SOVEREIGNTY LAW ATLAS — CH
Switzerland
The verdict.
FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04Switzerland offers a genuinely independent legal regime with EU adequacy — but a US-controlled provider in Zurich is still a US-controlled provider.
ATLAS RECOMMENDATION — DOCUMENTED CONTROL · Independent regime — local runtime, no overflow path. Seeded into the configurator; adjust anything.
The dossier.
SOURCES FOOTNOTED · EVIDENCE STATE LABELLEDDomains
D1 — Data residency & localization
The revised Federal Act on Data Protection (revFADP), in force September 2023, modernized Swiss law toward the GDPR model: cross-border disclosure requires an adequate protection level per the Federal Council's country list, or exceptions (consent, contract, safeguards).1 No localization mandate. The EU recognizes Swiss adequacy; the Swiss–US and UK–Swiss data frameworks are operational. (REPORTED)
D2 — AI-specific regulation
No AI statute. Switzerland signed the Council of Europe Framework Convention on AI in March 2025 (REPORTED); ratification and any implementing law were pending at capture. The Federal Council's stated approach is sectoral adaptation of existing law rather than a Swiss AI act.
D3 — Cloud & procurement sovereignty
No sovereign-cloud certification scheme. Federal cloud strategy relies on commercial providers under contract terms; cantonal and sectoral practice varies. There is no Swiss SecNumCloud or C5 equivalent.
D4 — Export & access
Switzerland sits outside the EU, Five Eyes, and the major access alliances — the basis of the "Swiss hosting" positioning. The caveat is structural: the CLOUD Act binds US-controlled entities wherever they operate, so Swiss location protects against Swiss-side and EU-side reach, not against US provider-level compulsion.
Extraterritorial exposure
Exposure is concentrated in provider control, not geography. A Swiss-controlled provider materially reduces US lawful-access exposure; a US-controlled provider in Switzerland reduces it not at all. US reference record deferred to Phase 2.
Disclaimer
This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied.
- Federal Act on Data Protection (revFADP), CC 2022/568 — Fedlex — fetch blocked by Fedlex HTML wrapper, cited to official source. (REPORTED) ↑
The instruments.
1 ON RECORD · 3 GAPSFederal Act on Data Protection (revFADP / nLPD), CC 2022/568
REPORTEDNo AI-specific statute; CoE AI Convention signed 2025-03 (reported), ratification pending
No sovereign-cloud certification scheme
US CLOUD Act / FISA 702 reference record deferred to Phase 2 (PRD §3.2)
This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.