Since the revised Swiss Federal Act on Data Protection (FADP / nDSG) came into force on 1 September 2023, Swiss enterprises must document and operate data processing transparently. Microsoft 365 can absolutely be operated in a FADP-compliant way – provided data residency, contracts and configuration are right. This guide shows how.
Swiss Microsoft data centres
Microsoft has operated Swiss cloud regions since 2019:
- Switzerland North (Zurich) – primary
- Switzerland West (Geneva) – secondary / disaster recovery
These regions back Microsoft 365 Multi-Geo, Azure services and, since 2023, Microsoft Defender, Purview and other services.
Which Microsoft 365 data stays in Switzerland?
With Microsoft 365 Multi-Geo Capability Swiss tenants can keep the following core data in Swiss data centres:
| Service | Swiss data residency? |
|---|---|
| Exchange Online (mailboxes) | ✅ Yes |
| SharePoint Online (site content) | ✅ Yes |
| OneDrive for Business | ✅ Yes |
| Teams files | ✅ Yes (stored in SharePoint/OneDrive) |
| Teams chat messages | ✅ Yes (Substrate) |
| Teams meeting recordings | ✅ Yes (OneDrive/SharePoint) |
| Microsoft 365 Copilot indexing | ⚠️ Partial – metadata global |
| Microsoft Defender logs | ⚠️ EU Data Boundary, not CH |
| Microsoft Purview audit logs | ⚠️ EU Data Boundary |
For data classes only available in the EU, the EU Data Boundary (since 2023) ensures data and logs are processed exclusively in EU/EFTA data centres – including support access.
Enable Microsoft 365 Multi-Geo
Multi-Geo allows a tenant to store data in multiple geographies simultaneously – including Switzerland. Requirements:
- At least 5,000 Microsoft 365 Multi-Geo Capability licences (~CHF 2.40 / user / month extra)
- Tenant default region can be set to Switzerland
- Per-user Preferred Data Location (PDL) configuration
For SMBs under 5,000 users: setting the tenant default to Switzerland is usually enough (no Multi-Geo required). Existing tenants can be migrated to Switzerland – a typical CNEXT project.
Data Processing Addendum (DPA)
The Microsoft Data Protection Addendum is part of the Microsoft Online Services Terms. Swiss enterprises must ensure:
- Current DPA version (2024 or later) is part of their Microsoft contracts
- Standard Contractual Clauses (SCC) and Swiss addendum are signed
- Microsoft's sub-processor list is documented (for FADP Art. 9)
Sensitivity Labels and DLP
Data residency alone is not enough. Swiss enterprises need a classification and protection concept:
- Sensitivity Labels (Microsoft Purview Information Protection): minimum 3 tiers
- DLP rules for personal data (AHV/social security numbers, credit cards), trade secrets, contract data
- Auto-labelling for sensitive content
- Encryption (e.g. Double Key Encryption for top secret)
Processing register (FADP Art. 12)
Swiss enterprises with 250+ employees (or high risk) must maintain a register of processing activities. CNEXT provides a Microsoft 365–specific template covering services, data categories, recipients, residency, retention, sub-processors and TOMs.
Preparing for an FDPIC audit
In case of an audit by the FDPIC, the following documents should be ready:
- 1Register of processing activities
- 2Microsoft DPA including Swiss addendum
- 3Sensitivity Labels concept and implementation evidence
- 4Data residency configuration (tenant setting screenshots)
- 5Adoption evidence (training, employee information)
Conclusion
Microsoft 365 can be fully FADP-compliant in 2026. Requirements: Swiss data residency (or EU Data Boundary), current DPA, Sensitivity Labels, DLP and a documented processing register. CNEXT supports Swiss enterprises across the entire configuration – from licence analysis to FDPIC audit readiness.

