Trusted cloud, act II: from Microsoft 365 to SecNumCloud, the case law reshuffling the deck | europeanGPU
← All articles Cloud & compliance

Trusted cloud, act II: from Microsoft 365 to SecNumCloud, the case law reshuffling the deck

3 July 2026·Read: 6 min

An Austrian ruling on Microsoft 365 Education, a Polytechnique case back in the spotlight, a framework agreement nonetheless extended: European cloud doctrine is advancing in zigzags. CIOs, meanwhile, must decide now.

Digital sovereignty is rarely decided in grand speeches; it is decided in litigation. Two cases reminded us of that this spring. In Austria, the data protection authority ruled that the use of Microsoft 365 Education violated the GDPR, notably because controllers were unable to genuinely master the data flows and the subcontracting chain. In France, the case of Polytechnique's choice of Microsoft returned to the foreground in early June, with the specialist press seeing it as a precedent likely to reshuffle the deck for the entire public sector. At the same time — and there lies the paradox — the framework agreement binding the national education ministry to the American vendor was extended.

What these rulings really say

What these cases have in common is not the anti-Americanism sometimes attributed to them. It is a question of effective control: who can access the data, under which law, with which enforceable guarantees? Since the Schrems-style invalidation of the Privacy Framework, every transfer arrangement rests on impact assessments that authorities now examine line by line. American law — FISA 702, the CLOUD Act — remains applicable to American providers wherever the data is hosted. No contractual clause neutralises a foreign overriding statute: it is this purely legal observation that regulators are beginning to follow through to its conclusion.

SecNumCloud, from doctrine to purchasing criterion

On the French side, ANSSI's SecNumCloud qualification is progressively establishing itself as the dividing line: beyond the technical requirements, it imposes a criterion of immunity from extraterritorial legislation via ownership and governance conditions. The "cloud at the centre" doctrine in principle reserves the state's sensitive data for qualified offerings. What changes in 2026 is the contagion beyond the state: regulated operators, healthcare, education, local authorities — and, by ricochet, their suppliers. For a software vendor, being deployable at a qualified host, or on-premise, becomes a first-rank commercial argument, not a compliance checkbox.

What CIOs can do without waiting

First, map by criticality rather than by comfort: which data, which processing genuinely require extraterritorial immunity? The honest answer is rarely "everything", but it is never "nothing". Second, demand reversibility from the contract onwards: open formats, documented export, capped exit costs. Third, encrypt with keys under your own control when the workload stays with a hyperscaler — keeping in mind that encryption does not protect data being processed. Fourth, build "sovereign pockets": rather than an illusory total migration, isolate the critical use cases on qualified offerings or on-premise, and own the hybrid for the rest.

The weak signal to watchThe multiplication of national data protection authority rulings is creating de facto case law faster than legislation. A prudent CIO now reads the decisions of Europe's privacy regulators the way they once read security advisories.

Act II of the trusted cloud will not be a revolution. It will be an accumulation of rulings, tenders and contract renewals in which, case after case, the question of effective control weighs a little heavier. Organisations that have prepared their sovereign pockets will decide with a clear head. The others will endure the regulators' calendar.

Also worth reading

Strategy · 6 min

Happy dependence? Why Europe will not leave the hyperscalers in 2026

No European player will leave AWS, Azure or Google Cloud in the short term. Five moves to turn an endured dependence into a managed one.

22 August 2026

Regulation · 6 min

AI Act: enforcement time has come — what actually changes since 2 August

The regulation has been enforced since 2 August. The real issue for European vendors is no longer the text, but the NIS2, CRA, GDPR, AI Act stack.

8 August 2026

Infrastructure · 6 min

Sovereign on-premise LLMs: the credible alternative to American APIs

Mature open models, accessible GPUs, growing constraints: local inference has become a rational architecture option.

17 August 2026

Does this topic concern you directly?

Book a meeting: we gladly turn an article into an answer to your specific case, with your hosting and compliance constraints.

Book a meeting