Switzerland built its reputation as a privacy haven - the country encrypted email and VPN providers chose precisely because its law did not force them to log or identify users. A proposed surveillance reform now threatens exactly that, and it has already pushed the biggest name in Swiss privacy, Proton, to start moving its infrastructure abroad. The company's founder went as far as to say the only comparable law in Europe belongs to Russia.
What the proposed reform would require
At issue is a revision of the VÜPF, Switzerland's ordinance on the surveillance of postal and telecommunications traffic. Crucially, the government is pushing it as an amendment to an ordinance - a change the Federal Council and the justice department can make without a full act of parliament. According to the draft, any email, messaging or VPN service with as few as 5,000 users would have to:
- Verify identity: collect a government-issued ID at sign-up, making anonymous accounts effectively impossible.
- Retain metadata: keep IP addresses, names, phone numbers and related connection data for six months.
- Hand over readable data: be technically able to deliver a user's data to authorities in plain text on request - in practice, stripping transport-level encryption - though genuine end-to-end messages exchanged between users are exempted.
Critics point out that authorities could reach much of this retained data through a simple request rather than a court order. The public consultation has already closed with heavy pushback from privacy firms, civil-society groups and political parties, and as of now the Federal Council has not finalised the text - so this is a live proposal, not yet law.
Why Proton is pulling out now
Proton, which runs Proton Mail and Proton VPN, is not waiting to find out. It has begun relocating IT infrastructure out of Switzerland, placing servers for its newer products in Germany and building out a presence in Norway, backed by a planned investment of more than 100 million euros in the EU. Founder Andy Yen framed the stakes bluntly: "The only country in Europe with a roughly equivalent law is Russia," adding that the company would have "no choice but to leave" if the amendment goes through. Other Swiss privacy outfits, including the network-privacy project Nym, have joined the opposition.
Why this matters for VPN users
The entire appeal of a Swiss-based VPN was the legal ground beneath it: a jurisdiction that did not compel logging meant a no-logs promise had real force. A rule that requires ID checks and six months of retained metadata inverts that - it turns a privacy provider into a data-retention point. This is the uncomfortable truth behind every no-logs claim: it is only ever as strong as the law of the country the provider answers to.
It is also a pattern, not a one-off. We saw the first stage of this story when Proton first announced it was moving servers out of Switzerland, and a similar clash surfaced around Canada's Bill C-26 and the encrypted services weighing an exit over it. Yen's comparison to Russia is pointed precisely because forced decryption and mandatory identity checks are the hallmark of the backdoor laws we have tracked across Russia, the UK, Canada and Australia - and Switzerland was supposed to be the counterexample.
For anyone choosing a VPN, the takeaway is not "avoid Switzerland" - it is to look past the marketing to the law. Where a provider is legally reachable determines what it can be forced to collect and reveal about you, no matter how strong its privacy branding. That question of jurisdiction has quietly become one of the most important things to check before you trust any provider with your traffic.