What is digital sovereignty?

In short

Digital sovereignty is the ability of a state, organisation, or individual to autonomously decide over digital infrastructure, data, and applications.

In Germany, the term is shaped especially by GDPR, the NIS2 directive1, and the Schrems II ruling2 — with the US CLOUD Act as the extraterritorial counter-pole.

Important: sovereignty is not equivalent to national isolation or hyperscaler abstinence. It is a question of control, traceability, and freedom of choice — and that is precisely the difference between a marketing slogan and an operational reality.

Three dimensions of cloud sovereignty

A workable model splits sovereignty into three dimensions:

Sovereignty starts in management, not the data centre

The most important insight from the field: real sovereignty doesn’t emerge from a single technical decision, but from a coordinated governance model. Where business and IT develop a cloud strategy together, risk drops, decisions speed up, silos are avoided. Where that is missing, shadow IT and non-auditable data flows grow.

Frameworks help: BSI C5, ISO/IEC 27001, SOC 1–3 structure compliance. But frameworks don’t replace a decision hierarchy: who makes cloud architecture decisions? Who reviews? Who escalates?

AWS European Sovereign Cloud (ESC)

The AWS European Sovereign Cloud is a prominent hyperscaler answer to European sovereignty requirements: a cloud operated entirely within the EU, physically and logically separate from the other AWS Regions, with its own corporate structure in Germany. Core characteristics according to AWS4:

For IT decision-makers this means, in my view: sovereignty is also achievable with global cloud providers, provided technical, legal, and organisational controls interlock. According to AWS, the ESC targets sectors including government, healthcare, financial services, energy, and telecommunications — with a service range that, at launch, is smaller than in the global AWS regions.

Caveat: the ESC is operated by companies incorporated in Germany6, but its ultimate parent is a US company. Whether that effectively rules out access under the US CLOUD Act is, in my view, not legally settled.

Disclosure: Storm Reply, where I am managing director, is an AWS partner.

Provider landscape in comparison

Germany’s cloud landscape is becoming more differentiated:

The right choice depends on the workload. A 23-category decision compass structures the evaluation — see the deeper dives below.

Sovereignty as a strategic process

The path to a sovereign cloud organisation follows a clear sequence:

  1. Sovereignty assessment — readiness check, regulatory mapping (GDPR, NIS2, KRITIS, BaFin), workload classification.
  2. Target architecture — landing zone, policy set, role model, KRITIS/BaFin blueprints.
  3. Pilot workloads — Infrastructure-as-Code, guardrails, gate decisions.
  4. Continuous compliance — policy-as-code, audit trails, regular reviews, evidence management.

Sovereignty is not a vendor label — it’s a property of your own operating model.

Frequently asked questions about digital sovereignty

How do separation models prevent EU versus US data routing?

Sovereign cloud models separate on three levels. Technically: a dedicated partition with its own infrastructure, separate from the global regions. Organisationally: operation by EU-resident staff under a European legal entity. Cryptographically: keys managed by the customer. The AWS European Sovereign Cloud has implemented the technical and organisational separation since its launch on 15 January 2026 (AWS announcement). One limit remains: the parent company is based in the US, and whether US authorities can still demand access under the CLOUD Act is, in my view, not legally settled.

Which providers offer sovereign cloud options?

Three groups: national providers such as IONOS, STACKIT and Open Telekom Cloud, operated in Germany or Europe and with a narrower service range; EU-sovereign hyperscaler models such as the AWS European Sovereign Cloud and Google Cloud Dedicated; and classic public-cloud regions in the EU with the broadest service range, but subject to the CLOUD Act. Data-residency controls such as the Microsoft EU Data Boundary or the Google Cloud Data Boundary belong to the third group. The right group depends on the workload.

What is the difference between data location and data sovereignty?

Data location only describes where data physically reside. Data sovereignty answers the more important question: who has legal access to the data? A US hyperscaler with an EU data centre is subject to the US CLOUD Act regardless of storage location. Sovereignty therefore requires both data location and operational/legal separation.

Is the AWS European Sovereign Cloud GDPR-compliant?

