Skip to main content

Command Palette

Search for a command to run...

Cloud Sovereignty in Germany

Reality, Options, and Uncomfortable Truths

Published
7 min readView as Markdown
Cloud Sovereignty in Germany
C
Lead Architect | Trusted Advisor | Engagement Manager | Digital Strategy | Cloud Transformation | 30+ years Tech & Cloud | Ex-Military Leader | Ex-Head of IT Systems

Cloud sovereignty is no longer a buzzword. It has reached boardrooms and executive teams because the risks are now very real legally, technically, and operationally.

This article is written for tech leads, CTOs, CIOs, and CEOs who are responsible for cloud decisions and accountable when things go wrong.

We will cover:

  • what cloud sovereignty really means

  • why “EU region” is often misleading

  • which realistic cloud options exist in Germany

  • where projects regularly fail, based on real-world experience

No marketing. No sugarcoating.


What Cloud Sovereignty Is Not

Before talking about solutions, let’s clear up a few assumptions that cause problems in real projects:

  • ❌ “Our data is stored in Frankfurt, so we’re sovereign”

  • ❌ “The provider is GDPR compliant, that’s enough”

  • ❌ “Sovereign cloud is just a feature”

  • ❌ “This is purely an infrastructure topic”

Cloud sovereignty is not about location.
It is about control and control does not stop at hardware.


A Practical Definition

For day-to-day decision-making, this definition works well:

Cloud sovereignty means that an organization retains actual control over
data, workloads, access, encryption keys, and operational processes
even with respect to the cloud provider and foreign jurisdictions.

The key word is actual.
Not “contractually promised”. Not “theoretically possible”.


Why This Matters So Much in Germany

1. Regulation Is Not Optional

GDPR, KRITIS, BAIT, DORA, and industry-specific regulations leave little room for interpretation especially when it comes to access and responsibility.

2. US Hyperscalers Dominate

AWS, Azure, and Google Cloud are technically strong.
But they are subject to US law including the CLOUD Act.

3. Critical Industries Are Under Pressure

Energy, manufacturing, finance, healthcare, public sector.
This is not about convenience; it’s about liability and operational resilience.

4. Dependencies Are Now Visible

Software stacks, platforms, updates, support.
Vendor dependency is no longer theoretical.


The CLOUD Act – Uncomfortable but Relevant

US companies can be legally compelled to provide access to data even if that data is stored in Europe.

Important points:

  • This is not about constant surveillance

  • It is about legal access possibilities

  • And the lack of control customers have over them

For many organizations, this risk alone is reason enough to look for alternatives.


Common Pitfalls from Real Projects

1. Sovereignty Is Deferred

“We’ll move fast first and fix it later.”

Once architecture, CI/CD, IAM, and operations are built around a hyperscaler, switching becomes expensive and painful.

Result:
Vendor lock-in without an exit strategy.


2. Key Management Exists Only on Paper

Customer-managed keys do not help if:

  • the KMS runs at the provider

  • root access is not under customer control

  • the provider decides in an emergency

No control over keys means no real sovereignty.


Contracts, policies, and architecture don’t align.

Outcome:
Workarounds, delays, and finger-pointing.


4. “German” or “European” Is Not Questioned

Even with local providers, teams often fail to ask:

  • who actually operates the platform?

  • who has admin access?

  • what dependencies exist in the stack?

Not every provider likes answering these questions.


Cloud Options in Germany – A Realistic View


1. Hyperscalers (Limited Sovereignty)

Examples: AWS, Microsoft Azure, Google Cloud

Strengths

  • Massive scale

  • Mature managed services

  • Large ecosystems

Weaknesses

  • US jurisdiction

  • Complex contracts

  • Limited control over operations and access

Reality
Fine for many workloads.
Problematic for sensitive or regulated data.


2. Sovereign Cloud Models by Hyperscalers

Examples

  • Delos Cloud (Microsoft, Germany)

  • AWS European Sovereign Cloud

Pros

  • Operated by European entities

  • Stronger isolation

Cons

  • Not broadly available yet

  • Technical details still unclear

  • Dependency remains


3. German and European Cloud Providers

This is where cloud sovereignty becomes practically achievable with clear trade-offs.

