Beyond data residency: Defining true cloud sovereignty

Beyond-data-residency:-Defining-true-cloud-sovereignty

In this ISJ exclusive, Martin Hosken, Field CTO of Broadcom discusses all things sovereign cloud and what this means for data.

Sovereign cloud is one of the most common buzzwords in enterprise technology today, yet there is still confusion over the true definition.

Cloud providers often position their offerings as sovereign by pointing to local data residency or European ringfencing.

However, these claims often disguise a more fundamental issue – who is ultimately controlling the data?

Rising concerns around the jurisdictional control of cloud services in Europe and the dominance of US hyperscalers is making this an even more pressing challenge.

More than two-thirds of Europe’s cloud computing market is controlled by Amazon Web Services, Microsoft Azure and Google Cloud (together).

Europe now faces a clear question: how can it build a cloud ecosystem that delivers both real jurisdictional control and long-term independence?

The foundations of true cloud sovereignty

Sovereign cloud is not only a question of where data physically resides, but also of who has legal authority over it and the dependencies associated with it.

These include technology, supply chains and vendor lock-in, which may either enable or constrain freedom of action as sovereignty is understood.

Data residency answers the ‘where’ question, sovereignty addresses the ‘who’ and “up to which point”. This distinction is crucial when considering the different aspects of sovereignty.

Take the question of legal authority for instance, in light of legislation such as the US CLOUD Act and Section 702 of the Foreign Intelligence Surveillance Act (FISA).

Both pieces of legislation permit US courts and agencies to require US-headquartered firms to provide access to data related to investigations via warrants or other processes, even when hosted abroad.

In practice, this means that a European bank, healthcare provider or government department relying on an American cloud operator may not easily determine whether the data of some of its European customers has been provided to US law enforcement or intelligence agencies, even if the data resided outside the US.

For organisations entrusted with sensitive information, that exposure is not theoretical. It is a live compliance and trust issue.

True sovereignty therefore requires more than local hosting. It demands that both the infrastructure and the jurisdiction are aligned with the customer’s own legal environment.

It also requires interoperability and portability across cloud environments, allowing organisations to choose where and how workloads run without being locked into a single provider.

It also requires transparency on the underlying technology and supply chain, as well as the ability to risk manage and make choices that reduce dependencies or concentration.

True sovereignty remains unclear

This is why there are still many questions surrounding the sovereign offerings from US hyperscalers.

Providers have launched initiatives that prioritise enhanced European control or partnerships with local entities.

Yet because the parent companies remain subject to US law, there are customer concerns of a jurisdictional gap.

Put simply, a sovereign wrapper around non-sovereign foundations does not fully resolve the issue in every case.

Customers may achieve greater assurances about data location or operational independence, but unless the operating entity is legally insulated from foreign jurisdiction and enables customers to make choices, the claim of sovereignty remains partial.

For critical workloads, such as those in public sector organisations, regulated industries and AI applications, relying on US-controlled clouds introduces operational and compliance risk that cannot be fully mitigated by local hosting alone.

The urgency for definition

The speed of market growth makes clarity urgent. The global sovereign cloud market size is projected to grow from USD 154.69 billion in 2025 to USD 823.91 billion by 2032.

Europe alone accounted for around 37% of the global market in 2024.

This growth reflects rising demand for secure, trusted environments, particularly in Europe, where regulatory frameworks such as DORA, the GDPR and Data Act emphasise local control, risk management, supply chain transparency and concentration risk.

The European Union, for instance, has made digital sovereignty a strategic priority, while countries like Germany and the UK are exploring frameworks to ensure their critical data assets cannot be subject to overseas legal claims.

The direction of travel is clear; sovereignty must be defined and enforced, not assumed.

The case for stronger sovereign ecosystems

What’s needed is a consistent framework defining what constitutes a sovereign cloud. EU Member States have created cloud certification schemes like C5 in Germany and SecNumCloud in France that contain sovereignty criteria.

DGIT, the European Commission IT service, has made a notable attempt in the context of procurement to define sovereignty in the form of a scale of requirements.

All these attempts, while welcome, demonstrate the fragmentation of the EU market.

Customers are often left to navigate competing claims and complex technical language without clear standards for comparison.

A truly sovereign cloud should guarantee that data is controlled, accessed and governed exclusively within the jurisdiction of the customer.

Achieving this does not mean retreating from global innovation.

It requires enabling local providers to deliver services that meet sovereignty criteria without compromise.

European cloud service providers such as Redcentric and ANS are well positioned to fulfil this role.

By operating under local legal and compliance frameworks and investing locally, they can give organisations genuine control over their data.

In many cases, this control is best realised through private cloud environments, where infrastructure, governance and operational authority can be aligned directly to sovereignty requirements.

Technology vendors have a role to play in supporting this ecosystem. By providing the platforms, infrastructure and interoperability frameworks, they can empower local providers without becoming operators themselves.

This distinction matters.

It avoids entanglement with foreign jurisdictions while fostering an environment where sovereignty is embedded by design rather than bolted on afterwards.

From rhetoric to reality: A sovereign future

The focus is now on whether sovereign cloud offerings can provide genuine, enforceable control over data in a way that meets customer needs.

True sovereignty must be embedded within cloud services from the outset, with governance structures aligned to the data they protect.

The discussion extends beyond infrastructure alone, with considerations such as trust, autonomy, resilience and long-term economic competitiveness increasingly shaping decision-making in the digital economy.

Businesses and governments must look beyond surface-level claims for a sovereign by design future.

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox