Updated juli 21, 2026
Summary: European regulated organisations face growing operational and legal risk from geopolitical trade tensions with US-controlled cloud providers; sovereign Swiss-hosted infrastructure under the revFADP offers a jurisdiction-neutral fallback that satisfies DORA, GDPR and NIS-2 requirements simultaneously.

Geopolitical trade risk sovereign cloud dependency describes the operational and legal vulnerability that arises when a regulated organisation’s critical workloads run on infrastructure controlled by a foreign jurisdiction whose trade policy, executive orders, or intelligence legislation can interrupt, surveil, or compel access to that infrastructure without the organisation’s consent. For European public-sector bodies, financial institutions, healthcare providers and law firms, this risk has moved from theoretical to boardroom-level in the period since 2018, accelerating sharply as US-EU trade tensions have intensified.

The Mechanism: How US Law Reaches European Data

The core legal instrument is the CLOUD Act, 18 U.S.C. § 2713, which requires US-controlled providers to disclose data to US authorities upon lawful order regardless of where that data is physically stored. Storing data in a Frankfurt or Amsterdam data centre operated by a US hyperscaler does not remove the CLOUD Act obligation from the provider. FISA Section 702 adds a parallel intelligence-collection pathway that operates without a warrant requirement for foreign persons, and the Patriot Act’s Section 215 successor provisions extend this reach further. Together, these statutes mean that any organisation running critical workloads on infrastructure ultimately controlled by a US parent company has implicitly accepted US jurisdictional exposure over that data.

What has changed since 2023 is that trade-war dynamics have introduced a second, distinct risk channel: the possibility that US executive orders issued under the International Emergency Economic Powers Act (IEEPA) could designate European entities, sectors or even member states in ways that trigger mandatory service suspension by US-controlled providers. An IEEPA-based sanctions designation can move from announcement to enforcement within days, and most hyperscaler service agreements contain force majeure and governmental-compliance carve-outs that explicitly exclude provider liability in such scenarios.

Let op: Review your cloud provider’s terms of service for clauses that permit unilateral service suspension “to comply with applicable law or governmental orders.” Under a trade-war escalation scenario, these clauses can be invoked with no contractual recourse available to the European customer.

Contractual Exposure: What SLAs Do Not Protect

Standard enterprise agreements from US hyperscalers typically guarantee uptime, support response times and data portability under normal operating conditions. They do not guarantee continuity of service when a US governmental authority orders restriction. The force majeure language in these agreements is broad enough to cover sanctions compliance, export-control mandates and national-security directives. A compliance officer reviewing these agreements should specifically look for three gaps: first, whether the provider has the contractual right to suspend access without notice when complying with a governmental order; second, whether the SLA explicitly excludes service credits for downtime caused by legal compliance; and third, whether the data portability clause specifies a timeframe for export that would be realistically executable during an emergency restriction event.

Organisations in the financial sector face a compounding obligation here. DORA Regulation (EU) 2022/2554 Article 28 requires that contracts with critical ICT third-party providers include mandatory provisions covering termination rights, data portability timelines, audit access and exit assistance. If the existing agreement with a US hyperscaler does not contain these provisions in enforceable form, the financial entity is already non-compliant with DORA, independently of any trade-war scenario.

See how Qsentinel solves this in practice.Start a 10-user pilot →

DORA, ICT Concentration Risk and the Register of Information

Financial entities subject to DORA must document all critical ICT third-party dependencies in an ICT Register of Information that is reportable to national competent authorities and, for systemic institutions, to the European Supervisory Authorities. Article 28 of DORA requires that this register capture not only the identity of the provider and the nature of the services, but also the concentration risk that arises when multiple critical functions depend on the same provider or on providers within the same jurisdictional or corporate group.

As the DORA Regulation itself states: “Financial entities shall manage ICT third-party risk as an integral component of ICT risk within their ICT risk management framework, and in accordance with the principle of proportionality.” In practice, this means that a bank or insurer that runs its core banking system, its disaster recovery environment and its collaboration tooling all on the same US-controlled hyperscaler must document this concentration explicitly, assess the geopolitical dimension of that concentration, and maintain a tested exit strategy. A sovereign, Swiss-hosted alternative that has been pre-qualified and tested constitutes the documented exit option that satisfies this requirement.

Risk dimension US hyperscaler (current state) Swiss sovereign hosting (alternative)
CLOUD Act exposure Yes, regardless of EU storage location No, if provider is Swiss-domiciled with no US parent
IEEPA/sanctions suspension risk Yes, via force majeure clause No direct US legal obligation on Swiss entity
GDPR adequacy status Requires SCCs and TIA Switzerland has EU adequacy decision
DORA exit strategy requirement Often underdeveloped or untested Can be pre-qualified as documented fallback
NIS-2 supply-chain risk Concentrated, single-jurisdiction dependency Reduced concentration, neutral jurisdiction

Updating the Transfer Impact Assessment Under GDPR Article 46

The European Data Protection Board has stated clearly: “The existence of legislation in a third country that may allow public authorities to access personal data transferred to that country must be taken into account when conducting a transfer impact assessment.” This guidance, from EDPB Recommendations 01/2020, establishes that a TIA is not a one-time document but a living assessment that must be revisited when the legal or political environment of the third country changes materially.

