Data sovereignty: Why European companies need to act now
Digital sovereignty is not a buzzword but risk management. If you keep control over your data, you keep control over your business.

When Microsoft blocked the email account of the Chief Prosecutor of the International Criminal Court (ICC) in May 2025, it was a wake-up call for many IT managers in Europe (heise online). The background: US President Trump had imposed sanctions on the ICC in February 2025. Microsoft enforced them, and the Chief Prosecutor had to switch to the Swiss email provider Proton.
The Open Source Business Alliance (OSBA) called the move unprecedented and urgently called for European alternatives.
What sounds like an isolated geopolitical incident reveals a structural problem that affects European companies of every size: if you run critical business processes and data on US cloud infrastructure, you give up some control, whether you realise it or not.
What does data sovereignty mean?
Data sovereignty (often also called digital sovereignty) is the ability to keep full control over your own data, systems and digital processes. This covers not only where the data is physically stored, but also which law the cloud provider is subject to, who has access to the infrastructure, and how transparently operations and governance are handled.
In practice, there are three dimensions:
Data ownership: Where is my data stored and processed? Who can access it? Does my data stay in Austria, or at least in the EU?
Technological sovereignty: Do I depend on one provider's proprietary services? How much work would it be to switch providers?
Operational sovereignty: Who actually runs the infrastructure? Which jurisdiction is the operator subject to?
Why isn't a data centre in the EU enough?
Many companies have a false sense of security because their US cloud provider runs data centres in Europe. But the physical location alone does not solve the problem.
The US CLOUD Act of 2018 requires US companies to hand over customer data when the authorities request it, even if that data is stored in data centres outside the US. In July 2025, Microsoft France's chief legal officer admitted before a Senate committee that Microsoft cannot guarantee that European customers' data will not be passed on to the US government (Golem, Dr. Datenschutz).
In other words: as long as the cloud provider is a US company, a residual risk remains, no matter where the data centre is. For companies that process personal data, work in regulated industries or operate critical infrastructure, that is a serious compliance and business risk.
The drivers: GDPR, NIS2 and geopolitical reality
Three developments make data sovereignty particularly urgent right now:
Regulatory pressure: The GDPR sets clear requirements for processing personal data. The NIS2 Directive tightens security requirements for operators of critical infrastructure and their suppliers. Companies that do not meet these requirements risk heavy fines.
Geopolitical uncertainty: The events around the ICC have shown that political decisions in the US can directly affect European IT infrastructure. In extreme cases, sanctions, export restrictions or political conflicts can lead to cloud services being restricted overnight.
Growing dependence: US hyperscalers still control around 70 percent of the European cloud market (Fortune Business Insights). The more companies invest in proprietary services, the harder and more expensive it becomes to switch later, which is known as vendor lock-in. A Bitkom survey confirms the trend: more and more companies in the DACH region are deliberately moving away from US providers.
What can SMEs and start-ups actually do?
The good news: data sovereignty is not a privilege of large corporations. SMEs and start-ups in particular have practical ways today to become digitally independent without giving up modern cloud technology.
Evaluate European cloud providers: The market for European alternatives is growing. Providers such as Exoscale, Hetzner, OVHcloud, Scaleway and STACKIT offer sovereign infrastructure with data residency in the EU, some with data centres in Austria itself. These providers are subject only to European law.
Build on open-source standards: If you build your infrastructure on open standards, you avoid the dreaded vendor lock-in. Containerised applications can be moved between cloud providers when needed, without rebuilding the entire architecture.
Estimate the migration effort realistically: Migrating from AWS, Azure or GCP to a European provider is not rocket science, provided you haven't relied too heavily on proprietary managed services. Standardised container workloads can usually be moved with manageable effort. We did exactly that with a healthcare application and documented what we learned migrating from AWS to Exoscale.
Plan for compliance from the start: For companies in healthcare, finance or the public sector in particular, sovereign cloud infrastructure is increasingly a regulatory requirement, not just a selling point.
Data sovereignty as an opportunity
Data sovereignty is often presented as a burden: one more requirement that costs money and adds complexity. I see it differently. If you move to sovereign infrastructure now, you gain not only compliance certainty but also the trust of customers and partners. In the DACH region in particular, data protection is seen as a mark of quality.
That is why data sovereignty is a central topic for us at agsolutions. We rely on European infrastructure and run our customers' applications on Exoscale, a European cloud provider with data centres in Vienna, among other locations. Combined with Kubernetes, Infrastructure as Code and automated CI/CD pipelines, this makes for a platform that is modern, scalable and sovereign.
If you are wondering whether a sovereign cloud solution is right for your company, take a look at our Sovereign EU Cloud & DevOps with Exoscale service. We offer a free workshop in which we analyse your starting point together and work out specific recommendations.
Got a similar project in mind?
In a free initial call we look at your situation and tell you what's realistic and what the next step looks like.

// about the author
Alexander J. Gassner, MSc
Founder and managing director of agsolutions, with more than 15 years in software development (MSc Software Engineering, FH Hagenberg). Builds and runs business-critical software from requirements to operations: Kotlin, Spring Boot and React in the code, Kubernetes, Pulumi and GitOps in operations, as an Exoscale Certified Solution Architect.


