Digital Samba English Blog

Sovereign Video Conferencing for the Public Sector | Guide

Written by Nina Benkotic | August 27, 2026

Since early 2026, sovereignty has moved from policy paper towards procurement clause. Reports in May 2026 suggested the European Commission was preparing a 'tech sovereignty package', and the Commission confirmed the plan on 3 June 2026 through the Cloud and AI Development Act (CADA). The proposal would bar US hyperscalers from the most sensitive government workloads in healthcare, finance, and justice. The concern isn't that those providers have done anything wrong. It's that the US CLOUD Act gives American authorities a legal route to data regardless of where it sits. Much of this is still proposed rather than in force, but France has already gone further in practice. It has rolled out its state-built video platform, Visio, with a target of replacing mainstream US conferencing tools across national agencies by 2027.

If your organisation issues public tenders, sovereignty isn't something you can plan for eventually. It's a live procurement question today, even though the EU-wide legal framework is still being finalised. For the underlying concept, our guide to what sovereign cloud actually means covers the fundamentals. This article is the practical follow-on: the certification schemes to specify, the use cases that trigger them, and a checklist for writing a tender that will hold up to scrutiny.

Table of contents

  1. Why sovereignty is now a public-sector procurement requirement
  2. The certification schemes public-sector buyers should look for
  3. Sovereign video in practice: public-sector use cases
  4. What to put in a sovereign video conferencing tender (RFP checklist)
  5. How Digital Samba supports public-sector sovereignty
  6. FAQ

Why sovereignty is now a public-sector procurement requirement

The policy direction is now explicit rather than aspirational. The Commission's proposals, put forward through CADA, would not ban US cloud providers from public contracts outright. They would introduce tiered restrictions based on data sensitivity, targeting sectors such as healthcare, finance, and justice, while leaving private-sector use largely untouched. Like any EU legislation of this kind, CADA still needs to clear the European Parliament and a qualified majority in the Council under the ordinary legislative procedure. It doesn't need a unanimous vote by all 27 member states. It isn't law yet either: none of its provisions are in force today.

A parallel initiative, the Cloud Sovereignty Framework (the Commission also publishes it as the Sovereign Cloud Framework), gives procurement teams a structured way to score providers. It rates them across eight dimensions, including legal jurisdiction, operational resilience, and supply chain transparency, on a five-tier Sovereignty Effectiveness Assurance Level (SEAL) scale running from SEAL-0 (No Sovereignty) to SEAL-4 (Full Digital Sovereignty). Keep it distinct from CADA itself, which sets out its own scale of four assurance levels that public bodies would apply according to their own risk assessment. Those run from data held on EU-located infrastructure at Level 1 to no third-country interference of any kind at Level 4. The two frameworks are related but separate, so a SEAL rating doesn't translate into a CADA level.

The Commission's own procurement gives a useful illustration of how the SEAL scale plays out in practice. In April 2026, it applied explicit sovereignty criteria to its own cloud procurement for the first time, awarding a €180 million contract over six years to four provider groups: Luxembourg's Post Telecom (with CleverCloud and OVHcloud), Germany's STACKIT, France's Scaleway, and Belgium's Proximus. Post Telecom, STACKIT, and Scaleway each reached SEAL-3, having no material non-EU supply chain dependencies. Proximus was awarded at the lower SEAL-2, because its consortium includes S3NS, a joint venture between Thales and Google Cloud. CISPE, the trade association representing 38 European cloud infrastructure providers, objected publicly: its secretary general called the decision to recognise S3NS as sovereign 'clearly an own goal' that 'threatens to institutionalize sovereignty washing at the highest levels'. For a procurement team the lesson is worth holding on to. A European name on the contract does not guarantee a European supply chain behind it, and that gap is exactly what a scored framework exists to expose.

National initiatives are moving in parallel. France's 'Cloud au Centre' doctrine has, since 2021, pushed sensitive public data towards SecNumCloud-qualified hosting, reinforced by a 2023 update, and the Visio rollout signals that the same logic now applies to the application layer, not just infrastructure. Germany has moved in a similar direction: Gaia-X adoption is growing among German public bodies, and the government folded digital sovereignty into a dedicated ministry, the Federal Ministry for Digital and State Modernisation (BMDS), created in May 2025. For public-sector video conferencing procurement teams, the practical upshot is that who can be compelled to hand over your data, and under which country's law, has become a scored criterion, not a footnote.

