The US CLOUD Act (Clarifying Lawful Overseas Use Of Data Act) obliges American companies to provide access to data stored on the internet, even if it is not stored in the USA. The GDPR protects the data of citizens of the EU and the European Economic Area and, in addition, data processed by European companies. Companies that breach the GDPR, for example by making data available to others, face drastic penalties of up to 20 million euros or 4% of global turnover. That creates a high potential for conflict between the CLOUD Act and the GDPR. According to the European Court of Justice, most US providers of cloud services may therefore no longer be used for processing personal data of EU citizens. In Switzerland too, processing personal data in the USA is generally not permitted. There are exceptions if the data is anonymised or encrypted. But risks remain here as well. The simplest and safest approach is to work with a European or domestic provider.
We at Vanillaplan have been committed to the security of our customers' data from the outset. Our data is located in an Exoscale data centre in Zurich and does not leave Switzerland. For the detailed white paper in English, why not visit the A1 Digital website:
https://www.a1.digitalblog/cloud-act-gdpr-die-sweizer-dsg-und-der-bank-act/




