GDPR-Compliant Monitoring Tools for Swiss Companies 2026
Is EU hosting legal for Swiss companies? revDSG, EU adequacy and the Swiss country list explained — plus GDPR-compliant monitoring tools compared.
Swiss companies choosing a monitoring tool in 2026 face a question German and French teams don’t have: which data protection law actually applies to us — the Swiss revDSG, the EU GDPR, or both? And is an EU-hosted tool even the right choice for a Swiss company, or does the data need to stay in Switzerland?
The short answer: for the large majority of Swiss companies, EU hosting is legally just as clean as Swiss hosting — Switzerland and the EU mutually recognise each other’s data protection level as adequate. The problematic category isn’t EU tools; it’s US tools. This guide explains the legal situation as of July 2026, shows where genuine Swiss data residency is actually required, and compares the relevant monitoring options.
A word on transparency up front: FoundersDeck, the provider behind this blog, is hosted in the EU (Nuremberg, Germany) — not in Switzerland. Why that’s no disadvantage for most Swiss companies, and when it is, is covered openly in this article.
Which Law Applies? revDSG, GDPR — or Both
Since September 1, 2023, Switzerland’s fully revised Data Protection Act (revDSG, also called nDSG) has been in force. It applies to every processing of personal data by Swiss companies — with no transition period and no de-minimis threshold.
The GDPR applies to Swiss companies in addition when one of the two conditions of Art. 3(2) GDPR is met: the company visibly targets its offering at people in the EU (euro pricing, EU domains, EU-focused marketing), or it monitors the behaviour of people in the EU. For most Swiss SaaS companies, agencies and e-commerce businesses with EU customers, the practical reality is: both regimes in parallel.
Why does this matter for monitoring specifically? Because monitoring data contains more personal data than is visible at first glance: alert email addresses and on-call contacts, subscribers of public status pages, IP addresses of status page visitors, sometimes user identifiers in incident notifications. That makes your monitoring provider a processor — Art. 9 DSG under Swiss law, Art. 28 GDPR under EU law — with everything that entails: a contract, a sub-processor list, a transfer assessment.
The 2026 Legal Situation in Three Points
If you take only one thing from this article, take these three verifiable facts:
- The EU recognises Switzerland as adequate. The adequacy decision has existed since 2000; on January 15, 2024, the European Commission confirmed after its first review under the GDPR that Switzerland continues to provide an adequate level of protection. Data can flow freely from the EU to Switzerland.
- Switzerland recognises the EU as adequate. All EU and EEA states are on the country list in Annex 1 of the Swiss Data Protection Ordinance (DSV, based on Art. 16(1) DSG). Data can flow from Switzerland to the EU without additional safeguards — hosting in Germany is legally uncomplicated from a Swiss perspective.
- For the USA, the Swiss-U.S. Data Privacy Framework has applied since September 15, 2024 — but only for certified US companies, and it changes nothing about the US CLOUD Act.
The consequence for tool selection: from a revDSG perspective, there is no legal difference in data transfer between a Swiss and an EU provider. The real dividing line runs between EU/Switzerland on one side and US jurisdiction on the other.
Why EU Hosting Is Legally Clean for Swiss Companies
The country list makes this case simple: when a Swiss company transfers personal data to a provider in Germany, Belgium or France, that is a disclosure to a state with an adequate level of protection (Art. 16(1) DSG in conjunction with Annex 1 DSV). It requires no standard contractual clauses, no transfer impact assessment and no consent from data subjects for the cross-border element.
There’s a practical bonus for Swiss companies with EU customers: if you fall under the GDPR anyway, you need to demonstrate a clean processing chain to your EU customers. A monitoring provider incorporated and hosted in the EU slots into that chain without opening a new third-country discussion — the Swiss company itself is the only “third country” in the chain, and that one is covered by the EU’s adequacy decision for Switzerland.
Put the other way around: an EU-hosted, EU-operated monitoring tool satisfies both regimes at once — the revDSG via the country list, the GDPR natively. That’s why this guide treats EU providers not as a compromise but as the default recommendation for Swiss teams.
Which providers are actually EU-incorporated and where their data lives is documented in our EU SaaS Jurisdiction Database — 57 tools, verified against each vendor’s imprint, terms and privacy policy.
US Tools from a Swiss Perspective: DPF, CLOUD Act and the GDPR Trap
Since September 15, 2024, the situation for US tools is formally more relaxed: the Federal Council added the USA — limited to companies certified under the Swiss-U.S. Data Privacy Framework — to Annex 1 of the DSV. Transfers to certified US providers are therefore permitted under the revDSG without additional safeguards.
To be fair: a Swiss company using UptimeRobot, Pingdom or BetterStack is not automatically acting unlawfully. Three caveats remain:
1. Certification is provider-specific. The DPF only covers companies that are actively certified and maintain their certification. That has to be verified and documented per provider — and lapses if the provider drops out of the program.
