cybersecurity
Switzerland struggles to balance cybercrime investigations with its privacy economy
Switzerland is weighing how to combat cybercrime and hostile-state activity without undermining the privacy-focused internet businesses that have made the country a global technology hub.

Switzerland Faces a Cybersecurity Reckoning
Around 65,000 cybercrime cases were reported in Switzerland in 2025, almost three times the level recorded five years earlier, according to figures from the National Cyber Security Centre cited by Swissinfo. The rise is pushing Bern to reconsider how digital services should cooperate with investigators.
The debate reaches far beyond police access to online accounts. Switzerland has built a strong position in privacy technology, drawing companies that sell encrypted email, cloud storage, artificial intelligence tools and other services designed to shield information from attackers and authorities. Geneva-based Proton places Swiss privacy law at the centre of its brand.
That commercial model now faces pressure from the same threat environment that makes secure communications attractive. Criminal groups, hostile states and terrorists can use encrypted systems to conceal their activity, while businesses and ordinary users rely on encryption to protect trade secrets, personal data and sensitive correspondence.
The government’s proposed response has focused on the Ordinance on the Surveillance of Postal and Telecommunications Traffic. Changes proposed in 2025 would clarify the obligations of internet service providers in criminal investigations. Larger platforms could face data-retention and cooperation requirements closer to those imposed on traditional telecom operators.
The choices made in Bern will affect both public security and the conditions that helped Switzerland become a technology hub.
Privacy Firms Push Back on Bern
Proton says it has halted plans to invest in more infrastructure in Switzerland, citing concerns about the direction of the proposed rules. The company argues that new retention and cooperation duties could weaken the trust on which privacy services depend.
Proton is no longer a niche Swiss startup. The Geneva-based firm has become Europe’s largest privacy technology company and has more than 100 million users worldwide, according to figures cited by Swissinfo. Its products include encrypted email, cloud storage and artificial intelligence services.
Chief operating officer Raphael Auphan said the dispute concerns Switzerland’s reputation as much as any individual compliance obligation. He warned that the country could lose companies that have grown under Swiss privacy protections and exported those standards to customers around the world.
The business case carries clear weight. Privacy companies choose jurisdictions partly for legal predictability and the credibility of their safeguards. If providers believe Switzerland will require broader data collection or faster access for investigators, they may redirect new servers, staff and investment elsewhere.
Companies also have a commercial interest in resisting rules that could increase costs or make their products less attractive. That does not settle the policy debate, but it explains why Proton and similar firms are pressing the government to narrow or reconsider the proposed obligations.
Bern Rewrites the Digital Rulebook
The proposed rules would place digital platforms closer to the legal framework used for traditional telecommunications operators. The aim is to give investigators clearer routes to information during criminal cases, while requiring some providers to retain or disclose more data.
That approach reflects a changing threat landscape. Swiss authorities are dealing with a rapid increase in reported cybercrime, alongside concerns that hostile states and terrorist networks can exploit online services. Investigators need usable evidence, and prosecutors need providers to respond within a predictable legal process.
Encryption complicates that process because strong privacy tools are designed to prevent unauthorised access. In many cases, the provider may not hold the content in a readable form. Data-retention requirements can also collide with a service’s technical design, particularly when a company has built its product around collecting as little information as possible.
The source material does not identify a final legislative text or a settled timetable for implementation. It does show that Switzerland is examining whether existing rules fit services that operate across borders and combine communications, storage and artificial intelligence.
The dispute therefore involves more than police procedure. It concerns how Swiss law defines an internet provider, what information companies should retain, and how far authorities can reach into systems used by customers outside Switzerland.
Switzerland Sets Its Digital Course
Switzerland’s decision will set conditions for a technology sector built on legal trust. The country’s constitutional tradition of protecting privacy has become a commercial asset, allowing firms to market Swiss jurisdiction to customers seeking protection from criminals, corporations and government surveillance.
The pressure is shared by liberal democracies across the European Union, the United States and the United Kingdom. Each is adapting rules to cybercrime and hostile-state activity while trying to preserve legitimate encryption. Switzerland’s distinctive challenge comes from the scale of its privacy economy and the strength of the national brand attached to it.
For Swiss residents, the outcome could affect the services they use for email, storage, payments and business communications. For companies, it could influence where they establish infrastructure and how much information they collect. For investigators, the value of any reform will depend on whether it produces evidence that providers can technically access and lawfully disclose.
The government must therefore resolve practical questions alongside political ones. Which providers should face enhanced duties? What data should be retained? How should cross-border investigations work? What safeguards should prevent routine access from expanding beyond serious cases?
Switzerland has yet to settle that balance. Its next regulatory steps will show whether the country can strengthen cybercrime investigations while keeping privacy protection credible to users and investors.