Skip to content

Sovereign clouds: can Europe protect its data from foreign laws?

Man in office pointing at digital map of Europe with security icons, holding EU card by laptop on desk

At the start of last year, Karim Khan, prosecutor of the International Criminal Court (ICC), lost access to his work email account, a service provided by the US company Microsoft. Shortly afterwards, his bank accounts were frozen. Meanwhile, US staff at the court in The Hague, Netherlands, were warned that travelling to the United States could result in their detention.

In February 2025, US President Donald Trump signed an executive order imposing sanctions on the court in response to the arrest warrants issued for Israeli Prime Minister Benjamin Netanyahu - one of Washington’s principal allies - and former Defence Minister Yoav Gallant. The repercussions, however, extended beyond politics. According to the Associated Press, some organisations stopped working with the ICC, while certain partners avoided replying to its messages.

Suddenly, a decision made outside Europe had affected the operation of an international institution through critical digital services controlled by a non-EU company. The incident highlighted a vulnerability now central to the technology debate: reliance on infrastructure and platforms beyond European control.

“Organisations in regulated sectors such as energy, finance, healthcare and public administration understand that data and, increasingly, AI [Artificial Intelligence] are critical to competitiveness and security. This reinforces the importance of protecting sensitive workloads and ensuring compliance. As cyber threats, geopolitical instability and fragmented regulations increase, digital sovereignty becomes a strategic priority, determining where data resides, who controls it, how AI is trained and which technology partners can be trusted,” says Carla Arend, research director for cloud computing in Europe at International Data Corporation (IDC), in a consultancy study published in March 2026.

The rise of sovereign clouds

It is against this backdrop that so-called sovereign clouds have begun to take shape. In practical terms, they are cloud-computing infrastructures built to meet stringent requirements on data location, security and regulatory compliance.

Germany’s Schwarz Group, the owner of Lidl, decided in 2021 to build its own infrastructure after determining that the market’s existing offerings could not ensure that its customers’ data would be kept in Germany and Austria. Soon afterwards, the group’s technology division, Schwarz Digits, began providing storage services to third parties, including SAP and Bayern Munich. It now operates seven data centres and records annual revenue of €1.9 billion.

Unlike conventional clouds, which are run globally and are often subject to foreign laws, sovereign clouds aim to ensure that information is stored and managed within a specific country or region, limiting exposure to decisions taken elsewhere.

The model has gained particular momentum in more sensitive sectors, including public administration, defence and healthcare, where safeguarding critical data and maintaining continuity of service are seen as essential.

Portugal is starting to feature on the map. In April, Amazon Web Services (AWS) unveiled AWS European Sovereign Cloud, a European cloud-computing infrastructure designed to meet the European Union’s digital-sovereignty requirements.

This cloud is based in Germany, where its major data centres are located. From there, AWS is establishing local extensions - known as local zones - in countries including Portugal, Belgium and the Netherlands. “It is local infrastructure connected to the core infrastructure, designed to serve customers with particular requirements concerning data kept within the country or applications that need low latency,” Stéphane Israël, managing director of AWS European Sovereign Cloud, told Expresso.

The scheme forms part of a €7.8 billion investment in Germany. The company has not disclosed a specific figure for its Portuguese operation, nor said when it will become operational. Even so, AWS estimates point to a direct and indirect contribution of €3 billion to the Portuguese economy and the creation of 17,000 jobs.

How is data sovereignty secured in sovereign clouds?

To ensure data remains under European control and is shielded from external interference, Stéphane Israël identifies several “additional safeguards” which, he says, set this cloud apart from others. According to him, not only primary information - such as files, databases and company content - but also so-called “metadata” - information associated with the use and administration of that data - will remain in Europe.

There is also “operational autonomy”. “This cloud is completely independent. It does not need the others to operate. It is managed by European operators, who must comply exclusively with European rules,” he says, adding that roughly 400 professionals run the operation. “Some of them have what we call a source-code replica. This means that, should a serious disruption occur, European Sovereign Cloud has every means needed to continue operating independently, regardless of what happens around it,” he explains.

