How Swiss Public Sector Organizations Benefit from MyWorkDrive

By Dan Gordon

Last Updated: September 15, 2026

In November 2025, Privatim, the Conference of Swiss Data Protection Commissioners, adopted a resolution with direct consequences for how public bodies can use cloud and SaaS platforms. Cantons are drafting their own information security laws for rollout through 2026, tenders are now testing these requirements directly, and the Privatim resolution discussed below gives data protection officers a specific, citable standard rather than a general principle. Together, these developments have turned a longstanding legal framework into an active procurement criterion.

The Privatim Resolution and Swiss Cloud Data Protection Rules

The resolution establishes that international SaaS solutions can only be used for particularly sensitive personal data or legally confidential data if that data is encrypted by the organization itself, with the cloud provider having no access to the encryption key. Privatim considers most current cloud deployments involving major international providers effectively non-compliant under this standard.

Official text · Privatim · 18 November 2025

«Die Nutzung internationaler SaaS-Lösungen für besonders schützenswerte oder einer gesetzlichen Geheimhaltungspflicht unterstehende Personendaten durch öffentliche Organe ist nur dann möglich, wenn die Daten vom verantwortlichen Organ selbst verschlüsselt werden und der Cloud-Anbieter keinen Zugang zum Schlüssel hat.»

EnglishPublic bodies may use international SaaS solutions for particularly sensitive personal data, or data subject to a statutory secrecy obligation, only if the responsible body encrypts the data itself and the cloud provider has no access to the key.

Privatim, Resolution zur Auslagerung von Datenbearbeitungen in die Cloud, adopted 18 November 2025, published 24 November 2025. The resolution names Microsoft 365 as its primary example of a deployment it considers impermissible in most cases.
The five grounds Privatim gives for its conclusion
#Ground (summarized from the German resolution)
1Most SaaS solutions still lack true end-to-end encryption that would prevent the provider from accessing plaintext data.
2Global providers offer too little transparency for Swiss authorities to verify contractual data protection and security obligations, including subcontractor chains, and providers can unilaterally change their terms.
3SaaS use brings a significant loss of control. A public body can only reduce the severity of potential rights violations by not releasing particularly sensitive data from the sphere it controls.
4For data under statutory secrecy obligations, there is considerable legal uncertainty about whether outsourcing to the cloud is permissible at all.
5US providers can be compelled under the 2018 CLOUD Act to hand over customer data to US authorities outside international mutual assistance rules, even when the data is stored in Swiss data centers.

Source: Privatim resolution (PDF, German)

The canton of Zurich moved first. Its data protection office has taken the position that foreign legal obligations make transferring personal data to a provider under US jurisdiction problematic the moment that data enters the provider's infrastructure, and it has extended this thinking to anything covered by professional secrecy, including medical records, tax data, social security information, and education records. Other cantons are expected to follow a similar line as their own procurement and information security rules catch up. The February 2026 market consultation for Swiss health data infrastructure, for example, already states that infrastructure components must have no technical or legal dependency on external jurisdictions.

Official text · Zürich Data Protection Commissioner · 2022

«Dieses Verfahren und dieser Zugriff auf Daten sind mit dem Datenschutzrecht und dem übergeordneten schweizerischen Recht nicht vereinbar. Es verstösst gegen den «ordre public» der Schweiz.»

«Vertragliche Absicherungen genügen nicht, da der Anbieter die Gesetze der USA und damit die Bestimmungen des CLOUD Act befolgen muss.»

EnglishThis procedure and this access to data are incompatible with data protection law and with higher-ranking Swiss law. It violates Switzerland's ordre public. Contractual safeguards are not sufficient, since the provider must comply with US law and therefore with the provisions of the CLOUD Act.

Datenschutzbeauftragte des Kantons Zürich, Tätigkeitsbericht 2022, "Risiken und Regeln". The same report states that data under special official secrecy or professional secrecy may only go to a US cloud provider if a technical measure, meaning encryption with the key held by the public body, prevents the provider from accessing it.
Procurement documents · BAG · February 2026

«Die gesamte SwissHDS-Infrastruktur muss ausschliesslich der Schweizer Rechtsordnung unterliegen.»

«Alle Infrastrukturkomponenten dürfen keine technische oder rechtliche Abhängigkeit von äusseren Jurisdiktionen (z. B. US Cloud Act) aufweisen.»

EnglishThe entire SwissHDS infrastructure must be subject exclusively to the Swiss legal order. No infrastructure component may have any technical or legal dependency on external jurisdictions (for example, the US CLOUD Act).

Bundesamt für Gesundheit (BAG), SwissHDS market consultation documents published on simap.ch, February 2026, as quoted by NZZ am Sonntag, 9 May 2026.

