Swiss law protects financial data through three layers. The Federal Act on Data Protection governs how a company may use it. Financial-intermediary confidentiality restricts who may see it. And Article 271 of the Swiss Criminal Code, the Swiss blocking statute, makes it a criminal offence to hand data directly to a foreign authority: foreign police forces and foreign court orders have no direct power on Swiss territory, and the only road in runs through Switzerland’s own mutual legal assistance process, where a Swiss authority decides. What Swiss privacy is not: anonymity. Swiss financial intermediaries verify their clients and operate under Swiss AML law, which is exactly why the protection is credible.
The Email That Prompted This Page
Not long ago, a national police cybercrime unit from outside Switzerland emailed us. Politely, professionally, through official channels, they asked whether TrustLinq would accept their country’s formal requests or court orders and hand over subscriber information and log data.
Our answer, on Swiss counsel’s advice, wasn’t a refusal to cooperate. It was a redirection: Swiss law prohibits us from acting on foreign requests directly, on pain of criminal liability, and routes every such request through Switzerland’s official mutual legal assistance channel, where it will be handled properly. Legitimate investigations get their road; it just runs through Bern, not through our inbox. That surprises people on both sides: authorities used to platforms that cooperate on request, and crypto users who assume every company folds the moment a badge appears. Both are working from assumptions Swiss law doesn’t share, so it’s worth laying out precisely how this works.
Layer One: Data Protection by Default
The revised Swiss Federal Act on Data Protection, in force since September 2023, governs the ordinary life of your data: collected for defined purposes, protected proportionately, never sold, never shared commercially. This layer resembles what Europeans know from the GDPR, and it’s the baseline, not the story.
Layer Two: Article 271, the Blocking Statute
The story is Article 271 of the Swiss Criminal Code, in force since 1935. It prohibits carrying out, on Swiss territory and without Swiss authorization, acts that belong to public authority, on behalf of a foreign state. Producing evidence for a foreign investigation is such an act. That means a Swiss financial intermediary that hands subscriber data, transaction records or logs directly to a foreign police force, or complies directly with a foreign court order, commits a criminal offence in Switzerland, prosecuted by the Office of the Attorney General.
This is not a theoretical rule. The Swiss Federal Supreme Court confirmed a conviction in 2021 in a case where a Swiss company’s chairman personally delivered client files to the US Department of Justice, under a negotiated non-prosecution agreement, after the DOJ had declined to use official channels. Cooperation with the world’s most powerful enforcement agency, in his own company’s interest, was still a crime, because the decision to move Swiss-held data abroad belongs to Swiss authorities and no one else. The court’s standard: information that could only lawfully be obtained through a Swiss authority’s order may not be handed to a foreign state directly, ever.
For a TrustLinq client, the practical meaning is simple. A foreign authority that wants anything from us doesn’t get to ask us. It has to ask Switzerland.
Layer Three: The Only Road In
Switzerland is not a data black hole, and pretending otherwise would be dishonest. Foreign authorities have a legitimate route: international mutual legal assistance, administered through the Swiss Federal Office of Justice. A foreign request is examined by Swiss authorities under Swiss standards before anything moves: the alleged conduct must be criminal under Swiss law too, fishing expeditions are refused, and information that is granted may only be used for the proceedings it was granted for.
The difference between this and “cooperating on request” is the difference between a process and a phone call. Under mutual legal assistance, a Swiss authority weighs the request, applies Swiss law, and issues any production order itself. The gatekeeper is the Swiss state, with its own courts reviewing the decision, not a compliance officer under pressure at 5pm on a Friday.
Switzerland vs the EU vs the UK: Who Can Order Your Data
The Swiss position is easiest to see next to its neighbours, and 2026 made the contrast sharper than it has ever been.
In the EU, the e-Evidence Regulation became applicable on 18 August 2026. Judicial authorities in one member state can now issue European Production Orders directly to service providers in another, bypassing mutual legal assistance entirely: ten days to comply, eight hours in emergencies, and penalties up to 2% of worldwide turnover for providers that don’t. A French prosecutor ordering a German provider no longer asks Germany; they ask the provider.
The UK moved the same direction earlier and further: under the UK-US Data Access Agreement, in force since 2022, US authorities can serve data demands directly on UK providers, and vice versa, without either government’s courts reviewing the individual request.
