Data sovereignty in 2026: what every European company needs to know about its cloud hosting
In 2026, data sovereignty is no longer a theoretical debate reserved for lawyers and large public bodies. It directly affects every company that uses a cloud service to host its applications, store customer data or run its databases. Between the US Cloud Act, tightening European regulation and recent geopolitical tensions, your choice of cloud provider has become a strategic decision in its own right.
This article takes stock of what digital sovereignty actually means for European startups, SMEs and engineering teams. No political posturing: facts, regulations currently in force, and practical pointers for making informed choices.
Data sovereignty: what exactly are we talking about?
Data sovereignty is an organisation's ability to keep control of its data: where it is stored, who can access it, and which jurisdiction it falls under. In practice, it comes down to three questions every engineering team should be asking.
Where is your data physically hosted? A datacentre in France, in Germany, in the United States? Physical location partly determines which laws apply, but it is not the only criterion — and this is where many companies get it wrong.
What is the legal nationality of your hosting provider? This is the crucial point. A datacentre located in France but operated by a subsidiary of a US group potentially remains subject to US law. Server location alone does not guarantee sovereignty.
Who can legally demand access to your data? Depending on the answers to the first two questions, foreign authorities may have a right of access to your information, sometimes without you ever being told.
The Cloud Act: why it is a real issue for your company
The Cloud Act (Clarifying Lawful Overseas Use of Data Act), passed in 2018, is a US federal law that allows US authorities to demand access to data held by American service providers, regardless of the country in which that data is physically stored.
In concrete terms, if you use AWS, Azure, Google Cloud or any other service operated by a company governed by US law, your data — even when stored in a Paris datacentre — can be the subject of an access request from US authorities, without you necessarily being notified and without going through European judicial procedures.
In December 2025, a legal opinion prepared by the University of Cologne for the German Federal Ministry of the Interior confirmed the scale of the problem: the Cloud Act, combined with Section 702 of FISA (Foreign Intelligence Surveillance Act), allows US agencies to access any data hosted on a service run by an American company, including through its local subsidiaries in Europe.
This is not a theoretical risk. The legal conflict between the Cloud Act and the GDPR puts European companies in an awkward position. Article 48 of the GDPR states that court orders from third countries are only enforceable if they are based on a recognised international agreement. The Cloud Act bypasses that mechanism. The result: a company that complies with a US request risks breaching the GDPR, and vice versa.
Beyond the law: geopolitical risk
The geopolitical tensions of 2025-2026 have made the issue more tangible still. Experts and the CNIL have warned of the risk of restricted access to US services in the event of sanctions or trade retaliation. For a company whose entire infrastructure rests on a US cloud provider, even a temporary block could bring the business to a standstill.
This scenario, long considered improbable, is now taken seriously by European authorities and industry analysts.
The European regulatory framework in 2026: GDPR, NIS2, EUCS and the Data Act
Europe is not standing still on these issues. Several regulations now shape the digital sovereignty landscape, and their implementation is gathering pace in 2026.
GDPR: still the foundation
In force since 2018, the General Data Protection Regulation remains the bedrock of personal data protection in Europe. It imposes strict obligations on the processing and transfer of personal data, and the way it collides with the Cloud Act creates a legal conflict that companies have to factor into their choice of hosting provider.
The NIS2 Directive: cybersecurity becomes a legal obligation
The NIS2 Directive, due to be transposed into French law during 2026 through the "Loi Résilience" (the French Resilience Act), considerably widens the range of companies subject to cybersecurity obligations. In France, between 15,000 and 18,000 entities will be covered, compared with a few hundred under NIS1.
The key points to remember:
- SMEs with more than 50 employees in critical sectors are potentially in scope, as are the subcontractors of those companies
- Senior management becomes personally liable for cybersecurity compliance
- The obligations cover risk management, incident notification (early warning within 24 hours, report within 72 hours) and supply chain security, including cloud providers
- Penalties can reach €10 million or 2% of worldwide turnover
For companies choosing their cloud infrastructure, NIS2 makes it all the more important to work with providers that can demonstrate an adequate level of security and clear data traceability.
The EU Data Act: portability and interoperability
Phased in from 2025-2026, the EU Data Act introduces new obligations on data portability and cloud service interoperability. The aim: to reduce the vendor lock-in that stops companies from switching provider. It is a tangible step forward for operational sovereignty.
