Switzerland-based vs. EU-based Merchant of Record: what the jurisdictional difference means for SaaS tax and data compliance
Where your MoR is based determines your tax regime and which privacy laws apply to your sales.

A Merchant of Record is the legal seller on every transaction. That one fact drags a lot behind it: VAT calculation, chargeback liability, fraud exposure, and the actual relationship with tax authorities. A payment button doesn't carry any of that weight. Where the MoR is based, Switzerland or somewhere inside the EU, decides which tax regime governs your sales, which privacy law applies to your customer data, and who gets to fine you when something goes sideways. That's the whole deal, not a footnote buried in a contract.
Quick contrast before we go further. A standard payment processor just moves money, and nothing more than that. You're still the merchant of record on paper, so you still hold the tax exposure and the legal risk yourself. An MoR is supposed to take that off your plate. The market for this has ballooned, sitting at $13.2 billion in 2025 and headed toward $35.4 billion by 2032 according to Research and Markets, growing almost 15% a year. Founders are buying into this category fast right now, often without realizing "MoR" isn't one product with two logos slapped on it. Where the company is domiciled changes what it actually does for you day to day.
How EU VAT works for digital services and what it requires of an EU-domiciled MoR
The EU rule for B2C digital services sounds simple and runs painful: VAT gets charged based on where the customer sits, not where you sit. Twenty-seven countries, twenty-seven rates, each one wanting its own attention and its own paperwork. B2B sales dodge most of this mess through the reverse charge mechanism, where the buyer handles VAT at home, so your filing load drops off a cliff by comparison.
Here's the detail that trips people up constantly: you can't just trust an IP address to know where a customer lives. EU rules want two data points that agree with each other, billing address plus IP, or phone country code plus bank details, something along those lines. One signal alone isn't proof anymore, no matter how confident it looks on a dashboard.
There's also a €10,000 threshold worth knowing. Stay under it as an EU-registered business and you can just apply your home country's VAT rate and move on with your life. Cross it, though, and the customer-location rules kick in for real, with no exceptions.
This is where an EU-domiciled MoR earns its paycheck: the Union OSS scheme. One consolidated return covers all 27 member states, filed from inside the bloc's own infrastructure, with a direct line to each country's tax office. An EU-based MoR sits inside this system automatically, without extra registration hoops or side quests to manage.
Missing the filing deadline costs real money, not a slap on the wrist. Germany alone can charge late-filing penalties up to 10% of the VAT owed, capped at €25,000, plus interest stacking on top. Regulators aren't easing off here, either. The European Commission put the 2023 EU VAT compliance gap at €128 billion, 9.5% of total VAT liability going uncollected. That's the number they're actively chasing down.
Swiss VAT (MWST) operates on entirely separate logic, with traps specific to SaaS
Switzerland runs its own show entirely. MWST has its own rates, its own registration rules, and zero seat at the EU's OSS table. The standard rate for SaaS and digital services sits at 8.1%, noticeably lower than most EU rates. Lower doesn't mean easier, though, since it just means the trap is cheaper to fall into.
Registration kicks in once your global turnover crosses CHF 100,000, as long as even CHF 1 of that came from a Swiss customer. For a digital service seller, in practice that means the moment you cross the global threshold and land one Swiss sale, you're in scope.
Now the part that actually bites people: the "force of attraction" principle. Say you sell only to verified Swiss businesses. You can stay outside MWST registration completely, sitting comfortably on the sidelines. Sell one thing to one Swiss consumer, though, and the whole picture flips. All your Swiss supplies, B2B included, suddenly become taxable, and that pulls in retroactive VAT across your entire Swiss sales history. For a SaaS company running a self-serve tier next to enterprise accounts, that's a Tuesday, not some rare disaster scenario.
There's a bit of relief tucked in here too. As of 2025, businesses with Swiss turnover at or under CHF 5 million can file annually instead of quarterly, which helps smaller teams breathe a little. But the 8.1% rate and the annual filing option don't erase the structural risk sitting underneath all of it, because Swiss MWST runs on its own rules and wants its own attention.
A Switzerland-based MoR must run two parallel compliance pipelines simultaneously
A Swiss-domiciled MoR selling into the EU can't touch Union OSS at all. It has to use Non-Union OSS instead, picking one EU member state as its "Member State of Identification" and filing quarterly from outside the bloc, looking in through the window.
