Industry report · aggregated
Where Swiss websites send data
Analysis of 120 websites with a Swiss connection, measured on 2026-08-15. This report deliberately names no individual organisation – it describes the landscape, not single houses. It rebuilds itself whenever new measurements arrive.
The core finding
76 of 95 measurable websites embed a provider based in a third country – and nobody checks
76 of 95 measurable websites (80 %) embed at least one service whose provider is based in a country whose level of data protection the Swiss Federal Council does not generally recognise as adequate – overwhelmingly the United States, where recognition applies only to DPF-certified companies. When such an embed loads, the provider typically receives at least the visitor's IP address and browser details. Whether that amounts to a disclosure requiring a safeguard under Art. 16 et seq. of the Swiss FADP depends on the actual processing location and on certifications such as the Swiss–U.S. Data Privacy Framework – the provider's seat alone does not tell.
That unknown is precisely the point: processing location, safeguards, certifications – none of it can be measured from the outside. Today every customer, business partner and supervisory authority has to ask one by one. A machine-readable declaration turns that into a one-second lookup.
Of the 120 websites examined, 1 so far publishes such a declaration.
What we cannot see
60 % use a tag manager – all figures are lower bounds
Essential for interpretation
A tag manager loads further services only once JavaScript runs. This measurement does not execute JavaScript. On 57 of the 95 measurable websites, more third-party services must therefore be expected than shown here – how many more, this method cannot say.
The same applies in reverse to the 18 % with no recognised service: that is not an acquittal, it is a statement about what is statically visible. Anyone quoting these figures should quote this caveat with them.
Sector comparison
Who embeds how much
Only groups of five or more measurable websites. Groups under ten should be read as an indication, not as robust sector statistics – with six websites, a single outlier decides the result.
| Sector | Websites | Ø services | abroad | none |
|---|---|---|---|---|
| Treuhand, Beratung, Recht SMALL GROUP | 6 | 2.7 | 100 % | 0 % |
| Bildung SMALL GROUP | 5 | 2.4 | 100 % | 0 % |
| Verbände und Kammern | 10 | 2.3 | 90 % | 10 % |
| Finanz und Versicherung | 13 | 2.2 | 77 % | 23 % |
| Mobilität, Reisen und Gastgewerbe SMALL GROUP | 6 | 1.7 | 100 % | 0 % |
| Gemeinnützige SMALL GROUP | 6 | 1.5 | 100 % | 0 % |
| Handel und Konsum | 13 | 1.5 | 77 % | 23 % |
| Digitalwirtschaft und Datenschutz SMALL GROUP | 6 | 1.3 | 67 % | 33 % |
| Medien SMALL GROUP | 9 | 1.2 | 67 % | 11 % |
| Öffentliche Hand | 13 | 0.9 | 77 % | 23 % |
| Alltag und Dienste SMALL GROUP | 7 | 0.7 | 57 % | 43 % |
The most remarkable finding sits at the top: fiduciary, consulting and legal services – the very sector that advises Swiss SMEs on data protection – embeds the most third-party services on average. The group is small, so read the finding with care. But it matches an experience many practitioners share: one's own website is rarely where one's own advice would be.
At the other end sits the public sector with an average of 0.9 services per website – an indication that few third-party services are possible when they are made a requirement.
Most common services
What gets embedded
| Service | Websites | Share of measurable |
|---|---|---|
| Google Tag Manager | 57 | 60 % |
| Google Analytics | 27 | 28 % |
| Matomo (selbst gehostet) | 9 | 9 % |
| Usercentrics | 9 | 9 % |
| Google Fonts | 6 | 6 % |
| Google reCAPTCHA | 5 | 5 % |
| Cloudflare Analytics | 5 | 5 % |
| Cookiebot | 5 | 5 % |
Side finding
The convention already works
53 of the 95 measurable websites
(56 %) publish a security.txt – a file at a
well-known location telling security researchers whom to contact. It is RFC 9116 today
and was mandated by no one.
This shows that Swiss organisations already place structured files under
/.well-known/ voluntarily when the benefit is plain. Privacy transparency
does not require inventing new behaviour.
Method
How this was measured – and what that cannot do
Approach: a single fetch of each home page, without executing
JavaScript. Recognised are statically embedded resources of known providers. The scanner
honours robots.txt and identifies itself as DatenflussScanner/0.1. Source
code and analysis are open.
Sample: 120 websites, selected for reach and sector mix – not a random sample. 25 websites blocked the scanner and are excluded from all percentages; 95 were analysed.
Limits: home pages only, no JavaScript, no statement on lawfulness. A provider's seat does not say where data is actually processed – US providers also serve from Switzerland and the EU, and vice versa. Whether an embedding is admissible depends on processing location, safeguards and consents that are invisible from the outside. This report measures; it does not judge.
Raw data: aggregated analysis as JSON · individual profiles in the register
Free to reuse under CC BY 4.0 with attribution "Datenfluss-Standard, measurement of 2026-08-15". Questions and corrections: kontakt@datenfluss-standard.ch