Where your data lives, whose law applies, and what to do about it
Europe’s Cloud Exit: Why Businesses Are Moving Data to Sovereign and Private Clouds
European organizations are moving sensitive data and critical workloads away from US hyperscalers toward European and private clouds. Location is only part of the reason: data in an EU region of AWS, Azure or Google Cloud still sits with a company that US law can compel. New EU rules, a fragile EU-US data deal, costly outages and transatlantic tension have turned sovereignty from a policy debate into a board-level risk. For most businesses the answer is not to abandon the hyperscalers, but to decide workload by workload where data must live, and to move what matters onto infrastructure under European control.
In short: keeping data inside EU borders is necessary but not sufficient. What decides who can get at your data is who operates the infrastructure, which country’s courts can reach that operator, who holds the encryption keys, and whether you can leave. In 2026 the EU began writing those questions into its own procurement rules, and companies such as Airbus and public bodies such as France’s Health Data Hub are already acting on them.

What happened: Europe’s cloud wake-up call
Data sovereignty used to be a topic for regulators and public-sector buyers. Over the past eighteen months a string of events moved it into ordinary boardrooms. The milestones, with the sources listed at the end of this article:
- May 2025 — the Associated Press reported that Microsoft cut off the email of the International Criminal Court’s chief prosecutor after US sanctions. Microsoft denies suspending services to the court itself; the ICC later announced a move of about 1,800 workstations to the German open-source suite openDesk.
- June 2025 — under oath before a French Senate inquiry, Microsoft France’s director of legal affairs said he could not guarantee that French customers’ data would never be handed to US authorities, adding that it had never happened.
- October 2025 — an AWS failure in its US-East region disrupted around 2,000 companies for about 14.5 hours, Euronews reported, including UK banks and the tax authority. Nine days later a global Azure outage hit retailers and Dutch Railways.
- November 2025 — France and Germany held a summit on European digital sovereignty in Berlin, and EU financial supervisors placed AWS, Google Cloud and Microsoft under direct oversight as critical ICT providers under DORA.
- January 2026 — AWS opened its European Sovereign Cloud in Brandenburg, Germany, and the European Parliament backed a resolution on technological sovereignty by 471 votes to 68.
- April 2026 — the European Commission awarded a €180 million sovereign cloud contract to four European groups, and France began moving its national Health Data Hub from Microsoft Azure to the French provider Scaleway.
- June 2026 — the Commission proposed the Cloud and AI Development Act, designated AWS and Azure as gatekeepers under the Digital Markets Act, and the US Supreme Court issued a ruling that put the EU-US Data Privacy Framework under fresh legal pressure.
- July 2026 — Airbus chose Scaleway to host about 70 critical applications, citing protection against a political “kill switch”.
Why an EU region is not the same as EU sovereignty
The hyperscalers have spent years building data centers in Frankfurt, Paris, Dublin and Amsterdam, and keeping data there does solve the residency question under GDPR. It does not solve the jurisdiction question. The US CLOUD Act of 2018 requires providers under US jurisdiction to disclose data responsive to valid US legal process “regardless of where the company stores the data”, in the words of the US Department of Justice. The Justice Department adds that this jurisdiction is not limited to US-headquartered companies; it depends on the facts.
That is why the June 2025 hearing in the French Senate landed so hard. Asked whether he could guarantee that French citizens’ data would never be passed to US authorities without French consent, Microsoft France’s legal director answered: “No, I cannot guarantee it,” while stressing that it had never happened. It was an honest answer, and it describes every US-owned provider, not only Microsoft.
The legal ground for sending personal data to the US is also less stable than it looks. The EU-US Data Privacy Framework survived a first challenge in September 2025, when the EU General Court dismissed the Latombe case; an appeal is pending at the Court of Justice. The framework leans on US oversight bodies, and those have weakened: the Privacy and Civil Liberties Oversight Board has lacked a quorum since three members were removed in January 2025, and on 29 June 2026 the US Supreme Court ruled in Trump v. Slaughter that the president can remove FTC commissioners without cause. The privacy group noyb, which counts 259 references to FTC independence in the adequacy decision, asked the Commission to repeal it, and the European Data Protection Board formally asked the Commission to assess the ruling’s impact. Meanwhile the US surveillance law at the heart of the original Schrems rulings, FISA Section 702, lapsed as a statute on 12 June 2026, but collection continues under a court approval valid until March 2027, NPR and the Brennan Center report.

