The US CLOUD Act (Clarifying Lawful Overseas Use Of Data Act) obliges American companies to provide access to data stored on the internet, even if it is not stored in the USA. The GDPR protects the data of citizens of the EU and the European Economic Area and, in addition, data processed by European companies. Companies that breach the GDPR, for example by making data available to others, face drastic penalties of up to 20 million euros or 4% of global turnover. That creates a high potential for conflict between the CLOUD Act and the GDPR. According to the European Court of Justice, most US providers of cloud services may therefore no longer be used for processing personal data of EU citizens. In Switzerland too, processing personal data in the USA is generally not permitted. There are exceptions if the data is anonymised or encrypted. But risks remain here as well. The simplest and safest approach is to work with a European or domestic provider.
We at Vanillaplan have been committed to the security of our customers' data from the outset. Our data is located in an Exoscale data centre in Zurich and does not leave Switzerland. For the detailed white paper in English, why not visit the A1 Digital website:
https://www.a1.digitalblog/cloud-act-gdpr-die-sweizer-dsg-und-der-bank-act/

The topic of data protection has gained more and more weight in recent years, both for private individuals and for companies. Politics too has made strengthening data protection its task, as shown among other things by the EU's General Data Protection Regulation (GDPR) but also by the revision of Switzerland's Data Protection Act. Last year «A1 Digital» therefore published a white paper on the contradictory rules of the GDPR and the American CLOUD Act. This January the paper was extended with a focus on Switzerland. «A1 Digital» is part of the Austrian Telekom Group and is the umbrella organisation of our Swiss cloud provider «Exoscale».



