Hosting-News · 4 Min. Lesezeit

European Sovereign Cloud IaaS Spending Is Up 83%, And "Sovereign" Is Doing a Lot of Work

European Sovereign Cloud IaaS Spending Is Up 83%, And "Sovereign" Is Doing a Lot of Work

Sovereign cloud has moved from policy papers into procurement budgets. Gartner projects worldwide sovereign cloud IaaS spending will hit $80 billion in 2026, and European spending on it to grow 83% year over year, from $6.9 billion in 2025 to $12.6 billion in 2026. Looking further out, Gartner expects businesses globally to move 20% of existing workloads from global cloud providers to local ones by 2029 because of sovereignty concerns. 1

That isn't a rounding error. It's a structural reallocation, and it's being driven by things that have already happened rather than by things people fear might.

Enforcement, evidence, and a response

Enforcement caught up first. DLA Piper's January 2026 survey put cumulative GDPR fines at €7.1 billion since the regulation took effect in 2018. 2 The Austrian, French and Italian data protection authorities have all found that sending analytics data to the US breached the GDPR's transfer rules. 3 Data residency stopped being a slide in a compliance deck and became a line item with a number attached.

Then someone said the quiet part under oath. Asked by a French Senate inquiry in June 2025 whether he could guarantee that French citizens' data would never be handed to US authorities without French consent, Microsoft France's director of public and legal affairs answered: "No. I cannot guarantee that, but, again, it has never happened before." Asked whether a properly framed request would oblige Microsoft to comply, he said it would. 4

That is the whole argument in two answers, from the vendor rather than from a competitor.

And the hyperscalers responded. AWS made its European Sovereign Cloud generally available in January 2026, opening in Brandenburg, Germany. AWS describes it as physically and logically separate from its other regions and operated exclusively by EU residents. The structure runs through a new parent company and three German subsidiaries, and AWS says operational control stays inside EU borders. 5

The sovereignty washing objection

That last point is where it gets contested. CISPE, the trade body for European cloud infrastructure providers, has publicly warned the Commission about "sovereignty washing", arguing that sovereignty has to be defined by control rather than by an EU presence. A US-headquartered company operating an EU sovereign region stays within reach of extraterritorial law like the CLOUD Act, regardless of where the racks are or who holds the badge at the door. 6

You don't have to pick a side to notice that the two claims aren't symmetrical. "Our data centre is in Frankfurt" is a statement about geography. "No non-EU government can lawfully compel disclosure of this data" is a statement about corporate structure and jurisdiction. Only the second is what most people mean by sovereignty, and only the second is hard.

The useful question isn't where the servers are. It's who can be served with an order, in what country, and whether they can comply without telling you.

Our position, plainly

We should be straightforward about what we are and what we aren't.

We're a European operator running services from four countries: Tirana, Skopje, Amsterdam and Dublin. Two of those are outside the EU entirely, which for some customers is the point and for others is a complication. Either way it's a real choice rather than a marketing region.

We're not a hyperscaler with a sovereignty programme. We're a small independent ISP, which means our answer to "who can be compelled" is short and checkable rather than a diagram.

The things that follow from that structure are concrete. We don't collect identity documents to sell you a server, so we don't hold a pile of them. We accept crypto, so payment doesn't require routing your identity through a card network. We don't monitor your traffic beyond what running the service requires, we run no website analytics, and visitor IP addresses are processed transiently by our abuse-prevention systems rather than retained, so there's less to produce. And you pick your jurisdiction per machine at deploy time, which means a €5/mo VPS is enough to put a workload under a different legal regime. That isn't the same as solving sovereignty, but it's a considerably cheaper experiment than a migration programme.

Questions instead of labels

Sovereignty isn't a product you buy. It's a property of an arrangement, and it's only ever partial. Transit crosses borders. Upstreams have their own obligations. Any provider, ourselves included, operates under laws we didn't write.

What you can do is stop treating it as binary and start asking the specific questions. Which entity holds the contract, under which law, what can compel them, what data actually exists to be compelled, and what happens if you need to leave.

An $80 billion market is going to produce a great deal of confident marketing over the next eighteen months. Those questions are how you tell it apart from the substance.

Sources

  1. Gartner: European spending on sovereign cloud IaaS to nearly double in 2026, Computerworld, 10 February 2026
  2. GDPR Fines and Data Breach Survey: January 2026, DLA Piper
  3. UPDATE: Further EU DPA orders stop of Google Analytics, noyb
  4. Microsoft admits it cannot guarantee data sovereignty, The Register, 25 July 2025
  5. AWS Launches AWS European Sovereign Cloud and Announces Expansion Across Europe, Amazon, 15 January 2026
  6. Don't let hyperscalers hijack digital sovereignty, EC told, The Register, 18 March 2026

Zurück zu Hosting-News