Sovereignty
A sovereign cloud is a service for which you can say who operates the data, which court can order its disclosure, and how you get it back. The term has no definition in the Data Protection Act 2017. It is a purchasing criterion, which becomes useful the day you translate it into verifiable questions.
Updated October 20268 min readOfficial sources cited
“Sovereign” has become a sales pitch. It appears on very different offerings: an email service installed in a Paris datacenter, an American office suite with a European data region, open source software, an infrastructure qualified by ANSSI. All of these offerings may have their merits. They do not answer the same question.
For an executive, a CIO or a DPO, the risk is ticking a box without knowing what it contains. The day a client asks where its data is, an auditor rereads the record of processing activities, or a provider changes owner, the label is of no use. Only written answers count: who operates, which law applies, how you exit.
This page explains the concept. The criteria grid for a tender is in definition, criteria and limits. The comparison between a European operator and an American software vendor is the subject of the page European cloud or American cloud.
A company entrusts its emails, files and client records to a third party. It wants to know three things.
If the contract answers these three points, the “sovereign” label has substance. If it merely says “datacenter in Paris” or “datacenter in Frankfurt”, it describes a place. A place is useful, notably for the record of processing activities. It does not say who can be compelled to produce the data.
In European tenders, the term generally covers five expectations.
The French SecNumCloud qualification, issued by ANSSI, formalises part of these expectations for a specific offering. It qualifies neither a company as a whole, nor an application merely because it is installed on qualified infrastructure. The ANSSI catalogue is authoritative, offering by offering. For an SME, the question arises mainly when the nature of the data or a principal client requires it.
It is not an immunity. A European operator remains subject to the law of its country, to local judicial requisitions, and to mutual legal assistance agreements. Sovereignty changes the legal framework. It does not eliminate every access request. What changes is the court that can order disclosure, the procedure followed and the remedies available to the operator and its client. For a European company, this is a framework its advisers know and within which it can act.
Nor is it a synonym for “open source”. The software tells you who wrote the program. Sovereignty tells you who holds the data and who holds the keys. Free software can be operated by a company subject to foreign law. Software from a foreign vendor can be operated by a European company that alone retains control over the data.
At Klytic, the data is held entirely by the client, or by Klytic on the client’s behalf, in a geographical area that falls under the applicable jurisdiction. It is encrypted natively, or according to the client’s choice. The key is held by the client, or kept in its account: Klytic has no access to it. To obtain it, Klytic would have to destroy or change a password it does not possess, and the client would notice.
Some stages remain encrypted by Klytic, because the service must process the content: emails quarantined by filtering, encrypted in the database, and emails and documents processed in the CRM. Emails are the only exception, when the client has enabled encryption with its own key. Access to files is also tightly restricted by limited access rights, and a connection audit raises an alert in the event of a fraudulent attempt. Details are on the page protecting a business from the CLOUD Act. The contract must describe this custody, this encryption and these safeguards.
Finally, it is not a promise of functions equivalent to Microsoft 365 or Google Workspace. You can have a European operator and a less complete office suite. You can have a very complete office suite and an American operator. These are two separate decisions.
Treating them separately avoids two symmetrical mistakes: abandoning a tool the business depends on as a matter of principle, or dismissing the legal question because teams like the tool. The threshold specific to Microsoft 365 is detailed in Microsoft 365 versus a sovereign solution.
Hypothetical case. A 25-person accounting firm receives a simple question from an industrial client: “Where are our accounting records, and who can access them?” The firm uses an email service and file sharing whose brochure says “hosted in France”.
Going through the three questions, the partner discovers that the invoicing company is French, but that operations and support are provided by the subsidiary of a foreign group, and that backups are entrusted to a processor whose contract does not name the country. The brochure was not false. It did not answer the client’s question.
The firm has two reasonable options: obtain written answers from the provider and add them to the file, or choose an operator whose answers suit it. Either way, it answers its client with facts, not with an adjective.
Ask for four documents, not a brochure.
If a provider cannot supply these elements in writing, that in itself is information. Then compare the answers with what your record of processing activities says: that is where discrepancies appear.
In Mauritius, the Data Protection Act 2017 governs transfers of data outside the country: a transfer requires demonstrated appropriate safeguards, the explicit consent of the individual, or a necessity provided for by law, such as the performance of a contract or a legal obligation (section 36). The Act also requires appropriate security measures, including encryption (section 31). For requests from foreign authorities, see the page on the CLOUD Act. For the list of purchasing criteria, see definition, criteria and limits.
No. The Data Protection Act 2017 governs the registration of controllers and processors (section 14), the security of processing (section 31) and transfers outside Mauritius (section 36). It does not define the word “sovereign” and does not require choosing any particular operator. It does, however, require safeguards for any transfer outside Mauritius, which overlaps with a large share of the questions on this page.
Not necessarily. Location is one of the expected answers, not the only one. You also need to know which company operates the service, which law applies to it, who can access the data and how to get it back.
When the nature of the data or a principal client requires it, yes, and the name of the offering must appear in the ANSSI catalogue. For SME email and file sharing, questions about the operator, access and reversibility are generally more decisive.
No. Open source makes it possible to read the code and makes it easier to change hosting provider. It does not say who holds the data or who holds the keys.
No. A European operator remains subject to the law of its country and to requisitions from its courts. The difference lies in the court, the procedure and the remedies.
Klytic is operated by Dedicace Software, a French company. The services are based on proven or open source solutions, and on modules and services developed by Klytic. The isolation of these services is ensured and managed by Klytic servers developed for this purpose.
Hosting is possible in any geographical area corresponding to the applicable jurisdiction, subject to the availability of the required services, for example in Europe or Mauritius, or on the client’s servers. Details are on the page hosting and sovereignty.
Klytic is not a SecNumCloud-qualified offering. Like any French operator, it remains subject to French law.
This page describes a general framework. It does not replace an analysis of your contract.
Legal status as of 5 October 2026. This text does not replace a contract review. In Mauritius, the Data Protection Act 2017 governs the processing of personal data and its transfer outside the country; the Data Protection Office oversees its application. The ANSSI catalogue is authoritative for SecNumCloud.
Accessed in October 2026.
Email, documents, video conferencing, CRM and telephony, hosted in the zone that matches your jurisdiction, for example in Europe or Mauritius, or on your premises.
Welcome offer
No-commitment trial offer. An advisor will call you back to understand your needs and prepare your Klytic space.