What is Cloud sovereignty actually about?
In the discussions surrounding Cloud sovereignty, one central theme consistently emerged: protecting data in the Cloud and data processed from the Cloud. We see that several aspects of data are being examined through the lens of sovereignty principles:
Jurisdiction: The Cloud is everywhere and nowhere, so what about the legislation governing its operation? Which law applies when an incident occurs during Cloud usage? Does the provider's origin determine which laws apply, or is the location where data is stored and processed the deciding factor?
Regulation: We are all familiar with GDPR, which was imposed by Europe to protect its citizens. However, there are other laws in effect within Europe, such as the Data Act and the AI Act, which became active this summer. This new law outlines how to handle data used in training AI models.
Architecture: The chosen Cloud platform and the method of data storage are central to this and are fundamental principles when it comes to sovereignty. Ensuring data is stored securely through encryption is the current standard, but we must already look ahead. With the advent of quantum computing, breaking current encryption mechanisms will become easy, and we will need to look at solutions like data tokenization.

