By Dan Gordon
Last Updated: September 15, 2026
/* Tables */ .mwd-swiss26-table-wrap.mwd-swiss26-table-wrap.mwd-swiss26-table-wrap { margin: 28px 0 !important; padding: 0 !important; overflow-x: auto !important; border: 1px solid #D9E0E8 !important; border-radius: 6px !important; background: #FFFFFF !important; box-shadow: none !important; } .mwd-swiss26-table-wrap .mwd-swiss26-table { width: 100%; margin: 0; padding: 0; border: 0; border-collapse: collapse; border-spacing: 0; table-layout: auto; font-family: inherit; font-size: 16px; line-height: 1.55; color: #1F2937; background: transparent; box-shadow: none; } .mwd-swiss26-table .mwd-swiss26-caption { caption-side: top; display: table-caption; text-align: left; margin: 0; padding: 12px 16px; font-family: inherit; font-size: 13.5px; font-weight: 600; font-style: normal; letter-spacing: 0.04em; text-transform: uppercase; color: #0F2A4A; background: #F4F7FA; border: 0; border-bottom: 1px solid #D9E0E8; } .mwd-swiss26-table .mwd-swiss26-tr { background: transparent; border: 0; } .mwd-swiss26-table .mwd-swiss26-th { text-align: left; vertical-align: middle; margin: 0; padding: 12px 16px; border: 0; background: #0F2A4A; color: #FFFFFF; font-family: inherit; font-size: 15px; font-weight: 600; font-style: normal; text-transform: none; letter-spacing: normal; line-height: 1.5; } .mwd-swiss26-table .mwd-swiss26-td { text-align: left; vertical-align: top; margin: 0; padding: 12px 16px; border: 0; border-top: 1px solid #E5EAF0; background: #FFFFFF; color: #1F2937; font-family: inherit; font-size: 16px; font-weight: 400; font-style: normal; line-height: 1.5; } .mwd-swiss26-table .mwd-swiss26-tr:nth-child(even) .mwd-swiss26-td { background: #FAFBFC; } .mwd-swiss26-table .mwd-swiss26-td.mwd-swiss26-num, .mwd-swiss26-table .mwd-swiss26-th.mwd-swiss26-num { width: 44px; text-align: center; font-weight: 700; } .mwd-swiss26-table .mwd-swiss26-td.mwd-swiss26-num { color: #1D6FD1; } .mwd-swiss26-table .mwd-swiss26-td.mwd-swiss26-status { white-space: nowrap; font-weight: 600; color: #0F7B4D; } .mwd-swiss26-table .mwd-swiss26-td.mwd-swiss26-pending { white-space: nowrap; font-weight: 600; color: #1D6FD1; } .mwd-swiss26-source.mwd-swiss26-source.mwd-swiss26-source { margin: 8px 0 0 !important; padding: 0 !important; font-family: inherit !important; font-size: 14px !important; font-style: normal !important; line-height: 1.5 !important; color: #5B6B7C !important; background: transparent !important; } .mwd-swiss26-source .mwd-swiss26-link { color: #1D6FD1; text-decoration: none; border-bottom: 1px solid #C7DAF3; background: transparent; box-shadow: none; }
/* Quote blocks (div-based, so theme blockquote rules never apply) */ .mwd-swiss26-quote.mwd-swiss26-quote.mwd-swiss26-quote { display: block !important; position: relative !important; margin: 36px 0 !important; padding: 28px 34px 24px 36px !important; background: #FFFFFF !important; border: 1px solid #E3E9F0 !important; border-left: 6px solid #1D6FD1 !important; border-radius: 10px !important; box-shadow: 0 8px 28px rgba(15, 42, 74, 0.07) !important; quotes: none !important; font-family: inherit !important; font-style: normal !important; overflow: hidden !important; } .mwd-swiss26-quote::after { content: none; display: none; } .mwd-swiss26-quote.mwd-swiss26-quote.mwd-swiss26-quote.mwd-swiss26-quote--statute { border-left-color: #0F2A4A !important; } .mwd-swiss26-quote.mwd-swiss26-quote.mwd-swiss26-quote.mwd-swiss26-quote--federal { border-left-color: #0F7B4D !important; } .mwd-swiss26-quote .mwd-swiss26-quote-eyebrow { display: