---
title: "Sovereignty Strategy & Cloud Advisory: Navigating Your Journey to STACKIT"
description: "Digital sovereignty as a strategic decision: GDPR-native architecture, Cloud Act immunity, the three-tier workload classification and STACKIT as a sovereign cloud provider."
sidebar:
  order: 5
  label: "Sovereignty Strategy"
source_url: "https://framework.stackit.cloud/advisory/cloud-vision-and-strategy/sovereignty/"
source_file: "docs/advisory/cloud-vision-and-strategy/sovereignty.mdx"
---

## Why sovereignty is a strategy, not a feature

Many organisations treat data sovereignty as a compliance checkbox. That is a mistake. Sovereignty is a strategic decision with profound consequences for provider selection, IT architecture, contract design and competitive positioning.

**The core question is not:** "Are we GDPR-compliant?"
**The core question is:** "Who has access to our data in an emergency — and can we control that?"

## The CLOUD Act: A concrete risk for Regulated Industries

The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) empowers US authorities to demand access to data from US companies — regardless of where that data is physically stored.

**The Reality:** Even if your data sits in a data centre in Frankfurt, a US provider may be legally obliged to hand that data to US authorities.

For organisations in highly regulated sectors this is not a theoretical risk but a concrete compliance and operational bottleneck:

- **Automotive:** TISAX requirements
- **Banking & Finance:** BAIT / DORA compliance
- **Healthcare:** KHZG regulations
- **Critical Infrastructure:** KRITIS / NIS-2 directives

## STACKIT: The Sovereign Cloud Alternative

STACKIT (the digital brand of Schwarz Digits, the IT powerhouse of the Schwarz Group) offers a distinct alternative to non-European hyperscalers. It is designed to completely eliminate third-country access risks.

### Key Sovereignty Characteristics

| Characteristic                        | Significance                                                                                          |
| ------------------------------------- | ----------------------------------------------------------------------------------------------------- |
| **German company**                    | No US Cloud Act risk — no obligation to disclose to US authorities                                    |
| **Data centres in Germany & Austria** | GDPR-native data residency, Art. 44 GDPR not a concern                                                |
| **Open standards**                    | Built on OpenStack, Kubernetes, Terraform — zero proprietary vendor lock-in                           |
| **Contractual guarantees**            | DPA per GDPR Art. 28, transparent data processing agreements, and a dedicated Data Protection Cockpit |
| **BSI C5 attestation**                | Demonstrated high-level security controls under the premier German standard                           |

### The Four Pillars of STACKIT Sovereignty

1. **Legal Sovereignty:** Data is stored and processed exclusively under European jurisdiction, shielded from extraterritorial laws.
2. **Technological Freedom:** Open-source architectures ensure maximum transparency, code auditability, and effortless interoperability.
3. **Organizational Independence:** Migration patterns and exit strategies are designed so you always retain absolute control over your operational data.
4. **Economic Stability:** Backed by the financial strength of the Schwarz Group, ensuring long-term operational viability free from volatile market shifts.

## Our 4-Phase Cloud Advisory Journey

Transitioning to a sovereign cloud requires a structured roadmap. We guide your organization from initial assessment to fully compliant, continuous operations on STACKIT.

![4-Phase Cloud Advisory Journey](./files/cloud-advisory-journey.svg)

### Phase 1: Sovereignty & Readiness Assessment

We audit your current IT landscape to identify third-party dependencies, map shadow IT, and classify your existing workloads based on regulatory and organizational needs.

### Phase 2: Strategic Architecture Design

We design hybrid or multi-cloud target architectures using open-source standards. This includes setting up secure zones, planning exit strategies, and ensuring complete interoperability.

### Phase 3: Migration & Compliance Integration

We align STACKIT's native security controls with your specific regulatory frameworks (BSI IT-Grundschutz, ISO 27001, GDPR). We then execute migration playbooks, beginning with low-risk pilots before moving core systems.

### Phase 4: Continuous Governance & AI Evolution

We establish sovereign GRC (Governance, Risk, Compliance) automation and lay the groundwork for adopting secure, sovereign AI models hosted entirely within STACKIT's secure infrastructure.

## Our Methodology: Three-Tier Workload Classification

Not all workloads have the same sovereignty requirements. To avoid over-engineering or unnecessary costs, we classify your applications into three distinct tiers:

### Tier 1: Sovereignty-mandatory

**Criteria:** Regulatory or contractual obligation for local data storage and processing; data that creates severe liability risks if accessed by foreign authorities; sensitive personal data (Art. 9 GDPR).

**Examples:** Core customer data, health records, financial transactions, TISAX-classified development files, and KRITIS control systems.

**Requirement:** Exclusively STACKIT (or equivalent sovereign cloud). No deployment on US hyperscalers.

### Tier 2: Sovereignty-preferred

**Criteria:** No hard regulatory veto, but elevated protection needs. Data that would cause reputational damage or competitive disadvantage if compromised.

**Examples:** ERP systems, HR databases (without special categories of personal data), internal communication platforms, and proprietary product designs.

**Requirement:** STACKIT preferred; other secure European providers acceptable. US hyperscalers are not recommended.

### Tier 3: Flexible

**Criteria:** No personal data, non-sensitive operational data, or public-facing assets where speed and global reach outweigh strict sovereignty.

**Examples:** Public websites, CDN content, open-source build artifacts, and isolated development sandboxes.

**Requirement:** Any cloud provider is acceptable.

### The Sovereignty Decision Tree

To determine where your workloads belong, we guide you through five core questions:

![Sovereignty Decision Tree](./files/sovereignty-decision-tree.svg)

## Practical steps

Securing your digital sovereignty is an active process. We work alongside your teams to execute these immediate, practical steps:

1. **Step 1:** Create workload inventory — Build a comprehensive directory of all applications and their respective data categories
2. **Step 2:** Sovereignty workshop — Bring together CISO, DPO and legal department to complete the three-tier classification
3. **Step 3:** Establish the sovereignty matrix — Set up a living, audited document that assigns clear ownership and hosting rules for every workload
4. **Step 4:** Appoint a Data Sovereignty Officer — Define clear accountability and sovereignty governance for cloud operations
5. **Step 5:** Contractual safeguarding — Finalize DPAs with STACKIT, configure the Data Protection Cockpit to match your security baseline.
