INSIGHT // 71 Cross-Border

Swiss Health Data for US SaaS and Digital Therapeutics: Where Neither HIPAA Nor the GDPR Predicts the DSG

Abstract: A US health-SaaS or digital-therapeutics vendor reaching Swiss users carries a compliance map drawn for HIPAA and the GDPR. The Swiss DSG follows neither. It attaches to the data category rather than to the entity holding it, and from there it adds a Swiss representative duty, a confidentiality bar built into its processor provision, a separate cantonal layer for public hospitals, a breach clock with no number on it, and criminal fines that name a natural person. With the first digital therapeutic reimbursed by Swiss mandatory health insurance from 1 July 2026, the divergence has become commercial rather than theoretical.
Plain Language Summary

Swiss data-protection law, the DSG, treats any data about a person's health as especially sensitive, no matter who holds it. That differs from the US approach, where the strictest rules apply only to health providers, insurers and their contractors. It also differs from the EU's GDPR in ways that matter to software companies. This article looks at what a US company takes on once its health app, hospital software platform or prescription digital therapy has Swiss users or Swiss hospital customers. The duties include a possible Swiss representative, medical-secrecy rules that decide whether a hospital may use the software at all, separate cantonal laws for public hospitals, transfer rules for sending data to the United States, breach notification without a fixed deadline, and fines that fall on named individuals. It describes where these duties come from and why they are easy to miss.

Table of Contents
  1. A Category, Not a Covered Entity: How the DSG Reaches a Health App
  2. Processor, Controller, or Auxiliary: The Role Question a Hospital Contract Does Not Settle
  3. Prescribed, Reimbursed, Self-Administered: The July 2026 Listing and the Duties It Pulls In
  4. A Clock Without a Number and a Fine With a Name: Transfers, Breaches and Personal Exposure
  5. Strategic Considerations

A US digital-health company that has finished its HIPAA analysis knows where it stands. It is a covered entity, a business associate, or neither, and for the consumer app that is neither, the Federal Trade Commission's Health Breach Notification Rule and a growing set of state statutes fill the gap. That map is drawn around who holds the data. Swiss law draws its map around what the data is. Under the DSG, Switzerland's federal data-protection statute, data about a person's health is sensitive personal data whoever processes it.1Datenschutzgesetz (DSG), SR 235.1, in force 1 September 2023; Art. 3(1) (effects in Switzerland) and Art. 5(c) (data about health as sensitive personal data). A wellness app with a few thousand Swiss users, a hospital-facing platform hosted in Virginia, and a prescription digital therapeutic newly listed for reimbursement on 1 July 2026 all inherit the same statutory category from the first Swiss user. What differs among them is not whether the DSG applies. It is which of its duties attach, in which role, alongside which other Swiss law, and who is personally exposed when one of them is missed.

1. A Category, Not a Covered Entity: How the DSG Reaches a Health App

The reach question comes first, and the DSG answers it with a formula the GDPR's vocabulary does not contain. Art. 3(1) DSG applies the statute to matters that have an effect in Switzerland, even where they are initiated abroad. Art. 3(2) GDPR asks whether a controller outside the Union offers goods or services to people in the Union or monitors their behavior. A US company that has concluded it does not target Europe in that sense has built its analysis around intent.2Regulation (EU) 2016/679 (GDPR), Art. 3(2) (targeting test), Art. 27 (representative), Art. 28 (processor), Art. 33 (notification within 72 hours). The Swiss test is built around effect. A German-language onboarding flow, a subscription priced in Swiss francs, or a hospital customer in Bern all produce effects in Switzerland without anyone having decided to target the country. The DSG's personal scope in Art. 2 DSG then asks only whether whoever processes the data is a private person or a federal body. It does not ask whether the company is large, whether it has an establishment in Switzerland, or whether health data is its business.

The category does the rest of the work. Art. 5(c) DSG lists data about health among the categories of sensitive personal data, next to genetic data and biometric data that uniquely identify a person, and it attaches the label to the data rather than to the entity holding them. That is the structural inversion of the HIPAA model. Under 45 C.F.R. Parts 160 and 164, protected health information is defined by its passage through a covered entity or a business associate. The same blood-pressure reading in a consumer app is not protected health information at all, which is why the FTC's rule, amended with effect from 29 July 2024, and Washington's My Health My Data Act, in force since 31 March 2024, exist to cover what HIPAA leaves out.345 C.F.R. Parts 160 and 164 (HIPAA rules); 16 C.F.R. Part 318 (FTC Health Breach Notification Rule, as amended effective 29 July 2024); Wash. Rev. Code ch. 19.373 (My Health My Data Act). The DSG has no sector to leave out. A step count, a mood diary, a medication reminder and a hospital's discharge summary are sensitive personal data on the same footing, and the consequences follow the label. Where consent is the ground relied on, Art. 6(7)(a) DSG requires that it be express. Disclosing sensitive data to a third party is, under Art. 30(2)(c) DSG, a violation of personality that needs a justification under Art. 31 DSG. And extensive processing of sensitive data is, by the terms of Art. 22(2)(a) DSG, high-risk processing that requires a data protection impact assessment before it begins, followed by a consultation of the EDÖB, the federal data-protection authority, under Art. 23 DSG where a high residual risk remains, unless a data protection advisor appointed under Art. 10 DSG has been consulted instead.

