Skip to content

Europe · Analysis

Independent · Brussels & Berlin

Technology · Digital sovereignty

EU Commission prepares cloud restrictions for sensitive government data

The European Commission will present a Tech Sovereignty Package on 27 May that would limit member states' use of US cloud providers for financial, judicial and health data, requiring sovereign European infrastructure instead.

By , Technology Editor

Published

6 min read

The European Commission is finalising a legislative package that would for the first time restrict the ability of EU member states to place their most sensitive government data on cloud platforms operated by companies outside the bloc, primarily targeting the dominance of US providers such as Amazon Web Services, Microsoft Azure and Google Cloud.

Sources inside the Commission confirm that the Tech Sovereignty Package, scheduled for presentation on 27 May 2026, will contain provisions defining sectors where public bodies must use European cloud capacity. Financial, judicial and health data processed by governments and public-sector organisations would be required to run on infrastructure deemed sovereign, meaning it is owned, operated and legally controlled within the EU.

What the package contains

The package bundles two flagship initiatives: the Cloud and AI Development Act (CADA) and a second iteration of the European Chips Act. CADA is designed to create a regulatory framework that encourages the development and procurement of European cloud and artificial intelligence services, while Chips Act 2.0 aims to double the EU's share of global semiconductor manufacturing capacity to 20% by 2030. Together they represent the most concerted attempt yet to translate the concept of strategic autonomy into binding rules for digital infrastructure.

Commission officials stress that the cloud restrictions would not amount to a prohibition on US companies bidding for public contracts. Instead, a tiered model would classify data by sensitivity. Routine administrative workloads could remain on any compliant platform, but datasets covering tax records, court proceedings, patient histories and similar categories would have to reside on certified sovereign clouds. The officials, who spoke on condition of anonymity because the discussions are not public, said the precise thresholds are still under negotiation.

Transatlantic friction sharpens the debate

The push has accelerated since the return of Donald Trump to the US presidency in January 2025. European capitals have watched the new administration's approach to trade, defence and technology policy with growing unease. The 2018 US Cloud Act, which permits American law enforcement to compel US-headquartered companies to hand over data regardless of where it is physically stored, has long been cited by European data-protection authorities as a structural vulnerability. That vulnerability is now being treated as a political risk.

In February 2026, several EU governments told reporters they were actively exploring homegrown and open-source alternatives to US platforms and increasing budgets for digital sovereignty. France announced the rollout of Visio, a state-developed video-conferencing tool intended to replace Microsoft Teams and Zoom across all central government services by 2027. The French prime minister's office described the move as a pilot for broader substitution of critical software dependencies.

Building a European supply side

Demand-side restrictions only work if a credible European supply side exists. In April 2026 the Commission awarded a 180 million euro tender to four European sovereign cloud consortia to supply EU institutions and agencies. One of the winning bids involves a joint venture between Thales, the French aerospace and defence group, and Google Cloud, a partnership that illustrates the blurred line between European sovereignty and US technology ownership. Other consortia are built around OVHcloud, Scaleway and a German-led grouping centred on Ionos and the Open Telekom Cloud.

Market analysts estimate that US hyperscalers still control roughly 70% of the European cloud infrastructure market. European providers have grown revenues at double-digit rates but from a much smaller base. The Commission's strategy assumes that guaranteed public-sector demand, combined with CADA's procurement preferences, will create the scale needed for European firms to invest in the next generation of data-centre capacity and AI-optimised hardware.

Political hurdles in the Council

The package faces a complex legislative path. As a regulation, it requires approval from both the European Parliament and the Council of the EU. In the Council, unanimity is likely needed for provisions touching on national security and public-sector organisation, giving any single member state a veto. Countries with deep existing contracts with US providers, notably the Netherlands, Belgium and Ireland, have historically resisted mandates that could trigger costly migrations or breach long-term framework agreements.

Industry lobbying is already intensifying. The major US cloud providers argue that their European data centres, staffed by EU nationals and operated under EU law, already meet the highest sovereignty standards. They warn that mandatory localisation will raise costs, fragment the digital single market and slow the adoption of AI services that depend on global scale. European cloud vendors, predictably, welcome the direction but caution that the certification regime for 'sovereign cloud' must be technically precise to avoid creating a protectionist label that locks in incumbents.

Private sector left outside the scope

A notable feature of the draft is its confinement to the public sector. Private companies, banks, insurers, manufacturers, healthcare providers operating outside direct state control, would face no new restrictions on their choice of cloud provider. Commission officials say this reflects both legal competence limits and a pragmatic judgement that the state should lead by example before imposing obligations on the wider economy. Critics argue the distinction is arbitrary: a hospital run by a regional health authority falls inside the rules; a private clinic processing identical patient data does not.

What happens next

The 27 May presentation kicks off a legislative process that typically takes 18 to 24 months. The Parliament's industry committee (ITRE) will lead on CADA, while the civil liberties committee (LIBE) will scrutinise data-protection implications. Member states will negotiate in parallel through the Council's working parties on telecommunications and information society. The first concrete milestone is the publication of the Commission's impact assessment and draft certification criteria for sovereign cloud, expected before the summer recess. France, holding the Council presidency in the second half of 2026, has signalled it will prioritise the file.

Sources

  1. CNBC

    cnbc.com · 2026-05-07

People mentioned

Organisations

European Commission · European Union

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.