#129 - More than just servers in Europe: What digital cloud sovereignty really means
Digital sovereignty is the strategic decision about control over your data, technologies and operations. In conversation with Marc Achsnich, we uncover the three decisive dimensions of cloud sovereignty and show how you can move from theory to practical implementation.
3 min read

Sovereignty begins where you truly take control of your data and technologies.
"Trump is our best salesperson." – This provocative claim kicked off a conversation between Joubin Rahimi and Marc Achsnich. And as absurd as that may sound at first, there's truth in it: hardly any topic has generated as much attention this year as digital sovereignty. Companies are unsettled, uncertain, and asking themselves: how much control do we actually still have over our data and technologies?
What sovereignty really means – beyond "servers in Europe"
Many mistakenly equate sovereignty with a "German cloud" or a "data centre in Europe". That falls short. Sovereignty means, above all, freedom and control: you determine who may see which data and when (data sovereignty), you choose technologies independently and retain freedom of choice over how long they're used (technological sovereignty), and you secure legal separation from non-European access rights (operational sovereignty). The operational level in particular is often underestimated. This isn't just about the physical location of data, but about legal protection against extraterritorial laws such as the US Cloud Act – a key point for regulated industries, critical infrastructure and companies with high compliance requirements. Keywords you should know • Digital sovereignty, data sovereignty, technological sovereignty, operational sovereignty • Cloud compliance, data protection, data location, EU data centre, jurisdictional separation • Cloud Act, FIS topics, Schrems rulings (Schrems I/II/III), protection needs analysis
Legal context: Schrems rulings, FIS/Cloud Act & co.
Transatlantic data transfer remains a dynamic field. The Schrems rulings and ongoing adjustments show just how sensitive the legal framework is. For you, that means: compliance isn't a state, it's a process. What's permissible today may be contested tomorrow – and vice versa. That's why you need a governance model that doesn't just know case law and Standard Contractual Clauses (SCCs), but makes them operationally actionable.
A practical guiding question: which categories of data do you process, which jurisdiction is involved, and which protective measures are demonstrably in place? Only from this combination do robust decisions on provider choice, operating model (public, private, hybrid), encryption and network segmentation emerge.
Protection needs analysis: the pragmatic entry point into data sovereignty
Not all data is equally critical. That's exactly why a protection needs analysis is your best tool for establishing appropriate security levels – efficiently, auditably and scalably. • Non-critical information (e.g. Publicly available T&Cs): low protection requirement. • Contractual and business data: end-to-end encryption, secure storage services, clear permissions. • Highly sensitive data (health data, formulas, KRITIS-relevant data): zone concepts, dedicated network segments, strict key management and legally shielded operating models. The goal is proportionality: maximum protection where necessary and lean operations where possible. This way, you combine compliance, risk reduction and cost efficiency.
From strategy to implementation: provider interpretations and operating models
Market leaders interpret "sovereignty" differently, ranging from European-operated clouds to customer-managed keys through to legally decoupled operating models. What matters is that you assess the offerings against your protection needs, use cases and audit requirements. Our whitepaper helps untangle terminology, classify architecture options and create decision templates.
Practical benefits
Clarity on data criticality and jurisdictions
Comparison with provider capabilities (e.g. Data location, key sovereignty, support model)
Roadmap from "quick wins" to "target operating model"
Would you like to listen to the full episode?
Here you'll find the podcast of the interview:
Please accept the corresponding cookies to view this embedded content.
Would you rather watch the episode? No problem!
Here you'll find a recording of the interview:
Please accept functional cookies to watch this video.
Would you rather read?
Joubin Rahimi
Great to have you back for a new episode of Insights! My name is Joubin Rahimi, and joining me today: Marc Achsnich. Hello Marc.
Marc Achsnich
Hi Joubin.
Joubin Rahimi
And we've got a really exciting topic. Before we get started, an anecdote first. At one of our partners, I got to give a webcast and had slides prepared with Trump on them, where I said: Trump is our best salesperson. They didn't want it on there, because they also have US business and are afraid of getting a rap on the knuckles for it. And that just reinforces this sales mentality around Trump, because it's about the topic of sovereignty, which has really had quite a boost this year. That's why I'm really glad Marc's here. Marc is a Fellow at TIMETOACT GROUP. They're our specialists, trusted advisors across the whole group, and he works on the topic of managed services. And sovereignty in particular has become close to your heart over the last few years, within synaigy. But sovereignty – I just said it's our best-selling horse in the stable, so to speak, Trump. Is that so? Do you see it that way too?
