The Swiss-US Data Privacy Framework has permitted data transfers to DPF-certified companies since August 2024; read about the obligations that now apply.
In short: The Swiss-US Data Privacy Framework has permitted transfers from Switzerland to DPF-certified US companies without additional safeguards since the Federal Council decision of 14 August 2024. The prerequisite is that the US organisation has explicitly self-certified for Switzerland. The corresponding amendment to Annex 1 of the Data Protection Ordinance entered into force on 15 September 2024. If the recipient is not certified, standard contractual clauses or other safeguards remain mandatory.
In short: - Only US companies that have explicitly self-certified for Switzerland may transfer data without additional safeguards. - If the recipient is not certified, standard contractual clauses remain the safe alternative. - Certification must be renewed annually; otherwise, the benefits lapse, and data may need to be deleted or returned. - Before each transfer, verify whether the US partner is listed on the official data list and whether the certification includes Switzerland. - In case of suspected violations or revocation of certification, independent complaint mechanisms and US authorities are available.
Table of Contents
- Core Components of the Adequacy Decision and Legal Basis
- Practical Compliance Steps for Swiss Companies
- Mechanics of Self-Certification, Re-Certification, and Consequences of Revocation
- Enforcement, Complaint Channels, and Remaining Risks
- Contractual Recommendations and Governance: SCCs as Fallback and Contract Clauses
- Practical Note: How We Support Clients in Implementation
- Professional Perspective: Opportunities and Precautions
- Support in Implementing the Swiss-US DPF
- FAQ
- Sources
Core Components of the Adequacy Decision and Legal Basis
The Federal Council determined on 14 August 2024 that certified US companies offer an adequate level of data protection. The amendment to Annex 1 of the Data Protection Ordinance entered into force on 15 September 2024 and now lists the United States as a country with adequate protection, but only with reference to certified organisations. This is an important distinction: Adequacy does not apply to the USA as a whole, but exclusively to companies that have submitted to the framework.
Legally, the construct is based on several US instruments, including Executive Order 14086, the newly established Data Protection Review Court, and supplementary guidelines on the proportionality of surveillance measures. These elements are intended to limit access by US authorities to transferred data and to provide data subjects with a legal remedy.
Crucial for in-house counsel is the distinction between formal adequacy and substantive equivalence:
- The adequacy decision is a legal risk allocation by the Federal Council, not a statement that the protection is identical to that under Swiss data protection law.
- The FDPIC points out that implementation is being monitored and that the assessment may change.
- For companies, this means: formal facilitation of transfers, but no exemption from the duty of care.
Practical Compliance Steps for Swiss Companies
The formal lawfulness of a data transfer depends on a single, verifiable fact: the listing of the recipient. Those who do not check this rely on an assertion rather than proof.
- Before each transfer, verify whether the US partner is listed on the official Data Privacy Framework List and whether the certification explicitly includes Switzerland, not just the EU.
- Adapt data protection policies and data processing agreements: specify the legal basis, link the certification evidence, and add dispute resolution clauses in accordance with the requirements of the Framework.
- Maintain an inventory of all data flows to the USA, including responsible parties, review date, and next re-check.
- Determine who within the company is responsible for the recurring status check, before a contract is signed, not afterwards.
Where the recipient is not certified or the certification remains unclear, standard contractual clauses remain the safest basis. In this case, document which clauses were used and when they were reviewed, so that a subsequent response to the FDPIC or a contractual partner can be provided without delay.
Pro Tip: Save a dated screenshot of the listing at each initial check, as the Data Privacy Framework List can change without you being automatically notified.
Mechanics of Self-Certification, Re-Certification, and Consequences of Revocation
A US organisation does not automatically become part of the framework. It must actively self-certify via dataprivacyframework.gov, acknowledge the principles, and have the commitment authorised by a person responsible within the company. This certification is not a one-time act.
- The organisation must re-certify annually; otherwise, it loses its status and the benefits of adequacy lapse.
- Synchronising deadlines with an existing EU-DPF certification is possible, which reduces organisational effort for the US side.
- If an organisation is removed from the list, it must return, delete, or continue to protect received personal data in accordance with the principles, as long as it still holds them.
For Swiss companies, this leads to a clear consequence: The partner's status is not a static fact, but a state that must be monitored continuously.