The hyperscalers have responded with “sovereign” offerings. The AWS European Sovereign Cloud, live since January 2026 with €7.8 billion of investment, runs through EU legal entities under German law with EU-resident staff. Microsoft has completed its EU Data Boundary, launched sovereign public and private cloud options, and in April 2026 said it had committed contractually to contest in court any order to suspend its cloud operations in Europe. Google offers sovereign tiers through partners such as S3NS, its joint venture with Thales in France. These are real improvements in operational control. They do not change ownership: as Forrester’s Dario Maisto told The Register, the AWS offering is “still entirely owned by the US mother company”, which limits its immunity from the CLOUD Act. When the Commission scored providers for its own sovereign cloud tender, the Google-linked bid reached only the minimum sovereignty level.
The rules now pushing companies to act
No single EU law tells a private company to host only in Europe. But several rules now make dependence on one foreign provider harder to justify and easier to escape:
- EU Data Act — in force since 12 September 2025. Cloud providers may charge only their costs for switching, and from 12 January 2027 all switching charges, egress fees included, disappear. Leaving a provider is becoming a planning question rather than a budget wall.
- NIS2 — essential and important entities must manage supply-chain risk, including their cloud providers. On 8 July 2026 the Commission took Ireland, Spain, France and the Netherlands to the Court of Justice for late transposition, so enforcement is tightening.
- DORA — banks, insurers and investment firms must hold exit strategies for critical ICT providers. In November 2025 EU supervisors designated 19 critical third-party providers, including the EU arms of AWS, Google Cloud and Microsoft.
- GDPR enforcement — unlawful transfers carry real fines, from Meta’s €1.2 billion in 2023 and Uber’s €290 million in 2024 for US transfers to TikTok’s €530 million in 2025 for transfers to China.
- Cloud and AI Development Act — proposed on 3 June 2026, it would introduce four sovereignty levels for public-sector cloud buying. At levels 3 and 4, control by non-EU companies is barred by default or entirely. Parliament and Council are still negotiating it, but suppliers to the public sector should plan for it now.
Reliability: the concentration risk nobody priced in
With three US companies holding about 70% of Europe’s cloud market, a bad day at one of them becomes a bad day for thousands of European businesses at once. On 19 and 20 October 2025 a race condition in DynamoDB’s DNS automation took down AWS’s US-East region for about 14.5 hours; in the UK, Lloyds and HMRC were among those hit. On 29 October a configuration change broke Azure Front Door, taking Asda, Marks & Spencer and Dutch Railways offline. “Systemic risk is fragility caused by concentration,” the CEO of the European cloud provider Civo told The Register afterwards. In July 2026 a power fault took a Google Cloud zone in the Netherlands down for nearly 15 hours, and at the end of August a global Microsoft 365 authentication failure disrupted email and Teams for several days.
The lesson is not that private or European clouds never fail; every data center can. It is that resilience comes from design you control: workloads spread across at least two sites, backups you have restored, a documented way to fail over, and an exit plan that works. That is much easier to build when you own the architecture than when your critical systems depend on a single global control plane.
Market reality: demand is rising, but few are leaving entirely

Synergy Research Group puts European providers’ share of their home market at about 15%, down from 29% in 2017 and flat since 2022; the largest, SAP and Deutsche Telekom, hold about 2% each. Sentiment is moving faster than market share. In Bitkom’s 2026 cloud report, 85% of German companies say the country is too dependent on US cloud providers, 64% say US policy is pushing them to rethink their cloud strategy, and while 71% use a US provider, only 8% say they would prefer one. A Gartner survey of 241 Western European CIOs found that 61% expect geopolitics to increase their reliance on local cloud providers.

Money is following. Gartner forecasts sovereign cloud infrastructure spending in Europe to rise from $6.9 billion in 2025 to $12.6 billion in 2026 and $23.1 billion in 2027. European providers are investing to meet it: Deutsche Telekom and Nvidia opened an industrial AI cloud in Munich in February 2026, Schwarz Digits, the owner of STACKIT, is building an €11 billion AI data center in Brandenburg, and OVHcloud reported public cloud revenue growth of more than 20% in its latest quarter. Capacity is not free, though: Hetzner raised prices twice in 2026 as memory and storage costs climbed.