European Sovereign Cloud is set up as a separate legal entity in Germany. “We take personal responsibility if we fail to honour these commitments [European legislation]. We are accountable to an advisory board made up of five European citizens, three Amazon employees and two independent members,” the AWS executive says.

It also has an independent monitoring and verification mechanism. AWS has established a dedicated set of rules - known as the Sovereign Reference Framework - setting out the requirements to be met, alongside external audits intended to ensure those obligations are genuinely observed. “They are not just promises,” he says, arguing that the model ensures the commitments made are actually delivered.

Are the data genuinely protected?

Yet even with these safeguards, how far are such data truly protected from foreign legislation? In March 2018, the United States enacted the CLOUD Act (Clarifying Lawful Overseas Use of Data Act). According to the US Department of Justice, the law enables US authorities to demand access to data held by companies headquartered in the country, “wherever they are located”, as part of investigations into serious crimes such as terrorism or cybercrime.

The scope of this legislation has fuelled concerns - especially in Europe - about the real level of data control and protection. In an opinion piece published in Forbes Portugal, Alexandre Carvalho, country director at Colt Technology Services, describes “a direct legal clash that calls into question autonomy and trust in global digital infrastructure”.

“The truth is that the CLOUD Act and the European Union’s General Data Protection Regulation (GDPR) are, in essence, incompatible. It is not possible to comply fully with both. One establishes extraterritorial reach for access by law-enforcement authorities; the other protects data sovereignty and individual rights. Companies operating across both jurisdictions are navigating obligations that are, in practice, mutually irreconcilable,” the executive wrote.

Figures from Synergy Research Group show that Amazon, Microsoft and Google, all US companies, jointly accounted for 63% of worldwide investment in cloud-infrastructure services in the third quarter of 2025. This means a substantial share of corporate and institutional data globally falls, directly or indirectly, under providers subject to US law.

Stéphane Israël acknowledges the complexity of the international legal framework. “All large companies operate in a world of legal complexity and extraterritoriality,” he says. Nevertheless, he argues that the answer lies in strengthening additional guarantees within European infrastructure itself. In AWS’s case, he stresses that European Sovereign Cloud governance is based on compliance with European law and a duty to act “in the best interest” of that structure.

In practice, he adds, there is no record of European data having been provided to US authorities. “Since 2020 [the year we began compiling this type of statistical information], we have never been in a situation where we had to disclose data located in Europe and belonging to a European Government or a European company to the United States administration,” he assures.

A similar view comes from another of the leading European players in this segment. SAP - which is also developing its own sovereign-cloud offering - recognises that laws such as the CLOUD Act raise questions, but argues that the risk depends primarily on how systems are designed.

“SAP’s approach focuses on ensuring that data location, system operations and access control are anchored in the relevant national jurisdiction and legal framework. In sovereign-cloud configurations, data are processed locally, operations are carried out by entities subject to local law, and access is tightly defined, controlled and auditable,” Martin Merz, president of SAP’s Sovereign Cloud division, told Expresso.

He points to Delos Cloud in Germany - a sovereign cloud developed for the public sector - as an example where, he says, there is a “clear legal and operational separation, ensuring that external providers have no direct access to customer data”.

“This does not remove the legislation, but it significantly reduces practical exposure and creates a transparent, legally grounded environment in which data governance follows national law and clearly defined responsibilities,” Martin Merz adds.

Asked about Europe’s dependence on foreign technology, Martin Merz rejects the notion that digital sovereignty requires a break with major international providers. “It is not about doing everything ourselves,” he says.

In that respect, he emphasises that using infrastructure from companies such as AWS or Microsoft is not ruled out, provided they meet strict requirements established by the authorities. The decision does not rest with the company itself, Martin Merz says, but with supervisory bodies such as BSI, Germany’s cyber-security agency, which assess and validate whether those solutions meet sovereignty criteria before they can be used.

Comments

No comments yet. Be the first to comment!

Leave a Comment