Compliance

Top 7 of regulated managed IT in Switzerland

Fiduciaries, medical practices, lawyers: the 7 requirements of managed IT that respects professional secrecy and the FADP in Switzerland, with the questions to ask.

David Cunha

David Cunha

Published on June 17, 2026 7 min read
COMPLIANCE

Managed IT for a regulated sector — fiduciary, medical practice, law or notary firm — must guarantee seven things that standard managed IT does not always guarantee: controlled Swiss hosting, named and traced access, reinforced contractual confidentiality, encrypted backups, documented breach management, full reversibility and documentation that stands up to an inspection. Here are those seven requirements, and the questions that verify each one before signing.

1. Swiss hosting, with no hidden exception

For data covered by professional secrecy, Swiss location must cover production, backups and the provider's tools (monitoring, ticketing, remote access) — the last point being the one almost nobody checks. American cloud suppliers remain subject to the CLOUD Act wherever the servers physically sit, a point detailed in our article on the Swiss cloud. Question to ask: "List, in writing, every location where my data and your tools are hosted."

2. Named, traced, revocable access

Every provider access to your systems must be individual (no shared "admin" account), protected by MFA, logged and immediately revocable. In an inspection or incident, you must be able to say who accessed what and when. Question to ask: "Can you provide the log of your technicians' access to my systems over the last month?"

3. Reinforced contractual confidentiality

The standard confidentiality clause of an IT contract is not enough when breaching professional secrecy is a criminal offence. The contract must explicitly extend the confidentiality obligation to data covered by secrecy, bind each of the provider's employees individually, and survive the end of the contract. Question to ask: "Does your confidentiality clause mention the professional secrecy I am bound by?"

7 requirements
separate regulated managed IT from standard managed IT
100% Swiss
production, backups and the provider's tools included
CHF 100–150
per workstation per month, the top of the standard range

4. Encrypted, tested backups

Backups contain the same secrets as production — client files, patient data, deeds — but leave your infrastructure. They must be encrypted before leaving, stored in Switzerland, and tested through regular documented restorations. Question to ask: "When did you last test a full restoration, and can you show me the report?"

5. Documented breach management

The FADP requires notifying the FDPIC "as soon as possible" for high-risk breaches — and for a regulated sector, almost any leak is high-risk. Your provider must contractually commit to alerting you without delay, with the factual elements needed for your assessment. Our FADP 2026 guide details this procedure. Question to ask: "Describe your exact procedure if you detect an intrusion on my systems on a Saturday evening."

6. Full reversibility

Changing providers must never endanger your data or hold you hostage. The contract must guarantee the return of all data in a usable format, the handover of passwords and documentation, and certified destruction of remaining copies at the provider. The precise clauses are detailed in our managed IT contract guide.

7. Documentation that stands up to inspection

In an inspection, dispute or disaster, you must be able to demonstrate diligence: system inventory, access register, processing agreements, restoration test reports, monthly reports. A provider for regulated sectors produces this documentation continuously, without you having to ask. It is what turns "we are careful" into evidence.

How to use this list

These seven requirements serve as a tender grid: put the seven questions in writing to each candidate and compare the answers. A provider used to regulated sectors answers precisely and promptly; vague or oral answers disqualify. Complete with the general criteria of our guide on choosing your IT provider.

At AlpenData, managed IT for regulated sectors is a core focus of AlpenCare — up to the Sovereign tier, designed to reduce dependencies on foreign clouds. We notably work with fiduciaries, medical practices and law and notary firms in French-speaking Switzerland.

Frequently asked questions

What is 'regulated' managed IT?

Managed IT designed for companies subject to reinforced legal obligations on their data: professional secrecy (lawyers, notaries, doctors, fiduciaries), banking secrecy or sector-specific requirements. Beyond the FADP that applies to everyone, the provider must guarantee controlled hosting, traced access, reinforced confidentiality and documentation that stands up to an inspection.

Can a medical practice outsource its IT?

Yes, and most do: electronic patient records require skills few practices have in-house. The condition: a provider that respects the framework of medical secrecy — health data hosted in Switzerland, named and traced access, a written confidentiality commitment, and technicians aware of the medical context.

Does professional secrecy forbid American clouds?

Not formally, but it seriously complicates them: American suppliers are subject to the CLOUD Act and cannot contractually guarantee that US authorities will never access the data. For data covered by professional secrecy, Swiss hosting is the lowest-risk path, recommended by most professional associations.

What must an IT provider log for a regulated sector?

Who accessed what and when: connections to servers and sensitive data, remote interventions on workstations, changes to access rights. These logs protect both parties: they demonstrate your diligence during an inspection and allow any incident to be investigated. A provider that does not log its own access is a blind spot in your compliance.

How much does managed IT cost for a regulated sector?

Expect the upper end of the standard range, i.e. CHF 100 to 150 per workstation per month: Swiss hosting, encrypted backups, traceability and reinforced documentation require more rigour, not necessarily more technology. The price gap with basic managed IT is small compared with the risk covered — breaching professional secrecy is a criminal offence.

David Cunha

Written by

David Cunha

Co-founder · Technical director, AlpenData

A computer engineer with over 10 years of experience managing systems, networks and infrastructure, David helps Swiss SMEs with their IT, security and compliance.

More about AlpenData →

First IT recommendations

Want to know where your SME is exposed?

Request a 30-minute conversation with an AlpenData engineer. You walk away with first recommendations on your security, your backups and your IT priorities, with no commitment.