The ordinance adds duties a US vendor rarely sees coming, because they are keyed to the same category. The DSV requires a private controller and its private processor that process sensitive personal data on a large scale to maintain a processing regulation, a Bearbeitungsreglement, covering internal organization, processing and control procedures and the security measures in place, and to keep it updated.4Datenschutzverordnung (DSV), SR 235.11; Art. 4 (logging), Art. 5 (processing regulation), Art. 7 (sub-processors), Art. 24 (record exemption unavailable for large-scale sensitive data). Where preventive measures cannot guarantee data protection, Art. 4 DSV requires logging of at least the storage, modification, disclosure, deletion and destruction of the data and of access to them, with the logs retained for at least one year, separately from the system that processed the data, and accessible only to those charged with verifying compliance or with safeguarding the data's confidentiality, integrity, availability and traceability. The record of processing activities under Art. 12 DSG, which Art. 24 DSV waives for companies with fewer than 250 employees, is not waived for them where sensitive data are processed on a large scale, so a forty-person digital-therapeutics company does not have the small-company exemption its headcount suggests. None of these duties is triggered by being a covered entity, a device manufacturer or a Swiss company. They are triggered by the data.

Reach and category together produce a further obligation that has no counterpart in the US framework and a misleading counterpart in the European one. Art. 14 DSG requires a private controller with its seat abroad to designate a representative in Switzerland where it processes data of persons in Switzerland in connection with offering goods or services or observing their behavior, and the processing is extensive, regular, and carries a high risk to the personality of the data subjects. The four conditions are cumulative.5EDÖB, guidance on the duty to designate a representative under Art. 14 DSG: four cumulative conditions; high risk assessed as gross risk, with sensitive personal data among the factors. The EDÖB's published reading assesses the high-risk condition as a gross risk across all existing and planned processing, before mitigating measures are counted, and names sensitive personal data among the factors that establish it. A consumer health application with a regular Swiss user base therefore tends to satisfy the fourth condition by its subject matter and the first three by its business model, on the day it has enough Swiss users to be called extensive, a threshold to which neither the statute nor the guidance attaches a number. The representative keeps the record of processing activities under Art. 15 DSG, answers the EDÖB, and tells data subjects how to exercise their rights. Its name and address must be published. A company that appointed a representative in the Union under Art. 27 GDPR has not appointed a Swiss one. The two are different offices under different statutes, and the EDÖB can order the appointment by decision under Art. 51(4) DSG.

The DSG attaches to the data category, not to the entity holding it, so a health app that HIPAA never reaches is sensitive-data processing under Swiss law from its first Swiss user.

The practical effect of the inversion is that a US vendor's compliance inventory is usually organized in the wrong order. HIPAA compliance is a question of contracts and roles. GDPR compliance is a question of legal bases and records. The DSG asks, before either, what the data are, and then follows that answer into duties the vendor may have assigned, in its own documentation, to a customer, to a downstream processor, or to nobody.

2. Processor, Controller, or Auxiliary: The Role Question a Hospital Contract Does Not Settle

The same platform is a controller, a Verantwortlicher under Art. 5(j) DSG, when it sells to consumers and a processor, an Auftragsbearbeiter under Art. 5(k) DSG, when it hosts a hospital's patient data. A US vendor that has drafted one data processing addendum on the Art. 28 GDPR model will find the Swiss processor provision shorter and, in one respect, sharper. Art. 9(1) DSG permits processing to be entrusted to a processor only where the data are processed as the controller itself would be permitted to process them and where no statutory or contractual duty of confidentiality prohibits the transfer. Art. 9(2) DSG requires the controller to satisfy itself that the processor can guarantee data security. Art. 9(3) DSG permits the processor to pass processing to a third party only with the controller's prior approval, which Art. 7 DSV allows to be general, provided the processor gives notice of every intended change in its sub-processors and the controller may object. There is no catalog of mandatory contract terms of the kind Art. 28(3) GDPR sets out, which US counsel tend to read as a lighter regime. The reading is incomplete. The confidentiality bar in Art. 9(1)(b) DSG is a statutory precondition rather than a contract term. Art. 61(b) DSG makes it a criminal offense, punishable by a fine of up to CHF 250,000 on complaint, for a private person intentionally to hand processing to a processor without the conditions of Art. 9(1) and (2) DSG being met. That exposure sits with the hospital, which is why a Swiss hospital's procurement questionnaire asks a US SaaS vendor questions that a HIPAA business associate agreement never anticipated.