A deterioration in US-EU trade relations represents exactly such a material change. When the US administration issues new executive orders expanding surveillance authorities, imposes tariffs accompanied by threats of digital-services retaliation, or signals willingness to use technology access as a negotiating instrument, a DPO has a defensible argument that the TIA baseline has shifted. The practical steps are: document the specific policy changes that triggered the reassessment; evaluate whether existing Standard Contractual Clauses and supplementary technical measures still provide “essentially equivalent” protection under the Schrems II standard; and if they do not, initiate a data repatriation or migration plan with a documented timeline. Regulators will expect this process to be auditable, which means contemporaneous records matter.

The EU Foreign Subsidies Regulation and CADA as Procurement Levers

The EU Foreign Subsidies Regulation (EU) 2022/2560 gives the European Commission authority to investigate and remedy distortions caused by non-EU subsidies in public procurement. While its primary target has been infrastructure and telecommunications, its logic applies to cloud procurement: a US hyperscaler benefiting from US governmental support or preferential treatment in ways that distort competition can, in principle, be subject to investigation. For procurement officers in regulated sectors, this creates a legitimate basis to weight sovereignty and jurisdictional neutrality as evaluation criteria, rather than treating them as soft preferences subordinate to price.

The CADA Article 29 sovereignty risk assessment mechanism, developed in the French administrative context but increasingly referenced in European procurement discussions, formalises the process by which a contracting authority must evaluate whether dependence on a specific provider creates unacceptable sovereignty risk. Combined with the FSR, this creates a two-layer procurement argument: the FSR addresses market distortion, while CADA-style sovereignty assessment addresses operational and national-security risk. Together they give a public-sector procurement team the documented justification to select a sovereign on-premises or Swiss-hosted alternative even when it is not the cheapest option.

Switzerland as a Jurisdiction-Neutral Fallback

Switzerland’s utility as a neutral hosting jurisdiction rests on three distinct foundations. First, the revised Swiss Federal Act on Data Protection (revFADP), in force since 1 September 2023, aligns Swiss data protection standards with GDPR in ways that preserve Switzerland’s EU adequacy status, meaning data flows from the EU to a Swiss-domiciled provider require no Standard Contractual Clauses. Second, Swiss law contains no equivalent of the CLOUD Act or FISA 702: a Swiss provider cannot be compelled to hand data to a foreign government without a mutual legal assistance procedure, which is transparent and contestable in Swiss courts. Third, Switzerland’s political neutrality and stable treaty relationships with both the EU and the US mean that it is not a realistic target for trade-war retaliation from either side, reducing the scenario in which the hosting jurisdiction itself becomes a risk factor.

IBM’s Cost of a Data Breach Report 2024 recorded the average total cost of a data breach at USD 4.88 million, the highest figure in the study’s history, with 40 percent of breaches involving data stored in public cloud environments, up from 35 percent the previous year. These figures underline that cloud concentration is not merely a regulatory compliance question: it carries a measurable financial tail risk that belongs in any business case for sovereign infrastructure investment.

Let op: If your Swiss hosting provider is a subsidiary of a US parent company, the CLOUD Act applies to the parent and may reach data held by the subsidiary. Verify the ultimate beneficial ownership structure, not just the operational entity, before treating Swiss hosting as jurisdictionally clean.

The European Banking Authority identified ICT third-party concentration as a key systemic risk in its 2024 Risk Assessment, reinforcing that supervisors are actively looking for this exposure in their oversight activities. For CISOs and DPOs preparing for regulatory inspection, a documented and tested sovereign exit strategy is no longer optional: it is the evidence that regulators will request first when reviewing ICT risk governance under DORA and NIS-2.

Building the Business Case: From Risk Assessment to Decision

The practical starting point is a dependency map that identifies which workloads, data categories and operational processes rely on US-controlled providers, and then overlays three risk lenses: legal exposure (CLOUD Act, FISA 702, IEEPA), contractual exposure (force majeure carve-outs, SLA exclusions) and regulatory exposure (DORA concentration risk, GDPR TIA obligations, NIS-2 supply-chain requirements). This map becomes the evidence base for the ICT Register of Information under DORA and the supplementary documentation for any TIA update under GDPR Article 46.

The exit strategy that follows from this map should specify, at minimum: an alternative provider in a neutral jurisdiction that has been pre-qualified and contractually engaged; a tested migration procedure for critical workloads with a realistic recovery time objective; and a governance process that triggers reassessment when geopolitical conditions change materially. Swiss-hosted sovereign infrastructure built on open-source components such as Nextcloud for collaboration and Mistral-based private AI for document processing satisfies each of these requirements while eliminating the CLOUD Act exposure that no contractual negotiation with a US hyperscaler can fully remove.

