# Spark Mail Data Protection, What IT Admins Need to Know

> Spark Mail at work: how its proxy architecture works, what access Spark gets, the allocation of roles, professional secrecy and alternatives.

- Source: https://www.sidd.swiss/en/insights/spark-mail-data-protection/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Oliver Stutz
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Spark Mail by Readdle is one of the most popular email clients for iOS, macOS, Windows and Android. It offers a modern UI, smart inbox features, team inboxes and AI capabilities. Yet exactly these convenience features are problematic from a data-protection standpoint: Spark does not connect your device directly to your mail server but routes a substantial part of the traffic via its own **mail-proxy servers** at Readdle. That architectural decision has significant consequences for SMEs, hospitals, law firms and any organisation handling professional secrecy or sensitive personal data.

This article shows:

- how Spark's mail-proxy architecture works technically;
- which OAuth permissions Spark obtains from Microsoft 365, Google Workspace or iCloud;
- which personal data Readdle processes as data processor and which as an independent controller;
- why holders of professional secrecy (Art. 321 of the Swiss Criminal Code) can hardly use Spark in its current form;
- which configuration paths still exist (self-hosted mode, on-prem setup);
- and which alternatives are realistic for Swiss organisations.

Legal anchors: Federal Act on Data Protection (DSG, Art. 6, 8, 9, 16, 22, 24), GDPR (Art. 28, 32, 44 et seq.), Art. 321 Swiss Criminal Code (professional secrecy), Art. 47 Swiss Banking Act, Art. 35 CISA, FINMA Circular 2018/3, Schrems II.

## How Spark Mail works technically

Unlike a classic email client (Outlook, Apple Mail, Thunderbird), which communicates directly with your mail server via IMAP/SMTP, Spark places its own cloud servers between device and mail server. Specifically:

1. During account setup, you hand Spark your credentials or an OAuth token for Microsoft 365 / Google Workspace.
2. Spark stores these credentials in the Readdle cloud (historically the US region, more recently EU region).
3. Readdle servers poll your mailbox on behalf of the Spark client and push notifications to your device.
4. Specific features (Snooze, Send Later, Team Inbox, AI Compose, link previews) require mail content or metadata to be processed and partly temporarily stored on Readdle servers.

This is **not an end-to-end architecture**. Even when your mail server is hosted in Switzerland (e.g. Infomaniak, Swisscom, Hostpoint, Exchange on-prem), every email passes through a US or EU cloud hop at Readdle. Under the DSG, this is a disclosure to Readdle as data processor (Art. 9 DSG) and a cross-border disclosure under Art. 16 DSG as soon as Readdle processes in a third country without an adequate level of protection.

## OAuth scopes and what Spark can actually see

When you connect Spark to Microsoft 365 or Google Workspace, the app requests OAuth permissions that go significantly beyond what one would expect from a pure email client. Typically:

- **Mail.ReadWrite, Mail.Send**, read, write and send all emails;
- **Calendars.ReadWrite**, calendar access;
- **Contacts.ReadWrite**, full address-book access;
- **offline_access**, refresh tokens that allow Readdle to access your mailbox practically without limit, even when the client is closed;
- **Files.Read.All**, with the attachment feature enabled, also read access to OneDrive / Google Drive.

These scopes technically allow Readdle to access all mailbox content, not just incoming push notifications, but the entire archive. Microsoft and Google administrators see Spark in Entra ID / Google Workspace Admin as an enterprise app with a long permission list. An admin approval workflow is essential; without it, individual users can authorise Spark freely.

That Readdle *can* technically access does not mean it *does*, the Readdle privacy policy limits the use to providing the services. From a regulatory standpoint, however, the **access capability** remains the audit-relevant factor, especially under the CLOUD Act and FISA 702.

## Role allocation, processor or controller

Under the DSG and the GDPR, Readdle wears two hats:

1. **Data processor** for the mail content, contacts and calendars you handle via Spark. This requires a data processing agreement (DPA) under Art. 9 DSG / Art. 28 GDPR. Readdle offers such a DPA, but for many Swiss use cases (hospitals, law firms, banks) it is not sufficient because it neither provides for Swiss law as jurisdiction nor contains FINMA audit rights.
2. **Independent controller** for telemetry and usage data of the Spark app (crashes, feature usage, account linkage), for marketing data and certain AI training data, subject to opt-in. This secondary processing must be transparently disclosed to your staff in your employee privacy notice.

