Swiss public-sector data protection officers have issued a resolution urging government agencies to avoid using international software-as-a-service (SaaS) platforms, such as Microsoft 365, for sensitive data unless true end-to-end encryption is implemented. The resolution highlights that most SaaS solutions do not provide end-to-end encryption, leaving data accessible to providers and subject to foreign legal processes like the US CLOUD Act. This lack of control is seen as a significant risk to data sovereignty, as agencies cannot guarantee the confidentiality of particularly sensitive or legally protected information when using these services.
The Swiss stance reflects a broader European skepticism toward foreign-owned hyperscale cloud providers, with similar concerns raised in Germany, France, Denmark, and by the European Commission. Security analysts emphasize that true data sovereignty requires government control over encryption keys, not just data residency. The resolution also warns that SaaS providers can unilaterally change terms and conditions, further eroding security and privacy guarantees for public sector data.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
Swiss public-sector data protection officers represented by Privatim issued a resolution advising government agencies not to use international SaaS platforms such as Microsoft 365 for sensitive data unless they provide true end-to-end encryption with customer-exclusive key control. The guidance cites data sovereignty and exposure to laws such as the US CLOUD Act as key concerns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
cio.com
Open sourcego.theregister.com
Open sourcecio.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.