However, the three have launched distinct sovereignty programs in recent years. AWS launched the European Sovereign Cloud, Google Cloud access controls and local partnerships, Microsoft the EU Data Boundary commitment. This comparison details what each actually covers, and what none of the three alone changes. The subject weighs little for a project without sensitive data. It becomes decisive as soon as a DPO, health data or a European public market enters the equation, a tipping point already detailed in our decision grid on the choice of a BaaS.
The essentials
- The CLOUD Act applies to the nationality of the operating company, not to the region of the data center: data hosted in the EU by an American company remains, in theory, accessible upon request under American law.
- AWS launched the European Sovereign Cloud (governance and operational staff based in EU, first region in Germany) but remains an offering from Amazon.com Inc.
- Microsoft applies an EU Data Boundary commitment which limits the processing of data from its main cloud services to European territory, without changing the nationality of Microsoft Corporation.
- Google Cloud offers sovereignty controls (client-side encryption, Key Access Justifications) and local partnerships, subject to the same reservation: Google LLC remains a subsidiary of Alphabet Inc.
- None of the three initiatives creates, to date, an operating company totally independent of American shareholders, unlike a supplier whose parent company is itself under European law.
Why a server region is not enough: brief reminder
The CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) authorizes US federal authorities to request data owned or controlled by a company subject to their jurisdiction, regardless of where the data is physically stored. The law targets the company, not the country of the data center.
A European subsidiary of an American group remains, ultimately, under the capital control of its parent company. It is this control link that triggers the theoretical exposure, not the address of the datacenter chosen in the console.
The details of the text and its articulation with the GDPR are covered in our guide GDPR compliant and EU sovereign backend, and the precise effect of the nationality of a supplier in our article nationality of the supplier and CLOUD Act exposure. This section is limited to what distinguishes the three hyperscalers studied here.
AWS: European regions and the European Sovereign Cloud
AWS operates multiple regions in the European Union, including Ireland (eu-west-1), Frankfurt (eu-central-1), and Paris (eu-west-3). Each meets data latency and residency requirements, without changing the legal entity signing the contract.
In late 2023, AWS announced theEuropean Sovereign Cloud, a distinct infrastructure designed for EU-based operational governance: staff and operational decision-making located in Europe, with the first region planned in Brandenburg, Germany. The program directly responds to the requirements expressed by public customers and regulated sectors.
This operational governance does not change the shareholder structure. The European Sovereign Cloud remains an offering from Amazon Web Services, Inc., a subsidiary of Amazon.com Inc., a company incorporated under American law. The CLOUD Act exposure is linked to this link of control, independently of the claimed operational independence.
Google Cloud: sovereignty controls and local partnerships
Google Cloud offers European regions in Brussels (europe-west1), Frankfurt (europe-west3), and several other cities across the continent. Its approach to sovereignty is based less on a distinct legal entity than on technical controls applied at thedata level.
Two concrete mechanisms illustrate this approach. Client-side encryption ensures that data is encrypted before reaching Google infrastructure, without Google holding the keys. Key Access Justifications show the customer each request for access to their data, including a government request, before it is honored.
Google Cloud has also established local partnerships, such as the S3NS joint venture with Thales in France, to offer a trusted cloud offering evaluated according to national security benchmarks. The underlying infrastructure nevertheless remains operated by Google LLC, a subsidiary of Alphabet Inc., a company incorporated under American law: the same capital control link applies.
Azure: EU regions and the EU Data Boundary commitment
Microsoft Azure offers many European regions: France Central, Germany West Central, West Europe (Netherlands) and North Europe (Ireland). Choosing an Azure EU region primarily meets latency and contractual data residency requirements.
Since 2021, Microsoft has been rolling out in phases a commitment called EU Data Boundary: data processed by its main cloud services, Azure, Microsoft 365, Dynamics 365 and Power Platform, is stored and processed within the European perimeter. The stated objective is to reduce transfers outside the EU that have become superfluous, not to create a legal entity separate from Microsoft Corporation.
