Your website does not have to sit in Switzerland

Why a Swiss server location is not a legal must under Swiss data protection law, what Art. 16 revFADP and Annex 1 of the Data Protection Ordinance actually require, and the three cases where I point you to a Swiss provider instead.

located in FalkensteinGermany, EU
daily, 14 versionsBackup, two weeks back
every 5 minutesThe server checks itself

Does the website have to sit in Switzerland?

No. For the vast majority of Swiss businesses, a Swiss server location is not a legal requirement under data protection law. And so you can place that sentence straight away: my server sits with Hetzner in Falkenstein, Germany. I make money from it.

Disclosure I earn money on hosting (CHF 19 per month) and on maintenance (from CHF 79 per month), and both run on my own server in Germany. Anyone claiming a Swiss location is unnecessary is also selling themselves. So here is the counter-test: if you genuinely need a Swiss location, I will name Swiss providers instead of selling you my hosting. That costs me the subscription. I prefer that to a customer sitting on the wrong server who only finds out when somebody asks.

The recommendation I am arguing against usually sounds like this: the website has to be in Switzerland, otherwise data protection is not clean. It comes from someone you know, from an advisory conversation, or from a host selling Swiss data centres. It sounds careful and responsible. As a blanket rule it is still wrong.

What the law actually requires

The revised Swiss Data Protection Act (revFADP, known in Switzerland as revDSG) has applied since 1 September 2023. It does not ban hosting abroad, it attaches a condition to it.

Art. 16 para. 1 revFADP says that personal data may be disclosed abroad if the Federal Council has found that the legislation of the country concerned guarantees adequate protection. Where to read that finding is set out in Art. 8 para. 1 of the Data Protection Ordinance: the countries, territories and sectors with adequate data protection are listed in Annex 1 to that ordinance.

Germany is listed in Annex 1, alongside all 27 EU states plus Iceland, Liechtenstein and Norway. The list has 44 entries in total, including a number of other countries and territories, and it is ordered alphabetically, so the sequence says nothing about the quality of protection. Its current version comes from the ordinance of 14 August 2024, in force since 15 September 2024 (AS 2024 435). For hosting in Germany that means, concretely: no standard data protection clauses needed, no specific safeguards, no consent from your visitors. The transfer is permitted by law under Art. 16 para. 1 revFADP.

Two things you do have to do. The first is inform people. Art. 19 para. 4 revFADP requires you to tell the data subject which country the data goes to. That is one line in your privacy policy, not a server move.

The second gets overlooked more often: hosting is processing on your behalf. Under Art. 9 revFADP you may hand processing to a third party, but only by contract or under the law, only to the extent that the data is processed as you would be allowed to process it yourself, and only where no statutory or contractual duty of confidentiality stands in the way. Para. 2 says explicitly that you must satisfy yourself that the processor is able to guarantee data security. In practice that means a contract with the host, not just a sentence in the privacy policy. Ask your host for its data processing agreement; the larger providers have one ready.

I am not a lawyer. What you read here is the practical view of a web developer who runs Swiss SME sites. For a binding assessment, a sensitive case belongs with a specialist or with the Federal Data Protection and Information Commissioner (FDPIC). You can look up both sources yourself: the revFADP under SR 235.1, the ordinance with Annex 1 under SR 235.11, both on fedlex.admin.ch.

What a Swiss location changes, and what it does not

To keep the argument fair: a Swiss location is not pointless. Three things about it are real.

  • Jurisdiction and contract law. A Swiss provider can be held to account under Swiss law. If a contract turns into a dispute, that is simpler than going after a foreign company.
  • Authority access. Which authority can reach data under which conditions follows the law where the server stands. If you want that circle kept narrow, a Swiss location involves fewer parties.

Now the other half, the part that rarely comes up in a sales conversation.

A Swiss location does not make your website faster. Load time is decided by how the site is built, by image sizes, by third-party scripts and by the server configuration, not by a few hundred kilometres of cable. I deliberately quote no millisecond figures here, because I have no measurement of my own that would carry a clean Switzerland-versus-Germany comparison. If somebody presents you with such numbers, ask where, when and with what they measured.

A Swiss location does not make your website safer either. A compromised WordPress site is just as compromised in Zurich as in Falkenstein. The break-in comes through an outdated extension or a weak password, not across a national border. What protects a site is updates, tested backups and someone paying attention. What that costs and what it covers is in What does website maintenance cost in Switzerland?.

When you do need a Swiss location after all

Three cases still speak for a Swiss location. In the first I actively advise against hosting with me; in the other two, you or your client decide.

Professional secrecy. Art. 321 of the Swiss Criminal Code makes breaching professional secrecy a criminal offence, for lawyers, notaries, doctors, psychologists, pharmacists and other professions, and explicitly for their auxiliary staff as well. In data protection terms the case hangs on Art. 9 para. 1 lit. b revFADP: handing processing to a processor is only permitted where no statutory or contractual duty of confidentiality stands in the way. Legally, the country is not really the crux here either; what matters is who has access to which data and what is secured by contract. In practice, though, the conversation with your supervisory body, your association and your clients is considerably shorter with a Swiss location, and that effort is not something I can take off your hands. As long as the website only carries a contact form with a name and a message, this is usually uncritical. Once client or patient data lives in the system, through a protected area or a booking form that asks what the appointment is about, the question belongs with a specialist before it belongs with the technology.

A contractual requirement. Some clients specify the location, public bodies for instance, or larger companies in their purchasing terms. At that point it no longer matters whether the requirement is technically necessary. It is in the contract, so it applies.