The duty of confidentiality that matters is criminal, not contractual. Art. 321 StGB makes it an offense for physicians, pharmacists, psychologists, nurses, physiotherapists and the other listed professions, and for their auxiliary persons, to disclose a secret entrusted to them in the exercise of their profession, punishable by imprisonment of up to three years or a monetary penalty, unless the person entitled has consented or the supervisory authority has authorized the disclosure in writing.6Strafgesetzbuch (StGB), SR 311.0, Art. 321 (professional secrecy of health professions and their auxiliary persons); privatim plenary of 17 May 2017 on outsourcing and the auxiliary-person question. Whether a cloud or SaaS provider can be an auxiliary person, a Hilfsperson, of the hospital is the question on which the lawfulness of the entire outsourcing turns, and no published decision of the Federal Supreme Court has answered it. Prevailing practice treats a provider bound by contract and instruction as an auxiliary person. The conference of Swiss data-protection commissioners, privatim, has rejected the view that every outsourcing contractor qualifies and in 2017 saw only two lawful routes, the patient's prior express consent or an encryption that leaves the provider no access to the data. Art. 62 DSG then adds a second, parallel offense. Anyone who intentionally discloses secret personal data learned in the exercise of a profession that requires knowledge of such data, or while working for a person bound by such a duty, faces a fine of up to CHF 250,000. Whether a vendor's own engineers with production access fall within that provision is not a question its US counsel has ever had to ask, and Swiss law has not answered it cleanly for them.

The fork widens when the customer is a public hospital. Art. 2 DSG confines the federal statute to private persons and federal bodies. A university hospital in Basel or Zurich is a cantonal public body, and its data processing answers to cantonal law. In Basel-Stadt that law is the Gesetz über die Information und den Datenschutz of 9 June 2010, in Zurich the Gesetz über die Information und den Datenschutz of 12 February 2007, each supervised by a cantonal data-protection commissioner rather than by the EDÖB.7IDG Basel-Stadt (SG 153.260) and IDG Zürich (LS 170.4); privatim, resolution on outsourcing data processing to the cloud (18 November 2025). Healthcare is cantonal in Switzerland. The twenty-six cantons retain primary jurisdiction over hospitals, and the closest US analogue, a state-by-state patchwork, understates the autonomy. On 18 November 2025 privatim adopted a resolution on outsourcing to the cloud that treats international SaaS providers as unsuitable for sensitive or secrecy-protected data unless the public body itself encrypts the data and the provider has no access to the key. The resolution cites the absence of true end-to-end encryption in most SaaS products, the limits of what a Swiss authority can verify about a global provider's staff and measures, and the reach of the US CLOUD Act into data held in Swiss data centers. It binds nobody by itself. It describes the posture the supervisors of Switzerland's largest hospitals bring to a US vendor's security annex, and a private hospital group across the street is, on the prevailing view, a private person under the DSG and subject to none of it. One master services agreement, presented to two Swiss hospitals, can be governed by two different statutes, two different regulators and two different views of whether the vendor may exist in the data flow at all.

One Digital Health Application, Four Swiss Deployment Paths A single digital health application feeds into four Swiss deployment paths: direct to consumer, where the vendor is the controller and the representative and impact-assessment duties attach; a private hospital customer, where the vendor is a processor and the confidentiality bar and the auxiliary-person question under the criminal code arise; a cantonal public hospital, which sits outside the federal statute under cantonal law and the privatim cloud resolution; and prescription under mandatory health insurance, which adds the July 2026 listing, invoicing data, device duties and the electronic health dossier. A band across the bottom lists what attaches on every path: sensitive data, transfer rules, breach notification and criminal fines on named persons. One Health Application same production system on every path Direct to consumer vendor is the controller Art. 14 DSG Swiss representative Art. 22 DSG impact assessment first Art. 6(7) DSG express consent Private hospital vendor is the processor Art. 9(1)(b) DSG confidentiality bar Art. 321 StGB auxiliary person? Art. 61(b) DSG on the hospital Cantonal hospital outside Art. 2 DSG cantonal IDG cantonal commissioner privatim, Nov 2025 encrypt, keep the key US CLOUD Act in view Prescribed, reimbursed MiGeL from 1 Jul 2026 Art. 42 KVG invoicing data to insurer Art. 51 MepV device representative E-GD horizon, 2030 Attaches on every path, whatever the role Art. 5(c) DSG sensitive data · Art. 16-17 DSG transfers · Art. 24 DSG breach, no fixed clock Art. 60-64 DSG criminal fines on a named natural person, up to CHF 250,000 the label follows the data, not the contract
One application, four Swiss deployment paths. The role changes on each, and the duties that follow the data do not.

