EU Cloud Sovereignty Law: How Europe Is Deciding Which Cloud Providers Governments Can Use

Europe wants more control over its most secret data. It wants to decide where this data is kept and who is allowed to touch it. This new EU plan is called the cloud sovereignty law. “The cloud” means keeping your data and running your apps on the internet, using other companies’ huge computers, instead of your own. Right now, a lot of Europe’s government data sits on clouds run by big US companies. The new EU rules want to change that for the most secret systems.

The plan sets clear levels. These levels measure how “sovereign” a cloud service is. Sovereign just means how free and independent it is. The plan then decides which companies governments may use for secret work. Here is how it all works, in simple words.

What “cloud sovereignty” means

Here, sovereignty means control. A sovereign cloud is one where European law fully applies. It is also one where other countries cannot easily force their way in to see the data.

The big worry is a US law called the CLOUD Act. This is a US law that can let US officials ask US companies to hand over data. It can do this even when the data is kept in other countries. So Europe wants choices where this risk is gone for its most important records.

The Cloud Sovereignty Framework and its levels

In October 2025, the European Commission shared its Cloud Sovereignty Framework. A framework is just a set of rules and tests. The European Commission is the EU’s main team that runs things, a bit like its head office. The plan sets eight sovereignty goals. These goals cover law, daily running, safety, the supply chain, and the environment. The supply chain means all the steps and parts needed to make and run something, from start to finish.

To grade providers, it uses levels called SEAL. SEAL is short for Sovereignty Effectiveness Assurance Levels. In plain words, SEAL is just a score for how independent a cloud is. The scores go from SEAL-0 up to SEAL-4.

  • SEAL-0: the provider has no sovereignty at all.
  • SEAL-2: this is “data sovereignty.” EU law applies and can be enforced. But some links to non-EU companies may still be there.
  • SEAL-4: this is the strictest score. It needs a full EU supply chain, from the chips right up to the software.

For the Commission’s own deal, SEAL-2 was the lowest score allowed to take part. The deal was set up through a tender. A tender is an official call that asks companies to bid for a contract.

Key facts

ItemAs reported
Framework publishedOctober 2025, by the European Commission
Sovereignty goalsEight objectives
Scoring levelsSEAL-0 to SEAL-4
Minimum to qualify (Commission tender)SEAL-2 (Data Sovereignty)
Sovereign cloud tenderAwarded April 2026, up to EUR 180 million over 6 years
Strictest tier impactLevels 3 and 4 need EU ownership; US hyperscalers barred at top tier

Which providers and governments are affected

The strictest rules are mainly for public bodies that handle secret data. This covers areas like banking, healthcare, and court records.

Levels 3 and 4 need EU ownership and full control over the supply chain. Non-European tech cannot do this because of the CLOUD Act. So at the most secret level, which covers key government systems, US cloud giants would be shut out completely. They would not even be allowed to bid. These US giants are often called hyperscalers. A hyperscaler is just a very large cloud company, like the biggest US providers.

In April 2026, the Commission gave out its Sovereign Cloud tender. Through this deal, EU offices and agencies can buy sovereign cloud services. They can spend up to EUR 180 million over six years.

Why it matters (especially for India and founders)

This is part of a big global trend. Many countries now want control over their own data. India has its own debates about data localisation. Data localisation means some data must be kept inside the country itself. Europe’s plan gives lawmakers a clear example to study.

For founders, there is a real chance here. Local sovereign cloud providers, data centres, and rule-checking tools could win work that once went only to global giants. If you build cloud or security products, one question is becoming very important: “Where is my data, and who can see it?”

FAQ

What is the EU cloud sovereignty law trying to do?

It wants to give Europe more control over its secret data. It grades cloud providers with scores. Then it saves the strictest government work for the most independent, EU-controlled choices.

What are SEAL levels?

SEAL stands for Sovereignty Effectiveness Assurance Levels. They score how independent a cloud service is. The scores go from SEAL-0 (no sovereignty) to SEAL-4 (a full EU supply chain).

Are US cloud companies banned?

Not everywhere. But at the strictest level (Levels 3 and 4), which covers key government systems, US hyperscalers would be shut out. They cannot meet the EU ownership rules because of the CLOUD Act.

How much money is involved in the tender?

The April 2026 Sovereign Cloud tender lets EU offices buy services for up to EUR 180 million over six years, as reported.

Takeaway

Europe is drawing a clear line. The more secret the data is, the more local control it asks for. The SEAL levels turn a fuzzy idea, “digital sovereignty,” into hard rules. These rules create real winners and losers. For the cloud industry, and for anyone watching how nations guard their data, this plan shows where the world is heading.

Source: MediaNama

Related coverage

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.