The debate that never ends
Every month, a client asks us the same question: "Where do we put our data?" The short answer: it depends. The long answer is this article.
I've spent the last five years helping companies, from Moroccan SMEs to Swiss publicly traded groups, make this decision. What I've learned fits in one sentence: most companies are solving the wrong problem. They obsess over geographic location. They should obsess over access control.
The false security of "everything stays in-house"
On-premise feels safe. Your servers, your room, your key. Except I've seen on-premise setups with admin passwords on sticky notes. Literally. I've seen "server rooms" that were actually a closet under the stairs with a portable air conditioner.
On-premise isn't inherently more secure. It's more controllable, if you have the team to control it. That's a nuance many people miss.
When on-premise makes sense:
- You process health data under strict sectoral regulations (HDS in France, FADP in Switzerland)
- Your data volume is stable and predictable, no seasonal spikes
- You have a competent internal infrastructure team with a tested disaster recovery plan
- Network latency is critical to your operations (manufacturing, real-time systems)
- Your regulator requires physical control of servers
If you check fewer than three boxes, on-premise will probably cost you more than it protects you.
Sovereign cloud in Europe: separating marketing from reality
The term "sovereign cloud" has become a marketing catch-all. Everyone claims it. Few actually deliver it.
A sovereign cloud worth the name means three things: datacenters on European soil, a European legal entity operating those datacenters, and no possible subjection to the US CLOUD Act or equivalent extraterritorial laws. OVHcloud, Scaleway, Infomaniak, they check these boxes. An "EU region" at a US hyperscaler? No. Your data is in Europe, but the legal entity operating it remains subject to American law.
For GDPR data hosting, this distinction is fundamental. Article 48 of the GDPR prohibits the transfer of personal data to a third country based on a foreign court decision, unless there's an international agreement. The CLOUD Act ignores this prohibition. As long as this legal conflict remains unresolved, using a European sovereign cloud isn't economic patriotism, it's risk management.
The Swiss case that changed everything for us
Last year, a health-tech company based in Zurich contacted us. Their problem: they processed medical data from Swiss patients, subject to the FADP (Federal Act on Data Protection), and their cloud provider had just been acquired by a US group.
Overnight, the legal basis for their hosting was compromised. Not because the data had physically moved, it was still in a Zurich datacenter. But because the operating legal entity had changed jurisdictions.
We built a hybrid architecture: patient data on on-premise infrastructure in a certified Swiss colocation datacenter, computation workloads (anonymized) on a European sovereign cloud, and an end-to-end encrypted data pipeline between the two. All in six weeks. Honestly, it was tight, but it forced us to industrialize our approach.
Most companies are fighting the wrong battle. Your real risk isn't where your data lives, it's who has access to it.
Morocco and Law 09-08: an underestimated framework
Moroccan companies aren't exempt. Law 09-08 on the protection of individuals with regard to personal data processing imposes clear obligations. Transferring data outside Morocco to a country not offering an "adequate" level of protection requires authorization from the CNDP.
In practice, many Moroccan companies use SaaS products hosted in the United States without asking the question. The risk is real, even if it's rarely enforced today. The CNDP is ramping up. Companies that anticipate now will have a competitive advantage, and avoid an emergency migration project down the line.
For our clients in Morocco, we often recommend hosting with providers that have datacenters in Casablanca or, failing that, in Europe with a solid contractual framework (standard contractual clauses plus additional technical measures).
The real cost of sovereign cloud
Let's talk money. A European sovereign cloud costs on average 20 to 40% more than a US hyperscaler for equivalent workloads. That's a fact.
But that's the wrong calculation. The right calculation includes: the cost of a GDPR non-compliance incident (up to 4% of global annual revenue), the cost of an emergency migration if your provider changes jurisdiction, the reputational cost if your clients discover their health data passes through a datacenter subject to the Patriot Act.
When you run the full numbers, the sovereign cloud premium becomes insurance. Not a luxury.
3 questions to ask before choosing
After dozens of engagements on this topic, I've distilled the decision into three questions. Simple, but they force clarity.
Question 1: What data do you process, and under which jurisdiction? Health data in Switzerland? On-premise or Swiss HDS-certified cloud. Marketing data from European prospects? A European sovereign cloud is enough. Application logs with no personal data? Go with the cheapest hyperscaler, seriously.
Question 2: Who has access to your data, at every layer of the stack? Can your cloud provider access data in cleartext? Do your subcontractors have admin access? Are your employees using SaaS tools that replicate data outside your control perimeter? That's where the risk actually hides.
Question 3: What's your worst-case scenario, and how much does it cost? If your provider gets acquired tomorrow, how long to migrate? If a regulator knocks on your door, can you demonstrate compliance within 48 hours? If the answer is "I don't know," you've found your priority.
Our approach at JADEV
We don't sell cloud. We don't sell servers. We help our clients make an informed decision, then we implement it.
In practice, every engagement starts with a data classification audit. We categorize: personal data, sensitive data, non-personal business data, public data. Each category has a different risk profile and therefore a different hosting fit.
The result, more often than not, is a hybrid architecture. The most sensitive data on-premise or sovereign cloud, the rest wherever it's most efficient. No dogma. Pragmatism.
If this is relevant to you, let's talk. The decision is never as complex as it looks, as long as you ask the right questions.
