Edge Rewrite
Jump to content

SWIPO (cloud computing)

From Wikipedia, the free encyclopedia

SWIPO (Switching Cloud Providers and Porting Data) or (SWItching and POrting) was an initiative set up in the context of Article 6 (Porting of data) of the European Union's Regulation on the Free Flow of non-personal Data to develop codes of conduct for switching cloud providers and porting data. The work was facilitated by the European Commission and divided between separate groups for Infrastructure as a service (IaaS) and Software as a service (SaaS).[1]

Background

[edit]

Article 6 of Regulation (EU) 2018/1807 provided for the development of self-regulatory codes of conduct on cloud switching and data porting.[2] The SWIPO working group began work in April 2018, ahead of the adoption of the regulation in November 2018.[1]

The IaaS group was co-chaired by Alban Schmutz of CISPE, representing cloud service providers, and Freddy van den Wyngaert of EuroCIO, representing cloud service users. The SaaS group had four co-chairs: Aniello Gentile (Confindustria, cloud users), Maurice van der Woude (BP Delivery, cloud user), Chris Francis (SAP, cloud provider), and Jörn Wittmann (SCOPE Europe, cloud provider).[1]

Development of the codes

[edit]

The IaaS group published a draft code for consultation in June 2018. Its core drafting group included representatives of CISPE/OVH, EuroCIO, Aruba, AWS, CERN, CIO Platform, Credit Suisse, IBM, Prologue, Santander and UpCloud.[3]

The two codes were presented in Helsinki in November 2019 during the Data Economy Conference of the Finnish Presidency of the Council of the European Union. Copies were presented to Roberto Viola, director-general of the commission's Directorate-General for Communications Networks, Content and Technology, and to Maria Rautavirta of the Finnish government.[4]

SWIPO AISBL

[edit]

An international non-profit association, SWIPO AISBL, was formed to administer and develop the codes.[5]

SWIPO AISBL published the IaaS and SaaS codes in July 2020.[6] The association ceased operating in August 2024.

Market reach

[edit]

In May 2021, CISPE announced declarations covering 21 IaaS services from eight of its members: 3DS Outscale, Aruba, AWS, CoreTech, Infoclip, Irideos, Leaseweb, OVHcloud and Scaleway.[7] In April 2022, Google Cloud published a transparency statement declaring services under the IaaS and SaaS codes.[8]

Gaia-X later referenced the SWIPO codes in its policy and compliance rules. The 22.11 Policy Rules and Labelling Document listed the SWIPO IaaS, SaaS and merged codes among accepted standards for criteria concerning switching and the porting of customer data.[9]

The references remained in later Gaia-X compliance material. In October 2025, Gaia-X removed SWIPO as an example standard, stating in its changelog that the SWIPO Secretariat no longer existed. In March 2026, it removed SWIPO as a permissible standard from several criteria and from its list of conformity assessment bodies.[10]

European Commission assessment

[edit]

The European Commission commissioned three legal assessments of the IaaS code, the SaaS code and the governance agreement. The study was published in 2022 and identified significant shortcomings in the documents.[11]

The SWIPO codes were also covered in the Data Act impact assessment. It recorded limited uptake at the time of the assessment and found that the codes concentrated mainly on pre-contractual transparency rather than removing all technical and economic obstacles to switching.[12]

Dispute over the SaaS code

[edit]

Cigref, the French association of CIOs, publicly challenged the outcome of the SaaS work. In November 2019, it said that the IaaS code was satisfactory, but that no consensus had been reached on the SaaS code or the governance arrangements. It also said that proposals from users on interoperability and software licence portability had not been incorporated.[13] Cigref was a member of EuroCIO, together with Beltug (Belgian CIOs), CIO Platform Nederland (Dutch CIOs) and VOICE (German CIOs).

Cigref asked for an independent audit and called on the commission to prepare legislation if a revised agreement could not be reached by May 2020.[13]

See also

[edit]

References

[edit]
  1. 1 2 3 "Cloud stakeholder working groups start their work on cloud switching and cloud security certification". European Commission. 12 April 2018.
  2. "Regulation (EU) 2018/1807 of the European Parliament and of the Council of 14 November 2018 on a framework for the free flow of non-personal data in the European Union". EUR-Lex. 14 November 2018.
  3. "Request for Comments: CIOs and cloud providers invited to provide feedback on new draft Code of Conduct for switching cloud infrastructure providers and avoiding vendor lock-in". CISPE. 12 June 2018.
  4. "Presentation of Codes of Conduct on cloud switching and data portability". European Commission. 9 December 2019.
  5. Activity Report 2019–2020 (PDF) (Report). Cigref. 2020.
  6. "SWIPO AISBL publishes Codes of Conduct". Euractiv PR. 24 July 2020.
  7. "3DS Outscale, Aruba, AWS, CoreTech, Infoclip, Irideos, Leaseweb, OVHcloud, and Scaleway to declare first cloud infrastructure services adhering to SWIPO IaaS Code for data porting". CISPE. 12 May 2021.
  8. "SWIPO Codes of Conduct for Switching and Data Portability (IaaS and SaaS): Google Cloud Transparency Statement" (PDF). Google Cloud. April 2022.
  9. "Gaia-X Policy Rules and Labelling Document – 22.11 Release". Gaia-X.
  10. "Gaia-X Compliance Document – Changelog". Gaia-X.
  11. "Study presenting assessments of codes of conduct on data porting and cloud switching". European Commission. 23 February 2022.
  12. Commission Staff Working Document: Impact Assessment Report accompanying the proposal for a Data Act (Report). European Commission. 2022.
  13. 1 2 "SWIPO: Failure to regulate the European cloud market". Cigref. 25 November 2019.