EUCS: the European cloud certification still under construction
The proposed European certification scheme EUCS (European Cybersecurity Certification Scheme for Cloud Services), led by ENISA, aims to create a common framework for assessing the security of cloud services across the Union. However, the project has been marked by significant disagreement between member states.
France, backed by Italy and Spain, is pushing for strict sovereignty criteria in the highest certification level — in particular, protection against extraterritorial laws such as the Cloud Act. Other countries, including Germany and the Netherlands, favour a more flexible approach.
In early 2026, Brussels chose to relaunch EUCS on "pure" cybersecurity grounds, and to announce a future companion text, CADA (Cloud and AI Development Act), to deal with industrial capacity and sovereignty. In the meantime, the CNIL has pointed out that EUCS, as it stands, cannot guarantee protection against foreign powers accessing data — unlike the French SecNumCloud certification.
SecNumCloud: the French benchmark
In the absence of a finished European framework, ANSSI's SecNumCloud standard remains the most demanding benchmark for sovereign cloud. Version 3.2 requires, among other things, that the provider be subject exclusively to European law and that data be hosted by European-owned entities.
A notable development in early 2026: the French state decided to migrate the French Health Data Hub (Plateforme des données de santé) to SecNumCloud-certified hosting, moving away from Microsoft. A strong political signal of the weight given to sovereignty for sensitive data.
The European industrial initiative: the Estia alliance
In November 2025, at the Summit on European Digital Sovereignty in Berlin, eleven major European groups — including Airbus, Dassault Systèmes, Orange, OVHcloud and Sopra Steria — formally launched the European Sovereign Tech Industry Alliance (Estia). The alliance, which will be operational in 2026, aims to coordinate industrial efforts to strengthen Europe's digital autonomy.
The initiative comes with investment pledges of more than €12 billion. It is an encouraging sign, even if those sums remain modest next to the resources the United States or China are putting into the sector.
For SMEs and startups, this momentum translates into a growing European ecosystem of cloud providers, with increasingly mature and competitive offerings.
What this means in practice for your infrastructure
Given this regulatory and geopolitical complexity, what practical decisions can you take for your cloud infrastructure?
Map your data and your dependencies
Before making any technical choice, establish clearly where your data is stored, who processes it, and which jurisdiction each link in your chain falls under. Many companies find out late in the day that a third-party service — a managed database, a CDN, a monitoring tool — is operated by a company subject to the Cloud Act.
Assess how sensitive your data is
Not all data needs the same level of protection. For personal, financial or health data, or for trade secrets, choosing a European provider that is not subject to extraterritorial laws is strongly recommended. For less sensitive data, the risk/benefit analysis may come out differently.
Favour European hosting providers
Infrastructure providers such as Hetzner, Scaleway and OVHcloud offer competitive solutions hosted in Europe and operated by entities governed by European law. Sovereignty aside, these providers are often significantly cheaper than the US hyperscalers, thanks to the absence of hidden charges (data transfer, NAT gateway, etc.).
The catch is that choosing a European provider only solves part of the equation. You still have to be able to deploy and run production infrastructure on it — which, with Kubernetes, usually calls for advanced DevOps skills. That is exactly the problem Fransys solves: the platform connects to all the European providers (Hetzner, Scaleway, OVH) and lets you deploy a complete Kubernetes infrastructure through a visual interface, without writing a line of YAML.
The benefit goes beyond simplicity. Fransys lets you choose the provider and the country where your data lives — France, Germany — according to your regulatory constraints or your preferences. And if your circumstances change tomorrow, the platform can migrate a complete infrastructure from one European provider to another, with no manual rebuild. That flexibility is a real asset for sovereignty: you depend neither on a US cloud nor on a single European provider.
Check portability and the absence of lock-in
Sovereignty is not just about where data is located. It also includes your ability to leave a provider if you need to. Before committing, check that your configurations, your data and your workflows can be exported in standard formats. That is, in fact, one of the aims of the EU Data Act: to ensure that switching provider remains technically and economically viable.
This is where many cloud platforms — European ones included — fall short: they build proprietary abstraction layers that make migration costly and complex. With Fransys, the approach is radically different. The infrastructure you build through the visual interface rests entirely on open standards: Kubernetes, Docker, Helm. If you decide to leave, you export your Kubernetes manifests and your Helm configuration, and you redeploy your application elsewhere without Fransys. No proprietary format, no hidden dependency.