block; margin: 0 0 16px; padding: 0; font-family: inherit; font-size: 13px; font-weight: 700; font-style: normal; letter-spacing: 0.14em; text-transform: uppercase; color: #1D6FD1; background: transparent; } .mwd-swiss26-quote.mwd-swiss26-quote--statute .mwd-swiss26-quote-eyebrow { color: #0F2A4A; } .mwd-swiss26-quote.mwd-swiss26-quote--federal .mwd-swiss26-quote-eyebrow { color: #0F7B4D; } .mwd-swiss26-quote .mwd-swiss26-quote-text { position: relative; margin: 0; padding: 0; font-family: inherit; font-size: 20px; font-weight: 500; font-style: normal; line-height: 1.6; color: #0F2A4A; background: transparent; text-indent: 0; letter-spacing: -0.005em; } .mwd-swiss26-quote .mwd-swiss26-quote-text + .mwd-swiss26-quote-text { margin-top: 14px; } .mwd-swiss26-quote .mwd-swiss26-quote-trans { margin: 20px 0 0; padding: 18px 0 0; border: 0; border-top: 1px solid #E9EEF4; font-family: inherit; font-size: 16.5px; font-weight: 400; font-style: normal; line-height: 1.65; color: #4B5A6B; background: transparent; text-indent: 0; } .mwd-swiss26-quote .mwd-swiss26-quote-translabel { display: inline-block; margin: 0 10px 0 0; padding: 2px 8px; border-radius: 4px; background: #F1F5F9; font-family: inherit; font-size: 12px; font-weight: 700; font-style: normal; letter-spacing: 0.1em; text-transform: uppercase; color: #5B6B7C; vertical-align: 2px; } .mwd-swiss26-quote .mwd-swiss26-quote-cite { display: block; margin: 18px 0 0; padding: 0; font-family: inherit; font-size: 14.5px; font-weight: 400; font-style: normal; line-height: 1.6; color: #6B7A8A; background: transparent; text-transform: none; letter-spacing: normal; } .mwd-swiss26-quote .mwd-swiss26-quote-cite::before { content: none; } .mwd-swiss26-quote .mwd-swiss26-quote-src { font-weight: 700; color: #0F2A4A; } .mwd-swiss26-quote .mwd-swiss26-quote-note { margin: 18px -36px -26px -40px; padding: 14px 36px 14px 40px; border: 0; border-top: 1px solid #E9EEF4; font-family: inherit; font-size: 14.5px; font-weight: 400; font-style: normal; line-height: 1.6; color: #5B6B7C; background: #F8FAFC; text-indent: 0; } .mwd-swiss26-quote .mwd-swiss26-link { color: #1D6FD1; text-decoration: none; border-bottom: 1px solid #C7DAF3; background: transparent; box-shadow: none; font-weight: inherit; } .mwd-swiss26-quote .mwd-swiss26-link:hover { border-bottom-color: #1D6FD1; } @media (max-width: 640px) { .mwd-swiss26-quote.mwd-swiss26-quote.mwd-swiss26-quote { padding: 24px 22px 20px 24px !important; } .mwd-swiss26-quote .mwd-swiss26-quote-text { font-size: 18px; } .mwd-swiss26-quote .mwd-swiss26-quote-note { margin: 16px -22px -20px -24px; padding: 12px 22px 12px 24px; } }
/* Sources box */ .mwd-swiss26-sources.mwd-swiss26-sources.mwd-swiss26-sources { margin: 32px 0 0 !important; padding: 18px 22px !important; border: 1px solid #D9E0E8 !important; border-radius: 6px !important; background: #FFFFFF !important; box-shadow: none !important; } .mwd-swiss26-sources .mwd-swiss26-sources-title { margin: 0 0 10px; padding: 0; font-family: inherit; font-size: 13px; font-weight: 600; font-style: normal; letter-spacing: 0.02em; text-transform: uppercase; color: #0F2A4A; background: transparent; } .mwd-swiss26-sources .mwd-swiss26-sources-list { margin: 0; padding: 0 0 0 18px; list-style: disc outside; background: transparent; } .mwd-swiss26-sources .mwd-swiss26-sources-item { margin: 0; padding: 0; font-family: inherit; font-size: 15px; font-weight: 400; font-style: normal; line-height: 1.7; color: #374151; background: transparent; } .mwd-swiss26-sources .mwd-swiss26-sources-item::before { content: none; } .mwd-swiss26-sources .mwd-swiss26-link { color: #1D6FD1; text-decoration: none; border-bottom: 1px solid #C7DAF3; background: transparent; box-shadow: none; }
