Since early 2026, sovereignty has moved from policy paper towards procurement clause. Reports in May 2026 suggested the European Commission was preparing a 'tech sovereignty package', and the Commission confirmed the plan on 3 June 2026 through the Cloud and AI Development Act (CADA). The proposal would bar US hyperscalers from the most sensitive government workloads in healthcare, finance, and justice. The concern isn't that those providers have done anything wrong. It's that the US CLOUD Act gives American authorities a legal route to data regardless of where it sits. Much of this is still proposed rather than in force, but France has already gone further in practice. It has rolled out its state-built video platform, Visio, with a target of replacing mainstream US conferencing tools across national agencies by 2027.
If your organisation issues public tenders, sovereignty isn't something you can plan for eventually. It's a live procurement question today, even though the EU-wide legal framework is still being finalised. For the underlying concept, our guide to what sovereign cloud actually means covers the fundamentals. This article is the practical follow-on: the certification schemes to specify, the use cases that trigger them, and a checklist for writing a tender that will hold up to scrutiny.
Table of contents
The policy direction is now explicit rather than aspirational. The Commission's proposals, put forward through CADA, would not ban US cloud providers from public contracts outright. They would introduce tiered restrictions based on data sensitivity, targeting sectors such as healthcare, finance, and justice, while leaving private-sector use largely untouched. Like any EU legislation of this kind, CADA still needs to clear the European Parliament and a qualified majority in the Council under the ordinary legislative procedure. It doesn't need a unanimous vote by all 27 member states. It isn't law yet either: none of its provisions are in force today.
A parallel initiative, the Cloud Sovereignty Framework (the Commission also publishes it as the Sovereign Cloud Framework), gives procurement teams a structured way to score providers. It rates them across eight dimensions, including legal jurisdiction, operational resilience, and supply chain transparency, on a five-tier Sovereignty Effectiveness Assurance Level (SEAL) scale running from SEAL-0 (No Sovereignty) to SEAL-4 (Full Digital Sovereignty). Keep it distinct from CADA itself, which sets out its own scale of four assurance levels that public bodies would apply according to their own risk assessment. Those run from data held on EU-located infrastructure at Level 1 to no third-country interference of any kind at Level 4. The two frameworks are related but separate, so a SEAL rating doesn't translate into a CADA level.
The Commission's own procurement gives a useful illustration of how the SEAL scale plays out in practice. In April 2026, it applied explicit sovereignty criteria to its own cloud procurement for the first time, awarding a €180 million contract over six years to four provider groups: Luxembourg's Post Telecom (with CleverCloud and OVHcloud), Germany's STACKIT, France's Scaleway, and Belgium's Proximus. Post Telecom, STACKIT, and Scaleway each reached SEAL-3, having no material non-EU supply chain dependencies. Proximus was awarded at the lower SEAL-2, because its consortium includes S3NS, a joint venture between Thales and Google Cloud. CISPE, the trade association representing 38 European cloud infrastructure providers, objected publicly: its secretary general called the decision to recognise S3NS as sovereign 'clearly an own goal' that 'threatens to institutionalize sovereignty washing at the highest levels'. For a procurement team the lesson is worth holding on to. A European name on the contract does not guarantee a European supply chain behind it, and that gap is exactly what a scored framework exists to expose.
National initiatives are moving in parallel. France's 'Cloud au Centre' doctrine has, since 2021, pushed sensitive public data towards SecNumCloud-qualified hosting, reinforced by a 2023 update, and the Visio rollout signals that the same logic now applies to the application layer, not just infrastructure. Germany has moved in a similar direction: Gaia-X adoption is growing among German public bodies, and the government folded digital sovereignty into a dedicated ministry, the Federal Ministry for Digital and State Modernisation (BMDS), created in May 2025. For public-sector video conferencing procurement teams, the practical upshot is that who can be compelled to hand over your data, and under which country's law, has become a scored criterion, not a footnote.
Visio itself shows what 'sovereign' can mean in practice. It isn't a commercial product bought off the shelf: it's a self-hosted platform, built on open-source WebRTC software, run on SecNumCloud-qualified infrastructure by France's own digital agency. Self-hosting a mature open-source stack, such as Jitsi Meet or BigBlueButton, is a legitimate route to sovereignty in its own right, not a consolation option. It hands full control of the infrastructure to the buyer. It also comes with real trade-offs: the operational burden of running and patching the platform falls on you, and it takes genuine in-house expertise to do it well. Most of this guide focuses on certifying and procuring a managed vendor, but decide early which route suits your organisation's resources, because it changes what the rest of your tender should ask for.
