Proton Mail instead of Gmail and Outlook

Updated · Thomas A. Thejn

Email is the best place to start a sovereignty programme, for a reason that has nothing to do with email: it is the most self-contained system you own.

You can move it without touching anything else. If it goes badly you can move back. And it settles the largest single category of business data sitting under foreign jurisdiction. Almost every other swap on this list is harder and less contained.

What you actually gain

Jurisdiction. Proton AG is Swiss. Switzerland is not subject to the US CLOUD Act, so the corporate-nationality problem described in the CLOUD Act guide does not apply. This is the whole point, and it is the one thing an EU region on a US provider cannot give you.

Zero-access encryption. Mailboxes are encrypted such that Proton cannot read them. This is stronger than "encrypted at rest", which almost every provider offers and which means the provider holds the keys. It also means a compelled disclosure produces ciphertext.

A business model that does not involve your data. Proton sells subscriptions. There is no advertising business that your message content improves.

What you give up

Be honest about these, because discovering them after migration is expensive.

AreaMicrosoft 365 / GoogleProtonDoes it matter?
Core email and calendarMatureMatureNo
Admin controls and provisioningExtensiveLighterFor large orgs, yes
e-discovery, legal hold, retentionPurview / VaultLimitedIn regulated sectors, decisively
Third-party integrationsVery large ecosystemSmallDepends on your stack
Desktop client supportNativeVia local BridgeAdministrative overhead
Server-side searchFullConstrained by encryptionMildly annoying, daily

The last row is the one people notice. Zero-access encryption means the server cannot index your plaintext, so search behaves differently from Gmail's. Proton does client-side indexing to compensate. It is good; it is not Gmail. If your organisation lives by searching a decade of mail, test this before you commit rather than after.

Who should not move

Organisations running on Teams and SharePoint. If your files, chat, meetings and identity all live in Microsoft, moving only email leaves you paying for M365 anyway and running two worlds. The sovereignty gain is real but partial, and the operational cost is not. Either plan the whole migration or do this one later.

Regulated organisations with active e-discovery obligations. Covered above. This is a genuine blocker, not an excuse.

Anyone who has not tested the shared-mailbox workflow. Every organisation has one team — support, invoicing, HR — that depends on a shared mailbox behaving a particular way. Test that one, specifically, with those people, before you decide.

How to run the migration

  1. Pilot with one team for a month. Preferably a team that uses email heavily and is willing to complain loudly. You want the objections early.
  2. Move the domain, not the addresses. Set up your domain in Proton and run it alongside for a defined period before cutting MX records.
  3. Import history with Easy Switch, then verify a sample by hand. Automated imports are good; nobody should discover a gap six months later.
  4. Decide on archives explicitly. Old mail that must be retained for compliance may be better exported to a controlled archive than carried into the new mailbox.
  5. Set a hard cut-over date for the MX change, communicate it, and hold it.

That is the same discipline as any platform migration, which is what this is. The migration sequence in the ServiceNow guide applies almost unchanged.

The verdict

If you are going to make one sovereignty move this year, make it this one. It is contained, reversible, well-trodden, and it settles the largest category of exposed data you have.

Verify the compliance-tooling question against your own obligations first. If that clears, the rest is project management.

Frequently asked questions

Is Switzerland good enough if we need EU data residency?
For the CLOUD Act question, yes — Swiss companies are not subject to US legal process. For a strict EU-residency requirement written into a contract or policy, check the wording: some policies say 'EU/EEA' and Switzerland is neither. Proton operates EU data centres as well, so this is usually answerable, but confirm it rather than assume.
Can we keep using Outlook as our mail client?
Yes, via Proton Mail Bridge, which runs locally and exposes IMAP and SMTP to a desktop client. It is a per-device install, which is an administrative cost at scale. Most organisations that move end up using Proton's own clients.
What about calendars and shared mailboxes?
Proton Calendar exists and is encrypted. Shared mailboxes, delegation and fine-grained admin controls have historically been lighter than Exchange. If your business runs on shared team mailboxes with complex permissions, test that specific workflow before committing.
What is the honest reason not to move?
Compliance tooling. If you are in a regulated sector with legal-hold, e-discovery and retention obligations, Microsoft Purview and Google Vault are mature and Proton's equivalents are not at that level. That is a legitimate reason to stay, and it is a different reason from inertia.

← Back to European technology alternatives

Reviewing a shortlist?

Two things worth doing properly: classify per workload what must be European and what can be risk-accepted, and make sure a European option got a fair hearing in the evaluation rather than a polite mention. Both are quick, and both are more defensible than a blanket policy in either direction.

thomas@thejn.dk +45 2048 3147

Copenhagen, Denmark · Nordic coverage · Independent & platform-agnostic