Microsoft says: sovereign. The question is: sovereign from what?
Microsoft ensures data residency for M365 Copilot in Germany. Andreas Knols from enthus cloud explains what this step resolves and which sovereignty…
Guest commentary by Andreas Knols, Director enthus cloud
Microsoft’s announcement to process M365 Copilot data on German servers in the future deserves neither reflexive skepticism nor uncritical applause. It deserves precision.
Key Takeaways
- Microsoft guarantees physical data residency: M365 Copilot requests and context data are processed in German data centers, no longer in the USA or Ireland.
- The CLOUD Act remains: Microsoft remains a US company. The server address does not change the applicable legal jurisdiction in case of access.
- BSI criteria catalog C3A makes sovereignty verifiable: Residency, portability, subcontractors, access rights, and legal jurisdiction as an operational framework prior to rollout.
Related:Google Gemini in the Enterprise: what the AI Act mandates / SAP Sovereign Cloud France: Implications for IT Decision‑Makers
What Microsoft concretely promises: physical data residency for inference processes within Germany. Whoever uses Copilot in Word, Teams, or Outlook, their requests and context data are processed on servers in German data centers – not in the USA, not in Ireland. For many companies we accompany on the path to the cloud, this is a substantial improvement over the previous state.
And yet: The step answers an important question. Not the decisive one.

What physical residency does not regulate
Jurisdiction. Microsoft remains a US company. The CLOUD Act of 2018 obligates US companies under certain conditions to disclose data upon government request – regardless of the country where these data are physically stored. A German data center does not change the provider’s corporate legal structure. It changes the server address.
This is not a hidden accusation. It is a statement of the legal situation – and one that Microsoft cannot resolve itself, because it depends on its corporate structure, not its infrastructure.
Whoever reads Microsoft’s sovereign commitment as a complete answer to the sovereignty question has omitted a dimension: Where a server is located and which legal jurisdiction applies in case of doubt to the content residing on it are two different statements. The first has Microsoft clarified with its announcement. The second remains open.
What the BSI Catalog Now Delivers
Exactly for this distinction, the C3A criteria catalog of the BSI published on April 27, 2026 is the right instrument. It makes sovereignty claims verifiable – as an operational grid: residency, portability, transparency about sub-service providers, access rights, and explicitly: the applicable law in the event of access.
Microsoft’s announcement meets, according to this grid, a relevant part of the requirements. It does not meet all of them. This is not a weakness of the provider – it is the finding of an honest analysis. And exactly that is the value of the catalog: It forces precision where previously mere assertion sufficed.
| Sovereignty Dimension | What Microsoft now commits to | What remains open |
|---|---|---|
| Physical Residency | Inference data in German data centers | Address issue resolved |
| Jurisdiction / CLOUD Act | unchanged: US corporate structure | Applicable law in the event of access remains open |
| BSI C3A Grid | relevant part met | not all criteria covered |
What decision makers should clarify before introduction
Don’t: avoid M365 Copilot. Don’t: take the announcement at face value and leave the contract unread.
Instead: ask three questions – best before the rollout decision is made. First: What does Microsoft contractually guarantee – and what is stated only in the product announcement? Second: What information obligations does Microsoft have towards authorities and under which legal jurisdiction? Third: If the answers to questions one and two change – can I switch without prohibitive migration costs?
We ask these questions in every cloud architecture project. The answers determine which data belongs in which environment – and which does not. This is not a compliance exercise. It is architectural craftsmanship.
Microsoft’s step is a good signal – that the market leader is responding to sovereignty requirements is relevant for us as cloud practitioners. But a signal is not a contract. Whoever asks the architecture question correctly today will not have to answer it under pressure tomorrow.
About the author: Andreas Knols is responsible for enthus cloud, the managed private cloud offering of enthus, and supports mid-sized companies in building sovereign, resilient cloud architectures.
Frequently Asked Questions
What does Microsoft specifically say about Sovereign Data Processing?
Physical data residency for inference processes within Germany. Queries and context data from M365 Copilot are processed on servers in German data centers, not in the USA and not in Ireland.
Why isn’t physical data residency sufficient for sovereignty?
Because it does not regulate jurisdiction. Microsoft remains a US company and the CLOUD Act of 2018 obliges US providers under certain conditions to disclose data, regardless of the physical storage location. Server address and applicable law are two different statements.
What does the BSI C3A criteria catalog provide?
It makes sovereignty claims verifiable. The operational grid includes residency, portability, transparency about sub-service providers, access rights, and explicitly the applicable law in the event of access. Published on 27. April 2026.
Which three questions should decision-makers clarify before rollout?
First: What does Microsoft contractually guarantee and what is only stated in the product announcement? Second: What disclosure obligations does Microsoft have towards governmental authorities and under which legal jurisdiction? Third: If the answers change, can I switch without prohibitive migration costs?
Does that mean we should avoid M365 Copilot?
No. But the architecture question belongs before the rollout decision, not after. The answers determine which data belongs in which environment and which does not. That is architecture craftsmanship.
Editor’s Reading Tips
- AWS Sovereign Cloud: what is truly separated
- BSI C3A: Cloud sovereignty becomes verifiable
- EU Data Act makes cloud portability mandatory
Image source: AI-generated (July 2026)

