Switzerland’s reputation as a privacy haven, the reason ProtonVPN, Threema, and other privacy-focused companies chose to headquarter there, is being tested by a proposed revision to the country’s surveillance law. As of mid-2026, the outcome is still unresolved, but the uncertainty alone has already pushed Proton to begin shifting infrastructure out of the country.

Why Switzerland mattered to privacy companies in the first place

Switzerland built its reputation as a data-privacy haven over decades, through strong statutory protections, a legal tradition of banking-style confidentiality that extended culturally into how the country approached digital services, and, crucially, staying outside every major intelligence-sharing alliance. That combination is why ProtonVPN, Threema, and a cluster of other privacy-focused companies chose to headquarter there rather than in the US, UK, or EU, none of which offer quite the same combination of legal protection and alliance-free status. The current ordinance proposal matters precisely because it threatens the specific thing that drew those companies to Switzerland in the first place.

What the proposed law would actually require

The Swiss Federal Council introduced a revision to the Ordinance on the Surveillance of Correspondence by Post and Telecommunications (OSCPT) in January 2025. The revision would extend surveillance obligations, previously limited to telecoms and internet service providers, to a much broader category the ordinance calls “derived communication service” providers: VPNs, encrypted messaging apps, and social networks.

Under the proposal, any qualifying provider with more than 5,000 users would be required to identify its customers, retain communications metadata for six months after a user’s account ends, and, where the provider holds encryption keys, decrypt content on request from authorities. Larger providers, those with over a million users or more than CHF 100 million in annual revenue, would face stricter, real-time interception obligations.

Why Proton is already acting on it

Proton, which runs Proton Mail, Proton VPN, Proton Drive, and Proton Pass from Geneva, has been the proposal’s most vocal opponent. The company has stated that if the amendment passes in anything close to its current form, its options narrow to either compromising its no-logs and end-to-end encryption commitments or leaving the jurisdiction. Proton founder Andy Yen has said the only European country with a roughly comparable surveillance law is Russia.

Rather than wait for a final decision, Proton confirmed it is gradually shifting parts of its physical infrastructure out of Switzerland, starting with its AI assistant Lumo, while keeping its headquarters, executive team, and policy lobbying in Geneva. The company has pointed to Germany and Norway as likely destinations for infrastructure moving forward, citing the EU’s GDPR framework and Norway’s data protection standards as comparable safeguards.

Where the process actually stands

Unlike a law passed through Switzerland’s parliament, the OSCPT revision is a federal ordinance, which the Federal Council can adopt without a parliamentary vote and, critically, without triggering Switzerland’s usual public referendum mechanism. Critics, including privacy companies and civil society groups, have specifically flagged this procedural path as a way to sidestep the kind of public scrutiny a change with this scope would normally receive.

The public consultation period on the proposal closed in mid-2025 with substantial pushback from privacy-focused companies, digital rights groups, and political parties. As of mid-2026, the Federal Council has not issued a final version of the ordinance, and no implementation date has been set. The proposal remains in legal limbo: not withdrawn, not finalized, and not scheduled for a public vote.

Why this matters beyond Switzerland

ProtonVPN is one of the most highly rated VPNs in our own database, and Swiss jurisdiction has consistently been cited, including by us, as one of its structural privacy advantages: no membership in Five Eyes, Nine Eyes, or Fourteen Eyes intelligence-sharing alliances, and historically strong statutory data protections. If Switzerland’s legal environment shifts toward mandatory identification and data retention for VPN providers, that advantage weakens regardless of how the affected companies respond individually.

This is also a preview of a broader regulatory pattern already visible elsewhere in Europe: our coverage of the EU’s Chat Control extension and the EU’s data retention proposals both reflect the same underlying tension between law enforcement access and end-to-end encrypted, no-logs services. Switzerland’s ordinance, notably, is being pursued through an even less visible procedural route than either of those EU processes.

Why Switzerland’s referendum system makes this unusual

Switzerland is known internationally for its direct democracy: citizens can force a public vote on legislation they oppose by gathering enough signatures, a mechanism that has historically given Swiss voters real influence over major policy changes. An ordinance issued directly by the Federal Council, rather than a law passed through parliament, does not carry the same referendum trigger, which is precisely the criticism privacy advocates have raised: a surveillance expansion of this scope, they argue, is exactly the kind of decision the referendum system exists to let the public weigh in on, and the ordinance route sidesteps that by design rather than by accident.

How other Swiss privacy companies are responding

Proton isn’t the only Swiss privacy company weighing in. Threema, the encrypted messaging app, and NymVPN have both publicly opposed the ordinance on similar grounds, warning that mandatory decryption and user-identification requirements would undercut the specific legal environment that made Switzerland attractive to privacy-focused companies in the first place. Not every Swiss provider agrees on the response, however: some Swiss cloud and hosting companies have taken a more conciliatory stance during the consultation process, arguing that compliance is manageable and that relocating infrastructure is an overreaction to a proposal that hasn’t been finalized. That split within the Swiss privacy sector is itself part of the story: it shows genuine uncertainty about how the ordinance will land, not a unified industry response.

What happens if the ordinance passes as written

If the Federal Council adopts the OSCPT revision in its current form, VPN providers based in Switzerland with more than 5,000 users would need to build the technical and legal infrastructure to identify customers and retain metadata, a fundamental shift for any provider whose entire product is built around not doing exactly that. For a no-logs VPN, this isn’t a matter of adjusting a policy document, it would require rearchitecting how the service handles user data at a structural level, which is precisely why Proton has framed its choice as compliance or departure rather than a smaller middle-ground adjustment.

What this doesn’t change yet

Proton has been explicit that its infrastructure changes so far are precautionary and targeted, not a full exit from Switzerland, and that its no-logs policies and end-to-end encryption remain unchanged regardless of where servers are physically located. ProtonVPN remains one of our top-rated picks for privacy-focused users while this plays out. ProtonVPN’s SOC 2 Type II certification and fourth consecutive no-logs audit, both completed in 2026, are unaffected by this ordinance process and reflect current operational reality, not a hedge against a law that hasn’t taken effect.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Our take

Switzerland's proposed OSCPT revision remains unresolved as of mid-2026, stuck in a procedural limbo that avoids both a parliamentary vote and a public referendum. Proton's decision to start moving infrastructure out of the country before the law is even finalized is a signal worth watching: it suggests the company sees a meaningful chance the ordinance passes in a form incompatible with its privacy commitments. For now, ProtonVPN's no-logs policy and audit record remain intact, but Swiss jurisdiction as a privacy selling point is less certain than it was a year ago.

If Swiss jurisdiction uncertainty gives you pause, NordVPN’s Panama jurisdiction is a well-audited alternative with no comparable legislative threat on the horizon.

Keep reading: ProtonVPN Review 2026: The Privacy-First Choice and Five Eyes, Nine Eyes, and Fourteen Eyes Explained.