FINMA · MiCA · AI Act · Data protection

Regulatory Lawyers in Switzerland

FinTech and crypto regulation, data protection and AI. The rules that decide whether you can ship.

FINMA token qualification, fixed fee CHF 5'500
MiCA classification, white paper and CASP licensing
AI Act, GDPR and FADP in one 2-hour workshop, CHF 3'000
Data protection to GDPR and FADP, from CHF 2'800
Ivan Cossu
“The cooperation was very good and I can already predict that we will approach LEXR again. We had a good feeling right from the start. This was then confirmed throughout the entire process. We had the feeling that LEXR was part of the deskbird team.”

Ivan Cossu · Co-Founder & CEO, deskbird

Trusted by 1'500+ tech companies & investors

Why LEXR for regulation

01

Classification before build

A token assessment names the category — payment, utility, asset or hybrid — and the licence path that follows from it, in writing, for CHF 5'500. That answer decides your architecture, so it belongs before the code, not after the launch.

02

Swiss and EU regimes from one desk

FINMA and SRO on one side, MiCA and the AI Act on the other, with offices in Zurich and Berlin. A Swiss company selling into the EU is inside both systems and should not be paying two firms to say so.

Global reach. Local roots. One team

LEXR offices

  • Zürich
  • Lausanne
  • St. Gallen
  • Davos
  • Brooklyn
  • Berlin
  • Munich
  • News LEXR writes the licensing guidelines for the EU's official Chips Design Platform EuroCDP
  • Deal LEXR represents a Swiss institution in a $100m+ acquisition of a Swiss FinTech
  • Deal LEXR structures a tokenized tracker certificate and drafts EU prospectus for retail distribution
  • Deal LEXR advises a FinTech scale-up on their Delaware flip to expand to the US market

Regulation FAQ

What founders and CFOs ask before they ship a regulated product.

FINMA classifies by function, not by name. A payment token is a means of payment and brings anti-money-laundering duties; a utility token gives access to an application and stays outside financial-market law only if that application already works at issuance; an asset token represents a claim or an asset and is treated as a security. A token with more than one function takes the strictest treatment of the ones it carries. The assessment states which category applies and what follows from it.

It turns on whether you hold third-party assets and what you do with them. Acting as a financial intermediary — exchanging, transferring or custodying crypto assets for clients — triggers the AML act, and for firms not directly supervised by FINMA that duty is met by joining a self-regulatory organisation. Taking public deposits, running a trading venue or issuing your own means of payment is licence territory instead. The difference is a scoping question, answered before you build the onboarding flow.

Yes, if you offer crypto-asset services to EU clients or market a token there — MiCA follows the market, not the domicile. Publicly offering a token means a white paper notified in a member state; providing services means a CASP authorisation, which in practice needs an EU entity. Relying on clients approaching you unprompted is a narrow exception and not a strategy. A Swiss licence does not passport into it.

It applies by role and by market. A Swiss provider whose system is placed on the EU market, or whose output is used in the EU, is in scope, and the duties scale by risk class rather than by company size: some uses are prohibited, high-risk uses carry documentation, data-governance and conformity obligations, and limited-risk uses need disclosure that the user is dealing with AI. Building on a foundation model adds duties from that model's own tier.

Usually both. The Swiss FADP applies because you are established here; the GDPR applies as soon as you offer goods or services to people in the EU or monitor their behaviour. The overlap is large enough that one set of documents serves both: a record of processing activities, a privacy and cookie policy, processor agreements, a breach process, and an EU representative if you have no establishment there.

Each recurring piece has a listed fixed fee: CHF 5'500 for a token assessment, CHF 3'000 for the AI workshop, CHF 6'500 for an SRO application, data protection from CHF 2'800. What no firm can fix is the regulator's timetable, so correspondence with FINMA or a supervisory body is drawn from a pre-paid block as it is used. A free data processing agreement generator covers the case where that is all you need.

Regulator on your roadmap? Let's get ahead of it

Thirty minutes with a regulatory lawyer. Bring the product and the countries you sell into.