Search

What are you looking for?

Search our services, use cases and practical insights.

Enter at least 2 characters

Popular starting points

Data & governance

How should data locations, subprocessors and international transfers be assessed?

An EU region label rarely describes the complete data flow. Model processing, storage, support, safety logs and connectors may involve different providers and countries.

The short answer

For each data type, an organisation should document who processes it, for what purpose, where storage and processing occur and which subprocessors are involved. Where personal data is disclosed abroad, adequacy, appropriate safeguards and remaining risks must also be assessed under Swiss law.

In brief

  • Data location should be assessed separately for storage, processing, support and metadata.
  • The primary provider is not the only recipient; subprocessors and optional services count too.
  • A region setting does not by itself establish that an international transfer is lawful.
  • Change notices and objection or exit routes belong in both the contract and operations.

Map the actual data flow first

Assessment begins with data types and components, not a list of countries. Only then can recipients, locations and legal roles be mapped meaningfully.

Map the actual data flow first
Data categoryPrimary serviceFurther recipient or accessLocations to recordEvidence and supplementary measure
Prompts, outputs and uploaded filesAI application and model endpointModel subprocessor, file service or content-safety serviceStorage, model processing and backup locationsRegion setting, retention matrix, minimisation and encryption in transit
RAG sources and permissionsSearch or vector serviceConnectors, source SaaS and indexing providerIndex storage, retrieval processing and source-system regionsSubprocessor list, permission enforcement and tested deletion or revocation
Identity, billing and usage metadataAccount and administration serviceIdentity provider, billing processor and analytics serviceAccount database, analytics and support-access countriesPurpose limitation, role controls and contract scope for global metadata
Diagnostics and support contentLogging and support platformObservability provider and authorised support personnelLog storage, remote access and incident-investigation locationsContent-minimising logs, access approval, audit trail and transfer safeguard

Assess the full processor chain

Under Swiss data protection law, the controller remains responsible when processing is outsourced. It must select, instruct and appropriately oversee processors. The subprocessing chain must therefore be transparent and contractually manageable.

  • Name, service and location of each relevant subprocessor
  • Data types and purposes assigned to each party
  • How new subprocessors are announced
  • Available objection, adjustment or termination rights
  • Support for deletion, access requests, security and incidents across the chain

A simple decision path for each destination country

The review can follow the same sequence for the primary provider, every relevant subprocessor and remote support access. It starts with the country list in Annex 1 to the Swiss Data Protection Ordinance, not with a provider’s label such as European hosting.

  1. Step 1

    Check adequacy

    Establish whether Annex 1 to the Data Protection Ordinance covers the specific recipient, sector and disclosure, including any restrictions and footnotes. A country name alone is not enough: for the United States, for example, adequacy applies only to organisations certified under the Swiss–U.S. Data Privacy Framework. Where the concrete transfer is covered, Article 16 paragraph 1 FADP permits disclosure on that basis while the remaining privacy duties still apply.

  2. Step 2

    Choose an Article 16 safeguard

    If there is no adequate level, identify an appropriate guarantee under Article 16 paragraph 2 FADP, such as recognised standard data protection clauses. An Article 17 exception is a narrowly assessed exception, not a routine substitute.

  3. Step 3

    Assess the actual transfer

    Check whether the recipient can comply with the guarantee in light of local law, public-authority access, the data and the practical processing. Record sources, assumptions and the processor chain.

  4. Step 4

    Add measures or stop

    Where the guarantee is not sufficient in practice, add effective measures such as data minimisation or encryption with controlled keys. Do not approve the transfer if adequate protection cannot be established.

  5. Step 5

    Document and monitor

    Record the decision, safeguard, supplementary measures and review triggers, and reassess when countries, subprocessors, access or services change.

International transfers require a separate legal assessment

Swiss law permits personal data to be disclosed abroad where statutory requirements are met. If the Federal Council has not recognised an adequate level of protection, appropriate safeguards and supplementary measures may be required depending on the circumstances.

  • Check the country list under the Data Protection Ordinance.
  • Document contractual safeguards and their applicability to the transfer.
  • Assess access under local law and the practical protection available.
  • Consider minimisation, encryption and control of keys as supplementary measures.
  • Assess professional, official and other secrecy duties separately.

Maintain evidence and control change

A one-off provider assessment becomes outdated. Subprocessors, regions and product architecture change, so the organisation needs a current source, review rhythm and defined response to material changes.

  1. Step 1

    Bundle evidence

    Version the contract, subprocessor list, regions, safeguards and architecture together.

  2. Step 2

    Subscribe to change

    Route provider notifications to an accountable function.

  3. Step 3

    Assess impact

    Compare new countries, services and access paths with data classes and approvals.

  4. Step 4

    Act

    Adjust configuration, object, reduce data or trigger the exit plan.

Example from day-to-day business

Example: European model region with global support

A provider stores customer content in an EU region but processes some diagnostic data through a global service and allows controlled support access from other countries. The organisation records these data separately, limits diagnostic content, assesses safeguards and support access and requires notice of subprocessor changes.

What to remember

Build a data-type matrix covering recipient, purpose, storage location, processing location and safeguard. A single region label is not complete evidence.

Sources and further reading

These primary sources provide further detail on definitions, technical foundations or responsible use.

Content reviewed

Reviewed 17 July 2026. General information, not legal advice. The specific legal position and applicable scope must be assessed for each use case.

Would you like to apply this to your situation?

Together, we clarify what makes sense for your process, data and systems – in plain language and without unnecessary complexity.

Discuss Your Project