FAQ

Can a US executive order legally force a cloud provider to suspend services to European customers?

US executive orders issued under IEEPA can designate entities or jurisdictions subject to sanctions or export controls that effectively prohibit a US-controlled provider from continuing to deliver services. European customers have no direct legal recourse against such an order under US law, and most hyperscaler service agreements explicitly exclude liability for compliance with governmental demands.

What does DORA Article 28 specifically require regarding geopolitical ICT concentration risk?

DORA Article 28 requires financial entities to identify, monitor and manage concentration risk arising from reliance on a single ICT third-party provider or a group of related providers. The ICT Register of Information must document all critical third-party dependencies, and exit strategies must be tested and kept current. Geopolitical risk, including the jurisdiction of the provider, is an explicit factor in the concentration risk assessment.

How does Switzerland’s revFADP differ from GDPR in ways that matter for data sovereignty?

The revised Swiss Federal Act on Data Protection, in force since 1 September 2023, aligns Switzerland closely with GDPR standards, preserving its EU adequacy status. Critically, Swiss law contains no equivalent of the CLOUD Act or FISA 702: Swiss authorities cannot compel a Swiss-domiciled provider to hand over data to a foreign government without going through mutual legal assistance treaty procedures, which are transparent and contestable in Swiss courts.

What should a Transfer Impact Assessment say when a US provider’s geopolitical risk profile has deteriorated?

Under GDPR Article 46 and EDPB Recommendations 01/2020, the TIA must be updated to reflect any material change in the legal or political environment of the recipient country. New executive orders expanding surveillance powers, trade-war escalation or credible reports of FISA 702 or CLOUD Act use against European data subjects all constitute material changes. The DPO must reassess whether existing Standard Contractual Clauses provide sufficient protection and document supplementary technical measures or trigger a data repatriation process.

Is Swiss-hosted infrastructure automatically GDPR-compliant if the provider is Swiss-domiciled?

Switzerland benefits from an EU adequacy decision, meaning personal data can flow from the EU to Switzerland without additional transfer mechanisms. However, compliance with GDPR still depends on the data processing agreement, the security measures in place and the ownership structure of the Swiss provider. If a Swiss entity is ultimately owned or controlled by a US parent company, the CLOUD Act may still apply and a TIA must address that residual exposure.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Can a US executive order legally force a cloud provider to suspend services to European customers?
US executive orders issued under the International Emergency Economic Powers Act (IEEPA) can designate entities or jurisdictions subject to sanctions or export controls that effectively prohibit a US-controlled provider from continuing to deliver services. European customers have no direct legal recourse against such an order under US law, and most hyperscaler service agreements explicitly exclude liability for compliance with governmental demands.
What does DORA Article 28 specifically require regarding geopolitical ICT concentration risk?
DORA Article 28 requires financial entities to identify, monitor and manage concentration risk arising from reliance on a single ICT third-party provider or a group of related providers. The ICT Register of Information must document all critical third-party dependencies, and exit strategies must be tested and kept current. Geopolitical risk, including the jurisdiction of the provider, is an explicit factor in the concentration risk assessment.
How does Switzerland's revFADP differ from GDPR in ways that matter for data sovereignty?
The revised Swiss Federal Act on Data Protection, in force since 1 September 2023, aligns Switzerland closely with GDPR standards, which is why the EU has maintained Switzerland's adequacy status. Critically, Swiss law does not contain an equivalent of the CLOUD Act or FISA 702: Swiss authorities cannot compel a Swiss-domiciled provider to hand over data to a foreign government without going through mutual legal assistance treaty procedures, which are transparent and contestable.
What should a Transfer Impact Assessment say when a US provider's geopolitical risk profile has deteriorated?
Under GDPR Article 46 and EDPB Recommendations 01/2020, the TIA must be updated to reflect any material change in the legal or political environment of the recipient country. A deterioration in US-EU trade relations, new executive orders expanding surveillance powers, or credible reports of FISA 702 or CLOUD Act use against European data subjects all constitute material changes that require the DPO to reassess whether the existing Standard Contractual Clauses provide sufficient protection, and to document supplementary technical measures or trigger a data repatriation process.
Is Swiss-hosted infrastructure automatically compliant with EU GDPR if the provider is Swiss-domiciled?
Switzerland benefits from an EU adequacy decision, meaning personal data can flow from the EU to Switzerland without additional transfer mechanisms. However, compliance with GDPR still depends on the contractual relationship, the data processing agreement, the security measures in place and, critically, the ownership structure of the Swiss provider: if a Swiss entity is ultimately owned or controlled by a US parent company, the CLOUD Act may still apply, and a TIA must address that residual exposure.