Here's the part that really changes the math: that €10,000 de minimis threshold doesn't apply to non-EU companies. A Swiss-based MoR owes EU registration starting with its very first B2C sale into the EU, with no grace period, no ramp-up, and no warning shot.
Add it up and a Swiss-based MoR selling globally juggles Swiss MWST, EU Non-Union OSS, UK VAT (its own separate post-Brexit regime), and whatever else applies outside those blocs. Separate systems, separate registration processes, separate filing calendars, separate enforcement relationships, all running at once, all the time.
That complexity costs actual money. Anrok found non-compliant SaaS businesses lose an average of 4.3% of revenue to penalties and uncollected tax. On thin infrastructure margins, that gap is the difference between a business that works and one that doesn't.
An EU-domiciled MoR sidesteps this entire split for EU sales, plain and simple. The real question for a Swiss-domiciled option is whether the lower MWST rate and the data-side advantages (we'll get to those) are worth carrying two tax pipelines instead of one.
Switzerland has EU data adequacy, what that means in practice and what it does not cover
Switzerland has held an EU adequacy decision since the original 1995 Data Protection Directive, and the European Commission reaffirmed it in 2024 after Switzerland updated its own privacy law, per PwC Switzerland. In plain terms, personal data moves freely between the EU and Switzerland with no Standard Contractual Clauses and no extra paperwork trailing behind it. Other non-adequate countries carry that legal maintenance burden constantly, while Switzerland simply doesn't.
The law doing the work here is the FADP, the Federal Act on Data Protection, revised and in effect since September 2023, rebuilt deliberately to track closer to GDPR so the adequacy relationship would hold up. Adequacy isn't the same thing as identical, though. The FADP carries its own specific requirements, sometimes called "Swiss Add-Ons" in industry writing (Usercentrics has covered this well), and GDPR compliance won't automatically catch them for you.
The trigger for each law is different, too. GDPR cares about EU establishment or activity aimed at the EU. FADP cares about effects felt inside Switzerland itself. The same customer interaction can trip both wires at once, which means passing one test doesn't mean you've passed the other.
One more wrinkle worth flagging: adequacy only covers the EU-to-Switzerland leg of the journey. It says nothing about a Swiss company sending that data onward, to a US cloud host, an analytics vendor, a support tool. Each onward transfer needs its own FADP look. The Swiss-US Data Privacy Framework, confirmed by the Swiss Federal Council on August 14, 2024, lets transfers go to certified US companies without extra safeguards, but somebody actually has to check the certification. It's not a blanket pass for every US vendor with a nice-looking logo.
A Swiss-domiciled MoR serving EU customers faces GDPR obligations in addition to FADP
Here's the twist a lot of Swiss companies miss entirely: GDPR doesn't care where your headquarters sits. If you're serving EU residents or tracking their behavior, GDPR reaches you regardless of your Swiss address on the letterhead. A Swiss MoR processing EU customer payment data, billing history, session logs, all of it falls under GDPR for those specific users, with no exceptions carved out for geography.
The penalties reflect how seriously regulators take this: fines up to a percentage of global annual turnover or tens of millions of euros, whichever number is bigger, plus whatever reputational mess follows a public enforcement action. FADP enforcement runs differently, with a more personal flavor. Swiss regulatory risk can land on individuals, directors and officers named specifically, not just the company treated as some faceless entity.
Being GDPR compliant doesn't hand you FADP compliance for free. The Swiss Add-Ons need their own legal review, which means a Swiss MoR ends up running two separate data compliance programs, the same way it runs two separate tax pipelines. There's a real pitch buried in here too: Swiss hosting offers a kind of political and legal neutrality, sitting apart from both EU and US jurisdiction, and that resonates with privacy-conscious enterprise buyers. Just know the dual-compliance overhead is the toll you pay for that positioning.
An EU-domiciled MoR's data compliance architecture and its own Swiss-side obligation
Flip the jurisdiction and the picture inverts completely. An EU-domiciled MoR sits under GDPR by establishment, directly, rather than through some extraterritorial reach across a border. EU customer data never leaves the GDPR zone, so there's no transfer mechanism to manage for EU-to-EU flows, and oversight sits cleanly with the supervisory authority in whichever member state the MoR calls home.
There's a structural cost that comes with this, too: appointing a Data Protection Officer where required under GDPR. That's a real hire, or a real contract with someone qualified, not a box you tick on a form.
