Compliance
Your Client Data in Switzerland — Why It Matters and What It Actually Costs
Most Swiss SMEs don't think about data residency until a client or lawyer asks where their data is stored. Here's what DSG and GDPR actually require, and what it costs to get this wrong.
Most SMEs don't think about data residency until a client asks "where is my data stored?" or a lawyer mentions DSG compliance in a contract review. By the time that question comes up, moving your data infrastructure is expensive, disruptive, and usually happens under time pressure — not the conditions you want for a decision this important.
What the Swiss DSG Actually Requires
The revised Swiss Federal Act on Data Protection (DSG / nDSG), in force since September 2023, sets out obligations for any company processing personal data of people in Switzerland. If your business handles client records, employee data, or any personal information tied to Swiss residents, you're expected to know — and be able to demonstrate — where that data lives and who can access it.
This isn't an abstract legal formality. It affects concrete decisions: which cloud provider you use, where their servers are physically located, and whether your provider can guarantee that data doesn't get processed or accessed outside Switzerland without your knowledge.
The GDPR Overlap
If your company serves clients in the EU — even occasionally — you're also likely subject to GDPR alongside DSG. That means dual compliance: satisfying Swiss requirements for data on Swiss residents, and GDPR requirements for data on EU residents, sometimes for the same client relationship if that client has operations in both regions.
Getting this wrong isn't a one-time paperwork issue. It's ongoing exposure every time you store or transmit personal data.
Where Your Data Actually Goes with Microsoft and Google
Here's the part that surprises a lot of SME owners: by default, Microsoft 365 and Google Workspace store data in data centers that are not necessarily in Switzerland — often in the US or wherever the provider's regional infrastructure happens to sit. Both companies offer EU-based data residency add-ons for enterprise customers, but two things are worth being direct about:
- EU is not Switzerland. Even if you pay extra for EU data residency, that satisfies a different legal framework than the Swiss DSG. Your data still isn't in a Swiss jurisdiction.
- These add-ons often require enterprise-tier plans, which price out most SMEs or require negotiating custom terms that a 15-person company has little leverage to negotiate.
So the default state for most SMEs using standard M365 or Google Workspace plans is: your clients' personal data is stored outside Switzerland, and quite possibly outside the EU entirely, without anyone at the company having made that decision on purpose. It was just the default configuration nobody changed.
Rocky Cloud Hub: Every Byte, Swiss Soil
Rocky Cloud Hub was built around a simple rule: every byte of data is stored in Swiss data centers, full stop. Not as an add-on, not as an enterprise-tier upgrade — as the default and only option. Swiss law applies to how that data is handled, and there are zero foreign subprocessors in the chain. When a client asks where their data is stored, the answer is unambiguous.
This matters most for companies handling sensitive categories of data: legal documents, financial records, health-adjacent information, or anything where a client's own compliance obligations flow down to you as their service provider.
Practical Scenario: A Medical Equipment Distributor
A medical equipment distributor we worked with had a specific, hard constraint: patient-adjacent documents — order records tied to medical devices used in patient care — could not leave Switzerland under their compliance obligations. That constraint alone ruled out standard Microsoft Teams and SharePoint deployments, since guaranteeing Swiss-only data residency would have required an enterprise negotiation the company wasn't positioned to pursue, both in terms of cost and contract complexity.
Rocky was set up for their team in 24 hours, with data residency guaranteed by default rather than negotiated as a special case. No enterprise sales cycle, no custom data-processing addendum to draft and review — the compliance requirement was already satisfied by how the platform is built.
The Price of Compliance vs. the Price of a Breach
It's worth putting real numbers next to this. Under the Swiss DSG, penalties for violations — such as failing to meet data security or disclosure obligations — can reach up to CHF 250,000 per incident, assessed against the responsible individual rather than just the company. That's before accounting for the reputational damage of a client finding out their data wasn't handled the way they assumed, or the cost of an emergency migration under regulatory pressure.
Compare that to the cost of choosing Swiss-hosted infrastructure from the start: no additional line item, no enterprise negotiation, just a platform that stores data where you need it stored by default.
Not Just Compliance — Trust
Beyond the legal exposure, there's a simpler commercial argument. Being able to tell a client, plainly and without caveats, "your data never leaves Switzerland" is a trust signal that matters increasingly in B2B sales — especially with clients in finance, healthcare, legal services, or the public sector, where data handling questions come up early in procurement conversations.
Saying it and meaning it — because the infrastructure actually guarantees it, not because a sales rep said so — is a different conversation than hoping the question doesn't come up.
Ready to Try Rocky Cloud Hub?
Swiss-hosted collaboration — files, chat, tasks, search. Setup in 24h.