Microsoft 365
Microsoft and Digital Sovereignty – Why the Debate Is Justified Yet Often Misses the Point
The debate around digital sovereignty has good reasons. But what does the US CLOUD Act actually say, how rarely does it apply in practice – and why won't Microsoft simply bow to the US government? A level-headed take for SMEs.
Introduction
Few topics preoccupy the European and Swiss IT world right now as much as digital sovereignty. Public authorities, industry associations and a growing number of companies are asking whether it is wise to entrust their data and their operations to a US corporation like Microsoft. The debate has a curious lopsidedness to it: on one side stand those who view every file held by Microsoft, Google or Amazon as already handed over to Washington. On the other stand those who dismiss the whole thing as scaremongering. Both camps are wrong.
In this article I attempt a level-headed take. I show why the discussion around digital sovereignty is justified, what the much-cited US CLOUD Act actually says – and how rarely it applies in practice. And I explain why Microsoft won't simply bow to the US government the way the debate so often assumes. The aim is neither an acquittal nor a conviction, but a foundation on which an SME can make a sensible decision.
What digital sovereignty is really about
Digital sovereignty is often reduced to the question of which country the server sits in. That falls short. Sovereignty means the ability to decide for yourself over your own data, systems and processes – even when the political or economic conditions change. It spans three levels: data control (who can access my data, and under whose law?), operational control (will my operations remain available even if the geopolitical climate deteriorates?) and technological independence (can I switch providers without starting from scratch?).
The reason the topic is so present right now lies less in a specific incident than in a changed climate of trust. The geopolitical situation has become more volatile, and many decision-makers are asking a question they rarely used to ask: what actually happens to my cloud if the relationship between Switzerland, the EU and the US deteriorates? That question is legitimate – and it leads almost inevitably to the CLOUD Act.
The CLOUD Act – what it actually says
The Clarifying Lawful Overseas Use of Data Act, or CLOUD Act for short, was passed in the US in 2018. Its core point can be summed up in a single sentence: a US company must grant American authorities access, upon a court order, to data it controls – regardless of where in the world that data is physically stored. It is precisely this extraterritorial character that lies at the heart of the concern: even data that Microsoft stores in a data centre in Zurich or Frankfurt falls, in principle, under this law, because the parent company is based in the US.
What matters just as much, though, is what the CLOUD Act is not. It is not a blank cheque for free access to data. Access requires a court order or a search warrant, it is tied to specific, usually serious offences – such as terrorism or organised cybercrime – and it is subject to procedural hurdles. US prosecutors need approval from the Department of Justice to request data held abroad. Providers can challenge an order in court if it conflicts with foreign law. And data that is encrypted, and whose keys the provider does not even hold, it cannot hand over.
The essence in one sentence: The CLOUD Act obliges US providers to hand over data upon a court order, no matter where it sits. But it is not blanket access – it is bound to a procedure, to serious offences and to legal remedies, and it ends where the provider has no technical access in the first place.
Why the debate is justified nonetheless
One might now say: if there are hurdles, then surely it's only half as bad. It isn't quite that simple – and here lies the legitimate core of the sovereignty debate. Because the decisive weakness is not that data is constantly flowing out, but that a guarantee is simply impossible.
This became strikingly visible in 2025. Before the French Senate, a senior Microsoft representative was asked under oath on 18 June 2025 whether he could guarantee that data of French citizens would never be passed to the US government without the consent of the French authorities. His answer was remarkably honest: no, he could not guarantee that – even though it had never happened to date. That statement captures the dilemma exactly. Microsoft can take technical and contractual protective measures, but it remains bound by US law, and so an absolute assurance is impossible.
For many use cases this theoretical residual access is meaningless. For others it is not: anyone processing especially sensitive data – public authorities, hospitals, law firms, companies with delicate trade secrets – will find the difference between "practically never" and "guaranteed never" highly relevant. An assurance you cannot obtain in law is a real gap. The debate is therefore not a figment of the imagination, but a factually appropriate engagement with a real risk.
How rarely the CLOUD Act actually applies
As justified as the question of principle is, the second half of the truth matters just as much: in practice, the CLOUD Act is almost never applied against corporate data from Europe. This is not reassurance for its own sake – it can be read straight from the providers' own transparency reports.
For the second half of 2024, Microsoft disclosed that it handed over content to US law enforcement for just five business customers outside the US – and not a single one of them was based in the EU or EFTA. Amazon Web Services, in turn, states that since 2020 it has not handed over any content of business or government customers stored outside the US to the US government at all. Against millions of business customers, these are homeopathic figures.
