PRODSovereign European BaaS platformOpen Dashboard →

Sovereignty · 9 min read

AWS, GCP, Azure in the EU: protected from the CLOUD Act?

Affane Daylami · Fondateur · May 2, 2026

Back to blog

No. Choosing an AWS region eu-west-1, a Google Cloud region europe-west1 or an Azure France Center region changes the physical location of the servers, not the nationality of the company that operates them. AWS, Google Cloud and Microsoft Azure remain subsidiaries of American companies: Amazon.com Inc., Alphabet Inc. and Microsoft Corporation. The CLOUD Act applies to the enterprise, not the data center.

This English text was generated automatically from the French original and has not been reviewed yet.

However, the three have launched distinct sovereignty programs in recent years. AWS launched the European Sovereign Cloud, Google Cloud access controls and local partnerships, Microsoft the EU Data Boundary commitment. This comparison details what each actually covers, and what none of the three alone changes. The subject weighs little for a project without sensitive data. It becomes decisive as soon as a DPO, health data or a European public market enters the equation, a tipping point already detailed in our decision grid on the choice of a BaaS.

The essentials

  • The CLOUD Act applies to the nationality of the operating company, not to the region of the data center: data hosted in the EU by an American company remains, in theory, accessible upon request under American law.
  • AWS launched the European Sovereign Cloud (governance and operational staff based in EU, first region in Germany) but remains an offering from Amazon.com Inc.
  • Microsoft applies an EU Data Boundary commitment which limits the processing of data from its main cloud services to European territory, without changing the nationality of Microsoft Corporation.
  • Google Cloud offers sovereignty controls (client-side encryption, Key Access Justifications) and local partnerships, subject to the same reservation: Google LLC remains a subsidiary of Alphabet Inc.
  • None of the three initiatives creates, to date, an operating company totally independent of American shareholders, unlike a supplier whose parent company is itself under European law.
#
Legal mechanism

Why a server region is not enough: brief reminder

The CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) authorizes US federal authorities to request data owned or controlled by a company subject to their jurisdiction, regardless of where the data is physically stored. The law targets the company, not the country of the data center.

A European subsidiary of an American group remains, ultimately, under the capital control of its parent company. It is this control link that triggers the theoretical exposure, not the address of the datacenter chosen in the console.

The details of the text and its articulation with the GDPR are covered in our guide GDPR compliant and EU sovereign backend, and the precise effect of the nationality of a supplier in our article nationality of the supplier and CLOUD Act exposure. This section is limited to what distinguishes the three hyperscalers studied here.

#
AWS

AWS: European regions and the European Sovereign Cloud

AWS operates multiple regions in the European Union, including Ireland (eu-west-1), Frankfurt (eu-central-1), and Paris (eu-west-3). Each meets data latency and residency requirements, without changing the legal entity signing the contract.

In late 2023, AWS announced theEuropean Sovereign Cloud, a distinct infrastructure designed for EU-based operational governance: staff and operational decision-making located in Europe, with the first region planned in Brandenburg, Germany. The program directly responds to the requirements expressed by public customers and regulated sectors.

This operational governance does not change the shareholder structure. The European Sovereign Cloud remains an offering from Amazon Web Services, Inc., a subsidiary of Amazon.com Inc., a company incorporated under American law. The CLOUD Act exposure is linked to this link of control, independently of the claimed operational independence.

#
Google Cloud

Google Cloud: sovereignty controls and local partnerships

Google Cloud offers European regions in Brussels (europe-west1), Frankfurt (europe-west3), and several other cities across the continent. Its approach to sovereignty is based less on a distinct legal entity than on technical controls applied at thedata level.

Two concrete mechanisms illustrate this approach. Client-side encryption ensures that data is encrypted before reaching Google infrastructure, without Google holding the keys. Key Access Justifications show the customer each request for access to their data, including a government request, before it is honored.

Google Cloud has also established local partnerships, such as the S3NS joint venture with Thales in France, to offer a trusted cloud offering evaluated according to national security benchmarks. The underlying infrastructure nevertheless remains operated by Google LLC, a subsidiary of Alphabet Inc., a company incorporated under American law: the same capital control link applies.

#
Microsoft Azure

Azure: EU regions and the EU Data Boundary commitment

Microsoft Azure offers many European regions: France Central, Germany West Central, West Europe (Netherlands) and North Europe (Ireland). Choosing an Azure EU region primarily meets latency and contractual data residency requirements.

Since 2021, Microsoft has been rolling out in phases a commitment called EU Data Boundary: data processed by its main cloud services, Azure, Microsoft 365, Dynamics 365 and Power Platform, is stored and processed within the European perimeter. The stated objective is to reduce transfers outside the EU that have become superfluous, not to create a legal entity separate from Microsoft Corporation.

Microsoft also publishes a transparency report detailing the volume of government requests received and the share that the company has responded to. This transparency documents the real exposure without eliminating it: Microsoft Corporation remains a company under American law, regardless of where the data is stored.