Switzerland is the counter-model. The same direct foreign order that EU and UK providers must obey is one a Swiss provider commits a crime by obeying. There’s no judgment in that observation about which system fights crime better; they’re different constitutional answers to the same question. But for the person whose data it is, the difference is structural: in one model, the gatekeeper is a provider on a deadline; in the other, the gatekeeper is the Swiss state.
| Switzerland | European Union | United Kingdom | |
|---|---|---|---|
| Data protection baseline | FADP (revised 2023) | GDPR | UK GDPR / DPA 2018 |
| Domestic authority access | Swiss authority orders; Swiss-law duties | National judicial orders | Court orders; Investigatory Powers Act |
| Direct order from another country’s authority | Criminal offence for the company to comply (Art. 271 SCC) | The payment company must comply, from any EU member state (e-Evidence, since Aug 2026) | The payment company must comply with US authorities (UK-US Data Access Agreement) |
| Blocking statute | Yes, with criminal sanctions | No general one | None |
| Route for other foreign states | Mutual legal assistance via the Federal Office of Justice, under Swiss standards | MLA or European Investigation Order | MLA, or direct agreements where in force |
| Who decides on a foreign request | A Swiss authority decides, never TrustLinq directly | The payment company itself, on a 10-day / 8-hour deadline | The payment company itself, under the agreement |
One reading of that table matters most: in the EU and UK models, the entity deciding whether your data moves is a payment company like ours, under deadline pressure. In the Swiss model, it’s a state authority applying published standards, with courts above it, and never TrustLinq itself. Neither system is lawless; only one puts a government’s own judgment between your data and a foreign request, every time.
Privacy, Properly Understood
Swiss privacy is often confused with anonymity, and it’s better than that. TrustLinq is a Swiss-regulated financial intermediary, supervised by SO-FIT, a FINMA-recognised self-regulatory organisation, which means clients verify once and payments are screened under Swiss law, the routine housekeeping of regulated finance, and the very reason a TrustLinq transfer lands at the recipient’s bank without a single question asked. The ordinary duties that come with Swiss status, domestic reporting where Swiss law requires it, and Switzerland’s own treaty-based tax cooperation covered in our DAC8, CARF and Swiss privacy analysis, are the same ones every bank in Zurich has carried for decades. Nothing about them involves foreign authorities, and nothing about them touches the ordinary client’s experience: verify once, then every payment is bank details and send.
That’s also why the protection holds. Privacy that lives inside a functioning legal order is privacy with a state and its courts behind it, credible to banks, durable across decades, and of no use to anyone with something to hide, which is exactly what keeps it strong for everyone else. Your funds stay in your wallet because the architecture is non-custodial; your data stays under Swiss law because Article 271 permits nothing less.
Why This Matters More for Crypto Than for Anything Else
Crypto users have watched a decade of the opposite model. Exchanges and platforms in most jurisdictions respond to domestic and foreign data demands as a matter of routine, and their terms of service say so. The industry’s answer was to flee regulation entirely, which produced platforms with no duty to anyone, until they collapsed or were seized, taking the data and the funds with them.
The Swiss model is the third option nobody built for crypto until now: a regulated intermediary whose duties run to Swiss law alone. Combined with non-custodial architecture, funds in your own wallet until the moment a payment executes, it means the two things a client actually worries about, their money and their data, are each protected by structure rather than by promise. The money is protected because we never hold it. The data is protected because handing it to a foreign state is a crime where we live. The full framework sits in our guide to Swiss crypto regulations, and the model it protects in crypto-funded fiat settlement.
What This Means for You, in Practice
Legal architecture is abstract until it touches a payment, so here’s where it lands.
Your on-chain life stays yours. When you pay rent or a supplier through TrustLinq, the recipient’s bank sees a clean transfer from a Swiss-regulated intermediary with an ordinary reference. Your wallet address, your holdings and your transaction history are not attached to the payment and are nobody’s business at the receiving end.
No bank builds a crypto profile on you. The classic route, cash out to your own account, then pay, hands your bank a running log of your crypto activity, which is exactly what triggers the reviews and freezes covered in why banks freeze crypto transfers. With direct settlement your personal bank account isn’t in the loop at all, because you don’t need one.
No honeypot. Custodial platforms concentrate two tempting things in one place: everyone’s funds and everyone’s data. TrustLinq’s non-custodial architecture means your funds sit in your own wallet until the moment a payment executes, and your data sits under the strictest jurisdiction available. Privacy here isn’t a toggle in the settings; it’s how the thing is built.