3. Prescribed, Reimbursed, Self-Administered: The July 2026 Listing and the Duties It Pulls In

Switzerland has no equivalent of Germany's DiGA fast track, and a US developer that has read the German pathway as the European template, a reading examined in Insight 50, will look for a Swiss listing procedure that does not exist. Reimbursement by the mandatory health insurance, the OKP, runs through the general architecture of the KVG. A service must be effective, appropriate and economical under Art. 32 KVG, and aids and devices applied by the patient are reimbursed only if listed in the Mittel- und Gegenständeliste, the MiGeL, which the EDI issues under Art. 52(1)(a)(3) KVG as Annex 2 to the KLV, on prescription by a physician under Art. 20 KLV and up to a maximum reimbursement amount under Art. 24 KLV.8KVG, SR 832.10, Art. 32, 42(3)-(3bis), 52(1)(a)(3); KLV, SR 832.112.31, Art. 20, 20a, 24 and Annex 2 (MiGeL); BAG media release of 4 December 2025 on reimbursement of digital therapy applications from 1 July 2026. On 4 December 2025 the BAG announced the first use of that route for software. With effect from 1 July 2026 the OKP reimburses a digital application delivering cognitive behavioral therapy for mild to moderate depressive episodes and recurrent depressive disorders, prescribed by a physician holding the specialist qualification the listing names, as a supplement to psychotherapy or as a bridge until it begins. The position was written around a single application already established in the German DiGA register, but the list names no product. The entry is generic, under evaluation until 31 December 2026, and the prescribing physician must name the product on the prescription. What the announcement created is a market. What it did not create is a data regime, and the one that applies was not designed with a self-administered therapy in mind.

The listing pulls in three layers that the developer's US model keeps apart. The first is product regulation. A therapeutic application is a medical device, and a manufacturer without a seat in Switzerland may place it on the market only through an authorized representative in Switzerland under Art. 51 MepV, an appointment whose liability profile Insights 05 and 07 examine.9Medizinprodukteverordnung (MepV), SR 812.213, Art. 51 (authorized representative for manufacturers without a seat in Switzerland). The second is the billing chain. Under Art. 42(3) and (3bis) KVG the provider must give the debtor a detailed invoice with the information needed to verify the calculation and the economic efficiency of the service, coded diagnoses and procedures included, and under the tiers payant system that debtor is the insurer. A reimbursed therapeutic therefore sits inside a flow in which a prescribing physician, a dispensing point, an insurer with its own statutory basis for processing, and the vendor each hold a fragment of the same episode of care. The vendor, whose application the physician does not enter, holds the only complete record of the therapy itself. The third layer is the DSG's treatment of what the application does with that record. A program that evaluates a user's responses to adapt the next session is evaluating aspects of that person's health, which is profiling within Art. 5(f) DSG. Whether it is profiling with high risk under Art. 5(g) DSG, permitting an assessment of essential aspects of the personality, is a question the definition invites and the vendor's documentation must answer, because Art. 6(7)(b) DSG requires express consent for high-risk profiling by a private person wherever consent is the ground relied on. A program that escalates, restricts or discharges a user on the strength of an automated assessment may be taking an automated individual decision within Art. 21 DSG, with the notice and human-review rights that follow, unless the decision is taken in direct connection with a contract with the user and grants the user's own request, or the user has expressly consented to its being automated. The impact assessment under Art. 22 DSG is owed before processing begins. For a product listed on 1 July 2026, the question is whether it exists, and whether it describes the reimbursed configuration rather than the consumer one.

