Sovereign Cloud Explained: Residency, Control, Law
What sovereign cloud means: data residency, operational control and legal jurisdiction explained, how the EU assesses it and how to check a provider's claims.
EU cloudPublished
A sovereign cloud is a cloud service in which data, operations and legal control remain within a defined jurisdiction, in the European context the EU, so that no foreign government or company can access the data or shut the service down outside European law. The term is used loosely in marketing. To judge an offer, separate three levels: where the data is stored, who operates the systems, and which law the operator answers to.
Three levels of sovereignty
1. Data residency
Data residency means data is stored and processed in a specific location, for example in data centres in Germany or the EU. It is the easiest level to promise and verify, and almost every large provider offers it today through region selection. On its own, it says nothing about who can access the data.
2. Operational sovereignty
Operational sovereignty concerns who runs the systems: who administers servers, who has privileged access, where support staff sit, and whether encryption keys are under the customer’s or the provider’s control. A provider with operations staff and key management in the EU offers more control than one that runs EU regions from a global operations centre.
3. Legal sovereignty
Legal sovereignty asks which legal order the operator is subject to. A provider headquartered in the EU is primarily subject to EU and member-state law. A provider whose parent company sits outside the EU may also be subject to that country’s laws. The most cited example is the US CLOUD Act of 2018, under which US authorities can, under certain conditions, require US providers to disclose data under their control, including data stored outside the US.
| Level | Question | How to check |
|---|---|---|
| Data residency | Where is the data stored and processed? | Region choice, contract, sub-processor list |
| Operational sovereignty | Who operates the systems and holds keys? | Support model, admin access, key management options |
| Legal sovereignty | Which law can compel the operator? | Company seat, parent company, contractual commitments |
How the EU frames it
The European Commission published a Cloud Sovereignty Framework in October 2025 to assess cloud services in its own procurement. It measures sovereignty against eight objectives, ranging from strategic, legal and operational aspects to supply-chain transparency, technological openness, security and compliance with EU law, and classifies offers by assurance levels. Implementation guidance followed in 2026 (Commission news).
The framework is a procurement tool for EU institutions, not a law that binds companies. It is still useful as a checklist: if a provider claims sovereignty, ask how it would score on those objectives.
The market in 2026
Three types of offers compete for the label.
European providers such as OVHcloud, STACKIT, IONOS, Open Telekom Cloud or Scaleway combine EU seat, EU operations and EU data centres. Their argument is that all three levels are covered by default. The trade-off is a smaller range of services than the largest hyperscalers. An overview is in European cloud providers, a deeper comparison in STACKIT, IONOS Cloud and OVHcloud.
Sovereign variants of US hyperscalers separate infrastructure and operations for Europe. AWS launched its European Sovereign Cloud in January 2026 with a first region in Brandenburg, Germany, operated separately from its other regions. Other hyperscalers offer comparable constructions, sometimes with European partners. These offers address data residency and operations; how far they address legal sovereignty is debated and depends on the contractual and corporate structure.
Partner models in which a European company operates a hyperscaler’s technology under its own control aim at the same gap, particularly for public-sector customers.
How to evaluate a provider’s claim
- Ask which level is meant. “Sovereign” without specifics usually means data residency only.
- Check the scope. Sovereignty commitments often apply to selected services or regions, not the whole catalogue.
- Look at operations. Where are administrators and support located? Can you hold your own encryption keys?
- Look at ownership. Where is the parent company? Which authorities could make demands on it?
- Read the contract. How does the provider handle government requests, and does it commit to inform you and challenge them?
- Plan the exit. Sovereignty also means being able to leave: open standards, data export and portable workloads.
Who needs what
Public bodies, critical infrastructure operators, healthcare and companies whose customers require it contractually will usually need all three levels. Many SMEs are well served by an EU region with a solid data processing agreement and good security practice; data protection basics are covered in GDPR-compliant cloud hosting. If you decide to move, migrating from AWS or Azure to a European cloud outlines the steps.
This page provides orientation and is not legal advice. Involve your data protection officer and, where needed, legal counsel for your specific situation.
Frequently asked questions
Is a cloud sovereign if the data centre is in the EU?
Not necessarily. Data residency is only the first level. If the operator is subject to non-EU law that can compel it to hand over data, or if staff outside the EU administer the systems, the service is resident but not fully sovereign.
What does the US CLOUD Act have to do with it?
The CLOUD Act of 2018 allows US authorities, under certain conditions, to require US-based providers to disclose data in their possession, custody or control, including data stored abroad. That is why the provider's legal seat, not only the server location, matters in sovereignty discussions.
Do US hyperscalers offer sovereign clouds?
Several offer separate sovereign or EU-operated variants. AWS, for example, launched its European Sovereign Cloud with a first region in Brandenburg, Germany, in January 2026. Whether such constructions meet your requirements depends on your risk assessment and the contractual details.
Do small companies need a sovereign cloud?
Often not. For many SMEs, an EU region, a solid data processing agreement and good security practice are enough. Sovereignty becomes important for public bodies, critical infrastructure, health data, or customers who demand it contractually.
More in EU cloud
Hetzner vs. DigitalOcean: Which Cloud Fits Your App?
Hetzner vs. DigitalOcean compared on pricing model, EU locations, included traffic, managed services and company seat, so you can pick the right cloud.
VPS for Developers: 7 Providers Compared for Europe
Seven VPS providers for developers compared on company seat, European locations, billing, API and extras, with clear criteria instead of a vague ranking.