European providers now hold only around 15 percent of their own cloud market
Sovereignty is not a state, but a property of architecture – to be decided in stages and per application
The practical benchmark is not the location of the data, but the actual ability to switch
- Blog
- From the Hospital Information System to the Digital Hospital
Quo Vadis Europe? A continent between hyperscaler cloud and the desire for digital sovereignty
Many hospitals are investing in digitization. However, the real challenge is to make the growing complexity of systems, information, processes, and regulatory requirements manageable.
:quality(75))
:quality(75))
Jonathan Bauer
CEO FC-X
The article classifies the sovereignty debate: Why it cannot be answered with the question of server location, which regulations now apply, and how organizations come to a robust own position.
The article classifies the sovereignty debate: Why it cannot be answered with the question of server location, which regulations now apply, and how organizations come to a robust own position.
At a glance
An uncomfortable starting position
The numbers are clear. According to surveys by the Synergy Research Group based on numbers for 2024, the share of European providers in the European market for cloud infrastructure has fallen from 29 percent in 2017 to about 15 percent. The three major US providers account for around 70 percent of the European market; the largest European providers each account for around two percent. European providers have significantly increased their sales during this period – the market just grew much faster.
In parallel, the political assessment of this dependency has fundamentally changed. What was long considered a question of efficiency is now discussed as a strategic risk: access possibilities from third countries, geopolitical vulnerability, lack of negotiating position, price and license developments without a real alternative.
The regulatory framework is becoming more concrete
The European response has so far been less about their own providers and more about rules. Two developments are directly relevant for organizations.
Since September 12, 2025, the switching regulations of the EU Data Act apply. Providers of data processing services must actively facilitate switching: with a notice period of no more than two months, a subsequent transition period of basically 30 days, open interfaces, support for export, and the goal of functional equivalence. Switching fees may already only be charged on a cost basis; as of January 12, 2027, they will be completely eliminated.
In addition, there is the Cloud and AI Development Act, with which the EU Commission aims to strengthen European cloud and AI capacity. Among other things, it provides for a significant expansion of data center capacity, a joint procurement framework for public administrations and – particularly relevant in practice – a unified sovereignty framework with graded assurance levels. These range from pure data retention in European infrastructure to complete control without the influence of third countries.
This very gradation is the real progress in the debate.
Sovereignty is not a yes-or-no question
The widespread dichotomy "hyperscalers or sovereignty" is misleading. Sovereignty is not a label that a provider carries, but a property that is decided by concrete questions:
Where is the data located – and where is it processed and secured?
Who operates the service, and under which law does this organization fall?
Who owns the cryptographic keys, and who can access them administratively?
How transparent are the supply chain, updates, and subcontractors?
How quickly and at what cost could the service actually be replaced?
These questions can be answered differently per application – and that is precisely the pragmatic approach. A website, a development environment, and a professional procedure with personal or classified data have different requirements. A uniform level of sovereignty for the entire portfolio is expensive, slow, and usually unjustifiable.
Even the much-discussed sovereign offerings of international providers can be evaluated so soberly: They significantly raise the level in individual dimensions – such as location, operating personnel, or key management. Whether they completely exclude an access possibility from the country of origin is another and much more difficult question to answer. Separating the dimensions leads to a reliable decision, instead of trusting a promise.
What organizations should do now
Differentiate protection needs
Classify applications and data by criticality, instead of deciding across the board.
Map dependencies
Make services, subcontractors, license models, and proprietary interfaces transparent.
Set sovereignty goals
Define a target level per application – from data retention in the EU to full operational sovereignty.
Test exit capabilities
Describe not only switching scenarios but also play them out with a real service.
Adjust contracts
Actively demand the rights from the Data Act regarding portability, deadlines, and fees.
Embed architectural principles
Set open formats, standardized interfaces, and own key sovereignty as a standard.
Frequently asked questions
Conclusion
Europe will not quickly regain the market shares of the past ten years. But that is not the decisive factor. What matters is whether organizations know their dependencies, consciously accept them, and can dissolve them if necessary. Sovereignty does not arise from choosing a provider, but from architectures, contracts, and competencies that make a choice possible in the first place. Those who invest today in transparency and the ability to switch do not buy independence – but room for maneuver. And that is currently the scarcer commodity.
The FC-Gruppe helps organizations turn the sovereignty debate into a decision: taking stock of cloud and software dependencies, analyzing protection needs and target images, assessing sovereign operating models, exit and migration concepts, as well as contractual and technical implementation. Contact us if you would like to determine your position.
FC-Gruppe GmbH
AdministrationAm Storrenacker 8 76139 Karlsruhe