Why Switzerland? An Analysis of Swiss Privacy Laws

Updated June 6, 2019

We are often asked why ProtonMail is based in Switzerland and whether there are real advantages to being a Swiss company. We believe there are several good reasons to call Switzerland home, and this article explains why.

ProtonMail’s roots are from the European Organization for Nuclear Research (CERN) in Geneva, where many of our early team members worked together on particle physics experiments. Thus, ProtonMail was born in Switzerland back in 2014. When we investigated the legal considerations about where to establish our growing service, it became clear that Switzerland was in fact a hospitable location for a tech company focused on privacy.

Unless you host your servers on a boat in international waters, you will need to be under some legal jurisdiction. Choosing one is particularly important because, as the Lavabit example shows, local laws can have an existential impact on the service. Given that we serve users with highly sensitive privacy and security requirements from around the world, Switzerland, being outside of US and EU jurisdiction, has the advantage of being a neutral location.

Switzerland also has a long history of privacy and security, dating back over a century, and its laws are much more protective of individual privacy rights. In the US and EU, gag orders can be issued to prevent an individual from knowing they are being investigated or under surveillance. While these type of orders also exist in Switzerland, the prosecutors have an obligation to notify the target of surveillance, and the target has an opportunity to appeal in court. There are no such things as National Security Letters, and all surveillance requests must go through the courts. Furthermore, while Switzerland is party to international assistance treaties, such requests for information must hold up under Swiss law, which has much stricter privacy provisions.

Nearly every country in the world has laws governing lawful interception of electronic communications for law enforcement purposes. In Switzerland, these regulations are set out in the Swiss Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTT), which was last revised on March 18, 2018. While parts of the SPTT are still in dispute and subject to various legal challenges within Switzerland (including a challenge from ProtonMail), the present interpretation does not subject ProtonMail to any mandatory data retention directives; nor does it enforce upon us a full obligation to identify ProtonMail users. Moreover, as a Swiss company, ProtonMail also cannot be compelled to engage in bulk surveillance on behalf of US or Swiss intelligence agencies.

While ProtonMail benefits from strong legal protections within Switzerland, we have also built in technological safeguards against surveillance, such as utilizing end-to-end encryption. We do not possess the keys required to decrypt users’ emails. Even emails between non-ProtonMail accounts cannot be decrypted on our servers thanks to our use of zero-access encryption. As a result, even if ProtonMail was forced to turn over all our computer systems, email contents will continue to be encrypted. These technical safeguards are the strongest privacy protections because unlike national laws, the laws of mathematics cannot be changed or altered.

We believe comprehensive security can only be achieved through a combination of technology and legal protections, and Switzerland provides the optimal combination of both. Because of Switzerland’s advanced IT infrastructure and its unique legal environment, ProtonMail can deliver a service that is both reliable and secure.

For more information about Internet surveillance in Switzerland and requests for information made to ProtonMail, please view our Transparency Report.

190 comments on "Why Switzerland? An Analysis of Swiss Privacy Laws

    • The bending of Swiss banks to the US has to be taken in context. Giving up the information of American tax-evaders is one thing, but violating personal privacy rights is a line the Swiss government is much less likely to cross. While the banks had information to give up, ProtonMail doesn’t actually have unencrypted user data to share.

        • Swiss direct democracy does have its downsides, in the years we have lived there, we have seen some pretty terrible measures passed via referendum. However, none of them have involved compromising privacy.

  • Please explain all encryption used to protect login password and if that password remains encrypted on your servers or is destroyed…

    • We only have a salted hash of your login password on our servers. The login password needs to come to the server in some form, there’s no other way to authenticate the account.

      • Actually, there might be an even safer authentication process to be found, maybe through Zero-knowledge proof of password, or at least any form of strong cryptographic auth challenge to avoid the sending of a password or any other secret over the network (we should not fully rely on SSL), don’t you think? Anyhow, kudos for your work! :-)

      • Actually that is changing with agron2 (obviously not tested enough yet) but something to definitely take a look at in the near future. Argon2 has been memory hardened meaning that it is “never” going to be easier on a gpu than a cpu as some of the older hashes have issues with…

  • As a former Lavabit user I applaud you in your attempt to provide a service that exceeds lavabits level of protection. I look forward to using your product that will help my personal business grow in a safe and secure manner.

  • Is Protonmail purely web based or is it possible to configure MS Outlook or other email client to be able to use it?

