The sovereign cloud: Who really has control over your data?
Reading time: 11 minutes
Three American corporations currently process the majority of European corporate data. The cloud you use determines how much control you retain over your data – and how much you relinquish. This has implications for information security, data protection, compliance and your ability to act. Find out more in our article about how clouds work, the consequences of your choice of cloud provider, and what you can do to identify a sovereign cloud and make independent decisions about your data.
What is the cloud?
The term ‘cloud’ sounds like something ethereal and hard to grasp. Yet it is actually something very concrete: a network of servers in data centres. When you save a file to the cloud, it is not stored on your local hard drive, but on a cloud provider’s servers.
The cloud allows you to outsource storage space and computing power. The servers used for this are accessible via the internet, and the data can be accessed from anywhere. Clouds also serve as backups or for sharing programmes. This allows flexible access for several people, who can, for example, edit documents together.
What businesses and public authorities store in the cloud
Which provider you choose and whether it is a sovereign cloud is crucial, as cloud services now process the majority of a business’s or public authority’s digital content:
- Personal data: Sensitive data relating to staff, customers and citizens, e.g. payslips, customer databases or registration and social security data in the public sector
- Business and trade secrets: Design plans, research findings, price calculations, draft contracts and similar
- Communication data: Email threads, chat logs or video conference recordings, which often provide insights into internal decision-making processes
- Identity and access data: Login credentials, certificates and keys
- Particularly sensitive data categories: Health data, data held by domestic intelligence and security agencies, or data from judicial and social proceedings, as found primarily in the public sector and strictly regulated industries
Four cloud models
There are essentially four ways to use the cloud. Your choice of model and cloud provider has far-reaching consequences for cloud sovereignty and your control over your data:
- On-premises (On-Prem): Here, you use your own hardware on your own premises. As a company, for example, you own the servers, operate them yourself and bear full responsibility – and you have full control. The price you pay for this is a high level of in-house effort for hardware, maintenance, disaster recovery and security updates.
- IaaS (Infrastructure as a Service): As an organisation, you rent computing power and storage space, but no longer need to worry about hardware, cooling or power supply. That falls within the remit of the IaaS providers. With this model, you bring in another organisation, which reduces your level of control – particularly if you use one of the US providers such as Amazon Web Services (AWS), Microsoft Azure or Google Cloud Platform.
- PaaS (Platform as a Service): Here, the provider supplies an entire development platform, including databases, runtime environments and interfaces. Developers focus on their own application, whilst virtually everything is managed by the provider in the background. If you build your application deeply into provider-specific interfaces, you can only replicate it elsewhere at considerable expense. Control shifts noticeably towards the PaaS provider.
- SaaS (Software as a Service): In this model, the provider takes care of everything: software, infrastructure, updates and security. All that remains for the company is to use the ready-made interface. Examples include Microsoft 365 and Google Workspace. This model is very convenient, but you have the least insight into what happens to your data. Users of this model should be particularly discerning when selecting their providers.
mailbox’s digital workplace is the sovereign alternative to Microsoft and Google.
Data in focus: Four dimensions and their implications
Data protection
A cloud provider processes large amounts of data and communications. This provides a detailed picture of the organisation: who communicates with whom, when, about what, and at what level in the hierarchy? From a data protection perspective, this increases the significance of every single vulnerability: a single instance of unauthorised access can reveal a coherent picture of the entire organisation.
Information security
From an information security perspective, the following applies: the more systems and data are held by a single provider, the greater the damage if something goes wrong. This concentration is exacerbated when a large proportion of the public sector or several industries rely on the same hyperscalers. This gives rise to what is known as a concentration risk.
Digital sovereignty
Administrative data in the public sector affects not only individual citizens, but also the very functioning of the state itself. If, for example, data and systems relating to local authority infrastructure are held by a provider subject to a foreign legal system, part of the state’s capacity to act is shifted to a foreign jurisdiction. The same applies to sensitive business data.
Cyber security
This concentration makes cloud infrastructures an attractive target for attack. If an attacker gains access to the central identity system of a major cloud provider, they could potentially gain access to the data of thousands of customer organisations simultaneously. This yields a significantly higher return than an attack on a single on-premises system.
Cloud sovereignty: Europe is dependent on the US
Europe is structurally dependent on US hyperscalers: approximately 70 per cent of the EU market for cloud infrastructure is covered by AWS, Microsoft Azure and Google Cloud. Furthermore, US providers also dominate the productivity software sector, such as Microsoft 365. Microsoft currently has a virtual monopoly in the German public sector: Microsoft’s market share in Germany for Office products stands at over 90 per cent.
When deep-rooted dependence meets a non-transparent pricing model, the risk is exacerbated: Microsoft has, for instance, continuously increased the price of Microsoft 365 in recent years – including for the public sector. Furthermore, this one-sided dependency carries a higher risk of service disruption.
All the signs point to the need for greater digital self-determination. Yet it is precisely this deep-rooted dependency, resulting from the use of an entire IT ecosystem, that makes it so difficult to switch to other providers. This dependence, and the high potential for damage that comes with it, makes these applications – which are used almost universally in the public sector – attractive targets for cyber-attacks and a popular means of exerting pressure in geopolitical conflicts.
