IT Advice

The CLOUD Act explained to a Geneva SME: what really changes

Ten minutes of reading. What the law allows, what it does not, and what you can decide this week. Guide published on 13 September 2026.

In one sentence

The CLOUD Act is a US law of March 2018 that lets US authorities compel a US company to hand over data it holds, wherever that data is stored. A server in Zurich rented from a US provider remains subject to it.

What the law allows

  • A US authority (federal police, courts) can, with a warrant or order, compel a provider subject to US law to deliver data, including data hosted outside the United States.
  • The provider may challenge the request before a US judge if it conflicts with the law of the country where the data sits. It may; it is not obliged to.
  • Switzerland has signed no bilateral executive agreement under the CLOUD Act. The United Kingdom and Australia have.

What the law does not allow

  • It does not give free, standing access to everyone's data: a procedure, a case and a warrant are needed.
  • It does not target Swiss companies specifically: it targets the US provider, and your data because it sits with them.
  • It does not make using Microsoft 365 or Google Workspace in Switzerland illegal. The question is not the legality of the tool, it is the promise you can make to your clients.

Why it matters to a Geneva accounting firm, practice or NGO

Three Swiss rules come into play, and none replaces the others:

  1. Professional secrecy (art. 321 of the Criminal Code for lawyers, doctors, notaries; art. 321 ff. for other professions): you are personally accountable for what leaves. A provider handing a file to a foreign authority releases you from nothing.
  2. The Data Protection Act (nLPD, 2023): transferring personal data abroad is allowed only to a country with adequate protection or with safeguards. Since 15 September 2024 the United States is recognised as adequate for companies certified under the Swiss-U.S. Data Privacy Framework. That recognition covers commercial transfer; it does not neutralise access by a US authority.
  3. Article 271 of the Criminal Code forbids performing acts for a foreign state on Swiss territory without authorisation. That is why a serious provider will challenge a US request aimed at data in Switzerland. But the provider decides whether to challenge, not you.

In practice: in June 2025, before a French Senate committee, an executive of Microsoft France acknowledged under oath that he could not guarantee that data hosted in Europe would never be handed to US authorities. The answer is honest, and it applies to Switzerland.

The real risk, without drama

The probability that a US authority requests the general ledger of an accounting firm in Carouge is low. The point is not the probability, it is the answer you can give when a client, an auditor, a donor or a professional body asks: "where is our data, and who can reach it?". With a US provider the honest answer is: "in Switzerland or Europe, but a US authority can reach it through legal process". With a Swiss provider without a US parent, the answer is: "in Switzerland, under Swiss law, and a foreign authority must go through Swiss mutual legal assistance".

"Our servers are in Zurich": why that is not enough

Microsoft, Google and Amazon offer Swiss regions. That helps latency and some contractual requirements; it does not change the law the provider answers to. The CLOUD Act attaches to the nationality of the company controlling the data, not to the building's address. The same goes for a Swiss subsidiary of a US group.

Three decisions an SME can take in a week

  1. Take the inventory: for each service (mail, files, calendars, video, line-of-business software, backups, website), note the provider, its country, the hosting location and the applicable law. Most directors discover two or three services they did not know about at this step.
  2. Sort by sensitivity: what falls under professional secrecy, health, beneficiary or payroll data first; the rest afterwards. Nobody migrates everything at once.
  3. Decide per block: stay with better settings (data residency, encryption, contract), or move to a Swiss or European provider outside the CLOUD Act. For mail and files, Infomaniak (Geneva) and Proton (Geneva) are the usual candidates; self-hosted Nextcloud when autonomy comes first. Migrating a 10 to 30 seat organisation usually takes three weeks, in waves, without losing a message.

What I will not say

I will not say a Swiss provider makes you "compliant": compliance depends on your contracts, your access and your practices, not on a logo. Nor will I say you must leave everything: I sometimes recommend staying, with better settings. The inventory decides, not ideology. And for any question of law, your lawyer remains the reference; this guide is not legal advice.

To go further: the IT Audit Express does exactly the inventory described above, in two hours, with a score and ten recommendations ranked by urgency. The Data sovereignty and migration service takes over when a migration is justified.

Frequently asked questions

Does the CLOUD Act apply to Microsoft 365 hosted in Switzerland?

Yes. The law targets the US provider, whatever the storage location. A Swiss region improves latency and some contract clauses; it does not change the applicable law.

Are Infomaniak and Proton really outside the CLOUD Act?

Both are Swiss-law companies based in Geneva, with no US parent. A foreign authority must go through Swiss mutual legal assistance to obtain data from them.

Does the Swiss-U.S. Data Privacy Framework solve the problem?

No. It makes the commercial transfer of personal data to certified US companies lawful under the nLPD. It does not limit the access of US authorities provided for by the CLOUD Act.

Next step

Two hours to know where you stand

The IT Audit Express reviews your services, your access and your backups, and leaves you a score and ten recommendations ranked by urgency. CHF 490, deducted from the first assignment that follows.

Book an IT Audit ExpressSee all prices