In November 2025, Privatim, the Conference of Swiss Data Protection Commissioners, adopted a resolution with direct consequences for how public bodies can use cloud and SaaS platforms. Cantons are drafting their own information security laws for rollout through 2026, tenders are now testing these requirements directly, and the Privatim resolution discussed below gives data protection officers a specific, citable standard rather than a general principle. Together, these developments have turned a longstanding legal framework into an active procurement criterion.
The Privatim Resolution and Swiss Cloud Data Protection Rules
The resolution establishes that international SaaS solutions can only be used for particularly sensitive personal data or legally confidential data if that data is encrypted by the organization itself, with the cloud provider having no access to the encryption key. Privatim considers most current cloud deployments involving major international providers effectively non-compliant under this standard.
| # | Ground (summarized from the German resolution) |
|---|---|
| 1 | Most SaaS solutions still lack true end-to-end encryption that would prevent the provider from accessing plaintext data. |
| 2 | Global providers offer too little transparency for Swiss authorities to verify contractual data protection and security obligations, including subcontractor chains, and providers can unilaterally change their terms. |
| 3 | SaaS use brings a significant loss of control. A public body can only reduce the severity of potential rights violations by not releasing particularly sensitive data from the sphere it controls. |
| 4 | For data under statutory secrecy obligations, there is considerable legal uncertainty about whether outsourcing to the cloud is permissible at all. |
| 5 | US providers can be compelled under the 2018 CLOUD Act to hand over customer data to US authorities outside international mutual assistance rules, even when the data is stored in Swiss data centers. |
Source: Privatim resolution (PDF, German)
The canton of Zurich moved first. Its data protection office has taken the position that foreign legal obligations make transferring personal data to a provider under US jurisdiction problematic the moment that data enters the provider's infrastructure, and it has extended this thinking to anything covered by professional secrecy, including medical records, tax data, social security information, and education records. Other cantons are expected to follow a similar line as their own procurement and information security rules catch up. The February 2026 market consultation for Swiss health data infrastructure, for example, already states that infrastructure components must have no technical or legal dependency on external jurisdictions.
revFADP, nLPD, and the US CLOUD Act Risk for Swiss Public Bodies
The revised Federal Act on Data Protection, known as revFADP or nLPD, has been in force since September 2023 and forms the baseline data protection law for any organization processing personal data in Switzerland. It sits alongside cantonal data protection acts, which each canton maintains on top of the federal law, and alongside the federal Informationssicherheitsgesetz (ISG), which already applies to cantons when they touch federal data or systems and which several cantons are actively extending into their own cantonal versions right now.
