"Swiss privacy" is doing a lot of heavy lifting
It's printed on every secure-email landing page and sits at the top of every VPN comparison table. But jurisdiction is law, not a flag — and in 2026 Swiss law is moving in a direction that should make anyone choosing a provider on the strength of the Swiss reputation stop and read the actual draft text. Germany, meanwhile, is the country most people file under "EU, fine, whatever." It happens to have constitutional protection for correspondence that has repeatedly survived contact with the courts. Here is the honest head-to-head: what each jurisdiction requires of a provider, where Switzerland still wins, and why Switzerland's own privacy flagship is shipping servers to Germany.
Germany: a constitution that treats correspondence as inviolable
The backbone is Article 10 of the Basic Law, the Grundgesetz. The privacy of correspondence, posts, and telecommunications is inviolable; restrictions may be ordered only by a law. That is not a policy a government revises by decree. It is a constitutional right the Federal Constitutional Court (BVerfG) enforces against the state, intelligence services included.
The track record is the whole argument. On 19 May 2020 the BVerfG ruled that the Federal Intelligence Service's bulk surveillance of foreign telecommunications violated Article 10 — and held that the constitution binds the BND even when it surveils non-Germans abroad. On retention, German and EU courts have struck down blanket data retention again and again: the BVerfG invalidated Germany's first retention law in 2010, the Court of Justice of the EU killed the underlying directive in 2014, and indiscriminate retention of everyone's traffic data has been ruled incompatible with EU fundamental rights ever since. The current German proposal, still suspended, would retain IP addresses only for three months — the floor the courts have signalled they might tolerate, not a dragnet. The German system fights blanket retention. It does not mandate it.
Switzerland: the VÜPF revision changes the calculus
This is the part the comparison tables haven't caught up to. Switzerland is revising the VÜPF, the Ordinance on the Surveillance of Postal and Telecommunications Traffic. The public consultation closed in May 2025, and the draft does two things that matter to anyone storing data with a Swiss provider.
- Mandatory retention at a low threshold. Email and VPN providers with as few as 5,000 users would have to log IP addresses and keep them for six months. That is the indiscriminate-retention model EU courts keep outlawing, arriving in the country famous for the opposite.
- A decryption obligation.
Article 50aof the draft would require providers to remove "the encryption provided by them or on their behalf." It does not reach true end-to-end messages between users — but for any provider that holds the keys, it is a lawful-access mandate.
And it is an ordinance, not a statute. The Federal Council and the Federal Department of Justice and Police are pushing it as an executive update, which sidesteps the full parliamentary process that Article 10-grade protection assumes in Germany. ISOC Switzerland and Swiss civil society have pushed back hard, and the proposal may yet be narrowed or shelved. But the asymmetry is real. In Germany the courts spent fifteen years dismantling blanket retention. In Switzerland the executive is trying to introduce it by decree.
The tell: Proton is moving to Germany
The cleanest evidence isn't a legal opinion. It's a capital decision. Proton — the Geneva company whose entire brand is Swiss privacy — began copying its infrastructure out of Switzerland in 2025, explicitly citing the VÜPF reform. CEO Andy Yen confirmed the company chose Germany to host servers for its new Lumo product and is building facilities in Norway at a reported CHF 100 million. Yen's line: Proton can now shut down its Swiss systems on short notice if the revision passes. A company that could pick any jurisdiction, choosing Germany over its own home, tells you more than any landing page. If you're weighing the two of us directly, our honest Beebeeb-vs-Proton-Drive comparison lays out where we match and where we differ — Proton's encryption and open-source clients are genuinely strong, and we won't pretend otherwise. On those, we match them rather than beat them.
Where Switzerland still has the edge
Fair is fair. Switzerland sits outside the EU and outside the reach of the US CLOUD Act, which can compel a US-headquartered provider to hand over data wherever it's physically stored. Swiss data-protection law is genuinely strong, and a Swiss company with no US parent isn't reachable by a US warrant the way a hyperscaler's "EU region" is. Tresorit — Zurich-based, end-to-end encrypted, and majority-owned by Swiss Post since 2021 — has built a serious business-grade product on exactly that footing, with real data-residency options for enterprise buyers. If your threat model is specifically US legal reach, Switzerland's non-EU status is a feature, and the VÜPF draft hasn't passed yet. Discounting that would be dishonest.
The catch: "not subject to the CLOUD Act" only protects you if the provider can't read your data in the first place. Jurisdiction is the second line of defence. The first is whether the provider holds your keys at all.
The deeper point: jurisdiction is a fallback, not a guarantee
Every jurisdiction argument hides the same assumption — that the provider can comply with a legal demand because it can read your files. The Article 50a decryption clause only bites on providers holding the keys. A retention mandate only exposes what the provider can already see. That is why we don't lead with a flag.
Beebeeb is end-to-end encrypted and zero-knowledge on every tier, including the free one. Your passphrase derives your keys on your device with Argon2id (256 MB, 4 iterations); files are sealed with AES-256-GCM and shared via X25519; login runs over OPAQUE, so the server never sees your password; your recovery is a BIP39 phrase only you hold; keys are zeroized after use. We can't read your files, so a retention or decryption order against us hands the authorities ciphertext and nothing else. Our infrastructure runs on dedicated servers in Falkenstein, Germany — under Article 10, outside the CLOUD Act, and inside the jurisdiction Proton just chose for itself. The full mechanism is on our security page, including the honest parts: our independent audit is planned, not yet done, and we'll publish the findings either way.
Germany gives you a constitution that treats correspondence as inviolable and courts that keep striking down blanket retention. Switzerland gives you distance from US law and a 2026 ordinance pulling hard in the other direction. Choose the jurisdiction with care — then choose a provider that doesn't need you to trust the jurisdiction at all.