This article is part of an evolving series on digital sovereignty in Europe and is regularly updated to reflect new regulatory and platform developments.
Last updated: July 2026, to reflect the EU Cloud and AI Development Act (CADA) proposal.
Sovereignty as a moving target
Digital sovereignty in the European Union is not a static discussion. It evolves alongside EU legislation, national government policies, and hyperscale cloud platform responses. What began as a debate about data residency has now expanded into enforceable governance, operational control, and regulatory alignment across EU member states.
Europe Demands More than Data Residency
For many organizations in Europe, especially those subject to European Union regulation, sovereignty now extends beyond data residency alone. To stay competitive, they must embrace cloud innovation. Yet the same cloud that drives growth also raises questions about who controls data, who can access it, and under which laws. Keeping information inside European borders once felt like enough. Today, that is only the beginning.
When Microsoft completed the final phase of the EU Data Boundary in February 2025, we explored in our previous article how it gave organizations renewed confidence that their data would stay within European borders and remain subject to EU law. That initiative marked a crucial step in restoring trust after years of uncertainty around cross-border data access.
Yet, as we noted at the time, it did not fully address the deeper question of sovereignty: how European institutions can operate in the cloud under their own governance, without depending on foreign oversight.
Since the original publication of this article, the regulatory landscape in the European Union has continued to mature. The implementation of the Digital Operational Resilience Act (DORA), expanding interpretations of the NIS2 Directive, and increasing enforcement of GDPR accountability have reinforced expectations around operational transparency, access governance, and supply chain control. Sovereignty is no longer framed as a preference. It is becoming a regulatory expectation, particularly for governments and regulated sectors.
More recently, EU sovereignty requirements have shifted towards provable control over identity, access, and operational processes, making policy enforcement and auditability core design principles rather than optional measures.
Enforcement Signals from EU Institutions
The clearest enforcement signal to date comes from the European Data Protection Supervisor (EDPS). In March 2024, the EDPS found that the European Commission’s own use of Microsoft 365 infringed EU data protection rules and imposed corrective measures. What followed shows what compliance actually takes. The Commission and Microsoft tightened purpose limitation, restricted transfers outside the EEA to named countries under defined legal grounds, and added binding contractual instructions covering subprocessors and disclosure requests. In July 2025, the EDPS confirmed the infringements were remedied and closed the case, then called on all other EU institutions using Microsoft 365 to carry out similar assessments. Enforcement is not hypothetical. It ran its full course here, and the remediation list reads like a sovereignty architecture.
EU Operational Sovereignty
Since this article was first published, Microsoft has formalized and expanded its approach under the broader Microsoft Sovereign Cloud portfolio. What started as “Cloud for Sovereignty” has evolved into a structured model that includes Sovereign Public Cloud, Sovereign Private Cloud, and national partner implementations.
This marks an important shift. The conversation is no longer limited to data residency. It now includes operational control, governance models, access transparency, and the ability for governments to define how cloud services are operated within their jurisdiction.
In practice, EU institutions and national governments are increasingly requiring demonstrable control over processing location, privileged access management, incident transparency, and legal enforceability. This reflects a broader EU policy direction in which digital infrastructure is viewed as part of strategic autonomy. The emphasis is not only on where data is stored, but on who can operate, access, and support the systems, and under which jurisdictional safeguards. This regulatory momentum culminated in October 2025 with the European Commission’s Cloud Sovereignty Framework, which sets measurable requirements across eight dimensions and is already shaping procurement for EU institutions and member states.
That momentum has now moved from framework to legislation. On 3 June 2026, the European Commission published the Cloud and AI Development Act (CADA), proposing a single EU sovereignty framework with four assurance levels, ranging from EU data location at level 1 to full supply chain control without third country interference at level 4. Public bodies would run a sovereignty risk assessment before procuring cloud and AI services. CADA does not ban American hyperscalers. It shapes the market through procurement, scoring providers on the Union added value they bring and reserving the top tier for services owned and operated in the EU. The proposal still has to clear Parliament and Council, with adoption not expected before 2027, so nothing is binding yet. The direction, though, is clear.
Globally, the other major hyperscalers including AWS and Google Cloud are also adapting roadmaps in response to EU sovereignty pressures. Recognizing differences in their approaches will be essential for multi-cloud and hybrid strategies.
From Data Location to True Control
The sovereign public model introduces several important safeguards. Through Data Guardian, any remote access by Microsoft engineers now requires explicit approval from personnel based in Europe. All activity is logged in a tamper-evident ledger. External Key Management allows customers to hold and manage their own encryption keys so that data remains unreadable without their consent. A new Regulated Environment Management portal provides a single place to configure and audit these controls. The goal is to apply sovereignty to existing Azure regions without forcing migrations or service disruption.

Azure’s new sovereignty model is built around three layers: sovereign public, sovereign private, and national partner clouds. Together, they give European organizations more freedom to choose how sovereignty applies to their workloads while still using Azure’s global capabilities.