#
Overview

Comparison: EU regions, sovereignty initiative, parent company

Three columns of facts, one constant: the nationality of the operating company does not change from one hyperscaler to another, regardless of the seriousness of the associated sovereignty program.

SupplierEU regions (examples)Sovereignty InitiativeNationality of parent company
AWSIreland (eu-west-1), Frankfurt (eu-central-1), Paris (eu-west-3)European Sovereign Cloud: EU-based operational governance and staff, first region announced in Brandenburg (Germany)United States (subsidiary of Amazon.com Inc.)
Google CloudBrussels (europe-west1), Frankfurt (europe-west3), Paris (europe-west9)Sovereignty controls (client-side encryption, Key Access Justifications) and local partnerships, including the S3NS joint venture with Thales in FranceUnited States (subsidiary of Alphabet Inc.)
Microsoft AzureFrance Centre, Germany West Central, West Europe (Netherlands), North Europe (Ireland)EU Data Boundary: storage and processing of data within the EU perimeter for the main cloud services, deployed in phases since 2021United States

The three lines in the “nationality” column are identical. This is precisely the point that this comparison documents: a sovereignty program does not modify this column.

#
What really changes

What these initiatives improve, and what they don’t change

These three programs improve real things: data residency, transparency of access, reduction of transfers outside the EU that are no longer necessary, and for AWS, operational governance ensured by staff based in Europe. These are measurable progress, not empty announcement effects.

None of the three, however, changes the link of shareholder control between the European subsidiary or division and its American parent company. A request addressed to the parent company, or which it can force its subsidiary to satisfy, remains, in legal theory, enforceable regardless of the operational independence displayed.

Factual tone, not a product review

This is not a questioning of the technical quality of these initiatives. It is an observation on the legal structure of the entity that holds them. A serious sovereignty program and unchanged legal exposure can coexist perfectly.

#
Verification grid

What to check before relying on a hyperscaler sovereignty program

Four questions to ask before considering a hyperscaler sovereignty program as sufficient for a sensitive project.

  1. Is the contract you sign attached to the sovereignty program entity, or does it remain attached to the standard US entity of the supplier?
  2. Does the program cover precisely the services you use (computing, storage, managed database), or only part of the catalog?
  3. Does the provider publicly document its position on the CLOUD Act, not just GDPR?
  4. Is there a contractual clause on the processing of government requests: notification, dispute, transparency?
#
Structural alternative

The other option: a parent company itself under EU jurisdiction

A structurally different approach consists of choosing a supplier whose parent company is itself incorporated under EU jurisdiction, which removes the link of control to an American company rather than regulating it.

This is the case of Aurabase SAS, a company incorporated under French law, whose verified production infrastructure operates in Germany and Finland. EU sovereignty depends on these two cumulative conditions, accommodation and the operating company, rather than just one of the two. The technical and legal details of this comparison against a comparable supplier are covered in Aurabase vs Supabase, and the complete compliance posture on the Aurabase compliance center.

#
Frequently Asked Questions

FAQs

Is the AWS European Sovereign Cloud exempt from the CLOUD Act?+
Not according to the dominant legal reading of the text. The program improves data residency and operational governance in the EU, but the entity remains an offering from Amazon Web Services, Inc., a subsidiary of Amazon.com Inc., a company incorporated under American law. It is the nationality of the company that determines CLOUD Act exposure, not the operational independence of a division.
Does Microsoft's EU Data Boundary protect against CLOUD Act requests?+
It limits where data is stored and processed, reducing some transfers outside the EU that have become unnecessary. It does not change the nationality of Microsoft Corporation. A request addressed to the parent company remains, in theory, valid regardless of the location of the data processed.
Is a company using AWS, Google Cloud or Azure in the EU region in violation of the GDPR?+
Not automatically. The GDPR regulates transfers outside the EU via specific mechanisms, such as standard contractual clauses or an adequacy decision, rather than prohibiting all use of an American hyperscaler. This is a separate topic from the CLOUD Act exhibition, although the two are often confused. See our GDPR and EU sovereign compliant Backend guide for details.
Is there a hyperscaler region completely independent of a US parent company?+
Not at AWS, Google Cloud or Azure to date: the three sovereignty programs studied here remain divisions or partnerships of an American parent company. Complete structural independence assumes an operating company itself incorporated under EU jurisdiction, with no link to American shareholder control.

AWS, Google Cloud and Microsoft Azure have each invested in a serious response to the question of sovereignty: operational governance in the EU at AWS, access controls and local partnerships at Google Cloud, data residency commitment at Microsoft. None of the three changes the box that matters most on a contract: the nationality of the company signing it.

For a project without sensitive data, this distinction remains secondary. For a DPO, health data or an EU public contract, it deserves to be verified before signing, not after.

For the complete decision grid applied to the choice of a BaaS, see why the CLOUD Act changes the choice of your BaaS. For details of what legally differentiates a supplier according to the nationality of its parent company, see nationality of the supplier and CLOUD Act exposure.

READY TO DEPLOY?

Your backend in five minutes.

No credit card required · 500 MB free · 50,000 MAU