What is a sovereign cloud?
A cloud where data, operations and control are fully subject to European law — with no access by third countries. It combines data residency, operational sovereignty and key ownership.
Does the US CLOUD Act apply to EU data centres?
Yes. If a US corporation operates the data centre, it can be compelled under the CLOUD Act to hand over data — regardless of whether the servers are in Frankfurt or Virginia.
Is EU data residency enough for sovereignty?
No. Data residency only governs the storage location. Sovereignty also requires protection from foreign access, operation by EU staff and key ownership.
How do BSI C5, EUCS and SecNumCloud differ?
BSI C5 (Germany) is a cloud-security audit catalogue, SecNumCloud (France) additionally requires immunity from non-European laws, and EUCS is the planned EU-wide certification scheme.
What do BYOK and HYOK mean?
BYOK (Bring Your Own Key) means you supply your own encryption key. HYOK (Hold Your Own Key) goes further: the key never leaves your control and the provider never sees data in clear text.
Is a sovereign cloud more expensive?
Not necessarily. European providers like OVHcloud or Hetzner are often cheaper than hyperscalers, especially on egress fees. Dedicated sovereignty features may carry a premium, however.
Which sovereign EU providers exist?
Among others STACKIT, OVHcloud, IONOS, Scaleway, T Cloud Public (Telekom), SysEleven, Hetzner and Infomaniak — with differing sovereignty, portfolio and certification profiles.
Does "not sovereign" also mean "insecure"?
No. Sovereignty and security are two different dimensions. Security comes from encryption, access control, certifications and clean operations — hyperscalers deliver this at a high level in EU regions as well. Sovereignty additionally describes the legal and operational independence from third countries. A provider can therefore be very secure and still not fully sovereign.
Does every workload really need to be sovereign?
No. How much sovereignty a workload needs depends on data classification, regulation and risk. For public or non-critical data, portfolio breadth, global reach, pace of innovation or cost often matter more. For regulated, personal or particularly sensitive data, sovereignty moves to the foreground. It makes sense to classify per workload rather than making a blanket decision.
Are hyperscalers insecure and EU providers automatically better?
No — both have their place. Hyperscalers stand out for their breadth of services, global scale and mature security, but as US corporations they are subject to foreign jurisdiction. European providers stand out for their sovereignty, EU jurisdiction and often more transparent pricing, with a more focused portfolio. It is not about good or evil, but about choosing the provider that fits the respective workload.