What the Swiss DPA must cover

Require from the provider:

  1. Contracting entity (CH).
  2. Processing description (hosting, email, backup).
  3. Sub-processor list and change notification.
  4. Documented security measures.
  5. Assistance for data subject rights and audits.

Cross-check your processing register and public privacy policy. If you process for clients, reflect the Swiss provider in your downstream DPA.

For Infomaniak specifically, see also Infomaniak and GDPR residency.

When adequacy is no longer enough

Common cases needing additional framework:

  • Provider's sub-processor in the US or India (support, monitoring).
  • Backup replication to a non-adequate region you chose.
  • Email or CRM added later outside Switzerland/EEA.
  • Legal change: watch Schrems developments and adequacy updates.

The guide Schrems II and hosting remains useful for method, even though Switzerland currently has its own adequacy decision.

The crux: the Swiss flag does not sign your transfer analysis

"Swiss hosting GDPR" pages imply magic equivalence. Auditors ask for a map, not a flag.

Decide and move forward without blind spots

  1. Confirm EU establishment and role (controller / processor).
  2. Sign the DPA with the chosen Swiss host.
  3. Map prod, email, backups, logs, third parties.
  4. Add clauses or measures for any link outside adequacy.
  5. Compare via the directory if strict EU constraint applies.

See transfers outside the EU for general framing.

Frequently asked questions

Does a Swiss host imply a transfer outside the EU?

Yes for a controller established in the EU. Adequacy eases the framework; DPA and documentation remain mandatory.

Is the adequacy decision enough alone?

No. It replaces SCCs to Switzerland under conditions, without removing register, DPA, and sub-processor analysis.

When are standard clauses still required?

Whenever a sub-processor processes outside Switzerland/EEA or a flow escapes adequacy.

Does it fit EU-only projects?

Often not without documented exception: Switzerland is outside the EEA. Prefer an EU host if the spec forbids it.


Before approving Switzerland, ask: which document proves only authorised flows leave the EEA?

HDS & compliance hosts

Filter European hosts by HDS, ISO and data residency.

Browse HDS hosts
Blog

Related reading

All articles →