2. The DPF changes nothing about the CLOUD Act. The US CLOUD Act compels US-incorporated companies to hand over customer data to US authorities — regardless of server location. For monitoring tools this is especially relevant, because monitor URLs, response times and incident histories reveal your infrastructure topology and its weak points. With a US provider, that metadata remains reachable by US authorities, DPF or not.
3. The GDPR trap for EU-facing Swiss companies. If you fall under the GDPR in parallel, the US transfer must also be justified under EU law. The EU-US counterpart to the DPF exists, but has been under political and legal scrutiny since its introduction — its predecessors Safe Harbor and Privacy Shield were both struck down by the CJEU. If you’d rather not build your compliance architecture on the survival of a contested framework, choose the route that doesn’t need one: an EU or Swiss provider.
In short: for Swiss companies, US tools are “permitted, with verification effort, documentation duty and residual risk”. EU tools are “permitted, full stop”.
When You Need Genuine Swiss Data Residency
Honesty cuts both ways: there are constellations where EU hosting isn’t enough — but they concern a minority of Swiss companies, and the requirement then comes from sector-specific or contract law, not from the revDSG:
- FINMA-supervised institutions: the outsourcing circular FINMA-RS 2018/3 and Swiss banking secrecy (Art. 47 BankG) mean in practice that banks and insurers often contractually require Swiss data storage, or permit processing abroad only under strict additional conditions — including for seemingly “technical” data.
- Public bodies: cantonal data protection laws contain their own conditions for processing abroad; public tenders not infrequently demand a Swiss data location explicitly.
- Contractual commitments: if you’ve promised your own customers that “data stays in Switzerland”, you can hardly send monitoring metadata to Nuremberg.
For these cases, the most defensible route is self-hosting on Swiss infrastructure: an open-source tool like Uptime Kuma on a Swiss provider (Infomaniak, Exoscale, cyon). No third party, no processing on behalf, no transfer question — the data never leaves your own Swiss environment.
A note from our research: there are services advertising “Swiss uptime monitoring”. For the offerings we checked (as of July 2026, including alptime.ch and swiss-monitor.ch), no operating legal entity could be found on their public pages — no imprint with a legal form, commercial register entry or responsible person. Apply the same standard here that this guide applies to every tool: if you can’t verify the operator, you can’t verify the data sovereignty promise either. A “Swiss” label in the name is no substitute for a verifiable imprint.
The Tools Compared
The selection criteria match our EU monitoring guide, extended by the Swiss perspective: operator jurisdiction (EU/Switzerland rather than US), guaranteed data residency rather than “EU region available”, an instantly available DPA, a transparent sub-processor list — and the question of which reliability primitives (uptime, heartbeat, status page) are covered.
1. FoundersDeck — EU-Hosted All-in-One Platform (Nuremberg)
FoundersDeck is an EU-first reliability platform, built in Germany and hosted exclusively on Netcup infrastructure in Nuremberg. For Swiss teams the assessment is simple: Germany is on the country list (Annex 1 DSV), the transfer is permitted without additional safeguards — and if you fall under the GDPR as well, EU compliance comes built in.
What makes the difference:
- Four primitives in one platform: uptime monitoring (HTTP, ping, keyword, 30-second intervals), heartbeat/cron monitoring, public status pages and multi-channel alerts — instead of three tools with three contracts and three sub-processor lists
- Cookie-free status pages — no consent banner needed; relevant because every status page visitor is a data subject
- 100% German infrastructure — not “EU region available” but exclusively Germany, documented on the Trust page
- DPA as instant download — no sales call, straight into your records of processing
Price: free tier (5 monitors, 1 status page, email alerts), paid plans from €9/month
Data sovereignty: EU (exclusively Germany, Nuremberg) — not Switzerland; not the right choice for hard FINMA-grade residency requirements, the uncomplicated one for every other Swiss team
Ideal for: Swiss founders, SaaS teams and agencies with EU customers who want to cover the revDSG and the GDPR with a single provider
2. Oh Dear — EU Option for Laravel/PHP Teams
Oh Dear is a Belgian monitoring tool from the team behind Spatie. Belgium is on the Swiss country list, so the transfer question doesn’t arise. Strong on extended checks: broken links, mixed content, certificate monitoring, scheduled tasks.
Price: from €13/month (no free tier, 10-day trial)
Data sovereignty: EU (Belgium)
Ideal for: PHP/Laravel teams in the Spatie ecosystem that need more than plain HTTP monitoring
3. Uptime Kuma on Swiss Infrastructure — Self-Hosting for Swiss Data Residency
Uptime Kuma is the leading open-source self-hosted monitoring tool — free, 90+ monitor types, active community. Run on a Swiss provider (Infomaniak, Exoscale, cyon), it is the only route in this comparison to hard Swiss data residency: no third party, no processing on behalf, no transfer question.
Price: free (software) + Swiss hosting costs
Data sovereignty: Switzerland — if that’s where you host it
Caveat: you run the monitoring infrastructure yourself — updates, availability of the monitor, alert delivery and audit logs are your responsibility. And: who monitors the monitoring? An external heartbeat on your self-hosted Kuma is mandatory.
