Amazon Web Services has announced the arrival of the AWS European Sovereign Cloud, a new independent cloud for Europe located entirely within the European Union (EU), and physically and logically separated from other AWS Regions.

The unique approach of the AWS European Sovereign Cloud makes it the only fully-featured sovereign cloud, independently operated and backed by robust technical controls, sovereignty guarantees and legal protections designed to meet the needs of European governments and businesses for sensitive data.

In parallel, AWS has also announced plans to expand the presence of the AWS European Sovereign Cloud from Germany to the entire EU to support strict requirements for isolation, in-country data residency, and low latency. This will begin with new AWS Sovereign Local Zones located in Portugal, Belgium, and the Netherlands.

Full location and data control

From day one, AWS’s global cloud and artificial intelligence (AI) infrastructure has been sovereign by design, giving customers complete control over the location and movement of their data. This is supported by a series of technical measures and operational controls that provide transparency and assurance, just as the global AWS infrastructure offers exceptionally high resilience, security and availability. The AWS European Sovereign Cloud is designed to meet the needs of organizations with the most extreme security and data privacy requirements.

In fact, most customers can meet their requirements using one of the six existing EU AWS Regions, as they are sovereign by design. On the other hand, the AWS European Sovereign Cloud is designed to offer customers additional options to meet the EU’s strict sovereignty requirements without compromising the robust capabilities of AWS.

Both the AWS European Sovereign Cloud, and the expansion of AWS Sovereign Local Zones to three additional countries, will provide organizations with more options to deploy cloud workloads with the highest level of sovereignty and operational independence, while maintaining the broad portfolio of AWS services that customers rely on to innovate and transform their organizations.

AWS Local Zones are a type of infrastructure that allows customers to store their data in a specific geographic location to meet data residency requirements or run latency-sensitive applications. The announced AWS Local Zones will now be part of the AWS European Sovereign Cloud, extending sovereignty controls from the AWS Region in Germany to the entire EU. This allows customers with stricter data independence or residency requirements to have the option to use AWS Dedicated Local Zones, AWS AI Factories, or AWS Outposts in locations they select, including their own on-premises data centers.

«Europe needs access to the most robust cloud and artificial intelligence technology. “Expanding AWS innovation in Europe will help drive customers’ growth and AI ambitions,” said Stéphane Israël, managing director of AWS European Sovereign Cloud and digital sovereignty. “Customers want the best of both worlds: being able to use AWS’s full portfolio of cloud and AI services while ensuring they can meet their strict sovereignty requirements. By building a cloud that is European in its infrastructure, operations and governance, we are empowering organizations to innovate with confidence while maintaining complete control over their digital assets.”

For her part, María González Veracruz, Secretary of State for Digitalization and Artificial Intelligence in Spain, highlights: «I positively value AWS’s commitment to Europe through the launch of its AWS European Sovereign Cloud. This initiative is aligned with the digital transformation strategy of the Spanish Government, which considers data governance as a cornerstone for the development of reliable, useful, productive and ethical artificial intelligence, and which prioritizes guaranteeing the security, privacy and rights of companies and citizens in the digital environment.

Managed, operated and protected in Europe

The AWS European Sovereign Cloud combines comprehensive and layered controls to provide a robust solution for customers who need to meet strict digital sovereignty requirements, while ensuring they benefit from the breadth of AWS cloud and AI innovation. Everything needed to operate the AWS European Sovereign Cloud is in the EU: the talent, the infrastructure and the leadership. There is no operational control outside the EU borders. Key capabilities include:

• European operational autonomy: The AWS European Sovereign Cloud is physically and logically separate from other AWS Regions. It is operated exclusively by EU residents, has no critical infrastructure dependencies outside the EU, and its unique design allows it to continue operations indefinitely, even in the event of a disruption of communications with the rest of the world. To support continuity even in extreme circumstances, AWS employees authorized to operate on the AWS European Sovereign Cloud, who are EU residents, will have independent access to a replica of the source code necessary to maintain the AWS European Sovereign Cloud services.

• Complete data residency: The AWS European Sovereign Cloud gives customers full control over where their data is stored. AWS European Sovereign Cloud allows customers to keep all the metadata they create (such as roles, permissions, resource tags, and configurations) entirely in the EU, including sovereign Identity and Access Management (IAM), billing, and usage metering systems.

