Data Protection While Travelling
Which countries protect your data and which do not?
The New Data Protection Act and Your Travel Data
Why the travel destination is decisive for your data protection
Since 1 September 2023, the revised Data Protection Act (DSG) has been in force in Switzerland. Among other things, it governs the conditions under which personal data may be transferred abroad.
According to Art. 16 DSG, personal data may only be disclosed abroad if the Federal Council has determined that the legislation of the country concerned ensures adequate protection. These countries are listed in Annex 1 of the Data Protection Ordinance (DSV).
Popular Travel Destinations Without Adequate Data Protection
These holiday destinations are not on the list of countries
Many of the most popular holiday destinations of the Swiss do not have adequate data protection under Swiss law. Your personal data, from the hotel booking to the credit card to the travel app, is less well protected there.
| Country | Risk | Typical data processing |
|---|---|---|
| Turkey | No adequate protection | Hotels, all-inclusive resorts, local apps |
| Egypt | No adequate protection | Nile cruises, resorts, local providers |
| Thailand | No adequate protection | Hotels, domestic flights, booking platforms |
| Maldives | No adequate protection | Luxury resorts, transfers, activities |
| Morocco | No adequate protection | Riads, local tours, transport |
| Tunisia | No adequate protection | Hotels, excursions, local service providers |
| Dominican Republic | No adequate protection | All-inclusive resorts, excursions |
| Mexico | No adequate protection | Hotels, rental cars, local providers |
| Vietnam | No adequate protection | Hotels, domestic flights, tours |
Complete List of Countries (Annex 1 DSV)
All countries with adequate data protection according to the Federal Council
The following list contains all countries that, according to Annex 1 of the Data Protection Ordinance (DSV), have adequate data protection. Only in these countries may personal data be transferred without additional protective measures.
| Country | Remark |
|---|---|
| Albania | |
| Andorra | |
| Argentina | |
| Belgium * | EU/EEA member |
| Bulgaria * | EU/EEA member |
| Denmark * | EU/EEA member |
| Germany * | EU/EEA member |
| Estonia * | EU/EEA member |
| Faroe Islands | |
| Finland * | EU/EEA member |
| France * | EU/EEA member |
| Gibraltar | |
| Greece * | EU/EEA member |
| United Kingdom | |
| Guernsey | |
| Ireland * | EU/EEA member |
| Iceland * | EEA member |
| Isle of Man | |
| Israel | |
| Italy * | EU/EEA member |
| Japan | |
| Jersey | |
| Canada | Only companies subject to PIPEDA |
| Colombia | |
| Korea (South) | |
| Croatia * | EU/EEA member |
| Latvia * | EU/EEA member |
| Liechtenstein * | EEA member |
| Lithuania * | EU/EEA member |
| Luxembourg * | EU/EEA member |
| Malta * | EU/EEA member |
| Monaco | |
| New Zealand | |
| Netherlands * | EU/EEA member |
| Norway * | EEA member |
| Austria * | EU/EEA member |
| Peru | |
| Poland * | EU/EEA member |
| Portugal * | EU/EEA member |
| Romania * | EU/EEA member |
| Sweden * | EU/EEA member |
| Serbia | |
| Slovakia * | EU/EEA member |
| Slovenia * | EU/EEA member |
| Spain * | EU/EEA member |
| Czechia * | EU/EEA member |
| Hungary * | EU/EEA member |
| Uruguay | |
| USA | Only companies under the Swiss-U.S. Data Privacy Framework |
| Cyprus * | EU/EEA member |
How to Protect Your Data While Travelling
Practical tips for Swiss travellers
Encrypt your connection, especially in hotels and at airports.
No e-banking or email over open networks without a VPN.
Disable unnecessary access, do not install unknown local apps.
Enable screen lock, encryption and remote wipe.
Leave sensitive documents at home or use a separate travel device.
Password manager and two-factor authentication for all important accounts.
Do you have questions about data protection while travelling?
Contact us, we are happy to help you.