Sovereign Cloud Does Not End at the Server Location
A single German data center does not ensure data sovereignty. Why Sovereign Cloud depends on jurisdiction, operation, key control, and exit.
A German data centre on the invoice may reassure many procurement departments, but it tells us little about who can access the data in an emergency. Sovereign Cloud is determined not by server location, but by four levels: legal, operational, key and exit.
Key Takeaways
- Location is only the first of five criteria. The US CLOUD Act grants US authorities access to a US company’s data, regardless of whether the server is in Frankfurt or Virginia. Jurisdiction follows the provider, not the hardware.
- Key sovereignty is the toughest lever. If you control the encryption yourself and keep the keys beyond the provider’s reach, any official access becomes technically worthless.
- Without an exit plan, you remain locked in. Sovereignty that vanishes when switching providers is no sovereignty at all. Portability must be in the contract, not buried in the fine print.
Related:BSI C3A: Cloud Sovereignty Becomes Auditable / EU Data Act: When Cloud Switching Fees Disappear
Why server location is only half the story
The question of location is valid, but it doesn’t go far enough. What matters is the jurisdiction under which a provider operates. A US corporation is subject to the 2018 CLOUD Act, which obliges it to grant US authorities access to stored data on demand, regardless of where the servers are located. A Frankfurt data centre does nothing to alter that legal reality.
Sovereignty is therefore less about place and more about a bundle of legal and technical assurances. Server location is the first criterion. It is necessary for GDPR compliance, but on its own it is not sufficient. Stopping at this point confuses data storage with data sovereignty.
Operational sovereignty: who has administrative access
The second criterion concerns day-to-day operations. Who administers the systems, who maintains them, and from which country? Even with a European data centre, support may be handled by a global team with potential visibility. Operational sovereignty means administration and support are handled by personnel subject to European law.
Managed-private-cloud models address this directly. Operations remain with a European provider, often with a contractually defined group of personnel authorised for privileged access. For regulated sectors such as finance or healthcare, this is not a convenience but a prerequisite.
Key sovereignty: the technical worst-case scenario
The third criterion is the most effective lever. If data is encrypted and the provider does not hold the keys, any official access attempt fails. Three levels matter. Bring Your Own Key lets the customer supply keys but manage them within the provider’s environment. Hold Your Own Key keeps the keys in an external system the provider cannot access. Confidential Computing encrypts data during processing in memory.
For most workloads, HYOK is the pragmatic target state. The effort is greater than with BYOK, but the sovereignty gain is clear: without the external key, the data remains unreadable even if someone gains physical access to the storage.
Exit and Portability: The Silent Lock-in
The fourth criterion is most often overlooked. A cloud from which you cannot extract your data without massive costs creates a de facto dependency. The EU Data Act addresses this by banning excessive switching fees from 2027 onwards. But don’t rely on that alone: proprietary data formats and provider-specific services still create ties even without fees.
True sovereignty requires a documented exit strategy. Which data formats can be exported, how long will migration take, and which services have no competitor equivalent? If you only ask these questions when a dispute arises, you’ve already lost leverage.
The Checklist for Selection
Five points turn a marketing promise into a verifiable guarantee. They can be checked before signing any contract:
- Jurisdiction: Under which law does the provider operate – not just where the servers are located?
- Operations: Who has administrative access, and from which country?
- Keys: Does key sovereignty rest with the customer, ideally as HYOK?
- Exit: Is there a documented, affordable exit path?
- Verification: Do certifications like BSI C5 or the new C3A independently validate these promises?
Sovereignty isn’t a label an operator can stamp on itself. It’s the result of five answers you demand in writing. Server location is just one piece of the puzzle – it doesn’t decide the matter alone.
Frequently Asked Questions
What is Sovereign Cloud?
Sovereign Cloud refers to cloud services where data and systems are fully governed by European law and operational control. The term encompasses more than just server location: it demands control over the provider’s jurisdiction, administrative access, encryption, and a verifiable exit path.
Is a German data center enough for data sovereignty?
No. While the location meets GDPR requirements for data storage, it doesn’t shield you from access under the provider’s jurisdiction. A US corporation remains subject to the CLOUD Act even with servers in Germany.
What does the US CLOUD Act mean for European customers?
The CLOUD Act obliges US companies to grant US authorities access to stored data upon request, regardless of where the data is physically located. Effective protection only exists if the customer holds encryption keys outside the provider’s reach.
What’s the difference between BYOK and HYOK?
With Bring Your Own Key, the customer supplies their own keys but manages them within the provider’s environment. With Hold Your Own Key, the keys reside in an external system with no provider access. HYOK delivers higher sovereignty because the provider cannot technically decrypt the data.
How do you independently verify sovereignty promises?
Through certifications. The BSI C5 framework documents security and operational promises, while the new C3A process specifically assesses sovereignty features. Neither replaces your own evaluation, but both provide an independent baseline.
Editor’s Reading Picks
- BSI C3A: Cloud sovereignty becomes auditable
- EU Data Act: When the cloud switching fee disappears
- Banning shadow AI is the costliest reflex in IT security
More from the MBF Media Network
MyBusinessFutureGermany’s AI oversight now has an official addressDigital ChiefsThe AI construction boom is coming with a cloud billSecurityTodayWhat is ISO 27001? Definition, certification and boundariesSource of title image: AI-generated
Image source: AI-generated