Figures instead of gut feeling: In the second half of 2024 Microsoft handed over content for exactly five non-US business customers to US authorities – none of them from the EU or EFTA. AWS reports zero disclosures of customer data held outside the US since 2020. The theoretical risk is real; the practical frequency against European corporate data is vanishingly small.
This is explained by the nature of the law. The CLOUD Act is an instrument of law enforcement for serious offences, not a tool of industrial espionage – the latter is explicitly not its purpose. The average Swiss SME, with its bookkeeping, its quotes and its customer data, is simply not a target. The discussion is therefore often conducted as if mass data outflow were the rule. In reality it is the extremely rare exception – and it is precisely this gap between perceived and actual risk that one should understand before making far-reaching decisions.
Why Microsoft won't simply bow
A further misconception in the debate is the notion that Microsoft would hand over its customers' data without complaint at a single phone call from Washington. That assumption underestimates both legal practice and the corporation's own economic self-interest.
Microsoft has a long history of resisting government access demands. The CLOUD Act itself came about as a reaction to a years-long legal dispute in which Microsoft refused, all the way to the US Supreme Court, to hand over emails stored in Ireland. The company has repeatedly sued against government disclosure orders and blanket gag orders. This stance is now institutionalised: under the banner of "Defending Your Data", Microsoft commits to challenging government data requests for customers in the European public sector and business wherever it has a lawful basis to do so.
On top of that comes a whole series of concrete commitments to Europe. Microsoft has implemented the so-called EU Data Boundary, storing and processing European customer data within the EU – by now also for AI services like Copilot. With the Microsoft Sovereign Cloud offering and additional control and encryption options, the company is trying to meet the sovereignty need on the technical side. And it has made its "Digital Resilience Commitment" – the contractual promise to challenge in court any government order to suspend European cloud operations – legally binding towards European governments.
The most important reason, though, is simply economic. Europe is a multi-billion market for Microsoft. A corporation that handed over customer data at the first opportunity would gamble away its most important asset: trust. The reputational damage and the loss of trust would be far more expensive for Microsoft than any single legal dispute with its own government. That is precisely why Microsoft won't bow "just like that" – not out of idealism, but because its business model rests on the opposite.
The honest summary: The CLOUD Act makes an absolute guarantee impossible – that is the legitimate core of the debate. At the same time, actual access to European corporate data is extremely rare, and Microsoft has strong legal and economic reasons to resist. Both truths hold simultaneously – anyone stressing only one of them distorts the picture.
What this means for Swiss SMEs in practice
What follows from this tangle is neither blind complacency nor a panicked retreat from the cloud. The sensible approach is a risk-based one that distinguishes between different kinds of data instead of lumping everything together.
The first step is an honest classification of your own data. For by far the largest part of what an SME processes – internal communication, quotes, project documents, everyday customer data – the CLOUD Act is not a realistic threat scenario, and the productivity and security of a mature platform like Microsoft 365 clearly outweigh it. For the small, genuinely highly sensitive part – special categories of personal data, professional secrets, strategically delicate information – a closer look, and where appropriate a different solution, is worth the effort.
For that sensitive segment there are concrete levers: encrypting data with your own, self-managed keys (so that provider access runs into a technical dead end), using sovereign or purely Swiss cloud offerings for the most delicate applications, and – above all – knowing your own exit: how do I get back out if it comes to that, and how long does it take? Sovereignty is not a switch you set to "on" or "off", but a spectrum on which you deliberately position yourself.
Swiss companies that also have to comply with the revised Data Protection Act should have these considerations documented anyway. The good news: a clean data classification and a deliberate provider strategy serve both purposes at once – they create legal certainty and answer the sovereignty question.
Conclusion
The discussion around digital sovereignty is justified, because it hits a real point: as long as a provider is subject to US law, there is no absolute guarantee against government access. At the same time, a sober look at the figures shows that this access against European and Swiss corporate data almost never happens in practice – and that Microsoft, for both legal and economic reasons, has a strong self-interest in resisting rather than bowing.
The right answer for an SME therefore lies not in either extreme, but in a differentiated stance: know the theoretical risk, assess the actual risk realistically, order your own data by sensitivity, and take deliberate precautions for the genuinely delicate part. Anyone who proceeds this way need neither forgo the advantages of modern cloud platforms nor harbour illusions about their limits.
How sovereign is your cloud strategy?
I help SMEs assess their data realistically, separate actual risk from perceived risk, and find a cloud strategy that sensibly balances productivity and data control.
Book a free initial consultation