Most Swiss SMEs cannot answer a deceptively simple question: where is their data, with which processors, under which law? CRM, email, accounting, backups – every tool is a processor, and every processor has processors of its own. That is exactly what the FADP expects of you: to know. The register of processing activities, the framework governing outsourcing, and control over transfers abroad all rest on that knowledge. A first serious inventory takes one morning.
Why almost no SME has done this inventory
Tools accumulate one decision at a time. An email service at incorporation, accounting software recommended by the fiduciary, a CRM adopted with the first salesperson, an HR platform for payslips, automatic backups switched on one cautious evening. Each choice, taken in isolation, was reasonable. Ten years on, no one holds the full picture – because keeping it was never anyone's job.
The most reliable starting point is neither the owner's memory nor the IT provider: it's the payments. Every subscription leaves a trace in the accounts or on the company card, and the resulting list is almost always longer than the one you'd have written from memory. In 2026, your SME uses the cloud – that much is settled. What remains is knowing with whom, where, and under which law. That has become my first scoping question: before any automation or AI project, the data flow comes before the choice of tool.
What exactly does "your SME's data" cover?
Four categories cover the essentials. Customer data: contact details, history, correspondence, sometimes financial information. Employee data: salaries, medical certificates, evaluations – the FADP classifies some of this as sensitive personal data, which calls for stronger protection. The company's own financial and tax data. And contractual documents, which fall less under data protection than under trade secrecy, but which no owner wants to see circulating freely.
The distinction matters: the FADP protects personal data – data concerning identifiable natural persons. Your trade secrets are not its subject. Yet they sit on the same drives, with the same processors – the inventory serves both concerns in a single move.
What the FADP expects of you, put simply
The Federal Act on Data Protection – the revised version, in force since September 1, 2023, often referred to as the nFADP – rests on a logic I'd summarise as follows: you remain responsible for the data you process, even when you entrust it to others[1].
Three mechanisms bear directly on the question of location. First, the register of processing activities. It's the documentary map of your data: which categories, for which purposes, with which processors, in which countries, with which protective measures. The law provides an exemption for companies with fewer than 250 employees whose processing presents limited risk – many SMEs qualify. The exercise remains the shortest route to regaining control regardless of whether the exemption applies to you.
Next, outsourcing to processors. Entrusting data to a provider is lawful, provided a contract governs it, the provider offers adequate security guarantees, and it does not in turn subcontract without your authorisation. This last point is the most overlooked: your invoicing tool has a hosting provider, which has its own suppliers in turn. The chain exists whether you're aware of it or not.
Finally, transfers abroad. Disclosing personal data outside Switzerland requires that the destination state ensure an adequate level of protection – the Federal Council maintains the list – or that safeguards, usually contractual, compensate for the gap. It's impossible to apply this rule without knowing which countries your tools host data in: everything comes back to the inventory. For specific cases, the statutory text is authoritative; here I describe the mechanics, not your particular situation.
What if the vendor is American? The extraterritorial question, without drama
Some of your processors operate under foreign law, and the most-discussed case is American. A 2018 federal law, the CLOUD Act, allows US authorities to request data from providers subject to their jurisdiction – regardless of which country the servers sit in. Its exact scope against Swiss law is debated among lawyers, and I won't pretend to settle what the courts have not yet fully clarified.
What I take from this for an SME fits in one word: classify. The point isn't to avoid every American vendor – you probably use several excellent ones – but to identify the data that would sit poorly with access by a foreign authority: salaries, health data, certain client files, an ongoing dispute. For that category, hosting location and the law applicable to the vendor become first-order criteria again. I detailed what location actually changes – and what it doesn't solve – in Hosting in Switzerland: what it actually changes.
Where to start, in a single morning
The exercise requires no software. Pull the payment statements from the last twelve months, highlight every software subscription or online service, then answer four questions per tool:
- What data lives there – customers, employees, finances, contracts?
- Where is it hosted, and under which law does the vendor operate? The answer is usually in the terms of service or privacy policy.
- Who has access within the company, and were accounts revoked when employees left?
- How would you get your data out – does a full export exist, and in what format?
The result fits on a single spreadsheet page. It's the embryo of a register of processing activities, and above all a decision-making tool: what stays where it is, what deserves to be moved, what needs a corrected contract. The last column – exit – sets up a topic I've covered separately in How to migrate data out of a SaaS without breaking anything; the underlying question, ownership, is addressed in Who actually owns your tool, your code, your data?.
This is also where I start every scoping conversation for a custom solution: connecting automation to flows nobody has mapped means building on land whose owner is unknown. And to place the inventory among an SME's other digital priorities, the overall framework is set out in What should a Swiss SME do about AI in 2026?.
Key takeaways
— Every online tool is a processor, and you remain responsible for the personal data you entrust to it. — Register of processing activities, processor contracts, transfers abroad: all three FADP mechanisms assume you know where your data is. — One morning and a spreadsheet are enough for the first inventory: payment statements in hand, four questions per tool.
FAQ
Does my ten-person SME need to keep a register of processing activities? The FADP allows companies with fewer than 250 employees to be exempted from the register when their processing presents limited risk, and many SMEs fall within that scope. The exemption notably lapses when sensitive personal data is processed on a large scale. My practical advice: do the inventory anyway – it costs one morning and pays off well beyond compliance. For a precise assessment of your situation, the statutory text is authoritative.
Does a Swiss hosting provider automatically make me compliant? No. Hosting in Switzerland simplifies the question of transfers abroad for that one layer, but compliance depends first on your processes: informing data subjects, proportionality of collection, processor contracts, access management. An excellent host doesn't compensate for a password that's been shared for years.
What counts as a transfer abroad under the FADP? Any disclosure of personal data outside Switzerland – including simply hosting it on servers located abroad. Transfers are permitted to states whose protection level the Federal Council recognises; to other states, additional safeguards, usually contractual, are required. If in doubt about a country or a tool, refer to the statutory text and the official list.
What does an SME that does nothing actually risk? The FADP provides for fines of up to CHF 250,000 for certain intentional violations, directed at the responsible individuals rather than the company. The more likely risk, however, is operational: being unable to respond to an access request, to document an outsourcing arrangement, or to cleanly exit a tool exactly when you need to.
You couldn't say today where your data actually lives? The AI Usage Diagnostic: sixty minutes to lay out your real data flows, identify what deserves a custom build, what stays in SaaS, and what needs no AI at all. Book a diagnostic
Sources
[1] Federal Act on Data Protection (FADP), revision of September 25, 2020, in force since September 1, 2023. www.fedlex.admin.ch/eli/cc/2022/491/fr [↩]
Jérôme Deshaie is CEO and founder of MCVA Consulting SA, an augmented agency based in Valais, Switzerland. Fifteen years serving major international brands, now working directly with Swiss SMEs. Background.