Switzerland

Non-Eyes state with an extensive network of data-sharing partnerships and mutual legal assistance treaties, plus cable reconnaissance powers and the Crypto AG legacy

← Back to Privacy Law Directory

Overview

Switzerland is a non-EU state that sits outside every Eyes alliance, belonging to neither the Five, Nine, nor Fourteen Eyes nor to Maximator, and that distance from the Anglo-American signals-intelligence bloc underpins its reputation as a home for privacy-oriented technology services. The reputation rests on Swiss domestic law, which is the narrowest part of the picture. Swiss protections are strongest for communications that stay inside the country; for the cross-border traffic that makes up almost everything flowing to and from a globally used email or VPN provider, a different regime applies, and that regime runs through the alliances and treaties Switzerland does belong to.

Those memberships are extensive. Switzerland is a full member of the Council of Europe (46 states), an associate member of the Schengen Area (29 states) with access to the Schengen Information System, and a founding member of the Club de Berne intelligence-sharing forum and its Counter Terrorism Group.[12] It is a party to the 1959 European Convention on Mutual Assistance in Criminal Matters (51 parties) and the 2001 Budapest Convention on Cybercrime (82 parties),[38] and participates in the Prüm biometric-exchange framework (31 states),[43] Interpol, the Egmont Group of financial intelligence units, and an operational cooperation agreement with Europol.[44] On top of the multilateral conventions it maintains bilateral mutual legal assistance treaties (MLATs) with 17 states: the United States (1973), Australia (1991), Canada (1993), Peru (1997), Ecuador (1997), Hong Kong SAR (1999), Egypt (2000), the Philippines (2002), Brazil (2004), Mexico (2005), Algeria (2006), Chile (2006), Argentina (2009), Colombia (2011), Indonesia (2019), Kosovo (2022), and Panama (2023), plus supplementary treaties layered on the 1959 Convention for its four neighbours (Germany, Austria, France, and Italy). Each of these frameworks, with its full membership, is detailed below.[39]

These frameworks are the channels through which the privacy reputation is qualified. Under the Intelligence Service Act (NDG) the Federal Intelligence Service runs cable reconnaissance, the bulk interception of cross-border fibre-optic traffic; a December 2025 Federal Administrative Court ruling (case A-6444/2020) found the practice incompatible with fundamental rights but recorded that it had excluded only purely domestic communications, leaving cross-border traffic exposed until a compliant regime is built by 2030.[2] Foreign authorities reach data physically held in Switzerland through mutual legal assistance, which Swiss law grants even where no treaty exists, and a US treaty request of exactly this kind unmasked an anonymous ProtonMail account in the “Stop Cop City” case.[40] The country’s own history sets the caution: the Crypto AG operation, revealed in 2020, showed Swiss intelligence complicit for decades in a CIA scheme that sold deliberately weakened encryption to more than 120 governments, an arrangement the CIA called “the intelligence coup of the century.”[1]

International Data Sharing Agreements

Despite Switzerland’s non-membership in Eyes alliances and robust domestic framework, extensive international agreements provide foreign agencies with pathways to access Swiss person data.

Mutual Legal Assistance: Layered Framework

Switzerland’s MLA framework is governed domestically by the Federal Act on International Mutual Assistance in Criminal Matters (IMAC/IRSG). The Federal Office of Justice serves as the central authority.[24]

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): With its Additional Protocols (1978, 2001), this is the general framework for cross-border criminal evidence. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation, which remains a party despite its 2022 expulsion from the Council of Europe).[38]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Built for exactly the kind of data an email or messaging provider holds, it provides for expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 the Budapest Convention has 82 parties: the 45 Council of Europe member states listed above that have ratified it (all 46 except Ireland, which has signed but not ratified), plus 37 non-member states (Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu). Switzerland is a party to both conventions.[38]

