Every Swiss financial institution we speak to has the same two beliefs about cloud migration: that it is now permitted, and that it is now complicated. Both are true, but not for the reasons usually given.

The revised Federal Act on Data Protection did not introduce a data-residency requirement. What it sharpened is accountability: you must be able to demonstrate, on request, where client-identifying data sits, who can reach it, and under what legal basis.

What actually blocks a migration

Three things, in this order.

  • Client-identifying data spread across systems nobody mapped. The migration cannot be scoped because the data cannot be located.
  • Outsourcing arrangements that predate the current rules. Contracts exist, but not the evidence trail the rules now expect.
  • Access paths through third parties. Support vendors with standing production access are the finding that most often stops a programme.

None of these are cloud problems. They are inventory problems that the cloud makes visible.

Does the revised FADP require Swiss data residency?

No. The revised FADP does not mandate that personal data remain in Switzerland. Transfers abroad are permitted where the destination provides adequate protection or where appropriate safeguards are in place. Residency is frequently adopted as an internal policy or a supervisory expectation, which is a different thing from a legal requirement and should be argued on its own merits.

What has to be documented before a migration?

At minimum: a data inventory that identifies client-identifying data by system, a record of processing activities, the legal basis for any cross-border transfer, and a demonstrable access model showing who can reach production data and how that access is granted, reviewed and revoked.

A sequence that works

  1. Inventory client-identifying data before choosing a target architecture. The inventory usually changes the architecture.
  2. Fix the access model in the current estate first. Migrating a broken access model reproduces it at scale.
  3. Migrate one non-critical workload end to end, including the evidence trail. The first migration is a rehearsal for the audit, not for the technology.
  4. Only then plan the core.

Institutions that follow this sequence tend to move faster overall, because the supervisory conversation stops being a blocker and becomes a checklist.

Is this different for a 30-person asset manager?

The obligations are the same; the effort is not. A smaller institution has fewer systems, fewer third parties and a shorter access list, so the inventory that takes a large bank a year can take a small one a fortnight. What catches smaller firms out is assuming the rules are aimed at someone else — supervisory expectations follow the data, not the headcount.

The practical difference is that a small firm cannot absorb a finding discovered during a migration. It has to do the inventory first, because there is no parallel team to fix it while the programme continues.

The access model is the whole exercise

Everything in the evidence pack except one item is documentation of decisions already made. The access model is different: it is the thing most likely to be wrong today.

Standing production access held by an integrator, a shared administrator account, a support path that bypasses your identity provider — these exist in almost every estate we assess, predate the current rules, and are invisible until someone asks for the list. Produce the list before a regulator or a client's due-diligence questionnaire does.

What the evidence pack has to contain

ArtefactQuestion it answersWho signs it
Data inventoryWhere is client-identifying data?Data owner
Record of processingWhy are we processing it?Compliance
Transfer basisOn what basis does it leave Switzerland?Legal
Access modelWho can reach production, and how is that revoked?IT and risk
Exit planWhat happens if the provider fails?Operations

Smaller institutions often assume this pack is disproportionate at their size. It is not — it is shorter, because the estate is smaller. What does not scale down is the requirement to have it.

The authoritative texts are published by the Federal Data Protection and Information Commissioner and in Fedlex; read those rather than a vendor's summary of them.

What this costs in time

The wider compliance surface is set out in our FADP compliance checklist, and the security priorities that usually surface alongside it are in cybersecurity priorities for a Swiss SME.

Budget one to three months for the inventory in a mid-sized institution, and expect it to surface at least one access finding that has to be remediated before anything moves. That finding is the value of the exercise, not a delay to it.

Working on this right now?

Tell us where you are in two questions. A consulting partner reviews every enquiry within 2 business days.