Microsoft 365 Data Residency in Switzerland: FADP-Compliant Configuration 2026

    Back to Blog
    Microsoft 365Featured

    Microsoft 365 Data Residency in Switzerland: FADP-Compliant Configuration 2026

    Replit Enterprise Self-Serve for Swiss companies: Build SME agents without an IT department – how your team gets started in 30 minutes.

    April 16, 202611 min read read
    Christian Flückiger

    Christian Flückiger

    Solution Architect

    christian.flueckiger@cnext.ch
    10+ Jahreexperience·SharePoint & Microsoft Teams
    CNEXT Microsoft Partner

    Quick Answer

    Replit Enterprise Self-Serve for Swiss companies: Build SME agents without an IT department – how your team gets started in 30 minutes.

    Since the revised Swiss Federal Act on Data Protection (FADP / nDSG) came into force on 1 September 2023, Swiss enterprises must document and operate data processing transparently. Microsoft 365 can absolutely be operated in a FADP-compliant way – provided data residency, contracts and configuration are right. This guide shows how.

    Swiss Microsoft data centres

    Microsoft has operated Swiss cloud regions since 2019:

    • Switzerland North (Zurich) – primary
    • Switzerland West (Geneva) – secondary / disaster recovery

    These regions back Microsoft 365 Multi-Geo, Azure services and, since 2023, Microsoft Defender, Purview and other services.

    Which Microsoft 365 data stays in Switzerland?

    With Microsoft 365 Multi-Geo Capability Swiss tenants can keep the following core data in Swiss data centres:

    ServiceSwiss data residency?
    Exchange Online (mailboxes)✅ Yes
    SharePoint Online (site content)✅ Yes
    OneDrive for Business✅ Yes
    Teams files✅ Yes (stored in SharePoint/OneDrive)
    Teams chat messages✅ Yes (Substrate)
    Teams meeting recordings✅ Yes (OneDrive/SharePoint)
    Microsoft 365 Copilot indexing⚠️ Partial – metadata global
    Microsoft Defender logs⚠️ EU Data Boundary, not CH
    Microsoft Purview audit logs⚠️ EU Data Boundary

    For data classes only available in the EU, the EU Data Boundary (since 2023) ensures data and logs are processed exclusively in EU/EFTA data centres – including support access.

    Enable Microsoft 365 Multi-Geo

    Multi-Geo allows a tenant to store data in multiple geographies simultaneously – including Switzerland. Requirements:

    • At least 5,000 Microsoft 365 Multi-Geo Capability licences (~CHF 2.40 / user / month extra)
    • Tenant default region can be set to Switzerland
    • Per-user Preferred Data Location (PDL) configuration

    For SMBs under 5,000 users: setting the tenant default to Switzerland is usually enough (no Multi-Geo required). Existing tenants can be migrated to Switzerland – a typical CNEXT project.

    Data Processing Addendum (DPA)

    The Microsoft Data Protection Addendum is part of the Microsoft Online Services Terms. Swiss enterprises must ensure:

    • Current DPA version (2024 or later) is part of their Microsoft contracts
    • Standard Contractual Clauses (SCC) and Swiss addendum are signed
    • Microsoft's sub-processor list is documented (for FADP Art. 9)

    Sensitivity Labels and DLP

    Data residency alone is not enough. Swiss enterprises need a classification and protection concept:

    • Sensitivity Labels (Microsoft Purview Information Protection): minimum 3 tiers
    • DLP rules for personal data (AHV/social security numbers, credit cards), trade secrets, contract data
    • Auto-labelling for sensitive content
    • Encryption (e.g. Double Key Encryption for top secret)

    Processing register (FADP Art. 12)

    Swiss enterprises with 250+ employees (or high risk) must maintain a register of processing activities. CNEXT provides a Microsoft 365–specific template covering services, data categories, recipients, residency, retention, sub-processors and TOMs.

    Preparing for an FDPIC audit

    In case of an audit by the FDPIC, the following documents should be ready:

    1. 1Register of processing activities
    2. 2Microsoft DPA including Swiss addendum
    3. 3Sensitivity Labels concept and implementation evidence
    4. 4Data residency configuration (tenant setting screenshots)
    5. 5Adoption evidence (training, employee information)

    Conclusion

    Microsoft 365 can be fully FADP-compliant in 2026. Requirements: Swiss data residency (or EU Data Boundary), current DPA, Sensitivity Labels, DLP and a documented processing register. CNEXT supports Swiss enterprises across the entire configuration – from licence analysis to FDPIC audit readiness.

    Microsoft 365DSGComplianceSchweiz
    Teilen:

    This article was created with the support of AI and reviewed by our team. We use AI tools to produce high-quality content efficiently — the editorial responsibility always lies with our experts.

    Christian Flückiger

    Christian Flückiger

    Solution Architect

    FADP-compliant Microsoft 365 configuration

    Have CNEXT audit your Microsoft 365 tenant.