Certification schemes vary in scope, legal weight, and evidentiary value. None of them alone guarantees GDPR-compliant video conferencing for government use, but together they let a procurement team build a defensible evidence base.
| Scheme | Administered by | What it proves | Relevance to video conferencing |
|---|---|---|---|
| EUCS (EU Cybersecurity Certification Scheme for Cloud Services) | ENISA, under the EU Cybersecurity Act | Baseline, substantial, and high-level cybersecurity controls for cloud services | Still in draft, and the sovereignty-specific 'High+' tier, which would have added requirements on immunity from non-EU law, has been dropped from recent versions. An EUCS rating, even at the highest level, doesn't tell you whether a video platform's call recordings or transcripts can be reached under non-EU law. |
| SecNumCloud | ANSSI (France) | Technical security (360+ requirements) plus legal sovereignty: EU legal domicile, EU-only data storage, and immunity from extraterritorial law such as the US CLOUD Act | The most stringent scheme in Europe and the reference point for French public-sector video tenders. Qualification requires proving that a video platform's call data, storage, and processing genuinely sit outside CLOUD Act reach, not just that its servers happen to be in the EU. |
| C5 (Cloud Computing Compliance Criteria Catalogue) | BSI (Germany) | Implemented security controls across governance, cryptography, and operations | A required baseline for federal public-sector procurement in Germany. It attests to a video vendor's security controls, such as encryption key handling and incident response, but not to jurisdictional independence: a C5-attested provider with a non-EU parent can still carry CLOUD Act exposure. |
| Gaia-X Label / Trust Framework | Gaia-X European Association (Brussels-based, founded by France and Germany) | Federated, verifiable compliance with sovereignty, transparency, and interoperability principles, across labelling tiers | Increasingly referenced in sovereignty discussions, and Gaia-X is lobbying for CADA to reference its labelling scheme directly. For now, CADA applies its own separate assurance levels and does not require a Gaia-X label. For a video platform, a Gaia-X label signals transparency about data flows and subprocessors, which makes it useful alongside a scheme like SecNumCloud. On its own it proves much less. |
| GDPR baseline | EU-wide (supervisory authorities) | Lawful processing, data subject rights, cross-border transfer safeguards | The legal floor every public-sector video tool must meet for call recordings, transcripts, and AI-generated summaries, but compliance alone doesn't establish sovereignty: GDPR-adequate processing can still coexist with CLOUD Act exposure. |
The practical takeaway for a tender: GDPR compliance is table stakes, C5 is a required security floor for German federal procurement and increasingly expected by German state and municipal buyers too, and SecNumCloud (or a comparable national qualification) is the strongest available proof of actual sovereignty for a video platform. Of everything in the table, it is the only scheme that addresses legal jurisdiction head-on; the others stop at technical controls.
Different parts of government trigger sovereignty requirements for different reasons. A tender should address each use case on its own terms.
Cabinet-level discussions, interdepartmental coordination, and classified or restricted briefings make the clearest case for government video conferencing that keeps data and metadata within a defined jurisdiction: the sensitivity of the content itself is the trigger, independent of any specific regulation.
Judicial proceedings, remote hearings, and case-related consultations fall squarely within the sectors the EU's proposed restrictions single out by name. Recordings, transcripts, and case metadata generated during a hearing carry the same sensitivity as the underlying case file, so the sovereignty requirement extends to storage and processing of session recordings as well as the live call.
Health data is one of the three sectors explicitly named in the Commission's tiered-restriction proposals, alongside finance and justice. A public health authority running telehealth consultations needs video conferencing for government-run clinical services where patient data, including any AI-generated consultation summaries, stays within EU jurisdiction and is handled in line with GDPR.
Public schools and universities increasingly deliver classes, oversee exams, and hold safeguarding-related meetings over video. The current tiered-restriction proposals don't name education. Even so, national data protection authorities in several member states already expect EU hosting for pupil and student data, which makes sovereign hosting a practical requirement in places where no rule strictly mandates it.
