Rico EberleDübendorf, home

Who holds the key to your mailbox?

What an encrypted mailbox like Proton does differently from a regular one, what stays visible anyway, and what Swiss law, the 2021 case and the planned revision of the Swiss surveillance ordinance mean for it.

Auf Deutsch lesen

Show transcript

Who can read your emails? With most providers: the provider itself.

With a regular mailbox, your emails are stored encrypted on the server. But the provider holds the key. It can technically read and search them. And when an authority comes knocking, it can hand them over.

Encrypted mailboxes turn this around. The key is protected by your password, and only you know it. On the server, there's only scrambled data. Proton calls this zero-access: even the provider can't get to the content. When two Proton users write to each other, the email is even end-to-end encrypted, from device to device.

But not everything is protected. Subject, sender and recipient are not end-to-end encrypted. Neither are emails to regular addresses, unless you protect them with a password.

Then there's the location. Proton is based in Geneva and subject to Swiss law. Foreign authorities have to go through Swiss legal assistance. With a court order, Proton still has to hand over data. In 2021, that's how Proton had to log the IP address of a French activist. The content of the emails stayed encrypted.

And Switzerland is changing, too. Because of a planned tightening of the surveillance ordinance, Proton has already moved parts of its infrastructure abroad.

My view: I've been using Proton for years. Mainly for email, but also for other services in the bundle. Not because it's perfect. But because the provider can't read my content. To me, that's digital sovereignty in everyday life.

Who can read your emails? With most providers, the honest answer is: the provider itself. Encrypted mailboxes promise something different. Here is what they deliver and where the limits are, using Proton as an example.

Regular mailbox: the provider holds the key

Even with a regular mailbox, emails are usually stored encrypted on the server. But the provider manages the key. It can technically read and search your emails, for search, spam filters or extra features. And when an authority arrives with a valid order, it can hand them over.

Diagram “Regular mailbox”: on the left “You” with a smartphone, on the right the “Provider” server with readable email text “Hi Tom, here’s the contract …”. The key sits with the provider, below it an arrow to “Authority”. Beside it: “Can be handed over on request”.

With a regular mailbox, the provider holds the key. It can read the emails and hand them over when ordered.

Encrypted mailbox: the key stays with you

Encrypted mailboxes turn this around. The key is protected by your password, and only you know the password. The server only holds scrambled data. Proton calls this zero-access encryption: even the provider can’t get to the content.

When two Proton users write to each other, it goes one step further. The email is then end-to-end encrypted, from the sender’s device to the recipient’s device. Nobody can read it in transit or on the server.

Simplified: behind the “key”, Proton uses a private key based on the OpenPGP standard and the password that protects it.

Diagram “Encrypted mailbox”: the key now sits with “You”, protected by a “Password”. The provider only holds scrambled characters. Beside it: “Zero-access: even the provider can’t get to the content”.

Same diagram, roles reversed: the key is protected by your password, and the server only sees encrypted data.

What stays visible anyway

Not everything is protected. According to Proton, subject lines, sender and recipient addresses are encrypted, but not end-to-end encrypted. Who writes to whom, when and about what is therefore not protected to the same degree as the content.

Emails to regular addresses, such as Gmail or Outlook, are not end-to-end encrypted either. The exception: you protect the email with a password that the recipient receives through another channel.

Email header “What stays visible”: From Lea, To Tom, Subject Contract, each marked “visible”. Below, with a padlock: “Content encrypted”. Beside it: “To regular addresses: not end-to-end, unless password-protected”.

The content is protected; sender, recipient and subject are not end-to-end encrypted.

Based in Switzerland: protection, not a free pass

Proton is based in Geneva and subject to Swiss law. Foreign authorities cannot force Proton to hand over data directly; Article 271 of the Swiss Criminal Code prohibits passing data directly to foreign authorities. They have to go through Swiss mutual legal assistance.

When a binding order under Swiss law arrives, Proton still has to provide data. The 2021 case shows this: French police sent their request via Europol to the Swiss authorities, who then required Proton to log the IP address of a French activist. Proton had to comply. The content of the emails stayed encrypted.

How often this happens is in Proton’s transparency report: in 2025, there were 9,301 orders for Proton Mail, of which 8,313 were complied with and 988 contested. Proton can hand over things like account details and activity logs, but no encrypted content.

Flow “Location: Switzerland”, “Geneva · Swiss law”: “Foreign authority” leads via “Swiss legal assistance” to “Court order”. Beside it the box “2021: IP address of a French activist logged. Email content stayed encrypted”.

Foreign authorities have to go through Swiss mutual legal assistance. Proton then has to hand over metadata such as an IP address, but no encrypted content.

Switzerland is changing too: the VÜPF revision

The Swiss ordinance on the surveillance of postal and telecommunications traffic (VÜPF) defines which providers have to assist with surveillance and how. The federal government wanted to tighten it. The draft failed in the 2025 consultation: the Greens, SP, GLP, FDP and SVP rejected it, as did industry associations and providers such as Threema and Proton.

Proton has already responded by moving parts of its infrastructure abroad. First, in 2025, its AI assistant Lumo moved to servers in Germany; further locations are being set up in Norway.

As of 2 October 2026: the revision is not in force. On 11 February 2026, the Federal Council took note of the consultation results, commissioned a regulatory impact assessment and announced a second consultation once the revised version is ready.

Slide “Surveillance ordinance (VÜPF)”: “Tightening planned, not in force as of October 2026”. Below, “Proton moves parts of its infrastructure”: arrow from “Switzerland” to “Germany · Norway”.

The revision is not yet in force. Proton has already responded anyway.

Three questions for your mailbox

  1. Who holds the key? You or the provider?
  2. What is end-to-end encrypted? Only the content, or also subject and recipients? And does it apply to emails sent outside the service?
  3. Which law is the provider subject to? And how does it handle orders, is there a transparency report?

My view

This is my personal assessment, not a recommendation for every case.

I’ve been using Proton for years, mainly for email, plus other services from the bundle. Not because it’s perfect: metadata stays visible, and Switzerland can change its rules too. But because the provider can’t read my content. For me, that is digital sovereignty in everyday life: not complete independence, but deciding consciously who holds the key.

And you?

Who holds the key to your mailbox?

Frequently asked questions

Can Proton read my emails?

Not the content. Proton stores emails with zero-access encryption: the key is protected by your password, and the server only holds encrypted data. Subject lines, sender and recipient addresses are encrypted, but not end-to-end encrypted.

Is an email from Proton to a Gmail address end-to-end encrypted?

No. Emails between two Proton accounts are end-to-end encrypted. Emails to regular addresses are only end-to-end encrypted if you protect them with a password that the recipient receives through another channel.

Does Proton have to hand data over to authorities?

Yes, when it receives a binding order under Swiss law, but not the content of encrypted emails, because Proton cannot decrypt it. It can hand over things like account details and activity logs. Foreign authorities have to go through Swiss mutual legal assistance. In 2021, such an order required Proton to log the IP address of a French activist.

Embed this learning nugget

For learning platforms, blogs and school websites. Content licensed under CC BY 4.0.

About the author

Rico Eberle

Rico Eberle is an e-learning expert, business economist (FH) and municipal councillor in Dübendorf, Switzerland. He chairs the foundation board of WBK Dübendorf, a continuing education foundation. In the learning nuggets he explains research on learning, AI and digital sovereignty, briefly and with sources.

Text, transcript and video by Rico Eberle under CC BY 4.0 (music and sound effects excluded). Reuse and open data.