Evidence / jurisdiction
Updated 14 Sep 2026

Your region is not your control boundary

A cloud region describes workload location, not who controls the service. Europe shows why legal, operational, supply-chain and technology control matter.

Your data can stay in the region you chose while control over the service sits somewhere else.

A region is a geographic placement option. It does not, by itself, determine corporate ownership, governing law, administrator access, software supply chains or whether you can keep operating without the provider.

That distinction applies everywhere. Europe is a useful case because its institutions have begun turning the abstract question of control into explicit procurement criteria.

Sovereignty entered procurement

In April 2026, the European Commission awarded a sovereign-cloud framework worth up to €180 million over six years. It evaluates strategic, legal, operational, supply-chain, technology, security, environmental and data sovereignty—not just server location.

Read the Commission announcement →

Policy became migration

France plans to replace extra-European videoconferencing across state services with Visio by 2027. Schleswig-Holstein reported LibreOffice across almost 80% of workplaces outside its tax administration by December 2025. Denmark’s Ministry of Digital Affairs began a smaller Collabora pilot.

The boundary

This is not a coordinated EU exit from public cloud. It is a move toward European providers, open source, private and hybrid systems, portability and jurisdictional control.

The point: Europe has started treating foreign-controlled technology dependencies as operational and geopolitical risks.