Bilateral treaties: Beyond the multilateral conventions, Switzerland has concluded standalone bilateral mutual-assistance treaties, catalogued in the Swiss systematic compilation of federal law under chapter 0.351, that extend the same machinery to states outside the European framework. The network reaches well beyond Europe and has kept growing; the most recent, with Panama, was signed in 2023. The seventeen standalone treaties in force are with:[25][39]

Two older bilateral arrangements take a lighter form: a 1937 reciprocity declaration with Japan and a 1989 exchange of letters with India. Switzerland’s four neighbours are handled not by standalone treaties but by supplementary bilateral treaties layered on top of the 1959 Convention: Germany (1969), Austria (1972), France (1996), and Italy (1998). Countries a reader might expect to see, including the Netherlands, Portugal, Spain, and the Republic of Korea, need no bilateral treaty because they are already parties to the 1959 Convention, which governs Swiss mutual assistance with them; the bilateral list adds to the multilateral framework rather than replacing it.[39]

IMAC fallback (worldwide): Under the IMAC, Switzerland may grant mutual assistance to any state, treaty or no treaty, requiring only a guarantee of reciprocity where no treaty exists, so the enumerated treaty partners are a floor, not a ceiling. Some partner states, however, cannot offer assistance without a treaty basis, which drives Switzerland’s ongoing treaty expansion programme. The Federal Office of Justice also uses Memoranda of Understanding as preliminary instruments with states not yet ready for formal treaty negotiations.[24][39]

The Framework in Action: Three Cases, Three Routes In

On January 25, 2024, the FBI submitted a request through the 1973 US-Switzerland MLAT for subscriber information on a ProtonMail account tied to the movement opposing the Atlanta police training centre. Swiss authorities approved the request and the data was returned through the treaty channel; a payment-card identifier in it unmasked the account holder. Proton stated that it did not hand data to the FBI directly but complied with a legally binding order from Swiss authorities, which then shared it through the MLAT process, and that it discloses data only after a Swiss court approves the request. The message encryption was never touched and was not the point: the identifying data was metadata the provider necessarily holds. What made the Swiss jurisdiction reachable was not a failure of encryption but a treaty request that a Swiss court granted.[40]

A French climate activist was reached three years earlier through a different channel. In September 2021 Proton disclosed that it had been ordered to log the IP address of a ProtonMail account used by a member of a Paris collective that had occupied premises near the Place Sainte-Marthe. The request originated with the French police, was transmitted through Europol, and was then executed as a legally binding order by the Swiss authorities, which Proton was obliged to obey. As in the American case the encrypted message contents were never at issue; what the order compelled was the collection and disclosure of the connection metadata the service would otherwise not retain.[45]

A Catalan activist was unmasked in 2024 through a third route. In a Spanish counter-terrorism investigation into the Tsunami Democràtic movement, concerning alleged threats to the King, the Guardia Civil obtained through the Swiss court system the recovery email address attached to a ProtonMail account used under the pseudonym “Xuxo Rondinaire.” That address was an Apple iCloud account, and Apple in turn supplied the holder’s name and home addresses, completing the identification. Proton noted that it offers “privacy by default, not anonymity by default,” that the recovery address had been added by the user, and that it cannot encrypt such an address because it must be able to send mail to it. Once again the encryption held, and once again a self-supplied identifier passed to Swiss judicial process was enough.[46]

Three cases, three different doors into the same jurisdiction: a bilateral MLAT (the United States), the Europol channel (France), and a domestic Swiss court order at a foreign state’s request (Spain). None turned on breaking encryption; each turned on metadata a provider must hold, an IP address, a payment-card identifier, a recovery email, and a Swiss legal instrument compelling its release.

