Data residency in Switzerland determines where your data sits. It offers no protection against the US CLOUD Act, because that law attaches to control over the data, not to its location. If the operator belongs to a US group, the obligation to hand over data applies regardless of where the servers stand. On 3 June 2026 the European Commission translated this distinction into a four-level assessment framework, the Cloud and AI Development Act. It is not yet law, but it shows precisely which evidence regulated companies will have to produce.
In this post
- What the CLOUD Act means for Swiss companies
- Why data residency answers only half of the sovereignty question
- The four CADA levels and where the line runs
- Why US providers structurally cannot reach the upper levels
- Whether Swiss providers can reach them
- Seven questions to put to your provider
- When Collabase fits as a Swiss alternative
What the CLOUD Act governs
The Clarifying Lawful Overseas Use of Data Act of 2018 obliges providers under US jurisdiction to hand over data in their possession, custody or control. What matters is the power of disposal. A European subsidiary remains covered as long as the parent group exercises control. Such orders usually carry a non-disclosure obligation that bars the provider from informing the customer.
For Swiss companies this creates a conflict within their own law. Anyone who assists a foreign official act on Swiss territory touches Article 271 of the Swiss Criminal Code; anyone who passes business secrets abroad touches Article 273. For banks, bank client confidentiality under Article 47 of the Banking Act applies on top; for healthcare institutions, professional secrecy under Article 321 of the Criminal Code. Supervised institutions additionally have to show that they uphold the rights of access, audit and instruction set out in the FINMA circular on outsourcing.
An individual case is assessed by a legal professional, not by a blog post. The structure, however, always stays the same: a provider under two legal orders has to choose between them when it comes to the crunch.
Is data residency in Switzerland enough?
Data residency answers where the data sits. Three questions that matter to supervisors remain open: who controls the operator? Who can access it administratively? How quickly can you get out again?
The large providers have responded. AWS made its European Sovereign Cloud generally available in January 2026 with a first region in Brandenburg, physically and logically separated from the remaining regions. Microsoft offers European sovereignty controls through the Sovereign Public Cloud, including oversight of remote administrative access; Google Cloud works with European partners such as S3NS and T-Systems.
These constructions solve real problems. They do not change ownership.
What the four CADA levels require
The Cloud and AI Development Act, formally COM(2026) 502, establishes four Union assurance levels. Public bodies assess the risk of a use case and then assign it to a level. The criteria are cumulative.
| Level | Core requirement | Evidence |
|---|---|---|
| Level 1 | Provider established in the Union, data including metadata and telemetry in the Union | Self-declaration with EU declaration of conformity |
| Level 2 | Additionally staff and support in the Union, usage data trains no third-country AI system, complete software bill of materials | Independent third-party audit |
| Level 3 | Additionally Union citizenship of staff, no third-country control except for recognised states | Independent third-party audit |
| Level 4 | No third-country control without exception, no effective third-country control over software development | Independent third-party audit |
Two things about this matter. Level 1 rests on a self-declaration by the provider; only from Level 2 upwards is there audited evidence behind it. And the widespread claim that CADA shuts American providers out is wrong: at Level 1 and Level 2 they remain admissible.
For collaboration platforms one detail of Level 2 is central. Data generated through usage must not train any AI system of a third-country actor and must not leave the Union. With that, the sovereignty question moves from data storage into the model pipeline.
Where the line runs for US providers
The decisive part sits in the audit annex. If the auditor finds that a provider is under third-country control, they require four additional pieces of evidence:
- a Commission decision on the third country in question
- proof that the provider is legally, technically and operationally unable to comply with an access request
- proof that the customer is informed about such a request, together with confirmation that it was refused
- an ongoing register of all such requests
For a provider under US jurisdiction this bundle cannot be met. The CLOUD Act demands compliance, not refusal. The non-disclosure obligation bars informing the customer. And a register of such requests contradicts that same obligation.
The requirement targets legal capability rather than technology. France has followed the same logic for years: SecNumCloud 3.2 requires immunity from extraterritorial laws and excludes US-owned operators regardless of where the servers stand.
The notion of control is drawn broadly here. What gets examined are all shareholders down to the beneficial owners from five percent upwards, veto rights, appointment of the decision-making bodies as well as commercial and financial dependencies. An extract from the commercial register does not suffice.
Can Swiss providers reach the upper levels?
