Appoint us
EU representative established in Prague acting for a company based in Switzerland

REP27 · Switzerland

Article 27 GDPR · Switzerland

EU representative for Swiss companies.

Switzerland is surrounded by Member States, holds an adequacy decision, and has its own modern data protection act. All three facts make Swiss companies assume the European question is settled. It is not: geography, adequacy and domestic compliance each solve something other than Article 27, which asks only whether someone inside the Union can be contacted.

Switzerland under two regimes: the revised Federal Act on Data Protection at home and the GDPR when reaching people in the European Union
Two regimes, two contact points, no overlap between them.

Why adequacy is the wrong tool for this

The Commission recognised Switzerland as providing adequate protection, and the recognition was maintained after the nFADP came into force. That decision governs transfers.

Article 27 governs contactability. It requires a designation in writing naming an entity established in the Union, so a data subject in Lisbon and the authority in Lisbon both have somewhere to write. No adequacy decision creates that address, which is why Japan, Canada, the United Kingdom and Switzerland — all adequate — are all in scope.

The two are so routinely confused that we treat it as the first thing to check on any Swiss file. Adequacy in the transfer register, representative in the privacy notice.

When a Swiss company crosses the line

When a Swiss company falls within Article 3(2) of the GDPR: shipping to the EU, euro pricing, analytics on EU visitors, B2B software used by EU staff
Territorial scope, not turnover, decides it.

The typical Swiss profile is a watch or luxury goods brand shipping across the border, a fintech with European users, a pharmaceutical or medtech supplier with EU clinical partners, or a private bank whose site is read across Europe.

Switzerland compared with its neighbours

CountryStatusArticle 27 representative
Germany, France, Italy, AustriaEU Member StateNot needed
Norway, Iceland, LiechtensteinEEA — GDPR applies directlyNot needed
SwitzerlandOutside EU and EEA, adequateRequired
United KingdomOutside EU, adequateRequired

Liechtenstein is the instructive case: a smaller neighbour, also outside the EU, but inside the EEA — and therefore exempt where Switzerland is not.

The Liechtenstein comparison, and why it matters

Liechtenstein is the clearest illustration of why geography does not decide this. It is smaller than most Swiss cantons, is not an EU Member State, shares a currency and a customs area with Switzerland, and yet its companies need no Article 27 representative — because it joined the European Economic Area, and the GDPR applies there directly.

Switzerland negotiated bilateral agreements instead of EEA membership, and data protection was never part of that package. The result is that two neighbouring countries, closely integrated with each other, sit on opposite sides of Article 3(2). A company in Vaduz processing data of people in Germany is inside the GDPR's own territory; a company twenty kilometres away in Buchs is a third-country controller.

The practical consequence for Swiss groups with a Liechtenstein entity is worth checking carefully: if the EEA entity genuinely carries out the processing, there may be an establishment in the Union's data protection area and no designation is needed. If it is a holding shell, there is not, and the Swiss parent is squarely in scope.

Questions from Swiss companies

Switzerland has an adequacy decision. Why is a representative still needed?

Adequacy means personal data may flow from the Union to Switzerland without Standard Contractual Clauses. It says nothing about whether a person in Spain or Poland can contact you. Article 27 is about contactability, and it applies to every company established outside the Union regardless of adequacy.

Is Switzerland in the EEA?

No. Norway, Iceland and Liechtenstein are in the EEA and apply the GDPR directly, so their companies need no representative. Switzerland is outside both the EU and the EEA, which is why Swiss companies are in exactly the same position as Japanese or Canadian ones.

Does complying with the revised Swiss act cover the GDPR?

No. The nFADP is Swiss law, supervised by the Federal Data Protection and Information Commissioner. The GDPR is EU law, supervised by twenty-seven other authorities. Compliance programmes built for one do not discharge the other.

We only sell in Switzerland but our site is in German and French. Are we caught?

Language alone is not decisive when it is also your domestic language. What matters is whether the offering is directed at people in the Union: euro pricing, shipping options to EU addresses, EU-targeted advertising, or analytics profiling European visitors.

Can our Swiss lawyer be the EU representative?

Only if they have an establishment in a Member State. A firm based in Zurich or Geneva cannot be designated under Article 27, because the representative must be established where the data subjects are.

What about the Swiss representative requirement in the other direction?

The nFADP has its own rules for foreign controllers with a Swiss link. It is a separate obligation with a separate contact point, and it does not interact with your Article 27 designation.

Do we need a UK representative too?

Only if you also target people in the United Kingdom. Since 2021 that is a third regime with its own regulator, requiring its own designation.

Check what your Swiss site says today

We read your public privacy notice and tell you in ten seconds whether a representative is named.

Run the free check   See pricing
European supervisory authority a Swiss company may be addressed by
European supervisory authority a Swiss company may be addressed by