Sovereign Cloud in Europe: a response to new regulatory requirements

Cloud · 1 min

Articles by Fábio Ribeiro

DORA, NIS2 and digital sovereignty requirements are transforming how organizations manage their data. Discover the principles of a sovereign cloud strategy.

Sovereign Cloud in Europe: a response to new regulatory requirements

TL;DR

The regulatory context

The increasing adoption of the cloud has been accompanied by a greater concern for digital sovereignty and data protection. Regulations such as DORA and [NIS2](/en/blog/nis2-os-principais-passos-para-reforcar-a-conformidade) reinforce the need for adequate management of risks associated with digital infrastructures and technology service providers. At the same time, the legislation applicable to certain international providers continues to fuel the debate about data location and access by authorities from different jurisdictions.

What characterizes a sovereign cloud approach

A [sovereign cloud](/en/solutions/sovereign-cloud) strategy seeks to ensure that data remains under adequate control of the organization, respecting applicable legal and regulatory requirements. Frequently considered elements include data location within the European Union, customer management of encryption keys, the use of hardware security modules (HSM), and the clear definition of the jurisdiction applicable to contracts and operations.

How to approach a migration

The first step consists of classifying data and identifying workloads subject to higher compliance or sensitivity requirements. From there, it is possible to define an adequate strategy, which can combine different platforms and implementation models, balancing regulatory requirements, performance, and [operational efficiency](/en/blog/gestao-de-dados-em-ambiente-multicloud-desafios-e-estrategias-para-soberania-e-e).

Sovereignty assessment in 10 days

We map which workloads should migrate — and which should not.

Related

References

  1. European Commission — Cloud Sovereignty Framework v1.2.1 (Out 2025, PDF)
  2. DORA — Regulation (EU) 2022/2554 (EUR-Lex)
  3. US Department of Justice — CLOUD Act White Paper (Apr 2019)
  4. ENISA — Candidate EUCS Scheme v1.0 (Cloud Services)