Two further features of Swiss law press on the design. Art. 25(3) DSG allows health data to be communicated to the data subject, with the data subject's consent, through a health professional the data subject designates, a mechanism drafted for a physician's file that a self-administered application has to reproduce without a physician in the loop. Art. 28 DSG gives a right to receive the data one has disclosed to the controller in a common electronic format, or to have them transferred to another controller where that needs no disproportionate effort, where processing is automated and rests on consent or on a contract with the data subject, which describes the consumer subscription exactly. Beyond the statute sits the national infrastructure. On 5 November 2025 the Federal Council submitted to Parliament the Bundesgesetz über das elektronische Gesundheitsdossier, the EGDG, which would replace the electronic patient record established under the EPDG with an opt-out dossier for every resident, operated by the Confederation with the data stored in Switzerland, that every provider billing the OKP must connect to and populate with treatment-relevant data.10EPDG, SR 816.1; Federal Council message of 5 November 2025 on the EGDG (opt-out dossier, mandatory participation of providers billing the OKP, earliest operation around 2030). The National Council's health committee voted to enter into the bill in February 2026 and began its detailed deliberation in April. The Federal Council's own estimate places the earliest operation around 2030. Whether a reimbursed digital therapeutic is a provider that must feed the dossier, whether its outputs are treatment-relevant data the prescribing physician must document, and how a vendor's US-hosted record meets a statutory requirement that dossier data remain in Switzerland are questions the message does not address, because its definitions were written around professions and institutions rather than software. A product architecture chosen in 2026 will meet that infrastructure with whatever answers the 2026 architecture happened to embed.

4. A Clock Without a Number and a Fine With a Name: Transfers, Breaches and Personal Exposure

Every path in the preceding sections ends at a server, and for most US vendors that server is in the United States. Art. 16(1) DSG permits disclosure abroad where the Federal Council has found the destination's legislation adequate, and the list in Annex 1 to the DSV names the United States only for organizations certified under the Swiss-US Data Privacy Framework, with effect from 15 September 2024.11Annex 1 DSV, entry for the United States (organizations certified under the Swiss-US Data Privacy Framework, effective 15 September 2024); EDÖB recognition of the EU standard contractual clauses (27 August 2021). For an uncertified recipient, Art. 16(2) DSG requires a treaty, contractual data-protection clauses notified in advance to the EDÖB, standard clauses the EDÖB has approved, issued or recognized, or binding corporate rules. The EDÖB's recognition, on 27 August 2021, of the European Commission's standard contractual clauses carries Swiss-specific adaptations that a US-drafted clause set often omits, and Art. 9 and 10 DSV then specify what such clauses must contain and require the exporter to take measures to ensure the importer honors them. The exceptions in Art. 17 DSG, express consent and a direct connection with a contract among them, are available but narrow, and Art. 61(a) DSG makes an intentional disclosure abroad without an adequacy finding, an Art. 16(2) DSG safeguard or an Art. 17 DSG exception a criminal offense. The Swiss framework runs on the same American architecture as the European one. The Federal Council's finding rests on Executive Order 14086 and the Data Protection Review Court, and the US Supreme Court's ruling of 29 June 2026 on the President's power to remove Federal Trade Commission members, examined in Insight 64, raises for the Swiss list the same question it raises for the EU adequacy decision. A vendor whose only transfer mechanism is its framework certification has a single point of failure on both sides of the Rhine.

The breach provision is where a US incident-response playbook fails quietly. HIPAA gives sixty days, the FTC rule gives sixty days, the GDPR gives seventy-two hours. Art. 24(1) DSG requires the controller to notify the EDÖB as quickly as possible, so rasch als möglich, of a breach that is likely to lead to a high risk to the personality or the fundamental rights of the data subject, and Art. 24(3) DSG requires the processor to notify the controller as quickly as possible, with no risk threshold at all. A clock without a number is not a clock without a deadline. It is a deadline that will be measured after the fact against what the company knew and when. Art. 15 DSV prescribes the content of the notification and requires the controller to document the breach, its effects and the measures taken and to keep that record for at least two years from the notification, while leaving open whether breaches below the notification threshold must be documented too, and Art. 24(5bis) DSG, in force since 1 April 2025, allows the EDÖB, with the controller's consent, to forward the notification to the BACS for analysis. The security floor beneath the notification duty is set by Art. 8 DSG and Art. 1 to 3 DSV, which require measures appropriate to the risk across confidentiality, availability, integrity and traceability. An intentional failure to meet the minimum requirements the Federal Council has laid down is, under Art. 61(c) DSG, itself an offense.

