For months now, European companies have been scrutinizing their dependence on U.S. cloud providers more critically than ever before. Geopolitical uncertainty, shifting U.S. government policies, and growing compliance requirements have brought a question to the attention of top management that was long considered a technical detail: Who actually has access to our data, and under what legal authority? Many IT managers answer this with a dangerous half-truth: “Our servers are located in Frankfurt, so we’re on the safe side.” It is precisely this statement that is one of the most persistent misconceptions in the current debate over data sovereignty.
After all, data sovereignty is not determined by the location of the hard drive, but by the legal system to which a provider is subject. A U.S. corporation remains subject to U.S. law, even if it has a data center in Germany. From our perspective at PTA IT Consulting, this is the real crux of the matter: not the question of whether data is stored in the cloud, but rather who is allowed to access it in an emergency and whether a company can control that access.
The need is measurable. According to the Cloud Report 2025 by the digital industry association Bitkom, 78 percent of German companies believe the country is too dependent on U.S. cloud providers, and 82 percent would prefer European or German hyperscalers. Virtually all of them would prefer a provider based in Germany. In reality, however, most continue to source their cloud services from the U.S. A second Bitkom study highlights the structural depth of this dependence: 96 percent of companies import digital technologies, and only a little over a third (38 percent) have full confidence in the U.S. as a supplier. The gap between desire and reality is precisely the space where data sovereignty becomes a strategic priority.
What Data Sovereignty Really Means
Digital sovereignty and data sovereignty are often used interchangeably, but they mean different things. Digital sovereignty is the umbrella term: the ability of a company—or a state—to make autonomous decisions regarding technologies, infrastructure, and providers, rather than falling into one-sided dependencies. Data sovereignty is the concrete, data-related core of this concept: complete control over who can access one’s own data and under what legal conditions.
The key point: Control is not purely a technical concept, but first and foremost a legal one. The physical location of data is secondary if the provider, due to its corporate structure, is subject to the jurisdiction of a third country. True data sovereignty can only be achieved when legal, technical, and organizational factors work together.
| Level | What It’s All About | What Companies Should Consider |
| Legal (Jurisdiction) | Which country’s laws apply to the provider? | Corporate headquarters and group structure—not just the server location. |
| Location (Hosting) | Where is data stored and processed? | Data centers in Germany or the EU; contracts governed by EU law. |
| Technical (Protection) | Who holds the keys to the data? | Encryption in which the provider itself does not have access to the plaintext data. |
| Organizational (Documentation) | Can sovereignty be proven? | Certifications such as ISO 27001 or BSI C5, documented processes, exit strategy. |
By considering these four levels together, you move beyond the mere question of location and arrive at a robust strategy. Our services page on digital sovereignty shows how this can be translated into a practical, EU-compliant cloud strategy for a specific company—from the current state analysis to vendor selection.
Three Common Misconceptions and Why They Can Be Costly
- “A German server location protects against unauthorized access.” The U.S. CLOUD Act of 2018 requires U.S. companies to hand over requested data to U.S. authorities, regardless of whether the servers are located in Virginia or Frankfurt. What matters is the provider’s jurisdiction, not the location of the hardware. This is in direct conflict with Article 48 of the GDPR, which prohibits the disclosure of data to authorities in third countries without an international agreement.
- “An EU subsidiary solves the problem.” As long as the parent company is subject to U.S. law, the CLOUD Act also applies to the European subsidiary. A formal EU presence does little to change the chain of control under corporate law. What matters is who controls the company.
- “Encryption by the provider is sufficient.” If the provider encrypts the data itself and also holds the keys, it can decrypt the data in an emergency and thus disclose it. The architecture is truly secure only when the keys are held exclusively by the company itself. What the provider cannot technically read, it cannot disclose.
A Boost from Brussels: The EU Data Act
One often-overlooked lever is regulation itself. The EU Data Act (Regulation (EU) 2023/2854) has been applicable throughout the EU since September 12, 2025, and explicitly aims to reduce lock-in effects in cloud services. Providers must facilitate switching both technically and contractually, provide open interfaces, and limit notice periods to a maximum of two months; switching fees will be completely eliminated by January 2027. For businesses, this means that breaking free from dependence will become more predictable and less costly. Data sovereignty is moving from a mere aspiration to the realm of economic feasibility.
