GitHub Sovereignty & Compliance Audit (EU, 2026)
Last reviewed: 6 February 2026
Sovereignty Verdict
Tool
GitHub
Sovereignty Score
Risk Level
GitHub is a US subsidiary of Microsoft and subject to CLOUD Act; source code and repository data are exposed to US jurisdictional risk.
GitHub is the dominant platform for source code hosting, collaboration, and CI/CD workflows globally. For European organisations, GitHub's position raises distinct sovereignty questions: source code represents core intellectual property, and its exposure to foreign jurisdiction carries strategic implications beyond personal data protection.
This audit examines GitHub through a European sovereignty lens, covering jurisdictional status, regulatory alignment, operational risk, and available alternatives. The assessment is indicative and continuously reviewed.
GitHub's acquisition by Microsoft in 2018 placed it squarely within US corporate jurisdiction, compounding existing sovereignty considerations with Microsoft's broader legal obligations.
Regulatory Exposure Analysis
GitHub, Inc. is a wholly-owned subsidiary of Microsoft Corporation, incorporated in the United States.
**GDPR**: GitHub provides a Data Protection Agreement and processes data in accordance with GDPR requirements. GitHub offers EU data residency for Enterprise accounts. However, GDPR primarily governs personal data—source code, while potentially containing personal data, is more commonly proprietary intellectual property, which falls outside GDPR's direct scope but within sovereignty concerns.
**CLOUD Act / Extraterritorial Access**: As a Microsoft subsidiary, GitHub is subject to the CLOUD Act. US authorities can compel GitHub to produce repository contents, metadata, access logs, and collaboration data regardless of storage location. For organisations whose source code represents strategic IP, this is a material concern.
**NIS2**: Organisations classified as essential or important entities must assess their software supply chain. Dependency on GitHub for CI/CD pipelines and code hosting may constitute supply chain risk under NIS2 if GitHub service disruption or compromise would affect critical operations.
**DORA**: Financial entities using GitHub for production deployment pipelines should evaluate whether this creates ICT concentration risk under DORA's third-party risk framework.
Operational & Strategic Risk
**Vendor lock-in**: GitHub creates moderate to high lock-in through GitHub Actions workflows, GitHub Packages, GitHub Pages, Dependabot, Copilot integration, and repository-linked project management. While Git itself is portable, the surrounding ecosystem is not.
**Auditability**: GitHub Enterprise offers audit log streaming, SAML SSO, and advanced security features (code scanning, secret scanning, dependency review). However, visibility into GitHub's own access to repository contents is limited to transparency reports.
**Lawful access exposure**: Source code repositories may contain trade secrets, proprietary algorithms, security configurations, and internal documentation. Exposure of this material through lawful access requests represents strategic risk distinct from personal data concerns.
**Switching cost implications**: Git repositories are portable. GitHub Actions workflows, integrations, and organisational tooling around GitHub are not. Migration effort is moderate for code, high for CI/CD and workflow automation.
European Alternatives
Alternatives for source code hosting and development infrastructure:
**GitLab** (originally Dutch, now US-incorporated): GitLab self-managed can be deployed on EU infrastructure, providing full sovereignty over source code. The SaaS offering (gitlab.com) is US-jurisdictioned. Trade-off: self-managed requires operational investment. Migration feasibility: moderate.
**Codeberg** (Germany): Non-profit Gitea-based hosting with EU jurisdiction. Suitable for open-source and smaller teams. Trade-off: limited CI/CD, fewer enterprise features. Migration feasibility: easy for basic hosting.
**Gitea / Forgejo** (self-hosted): Open-source Git forges deployable on EU infrastructure. Full sovereignty through self-hosting. Trade-off: operational overhead, fewer managed features. Migration feasibility: moderate.
**Source Hut** (non-US): Minimalist development platform. Trade-off: different workflow paradigm, smaller community.
GitLab self-managed on EU infrastructure is the most direct equivalent for organisations requiring full development platform capabilities with sovereignty control.
Who This Matters For
**Fractional CTOs and technical advisors**: Source code sovereignty is increasingly raised in due diligence, particularly for clients in defence, critical infrastructure, and regulated financial services.
**Engineering leaders**: Development teams should assess whether CI/CD pipelines, secrets management, and deployment workflows create hard dependencies on GitHub that would be costly to unwind.
**Procurement and due diligence**: GitHub Enterprise agreements should be evaluated for sovereignty implications, particularly when source code contains regulated data or strategic IP.
Key Takeaways for Technical Leaders
- •GitHub scores 22/100 on sovereignty due to Microsoft ownership, US jurisdiction, and CLOUD Act exposure over source code
- •Source code sovereignty extends beyond GDPR—proprietary algorithms and trade secrets warrant jurisdiction scrutiny
- •GitLab self-managed on EU infrastructure is the most capable sovereign alternative for full development workflows
- •Git repositories are portable but GitHub Actions, integrations, and organisational tooling create meaningful switching costs
- •Organisations in defence, critical infrastructure, and financial services face the strongest case for GitHub alternatives
Sovereignty Report Available
Quick-reference report with FAQ, topic cluster links, and structured data.
Migration Blueprints
Considering a move? See Migration Blueprints
Audit your technology stack
This analysis covers one tool. Your Technology Stack Audit scores your entire technology stack as one system and gives you a prioritised, fix-first roadmap. One-off €99.
Audit my technology stack — €99