My own career has run between European regulations and legal systems in the Americas, long enough that I’ve stopped expecting either one to feel fully like home. That in-between position has shaped how I think about sovereignty — particularly, in the cloud. 

When we hear “digital sovereignty,” we tend to assume the term refers to borders — data locked inside a country, governments protecting local industry and favouring its national companies. There’s real substance to that reading: investment in local champions, in European innovation, in less dependence on a handful of providers for critical infrastructure. But sovereignty is bigger than patriotism and treating it as a flag-waving exercise undersells what’s actually at stake. 

Our economies are too interconnected for the question to be local versus global. The real question is whether organisations can trust the systems, the partners and the legal frameworks underneath their businesses. Cloud sovereignty, for me, isn’t about building walls. It’s about creating confidence. That data is protected, that critical services keep running, and that companies can innovate with legal certainty over their own digital assets. 

Today, businesses across Europe are asking fundamental questions about who governs and accesses their data and how critical services keep operating through disruption. Among highly regulated industries especially, sovereignty has stopped being a compliance footnote and become a strategic requirement. 

Sovereignty is more than data location  

A decade ago, when the General Data Protection Regulation (GDPR) was enacted, most of the questions companies were asking were where their data sat, who’s the controller and who’s the processor. Today the questions have fragmented and refined: who can access data, where the operational teams are based, what technical and organisational measures apply, which third parties are involved, what happens if a government requests their assets, and whether the service survives a crisis intact. That’s not anxiety. It’s due diligence. Location still matters, but it’s no longer the whole story. 

Three dimensions of sovereignty  

Terms in the tech sovereignty realm tend to be used interchangeably — even regulators don’t fully agree on the boundaries between them. For the purposes of this piece, I find it useful to separate three dimensions: 

  • Data sovereignty is about confidence that data stays protected under the laws that matter to the organisation, with transparency about who can access it and when — this is typically where the GDPR-specific questions reside.
  • Operational sovereignty is about technical independence and business continuity autonomy — the assurance that critical services keep running through disruption. For financial institutions, this is typically translated into the binding requirement under the Digital Operational Resilience Act (DORA).
  • Jurisdictional sovereignty is where the gap between hosting and control actually shows up: data residency alone doesn’t resolve which law ultimately governs access, particularly when a provider’s corporate structure spans multiple jurisdictions.

International transfer mechanisms exist precisely to bridge that gap, but they’ve proven legally contestable over time if lacking the adequate supplementary measures. This is why sovereign deployments that keep both data and operational control within a single jurisdiction, with clear procedures on how a company should act when facing a law enforcement agency request, have become a credible answer in their own right. 

Why the conversation changed 

Artificial intelligence (AI) has accelerated this shift. Customers now want to understand how data is used within AI systems, how models are governed and kept reliable, and how organisations are adapting to the EU AI Act — concretely, whether their use case triggers high-risk classification, and whether the AI components they rely on come from providers meeting the Act’s transparency and assessment requirements. The focus has moved past compliance into accountability, transparency and auditable evidence.

This shift isn’t happening in isolation. A report from Genesys with AWS and PAC found that 88% of European business leaders see innovation and digital sovereignty as compatible strategic priorities, not competing ones. The discussion is no longer about whether companies should embrace cloud and AI — it’s about how to do so while keeping control, transparency and trust intact. 

Sovereignty shouldn’t mean isolation 

Perhaps the biggest misconception about sovereignty is that it requires organisations to reject foreign technology providers. I don’t share that view. Sovereignty isn’t about excluding companies based on where they’re headquartered — it’s about whether businesses can meet their own bar for security, privacy, resilience and governance, regardless of the origin of who delivers the service. 

Security is the foundation, and frameworks like France’s SecNumCloud or Germany’s C5 set a real, auditable bar for that layer. But security certification alone does not necessarily answer the full set of legal, operational and sovereignty questions companies are now asking. Depending on the framework, a certification may address important aspects of resilience, governance and even legal exposure. But that may not automatically resolve every concern around corporate control, compelled disclosure or business continuity.

A provider may hold strong security attestations and still require closer scrutiny of its control structure or subcontracting chain where that creates exposure to laws outside the relevant jurisdiction in which the customer intends its data to remain protected. Security is the ground floor for sovereignty. The rest of the house — protecting data, maintaining resilience and delivering meaningful value to customers — is what organisations are ultimately building toward. 

Looking ahead 

Europe’s sovereignty debate is sometimes portrayed as a choice between global innovation and local control. Here again, I tend to disagree. The most successful businesses will continue to work across borders, partner internationally and adopt the best technologies available — while expecting stronger guarantees around AI compliance, privacy, security, resilience and governance. That’s why cloud sovereignty matters. Not because businesses want isolation, but because they need confidence. In today’s economic and geopolitical climate, trust may be Europe’s most valuable strategic asset.

What exists today points in the right direction but doesn’t go far enough. The EU’s own cybersecurity certification scheme for cloud services, the EUCS, was meant to include sovereignty requirements for the most sensitive workloads — but those provisions were significantly diluted during negotiation. The fragmentation isn’t an absence of effort, and we now see interesting projects such as the EU Tech Sovereignty Package that may clarify these doubts. But until regulators and the markets have that fully clear, the gap will keep getting filled by industry itself — through partnerships and sovereign-compliant offers built ahead of, rather than in response to, the regulation that’s still being negotiated. 

Tomorrow’s market won’t settle on one model. National champions, global hyperscalers and sector-specific sovereign solutions will likely coexist, each answering a different version of the same question: whose protections can be trusted, and under what law. What’s missing isn’t more models — it’s a consistent framework underneath them, so the same protections hold whether the provider sits in Frankfurt, Northern Virginia or somewhere in between. That’s the challenge in front of all of us, including Genesys. 

This is for informational purposes only and does not constitute legal advice. 


Empowering innovation across Europe’s most regulated industries  

We’re excited to announce the availability of the Genesys Cloud™ European Sovereign region. This represents an important milestone in helping organisations address sovereignty requirements while continuing to innovate. Built on AWS European Sovereign Cloud, it is designed to give organisations greater control over data, operations and governance without compromising the benefits of modern cloud technology.

Learn more about Genesys Cloud European Sovereign region here.