The sovereign cloud is attracting more and more interest, but it’s also causing a lot of confusion. Key takeaways:
- Sovereignty is not limited to data localization.
- Regulatory compliance and sovereignty are two distinct issues.
- The level of sovereignty required depends on the risks, the data, and the sector.
- A hyperscaler can offer sovereignty guarantees, just as a European or Swiss provider may have certain dependencies.
- The right choice is, above all, to maintain sufficient control over your data, technologies, and suppliers.
What is the Sovereign Cloud?
Definition
A sovereign cloud refers to a cloud environment designed to maintain a sufficient level of control over your data, your infrastructure, and the conditions under which they are operated.
A study commissioned by the Latin Conference of Cantonal Directors of Digital Affairs defines digital sovereignty as:
“The capacity of a (legal) entity to exercise self-determination with respect to the entire lifecycle of a digital system—from design through use to decommissioning—as well as the digital systems and data that are processed and stored, and the processes they represent.”
In other words, an organization is digitally sovereign when it retains sufficient control over its IT systems and data, from the beginning to the end of their use.
But not every company has the same expectations; what is sufficient for one may not be for another. Thus, there is no single definition of a sovereign cloud, but rather different degrees of sovereignty.
👉 Clément Raussin discusses this in detail in his article on digital sovereignty.
Origins of the Concept and Significance of the CLOUD Act
The growth of the cloud has relied heavily on major U.S. providers—what are now known as “hyperscalers.” Gradually, growing awareness of the dependence on U.S. providers has prompted other countries to seek to regain control.
For example, the French Andromède project, launched in 2011.
However,Edward Snowden’s 2013 revelations about U.S. surveillance programs significantly accelerated awareness regarding data control and jurisdiction.
Since 2018, the Cloud Act has brought greater attention to this issue: a provider subject to U.S. jurisdiction may be required, as part of valid legal proceedings, to produce data under its control even when that data is stored abroad.
💡 Generally speaking, when geopolitical tensions are high, sovereignty rises to the top of the list of concerns.
What is the CLOUD Act?
The CLOUD Act (Clarifying Lawful Overseas Use of Data Act) is a U.S. federal law enacted in 2018, in the context of the legal dispute between Microsoft and the U.S. government over access to data stored abroad.
It clarifies that a service provider subject to U.S. jurisdiction may be required, as part of valid legal proceedings, to disclose certain data it possesses or controls, even when that data is stored outside the United States.
This does not mean giving U.S. authorities unrestricted access to data hosted abroad. However, the fact that data is located in Switzerland or Europe is not necessarily sufficient to exempt it from a request based on U.S. law if the service provider in question falls under U.S. jurisdiction.
How It Differs from Other Cloud Services
These concepts are not equivalent:
- Public cloud: Cloud resources are provided by a vendor to various customers.
- Private cloud: The infrastructure is reserved for use by a single organization.
- Hybrid cloud: It combines resources from the public cloud and the private cloud.
- Sovereign cloud: The issue is not whether the cloud is public or private, but rather what level of control the organization retains over its data, operations, legal framework, technological dependencies, and ability to switch providers.
- Trusted Cloud: This term places greater emphasis on verifiable guarantees of security and legal protection. In France, it is notably associated with services certified as SecNumCloud by ANSSI.
➡️ A private cloud is therefore not necessarily sovereign, and a public cloud is not necessarily devoid of guarantees of sovereignty.

Common Misconceptions About the Sovereign Cloud
Data hosted in Switzerland or Europe ≠ sovereign cloud
Let’s be very clear on one point: a cloud service cannot claim to be sovereign simply because its data is located in Switzerland or Europe. Sovereignty also pertains to:
- the law applicable to your cloud provider,
- access and operations control,
- dependence on suppliers and the technologies used;
- reversibility, that is, the ability to recover one’s data and switch to a different solution or service provider.
The location of data within a country is obviously an important criterion for sovereignty, but it is not enough.
GDPR or LPD ≠ sovereign cloud
Compliance with the LPD and/or the GDPR does not mean you are immune from the U.S. Cloud Act.
Although the two topics sometimes involve the same data and the same cloud providers, they are based on different approaches.
