Meet the Authors

Key Takeaways What you need to know
  1. Data sovereignty is a degree of control spread across data, operational, technical, and legal layers.

  2. The European Commission's Cloud Sovereignty Framework scores providers against 48 criteria and sets assurance thresholds.

  3. Sovereignty claims carry weight only when audits, access records, and contracts can verify them.

Data sovereignty describes how much control an organization retains over its data and the systems, operators, and jurisdictions surrounding it. The words “how much” deserve attention. Sovereignty is rarely complete or absent. An enterprise can hold strong control over where its data is stored while sharing control over who administers the environment, which software it depends on, and which laws can reach its provider.

Sovereignty then works as a degree of control across several layers. Vendors now describe it in those terms, and the European Commission has begun scoring it directly.

Control Sits in Several Layers

SAP describes sovereignty across four interdependent dimensions: data, operational, technical, and legal. The model separates how data is governed from who operates the environment, how independently its technology functions, and which legal authorities can reach it. Each layer can be stronger or weaker on its own, which is why sovereignty resists a single label.

Explore related questions

SAP CEO Christian Klein has framed the goal as verifiable governance. He has said credible sovereignty means being able to confirm where data is processed, who operates critical systems, and which legal framework applies, with clear accountability “at every level.”

Other vendors use similar terms. SUSE defines sovereignty around where data is stored, who can access it, and how it is governed.

The EU Framework Turns the Definition Into a Score

The European Commission’s Cloud Sovereignty Framework converts a layered definition into a measurement. It produces two results.

An overall sovereignty score draws on 48 defined criteria grouped into eight objectives, including legal and jurisdictional control, operations, supply chain, technology, and data and AI. A separate Sovereignty Effectiveness Assurance Level, or SEAL, tests whether a provider meets set thresholds, with the highest tiers covering data sovereignty, technological autonomy, and full sovereignty.

The Commission has already used the framework to make a buying decision. In April 2026, it scored bidders against the framework to select four European providers for up to €180 million in sovereign cloud contracts serving EU institutions and agencies over six years. The framework itself is open to wider use, and the Commission has encouraged public and private organizations to apply it in their own assessments.

Control Has to Be Verifiable

A degree of control counts only when the organization can confirm it. A provider’s description of a sovereign service remains a claim until evidence supports it.

SAP’s digital sovereignty guidance makes this point at the technical layer, saying customers should be able to verify controls through tenant isolation, encryption, and independent auditability. The same logic applies to the other layers. Operational control depends on records of who accessed and administered a system. Legal control depends on contractual and ownership arrangements that limit unwanted foreign access, which SAP’s guidance also identifies.

Verification also makes sovereignty comparable. When control is documented layer by layer, an enterprise can weigh one provider against another and see where its control remains partial.

What This Means for SAPinsiders

Assess sovereignty layer by layer. Review data, operational, technical, and legal control separately for each provider. A view of each layer shows where control is strong and where it is shared.

Use the EU criteria as a common vocabulary. The Commission’s 48 criteria give procurement, legal, and IT teams a shared reference. Aligning questions to them makes provider responses easier to compare.

Ask for evidence of control. Request audit reports, access records, and contractual terms that support each sovereignty claim. Documented evidence lets teams confirm the level of control they are paying for.

Events

29Oct
SAPinsider Summit New Orleans 2026New Orleans, Louisiana, United States
View All