Published on April 21, 2026 · Updated on September 2, 2026
Why your data is not safe on AWS, Azure or Google Cloud
«"Why can't you use AWS?" That's the question a prospect asked us last week. His reasoning was simple: AWS is reliable, scalable, and cheaper. Why complicate things?
Here is our answer.
1. The real problem is not technical, it is legal
When a Swiss SME entrusts its invoices, contracts, supplier data, or HR documents to an AI provider, it is entrusting them with sensitive data. Data protected by law. nLPD (new Federal Data Protection Act), which came into force on September 1, 2023.
The problem with AWS, Azure, or Google Cloud: your data passes through servers subject to American CLOUD Act. In practical terms, a US authority can demand access to your data, even if it is stored in Europe. Even if you are a small business in the canton of Vaud with 30 employees.
2. "But they have data centers in Switzerland now?"«
Yes, AWS, Azure, and Google Cloud have opened regions in Switzerland. But the physical location of the servers doesn't change the legal issue.
The CLOUD Act applies to any company incorporated under US law, regardless of where its servers are located. An Azure data center in Zurich remains subject to US law.
It's not where your data is located that matters—it's the legal entity that controls it. A server in Switzerland operated by an American company does not protect your data from the CLOUD Act.
3. What the nLPD says — and the sanctions
The new Swiss Data Protection Act (nLPD) imposes strict requirements regarding the transfer of personal data to countries that do not guarantee an adequate level of protection.
The United States is not on the list of countries offering adequate protection according to the Swiss Federal Council.
4. The CLOUD Act, in concrete terms
The Clarifying Lawful Overseas Use of Data Act (CLOUD Act), adopted in 2018, allows US authorities to compel any US-registered company to provide data stored on its servers, wherever they are in the world.
This means that if your AI provider uses AWS, Azure, or Google Cloud infrastructure, your billing data, contracts, and HR documents could theoretically be accessible to US authorities — without your knowledge.
Unlike the European GDPR, the CLOUD Act does not require notification to the data subject. Access can be completely opaque.
5. Copilot, ChatGPT, Gemini — same problem
It's not just a matter of cloud infrastructure. The most popular AI tools — Microsoft Copilot, OpenAI ChatGPT, Google Gemini — are all operated by US companies subject to the CLOUD Act.
Every prompt you send, every document you analyze with these tools, passes through servers controlled by entities governed by US law. Even if your instance is "dedicated" or "European".
6. The Swiss alternative exists
Providers such as Exoscale offer a 100% Swiss cloud infrastructure, operated by companies incorporated under Swiss law. This means:
→ Your data is hosted in Switzerland
→ The legal entity is Swiss (no CLOUD Act)
→ Native nLPD compliance
→ No cross-border data transfer
7. How to assess your exposure
Ask yourself these simple questions:
→ Is your AI provider a company governed by Swiss or European law?
→ Does the data pass through servers belonging to American companies?
→ Do you have a Data Processing Agreement (DPA) that complies with the nLPD?
→ Do you know where the data you send to your AI tools is stored?
If you cannot answer these questions with certainty, it is likely that your data is exposed under the CLOUD Act.
Data sovereignty is not a luxury—it's a legal obligation for any Swiss company handling personal data. And with the rise of AI in business, this issue is becoming critical.
Don't let ease of use mask a real legal risk. Choose partners who take the protection of your data as seriously as you do.
Also read: our approach to AI agents for Swiss companies, with data that remains in Switzerland.
Do you want to know if your AI tools comply with the nLPD? Let's talk about it.
Request an audit Discover our solutions