Marc Achsnich
Yes, absolutely. In the end, we've also been getting a lot of new enquiries from areas that maybe weren't so typical before, who are now simply sensing unease, feeling uncertain and just don't know how to assess it for themselves.
Joubin Rahimi
But is that sovereignty? You hear this a lot: you take something German or European. Does that make me sovereign straight away? Or how do you approach it properly?
Marc Achsnich
Yes, that's actually a bit more complicated. Crazy? Yes, it's not always straightforward. You see, the thing is, when people talk about sovereignty, they usually just mean that something should be encrypted or has to be located somewhere in Germany. But the underlying idea goes a step deeper, because it's really about freedom. And the sovereignty concept plays out in three directions. The first is freedom over control of your data. That means you're data sovereign in this area if you can simply decide who may see which data and when. Then there's technological sovereignty, where you can freely decide which technology is used, and there, for example, how long you want to use it or how long you have to use it, for as long as you like. And the third part, and that's exactly the part that concerns Europe, is operational sovereignty. And that's about the data centre not just being located in Europe, but the entities also being legally separated from one another in such a way that, because of the FISA or the Cloud Act, no data can now specifically be accessed.
Joubin Rahimi
What exactly is the FISA? Because I think that's a really important part of the discussion.
Marc Achsnich
The FISA, that's basically always been a kind of cat-and-mouse game. There are draft laws, drafts from America for example, and those then get challenged. And that's exactly one of those cases where it was found that there are clauses in there that are simply void for our state.
Joubin Rahimi
I think if anyone wants to google it, it's Schrems. Exactly, Schrems. Schrems. No, Schrems.
Marc Achsnich
Exactly, and there's Schrems one, Schrems two, because he's already had two attempts. And I mean, by now there's, I don't know if it's already been published, Schrems three, or whether it's still on its way out.
Joubin Rahimi
And what would you advise clients and companies who say sovereignty matters to them, what should they do?
Marc Achsnich
Well, again, it depends on what exactly they mean. Or need. Right, what they mean and what they need, because ultimately, for example, data sovereignty is a part that might not always be equally important or need to be treated the same way in every case. The same goes for technological sovereignty.
Joubin Rahimi
Data sovereignty in the sense that if I have medical data or product data, recipes, then I might not want to share that?
Marc Achsnich
Exactly, so put simply. A public set of T&Cs is somewhere on the internet anyway, it can sit wherever you want to put it. It doesn't need to be encrypted. If you've got contract data, that should just be encrypted, but it still doesn't matter where it's located. If it's data from, say, defence contractors or health data, then in that area you really need to think more carefully about how you protect it, and then it's not enough, for example, just to protect it. You need your own network, zone concept and so on. That means the bar for how you need to protect data simply differs depending on data sensitivity.
Joubin Rahimi
Do you have a tool or resource to quickly work out how much protection you need or how deep you should go into the topic of sovereignty?
Marc Achsnich
Surprisingly, yes.
Joubin Rahimi
No.
Marc Achsnich
The simple tool is called a protection needs analysis, and we'd also given this some thought. The question kept coming up, generally about sovereignty too, and we also noticed that it's simply increased more and more over the past months and weeks. So we took the time to assess it again and describe it in more detail. And in that context, for example, we've now brought out a whitepaper where we soberly lay out, in essence, what sovereignty adds up to, why it's becoming more important, why it's in the media now when two years ago nobody had heard a thing about it. Back then you could say sovereignty and people simply didn't care at all. And this year it's completely different. So we've finally written the whitepaper that assesses all of this and, in the same breath, in the next step, also says, if sovereignty now means a certain level of protection, how do the individual providers interpret that for themselves?
Joubin Rahimi
Then I'd say, either we're somewhere near the whitepaper in the video, in which case you can just download it directly, probably behind a little data wall. We're always glad to have your contact details. Where do we actually store those?
Marc Achsnich
At OVH.
Joubin Rahimi
At OVH? Are you mad? So much for sovereign.
Marc Achsnich
That's how it is.
Joubin Rahimi
Exactly. And we'll give you a call too. We're always happy to talk. If it's not a fit, that's completely fine too. But if you catch us on the video where we're not right next to the whitepaper, message Marc Achsnich, easy to find on LinkedIn, or message me, and we'll send it over to you. Marc, thanks for the insights, and thanks for the whitepaper and all the checklists you put together. My pleasure. Right, and thanks for listening and watching.
Have questions or feedback?
Then feel free to contact us directly.
- Joubin Rahimi
Managing Partnersynaigy
Show phone numberShow mobile numberShow email address
Subscribe to the blog now and never miss any news
✔️free ✔️weekly news ✔️expert knowledge
Please accept the corresponding cookies to view this embedded content.
