Residency ≠ Sovereignty
Residency ≠ Sovereignty
Why a 'sovereign' cloud from a US hyperscaler is not the same as sovereignty, and what genuine European sovereignty actually requires.
Why European Sovereignty Matters
Where your data sits is not the same question as whose law governs it. A sovereign cloud from a US hyperscaler can deliver the first. Your data stays in Frankfurt, the staff are European, the legal entity is local. But it remains fully reachable under the second, because the CLOUD Act follows control, not location. A US parent answers to Washington wherever its servers sit. This whitepaper separates the three questions the word sovereign often blurs together: residency, operations, and jurisdiction. Each can be answered on its own, tested against the providers' own documentation and their own admissions on the record. The short answer: US-owned clouds deliver residency in full, operational controls in part, and legal sovereignty not at all.
Legal Certainty
GDPR compliance requires knowing which jurisdiction governs your data. Location in Europe is not the same as immunity from US law. This distinction matters for regulated industries and public sector organizations.
Strategic Autonomy
The EU has identified digital sovereignty as a strategic priority. Genuine sovereignty means European organizations can operate critical infrastructure without depending on foreign legal jurisdictions.
Market Transparency
When providers claim 'sovereignty' but deliver only data residency, customers make decisions on incomplete information. Clarity benefits everyone: customers, genuine sovereign providers, and the market.
Download the Whitepaper
Get immediate access to the complete technical analysis of cloud sovereignty.
The Sovereignty Gap
Full report with legal analysis, technical architecture, provider assessments, and cited sources.
What's Inside
Ten chapters covering the legal, technical, and corporate architecture of cloud sovereignty.
Does Your Provider Meet These Sovereignty Requirements?
True sovereignty requires structural immunity at every layer. Compare how sovereign EU providers and US hyperscalers measure against each requirement.
Common Questions
Everything you need to know about cloud sovereignty and the hyperscalers' sovereign offerings.
Are AWS European Sovereign Cloud, Microsoft Cloud for Sovereignty, and Google's sovereign controls genuinely sovereign?
Short answer: They deliver data residency and partial operational sovereignty, but not legal sovereignty.
Why? Because all three companies:
- Are incorporated in the United States
- Maintain US parent company control over EU subsidiaries
- Are subject to US CLOUD Act and FISA Section 702
- Retain structural control points (identity systems, software supply chain, control plane)
What they deliver:
- ✅ Data residency: Data stored and processed in EU datacenters
- ⚠️ Partial operational sovereignty: Some local operations, but US parent oversight
- ❌ Legal sovereignty: US law can still reach data via parent-subsidiary corporate structure
The providers' position:
- "We've never disclosed customer data to US intelligence agencies"
- "We'll challenge any warrants in court"
- "Our EU entity structure insulates your data"
The legal reality:
- Past non-disclosure doesn't prevent future compelled disclosure
- Promise to challenge carries no binding legal force
- Corporate restructuring slows but does not break the CLOUD Act's reach
- Microsoft France testimony to French Senate (June 2025): "No, I cannot guarantee it" (immunity from US law)
Bottom line: These are sophisticated data residency offerings with operational improvements, but they cannot deliver legal immunity from US surveillance law due to corporate structure. This is a technical limitation, not a criticism of intent.
Is Leafcloud genuinely sovereign?
Yes. Leafcloud delivers all three layers of cloud sovereignty:
✅ Data Residency
- All infrastructure located in the Netherlands (Amsterdam and Ede datacenters)
- Data never leaves Dutch territory
- Compliant with Dutch and EU data protection law
✅ Operational Sovereignty
- Operated by Leafcloud B.V., a Dutch-registered company
- All staff based in the Netherlands
- No foreign parent company oversight
- Updates, patches, and operational control entirely within NL/EU jurisdiction
✅ Legal Sovereignty
- No US parent company → immune from US CLOUD Act
- Not subject to FISA Section 702 (applies only to US companies)
- Only Dutch/EU courts have jurisdiction
- Cannot be compelled to disclose data by US law enforcement
Corporate structure:
- Leafcloud B.V. (Netherlands) — independent Dutch company
- No US incorporation, no US subsidiaries, no US ownership structure
- Subject only to Dutch and EU law
Certifications:
- ISO 27001 (Information Security Management)
- SOC 2 Type II (Security, Availability, Confidentiality)
- NEN 7510 (Dutch healthcare data security standard)
Bottom line: Leafcloud is a genuinely sovereign EU cloud provider because we have no corporate ties that expose customers to extraterritorial US law. This is structural sovereignty, not just a marketing claim.
