Beyond ownership: Cloud sovereignty by design

Alert
|
8 min read

Digital sovereignty has become one of the defining themes of European Union (EU) technology policy. Over the past years, the EU and its Member States have introduced a steady stream of laws and initiatives addressing who controls the infrastructure, software, and data behind the European economy and its public services. These measures respond to a convergence of pressures: cybersecurity incidents, geopolitical fragmentation, export controls, and a broader reassessment of technology dependence.

The most recent step is the European Technological Sovereignty Package, published by the European Commission on 3 June 2026. Its centerpiece, the proposed Cloud and AI Development Act (CADA), aims to reduce the EU's reliance on third countries for cloud computing through a single, harmonised sovereignty framework with auditable criteria at different sovereignty levels, the most recent attempt to turn digital sovereignty from a policy concept into binding legal criteria.

The difficulty is that "sovereignty" has no single agreed meaning. It can mean data sovereignty (control over where data sits and who can access it), technological sovereignty (the ability to build and run critical infrastructure without depending on a small number of foreign suppliers), or a broader kind of operational independence from foreign government influence. This piece uses the term in that broader, practical sense: the ability of a customer, or its supplier, to keep a service running and its data protected from unwanted legal or government interference in line with applicable laws. In practice, some European businesses treat this as a black-and-white question, assuming that a provider owned or headquartered outside the EU fails the test at the first hurdle, while an EU-owned provider automatically passes it. This shortcut does not hold up to scrutiny and can lead businesses to ask their suppliers the wrong questions.

Why ownership alone does not answer the sovereignty question

The first common question when assessing a provider's sovereignty is a simple one: where is the entity operating the infrastructure established, and where is their parent company incorporated? That instinct is not unreasonable, and regulators do not ignore it either, as control may be a channel through which a third country's laws reach into the EU.

However, treating the parent company's country of origin as decisive would be an oversimplification — and a legally inaccurate one. EU instruments touching on sovereignty and resilience, from NIS2 to the Cybersecurity Act, the Foreign Subsidies Regulation, and the proposed CADA, all look past the parent company to a wider set of operational, contractual, and technical facts. Those facts, not the ownership chart, are what actually determine exposure.

A wholly EU-owned provider that outsources support to a third country, stores data outside the EU, or that cannot demonstrate appropriate sovereignty-related governance safeguards remains exposed regardless of its ownership. Conversely, a non-EU-owned provider may still be free of that exposure if appropriate safeguards are in place. To illustrate: an EU-headquartered and EU-owned cloud provider that operates data centres exclusively within EU countries such as France and Belgium may nonetheless maintain group sales companies in a third country, for example China. That cloud provider could, under Chinese law, be served with a data disclosure order by Chinese authorities.

Corporate structure alone does not give a clean answer: an EU subsidiary of a non-EU parent can meet demanding sovereignty criteria, while a nominally "European" provider that depends on foreign-controlled subcontractors or support functions may not.

Extraterritoriality, data protection, and conflict of laws

The legal dimension of sovereignty is less about the nationality of shareholders and more about who can compel a provider to act, and under what law. This is an objective, factual test independent of any single framework. Several factors matter together — not one in isolation — including whether the provider's governance structure, technical and operational measures, and contractual commitments include appropriate sovereignty safeguards and whether the entity holding the data is itself within reach of a requesting state, typically through incorporation, business presence, or possession, custody, or control of the data.

Extraterritorial reach in practice

The US CLOUD Act illustrates how this plays out: it lets US legal orders reach data that a provider subject to US jurisdiction holds abroad, and creates a parallel channel for qualifying foreign governments to seek data directly. This matters because a provider operating internationally can face conflicting disclosure obligations under more than one country's law at once.

Non-US entities, including EU-based providers, can themselves fall under US jurisdiction. Where an entity's contacts with the US are so continuous and systematic as to render it "essentially at home" there, US courts can treat it as subject to "general personal jurisdiction". In practice, this means that an EU-headquartered company with substantial US operations — offices, revenue, or customers — could itself be subject to US disclosure orders, regardless of where the data sits. This risk also arises where EU-based providers have connections to other non-EU jurisdictions like Canada, as we will discuss further below.

In any case, data access requests in relation to customer content are rare in practice and US Courts restrict their use to address only the most serious violations and crimes like terrorism, the sexual exploitation of children or cross-border cybercrime.