• Leading technical and compliance controls: Security is fundamental to digital sovereignty, and like other AWS Regions, the AWS European Sovereign Cloud is powered by the AWS Nitro System, which provides an industry-leading physical and logical security boundary to enforce access restrictions so that no one, including AWS employees, can access customer data running on Amazon EC2. AWS also provides advanced encryption, key management services, and hardware security modules that customers can use to further protect their content.

Encrypted content is useless without applicable decryption keys. AWS has also introduced the AWS European Sovereign Cloud Sovereignty Reference Framework (ESC-SRF), an independently validated framework to meet customers’ sovereignty requirements. Clients can use the third-party validated ESC-SRF auditor report to demonstrate clear and enforceable sovereignty assurances.

• European governance: AWS has established a dedicated governance structure in Europe, with a new parent company and three local subsidiaries incorporated in Germany (GmbH), led by EU citizens who are required to comply with European laws and act in the best interests of the AWS European Sovereign Cloud. It also includes an advisory board, which will provide expertise and accountability on sovereignty-related matters and is made up of three Amazon employees and two independent board members, all European citizens and residents.

Investment in European innovation and digital capabilities

The expansion of AWS European Sovereign Cloud to Belgium, the Netherlands and Portugal represents additional planned investment in new cutting-edge cloud and AI capabilities that will help support local economic growth, productivity and innovation. By bringing AWS cloud capabilities closer to customers, AWS is providing organizations with the tools they need to drive their digital transformation, while meeting strict data residency and low latency requirements.

Customers and partners using the AWS European Sovereign Cloud will benefit from the full power of AWS, including the same security, availability, performance, familiar architecture, APIs, and leading security innovations as the AWS Nitro System. The AWS European Sovereign Cloud will initially feature more than 90 services across a variety of categories, including artificial intelligence, compute, containers, databases, networking, security and storage.

Customers in the public sector and a wide variety of regulated industries across Europe have already chosen the AWS European Sovereign Cloud. For their part, AWS Partners are committed to providing their solutions for and within the AWS European Sovereign Cloud. Launch partners include: Accenture, Capgemini, Kyndryl, SAP and many more.

European customers across a variety of regulated industries, including government, healthcare, financial services, defense and aerospace, energy, telecommunications, and more, can now use the AWS European Sovereign Cloud to accelerate their innovation while meeting their strict data sovereignty and compliance requirements.

Secure cloud and managed services

“By making SAP Sovereign Cloud capabilities available on AWS European Sovereign Cloud, we are expanding customers’ options for sovereign cloud deployments in Europe. “This allows organizations to run critical workloads and apply artificial intelligence securely, under European governance, while selecting the deployment model that best suits their needs,” Martin Merz, president of Sovereign Cloud at SAP.

«European organizations are seeking greater flexibility and guarantees to address changing sovereignty needs. Capgemini brings AWS Digital Sovereignty and Trusted Secure Enclave competencies along with extensive experience in secure cloud architectures and managed services. With the AWS European Sovereign Cloud, we can help customers design, build and operate solutions that deliver tangible results in cloud, data and artificial intelligence,” Fernando Álvarez, Director of Strategy and Business Development and member of the Group Executive Council at Capgemini.

“Customers want cloud solutions that protect data sovereignty and enable continuous innovation, which is why Kyndryl is pleased to be among the first allied partners to support the AWS European Sovereign Cloud. With our experience managing critical systems in regulated environments, we understand that sovereignty must be integrated from design into the technological infrastructure. “We look forward to working with AWS to help customers meet regulatory expectations, support data residency and protection, and achieve their digital transformation goals,” Martin Schroeter, president and CEO of Kyndryl.

“Our customers managing highly sensitive workloads in the cloud need options on how to protect and manage their data, and solutions that allow them to modernize quickly and confidently. The AWS European Sovereign Cloud offers organizations in regulated industries additional sovereignty controls along with a broad set of services to innovate responsibly. As a launch partner, we are committed to helping our European clients leverage this ability to reinvent themselves and unlock new growth opportunities for their organizations,” Mauro Capo, Head of Digital Sovereignty for Europe, the Middle East and Africa (EMEA) at Accenture.