| Instrument | Level | Status | Key dates |
|---|---|---|---|
| Revised Federal Act on Data Protection (revFADP / nLPD / DSG), with the DSV and VDSZ ordinances | Federal | In force | 1 September 2023 |
| Informationssicherheitsgesetz (ISG) and its four implementing ordinances | Federal | In force | 1 January 2024 (Federal Council decision of 8 November 2023); revision consultation planned for mid-2027 |
| Privatim resolution on outsourcing data processing to the cloud | All cantonal data protection authorities | Adopted | Adopted 18 November 2025; published 24 November 2025 |
| Canton of Bern: revised Kantonales Datenschutzgesetz (KDSG) and Gesetz über Informations- und Cybersicherheit (ICSG) | Cantonal | KDSG in force; ICSG adopted | KDSG in force 1 September 2026; ICSG adopted 12 June 2025, in force 1 November 2026 |
| Canton of Aargau: Gesetz über die Informationssicherheit (InfoSiG) | Cantonal | Second reading | First reading passed 128 to 0 on 29 April 2025; second reading January 2026; targeted entry into force 1 July 2026 |
| Canton of Zug: Informationssicherheitsgesetz (ISG) and Informationssicherheitsverordnung (ISV) | Cantonal | In consultation | Draft approved in first reading 7 July 2026; consultation open until 9 November 2026 |
| Canton of Solothurn: revision of the Informations- und Datenschutzgesetz (InfoDG) | Cantonal | Consultation closed | Consultation ran 17 November 2025 to 17 February 2026 |
Sources: kmu.admin.ch, admin.ch and bacs.admin.ch (ISG), privatim.ch, kaio.fin.be.ch, ag.ch, zg.ch, so.ch. The federal cybersecurity office (BACS) confirms the ISG applies to cantons when they access classified federal information or federal IT resources.
The legal concern underneath all of this is the US CLOUD Act, which obliges providers under US jurisdiction to hand over data on request, regardless of where the servers physically sit. That means a Swiss data center address alone doesn't resolve the exposure if the operator can be compelled by a foreign authority. For a canton, hospital, or municipality bound by professional secrecy, that's not an acceptable risk to carry. This is a live legislative moment across Switzerland, not a settled one, and it's part of why interest in alternatives has picked up so quickly.
Secure File Access Without Data Migration: Where MyWorkDrive Fits
MyWorkDrive doesn't ask an organization to move its files anywhere. It's a secure file access gateway that connects to file servers, SharePoint, NAS, and other storage an organization already runs, without migrating or duplicating data into a third-party store. For a Swiss public body trying to satisfy Privatim's guidance, that distinction matters: there's no copy of sensitive data sitting with an outside provider to encrypt around, because the data never leaves the organization's own infrastructure in the first place. Access, authentication, and audit logging happen at the gateway, while control over the underlying files and their location stays exactly where it already was.
This also addresses a question Swiss buyers reasonably ask upfront: MyWorkDrive is a US-headquartered company, so why doesn't that reintroduce the CLOUD Act exposure discussed above. The answer is architectural rather than contractual. MyWorkDrive doesn't host, store, or hold a copy of customer files anywhere, in the US or otherwise. The files stay on the customer's own servers, on premises or in infrastructure the customer controls, and MyWorkDrive's role is limited to providing the access gateway. There's no customer data sitting on MyWorkDrive-operated infrastructure for a foreign authority to compel disclosure of, which is a different position than a SaaS or cloud storage vendor is in. That makes the vendor's country of incorporation far less consequential here than it would be for a platform that actually stores the data itself, and it's part of why the fit works even though MyWorkDrive isn't a Swiss or European product.
Cantonal and Municipal Administration File Access Use Case
A canton's IT department can give staff secure remote access to case files stored on an internal Windows file server, without opening that server directly to the internet and without migrating years of records into a cloud platform that may fall under foreign jurisdiction. Access stays tied to existing Active Directory accounts, and every file access is logged. See how this applies to government agencies more broadly.
Healthcare Data Access Under Swiss Confidentiality and Data Protection Law
Hospitals and clinics operate under confidentiality obligations that extend to their IT vendors and auxiliary staff. A hospital can let clinicians and administrative staff reach patient-related files from outside the building while keeping those files on servers the hospital itself controls, addressing both the professional secrecy obligation and the data security requirements tied to health data under Swiss data protection law.