Club de Berne: Counter-Terrorism Intelligence

As a founding member of the Club de Berne (1969), Switzerland has participated in European intelligence sharing for over five decades. The forum keeps no public membership roster; it is reported to comprise the intelligence services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland, with the United Kingdom also reported as a member. The Counter Terrorism Group (CTG) operates in parallel with substantially overlapping membership, comprising the domestic-security services of the EU member states plus Norway, Switzerland, and the United Kingdom.[12]

Schengen Information System (SIS II)

Switzerland’s Schengen association (operational since 2008) means alerts entered by Swiss police are visible in real time across all Schengen countries, and vice versa. The area comprises 29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland (Bulgaria and Romania joined as full members on January 1, 2025; Ireland and Cyprus are EU states outside the Schengen Area). The Schengen Data Protection Act (SDPA) (2018) governs data processing in Schengen contexts.[26]

Prüm Decision: Biometric Data Exchange

Switzerland participates in automated cross-border exchange of DNA profiles, fingerprints, and vehicle registration data. The framework binds all 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with the four non-EU Schengen-associated states (Iceland, Liechtenstein, Norway, and Switzerland); Switzerland and Liechtenstein joined through agreements signed on June 27, 2019, and Norway and Iceland through earlier 2009 agreements. The Prüm II Regulation (2024) expands this to facial images and police records.[27][43]

Financial Data Sharing

AEOI: Automatic exchange of bank account information with 100+ countries (described in Banking Secrecy section).

SWIFT/TFTP: Swiss persons’ international wire transfers are subject to US Treasury access under the Terrorist Finance Tracking Program.[28]

Egmont Group: The Swiss FIU shares financial intelligence across 164+ Financial Intelligence Units worldwide.

Other Frameworks

Interpol I-24/7: Switzerland participates in Interpol’s global police network (195 countries). PNR: Swiss air carriers transfer passenger data to US CBP for US-bound flights.[29]

Europol: Switzerland holds an operational cooperation agreement with Europol, the EU Agency for Law Enforcement Cooperation, enabling exchange of strategic and technical intelligence (including personal data) and a Swiss liaison office at Europol’s headquarters in The Hague. Europol is constituted by the 27 EU member states (Denmark, which holds a Justice and Home Affairs opt-out, participates through a separate operational agreement dated August 1, 2022). Beyond them, Europol maintains operational agreements permitting personal-data exchange with 17 non-EU states: Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States; it also holds agreements with the EU agencies Eurojust and Frontex and with Interpol. Because Europol in turn cooperates with the FBI, Swiss intelligence shared through it may flow onward to US law enforcement.[29][44]

The Privacy Backdoor Effect

Despite non-membership in Eyes alliances, the FADP, and NDG triple-lock authorisation, international agreements create alternative access pathways:

Surveillance Laws

BÜPF – Federal Act on the Surveillance of Post and Telecommunications (2018)

The BÜPF governs lawful interception by law enforcement. The 2018 revision substantially expanded capabilities:[8]

The Dienst ÜPF (Post and Telecommunications Surveillance Service) implements surveillance measures, serving cantonal prosecutors, the Attorney General, and the Federal Intelligence Service.

NDG – Federal Intelligence Service Act (2017)

The NDG was approved by referendum with 65.5% support and entered into force September 1, 2017. Key capabilities:[9]

Triple-Lock Authorisation

Special intelligence-gathering measures require three-stage approval: (1) Federal Administrative Court, (2) heads of the Departments of Defence, Justice, and Foreign Affairs, (3) Federal Council Security Committee. However, the December 2025 FAC ruling found this mechanism insufficient in practice to protect fundamental rights.[2]

Procedural Safeguards

The Swiss Criminal Procedure Code (StPO) requires post-surveillance notification to targets, access to results, right to independent expert review, right to challenge in court, and damages for successful challenges. Metadata obtained without judicial authorisation is inadmissible.[10]

Intelligence Services

NDB / FIS – Federal Intelligence Service

Established January 1, 2010 by merging the DAP (domestic security) and SND (foreign intelligence). Responsible for counter-terrorism, counter-espionage, counter-proliferation, and critical infrastructure protection. The NDB collaborates with over 100 foreign intelligence agencies (12,500 notifications received and 6,000 sent in 2017). A separate Military Intelligence service (MND) operates within the armed forces.[11]

