Regulation
5 min read
Published on
August 24, 2026

Switzerland’s transparency register is a data governance problem, not just a filing requirement

SecureSafe Team
Man working with papers with an office setting

Table Of Content

Name of the heading

Introduction

Switzerland's new Federal Act on the Transparency of Legal Entities and the Identification of Beneficial Owners, known by its German acronym TJPG, enters into force on October 1, 2026. Parliament passed the law on September 26, 2025, and the Federal Office of Justice has been running a voluntary pilot phase since June 16, 2026 to test the register's technical infrastructure before it goes live. Most of what has been written about the law so far reads like a legal bulletin: who has to file, by when, and what happens if they do not. That framing is accurate but incomplete. The harder problem sitting underneath the legal text is not filing. It is data governance, and it will land on more desks than the legal and compliance functions currently expect.

Key Takeaways

  • The TJPG and a revised Anti-Money Laundering Act both take effect on October 1, 2026.
  • The register is run by the Federal Office of Justice and is not publicly accessible. Access is limited to a control body attached to the Federal Department of Finance, designated authorities, financial intermediaries, and advisors subject to due diligence duties.
  • A person generally counts as a beneficial owner once they hold at least 25 percent of a company's capital or voting rights, or exercise comparable control by other means.
  • Reporting applies to Swiss corporations, GmbHs, cooperatives, certain investment companies, and specific foreign legal entities with a branch, real management, or real estate in Switzerland, based on self-declaration, with narrow exemptions for listed companies, pension institutions, and majority publicly held entities.
  • Registration itself is free of charge, though the law provides for administrative fines for willful violations of the identification and reporting duties, as set out in the TJPG legislative text.
  • The real ongoing burden is not the initial filing but maintaining accurate, verifiable, and securely stored evidence of ownership and control over time, since the underlying data must stay current and correct rather than sit as a one-time submission.

The mechanics of the TJPG are set out clearly on the Federal Office of Justice's own transparency register portal. Companies and other reporting entities identify their beneficial owners, verify the information, and report it through the EasyGov platform, which the federal administration uses to centralize both filings and authorized lookups. Reporting is based on self-declaration, meaning the responsibility to identify, verify, and keep the record current sits with the company itself, not with a government official checking the work at the point of filing.

None of that is unusual by international standards. Beneficial ownership registers have spread across jurisdictions for years, largely in response to Financial Action Task Force recommendations. What makes the Swiss version worth a closer look is a detail that gets mentioned and then quickly set aside: the register itself is not public. Access is restricted to a control body affiliated with the Federal Department of Finance, to specific authorities named in the law, and to financial intermediaries and advisors who fall under due diligence obligations in the Anti-Money Laundering Act. Companies cannot even look up their own filing directly. They can only request an extract or a confirmation of registration.

That single design choice changes where the real operational burden falls. In a public register model, a company files once, the record becomes visible, and the ongoing obligation is mostly to keep it current. In a non-public model built around due diligence access, the underlying evidence never stops mattering. Financial intermediaries, trustees, and advisors who touch this data are expected to hold verifiable, audit-ready proof of who the beneficial owners are, not just a submitted form sitting in a federal database. That proof typically includes identity documents, ownership agreements, board resolutions, and correspondence establishing control, and it needs to survive scrutiny well after the initial filing, particularly since changes affecting who qualifies as a beneficial owner must also be reported within thirty days of the chnage taking effect.

This is where the pain actually shows up inside organizations. A trustee managing beneficial ownership files for dozens of client structures needs a place to store identity documents and ownership evidence that is more secure than a shared drive and more structured than an email inbox. A law firm coordinating a filing with a client's finance team needs to exchange identity documents and signed declarations without those files ending up as unencrypted attachments scattered across several mailboxes. A mid-sized Swiss holding company with a foreign parent needs to be able to show, potentially years after the fact, that the ownership record it filed in 2026 was accurate at the time and has been updated every time the structure changed. None of these are legal questions in the strict sense. They are questions about where sensitive personal and ownership data lives, who can reach it, whether every access is logged, and whether the organization could reconstruct its evidence trail if a regulator or an authorized advisor asked.

