Skip to content
Swiss FADP

Cross-Border Data Transfers Under Swiss Law

6 min readUpdated 22 July 2026

The revised Swiss FADP regulates transfers of personal data outside Switzerland similarly to GDPR — but with a Swiss-specific framework, a separate adequacy list, and distinct transfer mechanisms. If you transfer data out of Switzerland, this article explains what the law requires.


The Core Rule

Under FADP Article 16, personal data may only be transferred to a foreign country if that country provides an adequate level of protection — or if an appropriate safeguard is in place.

Transfers without an adequate protection level and without appropriate safeguards are prohibited. This mirrors the GDPR Chapter V structure but runs on Switzerland's own regulatory framework.


The Swiss Adequacy List

The Swiss Federal Council maintains its own list of countries with an adequate level of data protection. This list is independent of the EU's adequacy decisions — some countries are on one list but not the other.

Countries on the Swiss adequacy list (key examples):

  • All EU/EEA member states
  • United Kingdom
  • Canada (commercial organisations)
  • Japan
  • Israel
  • Argentina
  • Uruguay
  • New Zealand
  • South Korea
  • Andorra, Guernsey, Isle of Man, Jersey, Faroe Islands

The United States: The US is not on the Swiss Federal Council's standard adequacy list. Transfers to the US require a transfer mechanism unless the recipient is certified under the Swiss-US Data Privacy Framework (DPF). Switzerland has published its own recognition of the DPF — Swiss-certified US companies can receive Swiss data on this basis.

Important: The EU adequacy list and the Swiss adequacy list are not identical. Always check the Swiss list, not just the EU list, for Swiss-to-country transfers.


Transfer Mechanisms When No Adequacy

If the destination country is not on the Swiss adequacy list and the recipient is not DPF-certified, you need an alternative safeguard.

Standard Data Protection Clauses (Swiss SCCs)

The FDPIC approves Standard Data Protection Clauses for international transfers. These are broadly equivalent to EU SCCs but Swiss-specific. They bind the data importer to FADP-equivalent protections and provide an enforcement mechanism for data subjects.

Swiss SCCs are available from the FDPIC website. Execute the appropriate module based on the transfer relationship (controller-to-controller, controller-to-processor, processor-to-processor).

Relationship to EU SCCs: If you are running GDPR-compliant transfers using EU SCCs for the same vendor, you may need to additionally execute Swiss SCCs (or Swiss-specific addenda) to cover the FADP transfer separately. Some major vendors provide combined EU/Swiss SCC documents. Check with your vendor.

Binding Corporate Rules

BCRs allow intra-group transfers for multinational organisations. They require FDPIC approval and are practical only for larger corporate groups.

Derogations (Article 17)

Limited exceptions apply for:

  • Explicit consent of the data subject for a specific transfer
  • Contract performance (the transfer is necessary to perform a contract with the data subject)
  • Compelling legitimate interests (overriding the interests of the affected individuals, only where no other transfer mechanism is available)
  • Vital interests
  • Public interest established by law

These derogations are narrow and cannot substitute for SCCs as a general mechanism for systematic transfers. They apply to occasional, specific transfers only.


Swiss-to-EU Transfers: The Adequacy Decision

The EU has granted Switzerland an adequacy decision — meaning transfers of personal data from the EU to Switzerland are lawful under GDPR without additional mechanisms. Swiss data is treated as adequately protected from the EU's perspective.

This adequacy decision applies in one direction (EU → Switzerland). For Switzerland → EU transfers, the FADP applies, but since EU/EEA countries are on the Swiss adequacy list, no additional mechanism is needed for those transfers either.


Switzerland → US Transfers: The DPF

Switzerland has recognised the EU-US Data Privacy Framework (with Swiss-specific modifications under the "Swiss-US DPF"). US companies can self-certify under the Swiss-US DPF to receive transfers from Switzerland.

Before relying on DPF certification for a US vendor:

  1. Check the official DPF list at dataprivacyframework.gov to confirm current certification
  2. Verify the certification covers the specific services and data types you are transferring
  3. Confirm the certification has not expired or been withdrawn

If DPF certification is not in place, use Swiss SCCs.

Risk note: The Swiss-US DPF, like its EU counterpart, is subject to legal challenge. A prudent approach is to maintain executed Swiss SCCs with US vendors even where DPF certification exists, providing belt-and-suspenders protection.


Disclosure Requirement

FADP Article 19 requires that your privacy notice discloses cross-border transfers — specifically:

  • Which countries data is transferred to
  • The safeguards applied (adequacy, DPF, SCCs)

This is more specific than what many GDPR privacy notices contain. Update your privacy notice to list the countries where your key vendors are located and the mechanism for each transfer.


Practical Transfer Compliance Checklist

  • Map all vendors processing personal data — note their location
  • Check each country against the Swiss Federal Council adequacy list
  • For EU/EEA vendors: adequacy applies — no additional mechanism needed
  • For US vendors: check DPF certification status at dataprivacyframework.gov
  • For non-DPF US vendors: execute Swiss SCCs
  • For vendors in other non-adequate countries: execute Swiss SCCs
  • Maintain a transfer record: vendor, country, mechanism, date mechanism executed
  • Update your privacy notice to disclose transfer countries and mechanisms
  • When you onboard new vendors, add transfer assessment to the due diligence process

Transfers from Both EU and Swiss Data

If you process both EU and Swiss personal data and transfer to the same US vendor:

  • The EU data requires GDPR-compliant SCCs (EU SCCs or DPF)
  • The Swiss data requires FADP-compliant safeguards (Swiss SCCs or Swiss DPF)
  • Many major vendors provide combined documentation covering both — check their DPA and addenda

Do not assume that executing EU SCCs with a vendor covers Swiss data transfers. They are separate legal frameworks and require separate instruments unless the vendor provides a combined solution.

ComplyOne assesses your FADP compliance alongside GDPR and identifies the gaps specific to Swiss law.

Check your Swiss FADP obligations →