- The GDPR regulates the processing of personal data in order to protect data subjects.
- The CLOUD Act pertains to U.S. authorities’ access to data in the context of legal proceedings: certain service providers subject to U.S. jurisdiction may be required to disclose data under their control, even when that data is stored abroad.
➡️ A service provider can therefore offer services that comply with the requirements of the GDPR while still being subject to certain obligations under U.S. law.
Can a U.S. hyperscale cloud provider be sovereign?
The issue is not quite that black and white. Digital sovereignty does not mean absolute independence from all foreign actors: it is measured across several dimensions and depends on the level of control sought by the organization.
Microsoft offers Microsoft Sovereign Cloud, and Google markets several Google Sovereign Cloud solutions.
Let’s take a closer look at the case of AWS.
In January 2026, AWS launched the AWS European Sovereign Cloud, designed specifically to meet European requirements. The measures put in place are significant:
- a first region located in Germany, physically and logically separate from the other AWS regions;
- dedicated European legal entities established under German law;
- operations managed by personnel residing in the European Union, with a transition toward operations carried out exclusively by EU citizens located in the EU;
- data and metadata stored within the EU;
- an infrastructure designed to continue operating independently of AWS systems located outside the EU.
The AWS European Sovereign Cloud thus significantly strengthens several aspects of sovereignty.
➡️ That said, the European entity remains owned by the American company Amazon. Thus, the legal aspect of sovereignty has not been established.
Why Choose a Sovereign Cloud?
Data Protection and Regulatory Compliance
As we’ve seen, choosing a sovereign cloud does not mean becoming compliant.
In Switzerland, the use of cloud services remains subject to the requirements of the Federal Act on Data Protection (FADP), particularly regarding data processing by third parties, security, and data transfers abroad. The fact that a cloud service is marketed as “sovereign” does not exempt an organization from these requirements.
However, a sovereign cloud can help mitigate certain regulatory risks (location, subcontracting, international transfers, access, jurisdiction) without, however, constituting a general certification of compliance.
💡 The FADP does not require that personal data remain in Switzerland. It may be transferred abroad if the recipient country provides an adequate level of protection or, failing that, if certain exceptions provided for by the FADP permit the transfer. (Source: FDPIC)
Protection Against Extraterritorial Legal Risks
The assumption that “data in Switzerland = protected” should not be replaced by another equally false assumption: “sovereign cloud = no foreign laws can apply.”
Storing data in Switzerland or Europe does not necessarily mean that it is exempt from all foreign laws. The jurisdiction to which the cloud provider is subject also matters.
The U.S. CLOUD Act illustrates this point well: a provider subject to U.S. jurisdiction may, as part of valid legal proceedings, be required to disclose certain data it possesses or controls, even if that data is stored abroad.
Choosing a sovereign cloud solution therefore allows for better management of this legal risk by considering:
- the law applicable to the supplier,
- its legal structure,
- the conditions for accessing the data.
However, this is not absolute immunity: legal sovereignty involves identifying and mitigating these dependencies and risks, not guaranteeing that no foreign authority will ever be able to intervene.
Digital independence and technological sovereignty
Let’s avoid the oversimplification that “foreign technology equals a lack of sovereignty” this time.
As with AWS previously, the appropriate framework for analysis remains the level of dependence and control, not simply the provider’s nationality.
The goal is not to be completely independent—which is rarely feasible—but to retain enough control to be able to take action in the event of a change or problem.
This independence hinges, in particular, on reversibility: the organization must be able to retrieve its data, migrate its services, and switch providers without becoming technically locked in.
It also involves limiting dependence on proprietary technologies or on a single provider, the unavailability of which could jeopardize business continuity. The Swiss Confederation specifically refers to“avoiding or reducing dependence in a targeted manner.”
The real question is, “Do we retain the ability to function, make decisions, and switch to a different solution if necessary?”
💡 Beyond these direct benefits, using a sovereign cloud can also
- Build trust among customers and partners by providing greater assurances regarding data control.
- contribute to the development of the regional digital ecosystem, particularly when it relies on local providers and infrastructure.
What are the specific features of the sovereign cloud in Switzerland?
