Independent comparison · no paid rankings
Home / Blog / Compliance / Infomaniak and GDPR residency: which data still needs mapping?

Infomaniak and GDPR residency: which data still needs mapping?

Infomaniak hosts in Switzerland with a strong GDPR story, but residency does not stop at the Geneva datacenter. Email, CDN, analytics, and backups all need an explicit data map.

Hébergeurs.eu Editorial Team 4 min read Updated Oct 24, 2026

An agency migrates twenty WordPress sites to Infomaniak relying on "Swiss hosting, GDPR compliant." Internal audit then asks where contact forms, access logs, nightly backups, and staff webmail actually flow. Nobody traced anything beyond datacenter D3.

Infomaniak is one of the most transparent francophone providers on residency and compliance. The trap is not lack of seriousness: it is confusing marketing location with a complete GDPR map.

What "Swiss residency" covers at Infomaniak

Infomaniak runs documented datacenters in Switzerland (Geneva, etc.), with an energy mix and governance clearly described in its public profile. For a site or app on that infrastructure, primary compute and storage are genuinely Swiss.

But GDPR cares about every processing of personal data: collection, access, copying, backup, support, logs, export.

LayerQuestion to askCommon risk
Web productionWhich offer, which DC site?Mixing shared hosting with external services
Email / kSuiteWhere are messages, contacts, attachments indexed?Forgetting team webmail
BackupsFrequency, encryption, second site?Undocumented copy
Logs & monitoringWho reads IPs, user agents, PHP errors?External analytics added later
Support & adminTickets, temporary access, sessionsProvider access not in register
Staging / devProd copies with real dataPII leak outside framework

Switzerland, the EU, and transfers: what to document

For a controller established in the EU, hosting with Infomaniak involves a transfer to a third country in the strict sense — even though Switzerland benefits from an adequacy decision easing that transfer.

In practice:

  1. Sign Infomaniak's DPA and review listed sub-processors.
  2. Update your processing register: purpose, data categories, retention.
  3. Identify replicas: backup, CDN, out-of-band support.
  4. Document access: who at Infomaniak or on your side can read what.

That framework works for many projects — unless you then add US Google Analytics, external SMTP, or a plugin syncing contacts to an American CRM without legal basis.

Infomaniak controls its infrastructure perimeter well. It does not control your WordPress stack or forgotten integrations.

The most frequent blind spots

External CDN or proxy. Once an asset goes through a non-Swiss edge network, the map changes. Check whether Infomaniak alone serves traffic or you added Cloudflare, Bunny, etc.

Transactional email. Forms via SendGrid, Mailgun, or Brevo: another sub-processor, another DPA.

Pre-production environments. A poorly anonymised copy is a violation waiting to happen.

Logs kept too long. Swiss location does not fix excessive retention or unjustified IPs.

Your own SaaS sub-processors. If you use Infomaniak as infra for your customers, you remain responsible for the downstream chain.

For general framing, see GDPR, HDS, SecNumCloud to separate real obligations from over-specification.

The crux: the Swiss map is not your register

That is what "GDPR compliant" quotes gloss over: compliance is a flow graph, not a single country.

Decide and move forward without blind spots

  1. Draw the flow from collection to archive (production, email, backup, logs, support).
  2. Request the DPA and Infomaniak sub-processor list for your plan.
  3. Flag every exit from Switzerland/EEA and justify it (adequacy, clauses, other basis).
  4. Anonymise staging or isolate it contractually.
  5. Compare via the directory if your constraint is strict EU rather than governed Switzerland.

Read the Infomaniak profile, then validate product by product in the panel.

Frequently asked questions

Does Infomaniak guarantee that all data stays in Switzerland?

Documented datacenters are Swiss, but effective residency depends on enabled services and copies. Trace every flow, not just the web server.

Is Switzerland equivalent to GDPR for an EU customer?

Switzerland has EU adequacy for transfers from the EU, subject to DPA and sub-processors. Mapping and documentation remain mandatory.

Which Infomaniak data do teams most often fail to map?

Application logs, email metadata, support tickets, staging, third-party monitoring, and replicated backups.

Does Infomaniak fit if I must stay in the EU only?

Infomaniak suits many GDPR projects with a governed transfer to Switzerland; strict "EU only" requires verifying contract, DPA, and no replication outside the EEA.


Before ticking "residency OK," ask: if the DPA or CNIL asked for a diagram tomorrow, could I draw it without improvising?

See the Infomaniak sheet

Independent scores, plans, pros/cons and alternatives to Infomaniak.

Open the Infomaniak sheet
Blog

Related reading

All articles →