Home›Guides›Sovereignty

Sovereignty

Sovereign cloud: definition, criteria and limits

In a procurement file, a sovereign cloud is a service whose operator, applicable law and administrative access are known, and whose data can be taken back. The marketing definition varies. The criteria, on the other hand, lend themselves to a grid.

Updated October 20269 min readOfficial sources cited

Why a grid rather than a label

Writing “sovereign cloud” in a call for tenders amounts to asking a question to which every bidder answers yes. The answers become impossible to compare, and the choice is made on price or on the impression left by the presentation.

A grid forces every bidder to answer the same question, with supporting evidence. It also protects the buyer after signature: a commitment written into the tender response can be carried over into the contract, whereas an adjective cannot be verified. The concept itself is explained in what is a sovereign cloud. This page is for purchasing.

A usable definition

Use this one.

A digital service is treated as sovereign, for a European buyer, when the company that operates it falls under European law, the data entrusted to it and its backups remain within the stated geographical perimeter, operational access is identified, and the client can export its data and then have it deleted.

This sentence is a working tool. It is not a section of the Data Protection Act 2017, which does not award a “sovereign” label.

In Mauritius, the Data Protection Act 2017 is enforced by the Data Protection Office, headed by the Data Protection Commissioner. It applies to controllers and processors established in Mauritius or using means of processing there, and requires their registration with the Commissioner (section 14), appropriate security measures including pseudonymisation and encryption (section 31), and notification of a breach no later than 72 hours after becoming aware of it (section 25). A transfer outside Mauritius requires demonstrated appropriate safeguards, the explicit consent of the individual, or a necessity provided for by law (section 36).

Each part of the sentence refers to one or more of the criteria below. That is what makes it usable: it can be broken down into questions and the answers scored.

Ten criteria

Each criterion is proven by a document, not by an adjective.

  1. Operating company. Company name, country of head office, and parent company. A European subsidiary of an American group can invoice in euros while belonging to a group subject to American law. This is the criterion that determines whom a foreign authority can approach.
  2. Governing law of the contract. Applicable law and competent court. Check that the general terms and conditions and the data processing agreement say the same thing.
  3. Data perimeter. Content (emails, files), backups, technical logs, support data. Content alone is not enough: a commitment that covers only mailboxes leaves the copies aside.
  4. Location. Country or region for each category in point 3. “Europe” must be specified: European Union, EFTA, or a named country.
  5. People who administer. Operator employees, processors, on-call staff outside the area. Remote access, even temporary, is processing. Also ask whether this access is logged and whether the client can consult the log.
  6. Encryption keys. Who holds them, who can use them for a restore, who can hand them over to a third party. The question is not “is the data encrypted?”, but “who can decrypt it?”.
  7. Processors. Up-to-date list: antispam, backup, support, audience measurement, identity. A processor subject to another law can cancel out the effect of criterion 1.
  8. Requests from authorities. Internal procedure when an authority requests data, and the law applicable to that request. Ask whether the provider undertakes to inform the client, insofar as the law permits.
  9. Reversibility. Formats, timeframe, cost, and what cannot be exported (chat histories, internal rules, logs). The safest approach is to test an export before signing.
  10. Any qualification. If the buyer requires SecNumCloud, the name of the qualified service must be the one in the ANSSI catalogue. An offering hosted on qualified infrastructure does not inherit the qualification. Since version 3.2 of its framework (2022), SecNumCloud includes requirements for protection against non-European laws, covering head office, control of capital, location and personnel.

How to weight them

The ten criteria do not carry the same weight for every buyer. For email and file sharing, criteria 1, 3, 4, 5 and 9 generally make the difference between offerings. Criterion 10 is eliminatory when required, and neutral otherwise. Decide on the weighting before opening the responses, not after.

The limits, stated clearly

Location is not law. A datacenter in Frankfurt operated by an American company remains a service of that company. The American CLOUD Act targets data held by a provider subject to United States jurisdiction, regardless of the country where the disk is located. See protecting a business from the CLOUD Act and the comparison European cloud or American cloud.

European law does not mean no requisitions. A French, German or Dutch judge can order an operator within their jurisdiction to disclose data. The difference lies in the court, the procedure and the means of appeal. A grid that suggested otherwise would mislead the buyer.

Software and operator are distinct. Nextcloud is published by Nextcloud GmbH, in Germany. Zimbra is published by Synacor, in the United States. BlueMind is a French company. In all three cases, the sovereignty of your service depends on who installs it, who backs it up and who answers the phone. The software vendor’s nationality matters mainly if it has access to the data: it is then addressed under criterion 7.

SecNumCloud is narrow. It is an ANSSI qualification, offering by offering, with a scope and an end date. It is often required for sensitive government data. It is disproportionate as the sole criterion for an SME looking for email and file sharing. It is insufficient if invoked without reading the decision.

No offering covers every use of Microsoft 365. Advanced Excel, Power BI, the Teams ecosystem and business add-ins have no general equivalent among European operators. The sovereignty criterion does not settle this point. It comes on top of it. If these uses are central, the grid may lead to keeping Microsoft 365 with full knowledge of the facts: see Microsoft 365 versus a sovereign solution.

