Blog

Data Sovereignty in Swiss E-Commerce: What Matters When Choosing a Platform

You are currently comparing a commerce platform, a SaaS tool or a hosting partner, and your checklist covers functionality, price and time-to-market. Where your customer data actually ends up rarely makes it to the top of that list. That is exactly what leads, later on, to questions from your legal department, or to a contract that can no longer be adjusted without friction.

In short: since the revised Federal Act on Data Protection, referred to here by its German abbreviation revDSG, came into force on 1 September 2023, every disclosure of personal data abroad needs a legal basis. That basis is either an adequacy decision by the Federal Council for the country in question, or an additional contractual safeguard such as standard data protection clauses. For the United States, a third, narrower option has existed since 15 September 2024: the Swiss-US Data Privacy Framework, which applies only to US companies certified under it, not automatically to every US provider. Even so, the location of the data centre alone does not fully answer the question. A provider with a Swiss or European data centre can still be subject to a foreign right of access if its parent company is based in a third country. Four points therefore decide the matter before any platform or partner choice: where the data is located, who actually controls it, whether a legal basis exists for that, and what you should demand from the provider in writing.

Data Sovereignty in Swiss E-Commerce: Where Your Data Actually Resides

The hosting location of a platform is not always the first thing mentioned in a sales conversation. With self-hostable, open systems (for example Drupal or the open-source edition of Adobe Commerce), you choose the data centre location yourself, for instance with a Swiss or EU hosting partner. With fully managed SaaS platforms (Software as a Service, where the provider is fully responsible for operations and infrastructure), it is usually the provider who determines which region your data resides in, and that region is not always freely selectable.

The large infrastructure providers that many SaaS commerce platforms technically run on now operate their own Swiss regions. Amazon Web Services opened its Europe (Zurich) region, internally named eu-central-2, in 2022, with three fully redundant Availability Zones (spatially separated data centre clusters) around Zurich. Microsoft operates the Switzerland North region in Zurich with three Availability Zones. Alongside it sits the Switzerland West region in Geneva, a so-called reserved-access region that is coupled exclusively to Switzerland North for geo-redundant data backup and has no Availability Zones of its own. Google Cloud opened its Swiss region, europe-west6, in Zurich back in 2019, with three zones for high-availability workloads.

In practice, that does not automatically mean a SaaS platform actually uses this Swiss region for your data. Shopify stores master data, order data and customer data for new European merchants by default in a region within the European Economic Area, the United Kingdom or Switzerland. The actual delivery of shop content for headless storefronts, however, runs through Shopify's hosting service Oxygen across more than 300 globally distributed edge locations, without merchants being able to choose that location themselves. The production database and content delivery can therefore sit in different parts of the world even when the core data is stored in Europe.

For platform and partner selection, this leads to a concrete question for every provider, regardless of whether it is Adobe Commerce, Shopify, BigCommerce, OroCommerce or a marketing automation tool: in which countries are the production, backup and CDN servers (Content Delivery Network, a globally distributed network that delivers content closer to the visitor) located, and who decides that, you or the provider?

What Art. 16 DSG Requires for Disclosing Personal Data Abroad

Art. 16 DSG (Article 16 of the Federal Act on Data Protection, DSG, Switzerland's data protection law) governs the conditions under which personal data may be disclosed abroad at all. Paragraph 1 permits this without further measures if the Federal Council has determined that the country in question offers an adequate level of data protection. Where no such decision exists, paragraph 2 still permits disclosure, but only via one of several additional safeguards: an international treaty, contractual data protection clauses notified in advance to the EDÖB (the Federal Data Protection and Information Commissioner, Switzerland's data protection authority), standard data protection clauses approved by the EDÖB, or approved binding corporate rules.

In practice, this means a provider headquartered in a country without an adequacy decision is not automatically ruled out. It does, however, need one of these additional mechanisms written into the contract, not merely a general data protection clause in its terms and conditions. If that mechanism is missing, it is the company responsible in Switzerland that discloses the data without a valid legal basis, not the provider abroad.

