Proton Docs instead of Google Workspace or Microsoft 365

Updated · Thomas A. Thejn

Every list like this has an entry where the honest answer is "not yet". This is that entry, and saying so is what makes the other entries worth reading.

What Proton Docs gets right

It is a real collaborative editor with end-to-end encryption, which is a genuinely difficult engineering problem — real-time collaboration and zero-access encryption pull against each other, and Proton has made it work.

For a document that must not be readable by the provider, it is a legitimately good answer today. The direction of travel is right and the privacy model is the strongest of anything in this category.

Why that is not enough

Because you are not replacing a document editor. You are replacing a suite, and the editor is the part that was always going to be solved first.

What an organisation actually depends on:

CapabilityReality today
Collaborative document editingSolid
Spreadsheets as a working toolThe weakest link, and often the most load-bearing
PresentationsNot the answer — see the Pitch entry
Storage, sharing, permissionsProton Drive works; the sharing model is simpler than Workspace
Admin, identity, SSO provisioningLighter than either incumbent
OfflineWeaker than desktop Office
Third-party integrationVery limited by comparison

The spreadsheet row is the one that decides it in practice. In most organisations there is a spreadsheet somewhere doing far more work than anyone planned — a model, a tracker, a reconciliation — and it is usually the thing that blocks a migration. Not because a replacement cannot open it, but because it cannot open it identically, and identical is what people mean by "it works".

The comparison nobody makes

Ask what you are actually protecting.

A large share of the documents in a typical organisation are drafts, notes, agendas and internal write-ups. The sensitive set — contracts, personal data, board material, anything under NDA — is usually much smaller than the instinctive answer.

Migrating the entire suite to protect that fraction is a poor trade when a targeted answer exists: put the sensitive set somewhere appropriate now, leave the rest, and revisit when the tooling is ready. That is available today and it costs almost nothing.

What to do instead

  1. Move email. Proton Mail is ready, contained, and settles the largest category of exposed data.
  2. Classify your documents. Which genuinely must not sit with a US provider? Be honest — the answer is smaller than it feels.
  3. Handle that set deliberately. Encrypted storage, or an EU-hosted alternative, for those documents specifically.
  4. Set a review date. Six to twelve months, in the calendar, with a name against it.

The verdict

Not yet, and we would rather say so than sell you a migration you will reverse.

Being wrong in this direction is cheap: you keep your suite and wait. Being wrong the other way costs an organisation-wide migration, a productivity dip, and the credibility of every future sovereignty proposal you make internally. That last one is the expensive part — the fastest way to kill a sovereignty programme is to make its first big move a visible failure.

Frequently asked questions

What specifically is missing?
Not one feature — the surrounding suite. Spreadsheets that survive real business use, presentations, a mature sharing and permissions model, admin and identity integration, dependable offline behaviour, and the integrations other systems assume. Any one of these is manageable; together they are a productivity suite, and that is what you would be replacing.
Is the encryption worth the trade?
For a small number of genuinely sensitive documents, absolutely — and you can use it for exactly those without moving your whole organisation. Treating it as a secure annexe alongside your main suite is a sensible use today, and it costs you nothing to start.
What should we do instead right now?
Move email, which is contained and ready. Classify your documents and identify the small set that genuinely should not sit with a US provider — for most organisations it is a much smaller set than the instinctive answer. Put those somewhere appropriate now and leave the rest until the tooling catches up.
When should we look again?
Set a calendar reminder for six to twelve months. This category is moving. The mistake is not choosing to wait — it is waiting by default and never revisiting, which is how organisations end up three years behind their own policy.

← Back to European technology alternatives

Reviewing a shortlist?

Two things worth doing properly: classify per workload what must be European and what can be risk-accepted, and make sure a European option got a fair hearing in the evaluation rather than a polite mention. Both are quick, and both are more defensible than a blanket policy in either direction.

thomas@thejn.dk +45 2048 3147

Copenhagen, Denmark · Nordic coverage · Independent & platform-agnostic