Local authorities embedding video consultations into benefits applications, planning appeals, or citizen advice portals need public-sector video conferencing that can be white-labelled into an existing digital service, while still meeting the same hosting and jurisdictional requirements as internal use. Citizen data carries the same sensitivity whether it arrives through a public-facing form or an internal call.
A tender for sovereign video conferencing procurement should go beyond a general data-protection clause and specify verifiable, auditable requirements. One caution before the checklist: this doesn't mean you can simply write 'EU-owned providers only' into a tender and exclude everyone else. Under the EU's public procurement rules (Directive 2014/24/EU) and the World Trade Organization's Government Procurement Agreement, contracting authorities must treat bidders equally regardless of nationality, with only narrow exceptions such as national security. The items below work as disclosure and evaluation criteria that a bidder has to answer and be scored against, not as grounds for a blanket nationality-based exclusion. Check any exclusion clause with your procurement lawyers before it goes out. At minimum, the tender should cover:
Digital Samba is registered in Spain, and our competent supervisory authority is the AEPD (Agencia Española de Protección de Datos). There is no non-EU parent company in our ownership structure, which answers the first item on the checklist above: there is no ownership chain running back to an entity exposed to the US CLOUD Act.
Our production infrastructure runs in the Netherlands, with backup infrastructure in Germany. Overflow capacity at peak demand sits with two European providers, one inside the EU and one in Switzerland. The Swiss capacity rests on adequacy rather than EU or EEA residency, which clears GDPR transfer rules but not a stricter EU-only requirement. Our security whitepaper names each infrastructure provider, where it operates and the certifications it holds.
We have designated a Data Protection Officer under GDPR Article 37, we maintain Records of Processing Activities under Article 30, and we carry out data protection impact assessments for high-risk processing. On the certification schemes themselves, and on ISO 27001 too, our controls are documented rather than certified: Digital Samba's information security management system uses ISO 27001:2022 as a reference framework, which is a general information security standard rather than a sovereignty scheme. We are working towards formal certification against it. If your evaluation needs the underlying documentation, or anything we have not covered here, our security team can be reached at security@digitalsamba.com and answers compliance and diligence questions directly.
For procurement teams that want infrastructure control beyond a managed EU-hosted service, we also offer an on-premises deployment option, which puts the whole infrastructure environment under your control. Our REST API, embeddable SDK and webhook-driven session and recording events let an integrator embed video into a citizen-facing service and see exactly what happens to call data at each stage, which is what the interoperability item asks for. For healthcare and justice, where AI-generated summaries need to stay within the same jurisdictional boundary as the underlying call, the relevant detail sits in our security and encryption architecture and our EU-hosted transcription and AI meeting summary capabilities.
Write the tender so a bidder can't wave a certificate around and call it done. Ask for evidence instead of assurances, and match what you ask for to what the use case actually needs. The rules are still being finalised at EU level, so expect this area to keep moving. Build a tender that asks the right questions now, and you won't have to rewrite it every time a new regulation lands.
At minimum: GDPR-compliant processing as a baseline, plus evidence against a recognised sovereignty scheme such as SecNumCloud in France or C5 in Germany, and a statement on EUCS and Gaia-X label status. Which of these matters most depends on the sector: courts and healthcare warrant the strictest evidence, while an internal scheduling tool for a local council might reasonably ask for less.
Currently, yes, in most cases. The EU's proposed restrictions target specific sensitive sectors: healthcare, finance, and justice. There is no blanket ban. CADA also still has to clear the European Parliament and win a qualified majority in the Council before it takes effect, and it does not need a unanimous vote of all 27 member states. Several national governments, France among them, are already moving to sovereign alternatives ahead of any binding EU-wide rule.
Not explicitly. GDPR allows data to move outside the EU under specific legal mechanisms, such as an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules. In practice, a public body handling sensitive citizen data often chooses EU hosting anyway, because relying on a transfer mechanism adds legal and administrative overhead that an EU-based vendor avoids entirely. Our detailed article on whether GDPR requires EU data hosting covers the mechanisms and their limits in full.
Not universally. France's 'Cloud au Centre' doctrine effectively steers sensitive French public-sector workloads towards SecNumCloud-qualified providers, and C5 is a required baseline for federal public-sector procurement in Germany, though state and municipal rules can differ. Requirements vary by member state and by data sensitivity tier, so confirm the applicable national rule; there is no EU-wide mandate to fall back on.