Alliance Status: Non-Member with Extensive Cooperation

Switzerland is not a member of the Five Eyes, Nine Eyes, Fourteen Eyes, or Maximator alliances. The reach of each alliance is the list of states inside it, so the memberships are set out below; these groupings are documented through leaked material and investigative and academic reporting rather than official rosters:[41][42]

Switzerland’s independence is nonetheless more nuanced than formal non-membership suggests:[12]

Crypto AG / Operation Rubicon

Revealed February 2020 by the Washington Post, ZDF, and SRF. Crypto AG, a Swiss-based encryption manufacturer, was secretly co-owned by the CIA and the West German BND from 1970 to 2018. They sold deliberately weakened encryption equipment to over 120 governments (including Iran, India, Pakistan, and Latin American nations), enabling the CIA and BND to read their encrypted communications. The BND sold its stake around 1993; the CIA maintained sole ownership until approximately 2018.[1]

The GPDel (Parliamentary Control Delegation) investigation found that Swiss intelligence (SND) knew the CIA was behind Crypto AG as far back as 1993 and subsequently collaborated. The report stated: “The Swiss authorities share responsibility for the activities of Crypto AG.” Current ministers were only informed in autumn 2019, months before media revelations.[13]

Oversight Bodies

AB-ND: Independent Oversight Authority for Intelligence Activities, established by the NDG. GPDel: Parliamentary Control Delegation with wide-ranging inspection rights. FDPIC: Checks legality of domestically collected intelligence data. Federal Audit Office: Financial oversight. The multi-layered structure reflects Swiss political culture, though Operation Rubicon showed it can fail when activities are concealed for decades.[14]

Recent Developments

Operation Saffron: Swiss Participation in First VPN Takedown (May 2026)

Switzerland was among the main participating states in Operation Saffron (May 19–20, 2026), the Europol- and Eurojust-supported, France/Netherlands-led action that dismantled the criminal anonymisation service “First VPN” used by 25+ ransomware groups. Authorities seized 33 servers across 27 countries and obtained the service’s complete user database of 5,000+ accounts, with intelligence on hundreds of users shared across partner states. Swiss involvement illustrates how Switzerland, despite its non-EU status and strong domestic privacy posture, cooperates closely in cross-border cybercrime-infrastructure takedowns and the attendant sharing of seized subscriber data.[35]

FAC Cable Surveillance Ruling (December 2, 2025)

The Federal Administrative Court (case A-6444/2020) ruled that cable reconnaissance and radio surveillance as practiced by the NDB are incompatible with the Federal Constitution and the ECHR. The court found insufficient protection against misuse, no instruments protecting journalistic sources or lawyer-client communications, and neither effective oversight nor legal remedy for affected parties. The legislature has a five-year transitional period; if a compliant system is not in place by 2030, cable and radio surveillance must be discontinued entirely.[2][30]

The ruling turned on a distinction that matters for any provider with an international user base: the court recorded that purely domestic Swiss communications were excluded from the intercepted material, while cross-border traffic was not. Swiss law protects domestic communications most fully, but nearly all traffic to and from an email or VPN provider whose users are spread across the world is, by definition, cross-border, and so falls in the category the interception program reached.[2]

NDG Revision Packages (2025–2026)

The Federal Council is pursuing multi-part NDG revision. The basic package dispatch was submitted to Parliament on February 13, 2026, extending the FIS mandate to all of cyberspace, authorising data collection from financial intermediaries, and strengthening AB-ND oversight. The controversial proposal to allow surveillance of persons with professional secrecy (lawyers, doctors) was dropped. A separate cable reconnaissance reform track addresses the FAC ruling’s 2030 deadline.[31][32]

VÜPF Surveillance Expansion Paused

The data retention expansion proposals (described in the Data Retention section below) were paused following industry backlash and the December 2025 parliamentary motion requiring an independent impact analysis before any new draft.[23]

