Skip to content
Trusted IT partner since 1994+1 917 628 2365
Free Security Check[email protected]

Where your data lives, whose law applies, and what to do about it

Europe’s Cloud Exit: Why Businesses Are Moving Data to Sovereign and Private Clouds

European organizations are moving sensitive data and critical workloads away from US hyperscalers toward European and private clouds. Location is only part of the reason: data in an EU region of AWS, Azure or Google Cloud still sits with a company that US law can compel. New EU rules, a fragile EU-US data deal, costly outages and transatlantic tension have turned sovereignty from a policy debate into a board-level risk. For most businesses the answer is not to abandon the hyperscalers, but to decide workload by workload where data must live, and to move what matters onto infrastructure under European control.

Updated · 14 min read

In short: keeping data inside EU borders is necessary but not sufficient. What decides who can get at your data is who operates the infrastructure, which country’s courts can reach that operator, who holds the encryption keys, and whether you can leave. In 2026 the EU began writing those questions into its own procurement rules, and companies such as Airbus and public bodies such as France’s Health Data Hub are already acting on them.

Diagram: a workload in a US hyperscaler’s EU region, still subject to US jurisdiction and lock-in, is assessed, classified, migrated and operated on a European private cloud with EU jurisdiction, customer-held keys and GDPR, NIS2 and DORA controls.
70%
of Europe’s cloud market is held by Amazon, Microsoft and Google
Synergy Research Group, 2025
85%
of German companies say they depend too much on US cloud providers
Bitkom Cloud Report, 2026
$23.1bn
forecast sovereign cloud spending in Europe in 2027, up from $6.9bn in 2025
Gartner, February 2026
Jan 2027
when the EU Data Act removes all cloud switching and egress charges
European Commission

What happened: Europe’s cloud wake-up call

Data sovereignty used to be a topic for regulators and public-sector buyers. Over the past eighteen months a string of events moved it into ordinary boardrooms. The milestones, with the sources listed at the end of this article:

  • May 2025 — the Associated Press reported that Microsoft cut off the email of the International Criminal Court’s chief prosecutor after US sanctions. Microsoft denies suspending services to the court itself; the ICC later announced a move of about 1,800 workstations to the German open-source suite openDesk.
  • June 2025 — under oath before a French Senate inquiry, Microsoft France’s director of legal affairs said he could not guarantee that French customers’ data would never be handed to US authorities, adding that it had never happened.
  • October 2025 — an AWS failure in its US-East region disrupted around 2,000 companies for about 14.5 hours, Euronews reported, including UK banks and the tax authority. Nine days later a global Azure outage hit retailers and Dutch Railways.
  • November 2025 — France and Germany held a summit on European digital sovereignty in Berlin, and EU financial supervisors placed AWS, Google Cloud and Microsoft under direct oversight as critical ICT providers under DORA.
  • January 2026 — AWS opened its European Sovereign Cloud in Brandenburg, Germany, and the European Parliament backed a resolution on technological sovereignty by 471 votes to 68.
  • April 2026 — the European Commission awarded a €180 million sovereign cloud contract to four European groups, and France began moving its national Health Data Hub from Microsoft Azure to the French provider Scaleway.
  • June 2026 — the Commission proposed the Cloud and AI Development Act, designated AWS and Azure as gatekeepers under the Digital Markets Act, and the US Supreme Court issued a ruling that put the EU-US Data Privacy Framework under fresh legal pressure.
  • July 2026 — Airbus chose Scaleway to host about 70 critical applications, citing protection against a political “kill switch”.

Why an EU region is not the same as EU sovereignty

The hyperscalers have spent years building data centers in Frankfurt, Paris, Dublin and Amsterdam, and keeping data there does solve the residency question under GDPR. It does not solve the jurisdiction question. The US CLOUD Act of 2018 requires providers under US jurisdiction to disclose data responsive to valid US legal process “regardless of where the company stores the data”, in the words of the US Department of Justice. The Justice Department adds that this jurisdiction is not limited to US-headquartered companies; it depends on the facts.

That is why the June 2025 hearing in the French Senate landed so hard. Asked whether he could guarantee that French citizens’ data would never be passed to US authorities without French consent, Microsoft France’s legal director answered: “No, I cannot guarantee it,” while stressing that it had never happened. It was an honest answer, and it describes every US-owned provider, not only Microsoft.

The legal ground for sending personal data to the US is also less stable than it looks. The EU-US Data Privacy Framework survived a first challenge in September 2025, when the EU General Court dismissed the Latombe case; an appeal is pending at the Court of Justice. The framework leans on US oversight bodies, and those have weakened: the Privacy and Civil Liberties Oversight Board has lacked a quorum since three members were removed in January 2025, and on 29 June 2026 the US Supreme Court ruled in Trump v. Slaughter that the president can remove FTC commissioners without cause. The privacy group noyb, which counts 259 references to FTC independence in the adequacy decision, asked the Commission to repeal it, and the European Data Protection Board formally asked the Commission to assess the ruling’s impact. Meanwhile the US surveillance law at the heart of the original Schrems rulings, FISA Section 702, lapsed as a statute on 12 June 2026, but collection continues under a court approval valid until March 2027, NPR and the Brennan Center report.