Particularly critical: **when Spark is installed privately by employees and business emails flow via Readdle without the IT team's knowledge**, there is an unauthorised disclosure to a processor. This violates the duty of care under Art. 8 DSG and can trigger a breach notification under Art. 24 DSG once it creates a high risk for data subjects.

## Professional secrecy and regulated sectors

For holders of professional secrecy, Spark in its default configuration is hardly defensible. Art. 321 of the Swiss Criminal Code (lawyers, notaries, physicians, pharmacists) and Art. 47 of the Banking Act (banking secrecy) require that protected information may only be passed on to third parties in narrowly defined statutory cases or with consent.

Disclosure to Readdle is a disclosure to a third party. Even with a DPA in place, the question remains whether a client would have consented to disclosure of their correspondence to a US provider. Mainstream doctrine (see the FMH cloud opinions, SwissBanking's cloud position and the supervisory practice of the bar associations) requires either:

- a written consent of the client or patient to cloud processing, or
- a technical architecture in which the cloud component cannot technically see the content (end-to-end encryption, zero knowledge).

Spark satisfies neither criterion out of the box. For FINMA-regulated institutions, Circular 2018/3 additionally requires every material outsourcing relationship to be reported to FINMA and equipped with audit rights, a requirement that Readdle does not meet in its currently publicly offered form.

## Compliance paths that may still work

If you want to use Spark in your organisation, realistic paths exist, each with trade-offs:

1. **Spark for Teams Self-Hosted (Enterprise tier):** Readdle offers larger customers a self-hosted setup in which the mail-proxy function runs in your own infrastructure. This eliminates third-country disclosure for mail content but retains processing for telemetry and account synchronisation.
2. **Tenant-level whitelisting:** Microsoft 365 / Google Workspace admins can either block Spark as an enterprise app or enable it with tightly scoped permissions and admin approval. This prevents unauthorised private installations.
3. **Strictly private use:** If employees use Spark only for private email accounts, the employer is not affected from a data-protection standpoint, provided no business email flows through the private account. The separation must be clearly defined in the IT usage policy.
4. **DPIA and risk balancing:** For non-regulated organisations with low secrecy density, a DPIA may conclude that Spark is acceptable, when the DPA, EU region, logging and exit strategy are cleanly documented.

Crucially, none of these options changes the basic architecture: Spark remains a cloud-intermediated app, not a classic direct client.

## Alternatives for Swiss organisations

If Spark cannot be defended, well-established alternatives match the Swiss compliance bar better:

- **Outlook (Microsoft 365):** direct sync via Exchange ActiveSync / Graph, no third party between client and server. Fully manageable with Intune and Conditional Access.
- **Apple Mail:** direct IMAP/EAS connection, no cloud intermediation. Often the simplest option for pure Apple fleets.
- **Mozilla Thunderbird:** open source, full self-control, native S/MIME and PGP support.
- **Proton Mail / Tutanota:** end-to-end-encrypted mail providers with their own clients, relevant for holders of professional secrecy and organisations with high confidentiality requirements.
- **Infomaniak Mail / kSuite:** Swiss providers with webclient and native apps; a native Swiss cloud solution.

If you do not want to give up the convenience of a modern inbox experience, Outlook Mobile with Microsoft Defender for Cloud Apps and a clean Conditional Access policy is usually the best balance between UX and compliance.

## How SIDD supports you

SIDD regularly assesses mail clients and collaboration tools within platform audits, DPIA mandates and ISO/IEC 27001 projects. For Spark Mail, we deliver a clear recommendation per use case, including the question whether the self-hosted tier is economically viable or whether an alternative is the better path.

Typical services:

- DPIA for Spark Mail or comparable cloud-intermediated mail clients;
- review of your Microsoft 365 / Google Workspace tenant configuration for unauthorised OAuth apps;
- drafting or updating the IT usage policy with a clear private/business split;
- mandates as external [data-protection advisor](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) or external [CISO/ISB](https://www.sidd.swiss/en/services/vciso);
- ISO/IEC 27001 support ([ISO 27001 / ISMS](https://www.sidd.swiss/en/services/iso-27001-isms));
- awareness training for employees ([IT security workshops](https://www.sidd.swiss/en/services/it-security-workshop-sme)).

Contact us via the [contact form](https://www.sidd.swiss/en/contact) or request a quote via the [quote form](https://www.sidd.swiss/en/quote). We deliver a rapid initial assessment for Spark Mail within two working days.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