Swiss-US Data Privacy Framework Stability

The Framework remains operational but faces deepening uncertainty after the termination of all three Democratic PCLOB members in January 2025, leaving the board without a quorum. The PCLOB plays a central role in the redress mechanism. Reinstatement litigation ended in practical defeat when the US Supreme Court’s Trump v. Slaughter decision (June 29, 2026) held that the President may remove members of multimember independent agencies at will, so the board’s lost quorum and independence are now a settled feature of the US landscape rather than a temporary dispute; the parallel EU adequacy decision faces a withdrawal demand and an announced CJEU challenge from noyb on the same ground. Legal commentators recommend maintaining SCCs as a precautionary fallback.[33][47]

Privacy Framework

The FDPIC (Federal Data Protection and Information Commissioner) is an independent authority supervising compliance with data protection law. Under the revised FADP (September 2023), the FDPIC gained power to issue legally binding administrative orders, a significant upgrade from the previous regime where only non-binding recommendations were possible. However, the FDPIC cannot impose fines: criminal penalties of up to CHF 250,000 are imposed on responsible natural persons (not organisations), prosecuted by cantonal authorities.[4][5]

The FADP protects only natural persons (aligning with GDPR), introduces the “effects doctrine” for extraterritorial application, distinguishes between ordinary and “high-risk” profiling, does not require mandatory DPOs, and sets breach notification at “as soon as possible” rather than the GDPR’s 72 hours. Unlike the GDPR’s closed list of legal bases, the FADP uses a principle-based approach where processing is generally permitted unless it violates personality rights. Switzerland maintains EU adequacy (first granted 2000, renewed January 2024) and approved the Swiss-US Data Privacy Framework in September 2024.[6][7]

Data Sovereignty: Rejecting Palantir

Swiss federal agencies have rejected Palantir Technologies at least nine times over seven years. In 2020, military evaluators rejected a Palantir bid for an intelligence service IT system, concluding it was unclear whether sensitive data could be safeguarded from US intelligence access. The Federal Office of Public Health chose competitors for pandemic management. The pattern reflects an institutional assessment that Palantir’s ties to US intelligence (initially funded by the CIA’s In-Q-Tel, extensive NSA/CIA contracts) create unacceptable sovereignty risks.[3]

This contrasts sharply with other privacy-conscious jurisdictions: the UK awarded Palantir £330M (NHS) and £240M (MOD), France renewed its DGSI contract, Denmark deployed POL-INTEL, and Germany allows three states to use Palantir despite federal concerns.[15]

However, investigative reporting in October 2023 revealed that Predator spyware (Intellexa/Cytrox) had been sold to Switzerland among 25 identified purchaser countries.[16]

Banking Secrecy and Financial Privacy

Article 47 of the Federal Act on Banks and Savings Banks (1934) makes disclosure of client information a federal crime punishable by up to five years’ imprisonment and CHF 250,000 fines. This transformed a civil-law tradition into one of the most widely recognised financial privacy regimes.[17]

However, banking secrecy has been substantially eroded since 2009 under international pressure. Switzerland adopted the Automatic Exchange of Information (AEOI) standard in 2017, with first exchanges in 2018. As of 2024–2026, AEOI covers 100+ partner countries, with millions of accounts shared annually (balances, interest, dividends, financial income, account holder identity). Crucially, AEOI applies only to foreign account holders; Swiss residents’ banking information is not exchanged automatically, meaning banking secrecy remains functionally intact domestically.[18]

Cryptography and Export Controls

The development, manufacturing, and use of cryptographic products is unrestricted within Switzerland. No authorisation, licensing, or registration is required. Switzerland participates in the Wassenaar Arrangement for export controls on dual-use goods, administered by SECO (State Secretariat for Economic Affairs). An Ordinary General License covers exports to 23 trusted countries. Under the Embargo Act, Switzerland also applies import controls on surveillance technology based on human rights considerations. Following Operation Rubicon, Switzerland strengthened due diligence for cryptographic product exports.[19][20]

Data Retention

Telecommunications providers must retain metadata (not content) for 6 months, including traffic data, subscriber data, location data, and IP addresses. Content is excluded.[8]

VÜPF Expansion Controversy (2025–2026)

