HomeBlog › Sovereignty

Technologies & IT Services · Montreux · Swiss Riviera

Digital sovereignty: where is your data really?

A breakdown, a question?

“Hosted in Switzerland” doesn’t tell the whole story. Two questions matter: where is the data stored, and which law governs the company that holds it. The answers are not always the same.

Published on 18 September 2026 · 6 min
  • Written without jargon
  • A question we are often asked
  • Updated when the tools change
Eramis
FREN

For an SME, digital sovereignty is no slogan: it is being able to know where your data is, who can access it, and under what rules. Most businesses do not know, and find out the day a client, an insurer or a principal asks the question.

Storage location and applicable law: two different things

A service can store your data in a data centre in Switzerland while being operated by a foreign company. In that case, the data is physically here, but the operator remains subject to the law of its country, including laws with extraterritorial reach that may, under certain conditions, oblige it to provide access to data it holds, wherever that data is located. Conversely, a Swiss hosting provider operating its own data centres in Switzerland is governed by Swiss law.

What the nFADP requires

The Federal Act on Data Protection does not prohibit the use of foreign services. It requires you to know where personal data goes, to provide a framework for disclosures abroad, and to take appropriate security measures. For sensitive data (health, legal files, clients’ financial data), the question of applicable law deserves careful examination. This is not legal advice.

Should everything be brought back?

No. The big collaboration suites are excellent tools, and for many businesses the right choice. The right question is not “Swiss or not Swiss”, but “which data, with what level of requirement”. You can perfectly well keep your e-mail where it is and put your backups and sensitive files with a Swiss hosting provider.

Concrete criteria for choosing

  • Who runs the service, and in which country that company is based
  • Where the data centres are, including those for backups
  • Who holds the encryption keys: you, or the provider
  • Which subcontractors are involved, and where
  • How to leave: getting your data back, in what format, and how quickly
  • What the contract says about access to data by authorities

Where to start

With the backups. They are the copy of everything you have, and the easiest thing to place in Switzerland, encrypted, with a key that only you hold. Then the inventory: for each service (email, files, accounting, business software), who runs it and where. For a small organisation, this is quick.

Our position

Eramis is independent of suppliers: we recommend what suits you, whatever the brand. The backups we manage are hosted in Switzerland, under Swiss law. For e-mail and files, we set up Microsoft 365 when it is the right choice, and a sovereign Swiss alternative when you prefer. We do not claim that everything is Swiss: this site itself uses service providers located in the European Union, and we say so in our privacy policy.

In short: ask where the data is and which law governs whoever holds it. Start with the backups. See Backup & Swiss cloud and Data security & nFADP.

Where are your backups?

Backup hosted in Switzerland, under Swiss law, encrypted with a key that you hold, and tested.

See the service