This is exactly where vendor-neutral consulting pays off—consulting that doesn’t sell a single product, but instead draws on a broad network of technologies and partners to put together the right, manageable solution for each situation, rather than leading customers into a new dependency.
When Data Sovereignty Becomes a Requirement
In many industries, data sovereignty is no longer a matter of choice but a regulatory requirement. Where personal or business-critical data is processed—such as in the insurance industry, the energy sector, or the life sciences—regulations like NIS-2, DORA, and the BDSG further tighten requirements for data access and audit trails. In healthcare and the public sector, a sovereign infrastructure is often required by law. The common thread: Anyone who relies on a cloud without clear jurisdiction in these sectors risks not only fines but also the loss of data control at a critical moment.
Outlook: From the Location Question to the Architectural Decision
The debate over data sovereignty is currently undergoing a fundamental shift. It is no longer merely a question of location or contract, but rather an architectural decision: sovereignty must be built into the choice of law, encryption, and interoperability from the very beginning, rather than being added as an afterthought. Geopolitical pressure, new regulations, and the growing maturity of European alternatives are all driving this shift in the same direction. For companies, this means the question is no longer whether data sovereignty belongs on the agenda, but how thoroughly it is embedded in their own IT infrastructure.
Want to know just how robust your current cloud strategy really is? During a consultation, we’ll assess your current situation, identify specific areas for action, and outline possible next steps.
Frequently asked questions (FAQs)
Is having a data center in Germany enough to be protected from the U.S. CLOUD Act?
No. The CLOUD Act is based on the provider’s jurisdiction, not on the server’s location. If a provider is subject to U.S. law—for example, as a U.S. corporation or its subsidiary—U.S. authorities can demand the disclosure of data, even if it is stored in a German data center. The decisive factors are the company’s registered office and corporate structure, not the physical location of the servers.
How can I tell if a provider offers reliable data hosting in Germany or the EU?
Based on a combination of several criteria: a provider that is subject exclusively to European law, data centers in Germany or the EU, contracts governed by EU law, recognized certifications such as ISO 27001 or BSI C5, and encryption where the keys remain with the customer. A single criterion—such as location alone—is not sufficient.
What does GDPR- or BDSG-compliant hosting mean?
This means that personal data is processed in a manner that complies with the requirements of the GDPR and the Federal Data Protection Act, in particular without any legally impermissible access by authorities from third countries. In practice, this means: a provider located outside foreign jurisdictions, clear contractual foundations, and technical safeguards that effectively prevent unauthorized access.
What is the difference between digital sovereignty and data sovereignty?
Digital sovereignty is the umbrella term for self-determined control over technologies, providers, and infrastructure. Data sovereignty is the data-related core of this concept: control over who can access one’s own data and under what legal basis. Data sovereignty is thus a central component of digital sovereignty.
Short Glossary
- Data sovereignty: A company’s complete control over who can access its data and under what legal conditions.
- Digital sovereignty: The ability to make autonomous decisions regarding technologies, providers, and infrastructure, rather than falling into one-sided dependencies.
- U.S. CLOUD Act: A U.S. law enacted in 2018 that requires U.S. service providers to disclose data to U.S. authorities regardless of where it is stored.
- EU Data Act: An EU regulation that takes effect on September 12, 2025, designed to facilitate cloud migration and reduce lock-in effects.
- Vendor lock-in: The technical, contractual, or economic dependence on a single vendor that makes it difficult to switch.
List of Sources
¹ Bitkom (2025): Cloud Report 2025 – 78% believe Germany is too dependent on U.S. cloud providers; 82% would like to see European/German hyperscalers. Press Release “Business Calls for a German Cloud,” Berlin, June 11, 2025. Available at: bitkom.org/Press/Press Release/Business-Calls-for-a-German-Cloud
² Bitkom (2025): Study report “Digital Sovereignty 2025” – 96% of companies import digital technologies; only 38% still trust the U.S. as a supplier. Available at: bitkom.org/Study-Reports/2025/Digital-Sovereignty
³ U.S. CLOUD Act (2018): Clarifying Lawful Overseas Use of Data Act – Requirement for U.S. providers to disclose data regardless of storage location; conflict with Article 48 of the GDPR. Available at: congress.gov/bill/115th-congress/house-bill/4943
⁴ EU Data Act: Regulation (EU) 2023/2854 – Facilitating cloud migration, reducing lock-in effects; effective as of September 12, 2025. Available at: eur-lex.europa.eu/eli/reg/2023/2854/oj