The case
According to privatim, the conference of Swiss data protection officers, outsourcing particularly sensitive or confidential personal data, such as tax details or medical information, to cloud services operated by international providers is generally not permitted.
Source: Datenschutz Schweiz aktuell
The commentary
Swiss authorities have virtually no way of verifying whether global cloud providers actually comply with contractually agreed data protection and security requirements, which leads to a significant loss of control.
Furthermore, under the US CLOUD Act, American providers can be compelled to hand over customer data to US authorities, even if the data is stored in Switzerland and even without international mutual legal assistance procedures.
For this reason, privatim states that authorities may use such Software-as-a-Service (SaaS) solutions only if they encrypt sensitive data themselves and ensure that the cloud provider has no access to the encryption keys.