Your own explicit wish. Part of your clientele simply wants it that way. That is not a legal argument, but it is a legitimate one. If that is what you want, that is reason enough, and I am not going to talk you out of it.

What happens in those cases: I tell you before you order, and I name Swiss providers that fit your situation. I have no partnership with any of them and take no commission, which also means I cannot promise you any particular terms. I will still build the website; the hosting simply will not run through me.

The three questions that matter more than the country

When you assess a provider, these three questions will tell you more than the location will. I am answering them for myself right here, including the places where I come off worse than others.

Where do the backups live, and how many versions are kept? With me, backups run daily and fourteen versions stay available, so two weeks back. Now the uncomfortable half: those versions sit on the same machine as the website. There is no second backup target that gets written automatically. What there is, is a copy on my own computer, which I fetch by hand and restore as a test so I know it holds. For the common case, where a change breaks something or a file goes missing, the backup on the machine is plenty. For the rare total loss of the machine, the copy on my computer is what remains, and how old it is when that happens depends on when I last fetched it. A scheduled second target would be better on this point. If somebody offers you a geographically separate target that gets written automatically, that is more than what I have, and I would rather say so myself than have you find out later.

Who notices an outage, and how? With me the server checks itself every five minutes and mails me as soon as the site fails to answer twice in a row. That approach has a built-in blind spot: if the machine goes down entirely, a check from the inside is exactly what will not notice. I have no external watchdog service. That is why I quote no availability figure either. A number I have not measured myself would be a claim, and this market has plenty of those.

Who answers when something goes wrong, and how quickly? With me: I do, within one business day (Mon to Fri). No queue, no ticket number, but no nights or weekends on call either. If you need that, you need a different provider, and that has nothing to do with the country.

Those three answers decide day to day whether your website is up and how fast it comes back. The server location does not.

What goes into your privacy policy when the server is abroad

Short and concrete, four items:

  • Who hosts. The company and its seat, in my case Hetzner Online GmbH, seated in Gunzenhausen, Germany.
  • Which country. Germany. Art. 19 para. 4 revFADP requires you to name it.
  • What for. Running and serving the website, plus the usual server log files.
  • On what basis. Germany is listed in Annex 1 of the Data Protection Ordinance, so the transfer is permitted under Art. 16 para. 1 revFADP. You do not need standard data protection clauses for this.

That belongs in the section on disclosure abroad, right after the third-party services. How the policy is built up and what else goes into it is in Privacy policy for Swiss websites. Whether you also need a banner is a completely separate question, which I took apart in Cookie banner Switzerland. The server location does not trigger one either way.

This belongs to the disclosure as well: I do not write legal texts. What I give you is the technical list, meaning which service runs where and which data flows where. From that you fill in a generator correctly or have the text reviewed.

And for an online shop?

With a shop the question shifts, so this is only a pointer. There it is no longer about server log files but about customer and order data, and with a rented platform that data does not sit with your host at all, it sits with the platform provider. The location question then looks entirely different from an installation you run yourself. I broke that down in WooCommerce or Shopify so it does not have to be repeated here.

My conclusion

A Swiss server location is not a legal must: Germany is listed in Annex 1 of the Data Protection Ordinance, which makes the transfer permitted under Art. 16 para. 1 revFADP. What the law requires is transparency, meaning the host and the country stated in your privacy policy. What keeps your website running day to day is backups, an outage alert and someone who answers. And if professional secrecy, a contract or simply your own preference speaks for Switzerland, that is a good reason, and I will say so even when it costs me a subscription.

If you do not know where your data sits today, I will go and look. All I need is your web address and a few minutes, and afterwards I will tell you which host in which country serves your site and whether your privacy policy says the right thing about it. One caveat belongs with that: if an intermediary service sits in front, speeding the site up or shielding it, all you see from outside is that service; then I need a look inside the hosting account. No sales pressure, a reply within one business day (Mon to Fri). What my own offer covers is on Hosting and Maintenance.

Common questions

Does my website have to be hosted in Switzerland?

For the vast majority of businesses, no. Art. 16 para. 1 revFADP allows disclosure abroad where the Federal Council has found that the destination country provides adequate protection. Under Art. 8 para. 1 of the Data Protection Ordinance those countries are listed in its Annex 1, and Germany is listed there alongside all 27 EU states. What is mandatory is not the location, but telling people about it in your privacy policy and having a processing agreement with your host under Art. 9 revFADP.

Where is your server?

In a data centre in Falkenstein, Germany, operated by Hetzner. So in the EU, not in Switzerland. I say this openly because I earn money on hosting and maintenance, and you should read this article with that in mind.

What goes into my privacy policy if the server is abroad?

Four things: who hosts, in which country, for what purpose, and on what legal basis the transfer is permitted. Art. 19 para. 4 revFADP explicitly requires you to name the country. With a server in Germany you do not need standard data protection clauses, because Germany is listed in Annex 1 of the Data Protection Ordinance. Separate from the text, but just as necessary: the processing agreement with your host.

What happens if I want to move to another host later?

You get a complete backup with database and files plus access to every login, and we coordinate the switch with the new host. No lock-in beyond the twelve-month minimum term of the maintenance subscription, no migration fee. That matters more to me than a subscription that only survives because leaving is a hassle.

Where do the backups of your customer sites live?

Backed up daily, fourteen versions kept, on the same machine as the website. There is no second target that gets written automatically; I pull the copy to my own computer by hand. A provider offering a scheduled, geographically separate target is offering more on this specific point.

Is a Swiss server safer than a German one?

Not because of the location. A break-in comes through an outdated extension or a weak password, not across a national border. Location is a legal and contractual question, not a security one.

A question about your web project?

Write to me

Related guides