Home›Guides›Sovereignty

Sovereignty

What is a sovereign cloud?

A sovereign cloud is a service for which you can say who operates the data, which court can order its disclosure, and how you get it back. The term has no single definition in the GDPR. It is a purchasing criterion, which becomes useful the day you translate it into verifiable questions.

Updated October 20268 min readOfficial sources cited

Why the term is a problem

“Sovereign” has become a sales pitch. It appears on very different offerings: an email service installed in a Paris datacenter, an American office suite with a European data region, open source software, an infrastructure qualified by ANSSI. All of these offerings may have their merits. They do not answer the same question.

For an executive, a CIO or a DPO, the risk is ticking a box without knowing what it contains. The day a client asks where its data is, an auditor rereads the record of processing activities, or a provider changes owner, the label is of no use. Only written answers count: who operates, which law applies, how you exit.

This page explains the concept. The criteria grid for a tender is in definition, criteria and limits. The comparison between a European operator and an American software vendor is the subject of the page European cloud or American cloud.

The question behind the term

A company entrusts its emails, files and client records to a third party. It wants to know three things.

  1. Who has technical control: who can open the system, restore a backup, reset a password. These actions are routine in the life of a service. They are also access to the data: whoever can restore a mailbox can read it.
  2. Which law applies to this operator: the law of the country of the company that controls the service, not just the country of the building. A request from an authority is addressed to a company, not to a building.
  3. How to exit: formats, timeframes, and what remains with the provider after termination. Data you cannot take back is controlled only in appearance.

If the contract answers these three points, the “sovereign” label has substance. If it merely says “datacenter in Paris” or “datacenter in Frankfurt”, it describes a place. A place is useful, notably for the record of processing activities. It does not say who can be compelled to produce the data.

What buyers mean by the term

In European tenders, the term generally covers five expectations.

  • A European operator. The service operator is a European company, not controlled by a company subject to an extraterritorial law that requires it to hand over data it holds. This is the central expectation: it determines whom a foreign authority can approach.
  • A stated perimeter. The service’s data, backups and operational logs are hosted within a stated perimeter, often the European Union or the European Economic Area. Backups and logs are often forgotten. Yet they are copies.
  • Identified administrators. The people who administer the service are identified, and their access is logged. Without a trail, no one can say afterwards who opened what.
  • Documented encryption. Encryption and key custody are described. Encryption for which the provider alone holds the key protects against disk theft. It does not make the data unreadable to the operator itself.
  • Written reversibility. Export, duration, format and deletion. This is what makes it possible to reverse the choice if the provider changes owner, price or policy.

The French SecNumCloud qualification, issued by ANSSI, formalises part of these expectations for a specific offering. It qualifies neither a company as a whole, nor an application merely because it is installed on qualified infrastructure. The ANSSI catalogue is authoritative, offering by offering. For an SME, the question arises mainly when the nature of the data or a principal client requires it.

What a sovereign cloud is not

Not an immunity

It is not an immunity. A European operator remains subject to the law of its country, to local judicial requisitions, and to mutual legal assistance agreements. Sovereignty changes the legal framework. It does not eliminate every access request. What changes is the court that can order disclosure, the procedure followed and the remedies available to the operator and its client. For a European company, this is a framework its advisers know and within which it can act.

Not a synonym for open source

Nor is it a synonym for “open source”. The software tells you who wrote the program. Sovereignty tells you who holds the data and who holds the keys. Free software can be operated by a company subject to foreign law. Software from a foreign vendor can be operated by a European company that alone retains control over the data.

At Klytic, the data is held entirely by the client, or by Klytic on the client’s behalf, in a geographical area that falls under the applicable jurisdiction. It is encrypted natively, or according to the client’s choice. The key is held by the client, or kept in its account: Klytic has no access to it. To obtain it, Klytic would have to destroy or change a password it does not possess, and the client would notice.

Some stages remain encrypted by Klytic, because the service must process the content: emails quarantined by filtering, encrypted in the database, and emails and documents processed in the CRM. Emails are the only exception, when the client has enabled encryption with its own key. Access to files is also tightly restricted by limited access rights, and a connection audit raises an alert in the event of a fraudulent attempt. Details are on the page protecting a business from the CLOUD Act. The contract must describe this custody, this encryption and these safeguards.

Not functional equivalence

Finally, it is not a promise of functions equivalent to Microsoft 365 or Google Workspace. You can have a European operator and a less complete office suite. You can have a very complete office suite and an American operator. These are two separate decisions.