Real moves are under way. Airbus picked Scaleway for about 70 critical applications by the end of 2028. France is moving its Health Data Hub to Scaleway and replacing Zoom and Teams with its own Visio for 2.5 million civil servants by 2027. Schleswig-Holstein has moved more than 40,000 mailboxes off Microsoft Exchange, and the Dutch government signed its first framework deal with a European cloud, STACKIT, and blocked the sale of the company that hosts its DigiD login system to a US buyer, citing the CLOUD Act. Yet IDC found that only 4% of European organizations plan to use local providers exclusively. The pattern is hybrid: sensitive and critical data moves under European control, while global and commodity workloads stay where they run best.
Hyperscaler, sovereign or private cloud? How to choose per workload
| Option | Where data lives | Who can compel access | Your control | Best for |
|---|---|---|---|---|
| US hyperscaler, EU region | EU data centers | EU authorities, and US authorities through the US parent (CLOUD Act) | Shared; customer-managed keys available | Global apps, non-sensitive data, burst capacity, specialist managed services |
| Hyperscaler sovereign cloud | EU data centers, EU staff | Operated by an EU entity, but the US parent’s ownership remains | Stronger operational separation; external key options | Regulated workloads that need hyperscaler services |
| European public cloud | EU data centers | EU law (check any non-EU subsidiaries) | Provider-operated, standard services | Sovereign-by-default general workloads and public-sector projects |
| Private cloud in an EU data center | A facility you choose, in one or more EU countries | EU law only | Full: dedicated hardware, your keys, your access rules | Crown-jewel data, regulated and critical systems, steady predictable workloads |
| On-premises | Your own sites | EU law only | Full, with every operational task on your team | Latency-critical, air-gapped or industrial systems |
A practical path to keeping your data in Europe
- 1. Map and classify — inventory your data and workloads, and classify each by sensitivity, regulation (GDPR, NIS2, DORA, sector rules) and business criticality.
- 2. Decide per workload — keep it where it is, move it to a sovereign offering, a European cloud or a private cloud. Most estates end up hybrid, by design.
- 3. Design the landing zone — at least two EU locations, encryption with keys you hold, identity and access you own, segmented networks and full logging.
- 4. Migrate in waves — start with the most sensitive and least coupled systems, replace proprietary managed services with portable ones where it reduces lock-in, and use the Data Act’s switching terms.
- 5. Operate and prove it — 24/7 monitoring and security operations, restore-tested backups, rehearsed failover and the audit evidence regulators ask for.
Execution decides whether sovereignty feels like progress or punishment. When the European Commission rolled out a self-hosted messaging tool as a “sovereign back-up to Teams” in 2026, Politico reported harsh reviews from its own staff. Users judge a migration by whether their work gets easier or harder, so plan the user experience as carefully as the data center.
How RHC Solutions keeps your data in Europe, secure and reliable
RHC Solutions has helped businesses run, secure and recover critical infrastructure since 1994, with teams in Lisbon, Sofia and Larnaca inside the EU. We work with European providers such as OVHcloud as well as AWS, Azure and Google Cloud, so we can recommend the right home for each workload rather than a single platform. We start with a sovereignty assessment of your data flows, jurisdiction exposure and exit costs; design private and sovereign cloud environments in European data centers, connected to the hyperscalers where they still make sense; migrate in phases with minimal downtime; and then keep it running with 24/7 operations, managed security, tested disaster recovery across sites, and the evidence your GDPR, NIS2 and DORA audits need.
Cloud Infrastructure
Assessment, landing zones and phased migration to European private, sovereign or hybrid cloud.
Learn moreBusiness Continuity
Disaster recovery across two EU sites, with failover you have actually rehearsed.
Learn moreManaged Security
Round-the-clock monitoring, detection and response for your European environment.
Learn moreCompliance
Controls and audit evidence for GDPR, NIS2 and DORA, mapped to how you really run.
Learn moreZero-Trust Architecture
Identity, encryption with your own keys, and least-privilege access by default.
Learn moreCISO as a Service
Senior security leadership to own your sovereignty strategy and the board conversation.
