Cross-Border Data Transfer
Federal Act on Data Protection — cross-border disclosure of personal data
Switzerland · September 1, 2023
Art. 16 permits disclosure abroad only where the destination state guarantees adequate protection — and Switzerland maintains its OWN adequacy list, in Annex 1 to the Data Protection Ordinance, decided by the Federal Council. It largely overlaps with the EU's but is not identical and does not update in lockstep, so a controller subject to both regimes cannot assume an EU adequacy decision carries over. Where the destination is not listed, Art. 16(2) allows safeguards — standard clauses approved or recognised by the FDPIC, binding corporate rules, a treaty, or specific contractual clauses notified in advance to the FDPIC — and Art. 17 supplies narrow derogations, including disclosure necessary to establish, exercise, or enforce legal rights before a foreign court or, under the revised Act, another competent foreign authority. Businesses relying on the EU SCCs for Swiss data typically need the FDPIC's recognised adaptations rather than the EU text as-is.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.