Microsoft, Amazon Web Services, and Google operate data centers in Europe and, in some cases, also in Switzerland. This allows companies to store their data relatively close geographically.
However, when it comes to data protection and data sovereignty, a single question is not enough: In which country is the server located?
Equally relevant is which company operates the service, which laws govern this company, and which other service providers are involved in the processing.
Especially with US cloud providers, this plays a US CLOUD Act an important role.
This article explains why server location and company headquarters are not the same thing, what a widely noticed statement by Microsoft before the French Senate actually means, and what Swiss companies should consider when choosing a hosting or cloud provider.
Server location and provider are two different things
When a cloud provider promotes a data center in Switzerland or within the European Union, this information is quite relevant.
Among other things, the physical location influences where data is processed and which requirements must be considered for cross-border data transfers.
However, it does not automatically answer the question, which law applies to the provider itself.
A US company remains a US company in principle, even if certain data is stored on servers in Zurich, Frankfurt, or Paris.
What is the US CLOUD Act?
The Clarifying Lawful Overseas Use of Data Act, short for CLOUD Act, is a US law from 2018.
Simply put, under certain legal conditions, US authorities can compel a provider subject to their jurisdiction to produce data that is in its possession, custody, or control.
It may also be relevant in this context that the data in question is located physically outside of the United States.
However, this does not mean that US authorities can access all data of an American cloud provider at will and at any time. Legal procedures apply to corresponding requests for disclosure, and providers can challenge certain orders.
Nevertheless, an important takeaway remains for companies: The physical location of a server alone does not eliminate potential legal access options.
What Microsoft said before the French Senate in 2025
This topic received particular attention in June 2025 through a hearing of Microsoft France before an investigative committee of the French Senate.
On June 10, 2025, Anton Carniaux, Director of Public and Legal Affairs at Microsoft France, was asked whether he could guarantee that data entrusted to Microsoft by French citizens would never be transferred pursuant to a U.S. government order without the explicit consent of the French authorities.
His answer was: No, he could not give such an absolute guarantee.
This statement was later also picked up in the French Senate's report on digital sovereignty.
However, the complete context is important: Microsoft stated during the same hearing that it challenges legally unjustified requests and notifies customers whenever possible. According to Microsoft, no European enterprise customer was affected by such a case at that time.
Therefore, the statement does not mean that American authorities automatically or regularly access European customer data.
However, it shows that even a European server location cannot offer an absolute guarantee against potential legal requests for disclosure.
Why the statement is interesting for Swiss companies
Today, Swiss companies also use numerous international cloud services: Microsoft 365, Azure, Amazon Web Services, Google Cloud, and many other platforms have long been a normal part of everyday business.
This is not fundamentally problematic. Cloud services can offer significant advantages in availability, scalability, collaboration, and security.
However, companies should know, where your data is processed and which companies are involved in it.
Especially when dealing with particularly sensitive data, the choice of a service provider should therefore not be based solely on marketing terms such as „Swiss Region“, „EU Region“ or „Data Center Switzerland“.
What the Swiss Data Protection Act requires
The Swiss Data Protection Act does not fundamentally prohibit the use of cloud services or foreign providers.
However, companies remain responsible for adequately protecting personal data and complying with legal requirements when processing or disclosing data abroad.
Depending on the destination country and the specific data processing, additional guarantees or legal bases may be required.
Therefore, it is crucial to examine the entire data flow:
- What data is processed?
- Where are they saved?
- Which companies can access this?
- In which countries are these companies located?
- Which subcontractors are used?
- What technical safeguards are in place?
- How is data encrypted?
In the case of particularly sensitive personal data or regulatory sensitive applications, the specific situation should also be reviewed legally.
Is European hosting automatically compliant with data protection laws?
No.
Even a server in Germany, France, or Switzerland does not automatically make a website compliant with data protection laws.
For example, a website can be operated in a European data center while simultaneously transferring data to analytics, advertising, payment, or cloud services in other countries.
Conversely, using an international service provider is not automatically a violation of data protection laws.
What is decisive are the specific data processing, the companies involved, the technical security measures, and the respective legal bases required.
Where is the CURIAWEB infrastructure located?
Here too, we would like to clearly distinguish between the company headquarters and the server location.
CURIAWEB is a Swiss company based in Chur. However, our hosting infrastructure is located in professional data centers in Germany.
Therefore, we currently do not operate any web hosting with a server location in Switzerland, and we also do not wish to give the impression that this is the case.
Our customers get a Swiss contracting partner and personal support from Chur, combined with high-performance European data center infrastructure.
You can find more information about our hosting offers at Web hosting with CURIAWEB.
What distinguishes CURIAWEB from a US cloud?
CURIAWEB is not a global hyperscaler and doesn't want to be one.
We offer classic web hosting, WordPress hosting, email services, domains, and other website-related services.
This is a different area of application than, for example, Microsoft Azure, Amazon Web Services, or Google Cloud. A direct performance comparison would therefore make little sense.
For a typical corporate website, a club, a WordPress project, or a smaller online shop, a complex hyperscale cloud is often not necessary at all.
Here, a manageable hosting offer, personal support, and a clearly defined infrastructure can represent the simpler solution.
European server location does not mean complete independence
Even with a European hosting provider, one should be cautious with terms like „complete digital sovereignty.“.
Modern hosting infrastructures consist of numerous components: hardware, operating systems, network components, software, certificate services, DNS, backup systems, and other external services.
Achieving absolute technical or legal independence from all foreign companies is difficult to attain in today's IT world.
Therefore, the more serious question is: Which dependencies actually exist and which of them are relevant to my data?
Which hosting solution is the right one?
That depends on which data and applications are run.
For a standard corporate website, the requirements are different than for patient data, lawyer files, financial information, or highly sensitive trade secrets.
When choosing a hosting or cloud provider, companies should therefore check at least the following points:
- Registered office of the provider
- physical server location
- applicable law
- deployed subcontractors
- Encryption and access control
- Backup and Security Concept
- Support and Responsibilities
- Industry-specific requirements
Conclusion: Don't just ask where the server is located
The location of a data center is an important part of a hosting decision. However, it is not the whole answer.
Anyone who takes data sovereignty seriously should consider at least three questions separately:
- Where is the server located?
- Who operates the service?
- What law governs this provider?
The hearing of Microsoft France before the French Senate made precisely this distinction visible: A European data storage location alone cannot provide an absolute guarantee that data will never become the subject of a foreign disclosure request.
Equally false, however, would be the assertion that every use of an American cloud is automatically insecure or unlawful under data protection laws.
The better decision comes from transparency, a realistic risk assessment, and a hosting solution that actually fits the processed data and the respective company.