How to write it into a specification

Replace “sovereign cloud” with the ten criteria, each with an expected piece of evidence. You can then compare a Microsoft offering with data residency, a Google offering with a data region, a Swiss offering such as Infomaniak, and an offering operated in France. The comparison becomes a reading of evidence, not a battle of adjectives.

CriterionQuestion put to the bidderExpected document
1. Operating companyWhich company operates the service, and who controls it?Company registration extract, group organisation chart
2. Governing lawWhich law, which court?Clause in the general terms and conditions and in the data processing agreement
3 and 4. Perimeter and locationWhich categories of data, in which countries?Table by category: content, backups, logs, support
5. AdministrationWho administers, from where, with what trail?Description of the teams and of logging
6. KeysWho can decrypt, and in which cases?Description of the encryption scheme
7. ProcessorsWho receives a copy or access?Named list with countries
8. AuthoritiesWhat do you do when faced with a request?Written procedure
9. ReversibilityHow do we get everything back, and how quickly?Export procedure, formats, trial run
10. QualificationIs the proposed offering qualified?Reference in the ANSSI catalogue, if required

Example: a mid-sized services company issuing a tender

Hypothetical case. A mid-sized services company is renewing its email and file sharing. The first version of its specification asks for “a sovereign cloud solution with hosting in Europe”. All three bidders answer yes.

The IT department rewrites the tender using the grid. The answers become readable. The first bidder hosts in Europe but belongs to a group subject to American law: criterion 1 not met, criteria 3 and 4 well documented. The second is a European company, but entrusts night-time support to a processor outside the area: criterion 5 to be negotiated. The third meets the legal criteria but does not cover one business use: management must make the call. The grid did not make the choice for the company. It made the choice explicit.

Common mistakes

  • Writing “sovereign” without defining it. Everyone ticks the box, and the tender no longer discriminates.
  • Limiting the commitment to content. Backups, logs and support data must be included in the same commitment (criterion 3).
  • Making SecNumCloud the only criterion. Suitable offerings are excluded, or an offering is accepted whose qualified scope does not cover the service purchased.
  • Mixing functions and sovereignty in a single score. A good functional score can mask an unmet legal criterion, and vice versa. Score them separately.
  • Not testing the export. Reversibility is the easiest criterion to verify before signing. It is also the one most often left on paper.

Frequently asked questions

Is there a legal definition of sovereign cloud?

No. The Data Protection Act 2017 does not award a “sovereign” label. SecNumCloud is an offering qualification issued by ANSSI, not a general definition. The definition proposed here is a working tool for a buyer.

Does a European subsidiary of an American group meet criterion 1?

Not in general. The criterion concerns the company that operates the service and the company that controls it. A subsidiary can invoice in euros and host in Europe while belonging to a group subject to American law. The page European cloud or American cloud details this difference.

Should all ten criteria be required?

They should all be asked, to obtain comparable answers. Their weight, however, depends on your data and your obligations. A weighting set in advance avoids adjusting the grid to the preferred bidder.

Can this grid be applied to Microsoft 365 or Google Workspace?

Yes, and that is its value. These software vendors’ data residency arrangements are assessed under criteria 3 and 4. The vendor’s nationality is assessed under criterion 1. The page Microsoft 365, Google Workspace or Klytic helps you choose between these offerings.

Where Klytic stands

Klytic ticks part of the grid and not the rest. The operator is Dedicace Software, a French company. The client chooses Klytic hosting in any geographical area corresponding to the applicable jurisdiction, subject to the availability of the required services, for example in Europe or Mauritius, or on the client’s servers. The email software vendor is American (Zimbra / Synacor), the documents software vendor is German (Nextcloud), with a dedicated instance per client.

On the keys criterion, the data is held entirely by the client, or by Klytic on the client’s behalf, in a geographical area that falls under the applicable jurisdiction. It is encrypted natively, or according to the client’s choice. The key is held by the client or kept in its account, and Klytic has no access to it. The stages where encryption is managed by Klytic are detailed on the page protecting a business from the CLOUD Act. The contract must describe this custody and this encryption.

Klytic does not hold a SecNumCloud qualification. Presenting it otherwise would be inaccurate.

This page describes a general framework. It does not replace an analysis of your contract.

Sources

Accessed in October 2026.

  • Data Protection Office, “The Data Protection Act 2017” (Act No. 20 of 2017). dataprotection.govmu.org
  • ANSSI, FAQ SecNumCloud, on the scope of the qualification, the absence of automatic inheritance and the requirements for protection against non-European laws introduced by version 3.2 of the framework. cyber.gouv.fr
  • 18 U.S.C. § 2713, obligation to disclose data held or controlled by a provider subject to American law, regardless of the storage location. govinfo
  • Zimbra, FAQ (software vendor: Synacor). zimbra.com/faqs
  • Nextcloud GmbH, legal notice. nextcloud.com/impressum
  • BlueMind, presentation of the software vendor. bluemind.net
  • Klytic, operator, hosting options and scope of services. klytic.com

A French operator for your data

Email, documents, video conferencing, CRM and telephony, hosted in the zone that matches your jurisdiction, for example in Europe or Mauritius, or on your premises.

Talk to an advisor →

Klytic hosting

Welcome offer

30-day free trial, assisted migration

No-commitment trial offer. An advisor will call you back to understand your needs and prepare your Klytic space.