This zero lock-in philosophy is fundamental to sovereignty: you stay because the service suits you, not because you are technically trapped. It is the difference between a choice and a constraint — and where sovereignty is concerned, that distinction is essential.
Get ahead of your NIS2 obligations
If your company falls within the scope of NIS2 — directly or as a subcontractor to a regulated entity — make sure your cloud infrastructure meets the requirements for traceability, monitoring and incident response. Choosing a platform with 24/7 monitoring, centralised logs and automatic backups built in can make compliance considerably simpler.
Sovereignty versus cost: a false dilemma
One misconception persists: that sovereign European hosting costs more. The reality is often the opposite. European providers such as Hetzner or Scaleway offer infrastructure prices up to 40 to 60% lower than AWS or Azure, mainly because they do not apply the same charges for data transfer and ancillary services.
The Institut Montaigne acknowledges that digital sovereignty does come at a cost in some cases — doing without non-European solutions can mean functional trade-offs on certain highly specialised services. But for hosting web applications, APIs and databases — the day-to-day of most startups and SMEs — the European alternatives are not only competitive but often cheaper.
The real cost to weigh up is not that of sovereignty but that of dependency: legal risk, business continuity risk, and the cost of a forced emergency migration if geopolitical conditions take a turn for the worse.
Fransys: a practical answer to the sovereignty question
If you sum up the pillars of a genuinely sovereign infrastructure — European hosting, no exposure to extraterritorial laws, real portability, and the ability to change provider — Fransys ticks those boxes by design, not by marketing.
Natively multi-provider, all European
Fransys is not tied to a single provider. The platform integrates natively with Hetzner, Scaleway and OVH, all European providers governed by European law. You choose your provider and the location of your data (France, Germany) at deployment time. This multi-provider architecture means your data is never exposed to the Cloud Act or any other extraterritorial legislation.
Simplified migration between providers
This is one of Fransys's most distinctive strengths when it comes to operational sovereignty. If your regulatory context shifts, if a provider changes its terms, or if you simply want to optimise your costs, Fransys can move a complete infrastructure from one European provider to another. No manual rebuild, no weeks of DevOps migration work. This mobility between providers is a concrete form of sovereignty: you keep the power to decide at every moment.
Zero vendor lock-in by design
Fransys generates standard Kubernetes infrastructure. Your manifests, your Docker configurations, your Helm files, your CI/CD: all of it belongs to you and all of it is exportable. If tomorrow you decide to run your Kubernetes in-house or move to another platform, you walk away with your entire configuration. It is a commitment to full reversibility, in keeping with the spirit of the EU Data Act.
Production-ready security and easier compliance
Every infrastructure deployed through Fransys is configured by default with security and production best practices: automatic SSL/TLS certificates, 24/7 monitoring, centralised logs, automatic backups, and a human DevOps team watching over your clusters. For companies within the scope of NIS2, these built-in features make compliance considerably simpler, without having to stitch together a stack of disparate tools.
Key takeaways
The Cloud Act allows US authorities to access data hosted by American providers, even in Europe. This conflict with the GDPR creates a real legal risk for European companies.
The European regulatory framework is tightening in 2026 with the transposition of NIS2, the application of the EU Data Act and continuing work on EUCS. These regulations push towards greater control over data and cloud providers.
Competitive European alternatives exist. Providers such as Hetzner, Scaleway and OVHcloud, and managed platforms such as Fransys that build on them, make it possible to combine sovereignty, performance and cost control. With Fransys, you also keep the flexibility to migrate between European providers and to export your entire configuration in open standards — real technical sovereignty, not just a sales pitch.
Data sovereignty deserves to be handled pragmatically, with neither scaremongering nor naivety. Every company has to assess its exposure according to the sensitivity of its data and its regulatory context. But ignoring the subject is no longer an option in 2026. And the good news is that there are now European solutions that combine sovereignty, simplicity and cost control — without locking you in.
Want to take back control of your hosting? Try Fransys for free with €5 of credit, no credit card required. Deploy your first infrastructure on the European provider of your choice in a few minutes, and see the difference for yourself. Need help migrating an existing infrastructure? Our DevOps team can help you assess and plan your move to sovereign hosting.