That criminal thread runs through the entire statute, and it is the divergence US counsel most consistently underestimate. HIPAA's civil money penalties and the FTC's orders bind the company, and the GDPR's administrative fines are levied on the undertaking. Art. 60 to 63 DSG impose fines of up to CHF 250,000 on private persons, prosecuted by the cantonal criminal authorities and, for most of the offenses, only on complaint, for intentionally providing false or incomplete information, intentionally failing to inform data subjects, unlawful disclosure abroad, unlawful engagement of a processor, failure to meet the minimum security standards, breach of professional confidentiality, and disregard of a decision of the EDÖB issued under reference to that penalty. Art. 64 DSG allows the fine to be imposed on the business instead of the individual only where the fine would not exceed CHF 50,000 and identifying the responsible person would require disproportionate investigative effort. The statute names a person, and which person is a question of who decided, not of who signed. The EDÖB itself has no power to fine. Its instruments are the investigation under Art. 49 DSG, the administrative measures under Art. 51 DSG, which the Federal Administrative Court upheld in a judgment of 6 October 2025 that confirmed the authority's practice under the revised statute, and the criminal complaint.12EDÖB, 33. Tätigkeitsbericht 2025/2026 (30 June 2026); Urteil BVGer A-2941/2024 vom 6. Oktober 2025, confirming the EDÖB's administrative measures. The authority's activity report published on 30 June 2026 records more than two thousand reports of suspected violations in the year, 156 interventions, nine formal investigations, and one criminal complaint against a private company that refused the cooperation Art. 49(3) DSG requires. For a US officer, a fine under a foreign criminal statute, imposed by name, is the kind of exposure that a standard directors' and officers' policy was rarely drafted to describe, and the disclosure question it raises in the United States does not wait for the Swiss proceeding to end.

5. Strategic Considerations

The questions that follow are not answerable from the outside, and most of them turn on facts the vendor's own records may not hold. In which of the four configurations does the application actually run in Switzerland today, and does the role the vendor assigned itself in each, controller here, processor there, survive the observation that the same production system serves all of them? When did the fourth condition of Art. 14 DSG trip, if it has, and was the Swiss user count that made the processing extensive noticed by anyone whose job it was to notice?

A hospital contract raises a different order of question. Was the data processing addendum drafted to Art. 28 GDPR, and if so, where in it is the customer's confidentiality bar under Art. 9(1)(b) DSG satisfied, by what characterization of the vendor as an auxiliary person, and on whose legal analysis? If the customer is a cantonal hospital, has the vendor's security annex been read against the privatim resolution of November 2025, and is the encryption architecture it describes one in which the vendor could not read the data if asked to, or one in which it merely does not? And for the reimbursed therapeutic, does the impact assessment under Art. 22 DSG that stands behind the July 2026 listing describe the profiling the product performs in the terms Art. 5(f) and (g) DSG use, or in the terms the product team uses?

The transfer and incident questions have the shortest fuse. What does the vendor rely on for Swiss data if its framework certification ceases to carry an adequacy finding, is that fallback already in the contracts, and does it carry the Swiss adaptations the EDÖB's recognition requires? What does an incident-response plan built around sixty days do with a Swiss obligation to notify as quickly as possible, and who, by name, is the natural person a cantonal prosecutor would identify as having decided the timing? Beneath all of these sits the question with the longest horizon. Will a product architecture fixed in 2026 meet the electronic health dossier that was still before Parliament in the summer of 2026 with the data in the right place, in the right hands, and under a role the vendor chose rather than one it discovered? These questions require analysis tailored to specific facts and commercial context.

