<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Compliance on AWS McMillearn Blog</title><link>https://aws.mcmillearn.net/categories/compliance/</link><description>Technical blog focused on AWS best practices and architecture patterns on AWS McMillearn Blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>John McMillan</managingEditor><webMaster>John McMillan</webMaster><lastBuildDate>Tue, 27 Jan 2026 09:00:00 +0000</lastBuildDate><atom:link href="https://aws.mcmillearn.net/categories/compliance/index.xml" rel="self" type="application/rss+xml"/><category>AWS</category><category>Cloud Computing</category><category>DevOps</category><category>Architecture</category><item><title>Why Cloud sovereignty suddenly matters.</title><link>https://aws.mcmillearn.net/posts/aws-eu-sov-cloud/</link><pubDate>Tue, 27 Jan 2026 09:00:00 +0000</pubDate><author>John McMillan</author><guid>https://aws.mcmillearn.net/posts/aws-eu-sov-cloud/</guid><description>What is Sovereignty and do your need it?</description><content:encoded><![CDATA[<h1 id="disclaimer">Disclaimer</h1>
<p><em><strong>AKA: Are you sure you want to read this?</strong></em><br>
Okay - so this isn&rsquo;t my typical technical approach to blogging.
This topic is regulatory heavy - unavoidably so if you&rsquo;re to understand and navigate it. You have been warned :).</p>
<h1 id="intro">Intro</h1>
<p>You might have noticed the world feels slightly less keen on being stable and predictable. Geopolitics, trade, and national interest are clashing more openly. Cloud computing is an area where we see some of the downstream consequences as a result. The &lsquo;Cloud&rsquo; has a truly global presence, and so perhaps it&rsquo;s unsurprising that it isn&rsquo;t immune from politics. Companies like AWS made it possible for organisations of any size to start small and grow rapidly to a huge global scale - &ldquo;reach your clients wherever they are&rdquo; - that wasn&rsquo;t by magic. It was <em>because</em> the cloud went global.</p>
<p>The cloud, being global by design, blurred many traditional boundaries. In doing so it made possible faster innovation and global reach to anyone with a good idea and the will to act on it. It also quietly blurred some legal and jurisdictional boundaries.</p>
<p>Over the past 10 years, laws like the <a href="https://www.justice.gov/criminal/cloud-act-resources">CLOUD Act</a> and before that, the PATRIOT Act, have forced business leaders and their legal teams to contemplate some uncomfortable, but legitimate, questions. e.g. <em>&ldquo;Who can access my data, and under what circumstances?&rdquo;</em>.</p>
<p>Some of these laws create the possibility that their corporate data, user data, or intellectual property held by a US based service provider, could be subject to a lawful access request from US legal authorities. Potentially without the client knowing.</p>
<p>Companies like AWS have offered strong assurances that they&rsquo;ll challenge overreach and advise any clients when this happens if they&rsquo;re legally permitted to. And they provide strong mechanisms to protect your data from unauthorised access, e.g. Nitro, which we&rsquo;ll take about later.
See <strong>&ldquo;How does AWS handle Law enforcement requests?&rdquo;</strong> in their <a href="https://aws.amazon.com/compliance/cloud-act/">CLOUD Act FAQs</a>.</p>
<p>But AWS don&rsquo;t need me to fight their corner. They have a few more resources than I have to throw at that.</p>
<p>Either way, Sovereign Cloud is here. It&rsquo;s up to us as IT professionals to understand what that means for us, our employers, clients, and their users.</p>
<p>In this blog I&rsquo;ll look at what Sovereignty is, what it&rsquo;s not - and how to avoid common missteps, e.g. that data residency equates to digital sovereignty. It doesn&rsquo;t.</p>
<h2 id="sovereignty">Sovereignty</h2>
<p>The Oxford English dictionary defines Sovereignty as&hellip;. no, that would be awful. :)</p>
<p>Digital Sovereignty is about a few things.</p>
<ul>
<li>Control - which outsiders can impact you, derail your business, or access your data?</li>
<li>Jurisdiction - which legal systems have authority over your data, applications, and services?</li>
<li>Auditability - who&rsquo;s done what, where, and when - and can I prove that to auditors?</li>
<li>Security - how do I protect my data and access to my systems?</li>
<li>Accountability - who am I answerable to? Users, regulators, shareholders, etc</li>
<li>Residency - where is my data located?</li>
<li>Operations - who manages, operates, and maintains my systems?</li>
</ul>
<p>You might be thinking, <em>some of those overlap</em>. Yup. The factors that contribute to Sovereignty do overlap somewhat.</p>
<p>So think about it this way:<br>
If your important data is <strong>classified correctly</strong>, you know <strong>where it is</strong> and it&rsquo;s <strong>confined to where you want</strong> it to be, you understand how to <strong>control access</strong> to it, you can audit <strong>who&rsquo;s had access</strong>, you know <strong>who you&rsquo;re subject to</strong> in terms of regulatory bodies &amp; compliance frameworks, <strong>who needs access</strong> to your systems, <strong>who <em>has</em> access</strong> to your systems, then you&rsquo;re in a good position.</p>
<p>If you answered positively to those then you&rsquo;re well on the way to understanding what Sovereignty is, and which aspects apply to you.</p>
