
Digital financial products and new payment models are constantly evolving. This gives rise to business models that do not always fit neatly into existing regulatory categories. In our FinTech & Payments practice area, we focus on the legal framework governing digital financial services, payment processes, platforms, and technology-based financial products.
New Models Confront Existing Regulations
Swiss financial market law is largely technology-neutral. New technologies therefore do not automatically create new regulatory categories. Innovative business models must also be reviewed to determine whether existing regulations—such as those under banking law, financial institutions law, anti-money laundering law, or financial services law—are applicable.
Cash flows are often crucial
In payment models, the actual structure of the cash flows is key. Of particular importance is who receives the funds, how long they are held, for whom they are intended, and what contractual relationships exist between the parties involved. Even minor differences in the payment process can lead to a different regulatory assessment.
Several areas of law are intertwined
FinTech projects rarely involve only financial market law. Data protection, contract law, IT law, corporate law, outsourcing, and cybersecurity can also be relevant. For this reason, the legal structure of a product often needs to be considered as a whole.
Regulation continues to evolve
Digital financial markets are changing rapidly. New business models, technologies, and European regulations are also shaping expectations for Swiss companies. It is therefore important for providers to keep a close eye on their legal status not only at the time of market launch, but also as their business model continues to evolve.
One of the first questions that regularly arises in FinTech projects is whether the business model is subject to any licensing, registration, or connection requirements. Of particular relevance may be regulations governing banks, financial institutions, financial services, and money laundering, as well as requirements pertaining to payment and settlement models.
It is not just the product's name that matters. What is crucial is how the business model actually works—in particular, the company's role, the flow of payments and services, and the involvement of external partners.
Payment models can take many different forms—ranging from traditional acquiring to digital wallets and payment platforms, all the way to payment features embedded within other products. From a legal perspective, questions arise, for example, regarding the roles of the parties involved, the processing of payment flows, contractual responsibilities, anti-money laundering obligations, and the involvement of banks, acquirers, or technical service providers.
Many FinTech and payment models must be reviewed to determine whether they constitute the activity of a financial intermediary. In this context, specific control over assets, the role in the payment process, and the contractual structure are particularly relevant. Depending on the model, obligations regarding registration, identification, monitoring, and organization may arise.
Any entity that provides financial services or manages assets may be subject to the FIDLEG or FINIG. In particular, it is important to determine whether a financial service is being provided, what type of client segmentation is required, what information and documentation obligations apply, and whether an institutional license may be required.
FinTech companies often process large volumes of customer, transaction, and usage data. In addition to the Swiss Data Protection Act, the GDPR may also apply, depending on the nature of the business. Key issues include transparency, purpose limitation, profiling, international data transfers, data processing on behalf of others, and the use of external cloud or technology providers.
FinTech business models often rely on external infrastructure and software providers. Cloud hosting, identity management solutions, payment processing, SaaS products, and data analysis are frequently outsourced. For regulated companies, in addition to data protection and contract law, additional requirements regarding governance, monitoring, audit rights, sub-outsourcing, business continuity, and exit strategies must be taken into account.
A legal assessment begins with how the product actually functions. This includes, in particular, customer relationships, cash flows, the technology used, and the roles of external partners.
On this basis, it is possible to assess which financial market regulations are relevant and whether licenses, registrations, or organizational adjustments may be required.
The regulatory framework must then be reflected in contracts, terms and conditions, data protection documentation, and internal processes.
Regulatory work does not end with market entry. New products, partners, or technical processes may require a new legal assessment.
Financial services are increasingly being integrated into products that did not originally have a financial focus. This is leading to a new division of roles among platform operators, financial institutions, and technology providers.
Digital platforms often connect multiple providers and customers. From a legal perspective, it is particularly important to clarify who provides which services and what responsibilities exist toward users.
Dependence on cloud and technology providers continues to grow. At the same time, regulatory expectations regarding control, resilience, and the ability to exit are increasing.
AI is increasingly being used for risk assessments, customer interaction, compliance, and operational processes. This raises additional questions regarding governance, data protection, and accountability.
Digital financial products can only be evaluated from a legal perspective if their technical and operational functioning is also understood.
We look not only at individual regulations, but also at the specific role the company plays within the overall business model.
A key focus is on regulatory classification under Swiss financial market law and on addressing issues relevant to FINMA.
FinTech involves financial market law, data protection, IT law, contract law, and governance. These areas are considered together.
Legal requirements must be able to be incorporated into products, processes, and contracts. That is why we take operational implementation into account from the very beginning.
FinTech models are evolving. Legal structures should therefore be designed in such a way that they can evolve alongside the business model.