Visio itself shows what 'sovereign' can mean in practice. It isn't a commercial product bought off the shelf: it's a self-hosted platform, built on open-source WebRTC software, run on SecNumCloud-qualified infrastructure by France's own digital agency. Self-hosting a mature open-source stack, such as Jitsi Meet or BigBlueButton, is a legitimate route to sovereignty in its own right, not a consolation option. It hands full control of the infrastructure to the buyer. It also comes with real trade-offs: the operational burden of running and patching the platform falls on you, and it takes genuine in-house expertise to do it well. Most of this guide focuses on certifying and procuring a managed vendor, but decide early which route suits your organisation's resources, because it changes what the rest of your tender should ask for.

The certification schemes public-sector buyers should look for

Certification schemes vary in scope, legal weight, and evidentiary value. None of them alone guarantees GDPR-compliant video conferencing for government use, but together they let a procurement team build a defensible evidence base.

Scheme Administered by What it proves Relevance to video conferencing
EUCS (EU Cybersecurity Certification Scheme for Cloud Services) ENISA, under the EU Cybersecurity Act Baseline, substantial, and high-level cybersecurity controls for cloud services Still in draft, and the sovereignty-specific 'High+' tier, which would have added requirements on immunity from non-EU law, has been dropped from recent versions. An EUCS rating, even at the highest level, doesn't tell you whether a video platform's call recordings or transcripts can be reached under non-EU law.
SecNumCloud ANSSI (France) Technical security (360+ requirements) plus legal sovereignty: EU legal domicile, EU-only data storage, and immunity from extraterritorial law such as the US CLOUD Act The most stringent scheme in Europe and the reference point for French public-sector video tenders. Qualification requires proving that a video platform's call data, storage, and processing genuinely sit outside CLOUD Act reach, not just that its servers happen to be in the EU.
C5 (Cloud Computing Compliance Criteria Catalogue) BSI (Germany) Implemented security controls across governance, cryptography, and operations A required baseline for federal public-sector procurement in Germany. It attests to a video vendor's security controls, such as encryption key handling and incident response, but not to jurisdictional independence: a C5-attested provider with a non-EU parent can still carry CLOUD Act exposure.
Gaia-X Label / Trust Framework Gaia-X European Association (Brussels-based, founded by France and Germany) Federated, verifiable compliance with sovereignty, transparency, and interoperability principles, across labelling tiers Increasingly referenced in sovereignty discussions, and Gaia-X is lobbying for CADA to reference its labelling scheme directly. For now, CADA applies its own separate assurance levels and does not require a Gaia-X label. For a video platform, a Gaia-X label signals transparency about data flows and subprocessors, which makes it useful alongside a scheme like SecNumCloud. On its own it proves much less.
GDPR baseline EU-wide (supervisory authorities) Lawful processing, data subject rights, cross-border transfer safeguards The legal floor every public-sector video tool must meet for call recordings, transcripts, and AI-generated summaries, but compliance alone doesn't establish sovereignty: GDPR-adequate processing can still coexist with CLOUD Act exposure.

The practical takeaway for a tender: GDPR compliance is table stakes, C5 is a required security floor for German federal procurement and increasingly expected by German state and municipal buyers too, and SecNumCloud (or a comparable national qualification) is the strongest available proof of actual sovereignty for a video platform. Of everything in the table, it is the only scheme that addresses legal jurisdiction head-on; the others stop at technical controls.

Sovereign video in practice: public-sector use cases

Different parts of government trigger sovereignty requirements for different reasons. A tender should address each use case on its own terms.

Secure internal government meetings

Cabinet-level discussions, interdepartmental coordination, and classified or restricted briefings make the clearest case for government video conferencing that keeps data and metadata within a defined jurisdiction: the sensitivity of the content itself is the trigger, independent of any specific regulation.

Courts and justice

Judicial proceedings, remote hearings, and case-related consultations fall squarely within the sectors the EU's proposed restrictions single out by name. Recordings, transcripts, and case metadata generated during a hearing carry the same sensitivity as the underlying case file, so the sovereignty requirement extends to storage and processing of session recordings as well as the live call.

Public healthcare and telehealth

Health data is one of the three sectors explicitly named in the Commission's tiered-restriction proposals, alongside finance and justice. A public health authority running telehealth consultations needs video conferencing for government-run clinical services where patient data, including any AI-generated consultation summaries, stays within EU jurisdiction and is handled in line with GDPR.

Education

Public schools and universities increasingly deliver classes, oversee exams, and hold safeguarding-related meetings over video. The current tiered-restriction proposals don't name education. Even so, national data protection authorities in several member states already expect EU hosting for pupil and student data, which makes sovereign hosting a practical requirement in places where no rule strictly mandates it.

