Data sovereignty has become a strategic priority for organizations across Europe. Yet despite growing attention from regulators, there is no single law that defines exactly how to achieve it. There is no dedicated "Data Sovereignty Act". Instead, a range of privacy and cybersecurity regulations outline what organizations are responsible for, how personal data must be protected, and what needs to be considered when working with cloud providers, external vendors, and international data transfers.
In our previous articles, we explored why data sovereignty depends on more than data residency and how technical architecture helps organizations maintain control over their data. This raises a natural next question: where do these requirements come from?
While Switzerland and the European Union approach data governance through different legal frameworks, they collectively point toward a common expectation: organizations must retain meaningful control over their data. So what do these regulations actually require, and how can organizations translate legal obligations into practical operational principles?
Data Sovereignty in Switzerland
1. FADP and DPO
In Switzerland, data protection is primarily governed by the Federal Act on Data Protection (FADP) and the Data Protection Ordinance (DPO). Public bodies at the cantonal and municipal level are also subject to their respective cantonal data protection laws.
Although the Swiss data protection law does not define or regulate "data sovereignty" as a distinct legal concept, it establishes a clear principle of accountability. Organizations remain responsible for protecting personal data and managing associated risks, even when processing activities are outsourced to third parties.
- Organizations must consider data protection from the outset when designing data processing activities
- Article 8 of the FADP requires security measures that are appropriate to the level of risk.
- Organizations using third-party service providers must assess whether those providers can ensure adequate data security.
- Additional requirements apply when transferring personal data abroad.
- Even when data processing is outsourced, the organization remains responsible for lawful processing and appropriate protection of personal data.
Organizations should classify data according to its sensitivity and risk profile and carefully assess service providers and subcontractors. Security measures such as encryption, strong authentication, and activity logging help safeguard sensitive data. In addition, documented processes for deletion, recovery, and oversight ensure that organizations remain operational in the event of incidents, outages, or contract termination.
2. Guidance from the Swiss Federal Data Protection and Information Commissioner (FDPIC)
The FDPIC has published guidance to help organizations apply Swiss data protection rules to outsourcing arrangements and cloud services.
The guidance emphasizes that assessing cloud providers requires more than reviewing contracts. Organizations should understand where data is processed, which subcontractors are involved, and how agreed safeguards can be verified in practice.
- Organizations must know where their data is processed and stored.
- Any subcontractors involved must be included in the assessment process.
- Potential disclosures and access from foreign jurisdictions must be considered.
- Organizations must be able to verify that agreed security measures are being implemented.
Organizations should maintain visibility into how and where third-party providers process data and which subcontractors are involved. Assessments should consider not only data residency but also the legal frameworks that apply and the possibility of access from foreign authorities. Organizations should regularly reassess security controls whenever circumstances change.
3. The Privatim resolution on international cloud services
The Privatim Resolution of November 24, 2025, provides important guidance for Swiss public-sector organizations evaluating international cloud services. While not legally binding, it reflects the shared position of Swiss data protection authorities and highlights a key sovereignty concern: outsourcing should not result in a loss of control over sensitive data.
- According to Privatim, the use of international SaaS providers for highly sensitive personal data or data protected by statutory confidentiality obligations present significant risks if the provider can access the data in plaintext.
- Such services may only be appropriate if data is encrypted before it reaches the cloud and the solution provider has no access to the encryption keys.
- Risk assessments must also account for foreign access laws. Privatim specifically references the U.S. CLOUD Act, under which U.S. providers may be compelled to disclose customer data to U.S. authorities, even when that data is stored in Swiss data centers. Data residency alone does not guarantee data sovereignty.
Public-sector organizations should first determine whether they process highly sensitive or legally protected personal data. They must then assess whether providers or subcontractors can access plaintext data or cryptographic keys. Control of encryption keys should remain with the responsible organization or authorized users. They must regularly review if changes in corporate ownership, legal obligations, service providers, or data flows should be incorporated into ongoing risk assessments.
Swiss regulations and requirements at a glance
| Regulatory framework | Key principle | Practical question |
| FADP & DPO | Responsibility and protection measures must be proportionate to risk. | Have we identified all relevant data, risks, and safeguards? |
| FDPIC Guidance | Outsourcing does not remove accountability or oversight obligations. | Do we know who processes our data, where, and how? |
| Privatim Resolution | Technical provider access matters, especially for sensitive data. | Can the provider access our content or encryption keys? |
Data Sovereignty in the European Union
Like Switzerland, the EU does not regulate data sovereignty through a single framework. Instead, sovereignty-related requirements emerge from data protection, international transfer, cybersecurity, and resilience obligations that increasingly require organizations to understand and manage third-party risks.
The General Data Protection Regulation (GDPR) is the primary framework governing the protection of personal data. For transfers outside the EU and European Economic Area, additional requirements stem from Chapter V of the GDPR, the Schrems II judgment, and guidance from the European Data Protection Board (EDPB).
For critical sectors, NIS2 and DORA introduce additional obligations related to cybersecurity, resilience, and third-party risk management.
1. General Data Protection Regulation (GDPR)
The GDPR is often viewed primarily as a privacy regulation. However, many of its core principles, including accountability, privacy by design, and processor oversight, directly support data sovereignty objectives. At its heart, the GDPR seeks to ensure that organizations remain responsible for personal data throughout its lifecycle, regardless of who processes it.
- Organizations must be accountable for how personal data is processed and be able to demonstrate compliance ((art. 5(2))
- Privacy and data protection considerations should be built into systems and workflows by design (art. 25)
- Organizations remain responsible for ensuring that service providers and subcontractors handling personal data provide appropriate safeguards (art. 28)
- Technical and organizational measures should be appropriate for the level of risk. (art. 32)
- Security measures must be reviewed and updated regularly.