In addition, Art. 9 DSG governs the case where a provider does not carry out the data processing entirely itself but transfers it to a further processor, a subcontractor. Under Art. 9 para. 3 DSG, this transfer to third parties may only take place with the prior authorisation of the controller, in other words with your consent as the customer. In practice, this shows up in the subcontractor list in the contract. If it only says "hosting partner, as required", the transparency that Art. 9 para. 3 DSG requires is missing.

Art. 17 DSG additionally sets out six exceptions under which disclosure abroad is permitted even without an adequacy decision and without an additional contractual mechanism. Two are particularly relevant for everyday e-commerce: the explicit consent of the data subject, and disclosure that is directly connected to concluding or performing a contract between the company and the customer. This second exception explains why an order shipped via a foreign logistics partner is generally unproblematic: disclosing the delivery address serves directly to perform the contract. It does not, however, automatically cover every data disclosure to a foreign marketing automation or analytics platform that has nothing to do with the specific order. These exceptions are, incidentally, narrowly construed individual cases, not a general legal basis for an ongoing contractual relationship with a cloud or SaaS provider.

Data Residency Is Not Data Sovereignty: What the US CLOUD Act Means

The sections above answer the question of where data physically resides, its data residency. A second, independent question is who actually has legal and technical access to that data, regardless of the server location: its data sovereignty. Both terms are often used as if they were synonyms in sales conversations, even though they cover different risks.

The difference becomes concrete with the US Clarifying Lawful Overseas Use of Data Act (CLOUD Act). This US law, enacted in 2018, obliges US companies to hand over data on the order of US authorities, regardless of which country that data is actually stored in. What matters is not the server location, but whether the provider or its parent company is subject to US jurisdiction.

The EDÖB confirmed this assessment on 13 June 2022 in an opinion on a risk analysis voluntarily submitted by the Swiss National Accident Insurance Fund (Suva). Suva examined outsourcing personal data to a Microsoft 365 data centre in Switzerland. Despite the Swiss server location, the EDÖB classified this plan as a cross-border disclosure of personal data to the United States. Its reasoning: Microsoft entities worldwide are subject to the CLOUD Act, and the US parent company can instruct its foreign subsidiaries to hand over data. According to the EDÖB, a contractual commitment to process data exclusively in Switzerland does not change that.

For platform selection, this means a contract that only regulates the server location does not cover data sovereignty. What matters is the provider's legal corporate affiliation. For a provider headquartered in, or with a parent company in, the United States, a CLOUD Act access risk exists even with a Swiss or European data centre. This risk exists independently of an adequacy decision under Art. 16 DSG, because the access occurs under US law, not through a disclosure by the controller in Switzerland. No separate agreement between Switzerland and the United States that would rule out this access currently exists.

The Adequacy List and the Swiss-US Data Privacy Framework in Practice

Before the revDSG, the EDÖB maintained an informal list of countries with an adequate level of data protection. Since the revDSG, the Federal Council sets this list itself, anchored in Annex 1 of the Data Protection Ordinance (DSV). An adequacy decision continues to apply to EU and EEA member states; for other countries, it is worth checking the current version of this annex before signing any contract, since the list can change over time.

The United States is a separate, two-tier case. Without any addition, no general adequacy decision applies to US companies. Since 15 September 2024, however, a narrower exception has applied: on 14 August 2024, the Federal Council decided that US companies certified under the Swiss-US Data Privacy Framework offer an adequate level of data protection. For platform selection, this means the decisive piece of information is not "the provider is American", but whether the specific contracting party that actually processes your data is listed as a participant in the Swiss-US Data Privacy Framework. A US group may have certified individual subsidiaries while leaving others uncertified.

Anyone integrating additional third-party providers into their system landscape, for example through a system integration between an ERP system (Enterprise Resource Planning, for merchandise management and finance), a CRM system (Customer Relationship Management, for managing customer relationships) and the shop, should carry out this check for each individual component, not just for the main platform. And as the previous section shows, even successful certification does not automatically resolve the question of corporate affiliation under the CLOUD Act.

