Site navigation

Is It Time For a New Sovereign Cloud Code in Europe?

Graham Turner

,

Sovereign Cloud Code
Concerns about data privacy, regulatory compliance, and foreign government access underscore the growing importance of sovereign cloud solutions.

A new report commissioned by Broadcom is calling for the establishment of a new Sovereign Cloud Code of Conduct to address legal uncertainty surrounding cloud services in Europe.

Authored by Johan David Michels based on research conducted for the Cloud Legal Project at the Centre for Commercial Law Studies, Queen Mary University of London, the report highlights widespread concerns among organisations regarding legal risks, compliance challenges, and the lack of clarity on cloud sovereignty.

Global spending on sovereign cloud solutions is set to reach nearly USD $260 billion by 2027, marking a significant shift in the cloud computing landscape. For European organisations, this is a time of reckoning and transformation, driven by the evolving regulatory environment and the heightened need for data privacy and control. As we delve into the concept of sovereign cloud, its growing importance, and the challenges facing European businesses, it becomes clear why 2025 marks a critical moment in the adoption of these technologies.

Titled Sovereign Cloud for Europe, the report’s findings come at a critical time as the European Union (EU) intensifies efforts to regulate digital infrastructure, including cloud services.

With data sovereignty becoming a growing priority for governments and businesses alike, the report sheds light on the challenges of navigating an increasingly complex regulatory environment while ensuring secure and reliable cloud adoption.

Understanding Sovereign Cloud

Sovereign cloud is a term that has generated much debate and discussion within the IT and legal sectors. While it means different things to different people, it is generally understood to be a cloud service offering that prioritises customer control and autonomy, especially in relation to the access and security of sensitive data.

At its core, sovereign cloud is about giving organisations more control over where their data resides, who can access it, and under what circumstances.

For European organisations, this concern stems from a deep-seated unease about foreign governments’ potential access to their data, especially after the Snowden revelations in 2013, which brought to light how US intelligence agencies could potentially access European data stored with US-based providers.

This fear has been compounded by the increasing complexity of cross-border data transfers, as evidenced in the Schrems I and II rulings by the European Court of Justice, which focused on the adequacy of data protection measures when data is transferred outside of the EU.

In essence, sovereign cloud represents a solution that not only addresses these concerns, but also provides European businesses with the ability to operate more independently and securely in an increasingly globalised digital world.

The Demand for Sovereign Cloud in Europe

The demand for sovereign cloud services is overwhelmingly driven by regulation. According to the report, 70% of European organisations expect to adopt sovereign cloud in order to ensure compliance with existing regulations and government standards, with concerns over data privacy and protection being top of mind.

The General Data Protection Regulation (GDPR) plays a significant role in this. The GDPR places strict requirements on the handling of European personal data, especially when it comes to cross-border data transfers.

These concerns are not limited to just any international transfers but particularly to those involving US-based providers, given the reach of US law, including provisions that may compel cloud providers to disclose customer data to US authorities without customer consent.

Adding to this complexity are national regulations in some EU member states, such as the French SecNumCloud certification, which mandates that cloud providers used by the government must not be subject to foreign ownership.

This reflects a growing recognition that data sovereignty is not just about controlling where data is stored, but also about ensuring that the service provider is not under the influence of foreign jurisdictions, particularly those with access to foreign intelligence agencies.

In light of these regulatory and geopolitical concerns, European organisations are increasingly turning to sovereign cloud solutions to mitigate the risks associated with external government access and data misuse.

Data Privacy and Foreign Government Access

According to the report, one of the most pressing concerns for European businesses when it comes to cloud computing is the potential exposure to foreign government access. In fact, 69% of European organisations cite concerns about the possibility of foreign governments accessing their data stored in the cloud.

To understand the gravity of this issue, consider that many US-based cloud providers are bound by US law, which requires them to disclose data to the US government upon request, often without the knowledge or consent of the customer. The GDPR requires data controllers to ensure that their cloud providers offer sufficient guarantees that the personal data they process will be protected in accordance with European standards.

When these providers are subject to foreign jurisdictions, particularly the US, the report poses the question: can they truly guarantee that data will not be handed over to foreign authorities?