The providers mentioned below are examples, not an exhaustive list.
The German and European cloud market is broader and continues to evolve. Availability, maturity, and suitability depend heavily on use case, industry, and regulatory context.

What these providers generally have in common is a stronger focus on data residency, legal clarity, and operational control often at the cost of convenience and breadth of managed services.


STACKIT – A Closer Look

STACKIT is the cloud platform of the Schwarz Group and is often underestimated.

Strengths

  • Fully operated in Germany

  • German legal entity and jurisdiction

  • Clear separation between provider and customer

  • Strong Kubernetes and platform foundations

  • No US parent company, no legal grey areas

Honest Take

  • Less convenience than hyperscalers

  • Fewer managed services

  • Requires a platform mindset

In Practice
A strong option for organizations that want real control and are willing to take responsibility.


IONOS – A Closer Look

IONOS is one of the best-known German providers and has long experience in the enterprise space.

Strengths

  • German company with strong EU focus

  • Data centers in Germany

  • Broad infrastructure portfolio

  • Solid foundation for traditional and modern workloads

Honest Take

  • Fewer cloud-native services

  • Developer experience is functional, not elegant

  • Platform services are not deeply integrated

In Practice
Works well for organizations that:

  • need stable infrastructure

  • require clear data residency

  • treat cloud more as controlled infrastructure than an innovation platform


plusserver – A Closer Look

plusserver comes from the hosting and managed services world and is deeply rooted in the German mid-market.

Strengths

  • German operator under German law

  • Strong customer proximity

  • Mature managed services capabilities

  • Well-suited for hybrid scenarios

Honest Take

  • Less self-service

  • Less platform standardization

  • Scaling is not hyperscaler-like

In Practice
Ideal for organizations that:

  • want to deliberately outsource operations

  • value clear points of contact

  • do not want to run everything themselves


The Shared Reality of German Providers

Advantages

  • Clear legal framework

  • Full data residency

  • Strong auditability

  • Lower geopolitical risk

Trade-offs

  • More customer responsibility

  • Less convenience

  • Less plug-and-play

That’s not a flaw it’s the cost of control.


4. Private Cloud and On-Prem with Cloud Principles

Technologies

  • Kubernetes on-prem

  • OpenStack

  • VMware (with limitations)

Strengths

  • Maximum control

  • No external dependencies

Weaknesses

  • High operational effort

  • Scarce skilled staff

  • Costs often underestimated

Reality
Only works if operations are treated as a core competency.


The Uncomfortable Truth

Cloud sovereignty almost always means:

  • less convenience

  • more responsibility

  • higher costs in the right places

Anyone expecting sovereign cloud to feel like AWS, but cheaper, will fail.


Which Option Fits Which Organization?

Short and honest:

  • Startups / lightly regulated products
    Hyperscalers, consciously accepted risk

  • Mid-sized companies with sensitive data
    German providers like STACKIT, IONOS, plusserver with clean architecture

  • KRITIS and highly regulated sectors
    Private cloud or strictly controlled German platforms


A Personal View: Why Germany Needs to Rethink Cloud Sovereignty

This is my personal opinion, based on what I’ve seen in projects over the last years.

Germany needs to rethink how it approaches cloud infrastructure and digital sovereignty.
For too long, the topic has been treated as a niche concern something for regulators, security teams, or public sector organizations. That view no longer holds.

Cloud sovereignty affects everyone: startups, mid-sized companies, large enterprises, critical infrastructure, and public institutions. Whether you build software, operate platforms, or rely on digital services you are part of the dependency chain.

What’s missing is a broader sense of ownership.
Not everything can or should be outsourced. Not every strategic dependency can be ignored because it’s convenient or cost-efficient in the short term.

This requires a mindset shift:

  • from speed-only decisions to risk-aware decisions

  • from convenience to conscious trade-offs

  • from “someone else will handle it” to shared responsibility

Cloud sovereignty deserves the same level of attention and seriousness that AI topics receive today. Not because it is more exciting, but because it quietly defines who controls the foundations our digital systems run on.

Ignoring it does not remove the risk. It just postpones the consequences.


What’s your take on cloud sovereignty?

Are you running workloads on hyperscalers, German providers, or a hybrid setup?
I’m curious what worked for you — and what didn’t. Share your experience in the comments.