Switzerland’s Federal Council is consulting on an amendment to its telecommunications surveillance ordinance (VÜPF) that would significantly extend monitoring and data‑retention obligations from traditional telecom operators to a broad category of “derived service providers” such as VPNs, secure email, messaging apps, and social networks. The proposal would apply to online services with at least 5,000 active users or turnover above a set threshold, obliging them to store connection metadata (including IP addresses and ports) for six months, identify users through official ID or phone number, and be technically able to deliver requested data to authorities in plain text. Public consultation on the draft runs until May 6, 2025, and as an ordinance-level revision it does not require a parliamentary vote or popular referendum under Swiss law. Privacy advocates warn that these changes would erode Switzerland’s long‑standing reputation as a privacy‑friendly jurisdiction, where strong constitutional protections, the Data Protection Act, and current practice have historically forbidden general data retention and protected no‑log VPN and secure communication services. Providers such as Proton and NymVPN, along with civil-society groups, argue the amendment would effectively end anonymous use of many Swiss‑based online services and force them to redesign infrastructure to facilitate decryption or traffic capture at their end, even if end‑to‑end encryption strictly between users is nominally exempt. While the draft is not yet in force and may be revised following consultation, the process signals a shift toward more expansive state surveillance in Switzerland that could reshape the country’s role as a hub for privacy‑focused digital services.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Encryption

Comments