For European regulators, this concern is part of a broader debate about Europe’s digital sovereignty. The overreliance on US-based cloud providers not only raises privacy and security risks but also undermines Europe’s strategic autonomy, making it vulnerable to potential political and economic influence from outside powers.

The European Commission has taken steps to address these concerns, advocating for the development of a European cloud ecosystem that would allow European businesses to store and process their data in Europe, free from the risk of foreign government interference. However, while these efforts are ongoing, they have yet to fully address the complex issues raised by US jurisdiction over cloud providers.

The Role of the 2023 EU-US Data Privacy Framework

In 2023, the EU and the US came together to create the EU-US Data Privacy Framework (DPF), a new agreement aimed at facilitating international data transfers while ensuring a higher level of protection for European personal data.

This framework was seen as a necessary step forward in the wake of the Schrems II ruling, which invalidated the previous Privacy Shield agreement due to concerns over US surveillance practices.

While the DPF represents progress, the report states that it has not fully resolved the issue of foreign government access to data, particularly when it comes to intelligence gathering. The framework primarily addresses commercial data transfers, but it does not explicitly cover situations in which data may be accessed for national security or law enforcement purposes. This leaves a gap in legal protections that sovereign cloud aims to fill.


Recommended reading


For European organisations, the DPF provides some reassurance, but it is far from a panacea. The key question remains whether US law offers sufficient protection against arbitrary or overreaching government access to personal data, a question that will ultimately be answered by the Court of Justice of the European Union (CJEU).

Challenges in Adopting Sovereign Cloud Solutions

While the demand for sovereign cloud is growing, the path to adoption is fraught with challenges. One of the most significant hurdles is the lack of interoperability and portability between different cloud environments. A typical European organisation may need to migrate its data and applications between multiple cloud providers to optimise performance, security, and cost-efficiency.

However, the lack of standardised protocols and technical tools for cloud migration makes this process cumbersome and costly.

Additionally, the complexity of compliance with regulations such as the GDPR further complicates the adoption of sovereign cloud. For instance, organisations must assess the sensitivity of the data they process and determine which data requires additional protection, a process that can be both time-consuming and resource-intensive.

These challenges are expected to be addressed, at least in part, by the EU’s upcoming Data Act, which is set to come into effect in September 2025.

The Data Act will introduce new requirements for cloud providers, including the need to identify the jurisdictions to which their infrastructure is subject and to describe the measures they have taken to prevent government access to data. However, it remains to be seen how effectively these measures will be implemented in practice.

The Need for a Sovereign Cloud Code of Conduct

Given the lack of clarity in the current regulatory landscape, the report proposes the development of a new Sovereign Cloud Code of Conduct as a potential solution to address the legal uncertainty surrounding the use of cloud providers subject to foreign jurisdictions.

The idea would be to create a set of industry-wide guidelines that can help cloud providers demonstrate their compliance with the GDPR and reassure customers that their data will not be exposed to undue government access.

The Code would build on existing codes of conduct for cloud services, such as the EU Cloud Code of Conduct (EUCoC) and the Cloud Infrastructure Service Providers in Europe (CISPE) Code. However, it would go further by addressing the specific risk of foreign government access and providing customers with clear assurances that their data will be protected from undue foreign influence.

While the creation of such a code is a complex, multi-year project, the report claims that it would represent a crucial step toward providing legal certainty and fostering trust in the sovereign cloud market. Once approved by regulators, it would give European organisations the confidence they need to adopt sovereign cloud solutions and protect their data.

“The push for sovereign cloud provides the perfect storm for Cloud Service Providers (CSPs) in Europe to thrive”, says Martin Hosken, Field CTO, Cloud Partners at Broadcom.

He adds: “They need to position themselves as trusted partners to those organisations on their sovereign cloud journey – helping them navigate the challenges of this move. This involves helping them assess and classify their data based on sensitivity and compliance needs, particularly for personal data under GDPR.

“CSPs can also help customers navigate through the complex mix of cloud services, enable a single operating model and maximize interoperability between providers to avoid isolated workloads.”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data