Enforcement, Complaint Channels, and Remaining Risks
If a data subject loses confidence in the data processing of a certified US company, several instances are available. The framework provides for independent complaint mechanisms to which data subjects should first turn.
- The FDPIC accepts complaints via the Model Complaint Form and forwards them to the competent US authority.
- On the US side, the FTC and the Department of Transportation review violations of the commitments made by certified companies.
- The newly established Data Protection Review Court can be invoked if a data subject suspects disproportionate access by US intelligence services.
The procedures have deadlines, such as a duty to respond by the authority concerned within 45 days. For companies, this means: Document all communication with partners regarding DPF status in writing, as in a dispute, proof counts, not memory.
Contractual Recommendations and Governance: SCCs as Fallback and Contract Clauses
Even with a certified partner, residual uncertainty remains: The certification can be revoked, a court may restrict the decision in the future, or the partner may violate its own commitments. Securing standard contractual clauses as a fallback is therefore not over-regulation, but a reasonable risk allocation.
- Include a purpose limitation clause that restricts data use to the purpose agreed in the contract.
- Contractually limit onward transfer to third parties and require a notification obligation for sub-processors.
- Oblige the partner to inform you immediately if the DPF certification expires or is revoked.
- Regulate the deletion or return of data for the case where the certification ends and no alternative safeguard applies.
On the governance side, a fixed review cycle is worthwhile: one responsible person per contractual relationship, an annual re-check parallel to the partner's re-certification, and a short report to management or the compliance function. Such clauses can be well integrated into existing contracts with an international nexus, rather than being maintained as a separate document.
Pro Tip: Anchor the SCC fallback clause as a condition subsequent that automatically takes effect as soon as the partner's DPF certification ends, instead of renegotiating a contract amendment only in the event of a dispute.
Practical Note: How We Support Clients in Implementation
Our data protection checks under the revised DSG include verifying whether a US partner is correctly certified and adapting the corresponding AI telephone assistants and automated customer service solutions contract clauses. We review and negotiate cross-border contracts in German, English, French, Ukrainian, and Russian, without external translation. This shortens coordination in international contractual relationships and reduces the risk of translation errors in data protection clauses.
Professional Perspective: Opportunities and Precautions
The Swiss-US DPF facilitates daily operations because not every transfer needs to be individually secured with standard contractual clauses. However, the uncertainty is only shifted, not eliminated: It now lies in monitoring the certification status rather than in contract design. Those who believe the topic is finished with the decision underestimate how quickly a certification can be revoked. Our priority for in-house counsel: immediate status check of all US partners, anchoring SCCs as a fallback in ongoing contracts, and keeping an eye on monitoring by the FDPIC, as future judicial restrictions are not excluded.
— Bitblade
Support in Implementing the Swiss-US DPF
We support companies in concrete implementation: from the initial review of existing US data flows to a contract workshop for adapting clauses, up to an ongoing compliance mandate for companies with regular data exchanges to the USA.
An initial consultation to assess your situation is available via our consultation packages. Consulting is available in German, English, French, Ukrainian, and Russian, directly and without an interpreter. For an overview of our other services in international commercial and contract law, visit our Services page.
FAQ
Does the Swiss-US DPF automatically apply to every US company?
No. Adequacy applies only to US organisations that have explicitly self-certified for Switzerland and are listed on the official list. If the partner is not listed, standard contractual clauses or other safeguards remain required.
Since when has the amendment to the Data Protection Ordinance been in effect?
The Federal Council adopted the adequacy decision on 14 August 2024; the amendment to Annex 1 of the Data Protection Ordinance entered into force on 15 September 2024. Since then, transfers to certified US companies have been possible without additional safeguards.
What happens if a US partner loses its certification?
The organisation must then return, delete, or continue to protect received data in accordance with the principles of the framework, as long as it still holds them, according to the program's requirements. Companies should immediately fall back on an SCC fallback clause in this case, if one was agreed.
Where can I complain about a violation of my data?
Data subjects can file a complaint via the Model Complaint Form with the FDPIC, which forwards the complaint to the competent US authority. Depending on the case, the FTC, the Department of Transportation, or the Data Protection Review Court is responsible.
What does an initial legal review of data transfers cost?
An initial consultation to assess your data transfers is available from 150 CHF per hour. The specific effort depends on the number of US partners and existing contracts to be reviewed.
Sources
Recommendations