EU law and conflict of laws

EU law does not override a foreign court's own view of its jurisdiction, but it gives grounds to resist compliance with such orders. First, EU-based actors may be barred from acting on a foreign disclosure order within the EU. Second, a foreign decision giving effect to extraterritorial laws may not be recognised or enforceable in the EU. Third, the GDPR's rules on international transfers, together with its restriction on recognising foreign judgments absent an international agreement, are designed to prevent a transfer from becoming a backdoor around EU data protection standards. Resolving the conflict in any given case comes down to appropriate safeguards and proportionality, applied on both sides. Courts deciding whether to enforce such an order increasingly weigh the competing state interests, the burden on the provider, and whether less intrusive means were available. In practical terms, the key question is whether the provider has the technical, governance, and contractual frameworks in place to invoke sovereignty protection.

EU providers are not immune

EU ownership does not shield a provider against third-country requests, as evidenced by evolving case law. A court outside both the EU and the United States may order an EU-headquartered cloud provider to hand over user data stored across jurisdictions around the globe, reasoning that the provider's global operations and local service offering were enough to establish jurisdiction. National blocking statutes offer no effective shield in such circumstances.

The technical and operational criteria for sovereignty by design

In substance, the sovereign nature of cloud services hinges on operational and technical facts that determine, in practice, whether a service can deliver on a sovereignty claim: where customer data and metadata are processed and stored; whether operational and technical support, including any outsourcing, is carried out within the EU (where applicable, by vetted personnel); and whether the provider maintains robust cybersecurity, verifiable against objective technical standards rather than any single scheme's label.

Several global cloud service providers have implemented dedicated sovereignty offerings which appear well aligned with those factors. Conversely, a provider can be entirely EU-owned while routing support through an offshore helpdesk or relying on a non-European subcontractor for infrastructure maintenance, each creating a channel through which control or access can flow outside the EU's legal reach.

Ongoing diligence: a snapshot is not enough

None of the above is a one-time assessment. A supplier's operations and corporate structure can change after a sovereignty assessment is completed. A snapshot taken at signing says little about the position two or three years later.

A practical diligence exercise should keep asking, over the life of the relationship:

  • Has the supplier's corporate control chain changed (e.g., acquisition, new investors, restructuring)?
  • Where is the supplier incorporated and where does it actually operate?
  • Has the supplier expanded operations or marketing into new jurisdictions outside the EU?
  • Does the supplier depend on partners, sub-processors, or infrastructure providers outside the EU?

Best practice would include an annual reconfirmation, supplemented by event-driven notifications to customers; for example, where the supplier enters a new market, is acquired by or merges with a non-EU entity, or materially changes its sub-processor chain.

Several of the frameworks discussed above, including NIS2's supply chain obligations and DORA's ICT third-party risk management requirements, already impose ongoing monitoring duties on customers. A framework that stops checking once a contract is signed will miss the kind of drift that most often turns a compliant arrangement into a non-compliant one.

The takeaway

For anyone facing the question of whether a cloud services provider qualifies as sovereign, the implication is clear: sovereignty due diligence cannot be limited to ownership considerations. A defensible assessment must work through the corporate control, governance, legal, technical, and supply chain factors set out above.

No corporate structure, whether EU-owned, joint-ventured, or ring-fenced, offers absolute immunity from extraterritorial legal demands. Structure can reduce exposure; only technology can eliminate access.

Sovereignty in EU digital policy is, and is likely to remain, a multi-factor, evidence-based standard — not a label earned by origin. The most durable safeguards are technical, not structural: encryption, customer-held keys, and technical restrictions on access are what actually stand between a foreign legal demand and EU data. For customers, the practical implication is this: assess providers against operational and technical criteria, demand ongoing transparency, and treat technical controls — not corporate origin — as the foundation of any sovereignty strategy.

Strengthening the EU's own digital ecosystem is a legitimate policy goal, but the exclusion of non-EU headquartered providers does not serve that goal. A more targeted approach, assessing each provider against the criteria above, lets genuinely sovereign non-EU-affiliated offerings qualify while still screening out arrangements that carry real extraterritorial exposure. This allows the emerging European ecosystem to benefit from partnerships with and innovative offerings from global cloud service providers, while ensuring strong sovereignty protections.

White & Case means the international legal practice comprising White & Case LLP, a New York State registered limited liability partnership, White & Case LLP, a limited liability partnership incorporated under English law and all other affiliated partnerships, companies and entities.

This article is prepared for the general information of interested persons. It is not, and does not attempt to be, comprehensive in nature. Due to the general nature of its content, it should not be regarded as legal advice.

© 2021 White & Case LLP

Top