REFERENCES

01
Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG) vom 25. September 2020 (SR 235.1), in force 1 September 2023; Art. 2 (personal scope: private persons and federal bodies), Art. 3(1) (territorial scope: matters with an effect in Switzerland, even where initiated abroad), Art. 5(c) (sensitive personal data, including data about health, genetic data and uniquely identifying biometric data), Art. 5(f) and (g) (profiling and profiling with high risk), Art. 5(j) and (k) (controller and processor), Art. 6(7) (express consent for sensitive personal data and for high-risk profiling by a private person), Art. 9 (processing by a processor), Art. 10 (data protection advisor), Art. 12 (record of processing activities), Art. 14 and 15 (representative in Switzerland and its duties), Art. 16 and 17 (disclosure abroad and exceptions), Art. 21 (automated individual decisions), Art. 22 and 23 (data protection impact assessment and consultation of the EDÖB), Art. 24 (notification of breaches of data security, including Art. 24(5bis), in force 1 April 2025), Art. 25(3) and Art. 28 (communication of health data through a designated health professional; data portability), Art. 30 and 31 (violations of personality and grounds of justification), Art. 49 and 51 (investigation and administrative measures, including Art. 51(4) on ordering the designation of a representative), Art. 60-64 (criminal provisions) and Art. 65 (prosecution by the cantons; the EDÖB's right to file a criminal complaint and to act as a private claimant).
02
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) [2016] OJ L119/1, Art. 3(2) (territorial scope by reference to offering goods or services to, or monitoring the behavior of, data subjects in the Union), Art. 9 (special categories of personal data), Art. 27 (representative of a controller or processor not established in the Union), Art. 28(2) and (3) (sub-processor authorization and mandatory content of the processing contract), and Art. 33(1) (notification of a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours).
03
Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, with the Privacy, Security and Breach Notification Rules at 45 C.F.R. Parts 160 and 164 (protected health information defined by reference to covered entities and business associates; 45 C.F.R. § 164.404 (notification without unreasonable delay and in no case later than 60 calendar days after discovery)); Health Breach Notification Rule, 16 C.F.R. Part 318, as amended by Final Rule, 89 Fed. Reg. 47028 (May 30, 2024), effective July 29, 2024 (vendors of personal health records and related entities outside HIPAA; 16 C.F.R. § 318.4(a) (notification without unreasonable delay and in no case later than 60 calendar days after discovery)); Washington My Health My Data Act, Wash. Rev. Code ch. 19.373, in force 31 March 2024 (30 June 2024 for small businesses).
04
Verordnung über den Datenschutz (Datenschutzverordnung, DSV) vom 31. August 2022 (SR 235.11), in force 1 September 2023; Art. 1-3 (minimum requirements for data security: confidentiality, availability, integrity and traceability), Art. 4 (logging by private controllers and processors of large-scale sensitive-data processing or high-risk profiling; the logging duty as amended with effect from 1 December 2025; retention of the logs for at least one year, separately from the processing system), Art. 5 (processing regulation of private persons processing sensitive personal data on a large scale or performing high-risk profiling), Art. 7 (specific or general prior approval of sub-processors, with notice of changes and a right to object), Art. 8 and Annex 1 (states, territories, sectors and international bodies with adequate protection), Art. 9-11 (contractual data-protection clauses, standard clauses and binding corporate rules), Art. 14 (retention of the impact assessment for at least two years after the end of processing), Art. 15 (content and documentation of breach notifications; documentation retained for at least two years), and Art. 24 (exemption from the record of processing activities for companies with fewer than 250 employees, unavailable where sensitive personal data are processed on a large scale or high-risk profiling is performed).
05
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), 'Pflicht zur Benennung einer Vertretung nach Artikel 14 DSG' (edoeb.admin.ch), explaining the four cumulative conditions of Art. 14(1) DSG, reading 'extensive' as processing that is more than isolated and 'regular' as processing that is more than occasional or limited in time, assessing the high-risk condition as a gross risk across all existing and planned processing before mitigating measures are taken into account, naming the type of data, and sensitive personal data in particular, among the factors that establish it, and noting the EDÖB's power under Art. 51(4) DSG to order the designation of a representative.
06
Schweizerisches Strafgesetzbuch (StGB) vom 21. Dezember 1937 (SR 311.0), Art. 321 (professional secrecy of clergy, lawyers, physicians, dentists, chiropractors, pharmacists, midwives, psychologists, nurses, physiotherapists and the other listed professions, and of their auxiliary persons; imprisonment of up to three years or a monetary penalty, on complaint; disclosure with the consent of the person entitled or with the written authorization of the supervisory authority not punishable), Art. 321bis (professional secrecy in research on humans). On the auxiliary-person characterization of outsourcing providers: privatim, Konferenz der schweizerischen Datenschutzbeauftragten, plenary of 17 May 2017 ('Überlebt das medizinische Berufsgeheimnis die Digitalisierung?'), rejecting the blanket characterization of outsourcing contractors as auxiliary persons and accepting outsourcing only with the patient's prior express consent or with encryption that gives the provider no potential access, the key management staying with the physician or hospital.