Organizations should understand their data flows, assess risks continuously, and maintain visibility into how personal data is handled across their systems and third-party services. Privacy and security need to be embedded into everyday operations.
When working with processors or subcontractors, organizations should assess not only contractual commitments but also the provider's actual ability to protect data. Access should be limited to what is necessary, and organizations should be able to demonstrate that their safeguards remain effective over time.
2. International data transfers, Schrems II, and EDPB recommendations
Schrems II fundamentally changed the conversation around international data transfers. Before the judgment, organizations often focused on transfer mechanisms such as Standard Contractual Clauses. Today, regulators expect organizations to look beyond paperwork and assess whether data remains protected in practice, including against foreign government access.
- Chapter V of the GDPR governs transfers of personal data to third countries.
- Where the destination country is not covered by an adequacy decision from the European Commission, organizations must rely on appropriate safeguards or specific legal exceptions.
- Data transfers must not undermine the level of protection guaranteed under EU law.
- In the Schrems II judgment, the Court of Justice of the European Union confirmed that Standard Contractual Clauses remain a valid transfer mechanism. It also emphasized that organizations must assess the legal environment and potential government access in the recipient country.
- Individuals must receive a level of protection that is essentially equivalent to that guaranteed within the EU.
- EDPB recommendations require organizations to map their international data transfers, evaluate transfer mechanisms, and implement supplementary safeguards where necessary.
- If adequate protection cannot be achieved, transfers must be suspended or discontinued.
Organizations should maintain a complete inventory of international data transfers and assess the legal frameworks and potential government access in destination countries. The question is not simply whether data leaves the EU, but whether it remains protected to a standard that is essentially equivalent to that guaranteed under EU law. If contractual commitments and technical safeguards together cannot ensure adequate protection, the transfer should not continue.
This may be the case, for example, if a provider controls the decryption keys and therefore has the technical ability to access data in plaintext. Assessments should be documented and updated whenever data flows, service providers, or applicable legal requirements change.
3. NIS2 and DORA: Additional requirements for cybersecurity and resilience
NIS2 and DORA do not directly regulate data sovereignty. However, they reinforce the broader governance framework by requiring affected organizations to manage operational risks arising from cybersecurity threats and third-party dependencies.
NIS2 requires essential and important entities to implement structured cyber risk management practices, including supply chain security, access control, incident response, and business continuity. DORA applies to financial entities and aims to ensure that organizations can manage ICT risks, oversee external ICT service providers, and maintain operational resilience in the face of disruptions.
In practice, this means organizations should not focus solely on protecting data. They must also understand which critical processes depend on external services and how those processes can continue during outages, disruptions, or provider transitions.
EU requirements at a glance
| Regulatory framework | Key principle | Practical question |
| GDPR | Data protection must be risk-based and demonstrable. | Can we prove that personal data is appropriately protected? |
| GDPR Chapter V, Schrems II & EDPB Guidance | The EU level of protection must be maintained during international transfers. | Do we understand all international transfers and potential foreign access risks? |
| NIS2 | Essential and important entities must manage cyber, supply chain, and operational risks. | Can critical services remain secure and resilient during disruptions? |
| DORA | Financial organizations must control ICT third-party risks and maintain operational resilience. | Can critical functions continue during an outage or provider change? |
Four practical principles for data sovereignty
Although Swiss and EU regulations were developed for different purposes, they repeatedly focus on the same practical questions:
- Do organizations understand where their data is processed?
- Do they know who can access it?
- Can they demonstrate oversight of third parties?
- Can they remain in control when circumstances change?
The four principles below translate these recurring regulatory expectations into practical guidance:
1. Understand your data flows and dependencies
Organizations need a clear picture of where data resides, who processes it, and how it moves across systems. This includes not only content but also metadata, backups, support access arrangements, service providers, and subcontractors. It is equally important to understand which legal jurisdictions apply and where dependencies on external services exist.
2. Limit technical access to data
Contracts and policies define who is allowed to access data, but true control requires technical enforcement. Organizations should understand who can decrypt data, who controls encryption keys, and whether service providers have any technical ability to access information in plaintext.
3. Manage access and permissions with precision
Both internal and external users should have access only to the data required for their specific responsibilities. Organizations should be able to grant, review, restrict, and revoke access as needed, while maintaining visibility into who can view, edit, download, or share information.
4. Stay in control, even during disruptions
Data sovereignty goes beyond preventing unauthorized access. Organizations must also be able to access their data and maintain critical operations during security incidents, system failures, or provider transitions. To achieve this, security measures, access controls, and risk assessments should be clearly documented and regularly reviewed. Organizations should also have defined processes for data recovery, deletion, migration, and provider transitions to ensure they remain in control throughout the data lifecycle.
Data sovereignty requires technical assurance
To achieve data sovereignty, organizations need more than compliance policies and contractual assurances. It requires a combination of technical architecture, governance processes, and demonstrable control.
Ultimately, the critical question is not what a contract promises, but whether your organization can retain control over its data flows in day-to-day operations.
Data sovereignty by design with Tresorit
The four principles outlined above demonstrate that data sovereignty depends on legal, organizational, and technical controls working together.
Tresorit helps organizations put these principles into practice: Our end-to-end encryption and zero-knowledge architecture ensures that only authorized users can access data – not even the provider. Flexible data locations, granular access and sharing controls, and detailed activity tracking support secure collaboration and data governance.
Do any of these four principles reveal gaps in your organization's approach to data sovereignty? Discover how Tresorit helps organizations achieve data sovereignty by design.
Oliver Jäger
View more articles from this author



