The Problem: Client Data Must Never Mix
For lawyers, notaries and tax advisors, client data separation isn't optional — it's legally required. Attorney-client privilege, professional secrecy under Art. 321 of the Swiss Criminal Code, and the Swiss Federal Act on Data Protection (FADP) all demand that no client can access another client's data. That includes internal access.
In theory, this sounds straightforward. In practice, it fails regularly: a misconfigured permission, a shared Teams channel, a document in the wrong folder — and suddenly a contract belonging to Client A is visible to Client B. On a classic network drive, this happens daily without anyone noticing.
SharePoint can solve this problem permanently — but only if the structure is right from day one.
Two Architectures for Client Separation
Option 1: One Site per Client (Maximum Isolation)
Each client gets their own SharePoint site with its own permissions, document libraries and Teams group. Firm staff are added as members. External clients can be invited as guests — with time-limited access restricted to explicitly shared documents only.
Advantages:
- Complete technical isolation: no shared libraries, no overlapping permissions
- Each client has their own space, manageable independently
- Guest access for client-side lawyers or trustees is possible
- Simple archiving when the mandate closes (site set to read-only or archived)
Option 2: Central Site with Metadata-Based Separation (for smaller firms)
All client documents live in a central library, separated by metadata columns ("Client", "File number") and filtered views. Permissions are set at library level — only firm staff have access; external clients cannot access anything.
This option is simpler to administer but provides no technical isolation between client data. Suitable when no external guest access is needed and all staff are permitted to see all mandates.
Permission Design: What to Avoid at All Costs
| Mistake | Risk | Solution |
|---|---|---|
| Per-document permissions | Unmanageable, hard to audit | Always use groups, never individuals |
| "Everyone except guests" sharing | Internal client data visible to all staff | Define explicit groups per client |
| No access review after staff changes | Former employees retain access | Entra ID lifecycle management with automatic offboarding |
Microsoft Entra ID as the Foundation
SharePoint permissions work best when tied to Microsoft Entra ID groups rather than individuals. When a staff member leaves, deactivating their Entra account automatically revokes all SharePoint access — no manual removal from 30 different sites required.
What CNEXT Delivers for Law Firms and Tax Advisors
We have implemented client data separation for several Swiss law firms and tax advisors — from concept through Entra ID group structure to the finished SharePoint build with audit configuration. Typical project duration: 4–8 weeks depending on firm size and existing IT setup.
If you are still working on network drives or unstructured OneDrive storage today, there is a better way. Talk to us — we will show you exactly what a compliant solution looks like for your firm.
