An Azure service that provides a general-purpose, serverless container platform.
There’s an important distinction here between customer data stored by a regional Azure service and all technical/operational metadata generated while Microsoft operates that service.
For the resources you listed:
- Azure Storage with ZRS keeps the storage data replicated across availability zones within the selected primary region. ZRS does not geo-replicate the storage account to another Azure region. So a ZRS account created in Switzerland North keeps those replicas within Switzerland North.
- Log Analytics is also regional. Microsoft states that each workspace resides in a specific Azure region and recommends deploying separate regional workspaces when data-residency requirements apply.
However, don't interpret those service-level statements as confirmation that every piece of technical data, telemetry, or metadata will always be processed exclusively inside Switzerland North.
Microsoft makes broader contractual commitments through the Microsoft Products and Services Data Protection Addendum (DPA) and, where applicable, the EU Data Boundary. The EU Data Boundary covers Azure and commits Microsoft to storing and processing covered Customer Data and personal data within that boundary, subject to documented exceptions. Switzerland is included within the EU Data Boundary geography.
Importantly, Microsoft also documents circumstances where data can still be transferred or remotely accessed outside the EU Data Boundary for service operation, security, customer-directed transfers, and other defined scenarios. Therefore, even the EU Data Boundary shouldn't be interpreted as an unconditional statement that all metadata never leaves the selected Azure region.
If your compliance requirement specifically requires written confirmation that Customer Data, diagnostic data, service-generated metadata, support data, etc. will never be processed outside Switzerland North, don't rely on a Microsoft Q&A response for that assurance.
You should request the required written confirmation through your Microsoft account team/licensing representative or Microsoft Azure Support, referencing the exact services and configuration:
- Azure Container Apps - Switzerland North
- Storage Account - Switzerland North, ZRS
- Log Analytics workspace - Switzerland North
Ask them to distinguish specifically between Customer Data, Personal Data, Professional Services Data, and service-generated/diagnostic data, and identify any applicable cross-region or EU Data Boundary exceptions.
Start with Microsoft's current Products and Services Data Protection Addendum (DPA).
In short: you can document regional residency for the regional service data, but “no technical data or metadata ever leaves Switzerland North” is a materially stronger requirement and needs contractual confirmation from Microsoft for the specific services and data categories involved.
References:
Microsoft Products and Services Data Protection Addendum (DPA)
Microsoft EU Data Boundary documentation
Azure Storage redundancy and ZRS
Log Analytics workspace architecture and regional residency
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.