In principle yes, but not automatically. Article 18 allows the Commission to recognise third countries as associated. Providers from those states may then be audited against Level 3. What is required includes an adequacy decision under the GDPR, no state access powers conflicting with EU law, and no power to disrupt the service or enforce sanctions.
For the United States this fails on the access and sanction powers. Switzerland holds an adequacy decision and plausibly meets the remaining criteria under the law as it stands today. A recognition, however, is not in place.
Independently of that, every level requires an establishment in the Union, and Level 3 additionally Union citizenship of staff. For Swiss customers in Switzerland, Swiss law therefore remains the benchmark. What CADA shows above all is where that benchmark is moving: away from the location of the data, towards control over the operator.
For the Swiss federal administration the same principle already applies. Directive W012 has obliged it since 1 January 2026 to assess and document digital sovereignty in new ICT projects, understood as the capacity to control and to act. It is not binding for your company, but it is usable as an assessment framework towards internal audit.
Seven questions to put to your provider
| # | Question |
|---|---|
| 1 | Who controls the operator up to the top level, and who can block strategic decisions? |
| 2 | Where is the staff with administrative access based, and through which paths do they connect? |
| 3 | How does the provider behave when a foreign disclosure request arrives, and may they inform you? |
| 4 | Which usage and telemetry data flow into AI features, and where do the models run? |
| 5 | Is there a complete software bill of materials with the origin of the components? |
| 6 | Is there a documented migration plan for the failure of a supplier? |
| 7 | Do all the answers also hold for add-on modules and extensions? |
Question 7 is the one most often overlooked. For the core application things are usually documented; for each extension they stay open individually.
When Collabase fits as a Swiss alternative
Collabase is a Swiss B2B collaboration platform. Docs covers knowledge work and documentation, Projects project and portfolio management, Registry the structured administration of assets and reference data. AI and Automation are part of the platform. Data and information processing takes place entirely in Switzerland, as a basic condition rather than a bookable option.
Measured against the seven questions: we are under Swiss control, which removes the conflict of norms. We run operations and support from Switzerland. The AI features are part of the same architecture, which is why question 4 does not lead through a chain of third parties. And because we concentrate the functional scope on the core rather than on hundreds of marketplace extensions, question 7 stays answerable.
Where the limits lie: anyone serving EU public sector clients assesses the Union levels separately, because they presuppose an establishment in the Union. And for software development with Git workflows, Collabase is not the fitting answer.
Frequently asked questions
Is CADA already applicable law?
No. It is a Commission proposal of 3 June 2026 in the ongoing legislative procedure. The regulation would become applicable one year after its entry into force. The strictest levels are politically contested and may still change.
Does a data centre in Switzerland protect against the CLOUD Act?
Only if the operator is also exclusively under Swiss control. The CLOUD Act attaches to the power of disposal over the data.
Does CADA shut American providers out of Europe?
No. At Level 1 and Level 2 they remain admissible, at Level 2 under considerable evidence obligations. Level 3 and Level 4 are closed to them.
Does CADA apply to private companies?
For now, impact assessments are voluntary for companies in the NIS2 sectors. The Commission can make them binding for sectors of high criticality through delegated acts. Those include energy, health and banking.
Does Directive W012 apply to us?
It is binding only for the central federal administration and for projects from 1 January 2026 onwards. As an assessment framework it is usable outside that scope too.
What to do next
- Take stock. Which services are in use, who operates them, who owns the operator, which extensions run alongside?
- Answer the seven questions. Whatever the provider cannot evidence belongs in the minutes as an open point.
- Bring contracts up to date. Do your contracts govern the procedure for foreign disclosure requests and the information of the customer?
- Classify the AI features. Which usage data flow into models, and where do those models run?
- Decide before the migration. Anyone facing a platform change anyway settles the sovereignty question beforehand. That includes everyone who has to move by 2029 because of the end of life of Atlassian Data Center. Corrections after the fact are the most expensive route.
If you want to check where your platform stands on these seven questions, or if a change of platform is coming anyway: talk to us. We will place your status quo and show you which steps are worth taking for your company.
Sources: Proposal for a Cloud and AI Development Act, COM(2026) 502 final of the European Commission, Directive W012 on digital sovereignty in the federal administration of the Swiss Federal Chancellery (German only).
Last reviewed: September 18, 2026