The Federal Office for Buildings and Logistics (BBL), which runs federal procurement, later characterized these documents as a preliminary market consultation rather than a WTO-rules tender, and stated that an outright exclusion of US firms would not be WTO-compliant in an eventual tender. The requirement as written nevertheless shows the direction of federal thinking on health data.

revFADP, nLPD, and the US CLOUD Act Risk for Swiss Public Bodies

The revised Federal Act on Data Protection, known as revFADP or nLPD, has been in force since September 2023 and forms the baseline data protection law for any organization processing personal data in Switzerland. It sits alongside cantonal data protection acts, which each canton maintains on top of the federal law, and alongside the federal Informationssicherheitsgesetz (ISG), which already applies to cantons when they touch federal data or systems and which several cantons are actively extending into their own cantonal versions right now.

Swiss legal framework for public sector cloud and file access, status as of September 2026
InstrumentLevelStatusKey dates
Revised Federal Act on Data Protection (revFADP / nLPD / DSG), with the DSV and VDSZ ordinancesFederalIn force1 September 2023
Informationssicherheitsgesetz (ISG) and its four implementing ordinancesFederalIn force1 January 2024 (Federal Council decision of 8 November 2023); revision consultation planned for mid-2027
Privatim resolution on outsourcing data processing to the cloudAll cantonal data protection authoritiesAdoptedAdopted 18 November 2025; published 24 November 2025
Canton of Bern: revised Kantonales Datenschutzgesetz (KDSG) and Gesetz über Informations- und Cybersicherheit (ICSG)CantonalKDSG in force; ICSG adoptedKDSG in force 1 September 2026; ICSG adopted 12 June 2025, in force 1 November 2026
Canton of Aargau: Gesetz über die Informationssicherheit (InfoSiG)CantonalSecond readingFirst reading passed 128 to 0 on 29 April 2025; second reading January 2026; targeted entry into force 1 July 2026
Canton of Zug: Informationssicherheitsgesetz (ISG) and Informationssicherheitsverordnung (ISV)CantonalIn consultationDraft approved in first reading 7 July 2026; consultation open until 9 November 2026
Canton of Solothurn: revision of the Informations- und Datenschutzgesetz (InfoDG)CantonalConsultation closedConsultation ran 17 November 2025 to 17 February 2026

Sources: kmu.admin.ch, admin.ch and bacs.admin.ch (ISG), privatim.ch, kaio.fin.be.ch, ag.ch, zg.ch, so.ch. The federal cybersecurity office (BACS) confirms the ISG applies to cantons when they access classified federal information or federal IT resources.

The legal concern underneath all of this is the US CLOUD Act, which obliges providers under US jurisdiction to hand over data on request, regardless of where the servers physically sit. That means a Swiss data center address alone doesn't resolve the exposure if the operator can be compelled by a foreign authority. For a canton, hospital, or municipality bound by professional secrecy, that's not an acceptable risk to carry. This is a live legislative moment across Switzerland, not a settled one, and it's part of why interest in alternatives has picked up so quickly.

Statute · 18 U.S.C. § 2713 · CLOUD Act 2018

"A provider of electronic communication service or remote computing service shall comply with the obligations of this chapter to preserve, backup, or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within such provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States."

18 U.S.C. § 2713, added by the CLOUD Act (Pub. L. 115-141, div. V, 23 March 2018). Full text at uscode.house.gov. The obligation attaches to data within the provider's possession, custody, or control; the statute then makes the physical location of that data irrelevant.

Secure File Access Without Data Migration: Where MyWorkDrive Fits

MyWorkDrive doesn't ask an organization to move its files anywhere. It's a secure file access gateway that connects to file servers, SharePoint, NAS, and other storage an organization already runs, without migrating or duplicating data into a third-party store. For a Swiss public body trying to satisfy Privatim's guidance, that distinction matters: there's no copy of sensitive data sitting with an outside provider to encrypt around, because the data never leaves the organization's own infrastructure in the first place. Access, authentication, and audit logging happen at the gateway, while control over the underlying files and their location stays exactly where it already was.

This also addresses a question Swiss buyers reasonably ask upfront: MyWorkDrive is a US-headquartered company, so why doesn't that reintroduce the CLOUD Act exposure discussed above. The answer is architectural rather than contractual. MyWorkDrive doesn't host, store, or hold a copy of customer files anywhere, in the US or otherwise. The files stay on the customer's own servers, on premises or in infrastructure the customer controls, and MyWorkDrive's role is limited to providing the access gateway. There's no customer data sitting on MyWorkDrive-operated infrastructure for a foreign authority to compel disclosure of, which is a different position than a SaaS or cloud storage vendor is in. That makes the vendor's country of incorporation far less consequential here than it would be for a platform that actually stores the data itself, and it's part of why the fit works even though MyWorkDrive isn't a Swiss or European product.

Cantonal and Municipal Administration File Access Use Case

A canton's IT department can give staff secure remote access to case files stored on an internal Windows file server, without opening that server directly to the internet and without migrating years of records into a cloud platform that may fall under foreign jurisdiction. Access stays tied to existing Active Directory accounts, and every file access is logged. See how this applies to government agencies more broadly.

