Sovereign Cloud Hosting Europe: GDPR Compliance & Data Control
What is sovereign cloud hosting in Europe? Learn why it differs from data residency, which providers offer true sovereignty (OVHcloud, Scaleway, Exoscale), and how to migrate from hyperscalers.
- Sovereignty combines European ownership, EU data centers, and legal independence from US law--data residency alone is insufficient under GDPR and NIS2.
- Regulatory mandates (NIS2, EU Data Act, EU Cloud & AI Act) make sovereign cloud mandatory for critical infrastructure and essential services.
- Top providers: OVHcloud (1.6M customers, 1.1B revenue, 40-50% cheaper than AWS), Scaleway, Exoscale, Hetzner, and STACKIT each serve different use cases.
- Combine sovereign cloud with managed deployment platforms like Ship to gain two-layer control: infrastructure sovereignty plus application-level privacy.
- Migrate incrementally: pilot non-critical workloads first, then hybrid approach, then full migration over 6-12 months.
Sovereign cloud hosting in Europe means your data stays under European legal jurisdiction, protected from US surveillance laws like FISA Section 702 and the CLOUD Act. This differs sharply from "data residency" alone: sovereignty requires the provider to be European-owned, the data centers in Europe, and all operations compliant with EU law. You need this now because NIS2 (effective 2024) and the EU Data Act make it a compliance mandate for critical infrastructure, not a competitive advantage anymore.
What Is Sovereign Cloud Hosting? Data Residency Is Not Enough
True sovereignty combines three elements: legal ownership (the provider is European-controlled), jurisdictional control (data centers sit in EU member states), and operational independence (the company and all personnel are bound by EU law, not US law). "Data residency" alone--where servers sit physically in Europe but the company is US-owned--does not grant sovereignty. AWS's "European Sovereign Cloud" marketing claims sovereignty but faces regulatory skepticism because Amazon remains a US corporation subject to CLOUD Act requests from US law enforcement. That means Amazon can be legally compelled to hand over your European customer data to US authorities.
The real danger emerged with the CLOUD Act (2018), which allows US law enforcement to request data from any US-registered company, anywhere. Then FISA Section 702 (US surveillance law) compounded the risk: US companies can be forced to hand over European customer data to US intelligence agencies without a warrant or any notice to you. GDPR theoretically forbids this, but regulators cannot enforce GDPR once a US federal court issues a secret order. You choose sovereign cloud to close that gap entirely: a truly European provider cannot comply with US legal demands because it has no US parent company and no US business requiring it to obey US court orders.
This distinction matters because regulators now enforce it. The European Court of Justice invalidated the Privacy Shield (2020) and placed strict conditions on Standard Contractual Clauses (2021), precisely because US law overrides them. The Schrems II decision (2021) established that US legislation and surveillance practice are fundamentally incompatible with EU standards. You cannot use US-based infrastructure for sensitive EU customer data and claim GDPR compliance anymore.
Why Sovereignty Matters for European Organizations in 2025-2026
Regulatory mandates are tightening aggressively. NIS2 (the revised Network and Information Security Directive) became enforceable in 2024 for operators of essential services and important digital services (energy, transport, water, finance, healthcare, digital infrastructure). It requires you to demonstrate control over where data lives and who can access it. Auditors will ask: "Where is your data? Who owns the infrastructure? What law applies?" A US-hosted provider fails this test.
The EU Data Act (2024) gives users the right to retrieve their data from a single provider in a common format, which is much easier with a European sovereign provider than a hyperscaler. The EU AI Act (2025) adds compliance layers around AI model training, data usage, and processing documentation. The EU Cloud & AI Act provisions designate "critical digital infrastructure"--healthcare, energy, finance, government--and require higher standards for these sectors. Sovereign cloud providers are preferred because they are easier to audit and regulate at the EU level.
But regulations are only part of the story. Geopolitical tension is real. US-EU disputes over data, trade, and technology have intensified. Companies relying on AWS, Google Cloud, or Azure have seen their data caught in political and legal conflicts. You also face customer pressure: enterprise buyers now demand "hosted on European sovereign infrastructure" clauses in contracts. B2B SaaS vendors targeting European organizations increasingly add sovereignty certifications to their sales materials because it is now expected. Cost pressure exists too: sovereign cloud providers often undercut hyperscalers by 40-50% because they have lower operational overhead and do not cross borders with compliance complexity.
The Legal & Regulatory Landscape That Now Governs Your Choice
GDPR remains the foundation, but alone it is insufficient because it cannot override US law. GDPR Article 5 demands lawful, fair, transparent processing. Article 44 restricts transfers of personal data outside the EU/EEA. But the CLOUD Act sidesteps GDPR entirely: a US company holding EU customer data can be compelled to hand it over regardless of GDPR contract language. The European Court of Justice (Schrems II, 2021) ruled that Standard Contractual Clauses cannot protect EU data transferred to US providers because US surveillance law overrides those clauses. You must treat US-based cloud infrastructure as non-compliant for sensitive data.