FINMA Circular 2018/3: When Your Company Is Itself Regulated

The sections above apply to any company disclosing personal data abroad. For part of the Swiss B2B commerce environment, an additional, stricter layer applies: financial service providers supervised by the Swiss Financial Market Supervisory Authority (FINMA), such as banks or insurers with their own online shop or their own B2B trading platform.

FINMA Circular 2018/3 "Outsourcing, Banks and Insurers" came into force on 1 April 2018. It defines outsourcing as transferring a function material to business operations to a service provider that carries out that function independently and on an ongoing basis. A function is considered material if compliance with regulatory requirements depends significantly on it. An e-commerce platform that processes customer data or is integrated into payment processes can, depending on how it is set up, fall within this definition.

For affected companies, the circular requires additional organisational measures for outsourcing that go beyond the general requirements of the DSG, for example in assessing the service provider's risk and in the contractual control and instruction rights.

Deliberately, there is no fixed numerical threshold for "material". The previous version of the circular still contained an annex with concrete examples for banks; Circular 2018/3 removed that annex without replacement and instead formulated materiality as an open, principles-based standard: a function is material if compliance with the objectives and rules of financial market supervisory legislation depends significantly on it, assessed by the size, complexity, structure and risk profile of the institution concerned. No percentage of revenue or customer count beyond which an e-commerce function automatically counts as material can be derived from this.

Whether a specific platform or hosting decision actually falls within the scope of the circular therefore cannot be answered in general terms, only case by case against these four criteria. Affected companies clarify this classification with their own compliance or legal department before making a SaaS or cloud decision.

What a Breach of Art. 16 or Art. 9 DSG Actually Costs

The sections above describe what the law requires. Equally concrete is what a breach costs. Art. 61 DSG penalises the intentional breach of duty-of-care obligations with a fine of up to CHF 250,000. Liable under it is anyone who discloses personal data abroad contrary to Art. 16 paras. 1 and 2 DSG without the conditions of Art. 17 DSG being met. Equally liable is anyone who transfers data processing to a processor without the conditions required under Art. 9 paras. 1 and 2 DSG, or who fails to comply with the minimum data security requirements set by the Federal Council under Art. 8 para. 3 DSG.

Two particularities matter in practice. First, only intentional conduct is punishable, negligence remains unpunished. Knowingly accepting a risk, so-called conditional intent, is, however, sufficient for liability. Second, under the DSG it is the natural person who actually committed the violation who is personally liable, not automatically the company as a legal entity. This practically shifts responsibility to the person who makes or approves the platform or contract decision, for instance the head of IT or the digital lead, not solely to executive management.

Alongside Art. 61 DSG, Art. 60 DSG penalises a related but different breach of duty with the same fine of up to CHF 250,000: anyone who intentionally gives data subjects false or incomplete information, who fails to provide the legally required information when collecting personal data, or who intentionally gives the EDÖB false information in an investigation or refuses to cooperate. For platform selection, this means the two fine provisions bite at different points. Art. 61 DSG concerns the data flow itself (disclosure abroad, transfer to processors, data security), while Art. 60 DSG concerns transparency towards data subjects and the supervisory authority. A complete data processing agreement (DPA, an agreement under Art. 9 DSG that governs data processing by the provider), examined in more depth in a later section, reduces the risk under both provisions, because it both documents the data flow and provides the basis for giving data subjects correct information.

Prosecution under this provision requires a complaint. Without a report from the data subject or an authority, no proceedings are automatically triggered. That does not fundamentally reduce the risk, it merely shifts it towards the question of whether a specific incident, for example a data breach with its own reporting obligation, ever comes to light at all.

Swiss Cloud Providers as an Alternative

Anyone wanting to resolve data residency and data sovereignty together should, alongside the large international infrastructure providers, also consider Swiss cloud providers whose registered office and infrastructure are entirely based in Switzerland. Examples from this market segment include Infomaniak (founded in Geneva in 1994, by its own account Switzerland's largest web hosting company, with its own data centres operated exclusively in Switzerland), Exoscale (headquartered in Switzerland, by its own account without a US subsidiary, with its own zone in Zurich), as well as Swisscom and CloudSigma as further Swiss providers with their own data centres in the country.

