← Blog
Sovereignty Cloud Act · Data Act

Operational sovereignty: what it is and how to measure it

by Team P3·15 July 2026·8 min read

Operational sovereignty is the ability to keep operating — accessing your data, running your systems, delivering your processes — regardless of decisions made by parties outside your control. It is not measured by where the server sits, but by who can interrupt, read or condition your processes. And it can genuinely be measured: with five tests, one per critical dependency.

01What is operational sovereignty?

Working definition, the one we use with clients: operational sovereignty is an organisation's ability to keep operating regardless of decisions made by parties it does not control. A vendor doubling the price or changing its terms of service. A non-EU jurisdiction ordering access to data. A sanction, an embargo, a political decision switching off a service. If any of these events stops one of your critical processes, that process is not sovereign — whatever the brochure says.

The distinction to hold on to is the one between data residency and sovereignty. Residency answers "where does the server sit"; sovereignty answers "who can compel the provider, who can read the data, what does it cost me to leave". The first is geography. The second is control. Nor is it the "digital sovereignty" of conference panels: it is an operational property that is either demonstrated with evidence — contracts, architectures, exit times — or does not exist.

Citable definition. Operational sovereignty: the ability to access your own data, run your own systems and deliver your own processes even when a third party — vendor, jurisdiction, platform — changes the rules. It is measured in evidence and in days, not in declarations.

02Why is "a datacenter in Europe" not enough?

Because jurisdiction follows the company, not the server. The US CLOUD Act (2018) made explicit that providers subject to US jurisdiction must preserve and produce data in their possession, custody or control regardless of where it is stored (US DoJ, CLOUD Act Resources; Congressional Research Service, R45173). A datacenter in Frankfurt operated by an American company answers to Washington before it answers to Brussels. As early as July 2019 the EDPB and EDPS, in the joint assessment requested by the European Parliament, found that this extraterritorial reach can place providers in a conflict of laws with the GDPR (EDPB-EDPS, joint response to the LIBE Committee, 2019).

For years the vendors' answer was "it has never happened, and we push back on requests". Then came the moment the question was asked under oath. On 10 June 2025, before the French Senate inquiry committee on public procurement and digital sovereignty, the director of public and legal affairs of Microsoft France was asked whether he could guarantee that French citizens' data would never be transmitted to US authorities without the agreement of the French authorities. The answer: I cannot guarantee it (ActuIA, French Senate hearing, June 2025). That is not a scandal: it is American law working as designed. The scandal is continuing to call "sovereign" what is not. We took the contractual mechanics apart piece by piece in the Cloud Act explained to a CFO.

Jurisdiction follows the company, not the server. A European datacenter with American keys is a vault with a spare key in Washington.

03How dependent is Europe on non-EU cloud?

The numbers describe a structural dependency, not a footnote. According to Synergy Research Group, Amazon, Microsoft and Google together account for about 70% of the European cloud market, while European providers' share of their own market has fallen from 29% in 2017 to 15%, where it has sat flat since 2022 — with the leading local players, SAP and Deutsche Telekom, at 2% each. All this in a market worth €61 billion in 2024 and growing at double digits (Synergy Research Group, July 2025).

The point is not that the three hyperscalers are bad vendors: it is that a 70% dependency on three companies subject to the same non-EU jurisdiction is a single point of failure — technical, contractual and geopolitical. The European Commission itself has now put this in writing: the proposal for a Cloud and AI Development Act presented on 3 June 2026, the centrepiece of the tech sovereignty package, states that over-reliance on non-EU cloud providers "poses a significant risk to Europe's digital autonomy and resilience" and aims to triple the EU's datacenter capacity within 5-7 years (European Commission, CADA, June 2026). The proposal is at the start of the legislative procedure: it will bear fruit in years. Your exposure, however, exists today.

70%
of the European cloud market held by three US providers (Synergy, 2025)
15%
European providers' share of their own market (was 29% in 2017)
12 Jan 2027
from this date cloud switching charges are banned (Data Act, Art. 29)

04How do you measure operational sovereignty? The five tests

Sovereignty is not an adjective for a tender document: it is a verifiable property. For every critical vendor — cloud, business SaaS, AI, email — apply five tests. Every answer must be documentable evidence, not an opinion.

Operational sovereignty is not a declaration. It is the number of days you need to leave, written in a document you have verified.

05What does the Data Act change (and what doesn't it)?

On the exit test, Europe has just shifted the balance towards the customer. The Data Act (Regulation EU 2023/2854), applicable since 12 September 2025, gives customers of data processing services — IaaS, PaaS, SaaS — the right to switch providers with a maximum notice period of two months and a 30-day transition period, and explicitly includes the right to move data and digital assets back to on-premises infrastructure (European Commission, Data Act; EUR-Lex, Reg. EU 2023/2854). On costs, two dates: since September 2025, switching charges must be limited to the costs actually incurred; from 12 January 2027 they are banned entirely.

What the Data Act does not do: it does not turn the right of exit into the capability to exit. The regulation covers "exportable data" — not the skills, not the architecture you have meanwhile built around the vendor's proprietary services, not the AI models trained inside a closed platform. And it does not touch the jurisdiction test: you can change hyperscaler in 30 days and remain under exactly the same extraterritorial law as before. The Data Act lowers the cost of the door. Walking through it — and choosing where it leads — remains an architecture job.

Right ≠ capability. From 12 January 2027 leaving will be contractually free. But if your data sits in proprietary formats and your processes only run on the vendor's services, the free door opens onto a wall. The exit test is passed in architecture, not in court.

06Where to start, concretely

Not with a position paper: with a dependency map. One sheet with three columns — critical process, vendor, jurisdiction — and the five tests applied to every row. It is the same method we use for NIS2 and DORA: first the snapshot, then the decisions. That is where the real priorities come from: the processes that need on-premises (critical data, keys, AI on sensitive data — the case for AI without vendor lock-in), those where an EU-hosted vendor with your keys is enough, and those where lock-in is acceptable because the exit is rehearsed and cheap.

It is the principle our operational sovereignty page and the whole P3 product line are built on: sovereign software, on-premises or EU-hosted, lock-in-free by design. If you want to start from the snapshot — network, data, vendors, jurisdictions — the first step is a seven-day on-prem audit. To discuss your case, write to us.

In short. Operational sovereignty is the ability to keep operating regardless of third-party decisions: it is measured by who can interrupt, read or condition your processes, not by where the server sits. The Cloud Act makes geography irrelevant (confirmed by Microsoft before the French Senate, June 2025); three US providers account for 70% of European cloud; the Data Act grants a right of exit since 12 September 2025 and bans switching charges from 12 January 2027. The five tests — jurisdiction, keys, exit, continuity, competence — turn sovereignty from a slogan into evidence.
[P3]
Team P3
Technical boutique · EU-hosted
P3 team notes on sovereignty, compliance and ICT resilience, written by those who apply them for European SMEs. Write to us →
Want to measure your operational sovereignty?

Start with the map of your dependencies.

[ Book Munin ]