Ideal for: FINMA-adjacent setups, public-sector buyers with a Swiss-location requirement, teams with ops capacity
4. Hyperping — API Monitoring from France
Hyperping is a French provider focused on API monitoring, synthetic checks and fast alerting. France is on the country list — uncomplicated from a Swiss perspective.
Price: free entry tier, paid plans from around $24/month
Data sovereignty: EU (France)
Ideal for: API-heavy products that need granular endpoint checks and fast alerts
5. Healthchecks.io — Heartbeat Monitoring from Latvia
Healthchecks.io is the specialist for cron job and heartbeat monitoring, operated from Latvia (EU). 20 checks free, open source with a self-hosting option — including on Swiss infrastructure.
Price: 20 heartbeat checks free, paid plans above that
Data sovereignty: EU (Latvia); self-hosted: your choice
Ideal for: teams that exclusively monitor cron jobs and background workers — uptime and status pages need a second tool
Decision Guide for Swiss Teams
Swiss SaaS company with EU customers, one tool for everything? → FoundersDeck (revDSG + GDPR covered with a single provider)
FINMA-regulated or contractually bound to Swiss data storage? → Uptime Kuma self-hosted on Infomaniak/Exoscale — plus an external heartbeat on the Kuma itself
Laravel shop with budget? → Oh Dear
Only monitoring cron jobs? → Healthchecks.io
US tool in place and no migration planned (yet)? → verify and document the provider’s DPF certification, assess the CLOUD Act residual risk — and price out the EU alternative at the next contract renewal
The rule of thumb is the same as in our EU comparison: the dividing line is not Switzerland vs. the EU — both sides recognise each other as adequate. The dividing line is EU/Switzerland vs. US jurisdiction. Draw it once, cleanly, and you’ve solved the transfer question for the revDSG and the GDPR at the same time.
Frequently Asked Questions
Does the GDPR apply to Swiss companies?
Switzerland is not an EU member, so Swiss companies are primarily governed by the revised Swiss Data Protection Act (revDSG, in force since September 1, 2023). The GDPR applies in addition through its extraterritorial scope (Art. 3(2) GDPR) as soon as a Swiss company visibly targets its offering at people in the EU or monitors the behaviour of people in the EU. For most Swiss SaaS companies with EU customers, that means both regimes apply in parallel — and a monitoring setup that satisfies the stricter GDPR requirements will, as a rule, cover the revDSG requirements as well.
Can a Swiss company host its monitoring data in the EU?
Yes, without any additional safeguards. The revDSG permits disclosure of personal data abroad when the Federal Council has recognised the destination country as providing an adequate level of data protection (Art. 16(1) DSG). All EU and EEA states are on that country list in Annex 1 of the Swiss Data Protection Ordinance (DSV). Hosting in Germany — Nuremberg, for example — is legally just as straightforward from a Swiss perspective as hosting in Switzerland itself: no standard contractual clauses, no additional safeguards, no transfer impact assessment required.
What about US monitoring tools under the Swiss-U.S. Data Privacy Framework?
Since September 15, 2024, the Federal Council treats US companies certified under the Swiss-U.S. Data Privacy Framework as providing adequate protection — commercial transfers to such providers are permitted without additional safeguards. Three caveats remain: first, this only covers certified companies, and certification must be verified per provider. Second, the DPF changes nothing about the US CLOUD Act — US authorities can still compel US-incorporated providers to hand over customer data, regardless of server location. Third, once the GDPR applies in parallel (EU customers), the transfer must also be clean under EU law. Choosing an EU or Swiss provider avoids this entire verification cascade.
When does a Swiss company need genuine Swiss data residency?
For most Swiss companies, EU hosting is legally sufficient — the country list makes the EU an unproblematic destination. Stricter requirements typically come from sector-specific or contract law, not from the revDSG: FINMA-supervised institutions are subject to the outsourcing circular (FINMA-RS 2018/3) and Swiss banking secrecy (Art. 47 BankG), which in practice often leads to contractually required Swiss data storage. Public bodies fall under cantonal data protection laws, some of which impose their own conditions on processing abroad. If you need hard Swiss data residency for monitoring, the most defensible route is self-hosting (e.g. Uptime Kuma) on Swiss infrastructure such as Infomaniak or Exoscale.
What’s the difference between the revDSG and the GDPR for monitoring?
Both laws protect personal data, and monitoring data contains more of it than many teams expect: alert email addresses and on-call contacts, status page subscribers, IP addresses of status page visitors. The practical differences: the GDPR requires data processing agreements under Art. 28 with detailed mandatory content, while the revDSG regulates processing on behalf in the leaner Art. 9 DSG. GDPR fines reach 4% of global revenue and target the company; revDSG fines reach CHF 250,000 and target the responsible individual. For tool selection the difference is small: a provider with EU data residency, an instantly available DPA and a transparent sub-processor list satisfies both regimes.
Engin Yildirim
Founder of FoundersDeck. 13+ years in software engineering. Building EU-first tools for founders.
Read more about me →