Here’s a question that comes up regularly: Is the sovereign cloud mandatory in Switzerland?
No, there is no general requirement mandating that Swiss companies use a sovereign cloud or host their data in Switzerland.
Even in the highly regulated financial sector, it is possible to outsource certain activities overseas. This is interesting because the financial sector might seem like an obvious candidate.
On the other hand, certain requirements may call for such a high level of control that a solution offering strong guarantees of sovereignty becomes, in practice, unavoidable. This is particularly the case:
- government agencies and public organizations;
- banks, insurance companies;
- operators ofcritical infrastructure;
- More generally, organizations that process particularly sensitive data, such as health data.
Examples:
- In 2026, the Swiss Army’s cybersecurity unit plans to migrate all of its workstations to an open-source solution. (Source)
- In 2026, the Federal Office of Public Health (FOPH) wants the “SwissHDS” project to be governed exclusively by Swiss law. (Source)
Is the sovereign cloud mandatory?
We need to distinguish between three situations:
- A legal requirement;
- Regulatory constraints that impose requirements similar to those of a sovereign state;
- Contractual or market requirements that may make a certain level of sovereignty essential to winning a contract.
1️⃣ Legally, as we have seen, the sovereign cloud is not mandatory for any organization in Switzerland, not even in the public sector or the financial sector.
2️⃣ However, there is now a much more restrictive requirement in France. Article 31 of the SREN Act and the April 2026 decree apply to certain public entities when they use a private cloud. The French Ministry of the Economy explicitly states that compliance requires, in particular, the use of SecNumCloud services.
So here, we are very close to a de facto sovereignty requirement for certain sensitive public workloads.
3️⃣ Public procurement can also make sovereignty mandatory. This is probably the best example of a constraint that is not universal but is nonetheless very real.
In 2025, the European Commission established a Cloud Sovereignty Framework for its cloud procurement. In the relevant market, it sets a minimum level—known as SEAL—for each aspect of sovereignty. If a bid does not meet the required minimums, it is rejected. Sovereignty thus becomes a criterion for eligibility in the market, not merely a marketing pitch.
4️⃣ In the European financial sector, the 2025 DORA (Digital Operational Resilience Act) does not require banks, insurance companies, and other European financial institutions to use a sovereign cloud.
On the other hand, when they outsource critical or important functions, they must:
- know the countries in which the services and data are processed or stored,
- assess the risks associated with service providers located in third countries,
- have effective exit strategies in place.
💡 Don’t confuse DORA (Digital Operational Resilience Act) with the organization DORA (DevOps Research and Assessment).
Key players in Sovereign Cloud
In Switzerland
The Swiss Confederation plays an important role in this development. With the Swiss Government Cloud (SGC), which is scheduled to be implemented between 2025 and 2032, it is developing an infrastructure capable of meeting various levels of digital sovereignty requirements. The project combines several cloud models rather than seeking a single solution applicable to all uses. (bit.admin.ch)
Organizations such as eCH, as well as Swiss research and higher education institutions, are also part of this ecosystem. For example,EPFL,ETH Zurich, and CSCS have developed Apertus, an open-source language model trained on the Swiss supercomputer Alps.
These initiatives illustrate another aspect of sovereignty: the ability to develop and master certain strategic technologies locally. (ech.ch) (epfl.ch)
Finally, cloud providers, data center operators, and integrators/IT services firms are involved at various stages of the chain: hosting, infrastructure, operations, migration, and architecture.
In Europe
The European Union is seeking to strengthen its control over the cloud. Its approach is interesting because it does not limit sovereignty to the location of data or the nationality of the provider.
Measuring Cloud Sovereignty in Practice with the Cloud Sovereignty Framework
The European Commission has therefore developed a Cloud Sovereignty Framework to provide a concrete assessment of the level of sovereignty of a cloud offering. First presented in 2025 and then detailed in June 2026, this framework examines eight dimensions:
- strategy,
- jurisdiction,
- data and AI,
- operation,
- supply chain,
- technology,
- security and compliance,
- environmental sustainability.
The Commission also calculates a score based on 48 specific criteria.
The goal, therefore, is not simply to determine whether a cloud is “sovereign” or “non-sovereign,” but to assess the level of control that the solution actually provides.