NIS2 (Directive 2022/2555) applies to operators of essential services and important digital services. It requires documented risk management, incident response plans, supply chain security audits, and regular third-party assessments. A sovereign cloud provider helps you meet this because you control the audit trail. You can prove that data never left your jurisdiction and that every access was logged.
SecNumCloud (French ANSSI certification) and BSI C5 (German certification) are regional regulatory frameworks. If you operate in France, SecNumCloud-certified providers (OVHcloud, Scaleway, Clever Cloud) give you direct regulatory comfort. Germany's BSI C5 similarly validates DACH-region providers like STACKIT and Hetzner. You should check whether your industry regulator or country of operation recognizes these certifications--they carry weight in government audits.
The EU Cloud & AI Act (2025) and the EU Data Act (2024) add compliance layers. Neither creates outright bans on US cloud providers, but both require demonstrable control, audit transparency, and compliance proof. Sovereign cloud providers make these requirements much cheaper to satisfy.
How to Evaluate a Provider: Five Criteria That Separate Real Sovereignty From Marketing
The market is flooded with "sovereign cloud" claims. Here is how to distinguish substance from marketing noise.
1. Ownership Structure: Is the company European-owned and independent, or does it have a US investor or parent? OVHcloud is French-founded (1999) and still majority-owned by founder Octave Klaba--you can verify this. Scaleway is French (owned by Iliad, a French telecom group). Hetzner is German and family-owned. STACKIT is German (owned by the Schwarz Group, the retailer behind Lidl and Kaufland). If a provider has US venture capital on the cap table or a US parent company, scrutinize the shareholder agreements and any clauses that allow US government access. Red flag: any US venture capitalist with board seats or investor protections that could force compliance with US law.
2. Data Center Jurisdiction: Where do the servers physically sit? Map the provider's data center locations. OVHcloud operates 43 data centers across 19 countries, including multiple EU zones (France, Germany, Poland, Czech Republic, UK, Netherlands). Exoscale runs on OVHcloud infrastructure, so it inherits those EU data center choices. Hetzner operates data centers in Germany, Finland, and other EU countries. If a provider claims "European" but lists servers in Switzerland only or UK-only (post-Brexit), check whether UK data is treated as EU-equivalent. It is not under GDPR: UK data transfers require additional safeguards.
3. Personnel & Operations: Are the company's engineers, support team, and security staff based in Europe? This matters because a US-based employee can be remotely compelled by US law to access systems. Many global providers operate support teams across US time zones and cannot guarantee that only European staff access infrastructure. Smaller providers (IONOS, Infomaniak, UpCloud) typically have European-based teams. Ask directly: "Where is your network operations center (NOC) and who monitors infrastructure during US business hours?" If the answer involves US contractors or US-based remote access, you lose true sovereignty.
4. Open Standards vs. Proprietary Lock-in: Does the provider use open standards (Kubernetes, OpenStack, REST APIs) or proprietary formats? OVHcloud and Exoscale offer Kubernetes-native deployments. They participate in Gaia-X, the open framework for federated European cloud. Hetzner offers standard Linux VMs with no proprietary abstractions. Providers that force you into proprietary services (AWS Lambda equivalents, custom databases, managed AI services) lock you in because you cannot easily migrate to another sovereign provider if the relationship sours. You must accept feature tradeoffs if you choose open-standards providers--they rarely match hyperscaler managed services, but you gain portability.
5. Audit & Compliance Transparency: Can you actually audit the provider's security and compliance, or do you have to trust their word? Ask for SOC 2 Type II reports, third-party security audit results, and proof of compliance with claimed certifications. OVHcloud publishes detailed compliance documentation. Exoscale offers audit trail access. Smaller providers may have limited audit evidence available. You need written proof--not a marketing slide--that the provider's infrastructure meets your requirements, especially if you operate in healthcare, finance, or critical infrastructure.
Leading European Sovereign Cloud Options: Brief Overview
OVHcloud (France, founded 1999) is the largest independent European cloud provider by scale. It serves 1.6 million customers and generated EUR 1.1 billion in annual revenue (2025). It runs 43 data centers across 19 countries. It offers a broad stack: virtual machines, Kubernetes, managed databases, object storage, backup services, and more. Pricing is significantly lower than AWS--typically 40-50% cheaper for equivalent compute and storage. The tradeoff: managed services are limited (no Lambda equivalent, limited AI/ML offerings). Ideal if you need breadth, European ownership assurance, and cost efficiency.