Frequently Asked Questions
Can foreign governments access my TrustLinq data?
Not directly, that’s a criminal offence under Article 271 of the Swiss Criminal Code. A foreign authority’s route is Switzerland’s mutual legal assistance process, where the Swiss Federal Office of Justice examines the request under Swiss standards, refuses fishing expeditions, and issues any production order itself. Requests arriving through that channel are handled promptly and completely; foreign authorities simply never obtain data from us directly, because Swiss authorities decide what leaves Switzerland.
What is Article 271 of the Swiss Criminal Code?
Switzerland’s blocking statute, in force since 1935. It makes it a criminal offence to perform acts reserved to public authority, including producing evidence or disclosing data for foreign proceedings, on Swiss territory for a foreign state without Swiss authorization. The Federal Supreme Court has confirmed convictions under it, including for disclosure made voluntarily to foreign enforcement agencies.
Does Swiss privacy mean my payments are anonymous?
No, and no legitimate route offers that. Every TrustLinq client is verified once, and every payment is screened under Swiss AML law before fiat is released. That verification is precisely what makes the transfers land cleanly at recipient banks, and what makes the privacy protections credible rather than cosmetic.
Who can actually see my payment data?
Your data lives in Switzerland under Swiss data protection law, handled by TrustLinq on a need-to-know basis, never sold, never shared commercially, never handed to third parties. It stays strictly between you and us, within the Swiss legal framework every Swiss financial institution operates in, and foreign authorities have no direct route to it: their only road runs through Switzerland’s own mutual legal assistance process, where a Swiss authority decides.
How does Swiss privacy compare to the GDPR?
The GDPR and the Swiss FADP are close cousins on how companies handle data day to day. The divergence is what happens when a foreign authority asks: since August 2026, the EU’s e-Evidence Regulation obliges providers to answer production orders from any member state’s judiciary directly, while Swiss law criminalizes exactly that kind of direct compliance and routes every foreign request through Swiss authorities. Same data-protection baseline, opposite answer on foreign reach.
Does the EU e-Evidence Regulation or the US CLOUD Act reach a Swiss company like TrustLinq?
Those regimes bind providers within their jurisdictions: the e-Evidence rules address providers offering covered communication, storage and platform services in the EU, and the CLOUD Act reaches providers subject to US jurisdiction. TrustLinq is a Swiss financial intermediary with data held in Switzerland under Swiss law, where Article 271 makes direct compliance with foreign orders a criminal offence. Any foreign authority’s road to Swiss-held data runs through Switzerland’s mutual legal assistance process, where a Swiss authority decides.
Do crypto platforms share my data with governments?
Most platforms operate in jurisdictions where responding to domestic and foreign data demands is routine, and their terms of service say so; since August 2026, EU-based providers must even answer production orders from any member state directly. The Swiss model is structurally different: a Swiss intermediary answers to Swiss law alone, and handing data directly to a foreign authority is a criminal offence here, not a policy choice.
What is the most private way to pay with crypto legally?
A verified, non-custodial, Swiss-regulated settlement service, and each of those words carries weight. Verified, because unverified routes end in frozen transfers. Non-custodial, because funds that never leave your wallet can’t be pooled, profiled or seized from a platform. Swiss, because your data ends up under the one framework where foreign reach is criminally blocked. Legal privacy comes from jurisdiction and architecture, not from hiding.
Is Swiss banking secrecy still real?
The casual version died with automatic tax-information exchange, and anyone selling you 1970s-style numbered-account secrecy is selling nostalgia. What remains is stronger where it matters: data protection law, financial-intermediary confidentiality, and a blocking statute with criminal teeth that keeps foreign authorities on the official road. Process replaced secrecy, and process is enforceable.
What is mutual legal assistance?
The treaty-based channel through which one country’s authorities request evidence from another. In Switzerland it runs through the Federal Office of Justice, applies Swiss legal standards including dual criminality, and ends, where granted, in a Swiss production order. It exists so that legitimate investigations proceed and unilateral foreign reach doesn’t.
Privacy by Law, Not by Promise
Your funds stay in your wallet until the moment you pay. Your data stays under Swiss law, where handing it to a foreign state is a crime.
Register at TrustLinq and pay any bank account in 190+ countries from your own wallet: verified, compliant, and with your data governed by Swiss law from end to end.