➡️ The Commission acknowledges, however, that this maximum level is not realistic at present for many services, particularly due to Europe’s dependence on chips and computer hardware.
List trusted suppliers
In April 2026, the Commission awarded a contract worth up to 180 million euros over six years to provide sovereign cloud services to EU institutions and agencies. Four providers were selected:
- Post Telecom, which relies on CleverCloud and OVHcloud,
- STACKIT,
- Scaleway,
- Proximus, which relies on S3NS, Clarence, and Mistral.
➡️ One point is particularly telling: the Commission specifies that non-European technologies can also meet the required level of sovereignty, provided they are used within a framework that offers sufficient safeguards.
Cloud and AI Development Act
In June 2026, the Commission presented a proposal for the Cloud and AI Development Act (CADA).
The text establishes a common framework for the entire Union:
- to assess the sovereignty of cloud and AI services,
- to significantly expand Europe’s data center capacity. The Commission aims to at least triple this capacity in the coming years.
💡 As of the time of this article’s publication, however, this is still a proposal, not a regulation that has been definitively adopted.
How do you go about choosing a sovereign cloud solution?
Selection criteria
Ask yourself a few specific questions:
- Where is my data stored and processed?
- Who has access to it, including at the supplier and its subcontractors?
- Under which jurisdictions is the supplier subject?
- Who actually operates the infrastructure, and from which countries?
- Which vendors or technologies will I be dependent on?
- Can I easily restore my data and apps?
- Can I switch providers without having to rebuild my entire system?
- What happens if the provider becomes unavailable, makes significant changes to its offerings, or discontinues the service?
💡 Our advice: Really dig into these simple questions with your provider. If they simply describe themselves as “sovereign,” no, that’s not enough.

Certifications, seals of approval, qualifications
Certainly, certifications and labels can supplement this analysis, but they must be interpreted based on what they actually cover.
Example: ISO/IEC 27001, which is often highlighted, primarily concerns information security management; it does not constitute proof of sovereignty.
That said, in France, the SecNumCloud certification is truly valuable: it incorporates technical, operational, and legal requirements designed to provide protection against extraterritorial laws.
Qim Info helps you set up a sovereign cloud
We do not view the sovereign cloud as a solution to be applied across the board. Our approach is to first determine the level of control that is actually necessary for your company.
A Cloud Foundation Designed to Keep You in Control
That is precisely the philosophy behind our Cloud Foundation: to create a standardized, automated, and ready-to-use cloud foundation, while preserving your freedom of choice.
Our goal, therefore, is not to lock you into “our” cloud, but to allow you to retain control over your infrastructure: whether you choose to operate it with Qim info, bring it in-house, or eventually entrust it to another service provider.
From Consulting to Migration
Our teams can also get involved early on to help you define your strategy and determine the architecture best suited to your requirements.
Our expertise in cloud consulting enables us, in particular, to help companies choose the right technologies, vendors, and the level of sovereignty that is truly necessary.
When a project involves upgrading an existing infrastructure, our cloud migration services cover the preparation and migration of applications and data to a new cloud architecture—whether it is sovereign, European, public, or hybrid.
Our guiding principle remains the same: to use the cloud to gain greater autonomy, resilience, and scalability—not to replace one dependency with another.
FAQ
What is a sovereign cloud?
A sovereign cloud is a cloud environment that allows an organization to maintain a sufficient level of control over its data, access to that data, the applicable jurisdiction, its technological dependencies, and its ability to switch providers. Therefore, the location of the data alone is not sufficient to make a cloud sovereign.
What is the difference between a cloud and a sovereign cloud?
A cloud provides remote computing resources: storage, computing power, applications, and so on. A sovereign cloud adds requirements regarding control over data, access, jurisdiction, operation, and reversibility. A public or private cloud can therefore offer varying degrees of sovereignty.
Which sovereign cloud is available in France?
There is no single sovereign cloud in France. For sensitive needs, ANSSI’s SecNumCloud certification serves as the French standard for trusted cloud services, with technical, operational, and legal requirements. In particular, offerings from Cloud Temple and S3NS are certified; the list of certified services is subject to change and should be verified with ANSSI.