AWS and European Digital Sovereignty
Last reviewed: 3 February 2026
Sovereignty Verdict
Tool
AWS
Sovereignty Score
Risk Level
AWS is subject to US jurisdiction and CLOUD Act obligations; EU region deployment addresses data residency but does not eliminate extraterritorial access risk.
Amazon Web Services dominates cloud infrastructure globally, including in Europe. For organisations with sovereignty concerns, understanding what AWS's European offerings actually provide—and what they don't—is essential for informed architecture decisions.
AWS markets data residency and compliance features extensively. This analysis examines those offerings against actual sovereignty requirements, distinguishing marketing from substance.
As with all vendor assessments, AWS's offerings, policies, and terms change over time. Verify current information against AWS documentation.
AWS Corporate Structure and Jurisdiction
The fundamental legal position:
**Corporate structure**: Amazon Web Services, Inc. is a subsidiary of Amazon.com, Inc., a US corporation headquartered in Seattle, Washington.
**Legal jurisdiction**: As a US company, AWS is subject to US law, including the CLOUD Act. US authorities can compel AWS to provide data regardless of where that data is physically stored.
**EU operations**: AWS has extensive European operations, including multiple data centre regions (Ireland, Frankfurt, Stockholm, Paris, Milan, London, etc.) and thousands of employees. This presence does not change the jurisdictional position.
**AWS European Sovereign Cloud**: AWS has announced a "European Sovereign Cloud" offering, designed for highly regulated workloads. This introduces operational separation but does not change the fundamental parent company jurisdiction. Details of this offering are still emerging.
The key point: using AWS EU regions keeps your data in Europe physically, but does not remove it from US legal reach through AWS.
What EU Region Deployment Actually Provides
Understanding the scope of data residency:
**Physical location**: Data stored in EU regions resides in data centres physically located in EU member states. This addresses data residency requirements that specify physical location.
**Regional isolation**: Resources deployed in EU regions don't automatically replicate to non-EU regions. You control where data goes through your architecture choices.
**Latency and availability**: EU deployment provides regional latency benefits and availability within European time zones.
**Some regulatory alignment**: Physical EU presence can help satisfy some regulatory requirements that specify EU location.
**What it does NOT provide**: - Protection from US government access requests (CLOUD Act applies) - Guarantee that no data touches US infrastructure ever (some global services may have US components) - Protection from AWS operational access (engineers globally may access systems for support) - Immunity from AWS terms of service changes
Data residency is one component of sovereignty, but it's not sufficient on its own for organisations with significant jurisdiction concerns.
AWS Compliance and Security Features
AWS offers extensive compliance tooling:
**Encryption options**: AWS provides encryption at rest and in transit. AWS Key Management Service (KMS) offers customer-managed keys (CMK), though AWS still has access to the KMS infrastructure. AWS CloudHSM provides hardware security modules that offer stronger key isolation.
**Access controls**: IAM provides granular access controls. AWS Organizations and Service Control Policies enable governance at scale.
**Audit and monitoring**: CloudTrail provides API activity logging. AWS Artifact provides access to compliance reports.
**Compliance certifications**: AWS holds extensive certifications (ISO 27001, SOC 2, etc.) and compliance attestations for various regulatory frameworks.
**GDPR tooling**: AWS provides Data Processing Addendum, sub-processor lists, and various features to support GDPR compliance.
These features are genuine and useful, but they address security and compliance—not the fundamental jurisdiction question. You can be well-protected against threats AND still exposed to lawful access requests from US authorities.
Sovereignty Risk Assessment
Evaluating AWS through sovereignty dimensions:
**Legal jurisdiction**: High concern. US-headquartered, CLOUD Act applies. European Sovereign Cloud may address some scenarios but parent company jurisdiction remains.
**Data residency**: Low concern (if EU regions used). Straightforward to ensure data remains in EU.
**Operational control**: Moderate concern. Customer has extensive control over resources, but AWS operational access exists for maintenance and support.
**Encryption**: Moderate concern. Customer-managed keys available but AWS infrastructure access remains. CloudHSM provides stronger isolation for sensitive keys.
**Data portability**: Low concern. Standard formats, open-source compatible. Migration is operationally complex but not technically constrained.
**Transparency**: Moderate. AWS publishes information request reports but with limited granularity.
**Overall**: For many workloads, AWS provides adequate practical protection. For highly sensitive workloads with genuine jurisdiction concerns, the fundamental US parent company issue remains unresolved.
European Cloud Alternatives
For organisations requiring European jurisdiction:
**OVHcloud**: French cloud provider, EU-headquartered. Strong in compute and bare-metal. Growing Kubernetes and PaaS offerings. Trade-off: Smaller service catalog than AWS.
**Scaleway**: French provider with developer-friendly approach. Competitive pricing. Trade-off: More limited global presence and enterprise features.
**Hetzner**: German provider known for value. Strong in dedicated servers and cloud compute. Trade-off: Fewer managed services.
**IONOS**: German provider (1&1 group) with enterprise positioning. Broad service offerings. Trade-off: Less developer-centric than hyperscalers.
**Exoscale**: Swiss provider with compliance focus. Clean API design. Trade-off: Smaller scale and service catalog.
**Sovereign cloud partnerships**: Some European providers partner with hyperscalers (e.g., T-Systems with Google, Orange with Microsoft). These offer local operational control with hyperscaler technology but introduce complexity.
None of these alternatives fully match AWS's service breadth and depth. The trade-off is capability versus jurisdiction. For many specific workloads, European alternatives are fully adequate.
Practical Recommendations
Context-dependent guidance:
**For most commercial workloads**: AWS EU regions with appropriate security controls may be acceptable. The practical risk of US government access to routine business data is often manageable.
**For regulated sectors**: Evaluate specific requirements. Healthcare, financial services, and public sector may have explicit guidance that affects AWS suitability.
**For highly sensitive data**: Consider European alternatives for the most sensitive workloads. Hybrid approaches—using AWS for general infrastructure while placing sensitive data with EU providers—are practical.
**Encryption is not a complete solution**: While client-side encryption before data reaches AWS provides protection, it may limit functionality. AWS KMS doesn't fully resolve the issue since AWS manages the infrastructure.
**Monitor developments**: AWS European Sovereign Cloud and evolving EU regulations may change the calculus over time.
**Document decisions**: If using AWS despite sovereignty concerns, document the risk assessment and acceptance. This supports compliance and future review.
The appropriate choice depends on specific requirements, risk tolerance, and practical constraints. AWS remains a powerful option for many use cases; the question is whether it's appropriate for yours.
Key Takeaways for Technical Leaders
- •AWS is US-headquartered and subject to CLOUD Act regardless of EU region deployment
- •EU regions provide physical data residency but not protection from US legal jurisdiction
- •AWS offers extensive compliance and security features, but these don't address the jurisdiction question
- •European cloud alternatives exist with varying trade-offs in capability versus jurisdiction
- •Hybrid approaches using EU providers for sensitive data alongside AWS for general workloads are practical
Sovereignty Report Available
Quick-reference report with FAQ, topic cluster links, and structured data.
Sovereignty Comparison Available
See how European alternatives compare in a structured sovereignty audit.
Migration Blueprints
Considering a move? See Migration Blueprints
Audit your technology stack
This analysis covers one tool. Your Technology Stack Audit scores your entire technology stack as one system and gives you a prioritised, fix-first roadmap. One-off €99.
Audit my technology stack — €99