For organizations that need full autonomy, Microsoft now offers Azure Local and Microsoft 365 Local. These allow workloads to run in datacenters controlled by the customer or trusted European partners. In France and Germany, national operators such as Bleu and Delos Cloud extend this concept further, providing sovereign environments managed under local laws and governance structures.
Azure Local is available in both hybrid and disconnected models, delivering core infrastructure services at the edge. This gives customers full control over their environment, workloads, and data.

Microsoft’s Sovereign Cloud portfolio has continued to expand in response to these regulatory signals. The structured introduction of Sovereign Public Cloud, Sovereign Private Cloud, and national partner models reflects direct alignment with EU regulatory frameworks and member state requirements. In parallel, the expansion of the EU Data Boundary across Azure and Microsoft 365 strengthens commitments around EU-based processing, operational access governance, and service coverage within EU jurisdictional boundaries.
This direction was independently validated in April 2026, when Forrester named Microsoft a Leader in The Forrester Wave: Sovereign Cloud Platforms, Q2 2026, alongside Google Cloud, AWS, Oracle, and Tencent. The evaluation specifically highlighted Microsoft’s ability to provide consistent sovereign controls across public, private, and partner-operated environments, using Azure Local and Azure Arc to keep the same management, governance, and deployment models in connected and disconnected scenarios. For European customers, the relevance is less about the recognition itself and more about what it confirms: sovereignty is now being assessed as a platform property, not a regional deployment choice.
What European Leaders Should Focus On
Governments in France, Germany, Italy, Spain, the Netherlands, and other EU member states are actively translating EU-level strategy into national cloud policies and procurement frameworks. This results in country-specific sovereignty interpretations layered on top of EU regulation. Public sector organizations are therefore navigating both European legislative expectations and domestic political requirements when making cloud decisions.
These capabilities strengthen Europe’s position in the global cloud landscape. They provide real tools for enforcing control and transparency instead of relying solely on legal promises. Still, important questions remain.
Microsoft continues to operate the underlying infrastructure and software updates, which means full independence is still out of reach. Legal experts point out that U.S. laws such as the CLOUD Act could still create conflicts, even with external key management in place. Others warn that the additional layers of governance may increase operational complexity for organizations already struggling with limited security and compliance resources.
Forrester’s own analysis frames the same point clearly: organizations don’t buy a sovereign cloud as a product, they architect for it over time, combining public, private, and disconnected environments to match their regulatory and operational risk profile. That framing matches what we are seeing in the field. The customers asking us about sovereignty rarely want a single sovereign region. They want consistent governance across the environments they already operate in.
Despite those concerns, the change is significant. For the first time, European customers can define and enforce boundaries that go beyond storage location. This shift turns sovereignty into a practical capability rather than an abstract policy goal.
Market momentum confirms the shift: Gartner forecasts European sovereign IaaS spending will nearly double in 2026, reaching $12.6 billion (83% growth), underscoring that sovereignty has moved from policy discussion to procurement priority.
Europe’s Cloud Identity
The expansion of Azure’s sovereign capabilities is not just a product update. It reflects a broader shift in Europe’s digital identity. Cloud adoption is no longer about moving faster; it is about doing so responsibly, under governance frameworks that reflect European values.
Sovereignty is becoming a design principle rather than an afterthought. Organizations that treat it as part of their architecture, balancing innovation with control, will build stronger trust with regulators, partners, and citizens. In that sense, Azure’s new sovereign solutions mark the start of a more mature and confident European cloud era.
The sovereignty debate in Europe is therefore no longer theoretical. It is shaped by active legislation, regulatory supervision, and national policy decisions. This article will continue to be updated as EU directives are implemented, enforcement matures, and hyperscale providers adapt their sovereign capabilities.
What Governments Evaluate in RFPs and Tenders
For SaaS providers targeting the European public sector, sovereignty is no longer a policy discussion. It appears directly in procurement criteria and contractual obligations. Governments increasingly evaluate where data is stored and processed, who can access systems and under which approval controls, whether encryption keys are customer-managed, how incident notification is handled, and whether sub-processors expose data to non-EU jurisdictions. Clear exit and data portability guarantees are also becoming standard requirements. These elements now influence award decisions as much as functionality and price.
From Policy to Platform Design
Digital sovereignty is influencing architecture decisions, DevOps practices, and cloud governance across Europe.
At The Masterminds Group, we help organizations structure their Azure environments using Infrastructure as Code, implement secure access governance, and design cloud platforms that remain transparent, controllable, and aligned with regulatory expectations. Our focus is not legal interpretation, but translating regulatory pressure into practical technical design and operational clarity.
If your organization operates in regulated markets or serves public sector customers, it may be time to assess whether your current Azure architecture and DevOps model truly support sovereign requirements. Contact us, or schedule a direct conversation with DevOps Masterminds CTO Rinie Huijgen.