The organizations most exposed are not necessarily the largest ones. Large financial institutions already run mature know-your-customer infrastructure and will absorb this requirement into existing workflows. The harder position belongs to the mid-market: trust companies, boutique law and notary practices, corporate service providers, and SMEs with layered ownership structures, all of whom now carry an identification and evidence-retention burden without necessarily having built the infrastructure for it. For many of these organizations, the TJPG will be the first time beneficial ownership documentation moves from something a lawyer keeps in a folder to something the organization needs to prove it handles securely, on an ongoing basis, under a law that provides for real administrative fines.

That is a data infrastructure problem before it is a legal one, and it is worth naming plainly rather than folding into a general compliance narrative. The question every affected organization should be asking is not only whether it has filed, but whether it could prove the accuracy and security of its beneficial ownership records if asked to do so six months from now, without reconstructing the file from scratch. Organizations that treat this as a one-time submission will find themselves rebuilding evidence under time pressure the next time it is requested. Organizations that treat it as an ongoing data governance obligation, with encrypted storage, controlled access, and a clear record of who touched what and when, will simply be able to answer the question.

This is also why the conversation belongs with whoever manages an organization's document and data infrastructure, not only with legal counsel. Encrypted storage, access logging, and secure document exchange are the practical tools that turn a standing legal obligation into something an organization can actually demonstrate on request, and Swiss providers built around that kind of data governance are a natural fit for the problem the TJPG has created.

Conclusion

The TJPG pilot has been running since June 2026, and the law itself takes effect on October 1, 2026, but the underlying obligation does not end on that date. It continues for as long as the company exists and its ownership structure can change. Organizations that build the data discipline now, rather than treating October 1 as a deadline to clear, will be far better positioned for the reporting cycles that follow it. The filing is a form. The evidence behind it is a standing responsibility, and that is the part worth getting right first.

How SecureSafe Can Help

Meeting the TJPG's ongoing evidence requirements comes down to three practical needs: a secure place to store identity documents and ownership records, a controlled way to exchange that documentation with advisors, notaries, or authorities without relying on email attachments, and a clear log of who accessed what and when. SecureSafe's platform is built around exactly this kind of secure document storage and exchange, with encryption designed so that even SecureSafe cannot read the underlying files, alongside access controls and audit trails that let organizations demonstrate their compliance posture on request rather than reconstruct it under time pressure.

If your organization is working through what the TJPG means for how you store and exchange beneficial ownership documentation, get in touch with the SecureSafe team to talk through your specific setup.

Related Articles

Regulation

DORA in 2026: what 15 months of enforcement have taught us

The Digital Operational Resilience Act (DORA) has been in full application since January 17, 2025. In the 15 months since, the first Register of Information submissions have been collected, the first Critical ICT Third-Party Providers (CTPPs) have been designated, and the operational reality of the regulation has started to take shape. For financial entities in scope, the questions in 2026 are no longer about readiness but about execution quality.

Regulation

From paper to digital: why the next ten years will be more about "how" than "if"

The shift from paper to digital is no longer a question of whether organizations go paperless, but how they do it: with privacy-oriented architecture, regulatory clarity, reliable long-term access, and measurable sustainability benefits. For companies handling sensitive financial, legal, or personnel documents, the bar has risen. Paperless workflows now need to be secure, auditable, interoperable, and resilient.

Sovereignty
Regulation

What digital sovereignty is, and why it matters more in 2026 than ever before

Digital sovereignty has three dimensions: legal, technical, and operational. Unless all three align, control over data is partial at best. This piece explains what genuine sovereignty requires, why 2026 has made it an operational necessity, and how Switzerland's legal and technical environment delivers it in practice.