Two different promises get sold as one word
Sovereign cloud is used to describe at least two unrelated guarantees, and the ambiguity does a lot of selling on a vendor's behalf: where your data physically sits, and which country's courts can compel a provider to hand it over. These are not the same question, and a product can answer the first one well while leaving the second one wide open.
Data residency is a location fact. Legal jurisdiction is a question about which government's courts and agencies have power over the company operating the servers, no matter where those servers sit. A cloud region physically located in Frankfurt or Paris does not, by itself, answer the jurisdiction question at all.
What the CLOUD Act actually says
The 2018 US CLOUD Act settled the jurisdiction question for any provider headquartered or doing sufficient business in the United States. Its operative text, codified at 18 U.S.C. 2713, requires a covered provider to comply with a legal demand to preserve, back up or disclose data 'regardless of whether such communication, record, or other information is located within or outside of the United States.'
Microsoft's own description of its EU Data Boundary commitments covers data residency and processing location in detail, but does not address CLOUD Act exposure anywhere in that description. The gap showed up directly under oath: in June 2025, Microsoft France's legal director, Anton Carniaux, told a French Senate committee examining public-procurement sovereignty that he could not guarantee EU-hosted customer data would never reach US authorities, adding only that it had not happened yet.
Only some sovereignty schemes touch the actual jurisdiction question
Three European certification names get used almost interchangeably, and only one of them actually restricts who can be legally compelled to hand your data over.
France's SecNumCloud, run by the cybersecurity agency ANSSI, requires that non-EU shareholders remain a minority stake in the operating company and states its purpose explicitly: shielding the operator from an order issued by a state outside the EU, so that the company answers only to EU law. Germany's C5 catalogue, run by the BSI, is a different kind of scheme entirely: an attestation of security controls, with the BSI stating plainly that it does not even vet the auditors who issue C5 reports, and no ownership or jurisdiction requirement anywhere in its criteria. The EU-wide scheme meant to sit above both, EUCS, remains formally unadopted as of August 2026. National certification authorities, including the Dutch NCCA, confirm that no certificates are being issued under it.
| Scheme | Jurisdiction guarantee | Status, August 2026 |
|---|---|---|
| SecNumCloud (France, ANSSI) | Yes, non-EU shareholders capped, non-EU legal orders blocked | Active, issuing qualifications |
| C5 (Germany, BSI) | No, security-control attestation only | Active, issuing reports |
| EUCS (EU-wide) | Disputed, would depend on final assurance level | Not yet adopted |
What this means for you
A compliance answer that says 'we use a sovereign cloud' is not a complete answer until you know which of the two guarantees it is actually buying you.
Ask the vendor directly whether the operating entity is legally immune from non-EU jurisdiction, the SecNumCloud model, or merely audited for security controls with data stored in-region, the C5 model that most 'EU region' offerings from global providers resemble. If your actual requirement is keeping data out of reach of a foreign government rather than satisfying a data-residency line item, only a jurisdiction-immune structure meets it.
Do not accept 'EU data boundary' language alone as proof of jurisdiction immunity. Ask the vendor's own legal counsel the same question the French Senate put to Microsoft's, and expect the same honest answer if the structure has not changed.
Read next: Europe Built the Digital Euro Cloud Without the US | France Moves Its Health Database Off Microsoft Azure



