← SOVEREIGNTY LAW ATLAS

SOVEREIGNTY LAW ATLAS — CH

Switzerland

TIER DEMO · STATUS PUBLISHED · LAST FULL REVIEW 2026-08-04 · 1 INSTRUMENTS ON RECORD

The verdict.

FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04
Data residency & localizationD1 — WHERE DATA MUST LIVE Transfer controls not localizationREPORTED
AI-specific regulationD2 — AI ACTS & REGISTRATION DUTIES No instrumentVERIFIED ABSENCE
Cloud & procurement sovereigntyD3 — CERTIFICATION & MANDATES No national schemeVERIFIED ABSENCE
Export & access lawsD4 — EXTRATERRITORIAL REACH Neutral haven reputationJUDGMENT
Instruments on record 1
Last full review 2026-08-04
Status PUBLISHED
For a buyer

Switzerland offers a genuinely independent legal regime with EU adequacy — but a US-controlled provider in Zurich is still a US-controlled provider.

Configure your SovereigntyBox for Switzerland →

ATLAS RECOMMENDATION — DOCUMENTED CONTROL · Independent regime — local runtime, no overflow path. Seeded into the configurator; adjust anything.

The dossier.

SOURCES FOOTNOTED · EVIDENCE STATE LABELLED

Domains

D1 — Data residency & localization

The revised Federal Act on Data Protection (revFADP), in force September 2023, modernized Swiss law toward the GDPR model: cross-border disclosure requires an adequate protection level per the Federal Council's country list, or exceptions (consent, contract, safeguards).1 No localization mandate. The EU recognizes Swiss adequacy; the Swiss–US and UK–Swiss data frameworks are operational. (REPORTED)

D2 — AI-specific regulation

No AI statute. Switzerland signed the Council of Europe Framework Convention on AI in March 2025 (REPORTED); ratification and any implementing law were pending at capture. The Federal Council's stated approach is sectoral adaptation of existing law rather than a Swiss AI act.

D3 — Cloud & procurement sovereignty

No sovereign-cloud certification scheme. Federal cloud strategy relies on commercial providers under contract terms; cantonal and sectoral practice varies. There is no Swiss SecNumCloud or C5 equivalent.

D4 — Export & access

Switzerland sits outside the EU, Five Eyes, and the major access alliances — the basis of the "Swiss hosting" positioning. The caveat is structural: the CLOUD Act binds US-controlled entities wherever they operate, so Swiss location protects against Swiss-side and EU-side reach, not against US provider-level compulsion.

Extraterritorial exposure

Exposure is concentrated in provider control, not geography. A Swiss-controlled provider materially reduces US lawful-access exposure; a US-controlled provider in Switzerland reduces it not at all. US reference record deferred to Phase 2.

Disclaimer

This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied.

  1. Federal Act on Data Protection (revFADP), CC 2022/568 — Fedlex — fetch blocked by Fedlex HTML wrapper, cited to official source. (REPORTED)

The instruments.

1 ON RECORD · 3 GAPS

Federal Act on Data Protection (revFADP / nLPD), CC 2022/568

REPORTED
TYPE STATUTESTATUS IN-FORCEENACTED 2020-09-25 · IN FORCE 2023-09-01
AuthorityFedlex
Evidencefetch-blocked — Fedlex serves HTML wrapper to scripted fetch (2026-08-04)
RAGnot-submitted
GAP — D2 · VERIFIED 2026-08-04VERIFIED ABSENCE

No AI-specific statute; CoE AI Convention signed 2025-03 (reported), ratification pending

GAP — D3 · VERIFIED 2026-08-04VERIFIED ABSENCE

No sovereign-cloud certification scheme

GAP — D4 · VERIFIED 2026-08-04VERIFIED ABSENCE

US CLOUD Act / FISA 702 reference record deferred to Phase 2 (PRD §3.2)

This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.

SBX CONCIERGEnothing leaves this page