Need to verify sovereignty for your compliance requirements? We're happy to provide detailed documentation: info@leaf.cloud
What are the three layers of cloud sovereignty?
Cloud sovereignty has three distinct layers. Most providers deliver only the first, while claiming "sovereignty":
1. Data Residency (Where are the bytes?)
- Physical location of data storage and processing
- Can be achieved by running infrastructure in EU datacenters
- All major providers deliver this via EU regions
- ✅ Necessary but not sufficient for sovereignty
2. Operational Sovereignty (Who runs the infrastructure?)
- Identity of the entity operating the infrastructure
- Nationality and employment location of staff with system access
- Control over updates, patches, and operational procedures
- ⚠️ Partial in most "sovereign" offerings (local operations but US parent company oversight)
3. Legal Sovereignty (Whose law ultimately governs?)
- Jurisdiction that can compel data access through legal process
- Whether parent company structure creates exposure to foreign law
- Immunity from extraterritorial surveillance laws (CLOUD Act, FISA 702)
- ❌ Cannot be delivered by US companies due to CLOUD Act reach through parent-subsidiary relationships
Why this matters: A cloud can deliver data residency without delivering legal sovereignty. The EU's own Cloud Sovereignty Framework recognizes these distinctions. Genuine sovereignty requires all three layers, not just data location.
What is the CLOUD Act and why does it matter for EU organizations?
The Clarifying Lawful Overseas Use of Data (CLOUD) Act is a 2018 US law that allows US law enforcement to compel US-based technology companies to hand over data stored anywhere in the world, including in the EU.
Key points:
- Extraterritorial reach: The CLOUD Act explicitly overrides where data is physically stored
- Applies to US companies: Any company incorporated in or doing significant business in the US can be served with a CLOUD Act warrant
- Includes subsidiaries: US parent companies can be compelled to access data held by foreign subsidiaries
- Conflicts with GDPR: Creates a legal conflict between US surveillance law and EU data protection law
- No EU court review: CLOUD Act warrants are issued by US courts without EU judicial oversight
For EU organizations, this means:
- Storing data in an EU region of a US cloud provider does not provide immunity from US law
- The legal question is who controls the infrastructure, not just where it sits
- Genuine sovereignty requires infrastructure operated by an EU entity with no US parent company
This is why data residency (location) is not the same as legal sovereignty (jurisdiction).
Who needs genuine cloud sovereignty?
Organizations that need legal certainty about data jurisdiction, not just physical location:
Public Sector
- Government agencies and ministries
- Healthcare providers (patient data under GDPR Article 9)
- Educational institutions (student data)
- Critical infrastructure operators
- Defense and intelligence contractors
Regulated Industries
- Financial services (banking, insurance, payments)
- Healthcare and life sciences (GDPR, NIS2, medical device regulations)
- Legal services (attorney-client privilege)
- Any organization handling sensitive personal data
Strategic Operations
- Companies competing with US tech giants
- Organizations subject to trade restrictions or sanctions
- Research institutions handling pre-publication IP
- Defense contractors and dual-use technology companies
GDPR/NIS2 Compliance
- Organizations needing to demonstrate "appropriate safeguards" for international transfers (GDPR Article 46)
- Essential entities and important entities under NIS2 Directive (requiring supply chain cybersecurity risk management)
- Organizations subject to Schrems II scrutiny (adequate protection against foreign surveillance)
Bottom line: If you answer "yes" to any of these questions, you need genuine sovereignty, not just data residency:
- Would foreign government access to your data create competitive, legal, or operational risk?
- Are you required to demonstrate GDPR compliance for sensitive data?
- Are you subject to NIS2 or other EU cybersecurity regulations?
- Do you need legal certainty about which courts have jurisdiction over your infrastructure?
Data residency addresses the first layer. Genuine sovereignty addresses all three: data location, operational control, and legal jurisdiction.
Run Your Workloads on Genuinely Sovereign Infrastructure
Leafcloud is a Dutch-owned cloud provider with infrastructure in the Netherlands. No US parent company, no CLOUD Act exposure, no sovereignty washing. Just compliant, sovereign EU cloud computing.