Citizen-facing services (embedded and white-label)

Local authorities embedding video consultations into benefits applications, planning appeals, or citizen advice portals need public-sector video conferencing that can be white-labelled into an existing digital service, while still meeting the same hosting and jurisdictional requirements as internal use. Citizen data carries the same sensitivity whether it arrives through a public-facing form or an internal call.

What to put in a sovereign video conferencing tender (RFP checklist)

A tender for sovereign video conferencing procurement should go beyond a general data-protection clause and specify verifiable, auditable requirements. One caution before the checklist: this doesn't mean you can simply write 'EU-owned providers only' into a tender and exclude everyone else. Under the EU's public procurement rules (Directive 2014/24/EU) and the World Trade Organization's Government Procurement Agreement, contracting authorities must treat bidders equally regardless of nationality, with only narrow exceptions such as national security. The items below work as disclosure and evaluation criteria that a bidder has to answer and be scored against, not as grounds for a blanket nationality-based exclusion. Check any exclusion clause with your procurement lawyers before it goes out. At minimum, the tender should cover:

  • Legal and corporate structure. Require disclosure of the provider's parent company jurisdiction, ownership structure, and any exposure to extraterritorial legislation such as the US CLOUD Act. A provider headquartered outside the EU, even with EU data centres, may still be compellable under its home jurisdiction's law.
  • Data residency and processing location. Specify where all call data, recordings, transcripts, chat logs, and any AI-generated summaries are stored and processed, and require that no traffic is routed by default through non-EU infrastructure for load balancing, transcription, or support functions. Decide explicitly which standard you are setting, because two different ones are in play. GDPR permits transfers to countries covered by an adequacy decision, so a provider holding capacity in the UK is on solid legal ground. Sovereignty is a stricter test, and a buyer who wants the operational chain inside the EU or EEA has to say so, because adequacy alone will not deliver it. Whichever standard you set, put it in writing and ask the bidder to evidence it, so that a disagreement about scope surfaces during evaluation instead of in year two.
  • Certification evidence. Ask for current status against SecNumCloud, C5, or an equivalent national scheme, plus a statement on EUCS and Gaia-X label alignment, backed by audit documentation you can actually check. Ask where the bidder sits on the SEAL scale and on what basis, since it is the measure the Commission applied to its own procurement. Expect most answers to be a vendor's own assessment against the framework rather than a rating awarded in a tender. A marketing claim of 'sovereignty' on its own proves nothing.
  • Encryption architecture. Require details on transport encryption (DTLS-SRTP is the WebRTC standard), and decide upfront which sessions need full end-to-end encryption and which need server-side recording or transcription. True end-to-end encryption means no server, including the provider's own, can read the media, so it rules out server-side recording and transcription of that same session. Ask for a clear technical description of key management for whichever sessions use end-to-end encryption, and of who, if anyone, can access session content for the rest.
  • Subprocessor transparency. Request a full list of subprocessors, including any dependency on non-EU cloud infrastructure providers, CDNs, or TURN/STUN relay services. A sovereignty claim is only as strong as its weakest subprocessor link.
  • Data subject and incident response commitments. Specify contractual response times for data subject access requests and breach notification that meet GDPR obligations, written into the contract itself.
  • Interoperability and embedding. For citizen-facing use cases, require API and SDK access that lets the video experience be embedded into existing government digital services, with webhook-based session and recording events fully documented.
  • Exit and data portability. Require a documented process for extracting call recordings, transcripts, and usage data on contract termination, in an open format, without dependency on the outgoing provider's continued cooperation.
  • Audit rights. Reserve the right to commission or review independent security audits over the contract term. Point-in-time certification alone won't tell you how a vendor is actually operating in year three of the contract.

How Digital Samba supports public-sector sovereignty

Digital Samba is registered in Spain, and our competent supervisory authority is the AEPD (Agencia Española de Protección de Datos). There is no non-EU parent company in our ownership structure, which answers the first item on the checklist above: there is no ownership chain running back to an entity exposed to the US CLOUD Act.

Our production infrastructure runs in the Netherlands, with backup infrastructure in Germany. Overflow capacity at peak demand sits with two European providers, one inside the EU and one in Switzerland. The Swiss capacity rests on adequacy rather than EU or EEA residency, which clears GDPR transfer rules but not a stricter EU-only requirement. Our security whitepaper names each infrastructure provider, where it operates and the certifications it holds.