This list is an example of known market participants, not an assessment or a recommendation. Arcmedia does not have a partnership with any of these providers in the sense of a technology partnership, as it does with Hyvä or Akeneo. Whether a Swiss cloud provider is the right fit depends on the specific use case, among other things on the scalability required, on the functional scope of the respective commerce platform on that infrastructure, and on the integration requirements with existing systems. A provider entirely based in Switzerland structurally resolves the underlying corporate affiliation problem discussed in the section on the CLOUD Act, because no foreign parent company can order the handover of data. It does not, however, automatically settle every other requirement around functional scope or system integration.

A Swiss cloud provider is not equally easy to reach for every platform. For self-hostable systems, such as the open-source edition of Adobe Commerce or Drupal, you choose the infrastructure provider freely and can switch if needed. For fully managed SaaS platforms such as Shopify, BigCommerce or OroCommerce, the provider itself determines which infrastructure it runs on, and switching to a Swiss cloud provider is, in that case, not a decision you can make alone as a customer. The choice between a self-hostable and a fully managed platform therefore also indirectly decides how much influence you will have over data residency later on.

What Evidence to Request Before Signing a Contract

A concrete checklist for contract negotiations can be drawn from the sections above, regardless of the specific technology chosen:

  • Location details in writing, not verbally. Production, backup and CDN locations as part of the contract, not as a statement in a sales call.
  • Data processing agreement (DPA). A standalone document under Art. 9 DSG that sets out how the provider may process your data, which security measures apply, and how long data is retained after the contract ends.
  • Complete subcontractor chain. A named list of all third parties who may access your data, including their location, with an obligation on the provider to report changes in advance (Art. 9 para. 3 DSG).
  • Export rights. The contractually recorded right to demand your own data in a machine-readable format, regardless of the reason the contract ends.
  • Deletion plan with a deadline. A concrete deadline by which data is actually removed after the contract ends or after a deletion request, including backups, not only in the production database.
  • Corporate affiliation and jurisdiction. Which parent company the contracting party belongs to and which national legislation that parent company is subject to, regardless of the server location (see the section on the CLOUD Act).

The second point on this list, the data processing agreement under Art. 9 DSG, deserves closer examination. The statement "a DPA is in place" says little on its own. A robust data processing agreement contains at least three further provisions:

  • Audit rights. The contractually recorded right to verify compliance with the agreed security measures through your own checks or through an independent third party, not merely the provider's assurance without any means of verification.
  • Breach notification deadlines. A concrete deadline, specified in hours or days, within which the provider reports a detected data security breach, not just a general phrase such as "without delay". This deadline decides whether you, as the controller, can meet your own reporting obligations to the EDÖB in time at all.
  • Full disclosure of the subcontractor cascade. Not just the first level of processing, but also who those subcontractors in turn pass data to, for example a cloud infrastructure provider behind a SaaS platform, including its location. Art. 9 para. 3 DSG requires the controller's prior authorisation for any transfer to third parties. A cascade that only becomes visible at the second or third level cannot be authorised, because it was not disclosed at the time of signing.

These points do not replace individual legal advice on a specific contract. They do, however, give IT or digital leads a basis for checking, during supplier selection, whether an offer even comes with the necessary documentation before the legal review begins. As the EDÖB/Suva case in the CLOUD Act section shows, a contractual assurance of a Swiss server location alone is not enough for that. Only the combination of location details, a complete subcontractor chain and a clarified corporate affiliation answers the question that only came to light afterwards at Suva.

Where a system integration affects several of these providers at once, for example connecting ERP, CRM and the shop to the same cloud provider, a combined review is worthwhile rather than reviewing each contract separately. Find out more in our Integration Services.