Microsoft also publishes a transparency report detailing the volume of government requests received and the share that the company has responded to. This transparency documents the real exposure without eliminating it: Microsoft Corporation remains a company under American law, regardless of where the data is stored.
Comparison: EU regions, sovereignty initiative, parent company
Three columns of facts, one constant: the nationality of the operating company does not change from one hyperscaler to another, regardless of the seriousness of the associated sovereignty program.
| Supplier | EU regions (examples) | Sovereignty Initiative | Nationality of parent company |
|---|---|---|---|
| AWS | Ireland (eu-west-1), Frankfurt (eu-central-1), Paris (eu-west-3) | European Sovereign Cloud: EU-based operational governance and staff, first region announced in Brandenburg (Germany) | United States (subsidiary of Amazon.com Inc.) |
| Google Cloud | Brussels (europe-west1), Frankfurt (europe-west3), Paris (europe-west9) | Sovereignty controls (client-side encryption, Key Access Justifications) and local partnerships, including the S3NS joint venture with Thales in France | United States (subsidiary of Alphabet Inc.) |
| Microsoft Azure | France Centre, Germany West Central, West Europe (Netherlands), North Europe (Ireland) | EU Data Boundary: storage and processing of data within the EU perimeter for the main cloud services, deployed in phases since 2021 | United States |
The three lines in the “nationality” column are identical. This is precisely the point that this comparison documents: a sovereignty program does not modify this column.
What these initiatives improve, and what they don’t change
These three programs improve real things: data residency, transparency of access, reduction of transfers outside the EU that are no longer necessary, and for AWS, operational governance ensured by staff based in Europe. These are measurable progress, not empty announcement effects.
None of the three, however, changes the link of shareholder control between the European subsidiary or division and its American parent company. A request addressed to the parent company, or which it can force its subsidiary to satisfy, remains, in legal theory, enforceable regardless of the operational independence displayed.
This is not a questioning of the technical quality of these initiatives. It is an observation on the legal structure of the entity that holds them. A serious sovereignty program and unchanged legal exposure can coexist perfectly.
What to check before relying on a hyperscaler sovereignty program
Four questions to ask before considering a hyperscaler sovereignty program as sufficient for a sensitive project.
- Is the contract you sign attached to the sovereignty program entity, or does it remain attached to the standard US entity of the supplier?
- Does the program cover precisely the services you use (computing, storage, managed database), or only part of the catalog?
- Does the provider publicly document its position on the CLOUD Act, not just GDPR?
- Is there a contractual clause on the processing of government requests: notification, dispute, transparency?
The other option: a parent company itself under EU jurisdiction
A structurally different approach consists of choosing a supplier whose parent company is itself incorporated under EU jurisdiction, which removes the link of control to an American company rather than regulating it.
This is the case of Aurabase SAS, a company incorporated under French law, whose verified production infrastructure operates in Germany and Finland. EU sovereignty depends on these two cumulative conditions, accommodation and the operating company, rather than just one of the two. The technical and legal details of this comparison against a comparable supplier are covered in Aurabase vs Supabase, and the complete compliance posture on the Aurabase compliance center.
FAQs
AWS, Google Cloud and Microsoft Azure have each invested in a serious response to the question of sovereignty: operational governance in the EU at AWS, access controls and local partnerships at Google Cloud, data residency commitment at Microsoft. None of the three changes the box that matters most on a contract: the nationality of the company signing it.
For a project without sensitive data, this distinction remains secondary. For a DPO, health data or an EU public contract, it deserves to be verified before signing, not after.
For the complete decision grid applied to the choice of a BaaS, see why the CLOUD Act changes the choice of your BaaS. For details of what legally differentiates a supplier according to the nationality of its parent company, see nationality of the supplier and CLOUD Act exposure.