Healthcare Data Access Under Swiss Confidentiality and Data Protection Law

Hospitals and clinics operate under confidentiality obligations that extend to their IT vendors and auxiliary staff. A hospital can let clinicians and administrative staff reach patient-related files from outside the building while keeping those files on servers the hospital itself controls, addressing both the professional secrecy obligation and the data security requirements tied to health data under Swiss data protection law.

Official text · DigiSanté · Federal administration

«Gesundheitsdaten bleiben bei den verantwortlichen Organisationen und werden als standardisierte Data Products über eine geteilte Service-Infrastruktur sicher, kontrolliert und organisationsübergreifend nutzbar gemacht.»

EnglishHealth data remain with the responsible organizations and are made securely, controllably, and cross-organizationally usable as standardized data products through a shared service infrastructure.

DigiSanté program, Swiss federal administration, Swiss Health Data Space (SwissHDS) project page. The federal government's own flagship health data project is built on the premise that data stays with the organization that holds it.

Non-Profit File Access Without a Cloud Migration Project

Smaller organizations often run lean IT teams and can't take on a multi-year migration project just to give a distributed staff or volunteer base access to shared files. MyWorkDrive lets them connect existing storage and grant access in hours rather than months, while keeping donor and beneficiary data on infrastructure they already manage.

Multi-Site and Federated Organization File Access

Cantons with multiple departments, healthcare networks with several facilities, and non-profits with regional chapters often have file storage spread across different servers and locations. A gateway approach lets each site keep its own storage and administrative boundaries while still giving authorized staff a single, controlled way to reach the files they need.

Frequently Asked Questions

What is the Privatim resolution and why does it affect cloud storage in Switzerland?

Privatim is the Conference of Swiss Data Protection Commissioners. Its November 2025 resolution states that public bodies can only use international SaaS platforms for sensitive or legally confidential data if the organization itself controls the encryption keys and the provider cannot access the data. Most current deployments of major international cloud platforms do not meet that bar.

Does storing data in a Swiss data center satisfy Swiss data protection requirements?

Not on its own. If the provider operating that data center is subject to US jurisdiction, the US CLOUD Act can still require it to hand over data on request regardless of where the servers are physically located. Swiss authorities increasingly look at who controls the infrastructure and under what law, not just where the hardware sits.

What is revFADP or nLPD?

revFADP, also referred to as nLPD, is the revised Federal Act on Data Protection, in force in Switzerland since September 2023. It sets the baseline requirements for processing personal data and applies alongside cantonal data protection acts and the federal Informationssicherheitsgesetz.

How does MyWorkDrive help Swiss government and public-sector organizations meet these requirements?

MyWorkDrive is a secure file access gateway rather than a storage platform. It connects to file servers, SharePoint, NAS, and similar storage that an organization already operates, without migrating or copying data into a third-party store. Since the data never leaves the organization's own infrastructure, there is no external copy of sensitive data for a third-party provider to hold or potentially be compelled to disclose.

Is MyWorkDrive suitable for smaller organizations like non-profits?

Yes. Because it connects to existing storage rather than requiring a migration, organizations with limited IT resources can set up secure file access in hours rather than undertaking a lengthy migration project.

MyWorkDrive is a US company. Does that create the same CLOUD Act risk as a US cloud provider?

No, because the underlying exposure is about where data is stored and who holds it, not where the vendor is incorporated. MyWorkDrive doesn't host or store customer files at all. Files remain on the customer's own servers, and MyWorkDrive provides the gateway that controls access to them. Since there's no customer data sitting on MyWorkDrive's infrastructure, there's no data for a foreign authority to compel MyWorkDrive to hand over. That's a structurally different position from a SaaS or cloud storage vendor, and it's why the fit holds even though MyWorkDrive isn't a Swiss or EU-based product.

Primary sources cited

  • Privatim, Resolution zur Auslagerung von Datenbearbeitungen in die Cloud (18 Nov 2025): privatim.ch (PDF)
  • Privatim press release (24 Nov 2025): privatim.ch
  • Datenschutzbeauftragte des Kantons Zürich, Tätigkeitsbericht 2022, Risiken und Regeln: datenschutz.ch
  • Kanton Zürich, Leitfaden Microsoft 365 in Gemeinden (June 2024): zh.ch
  • revFADP entry into force: kmu.admin.ch
  • ISG entry into force, Federal Council press release (8 Nov 2023): admin.ch
  • ISG revision announcement (6 May 2026): admin.ch
  • 18 U.S.C. § 2713: uscode.house.gov
  • SwissHDS project page, DigiSanté: digisante.admin.ch
  • NZZ am Sonntag on SwissHDS market consultation (9 May 2026): nzz.ch
  • Kanton Bern ICSG / KDSG: kaio.fin.be.ch
  • Kanton Zug ISG consultation: zg.ch


Start a free trialBook a demoView pricing


Dan Gordon

About Dan Gordon

Daniel, Founder of MyWorkDrive.com, has worked in various technology management roles serving enterprises, government and education in the San Francisco bay area since 1992. Daniel is certified in Microsoft Technologies and writes about information technology, security and strategy and has been awarded US Patent #9985930 in Remote Access Networking.