Scaleway (France, founded 1999, backed by Iliad) targets developers and startups. It offers object storage, managed Kubernetes, virtual machines, and serverless functions with a minimal, developer-friendly interface. It is SecNumCloud-certified (French regulatory validation). Pricing is competitive--slightly higher than OVHcloud but significantly lower than AWS. The tradeoff: fewer enterprise features (limited disaster recovery, no managed PostgreSQL replication across zones). Ideal if you run containerized workloads and value simplicity.
Exoscale (Switzerland, operated by Akenes SA and part of A1 Digital, the A1 Telekom Austria Group) provides managed Kubernetes and cloud-native tools from its own European data centers in Switzerland, Austria, Germany, Bulgaria and Croatia. The tradeoff: a smaller footprint than the hyperscalers and a narrower managed-service catalog. Ideal if you want managed Kubernetes without hyperscaler complexity.
Hetzner (Germany, family-owned) operates dedicated servers and cloud VMs with a minimalist model. It is known for low cost and good performance. It is not certified (no SecNumCloud or BSI C5), but operates transparently within Germany. Pricing is the lowest in the market. The tradeoff: minimal managed services, infrastructure only. Ideal for companies with internal DevOps expertise who prefer control and cost savings.
STACKIT (Germany, owned by the Schwarz Group, the retail group behind Lidl and Kaufland) focuses on enterprise use cases in DACH (Germany, Austria, Switzerland). It offers OpenStack-based virtual machines and Kubernetes, and runs data centers in Germany and Austria, keeping processing inside the EEA. Pricing is enterprise-grade (higher than OVHcloud). The tradeoff: lower market maturity outside DACH, limited geographic footprint. Ideal if you operate in German-speaking regions and need carrier-grade support.
Infomaniak (Switzerland, privacy-focused) emphasizes security and data ownership. It operates entirely within Switzerland under Swiss law (stricter than GDPR in several areas). Pricing is premium. The tradeoff: smaller ecosystem, limited managed services. Ideal for organizations that prioritize Swiss jurisdiction and privacy as a primary constraint.
Self-Hosted & Managed Deployment Platforms: How Ship Fits Into Sovereign Cloud Strategy
Sovereign cloud hosting alone does not guarantee privacy if your application leaks data or your deployment pipeline is compromised. Ship (a managed deployment platform) adds a second control layer: you deploy applications to sovereign cloud infrastructure while keeping your codebase, configuration, and data pipelines under your governance.
Ship works by running your application containers on your chosen cloud provider: a sovereign provider like OVHcloud, a private data center, or both. You define the deployment (Dockerfile, environment variables, database connection strings) and Ship orchestrates it. Critically, you own all credentials. You see every deployment. Data never passes through Ship's systems except in transit. This is radically different from Heroku or traditional PaaS providers, which abstract away infrastructure control and lock you into their proprietary platform.
The sovereignty angle: by combining Ship with sovereign cloud hosting, you achieve two-layer control. Your infrastructure is on OVHcloud or Scaleway (European ownership, no US law exposure). Your application deployment is managed by Ship, a tool that keeps your code and secrets private. You maintain an escape hatch: if you need to leave Ship, your code is already containerized and portable to any other sovereign cloud provider or self-hosted deployment system.
For applications handling sensitive data (customer PII, health records, financial data), this combination is powerful. You avoid hyperscaler SaaS lock-in and US law exposure simultaneously. You gain auditability: regulators can verify that data never left your chosen sovereign infrastructure.
Migration Path: Moving From Hyperscalers to Sovereign Cloud
Most organizations run on AWS, Google Cloud, or Azure. Moving to sovereign cloud is not trivial, but it is feasible and increasingly common.
Phase 1: Audit Your Workloads (2-4 weeks) Map which applications are on the hyperscaler. Identify critical (regulatory, high-performance) versus commodity workloads. Typically, 20-30% of workloads genuinely need hyperscaler features (Lambda, BigQuery, AI services). Seventy percent are standard VMs, relational databases, and object storage, which any sovereign cloud provider can handle at lower cost.
Phase 2: Pilot a Non-Critical Workload (4-8 weeks) Take a development or staging environment and migrate it to sovereign cloud (OVHcloud, Scaleway, or Exoscale). Use this to learn the provider's tooling, pricing model, and support responsiveness. Automate the deployment (Terraform, Infrastructure as Code) so you can replicate it. Measure latency, throughput, and cost against your hyperscaler baseline.
Phase 3: Hybrid Approach (ongoing) Keep the hyperscaler for Lambda, Rekognition, or other managed services you genuinely need. Migrate commodity workloads to sovereign cloud. Use a hybrid load balancer or multi-cloud orchestration tool (Terraform, Ansible) to manage both. This reduces risk and lets you migrate at your pace.
