Digital Sovereignty of Switzerland
Machine-supported translation — please verify against the German master version. — Original German version

The concrete problem: Office 365 in Swiss public administration
The Swiss federal administration, a majority of cantonal administrations and many municipalities work today with Microsoft 365 — e-mail (Exchange Online), documents (Word, Excel, PowerPoint in the cloud), chat (Teams), file sharing (OneDrive, SharePoint), identity management (Entra ID, formerly Azure AD). All these services are operated by Microsoft Corporation from Redmond, Washington, USA. The Swiss data copies are stored in the Microsoft data-centre regions «Switzerland North» (Zurich) and «Switzerland West» (Geneva).
At first glance this looks like sovereignty: data on Swiss soil, contracts with Swiss subsidiaries, certifications (ISO 27001, FedRAMP, BSI C5).
Legally, this sovereignty cannot be enforced. Three US-law mechanisms reach across the storage location:
- CLOUD Act (18 U.S.C. § 2713): US authorities can compel Microsoft Corporation in Redmond to hand over data in the corporation's «possession, custody or control» — regardless of whether the data sits in Zurich, Frankfurt or Texas. The «Switzerland North» region is irrelevant under US law.
- FISA Section 702 (50 U.S.C. § 1881a): The NSA can compel Microsoft to deliver communications data of non-US persons — without an individual warrant, and without Microsoft being allowed to inform the Swiss customer.
- National Security Letters (18 U.S.C. § 2709): The FBI can demand connection data, regularly with a gag order — Microsoft is not allowed to inform the customer.
In concrete terms for a Swiss federal office: an e-mail conversation with a foreign authority, a OneDrive file with case notes, a Teams chat between staff — all of this is reachable under US law at any time, without the Swiss oversight (FDPIC, PDel, IS-FIS) being informed. Claims like «EU Data Boundary» or «Microsoft Customer Lockbox» do not change this, because they rest on Microsoft's operational self-commitment — not on a US statutory limitation.
The Swiss Federal Chancellery awarded the «Cloud Services of the Public Administration» programme in 2021 to five US hyperscalers (AWS, Microsoft, Google, Oracle, IBM). Risk analyses were performed, but no exclusion of US-jurisdictional providers occurred. The FDPIC (Federal Data Protection and Information Commissioner) has pointed out the structural problem in several activity reports without this leading to a policy change.
This wiki documents the mechanics of this dependency, its Swiss enforcement dimension, the legal limits, and a concrete legislative recommendation (FADS — Federal Act on Digital Sovereignty).
About this chapter
This chapter is a reference work — a source-based assessment of the digital sovereignty of Switzerland in the tension between transatlantic data collection, Swiss enforcement practice and proprietary software tools.
Every page follows an eight-part outline (In three sentences / Mechanics / Sources / What this means for Switzerland / Logical conclusion / What this means for legislation / Further reading / Status and versioning) and rests exclusively on primary sources, source-curated reference materials and field dossiers. No literary narrative, no dramatisation — factual basis.
Sections
- Mechanisms of data collection — Selector, FISA 702, Cloud Act, Hyperscalers, PRISM, Incidental Collection
- The Swiss enforcement machinery — IntelSA 2017, PTSS, Cable Intelligence, IASA/INDEX, Five-Eyes liaison, IS-FIS, FBI Legat
- The tools — Palantir, Cellebrite, Watchlists, Border Search, Palantir-CH
- Legal protection and its limits — Schrems II, EO 14086, IntelSA 63, GDPR 15, FOIA, NGO litigation
- The sovereign alternative — Open Source, sovereign stack, SaaS providers, identity, Linux/GrapheneOS, migration
- Federal Act on Digital Sovereignty (FADS) — Complete legislative recommendation draft
- Workshop and contact points — Facsimiles, glossary, contact points, checklists