The mirror problem still shows up, running in both directions. An EU-based MoR serving Swiss customers has to work through FADP obligations for those users, Swiss Add-Ons included, since GDPR compliance won't cover them automatically. The weight it carries just depends on where most of your customers actually live.
For a SaaS company selling mostly into the EU, staying EU-domiciled keeps data governance in one place, concentrated, with the Swiss customer base treated as an added legal layer rather than a whole parallel system to maintain. GDPR compliance, done properly, tends to satisfy a good chunk of privacy law elsewhere in the world too. It's become close to the default global baseline at this point, so building on top of it instead of around it saves work down the line.
What founders are actually choosing when they pick an MoR by jurisdiction
The 8.1% MWST rate against EU VAT rates is a margin conversation, not a compliance shortcut. Don't let the lower number trick you into thinking Switzerland means less paperwork, because it means the opposite.
What you're really choosing between is two different operating models. An EU-domiciled MoR gives you a single VAT pipeline through Union OSS, native GDPR coverage, and a cleaner setup if your customers sit mostly in Europe, with FADP handled as an add-on for the occasional Swiss buyer. A Switzerland-domiciled MoR means two tax pipelines (MWST plus Non-Union OSS), FADP as home law with GDPR stacked on top for EU users, and a sovereignty story that plays well with privacy-focused enterprise buyers, at the cost of a genuinely more complicated day-to-day operation.
The force of attraction risk, stacked with Non-Union OSS having no de minimis floor at all, means a Swiss-based MoR has to be sharp from the very first sale. There's no "we'll sort out compliance once we're bigger" runway available to it, because that runway just doesn't exist here.
For a solo founder or a two-person team, that complexity doesn't show up once and disappear. Running two tax pipelines and two data compliance programs at the same time is ongoing work, month after month, not a setup task you check off once and forget about.
So ask the blunt question directly. Does this MoR actually own remittance and filing, or does it just calculate tax at checkout and leave you holding the bag for everything that happens after? A provider that only calculates tax at checkout functions more like a calculator with a nicer interface than a fully accountable Merchant of Record. Separate from jurisdiction entirely, ask whether the MoR's backend, authentication, billing, customer data, tax, is one real system or five tools stitched together with hope. A jurisdiction advantage on paper doesn't help much if your team is manually reconciling spreadsheets between disconnected platforms every single month.
Practical checklist for evaluating an MoR's jurisdictional fit before you sign
Start with the tax side. Confirm whether the provider is EU-domiciled and filing under Union OSS, or Switzerland-domiciled and filing under Non-Union OSS, and get that in writing, not implied over a sales call. Ask specifically how they handle Swiss MWST if it applies to you, and how they manage force of attraction risk if your Swiss customer base mixes B2B and B2C. Push on whether they own the full remittance and filing process end to end, or just the calculation step at checkout. Check whether they're actually registered and compliant in every market where you have real customers, UK, US states, Canada, wherever your business genuinely operates.
On data, find out where customer data physically sits (the real infrastructure location, not the legal mailing address on the incorporation papers). Ask what transfer mechanism governs data moving from that infrastructure to any US-based tooling, whether that's cloud hosting, analytics, or support software. If the MoR is Switzerland-domiciled, ask how it handles GDPR's extraterritorial reach for EU customers. If it's EU-domiciled, ask about its FADP procedures for Swiss users. Confirm GDPR compliance in substance, not a badge sitting in a website footer, with the Swiss Add-Ons addressed as their own separate line item.
Then there's the infrastructure question, which matters just as much as jurisdiction does. Does the MoR plug into your authentication, your customer database, your analytics, or does it sit off to the side as a separate silo you keep in sync by hand every week? Platforms like Tiun., built for AI and SaaS companies with European hosting and Merchant of Record handling built into the same system, keep billing, customer records, and compliance living in one place instead of scattered across five different tools. Worth a look alongside the jurisdiction-specific providers. And ask for a fee structure you can see in full before signing, not something you have to reverse-engineer from three separate invoices after the money's already moved.
The jurisdiction your MoR calls home decides your tax exposure, your data governance obligations, and how much operational overhead you've signed up for, starting from your very first sale. Treat it as an infrastructure decision, because that's exactly what it is, whether anyone tells you that up front or not.