07
Gesetz über die Information und den Datenschutz (Informations- und Datenschutzgesetz, IDG) vom 9. Juni 2010 (SG 153.260, Kanton Basel-Stadt), in force 1 January 2012, § 3 (public bodies); Gesetz über die Information und den Datenschutz (IDG) vom 12. Februar 2007 (LS 170.4, Kanton Zürich); privatim, Konferenz der schweizerischen Datenschutzbeauftragten, 'Resolution zur Auslagerung von Datenbearbeitungen in die Cloud' (Bern, 18 November 2025), read with its 'Merkblatt Cloud-spezifische Risiken und Massnahmen' (version 3.01, February 2022): outsourcing of sensitive or secrecy-protected personal data by public bodies to international SaaS providers only where the public body encrypts the data itself and the provider has no access to the key.
08
Bundesgesetz über die Krankenversicherung (KVG) vom 18. März 1994 (SR 832.10), Art. 32 (effectiveness, appropriateness and economic efficiency), Art. 42(3) and (3bis) (detailed invoice and the information owed to the debtor, including diagnoses and procedures coded to the classifications issued by the Department), Art. 52(1)(a)(3) (list of aids and devices issued by the Department); Verordnung des EDI über Leistungen in der obligatorischen Krankenpflegeversicherung (Krankenpflege-Leistungsverordnung, KLV) vom 29. September 1995 (SR 832.112.31), Art. 20 (aids and devices reimbursed on prescription by a physician and applied by the insured person), Art. 20a (the list in Annex 2, the MiGeL, published by the BAG), Art. 24 (maximum reimbursement amounts); Bundesamt für Gesundheit (BAG), 'Digitale Therapie-Angebote können neu von Krankenversicherung übernommen werden' (media release, 4 December 2025), announcing the amendments to the KLV and the MiGeL with effect from 1 July 2026 under which digital cognitive behavioral therapy applications for mild to moderate depressive episodes and recurrent depressive disorders are reimbursed on prescription by a physician with the required specialist qualification, as a supplement to psychotherapy or as a bridge until it begins; Änderungen Anhang 2 KLV (MiGeL) vom 2. Dezember 2025 per 1. Juli 2026, position 40.01.01.00.1 (an interactive digital health application for the cognitive behavioral therapy of depression for self-application by the patient, without access by the treating professional, reimbursed once per licence of 90 days at a maximum reimbursement amount of CHF 171.32, valid from 1 July 2026 and under evaluation until 31 December 2026, the prescribing physician identifying the product on the prescription), and BAG, 'Kommentar zu den Änderungen des Anhangs 2 der KLV' (2 December 2025), recording that the position was assessed on one application and is drafted generically.
09
Medizinprodukteverordnung (MepV) vom 1. Juli 2020 (SR 812.213), Art. 51 (a manufacturer without a seat in Switzerland may place its products on the market only through a person with a seat in Switzerland that it has authorized in writing; the representative's rights and duties follow Art. 11 MDR), issued under the Bundesgesetz über Arzneimittel und Medizinprodukte (Heilmittelgesetz, HMG) vom 15. Dezember 2000 (SR 812.21).
10
Bundesgesetz über das elektronische Patientendossier (EPDG) vom 19. Juni 2015 (SR 816.1); Bundesrat, 'Bundesrat beschliesst Neuausrichtung: Elektronisches Gesundheitsdossier E-GD löst EPD ab' (media release, 5 November 2025), transmitting to Parliament the message on a Bundesgesetz über das elektronische Gesundheitsdossier (EGDG): an opt-out dossier for every resident, mandatory participation of physicians, pharmacists, physiotherapists and other ambulatory providers billing the mandatory health insurance, central operation by the Confederation with the data stored in Switzerland, and earliest operation around 2030. The National Council's Commission for Social Security and Health voted to enter into the bill on 13 February 2026, by 16 votes to 8, and began the detailed deliberation on 17 April 2026, when it also decided unanimously that the Federal Council must define in implementing law which data count as treatment-relevant.
11
DSV (n 4), Annex 1, entry for the United States: an adequate level of protection for personal data processed by organizations certified under the Swiss-US Data Privacy Framework, on the basis of Executive Order 14086 of 7 October 2022, the Attorney General's regulation establishing the Data Protection Review Court and Intelligence Community Directive 126, recognized by the Federal Council with effect from 15 September 2024; EDÖB, 'Übermittlung von Personendaten in ein Land ohne angemessenes Datenschutzniveau gestützt auf anerkannte Standardvertragsklauseln und Musterverträge' (Mitteilung, 27 August 2021) and 'Die Übermittlung von Personendaten in ein Land ohne angemessenes Datenschutzniveau gestützt auf Standarddatenschutzklauseln nach Art. 16 Abs. 2 lit. d DSG' (guidance, 27 August 2021, last amended 12 February 2025), recognizing the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 as a safeguard under Swiss law subject to Swiss-specific adaptations. The Data Privacy Framework and the US Supreme Court's ruling of 29 June 2026 are examined in Insight 64.
12
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), 33. Tätigkeitsbericht 2025/2026 (EDÖB, 30 June 2026): more than 2,000 reports of suspected data-protection violations, 156 interventions against controllers, 22 preliminary clarifications, nine investigations, and one criminal complaint against a private company for refusing the cooperation required by Art. 49(3) DSG; Urteil BVGer A-2941/2024 vom 6. Oktober 2025 (Verein Bürgerforum Schweiz v EDÖB), dismissing the appeal against the EDÖB's decision of 9 April 2024 and confirming the authority's practice of ordering administrative measures under Art. 51 DSG.

The compliance map a US health application carries into Switzerland was drawn for HIPAA and the GDPR, and the DSG rewards neither assumption. The specifics decide where the exposure sits.

Get in Touch