Datenfluss·Standard

Industry report · aggregated

Where Swiss websites send data

Analysis of 120 websites with a Swiss connection, measured on 2026-08-15. This report deliberately names no individual organisation – it describes the landscape, not single houses. It rebuilds itself whenever new measurements arrive.

80 %
embed a provider based in a third country
84 %
of all services are US-based
60 %
use a tag manager
18 %
show no recognised third-party service

The core finding

76 of 95 measurable websites embed a provider based in a third country – and nobody checks

76 of 95 measurable websites (80 %) embed at least one service whose provider is based in a country whose level of data protection the Swiss Federal Council does not generally recognise as adequate – overwhelmingly the United States, where recognition applies only to DPF-certified companies. When such an embed loads, the provider typically receives at least the visitor's IP address and browser details. Whether that amounts to a disclosure requiring a safeguard under Art. 16 et seq. of the Swiss FADP depends on the actual processing location and on certifications such as the Swiss–U.S. Data Privacy Framework – the provider's seat alone does not tell.

That unknown is precisely the point: processing location, safeguards, certifications – none of it can be measured from the outside. Today every customer, business partner and supervisory authority has to ask one by one. A machine-readable declaration turns that into a one-second lookup.

Of the 120 websites examined, 1 so far publishes such a declaration.

What we cannot see

60 % use a tag manager – all figures are lower bounds

Essential for interpretation

A tag manager loads further services only once JavaScript runs. This measurement does not execute JavaScript. On 57 of the 95 measurable websites, more third-party services must therefore be expected than shown here – how many more, this method cannot say.

The same applies in reverse to the 18 % with no recognised service: that is not an acquittal, it is a statement about what is statically visible. Anyone quoting these figures should quote this caveat with them.

Sector comparison

Who embeds how much

Only groups of five or more measurable websites. Groups under ten should be read as an indication, not as robust sector statistics – with six websites, a single outlier decides the result.

SectorWebsitesØ servicesabroadnone
Treuhand, Beratung, Recht SMALL GROUP62.7100 %0 %
Bildung SMALL GROUP52.4100 %0 %
Verbände und Kammern102.390 %10 %
Finanz und Versicherung132.277 %23 %
Mobilität, Reisen und Gastgewerbe SMALL GROUP61.7100 %0 %
Gemeinnützige SMALL GROUP61.5100 %0 %
Handel und Konsum131.577 %23 %
Digitalwirtschaft und Datenschutz SMALL GROUP61.367 %33 %
Medien SMALL GROUP91.267 %11 %
Öffentliche Hand130.977 %23 %
Alltag und Dienste SMALL GROUP70.757 %43 %

The most remarkable finding sits at the top: fiduciary, consulting and legal services – the very sector that advises Swiss SMEs on data protection – embeds the most third-party services on average. The group is small, so read the finding with care. But it matches an experience many practitioners share: one's own website is rarely where one's own advice would be.

At the other end sits the public sector with an average of 0.9 services per website – an indication that few third-party services are possible when they are made a requirement.

Most common services

What gets embedded

ServiceWebsitesShare of measurable
Google Tag Manager5760 %
Google Analytics2728 %
Matomo (selbst gehostet)99 %
Usercentrics99 %
Google Fonts66 %
Google reCAPTCHA55 %
Cloudflare Analytics55 %
Cookiebot55 %

Side finding

The convention already works

53 of the 95 measurable websites (56 %) publish a security.txt – a file at a well-known location telling security researchers whom to contact. It is RFC 9116 today and was mandated by no one.

This shows that Swiss organisations already place structured files under /.well-known/ voluntarily when the benefit is plain. Privacy transparency does not require inventing new behaviour.

Method

How this was measured – and what that cannot do

Approach: a single fetch of each home page, without executing JavaScript. Recognised are statically embedded resources of known providers. The scanner honours robots.txt and identifies itself as DatenflussScanner/0.1. Source code and analysis are open.

Sample: 120 websites, selected for reach and sector mix – not a random sample. 25 websites blocked the scanner and are excluded from all percentages; 95 were analysed.

Limits: home pages only, no JavaScript, no statement on lawfulness. A provider's seat does not say where data is actually processed – US providers also serve from Switzerland and the EU, and vice versa. Whether an embedding is admissible depends on processing location, safeguards and consents that are invisible from the outside. This report measures; it does not judge.

Raw data: aggregated analysis as JSON · individual profiles in the register

Free to reuse under CC BY 4.0 with attribution "Datenfluss-Standard, measurement of 2026-08-15". Questions and corrections: kontakt@datenfluss-standard.ch

← Back to the home page