“Sovereign clouds” are American hyperscalers’ attempt to secure their attractive European business, while more and more companies are now demanding digital sovereignty: in other words, control over the location, access, and use of their data – not just GDPR compliance, but political and legal resilience against third countries, the USA for example.
“Sovereign cloud” sounds like security. In reality, it’s often just a new label on an old risk. US hyperscalers are selling Europe “sovereignty” that ultimately falls apart under US law. A recent analysis puts it exactly that way: pretty shells, no real independence. (Golem.de)
Reality check: The US CLOUD Act has extraterritorial effect. Meaning: even data in EU data centers can be pulled by a US order – conflict with EU law included. That’s not an opinion; it’s stated that way in the guidelines of the European data protection authorities. (European Data Protection Board)
Confirmed – in black and white: Microsoft’s France executives stated under oath before the Senate (June 10, 2025): they could not refuse a US order – even for data held in France. Several media outlets have documented this. (ActuIA, Forbes)
Political dependence is real, not theoretical. After US sanctions against the International Criminal Court, ICC staff reported that Microsoft had deactivated the chief prosecutor’s email account – who then switched to Switzerland’s Proton Mail. This is the blueprint for how quickly “digital lifelines” can be cut off politically. (AP News)
And when markets shift? In the spring, Microsoft cut central services for customers in China – Outlook, OneDrive, SharePoint for universities and biotech firms, for example. Notice periods: in some cases days. Anyone who hasn’t built their data and service paths to be portable learns about exit strategy the hard way. (South China Morning Post)
The IoT no-bullshit playbook (short & doable)
- Define sovereignty – contractually & technically. EU operation is mandatory, but not enough: exit clauses, data portability, open interfaces, documented models. Without an exit, no sovereignty.
- Keep control of your keys. Encryption is worthless if the provider holds the key. Customer-managed keys, HSM, separate trust.
- Minimize vendor lock-in. Standard protocols (OPC UA/MQTT/HTTPS), open SDKs, export paths, small-scale test migration every 6–12 months.
- Business before buzzword. Data must have a traceable effect in ERP/service/billing – otherwise it remains just an expensive dashboard. Track ROI & risk instead of clicks.
- Sovereignty is location policy. Hosting, operation, support in Europe – and in such a way that no US law can reach through (not even via subsidiaries).
Conclusion: Sovereignty is not a feeling but a capability: at any time auditable, revocable, portable.
Those who build this today buy themselves freedom, resilience, and bargaining power. Those who wait will pay. With dependence.