In January 2025, the Federal Council proposed expanding the VÜPF (implementing ordinance) to classify VPN services, encrypted messaging apps, social media, and email providers as telecommunications service providers subject to retention. The proposals included mandatory IP address logging for providers with 5,000+ users, mandatory identity verification (banning anonymous access), and potential obligations to build encryption backdoors.[21]

The backlash was severe: Swiss-based companies began relocating servers abroad, Proton relocated CHF 100 million in infrastructure to Germany and Norway, and 19 civil society organisations (including EDRi, Amnesty International, Privacy International) published an open letter demanding abandonment of the proposals. Parliament paused the process in December 2025, commissioning an independent impact analysis before any new draft.[22][23] In 2026 the Federal Council ordered an in-depth external regulatory impact assessment and confirmed it would prepare a second consultation rather than enact the original text, after both the National Council and the Council of States adopted motions demanding a fundamental revision. The government has set no binding timetable, and the revision still centres on whether cooperation obligations (including plaintext-delivery and identification duties) extend to communication platforms such as WhatsApp, Threema, and Proton.[34]

The leaked “VÜPF 2.0” draft (May 7, 2026): The pause did not stop the drafting. On May 7, 2026 the online magazine Republik, through technology journalist Adrienne Fichter, published a previously secret February 2026 draft that the Federal Department of Justice and Police, under Federal Councillor Beat Jans, had circulated to selected Swiss IT companies without a public consultation. The draft makes two changes of substance. First, end-to-end encryption in Swiss apps would be left untouched, a genuine concession to the criticism. Second, the threshold for the cooperation duties rises from providers with 5,000 users to those with more than 100,000 customers. That exempts small Swiss mail and hosting providers, but it does not exempt the companies the debate is actually about: Proton, Threema, and Tresorit would each still be required to identify their customers by official identification and to retain communications metadata, which cantonal police, the Office of the Attorney General, and fedpol could then query.[36]

The Digitale Gesellschaft called the manoeuvre a continuation of the Federal Council’s “ghost drive” against oncoming traffic, arguing that a raised threshold buys off small businesses without changing the principle: the state “makes successful data-minimising business models impossible.” Fichter’s central observation is structural rather than technical. The Confederation does not build the surveillance apparatus itself; it outsources the collection duty to private Swiss companies, which must gather and store more customer data than they want to hold, after which the authorities may draw on it. Raising the customer threshold narrows who must serve as the collector without disturbing the arrangement. Whether any of the leaked text survives into the formal proposal is unknown; the outstanding regulatory impact assessment is the gate, and the second consultation follows it. For a jurisdiction whose privacy reputation rests substantially on the presence of Proton and Threema, the revision poses the question directly: an identification duty is incompatible with anonymous accounts, whatever happens to the encryption.[36][37]