Treating them separately avoids two symmetrical mistakes: abandoning a tool the business depends on as a matter of principle, or dismissing the legal question because teams like the tool. The threshold specific to Microsoft 365 is detailed in Microsoft 365 versus a sovereign solution.

Example: a 25-person accounting firm

Hypothetical case. A 25-person accounting firm receives a simple question from an industrial client: “Where are our accounting records, and who can access them?” The firm uses an email service and file sharing whose brochure says “hosted in France”.

Going through the three questions, the partner discovers that the invoicing company is French, but that operations and support are provided by the subsidiary of a foreign group, and that backups are entrusted to a processor whose contract does not name the country. The brochure was not false. It did not answer the client’s question.

The firm has two reasonable options: obtain written answers from the provider and add them to the file, or choose an operator whose answers suit it. Either way, it answers its client with facts, not with an adjective.

Common mistakes

  • Confusing location and operator. “Hosted in France” describes a building. The useful question concerns the company that runs the service. The subject is developed in data hosted in Europe.
  • Forgetting the copies. Backups, logs, support tickets: these are data, sometimes hosted somewhere other than the main service.
  • Taking encryption as a guarantee of unreadability. Everything depends on who holds the key.
  • Expecting immunity. No operator offers it. A provider that promises it is misdescribing its own framework.
  • Postponing the exit question. Reversibility is negotiated at signature, not at termination.

How to check it in an hour

Ask for four documents, not a brochure.

  • The identity of the invoicing company, and of the operating company if they differ.
  • The location of content data, backups and logs.
  • The location from which support can connect, and whether this connection is logged.
  • The export and deletion procedure.

If a provider cannot supply these elements in writing, that in itself is information. Then compare the answers with what your record of processing activities says: that is where discrepancies appear.

For the legal framework governing transfers outside the European Union, see the page on the CLOUD Act and the one on data hosted in Europe. For the list of purchasing criteria, see definition, criteria and limits.

Frequently asked questions

Does the GDPR require a sovereign cloud?

No. The GDPR organises roles, transfers outside the Union and the rights of individuals. It does not define the word “sovereign” and does not require choosing a European operator. It does, however, require knowing where the data goes and on what basis, which overlaps with a large share of the questions on this page.

Is a cloud hosted in France sovereign?

Not necessarily. Location is one of the expected answers, not the only one. You also need to know which company operates the service, which law applies to it, who can access the data and how to get it back.

Should SecNumCloud be required?

When the nature of the data or a principal client requires it, yes, and the name of the offering must appear in the ANSSI catalogue. For SME email and file sharing, questions about the operator, access and reversibility are generally more decisive.

Is open source software enough?

No. Open source makes it possible to read the code and makes it easier to change hosting provider. It does not say who holds the data or who holds the keys.

Does a sovereign cloud protect against every access request?

No. A European operator remains subject to the law of its country and to requisitions from its courts. The difference lies in the court, the procedure and the remedies.

Where Klytic stands

Klytic is operated by Dedicace Software, a French company. The services are based on proven or open source solutions, and on modules and services developed by Klytic. The isolation of these services is ensured and managed by Klytic servers developed for this purpose.

Hosting is possible in any geographical area corresponding to the applicable jurisdiction, subject to the availability of the required services, for example in Europe or Mauritius, or on the client’s servers. Details are on the page hosting and sovereignty.

Klytic is not a SecNumCloud-qualified offering. Like any French operator, it remains subject to French law.

This page describes a general framework. It does not replace an analysis of your contract.

Sources

Accessed in October 2026.

  • Règlement (UE) 2016/679 (RGPD). It organises roles, transfers and the rights of individuals. It does not define the word “sovereign”. EUR-Lex
  • ANSSI, FAQ SecNumCloud: the qualification covers a specific offering, not a provider as a whole, and an application hosted on a qualified offering does not inherit the approval. cyber.gouv.fr
  • Klytic, published hosting options (Europe, Mauritius, or on the client’s premises). klytic.com

A French operator for your data

Email, documents, video conferencing, CRM and telephony, hosted in the zone that matches your jurisdiction, for example in Europe or Mauritius, or on your premises.

Talk to an advisor →

Klytic hosting

Welcome offer

30 days free trial, migration support included

No-commitment trial. An advisor calls you back to understand your needs and prepare your Klytic workspace.