Skip to content

GDPR and Data Sovereignty

Last reviewed: August 2026

The General Data Protection Regulation (GDPR) has continued to evolve since taking effect in 2018. Changes in recent years have shown up less in the statutory text itself than in the strengthening of demands around “where personal data is physically processed, and by whom.” This document outlines the cross-border transfer framework encountered when global enterprises expand cloud workloads to the EU or process EU customer data, and examines the “Sovereign Cloud” options that have emerged against this backdrop.

Chapter V of the GDPR requires separate safeguards for transfers of personal data outside the EU. The main mechanisms used in practice are as follows.

Mechanism Description
Adequacy Decision When the European Commission recognizes that a given country’s level of personal data protection is equivalent to the GDPR, transfers to that country require no additional safeguards
SCCs (Standard Contractual Clauses) European Commission-approved standard clauses executed between contracting parties for transfers to countries without an adequacy decision. The 2021 revision is the current version
BCRs (Binding Corporate Rules) Binding internal rules applied to transfers within a multinational corporate group

Adequacy Decisions Overview (Japan, Korea, UK, US DPF, etc.)

Section titled “Adequacy Decisions Overview (Japan, Korea, UK, US DPF, etc.)”

The European Commission has adopted adequacy decisions for key trading partners including Japan (2019), the Republic of Korea (December 2021), the United Kingdom, Switzerland, Canada, and the United States (EU-US Data Privacy Framework, 2023).

When a global enterprise uses cloud services in an EU region to process EU customer data or transfers data overseas, it must, regardless of the direction of transfer, confirm that the vendor contract (the DPA, or Data Processing Addendum) includes SCCs, and that the region and governance options the vendor offers satisfy its own data classification requirements.

The EU Data Boundary is a data-residency initiative that Microsoft has pursued, aimed at storing and processing the data of EU/EFTA customers only within the EU/EFTA.

  • January 2023: Phase 1 — customer data and pseudonymized personal data for core cloud services such as Microsoft 365, Dynamics 365, and Power Platform stored within the EU
  • February 26, 2025: Completion (Phase 3) — extended to Professional Services Data, including support logs and case notes, storing them within the EU/EFTA as well; Microsoft announced the completion of enhanced data residency and transparency (though some limited operational exceptions for cross-border access/transfer remain under documented conditions)

Other vendors are expanding similar in-region data-processing guarantees, but the “EU Data Boundary” name and its scope (which includes Professional Services Data) are specific to Microsoft’s initiative. The scope of EU-region data-residency guarantees for other vendors must be verified individually in each vendor’s contractual documentation (the DPA).

In response to demand to keep not just data storage location but also operating personnel, administrative access, and legal jurisdiction in emergencies confined to the EU, major vendors have operated or announced the following “sovereign cloud” options.

Vendor Option Form Status
AWS European Sovereign Cloud Independent region (physically and logically separated from existing AWS regions) Reached general availability (GA) on January 15, 2026, with Brandenburg, Germany as the first region. Announced a long-term €7.8 billion investment, with plans to expand sovereign Local Zones to Belgium, the Netherlands, and Portugal
Microsoft Bleu (France) / Delos Cloud (Germany) Partner-operated sovereign cloud (national partner cloud) Bleu is a joint venture between Orange and Capgemini (targeting SecNumCloud certification); Delos Cloud is an SAP subsidiary. A mutual-support agreement was signed in November 2025, and an MoU between Delos and Microsoft secures Delos’s legal right to access Microsoft’s cloud code in an emergency (such as a foreign government restricting service)
OCI EU Sovereign Cloud Physically separate, EU-dedicated regions Operating since June 2023, with Frankfurt and Madrid regions. Operated only by EU legal entities and EU-resident personnel, with no additional fees compared to commercial OCI
Google Cloud Sovereignty partnerships (T-Systems, Thales/S3NS, Proximus) Partner-operated regions Germany is handled by T-Systems, France by Thales subsidiary S3NS (targeting SecNumCloud), and Belgium/Luxembourg in partnership with Proximus. In May 2026, Thales and Google Cloud announced a new sovereign cloud partnership in Germany

The Fluid State of the EUCS Certification Scheme

Section titled “The Fluid State of the EUCS Certification Scheme”

EUCS (European Cybersecurity Certification Scheme for Cloud Services) is a common security certification framework for cloud services led by ENISA, originally intended to standardize cloud vendors’ security levels into EU-wide, mutually recognized tiers (Basic/Substantial/High).

EUCS remains a voluntary certification for now, but NIS2 and the Data Act (in force since January 2024, with core provisions applicable since September 2025) give member states and regulators the authority to mandate the use of EUCS-certified vendors for public bodies and essential/important entities, which could affect future procurement requirements.

  • Start with data classification: First classify which data is subject to EU in-region storage/processing obligations (public procurement requirements, contractual requirements, internal risk policy), then decide on region and vendor options.
  • Sovereign options come with cost/functionality trade-offs: Sovereign regions may offer a narrower range of services or lag behind in rolling out new features compared to standard commercial regions. Where it is not a strict requirement, a standard EU region combined with strengthened governance (encryption, access transparency logging) is often sufficient.
  • Reviewing the DPA and contract matters as much as region selection: Confirm directly in the contractual documentation whether SCCs are included, the list of sub-processors, and emergency access clauses.
  • Do not design around fluid regulations like EUCS as if they were settled: Rather than treating unfinalized certification requirements as a mandatory architectural premise, leave room to adapt once they are finalized.
  • Link to sovereign landing zone design: For concrete patterns that reflect EU data residency and processing jurisdiction requirements in landing zone guardrails, see Landing Zone — Sovereign Landing Zone.