Illustration: five places data can live, from most dependence to most control. A US hyperscaler’s EU region keeps data in the EU but its US parent is within CLOUD Act reach. A hyperscaler sovereign cloud is run by an EU entity with a US parent. A European public cloud is under EU law. A private cloud in an EU data center gives you the choice of facility, EU law only and your own keys. On-premises adds all operations to your team.

The hyperscalers have responded with “sovereign” offerings. The AWS European Sovereign Cloud, live since January 2026 with €7.8 billion of investment, runs through EU legal entities under German law with EU-resident staff. Microsoft has completed its EU Data Boundary, launched sovereign public and private cloud options, and in April 2026 said it had committed contractually to contest in court any order to suspend its cloud operations in Europe. Google offers sovereign tiers through partners such as S3NS, its joint venture with Thales in France. These are real improvements in operational control. They do not change ownership: as Forrester’s Dario Maisto told The Register, the AWS offering is “still entirely owned by the US mother company”, which limits its immunity from the CLOUD Act. When the Commission scored providers for its own sovereign cloud tender, the Google-linked bid reached only the minimum sovereignty level.

The rules now pushing companies to act

No single EU law tells a private company to host only in Europe. But several rules now make dependence on one foreign provider harder to justify and easier to escape:

  • EU Data Act — in force since 12 September 2025. Cloud providers may charge only their costs for switching, and from 12 January 2027 all switching charges, egress fees included, disappear. Leaving a provider is becoming a planning question rather than a budget wall.
  • NIS2 — essential and important entities must manage supply-chain risk, including their cloud providers. On 8 July 2026 the Commission took Ireland, Spain, France and the Netherlands to the Court of Justice for late transposition, so enforcement is tightening.
  • DORA — banks, insurers and investment firms must hold exit strategies for critical ICT providers. In November 2025 EU supervisors designated 19 critical third-party providers, including the EU arms of AWS, Google Cloud and Microsoft.
  • GDPR enforcement — unlawful transfers carry real fines, from Meta’s €1.2 billion in 2023 and Uber’s €290 million in 2024 for US transfers to TikTok’s €530 million in 2025 for transfers to China.
  • Cloud and AI Development Act — proposed on 3 June 2026, it would introduce four sovereignty levels for public-sector cloud buying. At levels 3 and 4, control by non-EU companies is barred by default or entirely. Parliament and Council are still negotiating it, but suppliers to the public sector should plan for it now.

Reliability: the concentration risk nobody priced in

With three US companies holding about 70% of Europe’s cloud market, a bad day at one of them becomes a bad day for thousands of European businesses at once. On 19 and 20 October 2025 a race condition in DynamoDB’s DNS automation took down AWS’s US-East region for about 14.5 hours; in the UK, Lloyds and HMRC were among those hit. On 29 October a configuration change broke Azure Front Door, taking Asda, Marks & Spencer and Dutch Railways offline. “Systemic risk is fragility caused by concentration,” the CEO of the European cloud provider Civo told The Register afterwards. In July 2026 a power fault took a Google Cloud zone in the Netherlands down for nearly 15 hours, and at the end of August a global Microsoft 365 authentication failure disrupted email and Teams for several days.

The lesson is not that private or European clouds never fail; every data center can. It is that resilience comes from design you control: workloads spread across at least two sites, backups you have restored, a documented way to fail over, and an exit plan that works. That is much easier to build when you own the architecture than when your critical systems depend on a single global control plane.

Market reality: demand is rising, but few are leaving entirely

Bar chart: share of Europe’s cloud market in 2025. Amazon, Microsoft and Google together hold 70%; other non-European providers 15%; all European providers combined 15%, down from 29% in 2017. Source: Synergy Research Group.

Synergy Research Group puts European providers’ share of their home market at about 15%, down from 29% in 2017 and flat since 2022; the largest, SAP and Deutsche Telekom, hold about 2% each. Sentiment is moving faster than market share. In Bitkom’s 2026 cloud report, 85% of German companies say the country is too dependent on US cloud providers, 64% say US policy is pushing them to rethink their cloud strategy, and while 71% use a US provider, only 8% say they would prefer one. A Gartner survey of 241 Western European CIOs found that 61% expect geopolitics to increase their reliance on local cloud providers.

Bar chart: Gartner forecast of sovereign cloud infrastructure spending in Europe: $6.9 billion in 2025, $12.6 billion in 2026 and $23.1 billion in 2027.

Money is following. Gartner forecasts sovereign cloud infrastructure spending in Europe to rise from $6.9 billion in 2025 to $12.6 billion in 2026 and $23.1 billion in 2027. European providers are investing to meet it: Deutsche Telekom and Nvidia opened an industrial AI cloud in Munich in February 2026, Schwarz Digits, the owner of STACKIT, is building an €11 billion AI data center in Brandenburg, and OVHcloud reported public cloud revenue growth of more than 20% in its latest quarter. Capacity is not free, though: Hetzner raised prices twice in 2026 as memory and storage costs climbed.

