Sovereign Clouds: Beyond Data Residency
May 13, 2026— Matt Hovis, Thread Lead, Multicloud Solutions 8 min read
Introduction
Any cloud implementation, multicloud or not, should take the data privacy of its customers into consideration. Due to evolving geopolitical regulations, organizations have begun to realize that more than where their data physically resides can determine who has authority over it.
Data Sovereignty and Sovereign Clouds Defined
Data Sovereignty is the principle that data is subject only to the laws and governance of the country where it is physically collected, stored, and processed.
While Commercial Clouds focus on global scalability and availability, a Sovereign Cloud is a cloud environment designed to ensure that data, operations, personnel, and technology all remain under the legal jurisdiction of a specific nation or region. Sovereign Clouds don’t pertain only to the technical configuration of the infrastructure, but to all other legal aspects as well. The primary objective of a Sovereign Cloud is to protect the data stored in the cloud from foreign access or laws.
Project Andromède – the Sovereign Cloud Prototype
The concept of Sovereign Clouds can be traced back to the 2011 Digital G8 Summit in France. With many technology leaders in presence, French President Sarkozy challenged Big Tech’s borderless philosophy of early cloud computing. He pushed strategic autonomy, placing the same national emphasis on digital infrastructure as energy or defense.
The summit led to a state-backed effort “Project Andromède”, an effort to build a French national cloud that would ensure strategic data remained under French jurisdiction. The project suffered from internal disagreements over leadership and implementation. While AWS and Azure continued innovating in features, accelerating adoption, and optimizing costs, Project Andromède lagged behind, generating only 2 million euro in revenue before being ultimately shut down in January 2020. Despite its failure, Project Andromède serves as an early attempt at establishing a Sovereign Cloud.
The Catalysts for Sovereign Clouds
During the early rise of cloud adoption, it was widely accepted that by applying regional constraints on data residency would be sufficient to protect data and privacy from foreign requests. Several legal rulings and court orders over the past few years have challenged the data residency belief and have contributed to the rise of Sovereign Clouds.
The Schrems Rulings
Max Schrems is an Austrian lawyer and digital privacy advocate. After attending a lecture by a Facebook lawyer, Schrems requested his own data from the company and received a 1,200 page PDF containing everything from deleted messages to his physical location. During this process, he realized that once European data hit US servers, it lost the stricter protections of EU law and became subject to US law enforcement and surveillance programs.
In Schrems I (2015), Schrems challenged the “Safe Harbor” framework which allowed companies to self-certify that they protected data transferred from the EU to the US. The Court of Justice of the European Union’s (CJEU) invalidated this framework and required that data protection authorities must be allowed to investigate and suspend data transfers if a country’s laws did not provide “essentially equivalent” protection as EU standards under the GDPR. The EU and US then negotiated a more rigorous agreement known as the Privacy Shield, requiring American companies to commit to a set of privacy principles that met European data protection standards.
The Schrems II (2020) ruling invalidated the Privacy Shield, ruling that it still failed to protect EU citizens sufficiently from US surveillance programs. In addition to introducing rigorous and ongoing auditing processes, the decision shifted the burden of proof from the regulator to the data exporter and introduced the Transfer Impact Assessment (TIA). The TIA requires the implementation of technical measures, such as advanced encryption to ensure that data privacy remains in place when crossing international borders.
The US CLOUD Act
The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act) was enacted in 2018. The CLOUD Act is a federal law granting US law enforcement the authority to compel US-based tech companies to provide data stored on their servers, whether physically located in the United States or abroad.
The act clarifies that service providers subject to US jurisdiction (e.g. AWS, Oracle, Google, Microsoft) must comply with legal requests for data they “possess, custody, or control”, regardless of where the data is physically located (i.e. data center location). To access the content of communications such as emails or private files, US authorities still must obtain a warrant based on probable cause, issued by a US judge.
Additionally, the Act allows the US to enter into bilateral agreements with other foreign governments to request data directly from US providers for serious crime investigations, provided that they meet high privacy and human rights standards.
By leveraging External Key Management (EKM) and Hold Your Own Key (HYOK), a CSP would technically not be able to decrypt the data to turn it over. However, the encryption keys would not be able to protect the metadata, traffic patterns, user identities, etc. surrounding the data or its usage.
Sovereign Cloud Implementation Overview
The four major CSPs now offer Sovereign Cloud models to address the data sovereignty concerns. Following the Schrems II ruling, they have moved beyond “EU regions” to create architecturally isolated environments designed to be immune to the US Cloud Act and foreign surveillance.