Learn moreIn the news: sources and further reading
News coverage
- Trump’s sanctions on ICC prosecutor have halted tribunal’s work — Associated Press (via The Boston Globe), 15 May 2025
- Overheid leunt veel meer op Amerikaanse clouds dan bekend (in Dutch) — NOS, 31 May 2025
- Microsoft exec admits it “cannot guarantee” data sovereignty — The Register, 25 July 2025
- Schleswig-Holstein’s e-mail systems converted to open source — heise online, 7 October 2025
- AWS services recover after daylong outage hits major sites — CNBC, 20 October 2025
- Amazon internet service outage highlights EU’s “overwhelming reliance on Big Tech” — Euronews, 21 October 2025
- Amazon explains exactly why its cloud server outage took down much of the internet — Euronews, 24 October 2025
- Azure’s bad night fuels fresh calls for cloud diversification in Europe — The Register, 30 October 2025
- AWS flips switch on Euro cloud as customers fret about digital sovereignty — The Register, 15 January 2026
- France dumps Zoom and Teams as Europe seeks digital autonomy from the US — Associated Press (via KSAT), 2 February 2026
- Digital sovereignty (1/3): Have Trump’s threats spurred a European awakening? — France 24, 2 February 2026
- Europe’s sovereign cloud spend set to triple as geopolitics bite — The Register, 9 February 2026
- EU Commission awards 180 million euro cloud contract to four European providers — Reuters (via Yahoo Finance), 17 April 2026
- Europe’s defence cloud reliance risks US “kill switch”, think tank warns — Euronews, 17 April 2026
- France moves public health data from Microsoft to French cloud provider — Euronews, 24 April 2026
- AWS parades orgs that took up its offer for Euro Sovereign Cloud — The Register, 21 May 2026
- Europe unveils tech sovereignty package amid growing concerns over reliance on U.S. tech: “We want to be sure nobody has a kill switch” — CNBC, 3 June 2026
- European Union launches new tech sovereignty package — Associated Press (via Fortune), 3 June 2026
- A key U.S. spy tool has lapsed — now what? — NPR, 12 June 2026
- EU’s cloud and AI development act gets mixed reception — Euronews, 22 June 2026
- Europeans want less dependence on foreign technologies, study finds — Euronews, 24 June 2026
- Brussels tightens rules on US cloud providers as it pushes for tech sovereignty — Euronews, 25 June 2026
- Supreme Court decision threatens EU-US data transfer agreement — The Record, 2 July 2026
- Airbus picks Iliad’s Scaleway for AI, defence work in sovereignty push — Reuters (via The Star), 16 July 2026
Primary sources and data
- The Purpose and Impact of the CLOUD Act (FAQ) — US Department of Justice
- Hearing record, public procurement inquiry, 10 June 2025 (in French) — French Senate
- General Court dismisses the action against the EU-US Data Privacy Framework — Court of Justice of the EU, 3 September 2025
- US Supreme Court just blew up EU-US data transfers — noyb, 29 June 2026
- Letter to the European Commission on Trump v. Slaughter — European Data Protection Board, 31 July 2026
- Data Act explained — European Commission
- Commission refers four member states to the Court of Justice over NIS2 — European Commission, 8 July 2026
- European Supervisory Authorities designate critical ICT third-party providers under DORA — ESMA, EBA and EIOPA, 18 November 2025
- Proposal for the Cloud and AI Development Act — European Commission, 3 June 2026
- Commission advances cloud sovereignty through strategic procurement — European Commission, 17 April 2026
- European cloud providers’ local market share now holds steady at 15% — Synergy Research Group, 24 July 2025
- Deutsche Cloud: 4 von 10 Unternehmen würden Abstriche in Kauf nehmen (in German) — Bitkom, 17 June 2026
- Geopolitics push European CIOs to think local on cloud (Gartner survey) — The Register, 13 November 2025
- Digital sovereignty in Europe in 2025: what’s “Plan B”? — IDC, 27 August 2025
- Summary of the Amazon DynamoDB service disruption in US-EAST-1 — Amazon Web Services
Frequently asked questions
Is data in an AWS, Azure or Google Cloud EU region safe from US access?
Do we have to leave the hyperscalers completely?
What is the difference between a sovereign cloud and a private cloud?
Is moving off a hyperscaler expensive?
Which regulations require data sovereignty?
Want your data under European control?
Talk to a senior consultant about which workloads should move, where they should go, and how to get there without downtime.