On paper, you are free to switch cloud providers. In practice, you are still locked in. The Data Act, the EU’s data regulation, gives you the right to move systems and data from one cloud provider to another. There is no shortage of alternatives, European providers exist. What keeps you locked in is friction.
It starts with the contract, with long commitment periods and termination terms that mean a switch has to be planned far in advance. Then comes the cost of getting your own data out: storing it with the provider is cheap, moving it out is expensive. And the more you run in the cloud, the more interconnected everything becomes. You have not simply stored data somewhere; you have built your operations on the provider’s specific services, from databases to queues and functions, which have no exact equivalent elsewhere.
“The Data Act can force providers to let you move your data. But it cannot force the next provider to offer exactly the same services. That is why switching often becomes a rebuild rather than a migration,” says Staffan Lindblad, specialist in cybersecurity and compliance at cloud provider Elastx.
That is precisely the friction the Data Act is intended to remove: it phases out switching charges, limits notice periods and requires data to be portable. But removing the barriers is not enough. Even when leaving becomes easy, the market will continue to tilt towards the largest providers, because European alternatives need scale and breadth to be able to take over the most business-critical systems. They will not achieve that scale until enough demand shifts towards them.
That is the catch-22. Customers gravitate towards the established providers because the alternatives are not yet large enough, and the alternatives remain too small because customers do not gravitate towards them. Rules do not build data centres – and that is the gap CADA is trying to close. The proposal tackles both sides at once: it makes it easier to build capacity and directs Europe’s collective public purchasing power towards sovereign providers. The framework is written for everyone, but the public sector is intended to give it momentum. When the public sector begins procuring sovereignty at sufficient scale, providers gain the scale that makes them credible alternatives for you as well.
Four levels and the battle over the third
At its core is a tiered model in which each use case is assigned the level justified by its sensitivity. Level 1 requires data to be processed within the EU. Level 2 requires the provider to be independent of third countries and to have a transparent supply chain. Level 3 requires the provider to be owned and controlled from within the EU, with requirements also covering who may hold sensitive roles. Level 4 requires full control over the entire supply chain without influence from third countries and is intended for defence and national security.
“A common misconception is that CADA would shut out foreign cloud giants. That is not the case. The lower levels are open to anyone who meets the requirements. What is restricted is access to the most sensitive assignments, not the market,” says Lindblad.
According to him, the real battle is over Level 3. There, and only there among the substantive levels, is a clause allowing the Commission to recognise providers from third countries that are deemed to offer sufficient guarantees, a mechanism similar to the GDPR’s adequacy decisions. Level 4 contains no such opening.
“If the clause is drafted generously, Level 3 becomes a back door for EU structures operated by foreign corporate groups. If it is drafted narrowly, it becomes a genuine sovereignty requirement. And the criteria point directly at the CLOUD Act, so as long as that law remains in place, recognising the US will be difficult. That wording will determine whether the framework has teeth or becomes yet another vehicle for sovereignty washing,” he says.
The provision that makes this an issue for the entire private sector
One underreported detail: CADA reaches beyond public authorities. The proposal opens the door for private essential entities under NIS2, in sectors such as energy, transport, banking, healthcare and digital infrastructure, to carry out equivalent sovereignty assessments of their cloud providers. It also gives the Commission the possibility of making this a requirement at a later stage through secondary legislation.
“A Swedish bank or healthcare provider that today thinks this only applies to public authorities could, in a few years, be required to carry out the same type of analysis of its cloud providers. If you are covered by the Cybersecurity Act, the Swedish NIS2 law, you should keep a close eye on this provision,” says Staffan Lindblad.
Five things to do now
- Inventory and classify your use cases: Which systems are in the cloud, and what level would an honest risk assessment place them at?
- Ask the ownership question: Who ultimately owns your provider, and which countries’ laws can reach the business through the ownership chain?
- Ask the operations question: Where are the people with administrative access located, including escalation chains?
- Demand a transparent supply chain: Providers that respond with documentation rather than brochures are the same regardless of CADA’s fate.
- If you are covered by NIS2: Carry out the cloud provider assessment voluntarily now. If it becomes a statutory requirement later, the homework will already be done.
“What we see in practice is that almost every procurement requires data to be stored within the EU, but few ask who owns the provider or where the administrators are located. CADA makes these questions standard, and that is beneficial regardless of the proposal’s fate. Digital sovereignty is not about where the data is located. It is about who has control,” says Lindblad.
