FRANKFURT not the Cloud Act
Europe has changed its position on the cloud. What was argued for years as a policy question has arrived in procurement departments. The latest Cloud Report from the German digital association Bitkom puts numbers to a shift that companies across Europe will recognise from their own boardrooms.
The Findings
85 percent of surveyed companies with 20 or more employees consider their dependence on US cloud providers too high. A year earlier the figure was 78 percent. The representative study covered 603 companies.
The gap between reality and preference is even more striking. 71 percent currently source cloud services from the US, yet only 8 percent would choose that origin if given a free hand. For domestic providers the ratio inverts: 53 percent use them today, 91 percent would prefer to.
That is a gap of almost 40 percentage points between what organisations buy and what they want to buy. The survey was conducted in Germany, but nothing in the underlying logic is specific to one country. Every organisation operating under the GDPR faces the same conflict between a legal framework that limits third country transfers and a supplier market dominated by companies headquartered outside the EU.
Discomfort has turned into willingness to act
More telling than the awareness is the willingness to pay for it. 37 percent would now choose a solution that processes data exclusively within their own country and shields it from foreign access, even at the cost of a higher price or a narrower feature set. The year before, 27 percent said the same.
And 64 percent of cloud users say US government policy is forcing them to reconsider their existing approach, up from 50 percent a year earlier.
This is the actual turning point. Sovereignty has stopped being a bonus criterion. It is now weighed against functionality and price, and it sometimes wins.
What actually decides a supplier choice
The report also shows which criteria carry weight. Trust in data protection, IT security and compliance ranks first at 95 percent, followed by performance and stability at 91 percent, data encryption at 89 percent, and protection against unauthorised access including access by the provider itself at 87 percent. The provider’s country of origin reaches 61 percent and the location of the data centres 57 percent.
So sovereignty does not sell on its own. It sells where it answers a concrete security question: who can reach the data, and under which legal system?
This is exactly where many offers stay vague. 87 percent of companies criticise a lack of transparency about data processing and access rights in the sovereign offerings of international providers. Germany’s Centre for Digital Sovereignty has explicitly warned about offers that promise sovereignty without anchoring it structurally.
Why this concerns software training directly
Training sessions involve something the sovereignty debate tends to overlook: real data flows through them. Participant lists with names, email addresses and company affiliations. In product training, often sample datasets, configurations or test data drawn from customer systems.
If your training computers run on a US hyperscaler, or on that hyperscaler’s European subsidiary, this data sits in an infrastructure subject to the CLOUD Act. A subsidiary registered in Ireland, the Netherlands or Germany does not change that, because the CLOUD Act attaches to control by the US parent company, not to the location of the servers. Offerings marketed as a “sovereign cloud” remain covered as long as the parent sits in the United States.
For training providers this has two consequences. First, hosting questions now appear routinely in tender processes, particularly from public sector, financial services and industrial clients. Second, the answer can be turned into a selling point rather than treated as a compliance nuisance.
The Lünendonk study 2026 on digital sovereignty supports this shift: 93 percent of surveyed companies now regard European cloud providers as competitive at infrastructure level. The argument that no real alternative exists no longer holds.
What this means in practice
Anyone offering software training should be able to answer three questions, and should communicate the answers actively:
Who operates the infrastructure? Not the region setting of a hyperscaler and not the registered office of a subsidiary, but the physical data centre and the corporate ownership of the operator.
Who has access? Technical access by the provider, sub-processors, and the legal system that applies to them.
What happens after the training? How long do environments and participant data persist, and how are they deleted?
These three answers increasingly determine whether a training offer survives a procurement process.
deskMate
deskMate is built for precisely this requirement. The Virtual Training Desktops run on Kivito’s own servers in Frankfurt am Main, with no US hyperscaler involved and no European subsidiary of one. Processing takes place exclusively within the EU, and the service is fully GDPR compliant.
The training computers within a session are networked with each other but completely isolated from every other session. When a training ends, the machines are deleted automatically and in full, not merely unassigned from their users.
And the effort involved stays minimal. A complete training environment with user accounts, access links, training computers and Trainer View is ready in under a minute, fully automatically.
If you want to see what that looks like for your own training sessions, get in touch. We will show you in 15 minutes.
