Knowledge · Technology and sovereignty
How do you assess cloud sovereignty?
You assess cloud sovereignty by asking who can access your data and how easily you can leave a provider again. That covers the storage location, the provider's jurisdiction, control over the encryption keys, dependence on individual services and the cost of an exit. Providers subject to US law can be compelled under the CLOUD Act to hand over data, even when the servers are located in Europe.
Author Thomas Wassum, Managing PartnerLast reviewed
Legal information as of 7 October 2026. This article is not legal advice.
The concept
Sovereign means staying in control.
Cloud sovereignty means that a company decides for itself about its data in the cloud: where it is stored, who can read it, who manages the keys and whether it can switch providers without putting the business at risk. Sovereignty is therefore not a property of a data center but of a contract, a jurisdiction and an architecture. It can be tested once the criteria are set.
Assessment criteria
- Storage location and the provider's jurisdiction
- Access by third parties, including authorities
- Control over keys and identities
- Ability to switch and the cost of an exit
- Cost over the full lifetime
Legal position
Why location is not enough.
The US CLOUD Act requires providers subject to US law to disclose data in their possession, custody or control, regardless of where that data is stored. Under FISA Section 702, US authorities can also compel providers to assist in the targeted surveillance of persons outside the United States. A data center in Europe does not change that as long as the provider itself is subject to US law.
For personal data, an adequacy decision of the European Commission has applied to certified US companies since July 10, 2023: the EU-US Data Privacy Framework. It makes transfers easier but does not change the disclosure obligations under US law. Its predecessor, the Privacy Shield, was declared invalid by the Court of Justice of the European Union in 2020 (Schrems II).
As of October 2026 · not legal advice
The approach
The same yardstick for every option.
A robust assessment sets the criteria before any offer is on the table: cost over the full lifetime, risks, operating effort, dependence on individual providers and the question of who can access the data. Your own data center, European and international clouds and hybrid models are then measured against the same yardstick. The result is a recommendation that holds up in front of shareholders and auditors.
Since September 12, 2025, the Data Act has also governed switching between cloud providers. The ability to switch has thus become a criterion you can demand in a contract. We treat control over your data as a criterion to be tested, not as a vendor's promise.
As of October 2026 · not legal advice
Questions from leadership
What executives ask about it.
Is a European subsidiary of a US provider enough?
Not without checking. What matters is whether the provider or its parent company is subject to US law and whether the data falls within its control. That depends on the operating model and belongs in the assessment, not in an assumption.
As of October 2026 · not legal advice
What does key control mean?
That the keys used to encrypt your data are under your control, not the provider's. If the provider holds the key, it can read the data and therefore also hand it over. Key control is one of the most effective criteria in the assessment.
Is the assessment only worthwhile in regulated industries?
No. It pays off wherever customer data, engineering data or trade secrets go into the cloud, and before any decision that ties a company to a provider for many years.
Author and sources
Who answers, and what it rests on.
Sources and further reading
- 18 U.S.C. § 2713 (CLOUD Act), Legal Information Institute, Cornell Law School (external site)
- 50 U.S.C. § 1881a (FISA Section 702), Legal Information Institute, Cornell Law School (external site)
- Court of Justice of the European Union: judgment of July 16, 2020, Case C-311/18 (Schrems II) (external site)
- Commission Implementing Decision (EU) 2023/1795 (EU-US Data Privacy Framework) (external site)
- Regulation (EU) 2023/2854 (Data Act) (external site)
Page last reviewed:
Read on
The next question and the path behind it.
Related question
When is a company AI-ready?
When use cases, data, technology and rules fit together. Data first, then the model.
Related question
How do you evaluate alternative enterprise architectures?
Several feasible variants, future scenarios and ten criteria instead of a premature target architecture.
Matching service
Infrastructure
How SIMO handles this topic in an engagement: approach, results and the questions executives ask.
See how SIMO structures and evaluates alternatives.
Your next step
From the answer to the decision.
The Decision Readiness Check shows how ready your own decision is. If you would rather talk directly, book an initial call with a managing partner.
How ready is your decision? Check it in 3 minutes.
45 minutes, and you will know whether SIMO fits your decision.
Or call us: +49 6021 625 63 40