In brief
- Data location should be assessed separately for storage, processing, support and metadata.
- The primary provider is not the only recipient; subprocessors and optional services count too.
- A region setting does not by itself establish that an international transfer is lawful.
- Change notices and objection or exit routes belong in both the contract and operations.
Map the actual data flow first
Assessment begins with data types and components, not a list of countries. Only then can recipients, locations and legal roles be mapped meaningfully.
| Data category | Primary service | Further recipient or access | Locations to record | Evidence and supplementary measure |
|---|---|---|---|---|
| Prompts, outputs and uploaded files | AI application and model endpoint | Model subprocessor, file service or content-safety service | Storage, model processing and backup locations | Region setting, retention matrix, minimisation and encryption in transit |
| RAG sources and permissions | Search or vector service | Connectors, source SaaS and indexing provider | Index storage, retrieval processing and source-system regions | Subprocessor list, permission enforcement and tested deletion or revocation |
| Identity, billing and usage metadata | Account and administration service | Identity provider, billing processor and analytics service | Account database, analytics and support-access countries | Purpose limitation, role controls and contract scope for global metadata |
| Diagnostics and support content | Logging and support platform | Observability provider and authorised support personnel | Log storage, remote access and incident-investigation locations | Content-minimising logs, access approval, audit trail and transfer safeguard |
Assess the full processor chain
Under Swiss data protection law, the controller remains responsible when processing is outsourced. It must select, instruct and appropriately oversee processors. The subprocessing chain must therefore be transparent and contractually manageable.
- Name, service and location of each relevant subprocessor
- Data types and purposes assigned to each party
- How new subprocessors are announced
- Available objection, adjustment or termination rights
- Support for deletion, access requests, security and incidents across the chain
A simple decision path for each destination country
The review can follow the same sequence for the primary provider, every relevant subprocessor and remote support access. It starts with the country list in Annex 1 to the Swiss Data Protection Ordinance, not with a provider’s label such as European hosting.
- Step 1
Check adequacy
Establish whether Annex 1 to the Data Protection Ordinance covers the specific recipient, sector and disclosure, including any restrictions and footnotes. A country name alone is not enough: for the United States, for example, adequacy applies only to organisations certified under the Swiss–U.S. Data Privacy Framework. Where the concrete transfer is covered, Article 16 paragraph 1 FADP permits disclosure on that basis while the remaining privacy duties still apply.
- Step 2
Choose an Article 16 safeguard
If there is no adequate level, identify an appropriate guarantee under Article 16 paragraph 2 FADP, such as recognised standard data protection clauses. An Article 17 exception is a narrowly assessed exception, not a routine substitute.
- Step 3
Assess the actual transfer
Check whether the recipient can comply with the guarantee in light of local law, public-authority access, the data and the practical processing. Record sources, assumptions and the processor chain.
- Step 4
Add measures or stop
Where the guarantee is not sufficient in practice, add effective measures such as data minimisation or encryption with controlled keys. Do not approve the transfer if adequate protection cannot be established.
- Step 5
Document and monitor
Record the decision, safeguard, supplementary measures and review triggers, and reassess when countries, subprocessors, access or services change.
International transfers require a separate legal assessment
Swiss law permits personal data to be disclosed abroad where statutory requirements are met. If the Federal Council has not recognised an adequate level of protection, appropriate safeguards and supplementary measures may be required depending on the circumstances.
- Check the country list under the Data Protection Ordinance.
- Document contractual safeguards and their applicability to the transfer.
- Assess access under local law and the practical protection available.
- Consider minimisation, encryption and control of keys as supplementary measures.
- Assess professional, official and other secrecy duties separately.
Maintain evidence and control change
A one-off provider assessment becomes outdated. Subprocessors, regions and product architecture change, so the organisation needs a current source, review rhythm and defined response to material changes.
- Step 1
Bundle evidence
Version the contract, subprocessor list, regions, safeguards and architecture together.
- Step 2
Subscribe to change
Route provider notifications to an accountable function.
- Step 3
Assess impact
Compare new countries, services and access paths with data classes and approvals.
- Step 4
Act
Adjust configuration, object, reduce data or trigger the exit plan.
Example: European model region with global support
A provider stores customer content in an EU region but processes some diagnostic data through a global service and allows controlled support access from other countries. The organisation records these data separately, limits diagnostic content, assesses safeguards and support access and requires notice of subprocessor changes.
What to remember
Build a data-type matrix covering recipient, purpose, storage location, processing location and safeguard. A single region label is not complete evidence.
Sources and further reading
These primary sources provide further detail on definitions, technical foundations or responsible use.
Content reviewed
Reviewed 17 July 2026. General information, not legal advice. The specific legal position and applicable scope must be assessed for each use case.