Non-Profit File Access Without a Cloud Migration Project
Smaller organizations often run lean IT teams and can't take on a multi-year migration project just to give a distributed staff or volunteer base access to shared files. MyWorkDrive lets them connect existing storage and grant access in hours rather than months, while keeping donor and beneficiary data on infrastructure they already manage.
Multi-Site and Federated Organization File Access
Cantons with multiple departments, healthcare networks with several facilities, and non-profits with regional chapters often have file storage spread across different servers and locations. A gateway approach lets each site keep its own storage and administrative boundaries while still giving authorized staff a single, controlled way to reach the files they need.
Frequently Asked Questions
What is the Privatim resolution and why does it affect cloud storage in Switzerland?
Privatim is the Conference of Swiss Data Protection Commissioners. Its November 2025 resolution states that public bodies can only use international SaaS platforms for sensitive or legally confidential data if the organization itself controls the encryption keys and the provider cannot access the data. Most current deployments of major international cloud platforms do not meet that bar.
Does storing data in a Swiss data center satisfy Swiss data protection requirements?
Not on its own. If the provider operating that data center is subject to US jurisdiction, the US CLOUD Act can still require it to hand over data on request regardless of where the servers are physically located. Swiss authorities increasingly look at who controls the infrastructure and under what law, not just where the hardware sits.
What is revFADP or nLPD?
revFADP, also referred to as nLPD, is the revised Federal Act on Data Protection, in force in Switzerland since September 2023. It sets the baseline requirements for processing personal data and applies alongside cantonal data protection acts and the federal Informationssicherheitsgesetz.
How does MyWorkDrive help Swiss government and public-sector organizations meet these requirements?
MyWorkDrive is a secure file access gateway rather than a storage platform. It connects to file servers, SharePoint, NAS, and similar storage that an organization already operates, without migrating or copying data into a third-party store. Since the data never leaves the organization's own infrastructure, there is no external copy of sensitive data for a third-party provider to hold or potentially be compelled to disclose.
Is MyWorkDrive suitable for smaller organizations like non-profits?
Yes. Because it connects to existing storage rather than requiring a migration, organizations with limited IT resources can set up secure file access in hours rather than undertaking a lengthy migration project.
MyWorkDrive is a US company. Does that create the same CLOUD Act risk as a US cloud provider?
No, because the underlying exposure is about where data is stored and who holds it, not where the vendor is incorporated. MyWorkDrive doesn't host or store customer files at all. Files remain on the customer's own servers, and MyWorkDrive provides the gateway that controls access to them. Since there's no customer data sitting on MyWorkDrive's infrastructure, there's no data for a foreign authority to compel MyWorkDrive to hand over. That's a structurally different position from a SaaS or cloud storage vendor, and it's why the fit holds even though MyWorkDrive isn't a Swiss or EU-based product.
Primary sources cited
- Privatim, Resolution zur Auslagerung von Datenbearbeitungen in die Cloud (18 Nov 2025): privatim.ch (PDF)
- Privatim press release (24 Nov 2025): privatim.ch
- Datenschutzbeauftragte des Kantons Zürich, Tätigkeitsbericht 2022, Risiken und Regeln: datenschutz.ch
- Kanton Zürich, Leitfaden Microsoft 365 in Gemeinden (June 2024): zh.ch
- revFADP entry into force: kmu.admin.ch
- ISG entry into force, Federal Council press release (8 Nov 2023): admin.ch
- ISG revision announcement (6 May 2026): admin.ch
- 18 U.S.C. § 2713: uscode.house.gov
- SwissHDS project page, DigiSanté: digisante.admin.ch
- NZZ am Sonntag on SwissHDS market consultation (9 May 2026): nzz.ch
- Kanton Bern ICSG / KDSG: kaio.fin.be.ch
- Kanton Zug ISG consultation: zg.ch
Start a free trialBook a demoView pricing
Daniel, Founder of MyWorkDrive.com, has worked in various technology management roles serving enterprises, government and education in the San Francisco bay area since 1992. Daniel is certified in Microsoft Technologies and writes about information technology, security and strategy and has been awarded US Patent #9985930 in Remote Access Networking.