Pending Legislation

Sources

[1] Washington Post: The Intelligence Coup of the Century (February 2020) – CIA/Crypto AG revelations, Operation Rubicon
[4] Adnovum: Swiss Federal Act on Data Protection 2023 – FDPIC powers, binding orders, no fine authority
[5] Mondaq: Who Will Be Penalised Under the New FADP? – CHF 250,000 individual penalties
[6] Secure Privacy: Switzerland’s New FADP – Key Changes – Effects doctrine, profiling, no mandatory DPO
[8] MLL Legal: Revised Federal Act on Surveillance (BÜPF 2018) – GovWare, IMSI catchers, metadata retention
[9] Wikipedia: Intelligence Service Act (Switzerland) – NDG, cable reconnaissance, triple-lock, 65.5% referendum approval
[11] Wikipedia: Swiss Intelligence Agencies – NDB formation (2010), international cooperation statistics
[12] ETH Zürich ISN Blog: Oversight and Intelligence Services – Switzerland – Club de Berne founding, CNE cooperation
[14] Intelligence Oversight: Switzerland – AB-ND, GPDel functions
[15] JVL: Palantir OK for UK But Not Switzerland – Contrast with UK, France, Denmark, Germany procurement
[16] Bleeping Computer: Intellexa/Cytrox Predator Spyware – Switzerland among 25 purchaser countries
[17] Goldblum: Bank Secrecy in Switzerland – Article 47, criminal penalties, five years imprisonment
[19] Cryptographie en Suisse: Considérations légales – Unrestricted domestic encryption use
[20] BIS: Switzerland Export Control Information – Wassenaar, SECO, OGL for 23 countries
[22] EDRi: Open Letter on Swiss Data Retention (February 2026) – 19 organisations, Proton CHF 100M relocation
[23] TechRadar: Switzerland Revises Proposal After Backlash – Parliamentary pause, impact analysis
[24] Federal Office of Justice: Expansion of the State Treaty Framework – IMAC framework, bilateral treaty programme, MoU instruments
[25] Swiss Federal Office of Justice: Guide to International Mutual Assistance in Criminal Matters (PDF) – 1973 US MLAT as first modern bilateral treaty, IMAC procedures
[26] European Commission: Schengen Information System – Real-time alert sharing
[27] European Commission: Prüm Framework – Biometric data exchange, Prüm II expansion
[29] Europol: Partners & Collaboration – Switzerland cooperation agreement, FBI channel
[30] Heise: Court Halts Mass Surveillance of Swiss Intelligence Service – Five-year deadline, 2030 discontinuation
[31] Digitec: Intelligence Service Act Expansion – NDG revision packages, professional secrecy dropped
[32] Swiss Federal Council: NDG Basic Package Dispatch (February 13, 2026) – Cyberspace mandate, AB-ND strengthened
[33] IAPP: Trump Administration Impact on Data Privacy Framework – PCLOB terminations, SCC fallback recommended
[34] ISOC Switzerland Chapter: Positive Development in the Swiss Surveillance (VÜPF / VD-ÜPF) Framework Debate (2026) – Following heavy consultation criticism, the Federal Council ordered an in-depth external regulatory impact assessment and is preparing a second consultation; National Council and Council of States adopted motions calling for a fundamental revision and new consultation; revision centres on cooperation obligations of platforms (WhatsApp, Threema, Proton); no binding timetable
[35] Help Net Security: Authorities Dismantle First VPN, Used by Ransomware Actors (May 21, 2026) – Operation Saffron (May 19–20, 2026) led by France and the Netherlands with Europol and Eurojust; Switzerland among the main participating states; 33 servers seized across 27 countries; complete user database of 5,000+ accounts obtained; intelligence on 506 users shared with partner countries
[36] Watson: Überwachung – Geleakter Entwurf zu VÜPF-Revision sorgt für neue Kritik (May 7, 2026)Republik journalist Adrienne Fichter published a secret February 2026 “VÜPF 2.0” draft prepared by Federal Councillor Beat Jans’s Justice and Police Department and circulated to selected Swiss IT firms; end-to-end encryption in Swiss apps to be left untouched; cooperation threshold raised from 5,000 users to more than 100,000 customers, still capturing Proton, Threema and Tresorit, which would have to identify customers by official ID and retain metadata accessible to cantons, the Office of the Attorney General and fedpol; Digitale Gesellschaft: the Federal Council “continues its ghost drive” and “makes successful data-minimising business models impossible”; next step is the outstanding regulatory impact assessment, then a second consultation
