Server with the Flag of Switzerland
– Getty Images

A Swiss regulatory body has restricted the use of international cloud service providers, including hyperscalers like Microsoft, AWS, and Google, amid privacy concerns.

The Conference of Swiss Data Protection Officers organization, known as Privatim, has effectively banned the use of these cloud services as comprehensive SaaS solutions where sensitive or legally confidential data is involved.

Privatim outlined last week that before outsourcing personal data to cloud services, the Swiss authorities must “analyze the particular risks in individual cases” and “reduce them to a sustainable measure with appropriate measures.”

Citing reasons such as U.S. hyperscalers offering “too little transparency to ensure that Swiss authorities can verify compliance with contractual obligations relating to data protection and security”, the regulatory body said the “use of SaaS applications is therefore accompanied by a significant loss of control.”

Another major consideration for the decision was the enmeshing of conflicting jurisdiction in certain cases where American-headquartered hyperscalers may be required to release their customers’ data to U.S. authorities without complying with the rules of international legal assistance – even if that data is stored in Swiss data centers.

The resolution also points out that cloud and SaaS service giants can amend the terms and conditions on their side, potentially harming the established security and privacy provisions.

“The use of international SaaS solutions for personal data, which is particularly worthy of protection or subject to a legal obligation of confidentiality by public bodies, is only possible if the data is encrypted by the responsible body itself and the cloud provider does not have access to the key,” Privatim concluded.

With this step, the Swiss regulators are effectively inching towards a return to on-premises infrastructure or a demand for specialized European providers for government functions and legally confidential data.

Switzerland’s decision comes amid increased push for EU data sovereignty and alternative ways for the bloc to protect and govern its own data.

In response to that, some tech giants have already made provisions to appease the continent’s demands, as last month, Microsoft pledged that AI user data will stay in the EU and Copilot interactions will be processed in-country by the end of 2025.

After facing increased scrutiny from continental lawmakers, Microsoft unveiled a flurry of new cloud capabilities, including all user data, whether at rest or in transit, being stored and processed exclusively in the EU, unless a user requests otherwise.

In a similar move, the EU Data Act in September made cloud provider lock-in harder, giving EU customers the right to switch providers with just two months' notice, in a bid to ensure a fairer data economy and greater freedom of choice. To comply, hyperscale giants scrapped data transfer fees as they are mandated to make it easier for customers to switch between providers.

One of the latest vendors to join this movement was Cisco, which further committed to the sovereignty race by giving customers full infrastructure control to meet EU data rules

Cisco’s Sovereign Critical Infrastructure portfolio now provides users with their own air-gapped environments across its core product line to enable them to build their own on-premises or hybrid sovereign infrastructure.