No cloud platform is GDPR-compliant per se — it can enable GDPR-compliant operation; whether that succeeds depends on how it is used. The AWS European Sovereign Cloud is designed around EU data-protection requirements. Operations exclusively by EU-resident personnel, customer metadata kept in the EU, and its own identity and billing systems create the structural prerequisites. As with any cloud service, GDPR compliance at workload level must be established by the using organisation (controller obligations, records of processing, technical and organisational measures).

How does the US CLOUD Act apply to European cloud services?

The US CLOUD Act obliges providers subject to US jurisdiction to disclose, on the order of US authorities, data in their possession, custody, or control — regardless of physical storage location. Consequence: a US provider with an EU data centre remains in principle CLOUD-Act-subject. Sovereignty models like the AWS European Sovereign Cloud address this through legally separated EU entities and EU-operated operations. The parent company, however, is US-based — whether that effectively rules out CLOUD Act access is, in my view, not legally settled.

Which frameworks help with cloud-sovereignty assessment?

BSI C5 (Cloud Computing Compliance Criteria Catalog), ISO/IEC 27001 (ISMS), SOC 1–3 (Service Organization Controls). For specific industries: BaFin requirements (financial services), KRITIS requirements (critical infrastructure), GxP/MDR (healthcare). At strategic level, the 23-category decision compass structures provider evaluation.

Does digital sovereignty make hyperscaler use impossible?

No — on the contrary. Digital sovereignty means informed freedom of choice, not isolation. Global cloud providers are usable when the required technical, legal, and organisational controls interlock. Offerings like the AWS European Sovereign Cloud exist for that purpose; pure data-residency commitments such as the Microsoft EU Data Boundary are not sufficient on their own.

What is NIS2 and how does it relate to sovereignty?

The NIS2 directive is the EU’s second cybersecurity directive; it sets expanded security and reporting obligations for critical and important sectors. In force since January 2023, member-state transposition deadline October 2024; Germany transposed it with its NIS2 Implementation Act, in force since 6 December 2025. It is not a direct sovereignty law, but it enforces resilience requirements that directly affect cloud architecture: supply-chain security, incident reporting, multi-factor authentication, recovery capability. For KRITIS operators, NIS2 fuses with sovereignty requirements.

Sources

  1. European Parliament and Council: “Directive (EU) 2022/2555 … (NIS2 Directive)”, OJ L 333, 27 December 2022; in force since 16 January 2023, transposition deadline 17 October 2024 (Art. 41), risk-management measures in Art. 21(2). eur-lex.europa.eu
  2. Court of Justice of the European Union: judgment C-311/18 “Data Protection Commissioner v Facebook Ireland and Maximillian Schrems” (Schrems II), 16 July 2020; press release No 91/20. curia.europa.eu
  3. US Congress: “18 U.S.C. § 2713 – Required preservation and disclosure of communications and records”, added by the CLOUD Act (Pub. L. 115-141, Div. V), 23 March 2018. law.cornell.edu
  4. Amazon Web Services: “AWS Launches AWS European Sovereign Cloud and Announces Expansion Across Europe”, press release, 15 January 2026. General availability, first region in Brandenburg, more than 90 services, operated exclusively by EU residents, customer-created metadata plus IAM, billing and usage metering kept in the EU. press.aboutamazon.com
  5. Colm MacCárthaigh, AWS Security Blog: “Establishing a European trust service provider for the AWS European Sovereign Cloud”, blog post, 10 July 2025 (updated 4 August 2025). aws.amazon.com
  6. Amazon: “Built, operated, controlled, and secured in Europe: AWS unveils new sovereign controls and governance structure for the AWS European Sovereign Cloud”, company announcement, 3 June 2025. Dedicated European root CA, German parent company with three GmbH subsidiaries, operations only by EU-resident staff. aboutamazon.eu
  7. STACKIT: “About STACKIT”, company profile, retrieved 27 September 2026. stackit.com
  8. Google Cloud: “Sovereign Cloud from Google”, product page, retrieved 27 September 2026. Portfolio: Google Cloud Data Boundary, Google Cloud Dedicated, Google Cloud Air-Gapped. cloud.google.com
  9. Julie Brill, Paul Lorimer (Microsoft): “Microsoft completes landmark EU Data Boundary, offering enhanced data residency and transparency”, blog post, 26 February 2025. blogs.microsoft.com

Deeper dives