Sovereign Cloud in Europe: a response to new regulatory requirements
Cloud · 1 min
Articles by Fábio Ribeiro
DORA, NIS2 and digital sovereignty requirements are transforming how organizations manage their data. Discover the principles of a sovereign cloud strategy.

TL;DR
- Digital sovereignty is gaining relevance in sectors subject to demanding regulatory requirements
- DORA and NIS2 reinforce attention on resilience, governance, and data location
- Customer management of encryption keys is an important component of many sovereignty strategies
- Platform choice must consider technical, legal, and operational requirements
The regulatory context
The increasing adoption of the cloud has been accompanied by a greater concern for digital sovereignty and data protection. Regulations such as DORA and [NIS2](/en/blog/nis2-os-principais-passos-para-reforcar-a-conformidade) reinforce the need for adequate management of risks associated with digital infrastructures and technology service providers. At the same time, the legislation applicable to certain international providers continues to fuel the debate about data location and access by authorities from different jurisdictions.
What characterizes a sovereign cloud approach
A [sovereign cloud](/en/solutions/sovereign-cloud) strategy seeks to ensure that data remains under adequate control of the organization, respecting applicable legal and regulatory requirements. Frequently considered elements include data location within the European Union, customer management of encryption keys, the use of hardware security modules (HSM), and the clear definition of the jurisdiction applicable to contracts and operations.
How to approach a migration
The first step consists of classifying data and identifying workloads subject to higher compliance or sensitivity requirements. From there, it is possible to define an adequate strategy, which can combine different platforms and implementation models, balancing regulatory requirements, performance, and [operational efficiency](/en/blog/gestao-de-dados-em-ambiente-multicloud-desafios-e-estrategias-para-soberania-e-e).
Sovereignty assessment in 10 days
We map which workloads should migrate — and which should not.
Related
- Sovereign Cloud
- Hybrid & Multicloud
- Confidential Computing