KMU-Magazin Nr. 4/5, April/Mai 2026 Cloud solutions: This is legally crucial

Without cloud solutions, the everyday business for Swiss SMEs would now be hardly imaginable. However, precisely because they have become so normal and indispensable, practical and legal questions continue to arise. We provide an overview of the legal framework and highlight what needs to be considered when selecting and using these solutions.

Cloud computing refers to a model of flexible, needs-oriented use of IT resources – such as servers, data storage or applications – via a (usually public) network, often the internet. An organisation’s own IT infrastructure is supplemented by external providers or, depending on the model, even replaced, enabling lower operating costs, the elimination of maintenance work and a high degree of scalability.

Cloud models

Cloud services are offered in various models. One of the most common cloud models is “Software as a Service” (SaaS). Under this model, companies obtain ready-made software applications (e.g. for accounting, CRM or Office) directly from the provider, do not have to install anything, and receive regular updates and support. The software is usually provided via the web, and the provider is responsible for operation and maintenance. A sub-type of this is the “Desktop as a Service” (DaaS) model. Here, the provider provides virtual desktop workstations from the cloud. The user receives a complete desktop that runs on the provider’s server. With the DaaS model, too, the provider bears full responsibility for the infrastructure. A third option is the “Infrastructure as a Service” (IaaS) model. Here, the company rents server capacity, storage space or network infrastructure and can run its own software on it. The responsibility for the physical infrastructure, reliability and basic data security lies with the provider. Unlike the other models, however, the company remains responsible for the operating system and the application layer.

From a legal perspective, cloud computing is particularly significant when personal data – such as customer data, personnel files, health information or other sensitive personal data – is processed. The mere storing of such data in the cloud is considered as processing and is subject to the provisions of the Federal Act on Data Protection (FADP). Among other things, the FADP stipulates that personal data must be processed in a transparent, purpose-limited and proportionate manner and protected by appropriate technical and organisational measures.

Important to know: companies remain responsible for complying with the provisions of the FADP even if they outsource data to the cloud and delegate technical tasks to the provider. It is therefore essential to exercise particular care when selecting a provider.

Criteria for selecting a provider

Swiss companies can identify the most suitable providers from the wide range available by taking into account not only the terms and conditions and the scope of services, but also aspects relating to data protection and professional confidentiality. The location of the data processing is a key criterion: it is advisable to choose providers whose data is processed in Swiss data centres or in countries with a comparable level of data protection. Particularly in the case of international providers, it should be checked whether backend or support operations are carried out from third countries (non-EU countries), as this may entail risks. Verifiable security standards such as certifications (e.g. ISO/IEC 27001), audits and independent test reports can provide additional reassurance. Transparency regarding all subcontractors and support structures, as well as contractual provisions governing approval of subcontracting, are also crucial for establishing control and trust.

The choice of provider is particularly important when dealing with sensitive personal data, such as health data, information on religion or ethnicity, or data subject to professional confidentiality or official secrecy. In such cases, companies must take even greater care to ensure that technical and organisational safeguards – such as strong encryption and a rigorous access policy – are effectively implemented, and that professional regulations are also complied with.

Service level agreements

Once a suitable provider has been selected, the next step is to set out the key terms of the contract in detail. The focus is initially on the service description: this sets out the types, scope, availability and performance of the services to be provided by the provider. It is also important to ensure that all fixed and variable cost items, such as storage expansions or special support services, are presented transparently and clearly to avoid any surprises regarding the total costs.

For business-critical cloud services, it is then strongly recommended that a Service Level Agreement (SLA) be concluded. An SLA can be agreed as part of the main contract or as a separate agreement, and sets out in detail availability commitments, response times and the procedures for dealing with disruptions or failures. This helps to reduce the risk of an interruption of business caused by a cloud service failure.

Furthermore, liability and warranty must be regulated in a clear and balanced manner. It should be noted that standard contracts drawn up by providers often contain limitations of liability to the detriment of the Customer. In such cases, particular caution is required and, where necessary, renegotiation is advisable.

The provisions governing the termination of the contract and the data return process constitute another key element of the contract: notice periods, the procedure for a smooth and complete data export, and the thorough deletion of all data backups must be set out in binding terms. At the same time, the portability and interoperability of data must be guaranteed, so that a switch to another provider or system remains possible without any interruption of business.