The separation is achieved through three distinct layers of control that firewall the sovereign regions from the provider’s global operations:
- Organizational/Corporate – the Sovereign Cloud is operated by a specific local legal entity such as an incorporated subsidiary with its own staff. The employees are residents of that region and the parent company is legally and technically blocked from accessing the data.
- Logical and Physical – the Sovereign Clouds exist in their own realms or zones (depending on each CSP’s terminology). They do not share authentication systems, metadata, or management consoles with the provider’s standard public cloud offerings, preventing leakage to foreign servers.
- Key Management – users can employ External Key Management (EKM) or Hold Your Own Key (HYOK) models. The encryption keys are stored on-premises or with a local third party so that the provider cannot decrypt data, even if served with a warrant.
Creating a local (i.e. foreign) subsidiary that is the contractual and operational owner of the data prevents the parent company from making a claim of “custody or control.”
CSP Sovereign Cloud Offerings
Oracle (OCI)
Despite entering the public cloud space later than the other CSPs, Oracle was the first to offer sovereign cloud regions. This capability stemmed from Oracle’s early strategy of prioritizing its OCI Dedicated Regions offering, Cloud@Customer, which launched in 2020. This early advantage enabled Oracle to announce the first EU sovereign cloud regions in 2022.
In June 2023, OCI announced that it had officially launched its EU Sovereign Cloud regions in Madrid, Spain and Frankfurt, Germany. These were the first hyperscalable public cloud regions dedicated specifically to meet EU sovereignty requirements.
While maintaining the same service offerings, Oracle also offers the same pricing model and credit programs as its standard commercial cloud regions.
Amazon Web Services (AWS)
AWS announced the development of its European Sovereign Cloud (ESC) in October 2023. The aws.eu region officially launched in January 2026. The eusc-de-east-1 region is physically located in Bradenburg, Germany. It is a completely separate AWS partition, similar to the US GovCloud and China regions.
AWS also announced that they will be extending new sovereign Local Zones in Belgium, the Netherlands, and Portugal.
AWS customers will also be able to extend their EU Sovereign Cloud infrastructure with Dedicated Local Zones, which offer a subset of AWS services on a customer’s site.
Microsoft (Azure)
Microsoft announced its Sovereign Private Cloud and National Partner Clouds offerings in July 2022, which have since evolved into the broader Microsoft Cloud for Sovereignty (or Microsoft Sovereign Cloud).
The Azure Sovereign Private Cloud model is similar to Oracle’s Cloud@Customer or AWS Dedicated Local Zones. The private cloud is delivered via Azure Local and Microsoft 365 Local, which can be self-hosted or partner-hosted, running out of the customer’s data center or on-premises. The Azure Sovereign Private Cloud was launched into General Availability in December, 2023.
The National Partner Cloud (NPC) regions guarantee that European data will stay in Europe and under European law. The regions are hosted in France and Germany, with Microsoft partnering with Bleu and Delos Cloud respectively to operate them. The new regions launched starting in 2024 and reached full availability in 2025.
In March 2026, Microsoft announced the opening of its new Denmark East region as part of its EU Sovereign Cloud offerings.
Google (GCP)
Google’s approach to digital sovereignty is similar to Microsoft’s in that they offer two models. Google offers the Google Cloud Dedicated (GCD) and Google Sovereign Cloud.
Google Cloud Dedicated is a locally-hosted environment, similar to AWS Dedicated Local Zones or Azure’s Sovereign Private Cloud. GCD offers the full suite of GCP services with no connection to the public internet or Google Cloud’s backbone. GCD entered GA in March 2023.
GCP launched its first Sovereign Cloud region in Munich, Germany, in November, 2025. In France, Google partnered with Thales to create S3NS (pronounced “sense”) to allow public and private organizations to use GCP tools. It is fully controlled and majority-owned by the French company Thales, and therefore immune to US data requests. Additionally, GCP now has sovereign regions in Germany, Luxembourg, Belgium, Spain, and Italy, all run by different partners.
Additionally, Google Cloud Data Boundary enables customers to restrict which regions their data can be stored at rest. This, combined with the Cloud External Key Manager (EKM) to use, rotate, and destroy encryption keys to ensure compliance.
In Conclusion
Data sovereignty is a newer aspect of both cloud architecture and data governance. While tools like External Key Management (EKM) and Hold Your Own Key (HYOK) are an important piece of the puzzle, they may not be sufficient to ensure the rigorous demands of European privacy standards. Sovereign cloud regions offer the additional protections that can ensure that the data, and metadata surrounding it, remain subject only to the laws of their residency.