That is also why Elastx built its platform on the principles the proposal now favours, long before CADA existed: European ownership, Swedish jurisdiction and a software stack built entirely on open source.
It starts with the contract, with long commitment periods and termination terms that mean a switch has to be planned far in advance. Then comes the cost of getting your own data out: storing it with the provider is cheap, moving it out is expensive. And the more you run in the cloud, the more interconnected everything becomes. You have not simply stored data somewhere; you have built your operations on the provider’s specific services, from databases to queues and functions, which have no exact equivalent elsewhere.
*“The Data Act can force providers to let you move your data. But it cannot force the next provider to offer exactly the same services. That is why switching often becomes a rebuild rather than a migration,” *says Staffan Lindblad, specialist in cybersecurity and compliance at cloud provider Elastx.
That is precisely the friction the Data Act is intended to remove: it phases out switching charges, limits notice periods and requires data to be portable. But removing the barriers is not enough. Even when leaving becomes easy, the market will continue to tilt towards the largest providers, because European alternatives need scale and breadth to be able to take over the most business-critical systems. They will not achieve that scale until enough demand shifts towards them.
That is the catch-22. Customers gravitate towards the established providers because the alternatives are not yet large enough, and the alternatives remain too small because customers do not gravitate towards them. Rules do not build data centres – and that is the gap CADA is trying to close. The proposal tackles both sides at once: it makes it easier to build capacity and directs Europe’s collective public purchasing power towards sovereign providers. The framework is written for everyone, but the public sector is intended to give it momentum. When the public sector begins procuring sovereignty at sufficient scale, providers gain the scale that makes them credible alternatives for you as well.
Four levels and the battle over the third
At its core is a tiered model in which each use case is assigned the level justified by its sensitivity. Level 1 requires data to be processed within the EU. Level 2 requires the provider to be independent of third countries and to have a transparent supply chain. Level 3 requires the provider to be owned and controlled from within the EU, with requirements also covering who may hold sensitive roles. Level 4 requires full control over the entire supply chain without influence from third countries and is intended for defence and national security.
“A common misconception is that CADA would shut out foreign cloud giants. That is not the case. The lower levels are open to anyone who meets the requirements. What is restricted is access to the most sensitive assignments, not the market,” says Lindblad.
According to him, the real battle is over Level 3. There, and only there among the substantive levels, is a clause allowing the Commission to recognise providers from third countries that are deemed to offer sufficient guarantees, a mechanism similar to the GDPR’s adequacy decisions. Level 4 contains no such opening.
“If the clause is drafted generously, Level 3 becomes a back door for EU structures operated by foreign corporate groups. If it is drafted narrowly, it becomes a genuine sovereignty requirement. And the criteria point directly at the CLOUD Act, so as long as that law remains in place, recognising the US will be difficult. That wording will determine whether the framework has teeth or becomes yet another vehicle for sovereignty washing,” he says.
The provision that makes this an issue for the entire private sector
One underreported detail: CADA reaches beyond public authorities. The proposal opens the door for private essential entities under NIS2, in sectors such as energy, transport, banking, healthcare and digital infrastructure, to carry out equivalent sovereignty assessments of their cloud providers. It also gives the Commission the possibility of making this a requirement at a later stage through secondary legislation.
“A Swedish bank or healthcare provider that today thinks this only applies to public authorities could, in a few years, be required to carry out the same type of analysis of its cloud providers. If you are covered by the Cybersecurity Act, the Swedish NIS2 law, you should keep a close eye on this provision,” says Staffan Lindblad.
Five things to do now
- Inventory and classify your use cases: Which systems are in the cloud, and what level would an honest risk assessment place them at?
- Ask the ownership question: Who ultimately owns your provider, and which countries’ laws can reach the business through the ownership chain?
- Ask the operations question: Where are the people with administrative access located, including escalation chains?
- Demand a transparent supply chain: Providers that respond with documentation rather than brochures are the same regardless of CADA’s fate.
- If you are covered by NIS2: Carry out the cloud provider assessment voluntarily now. If it becomes a statutory requirement later, the homework will already be done.
“What we see in practice is that almost every procurement requires data to be stored within the EU, but few ask who owns the provider or where the administrators are located. CADA makes these questions standard, and that is beneficial regardless of the proposal’s fate. Digital sovereignty is not about where the data is located. It is about who has control,” says Lindblad.
That is also why Elastx built its platform on the principles the proposal now favours, long before CADA existed: European ownership, Swedish jurisdiction and a software stack built entirely on open source.
