---
title: "How do you assess cloud sovereignty?"
description: "Cloud sovereignty depends on jurisdiction, key control and the ability to switch, not on location. Criteria, legal position with date, and an approach."
canonical: "https://simo-online.com/en/knowledge/cloud-sovereignty"
---

# How do you assess cloud sovereignty?

Cloud sovereignty depends on jurisdiction, key control and the ability to switch, not on location. Criteria, legal position with date, and an approach.

Dargestellte Fassung: https://simo-online.com/en/knowledge/cloud-sovereignty

## How do you assess cloud sovereignty?

You assess cloud sovereignty by asking who can access your data and how easily you can leave a provider again. That covers the storage location, the provider's jurisdiction, control over the encryption keys, dependence on individual services and the cost of an exit. Providers subject to US law can be compelled under the CLOUD Act to hand over data, even when the servers are located in Europe.

- Storage location alone does not make you sovereign.
- What matters is jurisdiction, key control and the ability to switch.
- Every option is measured against the same criteria, agreed in advance.
- For sovereignty-critical data, we do not recommend US hyperscalers.

### Sovereign means staying in control.

Cloud sovereignty means that a company decides for itself about its data in the cloud: where it is stored, who can read it, who manages the keys and whether it can switch providers without putting the business at risk. Sovereignty is therefore not a property of a data center but of a contract, a jurisdiction and an architecture. It can be tested once the criteria are set.

Assessment criteria

- Storage location and the provider's jurisdiction
- Access by third parties, including authorities
- Control over keys and identities
- Ability to switch and the cost of an exit
- Cost over the full lifetime

### Why location is not enough.

The US CLOUD Act requires providers subject to US law to disclose data in their possession, custody or control, regardless of where that data is stored. Under FISA Section 702, US authorities can also compel providers to assist in the targeted surveillance of persons outside the United States. A data center in Europe does not change that as long as the provider itself is subject to US law.

- For personal data, an adequacy decision of the European Commission has applied to certified US companies since July 10, 2023: the EU-US Data Privacy Framework. It makes transfers easier but does not change the disclosure obligations under US law. Its predecessor, the Privacy Shield, was declared invalid by the Court of Justice of the European Union in 2020 (Schrems II).

### The same yardstick for every option.

A robust assessment sets the criteria before any offer is on the table: cost over the full lifetime, risks, operating effort, dependence on individual providers and the question of who can access the data. Your own data center, European and international clouds and hybrid models are then measured against the same yardstick. The result is a recommendation that holds up in front of shareholders and auditors.

- Since September 12, 2025, the Data Act has also governed switching between cloud providers. The ability to switch has thus become a criterion you can demand in a contract. We treat control over your data as a criterion to be tested, not as a vendor's promise.

### Is a European subsidiary of a US provider enough?

Not without checking. What matters is whether the provider or its parent company is subject to US law and whether the data falls within its control. That depends on the operating model and belongs in the assessment, not in an assumption.

### What does key control mean?

That the keys used to encrypt your data are under your control, not the provider's. If the provider holds the key, it can read the data and therefore also hand it over. Key control is one of the most effective criteria in the assessment.

### Is the assessment only worthwhile in regulated industries?

No. It pays off wherever customer data, engineering data or trade secrets go into the cloud, and before any decision that ties a company to a provider for many years.

18 U.S.C. § 2713 (CLOUD Act), Legal Information Institute, Cornell Law School

50 U.S.C. § 1881a (FISA Section 702), Legal Information Institute, Cornell Law School

Court of Justice of the European Union: judgment of July 16, 2020, Case C-311/18 (Schrems II)

Commission Implementing Decision (EU) 2023/1795 (EU-US Data Privacy Framework)

Regulation (EU) 2023/2854 (Data Act)