  • I think instead of criticizing the ProtonMail team, people should enjoy the hard work they’re putting in. Not everyone is capable of doing as clean and clever a job as they do. They really put their hearts into it, and I really cant wait to see my invite pop in my inbox. As a matter of fact, I verify my inbox practically all the time all day long on all my devices no matter where I am. I can’t wait to have my ProtonMail account! I trust you guys to do the right job! Go, guys, go!

    • Can I get an AMEN! Yes, you are very right! Anyone with any kind of coding background should be in AWE of these guys! SHOUT THEIR PRAISES FROM THE MOUNTAIN TOPS because they are doing something more than merely TALKING about it!

        • Agree. Just got my ProtonMail account setup and very happy about it. Inviting my friends to create themselves a ProtonMail account. Love the work of all those who created ProtonMail. :)

  • Very happy to have my protonmail account active, there is trust and there is floss, how much of the code will eventually be floss?

  • No one has mentioned what a great message this sends to Yahoo and Google, perhaps in the future they will think twice about compromising our privacy when their accounts take flight and move to Switzerland. I’m a Swiss/American and I’m familiar with the downside of both countries. I’d trust the Swiss to look out for personal privacy before I’d trust the US.
    Thanks for your contribution to making our lives safer ProtonMail.

  • What if a smartphone manufacturer were to see all your keystrokes anyway? Most smartphone keyboards nowadays come built in with cloud-syncing, personalized suggestions / dictionaries. Not sure I feel safe entering my passwords on a smartphone. What if that were to happen for Desktop browsers too?

    • With open source browsers that will be detected faster than closed source ones. Same goes with operating systems.

      There are “Msg/month”. Is that going to increase after beta or is it just beta stuff?

      • The monthly message limit was just increased to 1000/month. We may increase this further, right now it is set to avoid people using ProtonMail to send spam.

  • This provides an extra measure of security between essentially warrant less data collection and the end user. By forcing the DoJ to operate through Swiss courts, it ensures that investigations are in fact legitimate and are not simply broad, sweeping investigations of anyone and everyone, which can most certainly include political dissidents, in essence helping to secure democracy against the agitations of the 21st century.

    • Thank you for the support! We regularly do tests and ask for help with auditing our server architecture. We plan to open source ProtonMail at some point in the future!

  • With the vote on 25 september 2016 of the Federal Act on the Intelligence Service (Intelligence Service Act, ISA) https://www.admin.ch/gov/en/start/documentation/votes/20160925/intelligence-service-act.html and the non-completion of the referendum against the Surveillance of Postal and Telecommunications Traffic (SPTT) (BUEPF in german ; LSCPT in french) https://www.lscpt.ch/ I think this article must be updated.

    What is the consequences of these laws for protonmail ?

    thx for your answer

  • if i have a protonmail account, would my mail recipient need one also to be able to read my message, Would mail to me from any one without an account be encripted.

  • I applaud your service and choice of Switzerland. However, I mean, all a user has to do is download gpg (open source), encrypt message on an old air-gapped computer using receiver public key, copy over encrypted text to connected computer and send via any email medium (gmail, outlook, all the known NSA puppets).

    At that point it really doesn’t matter where the message finally sits – it is, well and truly, end-to-end encrypted.

    Headers are going to be captured regardless.

  • The law in Switzerland about online privacy has recently changed. What does that mean for proton users?

  • If I use ProtonMail, will my contacts list on ProtonMail be encrypted on your servers as well?

  • If I send email from Proton to any other email account, such as Gmail, can Google intercept and decode that email or, is it not possible for them to read it?

  • The thing to remember about protecting your privacy is that the more private you want to be, the more expensive it becomes. Encrypted email is a big problem for overseas intelligence agencies. The NSA actually gave up trying to crack https email. So their solution is to hoover up all email messages going over the internet and creating the worlds biggest server farm to do that in the US state of Utah. They hope that one day they will have the technology to decrypt it all. But there is so much data that it will be an impossibility.
    The weakness of contemporary intelligence gathering is that human intelligence has given way to electronic methods. This is good for the person who needs absolute privacy. Just stay away from the internet completely and that also means mobile communications. Do you have some important information to send to someone? Send it through the post to a post office box where the recipient has the key. Want to go more covert, send it by private courier who never loses possession of the package. Thats also a bit expensive.
    If you still want privacy using email then this system is as good as it gets. And this is not a paid comment. Its the truth. But please bare in mind that the most insecure communications are with your mobile phone. You don’t even get protection by switching it off, nor by removing the battery. It is also worth remembering that even using a public phone is not secure. Authorities already have your voice print in a database and the NSA and GCHQ computers can pick it up about as fast as a search made in Google on any comms voice network.

