Skip to content

Data sovereignty: who has access to your correspondence?

A sealed envelope is a simple promise: only those who are allowed to open it can read what’s inside. In digital communication, we first think of firewalls, encryption and access rights when we make this promise. But one question often remains unanswered: under which law is your business data stored – and who can access it? After all, digital communication is only as trustworthy as the infrastructure it runs on.

A man sits at a table in an open-plan office. He is working on his laptop.

Where your business documents really are

Contracts, quotes, personnel files, invoices: business correspondence today is conducted on digital platforms. This creates more efficient processes and customer-friendly services. But when choosing a tool, one question is rarely asked: where are these documents stored and processed, and which law applies? This creates a blind spot for CISOs, IT and compliance managers in a highly regulated area.

Why data sovereignty is more important than ever

Digital sovereignty describes the ability of an organisation or country to act in the digital space – from infrastructure to skills. Data sovereignty is the part of it that affects you in your day-to-day work: control over where your data is stored, which law applies and who can access it. Four developments make this topic urgent.

First, the geopolitical situation: ‘digital sovereignty’ has gone from being a technical term to an agenda item at board and government level. Second, the legal framework: US-based providers can be compelled to hand over data under the US CLOUD Act by a court order in criminal proceedings – even if the data is stored outside the US. However, many countries, including Switzerland, have similar access rights. In practice, cyberattacks by organised crime are a much more common threat scenario. Third, regulation: the revised Swiss Federal Act on Data Protection (FADP) and – depending on the situation – the GDPR set out specific requirements; depending on the industry, there are additional obligations, such as in the financial and healthcare sectors, official secrecy in public administration, or professional secrecy under Article 321 of the Swiss Criminal Code. Fourth, expectations: confidentiality has become a factor of trust and competition – with customers, partners and regulators.

The three dimensions of data sovereignty

Sovereignty is not a single feature, but the interplay of three levels:

  • Legal: which law applies, which jurisdiction is responsible, and what agreement is in place with the provider (e.g. a data processing agreement)?
  • Technical: where is the data stored, how is it encrypted, and who manages the keys?
  • Organisational: who has access, which sub-processors are involved, and is this documented in a traceable way?

Only when all three levels are in place is data sovereignty more than just a promise. If one falls away, the whole structure crumbles.

From principle to practice: how ePost protects your mail

How mail secrecy is transferred to the digital world – with encryption, verified senders and Swiss data storage:

‘Digital mail secrecy: how ePost protects your mail’.

What ISO 27001, ISAE 3000 and data protection law actually mean

Certificates and laws are not marketing labels, but verifiable assurances. ISO/IEC 27001:2022 certifies a management system for information security – meaning documented processes and controls that are audited externally, not a single technical feature. The ISAE 3000 audit attests to tamper-proof, legally compliant archiving. The revised FADP and the GDPR regulate how personal data is processed lawfully.

For decision-makers, this means: a logo in marketing does not replace proof. Ask for certificates, audit reports and information about oversight – and check that they are current and relevant.

Sovereignty does not mean ‘no cloud’, but ‘controlled cloud’

A common misconception: data sovereignty means giving up powerful cloud technology. The opposite is true. The question is not whether a cloud is used, but under what conditions.

ePost shows how this can be done. The platform uses modern cloud technology – the Google Cloud Platform in the Swiss region of Zurich – but under Swiss conditions: the content data is stored and processed exclusively in Switzerland and in accordance with Swiss law. It is encrypted during transmission and storage. The key point is the separation: key management is with ePost, not with the cloud provider. The cloud provider cannot access readable content due to the security model. Even ePost does not have free access; after delivery, a letter is only readable by the recipient. And remote access to the stored data by people outside Switzerland is technically and contractually excluded.

And what about the US CLOUD Act? Through organisational, technical and legal measures, access by US authorities is not possible; mail secrecy is guaranteed. Specifically, these measures include encryption, separate key management, the Swiss data location, and a defined procedure for official requests.

This protection is externally verified: the ePost platform is certified to ISO/IEC 27001:2022 and audited to ISAE 3000; for services under the Postal Ordinance, a data protection impact assessment by the Federal Data Protection and Information Commissioner (FDPIC) and an audit by PostCom also apply. The list of sub-processors is publicly available.

The Academy article ‘Where are your data stored? Swiss servers and data storage’ shows how this protection works technically. The article on compliant archiving explains what this means for data retention.

What this means for your procurement

You do not need to visit a data centre to assess sovereignty. Six criteria are enough to classify a provider – regardless of who they are:

Assessment criterion What you should look out for
Data location Where content data is stored and processed – not just where the provider is based
Applicable law Which law applies, and whether the provider is subject to foreign law with extraterritorial effect
Access to plain text Whether the cloud provider can see unencrypted content
Key sovereignty Who manages the keys and whether this is separate from cloud operations
Oversight and evidence Which certificates, audits and oversight relationships can be demonstrated
Sub-processors Whether the list is transparent and up to date

The clearer and more verifiable the answers, the more sovereign the solution.

Conclusion: sovereignty is a decision, not an accident

The question of who has access to your business data is not a technical detail, but a strategic decision between law, security and trust. Those who consciously choose data sovereignty and ask the right questions reduce risks – and strengthen the trust of customers and regulators. Sovereignty does not mean giving up modern technology, but using it within clearly defined legal, technical and organisational frameworks.

Sovereign storage: your business archive in Switzerland

What applies to your communication also applies to your storage. With ePost eArchiv, you store business documents securely and in Switzerland – in compliance with the AccO (Ordinance on the Keeping and Preservation of Account Books), encrypted and always available.

Subscribe to the blog

Sign up for our Swiss Post Digital Blog and you’ll receive regular updates on our latest blog articles, expert opinions and industry trends.