# Cloud Sovereignty in Germany

Cloud sovereignty is no longer a buzzword. It has reached boardrooms and executive teams because the risks are now very real legally, technically, and operationally.

This article is written for tech leads, CTOs, CIOs, and CEOs who are responsible for cloud decisions and accountable when things go wrong.

We will cover:

* what cloud sovereignty really means
    
* why “EU region” is often misleading
    
* which **realistic cloud options exist in Germany**
    
* where projects regularly fail, based on real-world experience
    

No marketing. No sugarcoating.

---

## What Cloud Sovereignty Is *Not*

Before talking about solutions, let’s clear up a few assumptions that cause problems in real projects:

* ❌ “Our data is stored in Frankfurt, so we’re sovereign”
    
* ❌ “The provider is GDPR compliant, that’s enough”
    
* ❌ “Sovereign cloud is just a feature”
    
* ❌ “This is purely an infrastructure topic”
    

**Cloud sovereignty is not about location.**  
It is about control and control does not stop at hardware.

---

## A Practical Definition

For day-to-day decision-making, this definition works well:

> Cloud sovereignty means that an organization retains **actual control** over  
> data, workloads, access, encryption keys, and operational processes  
> even with respect to the cloud provider and foreign jurisdictions.

The key word is *actual*.  
Not “contractually promised”. Not “theoretically possible”.

---

## Why This Matters So Much in Germany

### 1\. Regulation Is Not Optional

GDPR, KRITIS, BAIT, DORA, and industry-specific regulations leave little room for interpretation especially when it comes to access and responsibility.

### 2\. US Hyperscalers Dominate

AWS, Azure, and Google Cloud are technically strong.  
But they are subject to US law including the CLOUD Act.

### 3\. Critical Industries Are Under Pressure

Energy, manufacturing, finance, healthcare, public sector.  
This is not about convenience; it’s about liability and operational resilience.

### 4\. Dependencies Are Now Visible

Software stacks, platforms, updates, support.  
Vendor dependency is no longer theoretical.

---

## The CLOUD Act – Uncomfortable but Relevant

US companies can be legally compelled to provide access to data **even if that data is stored in Europe**.

Important points:

* This is not about constant surveillance
    
* It is about **legal access possibilities**
    
* And the lack of control customers have over them
    

For many organizations, this risk alone is reason enough to look for alternatives.

---

## Common Pitfalls from Real Projects

### 1\. Sovereignty Is Deferred

“We’ll move fast first and fix it later.”

Once architecture, CI/CD, IAM, and operations are built around a hyperscaler, switching becomes expensive and painful.

**Result:**  
Vendor lock-in without an exit strategy.

---

### 2\. Key Management Exists Only on Paper

Customer-managed keys do not help if:

* the KMS runs at the provider
    
* root access is not under customer control
    
* the provider decides in an emergency
    

**No control over keys means no real sovereignty.**

---

### 3\. Legal, Security, and IT Work in Silos

Contracts, policies, and architecture don’t align.

**Outcome:**  
Workarounds, delays, and finger-pointing.

---

### 4\. “German” or “European” Is Not Questioned

Even with local providers, teams often fail to ask:

* who actually operates the platform?
    
* who has admin access?
    
* what dependencies exist in the stack?
    

Not every provider likes answering these questions.

---

## Cloud Options in Germany – A Realistic View

---

## 1\. Hyperscalers (Limited Sovereignty)

**Examples:** AWS, Microsoft Azure, Google Cloud

**Strengths**

* Massive scale
    
* Mature managed services
    
* Large ecosystems
    

**Weaknesses**

* US jurisdiction
    
* Complex contracts
    
* Limited control over operations and access
    

**Reality**  
Fine for many workloads.  
Problematic for sensitive or regulated data.

---

## 2\. Sovereign Cloud Models by Hyperscalers

**Examples**

* Delos Cloud (Microsoft, Germany)
    
* AWS European Sovereign Cloud
    

**Pros**

* Operated by European entities
    
* Stronger isolation
    

**Cons**

* Not broadly available yet
    
* Technical details still unclear
    
* Dependency remains
    

---

## 3\. German and European Cloud Providers

This is where cloud sovereignty becomes practically achievable with clear trade-offs.

The providers mentioned below are **examples**, not an exhaustive list.  
The German and European cloud market is broader and continues to evolve. Availability, maturity, and suitability depend heavily on use case, industry, and regulatory context.

