Though I'm not sure if the GDPR allows for data to be stationed in Switzerland. It's not EU but it is party to a lot of treaties so it's not out of the question.
Ironically it might become a safer place to station data if the EU manages to push through more surveillance decrees.
There is a treaty between the EU and Switzerland for this. Full list of countries here: https://commission.europa.eu/law/law-topic/data-protection/i...
Being inside of the EU also won't ensure your privacy: https://argos.vpro.nl/artikelen/former-philips-top-cryptogra...
And let's not forget that the Swiss are just as willing to implement privacy infringing laws as any other country these days: https://tuta.com/blog/switzerland-surveillance-plan
Don't trust a company just because it's situated somewhere. When governments friendly to yours want to spy on you, they don't necessarily let borders stop them.
CryptoAG and the CIA's decision to release the history document of that operation is such an interesting story. In particular, it had this effect of getting people to distrust Swiss companies, for better or for worse. It makes it sound plausible, if however unlikely, that a company such as Proton is actually a front for US cyber warfare. (I don't think it is but it might be; it seems like that may have been the point.)