Sovereignty

The EU cloud, where sovereignty and cost point the same way

European providers still hold around 15% of their own cloud market, the three American hyperscalers about 70%. That is a strategic dependency, and the cheapest way to reduce it is the same one you already wanted: ownership and portability.

Berkan Alci, founder of YK TechnologiesBerkan Alci5 min readExecutives and IT

In brief

  • European cloud providers now hold about 15% of their own home market, down from 29% in 2017, while AWS, Microsoft and Google together control around 70% (Synergy Research Group, 2025). That ratio is your starting point in every negotiation.
  • Residency and jurisdiction are two different questions. The American CLOUD Act allows US authorities to request data from US providers, even when it physically sits in a European data center (Orrick, 2026).
  • Regulation points the same way: the EU Data Act (Regulation (EU) 2023/2854, applicable since 12 September 2025) enforces portability and the phase-out of egress fees, and NIS2 places the burden of proving data residency with management.
  • Cost pulls along with it. 84% call managing cloud costs their biggest challenge, with a 17% average budget overrun (Flexera 2025), and 83% of CIOs planned to repatriate at least one workload in 2024, against 43% at the end of 2020 (Barclays CIO Survey, 2024). Full exits do remain rare.
  • One open-source platform in your own ownership on an EU cloud brings residency, portability and lock-in together under your control: code in your repository from day 1, open formats, transferable to any integrator.

An architect points to the region in the cloud portal: Frankfurt. The data stays in Europe, he says, and technically that is correct. Yet the most important question is not answered by it. The disks sit in Germany, the provider sits in the United States, and that second fact determines which law your data falls under.

Zoom out and the dependency comes into view. European cloud providers still hold about 15% of their own home market, down from 29% in 2017. AWS, Microsoft and Google together take around 70% (Synergy Research Group, 2025). For a continent that calls its data a strategic resource, that is a lopsided ratio. It sets the negotiating position of every Belgian organization, even though it rarely appears in a quote.

Where the data sits, and under which law it falls

Residency and jurisdiction are often confused, while they are two separate questions. Residency is about the physical location of the disks. Jurisdiction is about who can reach it through legal means. The American CLOUD Act allows US authorities to request data from US cloud providers, regardless of where it physically sits, including in European data centers (Orrick, 2026). A data center in Frankfurt that belongs to an American company therefore does not put your data beyond American reach.

That is no reason for alarm. In practice, something rarely happens, and for a large part of your data the question also matters little. But think of a hospital with patient records, a bank with transaction data, a government service with national registry numbers. For an executive team that has to weigh risk there, a legal channel you cannot see and cannot contest is a real item. You do not need to overstate the odds to factor it in.

Regulation pushes the same way

Europe has seen that dependency and is adjusting. The Data Act, Regulation (EU) 2023/2854, applies since 12 September 2025 and imposes switching obligations: functional equivalence, interoperability, and a phase-out of switching and egress fees. Leaving a provider becomes a right, where it used to be a favor you bought off per gigabyte.

NIS2 works along the side of accountability. The directive expects you to be able to show where your data sits and who can reach it, and it places oversight of that with management. So the question of where your data lives and under which jurisdiction it falls moves from the server room to the executive table. A cyber security audit puts exactly those two points on the table: under which law does your data fall, and what does it cost you to leave.

The exit has become cheaper In 2024, Google Cloud in January and AWS on 5 March scrapped the egress fees for those who leave the cloud, partly under pressure from the EU Data Act (SiliconAngle, 2024). The bill to leave is therefore smaller than a few years ago. The switch itself does remain a project, because data is often locked in formats and services that only work together smoothly with that one provider.

Cost pulls the same way

Sovereignty is not the only reason teams reconsider their cloud position. The bill is just as much a reason. In the Flexera 2025 State of the Cloud, 84% of organizations call managing cloud costs their biggest challenge, with an average budget overrun of 17%. What started as a variable cost that grows with you sits, after a few years, on the books as a fixed burden that is hard to unwind.

That frustration sets people in motion. In the Barclays CIO Survey of 2024, 83% of CIOs want to repatriate at least one workload from the public cloud that year, against 43% at the end of 2020, with cost as the main driver. The nuance counts: full exits remain rare, most organizations stay hybrid. The aim is not leaving the cloud, but getting a grip on your own position, on which cloud you run and at what price you can get out again.

The constructive choice: an open stack under your own control on EU cloud

Put those two lines side by side, sovereignty and cost, and they point the same way. The approach that reduces your legal exposure is usually also the approach that tames your run-rate. At YK that is one open-source platform in your ownership, on a European cloud, with a standard stack that every developer can read: Kubernetes, PostgreSQL, ClickHouse, Metabase. The code sits in your repository from day 1, not in ours.

The interoperability that the Data Act formulates as a right is already in the way this is built. That works on four fronts at once:

  • Residency: your data sits in a European region, with a European provider, outside the reach of the CLOUD Act.
  • Jurisdiction: you show where the data sits and who can reach it, exactly what an audit and NIS2 ask of you.
  • Portability: open source and open formats, so a switch does not require reverse engineering.
  • Cost: a run-rate you steer yourself, without per-user licences that creep up as you grow.

For finance, the accounting model changes too. You pay for the infrastructure you actually run, plus the maintenance, instead of a per-user licence that rises with every hire. The cloud bill stays variable, but you can measure it against alternatives, because nothing in the stack locks you to one provider. That is the difference between a cost you endure and a cost you steer.

A European cloud is not automatically cheaper or richer in features, and on that point the hyperscalers have a real lead. The choice therefore goes beyond the feature list. It is about control: who decides where your data lives, who can formally reach it, and what it costs to leave. Whoever settles that at the front of the journey rather than at renewal keeps both the bill and the control on their side. Our approach builds that in waves with a go or no-go at each step, so the legacy keeps running until each wave is stable and you never put everything at stake at once.

Want to apply this to your own situation?

Belgian, founder-led and built to hand over. One email is enough.