Microsoft and AWS Promise Europeans Greater Digital Sovereignty
Digital sovereignty is currently a hot topic. In Europe, it is primarily associated with the desire for greater independence from U.S. providers. However, the promises made by hyperscalers focus on the sovereignty …
Digital sovereignty is currently a hot topic. In Europe, it is primarily associated with the desire for greater independence from U.S. providers. However, the promises made by hyperscalers focus on the sovereignty of European data and protection against U.S. access.
TL;DR
- Max Schrems successfully challenged Safe Harbor and the EU-U.S. Privacy Shield due to U.S. surveillance.
- Starting in 2025, Microsoft will offer three sovereign cloud models with data remaining in Europe.
- With Microsoft’s solution, customers retain control over encryption keys via Azure Managed HSM.
- AWS is establishing a European organization headquartered in Germany for its Sovereign Cloud by end of 2025.
- Critics doubt that U.S. providers can legally shield themselves from U.S. surveillance laws.
European data protection authorities have long been concerned that U.S. authorities can, if necessary, access data hosted in Europe – and not only that. There have also been documented cases of industrial espionage through these channels.
Austrian privacy activist and lawyer Max Schrems therefore successfully brought down the transatlantic Safe Harbor agreement before the Court of Justice of the European Union (CJEU) in 2016, and four years later, the EU-U.S. Privacy Shield as well.
Diametral Sovereignty Concepts
American cloud giants AWS and Microsoft have attempted to meet the stricter requirements of the GDPR and other data protection regulations by establishing data centers within the EU. Now, however, they are promising a form of digital sovereignty diametrically opposed to the European understanding – less about reducing dependency on companies like themselves, and more about protecting data itself.
Microsoft and AWS are developing sovereign cloud solutions for European customers. Image source: Pexels
According to IT-Business, a German trade publication, both cloud providers have independently taken steps toward enhanced digital sovereignty aimed at protecting – or even isolating – European data.
As reported, Microsoft CEO Satya Nadella unveiled a new concept during the AI Tour in Amsterdam in mid-June 2025, ensuring that European customer data stored in Microsoft’s cloud solutions remains within Europe. To prevent data from being transferred to the U.S. or elsewhere, European employees will manage operations and access, while customers retain full encrypted control. A central component of this jointly developed solution is Azure Managed HSM Encryption, which allows customers to hold their own encryption keys and generate, manage, and securely store them either independently or through partners.
Microsoft Sees Encryption as the Key
This approach can be integrated with an external key manager, offering the advantage of key generation compliant with the highest FIPS standards. The integrated hardware security module (HSM) can be deployed either as an on-premises appliance or as a service.
In Amsterdam, Nadella presented three distinct variants of this new concept, all expected to become available by year-end:
- A Sovereign or “Sovereign Public Cloud” ensuring that customer data remains and is controlled exclusively within Europe, leveraging existing European data centers
- A “Sovereign Private Cloud” hosted in local Microsoft data centers, supporting hybrid cloud deployments on-premises or via partners
- A “National Partner Cloud,” specifically tailored for government agencies and operators of critical infrastructure
“No Blank Check from U.S. Surveillance Laws”
Benjamin Schilz, CEO of Berlin-based secure messaging specialist Wire, expressed initial skepticism: “Microsoft does not have a blank check from U.S. surveillance laws. The promised sovereign private cloud makes commitments that cannot be legally fulfilled. This isn’t about good intentions – it’s a simple fact: every U.S. software provider can be legally compelled to carry out surveillance measures or arbitrarily block access to services.”
He further noted that Microsoft’s source code is not open, and there are no legal barriers preventing the U.S. government from demanding the insertion of “backdoors” to extract cryptographic keys, customer data, or metadata.
AWS Goes One Step Further
Is AWS’s data space truly sovereign? IT-Business raises this question regarding another U.S. hyperscaler. In Hamburg, Amazon Web Services recently announced new sovereignty controls and a governance structure for its “AWS European Sovereign Cloud,” pledging not to share data with third parties – similar to Microsoft’s approach.
Kathrin Reiz, currently Vice President of AWS Industries in Germany, will lead governance efforts and head a dedicated Security Operations Center (SoC). The AWS European Sovereign Cloud – which won’t be available until end of 2025 – will otherwise provide the familiar APIs from the AWS Nitro System.
For this “sovereign offering,” AWS is establishing a European organization comprising a parent company and three subsidiaries based in Germany. In addition to Reiz on the management team, the structure will include EU-based security and data protection officers. An independent four-member advisory board composed of experts from EU member states will serve as an oversight body and report on the AWS European Sovereign Cloud.
The critical question remains: would AWS defy a U.S. court order demanding access to European data? According to AWS, it has never received a request resulting in the disclosure of corporate or governmental data stored outside the U.S. to the U.S. government – but it cannot guarantee this will never happen.
Frequently Asked Questions
Why were Safe Harbor and Privacy Shield invalidated?
Because U.S. authorities could access data stored in Europe. Max Schrems highlighted violations of fundamental data protection rights.
What does Microsoft promise with its sovereign cloud?
European customer data stays in Europe. Access is controlled by European staff, and customers retain ownership of encryption keys.
How does encryption work in Microsoft’s sovereign cloud?
Via Azure Managed HSM, customers can generate, manage, and store their own keys – the key never leaves their control.
What is AWS doing to enhance digital sovereignty?
AWS is creating a European organization headquartered in the EU, with dedicated EU-based security and data protection officers and a Security Operations Center in Germany.
Why is the sovereignty of U.S. cloud providers criticized?
U.S. providers can be legally required to conduct surveillance. There are no legal safeguards against backdoors or forced data access.
Editor’s Reading Recommendations
- API-First: Why modern cloud architectures live or die by API design
- Pretext: Does a JavaScript library solve a 30-year browser problem – or is it just hype?
- AWS vs. Azure vs. Google Cloud 2026: An honest comparison for DACH enterprises
More from the MBF Media Network
SecurityToday | MyBusinessFuture | Digital Chiefs
Header Image Source: Pexels / Angel Bena

