Skip to content
Swiss FADP

Switzerland and EU Adequacy: What It Means for Your Data

4 min readUpdated 29 July 2026

Switzerland holds EU adequacy status for data protection purposes — meaning the EU recognises that Switzerland provides an "adequate" level of data protection. This has a direct practical consequence: personal data can flow from EU member states to Switzerland without requiring SCCs, BCRs, or other transfer mechanisms.

But the relationship is more complex than it first appears, and the adequacy arrangements work differently depending on the direction of data flow.


EU Adequacy for Switzerland: The Basics

The EU's adequacy decision for Switzerland has been in place since 2000. Under GDPR Article 45, adequacy decisions allow personal data to be transferred to third countries without additional safeguards.

What this means in practice:

  • An EU company can send customer data to a Swiss data processor without SCCs
  • An EU company can transfer employee data to Swiss HR systems without additional mechanisms
  • The transfer is treated as equivalent to a transfer within the EEA

This simplifies data flows significantly for companies with EU-Swiss operations. Many companies with dual EU/Swiss operations run data through Swiss infrastructure without additional GDPR transfer documentation.


The Adequacy Decision Is Under Review

The European Commission reviews adequacy decisions periodically. Switzerland's adequacy decision was granted based on the old Swiss Federal Data Protection Act. The revised FADP (in force September 2023) is significantly more robust.

The EU Commission has been reviewing the Swiss adequacy decision to confirm it covers the revised FADP. The current adequacy decision has been confirmed as continuing to apply during this review period. However:

  • If the review results in conditions or changes, the terms may change
  • Companies relying on adequacy without fallback SCCs carry some risk if adequacy is modified
  • Best practice is to have SCCs available as a fallback even when relying on adequacy

Switzerland's Own Adequacy List

Switzerland maintains its own list of countries it deems to provide adequate protection for data exported from Switzerland. This is the FDPIC's adequacy list — separate from the EU's adequacy list.

Countries on Switzerland's adequacy list include: Most EU/EEA member states, UK, Canada, Argentina, Israel, Japan, New Zealand, South Korea, and others.

Countries not on Switzerland's adequacy list: China, India, and most countries not on the EU adequacy list are also not on Switzerland's list. The United States is handled differently — through the Swiss-US Data Privacy Framework.

For data flowing from Switzerland to these countries: Transfer mechanisms are required — Swiss SCCs or Swiss DPF certification.


The Swiss-US Data Privacy Framework

Switzerland and the United States have a bilateral arrangement analogous to the EU-US Data Privacy Framework: the Swiss-US Data Privacy Framework (DPF). US companies can certify under this framework at dataprivacyframework.gov — they certify separately for EU and Swiss frameworks.

For transfers of Swiss personal data to the US:

  • Check if the US vendor has Swiss DPF certification (not just EU DPF certification — these are separate)
  • If Swiss DPF certified: transfer is covered without SCCs
  • If not Swiss DPF certified: Swiss SCCs are required

Many large US vendors (Google, Microsoft, Stripe, AWS) hold both EU and Swiss DPF certifications. But do not assume — verify on the DPF certification list.


Practical Scenarios

Scenario 1: EU SaaS company processes data for Swiss customers The data flows from Switzerland (where the Swiss customers are) to the EU company's servers. Switzerland considers EU member states adequate — no Swiss transfer mechanism required. But the EU company must comply with FADP in how it processes Swiss customers' data.

Scenario 2: Swiss company uses a US cloud provider The data flows from Switzerland to the US. EU adequacy does not apply to this transfer. Swiss DPF certification or Swiss SCCs required from the US provider.

Scenario 3: EU SaaS company hosts in Ireland but has Swiss enterprise customers The Swiss customer sends data to Ireland (EU). EU adequacy covers the flow to Ireland. If the Irish company then sends data to US sub-processors, Swiss SCCs or Swiss DPF required for the Swiss customers' data.

Scenario 4: UK company serving Swiss customers post-Brexit The UK is on Switzerland's adequacy list — UK adequacy for Swiss purposes was confirmed. Data can flow from Switzerland to the UK without Swiss transfer mechanisms.


What Has Changed with the Revised FADP

The revised FADP (in force 2023) updated Switzerland's own rules significantly, which is one reason the EU adequacy review is ongoing. The revised FADP aligned more closely with GDPR in several respects:

  • Enhanced data subject rights
  • Strengthened breach notification obligations
  • Expanded FDPIC enforcement powers
  • New rules on high-risk profiling and DPIAs

This closer alignment is why the EU adequacy review is expected to confirm continued adequacy — but nothing is guaranteed until the review concludes.

ComplyOne assesses your FADP compliance alongside GDPR and identifies the gaps specific to Swiss law.

Check your Swiss FADP obligations →