The truly sovereign cloud: distinguishing between server location and jurisdiction
Cloud providers’ data centres are located in fixed locations and are therefore subject, on the one hand, to the law of the respective country. In addition, the company operating the infrastructure is subject to the law of the country in which it has its headquarters. For international corporations, this means that they are also subject to the law of the parent company, even if the operating subsidiary is formally registered in Europe.
When you save a file to Google Drive, you are storing it on one of the numerous servers that Google operates worldwide – including in Europe. If the file is stored in one of these European data centres, this may seem reassuring at first glance. Furthermore, the contractual partner for European customers is often a European Google subsidiary.
However, this company ultimately belongs to Google LLC, which is registered in the US and is, in turn, part of the US-based Alphabet Inc. The parent company to which you entrust your data is therefore subject to US law. Neither the server location nor even the address of the contracting company alters this overarching control. The same applies to Microsoft and AWS.
US CLOUD Act: US law determines your data protection
The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act) has been in force since 2018. Under this law, US tech companies are obliged to grant US authorities access to data they store – even if the companies do not store the data in the US at all, but in Europe, for example. Under the law, IT companies may be prohibited from informing the individuals concerned. Users of these services may therefore not even be aware that they are affected by data access by US authorities.
A request from US authorities to Microsoft may therefore well concern the emails of a German organisation, even if the server is located in Germany and even if this contravenes the GDPR applicable in the EU. This structural dependence on US hyperscalers thus adds a further layer of dependence and poses a threat to Europe’s sovereignty.
In 2025, Microsoft’s then Head of Legal Affairs admitted under oath before the French Senate that the company cannot guarantee that European customer data is protected from access by US authorities – regardless of where the data is stored.
So-called ‘sovereign cloud’ offerings and European data centres do nothing to alter the fact that the US companies behind these services are ultimately subject to US law.
When the digital plug is pulled, dependence and sovereignty come to light
Furthermore, the US Supreme Court’s ruling in the ‘Trump v Slaughter’ case in June 2026 destroyed the foundation of transatlantic data protection: The ruling strengthens the powers of the US President and weakens the independence of the Federal Trade Commission (FTC), which is responsible for enforcing data protection principles in the US.
Another event from June 2026 shows that the control exercised by a foreign authority can extend to the very question of whether a service remains available at all: Anthropic, the US company behind the Claude models, was forced to disable access to two of its AI models on the direct orders of the US government. The software, which was already widely used, was subsequently no longer available worldwide.
A company that has built its processes on US IT infrastructure and is dependent on this ecosystem runs the risk of being rendered digitally incapacitated following an official directive from the US.
The choice of cloud provider determines your independence
If you hand over control of your infrastructure and data, you are giving up more than you might initially realise. Be clear about the areas where your digital sovereignty requires particularly critical decisions:
- Technical: The choice of cloud model determines, to a considerable extent, the extent of your control over your data.
- In terms of content: Be aware of which (sensitive) data you are entrusting to a cloud provider.
- Legal: Check whether the cloud providers under consideration are subject to foreign law, e.g. the US CLOUD Act, and what impact this has on information security and data protection.
- Political: When making your choice, bear in mind the consequences of geopolitical changes, the effects of which have long been felt. The Anthropic case illustrates that control affects not only data, but also the availability of a service.
- Economic: Check whether your choice of cloud provider is leading you into digital dependency or even vendor lock-in, and take active steps to counteract this.
Three key questions for identifying a sovereign cloud
The market for sovereign cloud solutions is growing, and with it the number of providers who use sovereignty as a selling point without structurally delivering on it. European data centres, GDPR certificates and ‘sovereign cloud’ labels are no guarantee that a service is actually free from foreign legal jurisdiction.
Anyone who fails to check carefully runs the risk of falling for so-called ‘sovereignty washing’ – that is, an offering that suggests independence but does not deliver on it. Three key questions help to distinguish genuine sovereignty from supposed sovereignty:
- Where is the parent company legally based?
- Where is the data stored – and on whose infrastructure?
- Is there verifiable evidence?
Make sure that behind the supposedly sovereign cloud lies a genuinely sovereign cloud, and that you do not fall victim to ‘sovereignty washing’. You can find support for this in the Tech Sovereignty Catalogue, Europe’s verified list for proven digital sovereignty. The catalogue helps to identify genuine European alternatives to Google, Microsoft and AWS. Providers listed in the Tech Sovereignty Catalogue must meet the criteria of the catalogue.
BSI C5: Guidance on evaluating cloud providers
Digital sovereignty affects every business, every public authority and every individual. So choose your cloud provider carefully. The BSI C5 catalogue provides a reliable framework for evaluating cloud providers.
The Cloud Computing Compliance Criteria Catalogue (C5) of the Federal Office for Information Security (BSI) is explicitly tailored to cloud services: It assesses cloud-specific requirements across 17 criteria domains, including data localisation, client isolation, transparency regarding subcontractors and processing locations, and the ability to exit the service. For companies wishing to evaluate cloud providers in a structured manner, and for organisations operating in a regulated environment, a C5 certificate is therefore more meaningful than ISO 27001 certification alone.
Find out more about our safety and quality standards