Specific obligations

Finally, data protection obligations must also be agreed: the provider and all subcontractors must be contractually bound to comply fully with the applicable data protection laws. This includes, amongst other things, the provider’s obligation to report data breaches and to assist the customer in fulfilling regulatory duties to provide information and cooperate.

Particularly for companies and individuals subject to professional confidentiality under Art. 321 of the Swiss Criminal Code (e.g. lawyers or doctors), stricter requirements apply when using cloud services: the mere technical possibility of the provider accessing unencrypted data may constitute a disclosure that meets the criteria of the offence. It must therefore be ensured contractually that providers and subcontractors are subject to a duty of confidentiality equivalent to professional confidentiality. It is also recommended to clarify the permissibility of the data outsourcing in advance with the relevant supervisory authority or professional association, or to consult their guidelines. In some circumstances, it may be necessary to conclude specific supplementary agreements with the cloud provider regarding professional confidentiality in order to meet the legal requirements. Certain providers already make such supplementary agreements available as standard.

Cloud and data protection

Data protection, a topic already addressed in the context of selecting a provider and drafting contracts, is central to cloud computing. The key data protection challenges are outlined again below. In the relationship between companies and their cloud providers, the company is generally regarded as the controller under the FADP, as it determines the purposes and means of the data processing. The cloud provider, on the other hand, generally acts as a processor and may process personal data exclusively on the instructions of the controller. A clear and contractually defined demarcation of these roles is essential, both in terms of liability and control rights. This is usually set out in a separate data processing agreement, the conclusion of which is strongly recommended for all outsourcing projects involving personal data. Where sensitive personal data is processed, stricter requirements must be observed: sub-delegation to further processors should not be permitted, or only to a limited extent; liability must not be excluded or reduced; and, particularly in the case of SaaS solutions, technical measures must be implemented to ensure that the provider is denied access to sensitive content, for example through encryption or local data storage. When transmitting personal data abroad, which may be necessary depending on the provider, it must always be checked whether the recipient country offers an adequate level of data protection. The Federal Council maintains a corresponding list. Adequate protection exists for the EU and US companies certified under the Swiss-U.S. Data Privacy Framework. Otherwise, supplementary contractual guarantees must be provided.

This is what matters

Cloud computing has become an indispensable technology in everyday business life in Switzerland. The wide-ranging benefits, from increased flexibility and scalability to significant efficiency gains, have long been a reality for companies. At the same time, the legally compliant use of cloud services places high demands on organisations and requires the careful selection of trustworthy providers, transparent contract drafting and consistent compliance with data protection and professional regulations. Control mechanisms, clear responsibilities and technical security measures are essential, particularly when processing sensitive personal data. Those who take these aspects to heart can make the most of the potential of cloud solutions whilst reliably minimising risks.

Further articles

Unternehmen M&A Nachfolge
Corporate / M&A / Succession
04.08.2026

The forthcoming introduction of a federal register of beneficial owners

On 26 September 2025, Parliament passed the Federal Act on the Transparency of Legal Entities and the Identification of Beneficial Owners (TJPG), alongside the amendment to the Anti-Money Laundering Act (AMLA). At the heart of the TJPG is the central transparency register, in which the beneficial owners of all companies and legal entities subject to the Act are recorded. The two Acts, together with the associated ordinances, will come into force on 1 October 2026. The most important questions regarding this are answered below in advance.

Read article
Immobilien Bauen
Condominium/rent
25.06.2026

Condominium ownership: What business owners need to know

With condominium ownership, it is not just the value of one’s own unit that determines the value of an investment. Regulations, renovations, renovation funds and decisions taken by the condominium association can be just as important to business owners as location, price and possible uses.

Read article
IT ICT Datenschutz
13.03.2026

Electronic signatures and digital contracts: Legal basis and practical information

Digital business processes now determine contract processing in almost all industries. Electronic signatures are a key tool for efficiency and flexibility, but the legal framework is complex and raises practical questions. The following article provides an overview of the legal requirements and practical obstacles involved in using electronic signatures in Switzerland.

Read article