Skip to main content

Residency ≠ Sovereignty

Residency ≠ Sovereignty

Why a 'sovereign' cloud from a US hyperscaler is not the same as sovereignty, and what genuine European sovereignty actually requires.

Why European Sovereignty Matters

Where your data sits is not the same question as whose law governs it. A sovereign cloud from a US hyperscaler can deliver the first. Your data stays in Frankfurt, the staff are European, the legal entity is local. But it remains fully reachable under the second, because the CLOUD Act follows control, not location. A US parent answers to Washington wherever its servers sit. This whitepaper separates the three questions the word sovereign often blurs together: residency, operations, and jurisdiction. Each can be answered on its own, tested against the providers' own documentation and their own admissions on the record. The short answer: US-owned clouds deliver residency in full, operational controls in part, and legal sovereignty not at all.

The market
$80B
Sovereign cloud spending in 2026, with Europe the fastest-growing region (Gartner)
The concentration
~70%
Of European cloud infrastructure revenue held by AWS, Microsoft, and Google
The bind
4%
Of worldwide turnover: the GDPR fine exposure for complying with a US disclosure order
The shift
~2×
European sovereign-cloud spending expected to roughly double in a single year

Legal Certainty

GDPR compliance requires knowing which jurisdiction governs your data. Location in Europe is not the same as immunity from US law. This distinction matters for regulated industries and public sector organizations.

Strategic Autonomy

The EU has identified digital sovereignty as a strategic priority. Genuine sovereignty means European organizations can operate critical infrastructure without depending on foreign legal jurisdictions.

Market Transparency

When providers claim 'sovereignty' but deliver only data residency, customers make decisions on incomplete information. Clarity benefits everyone: customers, genuine sovereign providers, and the market.

Download the Whitepaper

Get immediate access to the complete technical analysis of cloud sovereignty.

Full Report

The Sovereignty Gap

Full report with legal analysis, technical architecture, provider assessments, and cited sources.

What's Inside

Ten chapters covering the legal, technical, and corporate architecture of cloud sovereignty.

Does Your Provider Meet These Sovereignty Requirements?

True sovereignty requires structural immunity at every layer. Compare how sovereign EU providers and US hyperscalers measure against each requirement.

requirement Sovereign EU Provider US Hyperscaler EU Region
Data Residency EU-only storage and processing EU datacenter (physical location)
Operational Sovereignty EU entities, EU staff US parent controls operations
Legal Sovereignty Immune from US CLOUD Act/FISA 702 Subject to US extraterritorial law
Corporate Independence No US parent company US parent with hierarchy access
Technical Isolation EU-only control plane & identity US control plane dependencies
Complete Structural Immunity Eliminates jurisdiction exposure Only slows, doesn't eliminate
Verifiable Sovereignty Transparent legal structure Marketing vs structural reality
Binding Legal Protection Jurisdictional immunity Discretionary challenge promises

Common Questions

Everything you need to know about cloud sovereignty and the hyperscalers' sovereign offerings.

Short answer: They deliver data residency and partial operational sovereignty, but not legal sovereignty.

Why? Because all three companies:

  • Are incorporated in the United States
  • Maintain US parent company control over EU subsidiaries
  • Are subject to US CLOUD Act and FISA Section 702
  • Retain structural control points (identity systems, software supply chain, control plane)

What they deliver:

  • Data residency: Data stored and processed in EU datacenters
  • ⚠️ Partial operational sovereignty: Some local operations, but US parent oversight
  • Legal sovereignty: US law can still reach data via parent-subsidiary corporate structure

The providers' position:

  • "We've never disclosed customer data to US intelligence agencies"
  • "We'll challenge any warrants in court"
  • "Our EU entity structure insulates your data"

The legal reality:

  • Past non-disclosure doesn't prevent future compelled disclosure
  • Promise to challenge carries no binding legal force
  • Corporate restructuring slows but does not break the CLOUD Act's reach
  • Microsoft France testimony to French Senate (June 2025): "No, I cannot guarantee it" (immunity from US law)

Bottom line: These are sophisticated data residency offerings with operational improvements, but they cannot deliver legal immunity from US surveillance law due to corporate structure. This is a technical limitation, not a criticism of intent.

