13.06.2022 - Outsourcing of personal data processing by Suva to a Microsoft cloud service

Outsourcing of personal data processing by Suva to a Microsoft cloud service

13.06.2022 - In view of certain differences of legal opinion, the FDPIC is advising Suva to reconsider the decision to outsource its personal data processing to a cloud service operated by the US company Microsoft.

On 10 December 2021 Suva voluntarily sent the FDPIC a document entitled Risk Assessment Project Digital Workplace M365. This project concerns the outsourcing – imminent at the time – of Suva's personal data processing from an on-premises solution, i.e. on its own infrastructure, to a data centre operated on Swiss territory by the US company Microsoft. 

After studying the documentation voluntarily submitted to him, the Commissioner welcomes the fact that Suva presented its outsourcing project for an independent data protection review. However, he advises Suva to reassess the outsourcing forthwith. 

In view of the widespread use of Microsoft products and services throughout the private and public sectors in Switzerland, this outsourcing project is of interest to a broad public, which is why the Commissioner is publishing his summary statement in this regard. 

As there is not yet any legal precedent in Switzerland on the outsourcing issue raised, the FDPIC, with Suva's approval, is also publishing Suva's written response, which reveals differences of opinion in certain respects.

Depending on the evolution of the situation and the legal position, the Commissioner reserves the right to take supervisory action ex officio at a later stage.

Stellungnahme des EDÖB Risikobeurteilung Suva Projekt Digital Workplace M365 (PDF, 1 MB, 10.05.2023)

Antwort Suva zur Stellungnahme des EDÖB zum Projekt Digital Workplace M365 (PDF, 987 kB, 10.05.2023)

Webmaster
Last modification 16.05.2023

Top of page