The EU’s proposed cloud sovereignty law could determine which providers governments can use
The law mandates that EU governments assess their cloud providers for sovereignty risks and switch within 12 months if needed. A 2026 deadline is set, with non-EU hyperscalers dominating 70% of the European market.
The European Union is pushing for a cloud sovereignty law that would require governments to evaluate their cloud service providers for potential risks to data sovereignty. If any risks are identified, governments would be mandated to switch providers within 12 months. This initiative aims to ensure that EU governments are not overly reliant on non-EU cloud providers, which currently control a significant portion of the market.
The urgency behind the proposal is clear: the share of EU-based cloud providers in the European market has declined sharply, from 29% in 2017 to 15% in 2022, with no significant recovery since. This decline has led to a situation where three non-EU hyperscalers now control over 70% of the European cloud market. The European Commission is seeking to address this imbalance by introducing stricter regulations that would compel governments to reassess their cloud provider choices.
A key number associated with this initiative is 223, which refers to a specific incident involving a Google Cloud outage in Delhi following a fire at one of its facilities. This event raised questions about the digital resilience of cloud infrastructure in India and highlighted the potential risks of relying on non-EU providers. The incident underscores the need for governments to consider not only the geopolitical implications but also the physical and operational reliability of their cloud providers.
In India, the proposed EU cloud sovereignty law could have significant implications for both local and international cloud providers. The incident in Delhi, which involved a Google Cloud outage, has already sparked discussions about the reliability of cloud infrastructure in the region. Indian regulators and builders may need to reassess their reliance on non-EU providers, particularly in light of the EU’s push for greater sovereignty and control over data. This could lead to increased scrutiny of cloud providers operating in India and potentially influence future regulatory frameworks.
The proposed law represents a significant shift in how governments approach cloud services, emphasizing sovereignty and control over data. As the EU moves forward with its 2026 deadline, the impact on global cloud providers and the broader digital ecosystem will be closely watched. The law could set a precedent for other regions to follow, potentially reshaping the landscape of cloud computing on a global scale.