If you're a Swiss company considering managing sensitive project, customer, or HR data on monday.com, sooner or later one question comes up: where does this data actually end up, and which laws apply? For Swiss SMEs, this isn't just a GDPR question – since September 2023, the revised Swiss Federal Act on Data Protection (FADP) has also applied, bringing its own requirements. This article shows you what monday.com actually offers in terms of data protection and security, where the limits are, and what that means for your company.
Is monday.com GDPR- and FADP-compliant?
monday.com meets the requirements of the EU General Data Protection Regulation (GDPR) and states that it regularly reviews its own practices through internal legal and privacy teams. For Swiss companies, that alone isn't enough as a legal basis: since September 1, 2023, the revised Swiss Federal Act on Data Protection (FADP) has been in force. It aligns closely with the GDPR but forms its own independent legal basis rather than simply mirroring it.
Important to know: if your company processes personal data of people in Switzerland, the FADP applies regardless of where the data is technically processed. If you also offer goods or services in the EU or monitor the behaviour of people in the EU, the GDPR applies in parallel. For data transfers between the EU and Switzerland, the European Commission renewed its adequacy decision based on the FADP in January 2024 – allowing transfers without additional Standard Contractual Clauses (SCCs).
Which security certifications and compliance programs does monday.com hold?
monday.com currently lists the following certifications and compliance programs:
- ISO 27001, ISO 27017, ISO 27018, ISO 27032, ISO 27701
- SOC 1 Type II, SOC 2 Type II, SOC 3
- HIPAA
- GDPR, CCPA
- Additional programs such as LGPD, PIPEDA, TX-RAMP, FedRAMP, CSA, DPF, OAIC, and DORA
These certifications are continuously expanded – independent third-party penetration tests and security audits reportedly take place annually, while dynamic application security testing (DAST) runs at least weekly. You can review all certificates and reports in monday.com's Trust Center.
How does monday.com encrypt my data?
monday.com uses the following encryption methods for customer data:
- Data at rest is encrypted using AES-256.
- Data in transit over open networks is encrypted using TLS 1.3 (minimum TLS 1.2).
- User passwords are hashed and salted with an additional secret value.
For Enterprise customers with elevated requirements, monday.com also offers the "Guardian" add-on, which includes additional encryption controls such as an organization-specific encryption layer and the option to bring your own key (BYOK).
How does monday.com protect access to my account?
Alongside data encryption, account access control plays a central role. monday.com offers:
- Login via username/password or external identity providers such as Google SSO (Pro and Enterprise plans), Okta, OneLogin, and custom SAML 2.0 (Enterprise only)
- Optional two-factor authentication (2FA) via SMS or an authenticator app, which account admins can enable
- Configurable password policies requiring at least 8 characters, optionally with digits, lowercase, and uppercase letters
Credit card data is not stored on monday.com itself: payments are processed through a PCI-DSS certified external billing provider, meaning monday.com does not need its own PCI-DSS certification. Security efforts are reportedly overseen by a dedicated Security Team and a broader "Security Forum" with representatives from Infrastructure, R&D, Operations, and IT.