Real moves are under way. Airbus picked Scaleway for about 70 critical applications by the end of 2028. France is moving its Health Data Hub to Scaleway and replacing Zoom and Teams with its own Visio for 2.5 million civil servants by 2027. Schleswig-Holstein has moved more than 40,000 mailboxes off Microsoft Exchange, and the Dutch government signed its first framework deal with a European cloud, STACKIT, and blocked the sale of the company that hosts its DigiD login system to a US buyer, citing the CLOUD Act. Yet IDC found that only 4% of European organizations plan to use local providers exclusively. The pattern is hybrid: sensitive and critical data moves under European control, while global and commodity workloads stay where they run best.

Hyperscaler, sovereign or private cloud? How to choose per workload

OptionWhere data livesWho can compel accessYour controlBest for
US hyperscaler, EU regionEU data centersEU authorities, and US authorities through the US parent (CLOUD Act)Shared; customer-managed keys availableGlobal apps, non-sensitive data, burst capacity, specialist managed services
Hyperscaler sovereign cloudEU data centers, EU staffOperated by an EU entity, but the US parent’s ownership remainsStronger operational separation; external key optionsRegulated workloads that need hyperscaler services
European public cloudEU data centersEU law (check any non-EU subsidiaries)Provider-operated, standard servicesSovereign-by-default general workloads and public-sector projects
Private cloud in an EU data centerA facility you choose, in one or more EU countriesEU law onlyFull: dedicated hardware, your keys, your access rulesCrown-jewel data, regulated and critical systems, steady predictable workloads
On-premisesYour own sitesEU law onlyFull, with every operational task on your teamLatency-critical, air-gapped or industrial systems

A practical path to keeping your data in Europe

  • 1. Map and classify — inventory your data and workloads, and classify each by sensitivity, regulation (GDPR, NIS2, DORA, sector rules) and business criticality.
  • 2. Decide per workload — keep it where it is, move it to a sovereign offering, a European cloud or a private cloud. Most estates end up hybrid, by design.
  • 3. Design the landing zone — at least two EU locations, encryption with keys you hold, identity and access you own, segmented networks and full logging.
  • 4. Migrate in waves — start with the most sensitive and least coupled systems, replace proprietary managed services with portable ones where it reduces lock-in, and use the Data Act’s switching terms.
  • 5. Operate and prove it — 24/7 monitoring and security operations, restore-tested backups, rehearsed failover and the audit evidence regulators ask for.

Execution decides whether sovereignty feels like progress or punishment. When the European Commission rolled out a self-hosted messaging tool as a “sovereign back-up to Teams” in 2026, Politico reported harsh reviews from its own staff. Users judge a migration by whether their work gets easier or harder, so plan the user experience as carefully as the data center.

How RHC Solutions keeps your data in Europe, secure and reliable

RHC Solutions has helped businesses run, secure and recover critical infrastructure since 1994, with teams in Lisbon, Sofia and Larnaca inside the EU. We work with European providers such as OVHcloud as well as AWS, Azure and Google Cloud, so we can recommend the right home for each workload rather than a single platform. We start with a sovereignty assessment of your data flows, jurisdiction exposure and exit costs; design private and sovereign cloud environments in European data centers, connected to the hyperscalers where they still make sense; migrate in phases with minimal downtime; and then keep it running with 24/7 operations, managed security, tested disaster recovery across sites, and the evidence your GDPR, NIS2 and DORA audits need.

In the news: sources and further reading

News coverage

Primary sources and data

Frequently asked questions

Is data in an AWS, Azure or Google Cloud EU region safe from US access?
Keeping data in an EU region helps with GDPR residency, but US law can require providers under US jurisdiction to disclose data wherever it is stored (the CLOUD Act). Sovereign offerings and encryption keys you hold reduce that exposure. Only infrastructure operated entirely under EU control removes the ownership question.
Do we have to leave the hyperscalers completely?
No, and few organizations do: IDC found that only 4% of European organizations plan to use local providers exclusively. The practical approach is hybrid. Move sensitive and critical data under European control first, and keep global or commodity workloads where they run best.
What is the difference between a sovereign cloud and a private cloud?
A sovereign cloud is a provider’s service designed to keep data, operations and staff within a jurisdiction, such as the EU. A private cloud is dedicated infrastructure for one organization, in a data center you choose, run by your team or a managed partner. A private cloud in an EU data center gives you the most control, with the most operational responsibility.
Is moving off a hyperscaler expensive?
Less than it used to be. Under the EU Data Act, providers may only charge their costs for switching, and from 12 January 2027 switching and egress charges disappear entirely. Steady, predictable workloads often cost less on dedicated infrastructure, but a private cloud also needs 24/7 operations, so budget for an in-house team or a managed partner.
Which regulations require data sovereignty?
No single EU law requires private companies to host only in Europe. GDPR restricts personal data transfers, NIS2 requires managing supply-chain risk, and DORA requires financial firms to have exit strategies for critical ICT providers. Public-sector buying is moving toward explicit sovereignty levels under the proposed Cloud and AI Development Act, and sector rules can add more.

Want your data under European control?

Talk to a senior consultant about which workloads should move, where they should go, and how to get there without downtime.