[37] Digitale Gesellschaft: Massenüberwachung – Geisterfahrt des Bundesrates endlich stoppen (May 7, 2026) – Response to the leaked draft; the proposal “remains an attack on fundamental rights, economy and society” and “threatens data-sparse communication services like Proton and Threema”; raised threshold exempts some small SMEs without changing the principle; in the first consultation (summer 2025) every actor except the cantons opposed the revised VÜPF; civil society excluded from the ordinance revision
[38] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) and Convention on Cybercrime (ETS No. 185) – Charts of signatures and ratifications, status as of July 22, 2026: 51 parties to the 1959 Convention (46 Council of Europe members plus Chile, Israel, Mongolia, the Republic of Korea and Russia) and 82 parties to the Budapest Convention (every member except Ireland plus 37 non-members); Switzerland is a party to both
[39] Swiss systematic compilation of federal law (Fedlex), chapter 0.351: mutual assistance in criminal matters; and Pascal Gossin (Head, International Legal Assistance Section, Swiss Federal Office of Justice), “International Mutual Legal Assistance in Switzerland”, UNAFEI Resource Material Series No. 77 – The seventeen standalone bilateral treaties in force (US 1973, Australia 1991, Canada 1993, Peru 1997, Ecuador 1997, Hong Kong 1999, Egypt 2000, Philippines 2002, Brazil 2004, Mexico 2005, Algeria 2006, Chile 2006, Argentina 2009, Colombia 2011, Indonesia 2019, Kosovo 2022, Panama 2023); lighter arrangements with Japan (1937) and India (1989); supplementary treaties with Germany, Austria, France and Italy layered on the 1959 Convention; the IMAC “any state” reciprocity rule
[40] 404 Media: Proton Mail Helped FBI Unmask Anonymous “Stop Cop City” Protester – January 25, 2024 FBI request via the 1973 US-Switzerland MLAT; Swiss authorities approved and returned the data through the treaty channel; a payment-card identifier unmasked the account; message encryption was not bypassed
[41] Proton VPN: The 5, 9, and 14 Eyes surveillance alliances explained; and Wikipedia: Five Eyes (UKUSA Agreement, SIGINT Seniors Europe) – Five Eyes (Australia, Canada, New Zealand, the UK, the US); Nine Eyes adds Denmark, France, the Netherlands and Norway; Fourteen Eyes / SIGINT Seniors Europe (SSEUR) adds Belgium, Germany, Italy, Spain and Sweden; these memberships are documented through leaked material and reporting, not official rosters
[42] Bart Jacobs, “Maximator: European signals intelligence cooperation, from a Dutch perspective,” Intelligence and National Security 35:5 (2020) – The Maximator SIGINT alliance (Denmark, France, Germany, the Netherlands, Sweden), secret from 1976 until its 2020 disclosure; members shared intelligence derived from rigged Crypto AG cipher devices
[43] Swiss Federal Department of Foreign Affairs: Police Cooperation (Prüm Decisions); and eucrim: Prüm Cooperation Agreements with Switzerland and Liechtenstein – The Prüm framework binds all 27 EU member states plus the non-EU Schengen-associated states Iceland, Liechtenstein, Norway and Switzerland; the EU signed participation agreements with Switzerland and Liechtenstein on June 27, 2019, and with Norway and Iceland in 2009
[44] Europol: Operational Agreements – Europol’s operational cooperation agreements (permitting exchange of personal data) with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States), plus Denmark under a separate agreement owing to its Justice and Home Affairs opt-out (dated August 1, 2022), and agreements with the EU agencies Eurojust and Frontex and with Interpol; Switzerland’s agreement is listed at October 25, 2016
[45] Proton: Important clarifications regarding the arrest of a climate activist (September 2021); and TechCrunch: ProtonMail logged IP address of French activist after order by Swiss authorities – French police request transmitted via Europol; Swiss authorities issued a legally binding order; Proton logged and disclosed the account’s IP address; message contents were not accessed
[46] TechRadar: Proton Mail recovery email leads to arrest of Catalan activist (May 2024); and CyberInsider: Proton Mail Discloses User Data Leading to Arrest in Spain – Spanish Guardia Civil counter-terrorism probe into Tsunami Democràtic; through the Swiss court system Proton disclosed the account’s recovery email (an Apple iCloud address), and Apple then provided the holder’s name and addresses; pseudonym “Xuxo Rondinaire”
[47] Supreme Court of the United States: Trump v. Slaughter, No. 25-332 (June 29, 2026) – 6–3 decision overruling Humphrey’s Executor (1935), permitting at-will presidential removal of multimember independent-agency members; the PCLOB reinstatement appeal had been deferred pending this ruling, leaving the board’s lost quorum in place
← Back to Privacy Law Directory