Compliant IT outsourcing in Switzerland rests on one simple principle: you can delegate the operations, never the responsibility. The Swiss Data Protection Act (FADP) fully allows IT subcontracting, provided a contract governs the data processing, you know where the data is stored and by whom, and the provider offers sufficient guarantees. Here is what that means concretely in 2026 for an SME, from choosing the provider to the contract clauses.
What the FADP says about IT outsourcing
Your managed IT provider, your host and your cloud email supplier are processors within the meaning of the FADP: they process personal data on your behalf. The law sets three conditions for this delegation: the processing must be governed by a contract or by law, the provider may only process the data within the framework you have defined, and it must guarantee a level of data protection equivalent to yours.
The practical consequence: outsourcing without a written data processing agreement means being non-compliant — even if the provider does its job well. And since FADP penalties target the responsible individuals (up to CHF 250,000 for intentional offences), the subject deserves more than a handshake. Our FADP 2026 guide for SMEs covers the general framework.
The central question: where is your data, really?
"Your data is with us" means nothing. IT outsourcing actually involves several locations to verify one by one:
- Production data: servers, files, email — with which host, in which country?
- Backups: often with a different supplier than production, sometimes outside Switzerland without anyone having checked
- The provider's tools: monitoring, ticketing, remote access — these tools see your screens and systems, and are frequently American cloud services
- The provider's subcontractors: outsourced helpdesk, third-party datacenter, tool vendors
Swiss hosting is not an absolute legal obligation, but it radically simplifies compliance: no international transfer analysis, no exposure to the US CLOUD Act. Our article on migrating to a Swiss cloud details these sovereignty issues.
The clauses that make outsourcing compliant
The contract with your IT provider must explicitly cover:
- The subject of the processing: which categories of data, for which purposes
- Security measures: encryption, access control, MFA, logging
- Location: data, backups and tools, with an obligation to inform you of any change
- Sub-processors: list, and the right to be informed of or object to a change
- Data breaches: obligation to alert you without delay, with the information needed to assess the risk and notify the FDPIC if necessary
- Contract end: return or destruction of the data, handover of documentation and access
These clauses largely overlap with those of a good managed IT contract — SLA, scope, reversibility — which we detail in our contract comparison guide. Compliance and service quality are negotiated at the same moment: before signing.
Regulated sectors: one notch higher
Fiduciaries, medical practices, lawyers and notaries add professional secrecy to the FADP obligations: the confidentiality of client or patient data is protected under criminal law. For these sectors, outsourcing requires a provider that understands these constraints — Swiss hosting, traced access, reinforced contractual confidentiality. It is a topic in its own right, covered in our top 7 of regulated managed IT and in our pages for fiduciaries, medical practices and lawyers and notaries.
The approach in five steps
- 1. Inventory your personal data and where it lives (the foundation of all FADP compliance)
- 2. Question every existing or candidate IT provider: location, subcontractors, security, breach procedure — in writing
- 3. Contractualise: data processing agreement or amendment to existing contracts
- 4. Control access: named accounts, least privilege, MFA, annual review
- 5. Document everything in your record of processing activities
If you do not know where you stand, an FADP audit maps your data and produces a documented action plan. And if you are looking for a provider that ticks these boxes by design — data operated primarily on Swiss infrastructure, documented subcontractors, exit clause included — that is how we built AlpenCare, our managed IT for SMEs, up to its Sovereign tier designed to reduce dependencies on foreign clouds.
Frequently asked questions
Is IT outsourcing compatible with the Swiss Data Protection Act?
Yes, provided it is done properly: the FADP explicitly allows data processing to be subcontracted. Your company remains responsible, but may entrust operations to a provider if a contract governs the processing, if the provider guarantees an adequate level of protection and if you know where your data is stored and who accesses it.
What must the contract with an IT provider contain to be FADP-compliant?
A data processing agreement (or dedicated clauses) specifying: the categories of data processed, the purposes, the security measures, the location of data and backups, the list of sub-processors, the obligations in the event of a data breach, and what happens to the data at the end of the contract. Without that written framework, your compliance rests on trust, not on law.
Must a Swiss SME's data stay in Switzerland?
No, the FADP does not require Swiss hosting: it requires that transfers abroad go to countries with an adequate level of protection or under appropriate guarantees. In practice, Swiss hosting simplifies everything: no transfer analysis, no exposure to the US CLOUD Act, and a clear argument towards your clients. For professions bound by professional secrecy, it is strongly recommended.
Who is liable if data leaks at the IT provider?
Your company remains responsible within the meaning of the FADP: you must notify the FDPIC if the risk is high, and it is your reputation at stake. The provider has its own contractual obligations and may be liable towards you, but outsourcing never transfers the legal responsibility for the processing.
How do you verify that an IT provider is actually compliant?
Ask for written evidence: exact location of data and tools (monitoring, ticketing, remote access), list of sub-processors, breach management procedure, and references in demanding sectors. A compliant provider answers these questions in writing without difficulty; evasive answers are a warning signal.
Written by
David Cunha
Co-founder · Technical director, AlpenData
A computer engineer with over 10 years of experience managing systems, networks and infrastructure, David helps Swiss SMEs with their IT, security and compliance.
More about AlpenData →