We have designated a Data Protection Officer under GDPR Article 37, we maintain Records of Processing Activities under Article 30, and we carry out data protection impact assessments for high-risk processing. On the certification schemes themselves, and on ISO 27001 too, our controls are documented rather than certified: Digital Samba's information security management system uses ISO 27001:2022 as a reference framework, which is a general information security standard rather than a sovereignty scheme. We are working towards formal certification against it. If your evaluation needs the underlying documentation, or anything we have not covered here, our security team can be reached at security@digitalsamba.com and answers compliance and diligence questions directly.

For procurement teams that want infrastructure control beyond a managed EU-hosted service, we also offer an on-premises deployment option, which puts the whole infrastructure environment under your control. Our REST API, embeddable SDK and webhook-driven session and recording events let an integrator embed video into a citizen-facing service and see exactly what happens to call data at each stage, which is what the interoperability item asks for. For healthcare and justice, where AI-generated summaries need to stay within the same jurisdictional boundary as the underlying call, the relevant detail sits in our security and encryption architecture and our EU-hosted transcription and AI meeting summary capabilities.

Writing a tender that holds up

Write the tender so a bidder can't wave a certificate around and call it done. Ask for evidence instead of assurances, and match what you ask for to what the use case actually needs. The rules are still being finalised at EU level, so expect this area to keep moving. Build a tender that asks the right questions now, and you won't have to rewrite it every time a new regulation lands.

FAQ

What certifications should a public-sector body require for sovereign video conferencing?

At minimum: GDPR-compliant processing as a baseline, plus evidence against a recognised sovereignty scheme such as SecNumCloud in France or C5 in Germany, and a statement on EUCS and Gaia-X label status. Which of these matters most depends on the sector: courts and healthcare warrant the strictest evidence, while an internal scheduling tool for a local council might reasonably ask for less.

Can government bodies legally use US-owned video conferencing tools?

Currently, yes, in most cases. The EU's proposed restrictions target specific sensitive sectors: healthcare, finance, and justice. There is no blanket ban. CADA also still has to clear the European Parliament and win a qualified majority in the Council before it takes effect, and it does not need a unanimous vote of all 27 member states. Several national governments, France among them, are already moving to sovereign alternatives ahead of any binding EU-wide rule.

Does GDPR require EU hosting for government video calls?

Not explicitly. GDPR allows data to move outside the EU under specific legal mechanisms, such as an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules. In practice, a public body handling sensitive citizen data often chooses EU hosting anyway, because relying on a transfer mechanism adds legal and administrative overhead that an EU-based vendor avoids entirely. Our detailed article on whether GDPR requires EU data hosting covers the mechanisms and their limits in full.

Is SecNumCloud or C5 mandatory for public-sector video conferencing?

Not universally. France's 'Cloud au Centre' doctrine effectively steers sensitive French public-sector workloads towards SecNumCloud-qualified providers, and C5 is a required baseline for federal public-sector procurement in Germany, though state and municipal rules can differ. Requirements vary by member state and by data sensitivity tier, so confirm the applicable national rule; there is no EU-wide mandate to fall back on.

Sources

  1. ANSSI / cyber.gouv.fr. (n.d.). Référentiels d'exigences pour la qualification.
  2. BSI (Bundesamt für Sicherheit in der Informationstechnik). (2026, May 28). C5: FAQ.
  3. CNBC. (2026, May 7). EU weighs restricting use of U.S. cloud platforms to process sensitive government data, sources tell CNBC.
  4. DINUM (Direction interministérielle du numérique). (n.d.). La doctrine cloud au centre.
  5. ENISA (European Union Agency for Cybersecurity). (2020, December 22). EUCS: cloud services scheme.
  6. Euronews. (2026, January 27). France to ditch US platforms Microsoft Teams, Zoom for sovereign platform amid security concerns.
  7. European Commission. (2026, April 17). Commission advances cloud sovereignty through strategic procurement.
  8. European Commission. (2026, June 1). Sovereign Cloud Framework explained.
  9. European Commission. (2026, June 3). Strengthening Europe's tech sovereignty.
  10. European Commission. (n.d.). Proposal for the Cloud and AI Development Act (CADA).
  11. European Parliament. (n.d.). Cloud and AI Development Act: Legislative Train Schedule.
  12. Gaia-X European Association. (2026, June). Position paper: why the Cloud and AI Development Act needs trust, governance and interoperability.
  13. Raconteur. (2026, June 2). EU restricts US cloud services plan: key rules and questions.
  14. The Register. (2026, April 20). Europe picks 4 sovereign cloud providers, but one has Google inside.