What these providers generally have in common is a stronger focus on data residency, legal clarity, and operational control often at the cost of convenience and breadth of managed services.

---

## STACKIT – A Closer Look

STACKIT is the cloud platform of the Schwarz Group and is often underestimated.

**Strengths**

* Fully operated in Germany
    
* German legal entity and jurisdiction
    
* Clear separation between provider and customer
    
* Strong Kubernetes and platform foundations
    
* No US parent company, no legal grey areas
    

**Honest Take**

* Less convenience than hyperscalers
    
* Fewer managed services
    
* Requires a platform mindset
    

**In Practice**  
A strong option for organizations that want real control and are willing to take responsibility.

---

## IONOS – A Closer Look

IONOS is one of the best-known German providers and has long experience in the enterprise space.

**Strengths**

* German company with strong EU focus
    
* Data centers in Germany
    
* Broad infrastructure portfolio
    
* Solid foundation for traditional and modern workloads
    

**Honest Take**

* Fewer cloud-native services
    
* Developer experience is functional, not elegant
    
* Platform services are not deeply integrated
    

**In Practice**  
Works well for organizations that:

* need stable infrastructure
    
* require clear data residency
    
* treat cloud more as controlled infrastructure than an innovation platform
    

---

## plusserver – A Closer Look

plusserver comes from the hosting and managed services world and is deeply rooted in the German mid-market.

**Strengths**

* German operator under German law
    
* Strong customer proximity
    
* Mature managed services capabilities
    
* Well-suited for hybrid scenarios
    

**Honest Take**

* Less self-service
    
* Less platform standardization
    
* Scaling is not hyperscaler-like
    

**In Practice**  
Ideal for organizations that:

* want to deliberately outsource operations
    
* value clear points of contact
    
* do not want to run everything themselves
    

---

## The Shared Reality of German Providers

**Advantages**

* Clear legal framework
    
* Full data residency
    
* Strong auditability
    
* Lower geopolitical risk
    

**Trade-offs**

* More customer responsibility
    
* Less convenience
    
* Less plug-and-play
    

That’s not a flaw it’s the cost of control.

---

## 4\. Private Cloud and On-Prem with Cloud Principles

**Technologies**

* Kubernetes on-prem
    
* OpenStack
    
* VMware (with limitations)
    

**Strengths**

* Maximum control
    
* No external dependencies
    

**Weaknesses**

* High operational effort
    
* Scarce skilled staff
    
* Costs often underestimated
    

**Reality**  
Only works if operations are treated as a core competency.

---

## The Uncomfortable Truth

Cloud sovereignty almost always means:

* less convenience
    
* more responsibility
    
* higher costs in the right places
    

Anyone expecting sovereign cloud to feel like AWS, but cheaper, will fail.

---

## Which Option Fits Which Organization?

Short and honest:

* **Startups / lightly regulated products**  
    Hyperscalers, consciously accepted risk
    
* **Mid-sized companies with sensitive data**  
    German providers like STACKIT, IONOS, plusserver with clean architecture
    
* **KRITIS and highly regulated sectors**  
    Private cloud or strictly controlled German platforms
    

---

## A Personal View: Why Germany Needs to Rethink Cloud Sovereignty

This is my personal opinion, based on what I’ve seen in projects over the last years.

Germany needs to rethink how it approaches cloud infrastructure and digital sovereignty.  
For too long, the topic has been treated as a niche concern something for regulators, security teams, or public sector organizations. That view no longer holds.

Cloud sovereignty affects **everyone**: startups, mid-sized companies, large enterprises, critical infrastructure, and public institutions. Whether you build software, operate platforms, or rely on digital services you are part of the dependency chain.

What’s missing is a broader sense of ownership.  
Not everything can or should be outsourced. Not every strategic dependency can be ignored because it’s convenient or cost-efficient in the short term.

This requires a mindset shift:

* from speed-only decisions to risk-aware decisions
    
* from convenience to conscious trade-offs
    
* from “someone else will handle it” to shared responsibility
    

Cloud sovereignty deserves the same level of attention and seriousness that AI topics receive today. Not because it is more exciting, but because it quietly defines who controls the foundations our digital systems run on.

Ignoring it does not remove the risk. It just postpones the consequences.

---

## **What’s your take on cloud sovereignty?**

Are you running workloads on hyperscalers, German providers, or a hybrid setup?  
I’m curious what worked for you — and what didn’t. Share your experience in the comments.