Phase 4: Full Migration or Sunset (6-12 months) Once you have proven sovereign cloud handles the bulk of your workloads, decide: migrate what is left (rewrite Lambda to cron jobs, switch BigQuery to SQL), or accept the cost of maintaining both. Full migration saves money (sovereign cloud is 30-50% cheaper) and removes US law exposure. Most organizations complete this within 12 months if they prioritize it.
Hidden complexity: hyperscalers auto-scale transparently, so migrating a workload that spikes to 10x traffic requires you to think about scaling upfront on sovereign cloud. Most sovereign providers support auto-scaling (OVHcloud, Scaleway, Exoscale), but you must configure it explicitly. Allow 1-2 weeks per critical workload for this tuning. Ship's deployment automation reduces this overhead by handling scaling configuration for you.
Frequently Asked Questions
What is the difference between data residency and data sovereignty?
Data residency means your data sits in a specific geographic location (e.g., servers in Germany). Data sovereignty means your data is under the legal control and jurisdiction of that country--both the infrastructure location and the company operating it are subject to that country's law. You can have residency without sovereignty: AWS Europe (Ireland) is physically in Ireland but legally subject to US law. You need sovereignty to pass NIS2 and GDPR audits.
Does AWS European Sovereign Cloud actually provide sovereignty?
No. AWS remains a US corporation owned by US shareholders and subject to US law, including the CLOUD Act and FISA Section 702. Amazon can be legally compelled to hand over data. True sovereignty requires the provider itself to be European-owned and operated. OVHcloud, Scaleway, and Hetzner provide actual sovereignty. AWS's "European Sovereign Cloud" is data residency marketing, not sovereignty.
What does NIS2 require regarding cloud infrastructure?
NIS2 (Directive 2022/2555) requires operators of essential services and important digital services to maintain control over data location, implement documented risk management, conduct regular security audits, and report incidents. It does not ban US cloud providers, but it requires you to prove control and auditability. Sovereign cloud providers make this proof easier because you control the entire stack and can demonstrate compliance.
Can I use a mix of sovereign and hyperscaler infrastructure?
Yes. Many organizations run sensitive workloads on sovereign cloud (customer PII, health data, financial data) and less sensitive workloads on hyperscalers (development environments, non-critical services). This hybrid approach reduces risk and lets you migrate incrementally. Use a load balancer or orchestration tool (Terraform) to manage both.
Which European sovereign cloud provider is cheapest?
Hetzner is the lowest-cost option for raw compute. OVHcloud is slightly higher but offers a broader managed services stack. Scaleway is competitive and includes managed Kubernetes. Pricing varies by workload: OVHcloud may be cheaper for database workloads, Hetzner for compute-only. Get quotes for your specific workload before deciding.
Is sovereign cloud suitable for large enterprises?
Yes, but with caveats. OVHcloud and STACKIT serve large enterprises. Exoscale and Scaleway suit mid-market and startup workloads. All sovereign providers have smaller managed services ecosystems than hyperscalers, so you may need to run more infrastructure yourself. This is a tradeoff: less managed convenience, but more control and compliance certitude.
What certifications should I look for in a sovereign cloud provider?
Look for SOC 2 Type II (security audit), SecNumCloud (French ANSSI certification), BSI C5 (German certification), ISO 27001 (security management), and third-party penetration test results. These prove the provider has undergone external audits. Do not trust "security by marketing"--ask for proof.
How long does it take to migrate from AWS to sovereign cloud?
A small workload (single application) takes 4-8 weeks. A large organization with 50+ applications takes 6-12 months if prioritized. The biggest delays come from feature parity (rewriting Lambda functions, migrating from managed services) and organizational change management (ops teams learning new tools). Start with non-critical workloads to build confidence.
The Bottom Line
Sovereign cloud hosting is no longer optional. NIS2, the EU Data Act, and geopolitical tension make it a compliance requirement and strategic imperative. You must distinguish between data residency (physical location) and sovereignty (legal control and European ownership). Evaluate providers on ownership structure, data center jurisdiction, personnel location, standards openness, and audit transparency. For European organizations handling sensitive data, OVHcloud and Scaleway are proven choices with regulatory certifications. For development-first teams, Scaleway and Exoscale reduce operational friction. For cost-conscious infrastructure, Hetzner delivers. For enterprise DACH operations, STACKIT carries carrier credibility.
Deploy to sovereign cloud with a managed platform like Ship to layer governance and deployment control on top of your infrastructure choice. Combine infrastructure sovereignty with application-level control, and you close both the legal and operational gaps that hyperscalers leave open. Start by auditing your non-critical workloads and piloting a migration to your chosen provider within the next quarter. If you are building for European customers or handling regulated data, sovereign cloud is now table stakes for credibility and compliance.