The choice between on-premise and cloud deployment is, at its core, a question of where authority over your data actually resides: legally, physically and operationally. For organisations handling regulated, sensitive or strategically sensitive information, the answer to that question has direct compliance and liability consequences, not just technical ones.
When On-Premise Is the Right Choice
On-premise deployment is preferable when data sovereignty, regulatory compliance or operational continuity requirements cannot be reliably guaranteed through a third-party hosting arrangement.
Several concrete scenarios make on-premise the defensible default:
- Regulated data categories under GDPR Article 9 (health, biometric or criminal record data) where the data controller must demonstrate technical control, not just contractual assurance.
- Sector-specific rules such as NIS2 (Directive 2022/2555/EU) for operators of essential services, which require documented control over the IT environments underpinning critical functions.
- Foreign jurisdiction exposure: US cloud providers remain subject to the CLOUD Act (18 U.S.C. § 2713), which allows US authorities to compel disclosure of data stored anywhere in the world, regardless of local law. Standard Contractual Clauses do not neutralise this risk.
- Air gap requirements: defence contractors, intelligence-adjacent organisations and some critical infrastructure operators are required or strongly advised to maintain systems with no external network connectivity at all. A cloud model is structurally incompatible with a true air gap.
The European Data Protection Board has been explicit on the jurisdictional problem: “Cloud services subject to foreign jurisdiction laws create an inherent tension with GDPR’s data transfer restrictions that contractual clauses alone cannot fully resolve.” (EDPB Guidelines 05/2021 on transfers of personal data.)
A Eurostat ICT survey from 2023 found that 41% of European enterprises identified data residency and sovereignty as a primary barrier to broader cloud adoption, reflecting how widely this concern is felt at the operational level.
What On-Premise Deployment Looks Like in Practice
On-premise is not a single configuration: it ranges from a rack of servers in your own server room to a hardware appliance installed behind your firewall with remote management handled by a specialist.
A hardware appliance model is particularly relevant for mid-sized organisations that lack a dedicated infrastructure team but still need full data locality. The appliance ships pre-configured, is installed within the organisation’s physical perimeter, and all data written to it stays on that device. Management, patching and monitoring can be handled remotely by a managed service provider, but without data ever leaving the customer’s network. Qsentinel, for example, offers this model for organisations deploying Nextcloud Enterprise, combining managed operations with on-premise data residency and post-quantum encryption at the storage layer.
Key operational considerations for on-premise deployment include:
- Physical security of the server room (ISO 27001 alignment is a common baseline).
- Redundant power and network paths to meet uptime requirements comparable to cloud SLAs.
- Defined procedures for hardware failure and disaster recovery, which are the customer’s responsibility unless contractually delegated.
- Clear access logging to satisfy audit requirements under regulations such as NIS2 or the Dutch BIO (Baseline Informatiebeveiliging Overheid).
The Hybrid Model: Combining On-Premise and Cloud
A hybrid deployment separates workloads by sensitivity level, keeping regulated or confidential data on-premise while using cloud infrastructure for lower-risk collaboration or public-facing services. According to Flexera’s State of the Cloud Report 2024, 72% of organisations now use a hybrid cloud strategy, reflecting how rarely a pure on-premise or pure cloud model fits all workloads.
In practice, a workable hybrid architecture for a European organisation might look like this:
| Workload type | Deployment model | Rationale |
|---|---|---|
| HR records, financial data, legal documents | On-premise or Swiss cloud | GDPR Article 9, audit trail requirements, no foreign jurisdiction exposure |
| Internal collaboration (chat, calendar, file sharing) | Private cloud or managed Nextcloud | Controlled environment, data residency in EEA or Switzerland |
| Public website, marketing tools | Standard cloud | No personal or regulated data; latency and scalability matter more |
Swiss cloud hosting occupies a useful middle position for organisations that cannot maintain their own hardware but distrust US-based hyperscalers. Switzerland sits outside EU jurisdiction and outside the scope of US FISA Section 702 surveillance provisions. The revised Swiss Federal Act on Data Protection (nFADP), which entered into force in September 2023, aligns with GDPR principles while remaining under Swiss judicial oversight exclusively.
The practical challenge in hybrid models is identity and access management across perimeters, consistent encryption standards, and ensuring that synchronisation between on-premise and cloud nodes does not inadvertently expose regulated data to infrastructure governed by foreign law. These are engineering problems with known solutions, but they require explicit design rather than default configurations.
FAQ
Is on-premise always more expensive than cloud?
Not necessarily. Upfront hardware and setup costs are higher, but organisations with large, stable workloads often find that total cost of ownership over five or more years is comparable or lower than subscription-based cloud services, particularly when bandwidth and compliance overhead are factored in.
Does GDPR require on-premise hosting?
GDPR does not mandate on-premise hosting, but it does require that personal data transferred outside the EEA is protected by adequate safeguards. For US-based cloud providers subject to CLOUD Act obligations, achieving reliable adequacy in practice is structurally difficult.
What is an air gap and when is it necessary?
An air gap is a complete physical and logical separation of a system from any external network. It is typically required in critical infrastructure, defence and intelligence contexts where even encrypted remote connections are considered unacceptable risk vectors.
Can a managed Nextcloud deployment be considered on-premise?
Yes, if the hardware sits in your own data centre or server room and you retain full administrative control. A managed service provider can handle updates and monitoring without this constituting cloud hosting, provided no data leaves your perimeter without your explicit consent.
How does Swiss cloud hosting differ from standard EU cloud hosting?
Switzerland is not subject to EU directives, US CLOUD Act or FISA Section 702 in the same way as EU-based providers using US infrastructure. The nFADP (in force since September 2023) aligns with GDPR principles but places oversight exclusively with Swiss authorities, which is a meaningful distinction for organisations facing cross-border legal exposure.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
