Cloud Sovereignty in Germany
Reality, Options, and Uncomfortable Truths

Search for a command to run...
Reality, Options, and Uncomfortable Truths

No comments yet. Be the first to comment.
What nobody draws Most organizations have architecture diagrams. They show services, databases, APIs, infrastructure. What they rarely show is how teams relate to each other, who depends on whom, wher

The decision nobody documents Most architecture diagrams show services. What they don't show: where one team's responsibility ends and another's begins. That boundary is where most long-term architect

The first workshop The first time I facilitated a Domain Driven Design workshop, we filled three whiteboards with context boundaries in two hours. Six months later, half of those boundaries had been r
Not Just Because of GDPR

Cloud sovereignty is no longer a buzzword. It has reached boardrooms and executive teams because the risks are now very real legally, technically, and operationally.
This article is written for tech leads, CTOs, CIOs, and CEOs who are responsible for cloud decisions and accountable when things go wrong.
We will cover:
what cloud sovereignty really means
why “EU region” is often misleading
which realistic cloud options exist in Germany
where projects regularly fail, based on real-world experience
No marketing. No sugarcoating.
Before talking about solutions, let’s clear up a few assumptions that cause problems in real projects:
❌ “Our data is stored in Frankfurt, so we’re sovereign”
❌ “The provider is GDPR compliant, that’s enough”
❌ “Sovereign cloud is just a feature”
❌ “This is purely an infrastructure topic”
Cloud sovereignty is not about location.
It is about control and control does not stop at hardware.
For day-to-day decision-making, this definition works well:
Cloud sovereignty means that an organization retains actual control over
data, workloads, access, encryption keys, and operational processes
even with respect to the cloud provider and foreign jurisdictions.
The key word is actual.
Not “contractually promised”. Not “theoretically possible”.
GDPR, KRITIS, BAIT, DORA, and industry-specific regulations leave little room for interpretation especially when it comes to access and responsibility.
AWS, Azure, and Google Cloud are technically strong.
But they are subject to US law including the CLOUD Act.
Energy, manufacturing, finance, healthcare, public sector.
This is not about convenience; it’s about liability and operational resilience.
Software stacks, platforms, updates, support.
Vendor dependency is no longer theoretical.
US companies can be legally compelled to provide access to data even if that data is stored in Europe.
Important points:
This is not about constant surveillance
It is about legal access possibilities
And the lack of control customers have over them
For many organizations, this risk alone is reason enough to look for alternatives.
“We’ll move fast first and fix it later.”
Once architecture, CI/CD, IAM, and operations are built around a hyperscaler, switching becomes expensive and painful.
Result:
Vendor lock-in without an exit strategy.
Customer-managed keys do not help if:
the KMS runs at the provider
root access is not under customer control
the provider decides in an emergency
No control over keys means no real sovereignty.
Contracts, policies, and architecture don’t align.
Outcome:
Workarounds, delays, and finger-pointing.
Even with local providers, teams often fail to ask:
who actually operates the platform?
who has admin access?
what dependencies exist in the stack?
Not every provider likes answering these questions.
Examples: AWS, Microsoft Azure, Google Cloud
Strengths
Massive scale
Mature managed services
Large ecosystems
Weaknesses
US jurisdiction
Complex contracts
Limited control over operations and access
Reality
Fine for many workloads.
Problematic for sensitive or regulated data.
Examples
Delos Cloud (Microsoft, Germany)
AWS European Sovereign Cloud
Pros
Operated by European entities
Stronger isolation
Cons
Not broadly available yet
Technical details still unclear
Dependency remains
This is where cloud sovereignty becomes practically achievable with clear trade-offs.
The providers mentioned below are examples, not an exhaustive list.
The German and European cloud market is broader and continues to evolve. Availability, maturity, and suitability depend heavily on use case, industry, and regulatory context.
What these providers generally have in common is a stronger focus on data residency, legal clarity, and operational control often at the cost of convenience and breadth of managed services.
STACKIT is the cloud platform of the Schwarz Group and is often underestimated.
Strengths
Fully operated in Germany
German legal entity and jurisdiction
Clear separation between provider and customer
Strong Kubernetes and platform foundations
No US parent company, no legal grey areas
Honest Take
Less convenience than hyperscalers
Fewer managed services
Requires a platform mindset
In Practice
A strong option for organizations that want real control and are willing to take responsibility.
IONOS is one of the best-known German providers and has long experience in the enterprise space.
Strengths
German company with strong EU focus
Data centers in Germany
Broad infrastructure portfolio
Solid foundation for traditional and modern workloads
Honest Take
Fewer cloud-native services
Developer experience is functional, not elegant
Platform services are not deeply integrated
In Practice
Works well for organizations that:
need stable infrastructure
require clear data residency
treat cloud more as controlled infrastructure than an innovation platform
plusserver comes from the hosting and managed services world and is deeply rooted in the German mid-market.
Strengths
German operator under German law
Strong customer proximity
Mature managed services capabilities
Well-suited for hybrid scenarios
Honest Take
Less self-service
Less platform standardization
Scaling is not hyperscaler-like
In Practice
Ideal for organizations that:
want to deliberately outsource operations
value clear points of contact
do not want to run everything themselves
Advantages
Clear legal framework
Full data residency
Strong auditability
Lower geopolitical risk
Trade-offs
More customer responsibility
Less convenience
Less plug-and-play
That’s not a flaw it’s the cost of control.
Technologies
Kubernetes on-prem
OpenStack
VMware (with limitations)
Strengths
Maximum control
No external dependencies
Weaknesses
High operational effort
Scarce skilled staff
Costs often underestimated
Reality
Only works if operations are treated as a core competency.
Cloud sovereignty almost always means:
less convenience
more responsibility
higher costs in the right places
Anyone expecting sovereign cloud to feel like AWS, but cheaper, will fail.
Short and honest:
Startups / lightly regulated products
Hyperscalers, consciously accepted risk
Mid-sized companies with sensitive data
German providers like STACKIT, IONOS, plusserver with clean architecture
KRITIS and highly regulated sectors
Private cloud or strictly controlled German platforms
This is my personal opinion, based on what I’ve seen in projects over the last years.
Germany needs to rethink how it approaches cloud infrastructure and digital sovereignty.
For too long, the topic has been treated as a niche concern something for regulators, security teams, or public sector organizations. That view no longer holds.
Cloud sovereignty affects everyone: startups, mid-sized companies, large enterprises, critical infrastructure, and public institutions. Whether you build software, operate platforms, or rely on digital services you are part of the dependency chain.
What’s missing is a broader sense of ownership.
Not everything can or should be outsourced. Not every strategic dependency can be ignored because it’s convenient or cost-efficient in the short term.
This requires a mindset shift:
from speed-only decisions to risk-aware decisions
from convenience to conscious trade-offs
from “someone else will handle it” to shared responsibility
Cloud sovereignty deserves the same level of attention and seriousness that AI topics receive today. Not because it is more exciting, but because it quietly defines who controls the foundations our digital systems run on.
Ignoring it does not remove the risk. It just postpones the consequences.
Are you running workloads on hyperscalers, German providers, or a hybrid setup?
I’m curious what worked for you — and what didn’t. Share your experience in the comments.