    • We cannot comment on other providers but we can inform you that ProtonMail is end-to-end encrypted email service. This means even we cannot decrypt and read your emails. As a result, your encrypted emails cannot be shared with third parties. Also, no personal information is required to create your secure email account. By default, we do not keep any IP logs which can be linked to your anonymous email account. Our code is open source. https://protonmail.com/security-details

  • I’m just learning but am impressed. Being 76 years old & a Brain Injury victim makes it difficult relearning this technology but fortunately I am able to relearn, just short term memory problem. My son told me about protonmail & I like it, just having problems figuring out how to set up several email accounts. I think Google works hard to cause problems because they obviously work underhanded. This is a learning process. Thank you.

  • Without using a data key for end to end encryption, and just using Proton mail as I would a regular email account, to send emails to potential employers, is Proton Mail more secure than regular email from hackers that want to hack into your servers, just so they can read my email? And if so, what are you doing to accomplish this?

    • You will not receive assistance from ProtonMail to identify that stalker in such a case. Indeed, this process would have to be performed either directly to Yahoo’s anti-abuse department or your local authorities. They very often require a personal component so it would appear dubious that ProtonMail would have any real value to offer in this context, as the address in question would not be a ProtonMail address.

  • Just curious Cort order from Geneva court could be filed and from out of your country? Or you must present in person at that moment?

    • You don’t have to necessarily be physically present in Switzerland to file a criminal complaint. However, the offense must have a territorial link with Switzerland for the authorities to declare themselves competent. Alternatively, a complaint can be filed by your local authorities and data requested through international mutual legal assistance.

    How do mutual legal assistance treaties play into this? I’m not talking privacy protection here in terms of data at rest/in-transit, I’m speaking to the legal requirement to exchange data which exists outside the scope of privacy, between Switzerland and the USA, for example.

    I’m also curious about the term ‘end-to-end’ encryption – is this strictly the connection, or is the content of a message also encrypted such that once it is delivered to a Gmail account – and now at rest on their servers – the message must then be decrypted?

    Thank you.

    • For requests for assistance must be approved by Swiss authorities, and we must receive a valid legal order before we will turn over any user data to anyone. As for end-to-end encryption, this only applies to messages between ProtonMail accounts or using our encrypt-to-outside feature. Messages from ProtonMail to Gmail, for example, are only TLS encrypted in transit and can be read by Google on their servers (but not by ProtonMail because of our zero-access encryption at rest).

  • Is it possible for ProtonMail to provide and synchronize emails for people who have more that 1 computer? If so, how is this done?

    In other words, what specifies and/or connects ProtonMail to any specific computer and/or computers?

    If I create an email, I want to be able to read and/or respond to this email on all of my computers.

    • With ProtonMail, your mailbox is synced no matter how you access your account. Just log in to your account on any browser on any device or one of our mobile apps.

  • Someone forged my email address and sent spam. If you receive a complaint, will my mailbox be stopped. The mailbox is encrypted. You can’t see the information inside. How to judge whether to send spam?

  • Can Protonmail be set to only exchange email with other Protonmail accounts, so that it will reject email from any other kind of account?

    • That is not a feature that we offer at the moment, but it is an interesting idea. Thanks!

  • Can I send an email from a Proton account to a regular Email address without the receiver being able to discover my details ? I primarily need an account to be a whistle blower for an incident at work.

  • If China uses protonmail and is investigated by the police after violating Chinese laws, will the email data be handed over to the Chinese government?

    • ProtonMail will not turn over email data to the Chinese government unless we are ordered to do so by the Swiss authorities. And even then, we may choose to fight the case in court considering China’s record. Also, the contents of ProtonMail emails are encrypted such that only the sender and recipient can access them. Therefore, it is highly unlikely the Chinese government could access a ProtonMail user’s email data via legal means. Please read our threat model for more information: https://protonmail.com/blog/protonmail-threat-model/

    • Hi Gordon. ProtonMail does not record the IP address of senders, so we have no idea of our users’ location.