EU sovereignty

Cloud Sovereignty: Why EU Hosting and EU Jurisdiction Matter

A data centre in Frankfurt does not put your data beyond the reach of US law. Here is why legal jurisdiction — not just server location — decides cloud sovereignty, and what European organisations can do about it.

Ask most IT buyers whether their cloud is "in Europe" and they will point to a data centre map: Frankfurt, Dublin, Paris. The servers are on European soil, the latency is good, the marketing says "EU region." It feels sovereign. It is not — at least not in the sense that matters when a foreign government comes asking for the data.

Cloud sovereignty is a question of law, not geography. It asks: whose courts, whose subpoenas, whose emergency orders can compel access to your data, and under which safeguards? A hyperscaler can store your files in Frankfurt and still be legally bound to hand them to Washington. Understanding that gap — between where data sits and who ultimately controls it — is the single most important step for any European business or public body choosing a cloud today.

Data residency is not data sovereignty

The industry sells two things under one word. Data residency means your data physically lives in a specific country or region. Data sovereignty means your data is governed exclusively by the laws of that jurisdiction, and no foreign authority can lawfully compel access.

A US provider with EU data centres gives you residency. It does not give you sovereignty. The physical location of a disk is almost irrelevant to a legal access order served on the company that operates it. What matters is the provider's corporate nationality and its chain of ownership. If the parent company is subject to US law, so — in practice — is your data, wherever the bytes happen to rest.

This distinction is not academic. It changes which contracts you can sign, which workloads you can safely place in a given cloud, and what you must tell your own regulators, works councils, and customers.

The CLOUD Act: how far US law reaches

The US Clarifying Lawful Overseas Use of Data Act, passed in 2018, is the clearest expression of the problem. It obliges US-based providers to produce data in their "possession, custody, or control" when served with a valid US legal order — regardless of where in the world that data is stored. A server in Ireland or Germany offers no shelter.

The reach is extraterritorial by design. US authorities can compel a provider to hand over personal, corporate, or sensitive data, often without prior notice to the affected users or to European regulators. The trigger is not where the data is; it is whether the company falls under US jurisdiction — which every US-headquartered firm and, arguably, their EU subsidiaries do.

For a European organisation this means a hard truth: choosing a US cloud provider, even one running entirely on European infrastructure with European staff, does not remove the legal pathway by which US law can reach your data.

Where EU and US law collide

European law pushes in the opposite direction. Under the GDPR, Article 48 says a court or authority order from a non-EU country is only enforceable in the EU if it rests on an international agreement such as a mutual legal assistance treaty. The CLOUD Act largely bypasses that route — putting providers in a genuine bind between two legal systems.

The Court of Justice underlined the stakes in its 2020 Schrems II ruling, which struck down the EU-US Privacy Shield precisely because US surveillance law did not offer European data subjects adequate protection or redress. Transfers were left on shaky legal footing until the EU-US Data Privacy Framework adequacy decision in 2023 restored a lawful transfer mechanism — though critics note it rests on the same US legal architecture and faces likely challenge.

The newer EU Data Act, in force since 2024 and applying from September 2025, goes further for non-personal data: it requires cloud providers operating in the EU to put technical and organisational safeguards in place against unlawful third-country government access, and to challenge orders that conflict with EU law. The direction of travel is clear — but so is the underlying conflict.

The rise — and limits — of "sovereign cloud"

The hyperscalers have heard the concern and answered with "sovereign cloud" offerings. AWS opened its European Sovereign Cloud in Brandenburg in early 2026, structured as a standalone German entity with EU-based leadership and physically isolated infrastructure. Microsoft has expanded Azure Local and Microsoft 365 Local for sovereign and disconnected scenarios. In Germany, Delos Cloud offers a Microsoft-based stack aimed at the public sector.

These are serious engineering efforts and they genuinely raise the bar on data residency, operational control, and local staffing. But read the fine print. Where the ultimate parent remains US-based, the CLOUD Act argument does not simply disappear — it is reduced, not removed. At the December 2025 Gaia-X summit, European voices were blunt: for the most sensitive workloads, the highest level of sovereignty is only achievable through providers actually headquartered in Europe.

"Sovereign" is a marketing word before it is a legal one. Treat each offering as a claim to be verified against ownership structure, contractual guarantees, and the specific access-request commitments in writing — not as a settled fact.

The EUCS certification debate

Europe tried to turn sovereignty into a checkbox with the EU Cybersecurity Certification Scheme for Cloud Services (EUCS), developed under the Cybersecurity Act. Its most contentious element was an "immunity" requirement: to reach the highest assurance level, a provider would have had to be legally shielded from non-EU jurisdiction — in practice meaning EU headquarters and EU ownership.

That requirement was stripped from the 2024 draft after heavy lobbying from some member states and industry bodies, so that non-EU providers would not be excluded from the top tier. Digital-sovereignty advocates called it a retreat; US industry welcomed it. The fight is not over: the Council has pressed the Commission and ENISA for a clearer framework, and sovereignty criteria may yet return through national rules or complementary legislation such as the Cloud and AI Development Act.

The lesson for buyers: certification schemes are politically contested and still moving. Do not outsource your own risk assessment to a label that may or may not include the guarantees you need.

Europe's own stack is real

The encouraging news is that credible European alternatives exist across the stack, and public bodies are proving they work at scale. The German state of Schleswig-Holstein has been migrating roughly 30,000 workstations off Microsoft — moving to LibreOffice, Linux, and Open-Xchange with Thunderbird — and completed a shift of more than 40,000 mailboxes and over 100 million emails and calendar entries off Exchange and Outlook in October 2025, saving eight-figure licensing costs and drawing interest from other governments.

At the infrastructure layer, providers such as OVHcloud, Scaleway, Hetzner, IONOS, and Exoscale offer EU-headquartered hosting outside US jurisdiction. For the digital workplace, Germany's openDesk (developed via ZenDiS) and tools like Nextcloud provide a sovereign alternative to the big collaboration suites. Gaia-X, despite a rocky start, has released its Trust Framework 3.0 and seen its first providers certified at its highest label level.

None of this is a like-for-like drop-in for every use case, and honesty about the migration effort matters. But the claim that "there is no European alternative" is no longer true.

What decision-makers should do now

Start by classifying your workloads. Not everything needs sovereign hosting — but personal data on citizens and patients, source code, legal files, and strategic business data deserve a jurisdiction test, not just a residency check. Ask each provider directly, in writing: who is your ultimate parent, which laws bind you, and what will you do if a foreign authority serves an access order?

Read contracts for the substance behind the sovereignty label: ownership structure, operational control by EU staff, encryption with keys you hold, and explicit commitments to notify and to challenge unlawful requests. Where the answers are weak for sensitive data, move that data to an EU-headquartered provider — and treat the rest as a managed, documented risk.

Cloud sovereignty is not an all-or-nothing purity test; it is risk management with the map drawn correctly. Know where your data lives, know which flag flies over the company that controls it, and choose deliberately. European alternatives now exist for organisations ready to switch — the question is no longer whether you can, but which workloads you should move first.

Ready to become more independent?

Explore European alternatives to the services you use every day.

Explore alternatives