For municipalities

Cloud and geodata security for municipalities

Schrems II, the CLOUD Act and Swedish hosting in plain language — with straight answers on where OrbGIS stands on every point. This page is written to be forwarded to whoever owns information security in your organization.


The short answer

Four things your IT security team wants to know first.

01

Swedish hosting, for real

The entire platform runs on Swedish cloud infrastructure in Swedish data centers, operated by us. Swedish data residency can be written into the contract.

02

Out of the CLOUD Act's reach

The CLOUD Act applies to US companies. There are none in the OrbGIS operating chain — so there is no one a disclosure order could be served on.

03

Open source, no lock-in

The platform is built on proven open source — PostgreSQL and PostGIS at its core. Your data can always be exported for free, in open formats.

04

Paperwork that survives scrutiny

A data processing agreement, documented subprocessors, a contractual SLA and security documentation — ready for your procurement.


Why this page exists

When a municipality adopts a new GIS tool, three people usually decide: the person who will work in it, the manager who pays for it — and the person responsible for information security. The first two, the product can convince on its own. The third has a different job: asking where the data ends up, who could be compelled to hand it over, and what happens the day you want to leave.

Those are the right questions, and they deserve straight answers. This page is written so it can be forwarded as-is — to your CISO, data protection officer or procurement lead — and finished in five minutes.

Geodata is a security matter

A GIS platform rarely holds just background maps. It holds utility networks and sensitive sites, cases tied to properties and addresses — and the moment you collect survey responses from citizens, it holds personal data in the legal sense.

Choosing a GIS platform is therefore not just a tooling question. The same requirements that apply to any line-of-business system — information classification, a data processing agreement, protection against unauthorized access — apply here too. And in a classification exercise, geodata tends to land higher than people first expect.

Schrems II, in plain language

Schrems II is the 2020 ruling by the Court of Justice of the EU that invalidated Privacy Shield, the framework of the day for transferring personal data to the US. The core of the ruling is easy to summarize: US surveillance law gives US authorities access to data held by US service providers in a way EU law does not accept — and that access cannot be contracted away with standard clauses.

Since 2023 there is a successor, the adequacy decision for the EU–US Data Privacy Framework, which again permits transfers to certified US companies. But it is the third attempt down the same road — Safe Harbor and Privacy Shield were both struck down — and the current decision is contested and expected to be tested again. Building your operations on US cloud services means building on legal ground that has already been pulled away twice.

For OrbGIS the question never arises: your data — the geodata you upload, your users, your survey responses — is stored and processed within the EU, with European providers. There is no US transfer in the operation to run an impact assessment on.

The CLOUD Act, in plain language

The CLOUD Act is a US law from 2018 that lets US authorities demand data from US service providers — regardless of where in the world the data is stored. A US cloud giant placing its servers in Stockholm or Frankfurt changes nothing: what decides is the jurisdiction of the company, not the address of the server hall.

“Data centers in the EU” is therefore not the same thing as European control. If you seriously want data out of the CLOUD Act’s reach, looking at the map is not enough — you have to look at the ownership chain.

OrbGIS is a Swedish-owned company, the platform is operated by us, and the infrastructure comes from Swedish providers. A CLOUD Act order simply has no recipient: there is no US company in the chain to serve it on.

What “Swedish hosting” has to mean

“Swedish hosting” has become a sales phrase, used for everything from a Swedish reseller of US cloud services to actual operations under Swedish control. Three questions separate the two: Where are the servers? Who owns the companies running them? And who holds day-to-day technical control of the data?

Here is how those answers look for OrbGIS:

  • The whole platform on Swedish infrastructure. Database, map engine, file storage and backups run on Swedish cloud infrastructure in Swedish data centers.
  • We operate it ourselves. The platform is built on proven open source — PostgreSQL with PostGIS at the core — and we run it ourselves rather than renting a managed backend from someone else.
  • Backups in Sweden. Backup copies are encrypted and stored separately from production, in more than one location in Sweden.
  • AI within the EU. The platform’s AI features run with a Swedish AI provider inside the EU. Your data is never sent to US AI services.
  • Residency in the contract. Storage within the EU is the contractual default. If your municipality requires Swedish data residency, it is written into the contract as part of the Swedish hosting option.

Security inside the platform

Jurisdiction is half the answer. The other half is how the platform is built — what actually decides who can reach what, day to day.

  • Row-level separation. Every organization’s content is isolated with row-level security in the database itself, not just in application code. Users in one organization cannot reach another organization’s data.
  • Roles and privileges. Role-based access control decides who may view, edit, share and publish. Single sign-on via SAML / OIDC — including Microsoft Entra ID — is available through the service agreement.
  • Nothing goes public by accident. Publishing is a deliberate action that requires a specific privilege. Until then, content is visible only to signed-in members of your organization.
  • Encrypted throughout. All traffic is encrypted with TLS, and backups are encrypted.
  • Backups that are actually tested. Continuous backup with an extra encrypted copy in Sweden. With the service agreement: 90-day retention, at most 10 minutes of data loss, recovery within 4 hours — verified by quarterly restore tests.
  • A clear way out. All your data can be exported for free at any time, in open formats, and the QGIS plugin gives full desktop access. If you switch systems, your data comes with you.

Quick answers for the security review

The questions that tend to come up in a security review — and the answers, in short form.

The questionThe short answer
Where is our data stored?On Swedish cloud infrastructure in Swedish data centers. Contractually: within the EU by default, Swedish residency as an option.
Who operates the platform?OrbGIS ourselves — a Swedish-owned company — on infrastructure from Swedish providers.
Is the operation subject to the CLOUD Act?No. There is no US cloud provider and no US ownership in the operating chain.
Are there third-country transfers?Not of your data in the operation — storage and processing happen within the EU.
Is there a data processing agreement?Yes — standard or negotiated, with documented subprocessors.
How is our data isolated from other customers?Row-level security per organization in the database itself, on top of role-based access control.
What does backup look like?Continuous, with an encrypted copy in Sweden. With the service agreement: 90-day retention, at most 10 minutes of data loss, recovery within 4 hours.
Is there single sign-on?Yes — SAML / OIDC, including Microsoft Entra ID, through the service agreement.
What happens if we leave?You export all your data for free, in open formats. No lock-in.
Can we ask follow-up questions?Yes — directly to the team that builds the platform. Security documentation and procurement support are part of the service agreement.
Good to know

This page describes how OrbGIS is built and operated — it is not legal advice, and your assessment is your own. But you do not have to make it alone: we are happy to walk through classification, the data processing agreement and security questions together with your IT security function.

Forward the page — or the questions, straight to us.

Hand this page to whoever owns your information security, and book a meeting for the rest. You will be talking to the team that builds the platform.