Yes. Leafcloud delivers all three layers of cloud sovereignty:

✅ Data Residency

  • All infrastructure located in the Netherlands (Amsterdam and Ede datacenters)
  • Data never leaves Dutch territory
  • Compliant with Dutch and EU data protection law

✅ Operational Sovereignty

  • Operated by Leafcloud B.V., a Dutch-registered company
  • All staff based in the Netherlands
  • No foreign parent company oversight
  • Updates, patches, and operational control entirely within NL/EU jurisdiction

✅ Legal Sovereignty

  • No US parent company → immune from US CLOUD Act
  • Not subject to FISA Section 702 (applies only to US companies)
  • Only Dutch/EU courts have jurisdiction
  • Cannot be compelled to disclose data by US law enforcement

Corporate structure:

  • Leafcloud B.V. (Netherlands) — independent Dutch company
  • No US incorporation, no US subsidiaries, no US ownership structure
  • Subject only to Dutch and EU law

Certifications:

  • ISO 27001 (Information Security Management)
  • SOC 2 Type II (Security, Availability, Confidentiality)
  • NEN 7510 (Dutch healthcare data security standard)

Bottom line: Leafcloud is a genuinely sovereign EU cloud provider because we have no corporate ties that expose customers to extraterritorial US law. This is structural sovereignty, not just a marketing claim.

Need to verify sovereignty for your compliance requirements? We're happy to provide detailed documentation: info@leaf.cloud

Cloud sovereignty has three distinct layers. Most providers deliver only the first, while claiming "sovereignty":

1. Data Residency (Where are the bytes?)

  • Physical location of data storage and processing
  • Can be achieved by running infrastructure in EU datacenters
  • All major providers deliver this via EU regions
  • ✅ Necessary but not sufficient for sovereignty

2. Operational Sovereignty (Who runs the infrastructure?)

  • Identity of the entity operating the infrastructure
  • Nationality and employment location of staff with system access
  • Control over updates, patches, and operational procedures
  • ⚠️ Partial in most "sovereign" offerings (local operations but US parent company oversight)

3. Legal Sovereignty (Whose law ultimately governs?)

  • Jurisdiction that can compel data access through legal process
  • Whether parent company structure creates exposure to foreign law
  • Immunity from extraterritorial surveillance laws (CLOUD Act, FISA 702)
  • Cannot be delivered by US companies due to CLOUD Act reach through parent-subsidiary relationships

Why this matters: A cloud can deliver data residency without delivering legal sovereignty. The EU's own Cloud Sovereignty Framework recognizes these distinctions. Genuine sovereignty requires all three layers, not just data location.

The Clarifying Lawful Overseas Use of Data (CLOUD) Act is a 2018 US law that allows US law enforcement to compel US-based technology companies to hand over data stored anywhere in the world, including in the EU.

Key points:

  • Extraterritorial reach: The CLOUD Act explicitly overrides where data is physically stored
  • Applies to US companies: Any company incorporated in or doing significant business in the US can be served with a CLOUD Act warrant
  • Includes subsidiaries: US parent companies can be compelled to access data held by foreign subsidiaries
  • Conflicts with GDPR: Creates a legal conflict between US surveillance law and EU data protection law
  • No EU court review: CLOUD Act warrants are issued by US courts without EU judicial oversight

For EU organizations, this means:

  • Storing data in an EU region of a US cloud provider does not provide immunity from US law
  • The legal question is who controls the infrastructure, not just where it sits
  • Genuine sovereignty requires infrastructure operated by an EU entity with no US parent company

This is why data residency (location) is not the same as legal sovereignty (jurisdiction).

Organizations that need legal certainty about data jurisdiction, not just physical location:

Public Sector

  • Government agencies and ministries
  • Healthcare providers (patient data under GDPR Article 9)
  • Educational institutions (student data)
  • Critical infrastructure operators
  • Defense and intelligence contractors

Regulated Industries

  • Financial services (banking, insurance, payments)
  • Healthcare and life sciences (GDPR, NIS2, medical device regulations)
  • Legal services (attorney-client privilege)
  • Any organization handling sensitive personal data

Strategic Operations

  • Companies competing with US tech giants
  • Organizations subject to trade restrictions or sanctions
  • Research institutions handling pre-publication IP
  • Defense contractors and dual-use technology companies

GDPR/NIS2 Compliance

  • Organizations needing to demonstrate "appropriate safeguards" for international transfers (GDPR Article 46)
  • Essential entities and important entities under NIS2 Directive (requiring supply chain cybersecurity risk management)
  • Organizations subject to Schrems II scrutiny (adequate protection against foreign surveillance)

Bottom line: If you answer "yes" to any of these questions, you need genuine sovereignty, not just data residency:

  • Would foreign government access to your data create competitive, legal, or operational risk?
  • Are you required to demonstrate GDPR compliance for sensitive data?
  • Are you subject to NIS2 or other EU cybersecurity regulations?
  • Do you need legal certainty about which courts have jurisdiction over your infrastructure?

Data residency addresses the first layer. Genuine sovereignty addresses all three: data location, operational control, and legal jurisdiction.

Run Your Workloads on Genuinely Sovereign Infrastructure

Leafcloud is a Dutch-owned cloud provider with infrastructure in the Netherlands. No US parent company, no CLOUD Act exposure, no sovereignty washing. Just compliant, sovereign EU cloud computing.