Hosting and backups

Backups in Switzerland: what an SME should check before choosing a host

A continuity plan is only as good as its recovery copies: where they are, how independent they are, and proof that you can restore them. Here are the questions to ask, in order.

Why the location of backups matters

When an SME talks about sovereignty, it often means the website or the mailbox. For business continuity, the decisive question is elsewhere: where do the copies live that will let you restart after an outage, a human error or ransomware, and who can access them?

This page looks at the topic from the point of view of a company preparing its recovery. It complements the Sovereignty page, which explains how Contivaro itself handles data, and the approach described in the framework.

A concrete example of a Swiss host is shown further down, with facts declared by the provider and one clear reservation: web hosting is not a continuity plan.

The 3-2-1 rule

Three copies, two media, one off site: without leaving Switzerland

The 3-2-1 rule is a practice standard, not a legal requirement. It can be applied entirely within Switzerland, provided each copy is genuinely independent of the others.

01

Three copies of the data

The original plus two copies. A copy that lives in the same account, with the same credentials as the original, falls with it.

02

Two different media

For example on-site storage and online storage. Two media of the same technology and the same supplier count as a single point of failure.

03

One off-site copy, in Switzerland

Another data centre in the same country. Ask for the location to be written into the contract and not merely displayed on the sales page.

04

One copy out of an attacker's reach

Ransomware encrypts what it can reach. An immutable or disconnected copy stays readable when administrator credentials have been stolen.

Five questions to ask any supplier

They apply to a host, a backup provider or a managed service provider. A vague answer is already an answer.

  • Where is the data, and where are the copies?

    The main data centre, the data centre of the recovery copy, and the location where support is handled. All three can differ.

  • Has restoration been tested, and with what result?

    A backup that has never been restored is a hypothesis. Ask for the date of the last test, the measured duration and what was missing. See the [restore drills](kind:exercices).

  • How long does restoration take, and how far back can you go?

    These are your tolerable downtime and tolerable data loss, written in hours. The supplier cannot guess them for you.

  • Who are the subprocessors, and will you be told if they change?

    A supplier that entrusts part of the processing to a third party must make this known and obtain your prior agreement for any new subprocessor.

  • How do you leave the contract?

    Format of the data returned, timeline, cost, erasure confirmed in writing. An exit that has never been rehearsed is not an exit.

One supplier, one single point of failure

Grouping hosting, mail and backups with a single provider is convenient and often cheaper. It is also a continuity risk that should be named.

The same account for everything

If an administration login is compromised, the original and the backup can be reached together. Separate the credentials and enable strong authentication everywhere.

The same outage for everything

An incident at one supplier affects everything it hosts for you. Keep at least one usable copy outside its infrastructure.

The same billing for everything

A dispute or an account suspension stops everything at once. Plan for the case where the account is blocked on a Friday evening.

A rehearsed exit

Know how to restore at another supplier, even slowly. The most revealing test is to bring a service back up on an infrastructure that is not your usual one.

What the nDPA asks for, in plain words

Articles of the Federal Act of 25 September 2020 on Data Protection (SR 235.1), checked on Fedlex on 29 September 2026. The official titles are quoted from the French text. This is not legal advice.

ArticleOfficial titleWhat it changes for your backups
Art. 8Data security (Sécurité des données)The controller and the processor ensure, through appropriate organisational and technical measures, security that is adequate to the risk. A backup containing personal data is concerned.
Art. 9Processing by a processor (Sous-traitance)Entrusting processing to a third party requires a contract or a legal basis. The controller makes sure the processor can guarantee data security, and the processor may subcontract in turn only with the controller's prior authorisation.
Art. 16Principles on disclosure abroad (Principes)Personal data may be disclosed abroad only if the Federal Council has determined an adequate level of protection, or if appropriate safeguards exist.
Art. 17Exceptions (Dérogations)Exceptions to article 16 exist, for example express consent or performance of a contract. A copy that stays in Switzerland avoids the question.

Transparency about this link

Links marked "affiliate link" are affiliate links. We may receive a commission if you subscribe through this link, at no extra cost to you. The commission does not influence the content of this page: the reservations and limits appear regardless, and other Swiss hosts exist.

What a Swiss host does not remove

A Swiss provider remains subject to Swiss law: an authority can order it to hand over data, and a foreign authority can go through mutual legal assistance. Hosting in Switzerland does not remove the risk of outage, error or attack either. It reduces legal exposure and simplifies applying the nDPA, but it replaces neither encryption, nor an independent copy, nor a restore test.

Official sources

Text of the law: Federal Act on Data Protection on Fedlex, articles 8, 9, 16 and 17.

Supervisory authority: Federal Data Protection and Information Commissioner.

Cybersecurity: National Cyber Security Centre, for incident reporting and recommendations to companies.

FAQ

Frequently asked questions

Is Swiss hosting enough to comply with the nDPA?

No. The location simplifies the question of transfers abroad, but the law also requires adequate security (art. 8) and a contractual framework for processors (art. 9). Location does not replace these measures.

Can shared web hosting serve as a backup?

Not as the company's main backup. It protects a website, over a short period. Your workstations, servers and mail need their own copy strategy.

Do we have to change supplier to follow the 3-2-1 rule?

Not necessarily. The copies must be independent: another account, another site, ideally another technology, and a tested restore.

Do you receive a commission on the host shown?

A commission may be paid to us if you subscribe through the link marked "affiliate link", at no extra cost to you. It does not influence the content of the page.

Request an assessment

Start by knowing where you stand

Tell us which applications you cannot lose, how long you could hold out without them, and when a restore was last actually tested. We reply within two working days.

  • Swiss engineering
  • Reply within two working days

Email Contivaro

Tell us when a restore was last tested. If the answer is “never”, let’s start there.

Email Contivaro