Conclusion

Data sovereignty is not decided at go-live, but when reading the proposal. Anyone who knows, before signing, where the data is located, who actually controls it, whether a legal basis exists for that under Art. 16 DSG, and whether the provider supplies a complete data processing agreement, saves themselves the renegotiation that otherwise only arises once the legal department sees the finished contract for the first time. The requirements do not fundamentally change depending on the platform. They apply equally to a self-hostable solution and to a fully managed SaaS offering, only the answers differ. Anyone additionally regulated, for instance as a financial service provider, or anyone wanting to structurally rule out the provider's corporate affiliation because of the CLOUD Act, extends this review to include FINMA Circular 2018/3 or a Swiss cloud provider as an alternative. The financial framework for this review is not abstract: a breach of the disclosure or processing rules can, under Art. 61 DSG, end in a fine of up to CHF 250,000, and that fine falls personally on the person who made or approved the decision, not automatically on the company. This personal element is one more reason not to leave the checklist in this article to the next contract renewal, but to build it into the tender or the requirements specification for the next platform decision.


Planning a platform, SaaS or hosting decision and want to clarify data residency in advance?

Arcmedia has been supporting companies with digital commerce projects since 1995, from analysis through implementation to ongoing operations. Our experts are happy to advise you on your project.

Get in Touch

Always up to date with the latest trends and tips: subscribe to our newsletter.


Sources

Art. 16 paras. 1 to 3 DSG, Fedlex, Federal Act on Data Protection (DSG), SR 235.1, accessed 7 October 2026.

Art. 9 paras. 1 to 4 DSG, Fedlex, DSG SR 235.1, accessed 7 October 2026.

Federal Data Protection and Information Commissioner (EDÖB): entry into force of the revDSG on 1 September 2023, admin.ch, accessed 7 October 2026.

EDÖB, "Adequacy" ("Angemessenheit"), edoeb.admin.ch/de/angemessenheit, accessed 7 October 2026.

EDÖB, press release "New data protection framework between Switzerland and the United States", edoeb.admin.ch/de/20240815-swiss-us-dpf, accessed 7 October 2026.

AWS News Blog, "A New AWS Region Opens in Switzerland", aws.amazon.com/blogs/aws/a-new-aws-region-opens-in-switzerland/, accessed 8 October 2026.

Microsoft Learn, "List of Azure regions", learn.microsoft.com/en-us/azure/reliability/regions-list, as of 23 September 2025, accessed 8 October 2026.

Google Cloud Blog, "New GCP region in Zurich", cloud.google.com/blog/products/infrastructure/new-gcp-region-in-zurich-growing-our-support-for-swiss-and-european-businesses, accessed 8 October 2026.

Shopify Help Center, "International data transfers: onward transfers", help.shopify.com/en/manual/privacy-and-security/privacy/international-data-transfers/onward-transfers, accessed 8 October 2026.

Shopify Developer Documentation, "Hydrogen and Oxygen fundamentals", shopify.dev/docs/storefronts/headless/hydrogen/fundamentals, accessed 8 October 2026.

MLL News Portal, "EDÖB on outsourcing personal data to a Microsoft 365 cloud: doubts about the risk-based approach", mll-news.com, accessed 8 October 2026.

Swiss Financial Market Supervisory Authority FINMA, Circular 2018/3 "Outsourcing, Banks and Insurers", finma.ch, in force since 1 April 2018, accessed 8 October 2026.

Art. 17 DSG, DSG SR 235.1, reproduced at dsg.ch/kapitel02/artikel17/, accessed 8 October 2026.

Art. 60 DSG, DSG SR 235.1, reproduced at dsg.ch/kapitel08/artikel60/, accessed 8 October 2026.

Art. 61 DSG, DSG SR 235.1, reproduced at dsg.ch/kapitel08/artikel61/, accessed 8 October 2026.

Exoscale, "Swiss Cloud Hosting", exoscale.com/lp/swiss-cloud-hosting/, accessed 8 October 2026.

Infomaniak, "Discover Infomaniak", infomaniak.com/en/support/faq/71/discover-infomaniak, accessed 8 October 2026.

Author
Alexander Dominik has been working at the intersection of brand strategy, creative direction, and performance marketing for more than ten years. At Arcmedia, he leads Demand Generation and focuses on how AI, data, and automation can make modern marketing processes more efficient and effective. His experience spans SaaS, agencies, international brands, and companies across a variety of industries.