<h3 id="what-sovereignty-isnt">What Sovereignty isn&rsquo;t</h3>
<p><strong>Data residency (location) is not Digital Sovereignty.</strong>
It&rsquo;s likely that some clients will ask for Sovereign solutions when in actual fact, they&rsquo;re really concerned about data residency and security. Helping those clients understand the difference between where data can be stored and secured (Residency) and who can legally compel access (legal Jurisdiction) is a difference to be understood.</p>
<p><em><strong>Make my solution fully Sovereign - retrospectively</strong></em><br>
If a client states that they want to keep their existing solution but &ldquo;make it Sovereign&rdquo;&hellip; that&rsquo;s not necessarily impossible, but it&rsquo;s tricky. Sovereignty is a design time decision. To achieve the best possible sovereign posture for your solution, the design needs to factor in the Sovereignty objectives and address each where possible. (good luck with Supply Chain Sovereignty).</p>
<p><em><strong>I want to increase my Sovereignty without compromise</strong></em><br>
For some clients, the appeal of being sovereign and independent from foreign owned companies will be appealing.</p>
<h2 id="eu-sentiment">EU Sentiment</h2>
<p>I won&rsquo;t spend time talking about the <a href="https://www.europarl.europa.eu/RegData/etudes/ATAG/2020/652073/EPRS_ATA(2020)652073_EN.pdf">Schrems II ruling</a>, but I&rsquo;d recommend having a look into that for some context - it gets to the heart of some of the trust issues that are at the centre of the CLOUD Act, conflicting national interests, and the EU position on the subject.<br>
Suffice it to say, the EU have been concerned for some time about their belief that a lack of equivalence exists in data protection laws between the EU and US, and this creates risk for EU based organisations using US based cloud providers.</p>
<p>On the point of <strong>trust</strong> — it’s an important distinction to make, but the European Commission created the EU Sovereign Cloud framework because the EU considers foreign legal reach to be a risk that could undermine things like GDPR, not because it distrusts cloud technology.</p>
<p>Organisations that are subject to foreign legal obligations, such as the US CLOUD Act, may be viewed through a sovereignty lens as presenting a potential avenue for legal overreach.</p>
<h3 id="enter-the-eu-cloud-sovereign-framework">Enter the EU Cloud Sovereign Framework</h3>
<p>It&rsquo;s no surprise then that the EU decided to produce a framework that helps organizations assess their current sovereignty posture and to provide some clear guidance and metrics in the form of the <a href="https://commission.europa.eu/document/download/09579818-64a6-4dd5-9577-446ab6219113_en?filename=Cloud-Sovereignty-Framework.pdf">EU Cloud Sovereignty Framework</a>.</p>
<h3 id="what-does-the-framework-define">What does the framework define</h3>
<p>It&rsquo;s definitely worth reading the <a href="https://commission.europa.eu/document/download/09579818-64a6-4dd5-9577-446ab6219113_en?filename=Cloud-Sovereignty-Framework.pdf">framework</a>, it&rsquo;s actually very concise considering what it is, but in the meantime, I&rsquo;ll summarise here:</p>
<h4 id="seal-scores">SEAL scores</h4>
<p>The document explains the concept of SEAL scores - <strong>Sovereignty Effectiveness Assurance Level</strong>.<br>
There are eight contributing &lsquo;Sovereignty Objectives&rsquo;, and a related formula that accounts for different weightings, that provide the inputs for calculating the SEAL score of a platform or solution.</p>
<h4 id="sovereign-objectives-the-factors">Sovereign Objectives (the factors)</h4>
<ul>
<li><strong>Strategic Sovereignty</strong> - This assesses the supplier&rsquo;s ownership stability, governance influence, &amp; alignment with EU Strategic priorities.</li>
<li><strong>Legal &amp; Jurisdictional Sovereignty</strong> - Evaluates the legal environment, exposure to foreign authority, &amp; enforceability of rights.</li>
<li><strong>Data &amp; AI Sovereignty</strong> - Focuses on how data and AI services are secured, protected, controlled, where they&rsquo;re located, and where they&rsquo;re processed from.</li>
<li><strong>Operation Sovereignty</strong> - Assess the ability of EU based organizations to support, patch, maintain, service, and evolve a technology or solution independent of non-EU control.</li>
<li><strong>Supply Chain Sovereignty</strong> - Evaluates the geographic origin, transparency, and resilience of the supply chain, with a specific focus on the extent critical components are or aren&rsquo;t controlled by the EU.</li>
<li><strong>Technology Sovereignty</strong> - Considers the degree of transparency and independence in the technology stack. Can EU organizations, operate the technology, audit it, and evolve it without lock-in to foreign owned systems.</li>
<li><strong>Security &amp; Compliance Sovereignty</strong> - Assesses the extent to which security operations, compliance obligations, and resilience are controlled within the EU, without reliance on foreign jurisdictions.</li>
<li><strong>Environmental Sustainability</strong> - This assesses the autonomy &amp; resilience of cloud services over the long term in relation to energy usage, dependency, and raw material security. (aka - can you be Sovereign if you&rsquo;re not energy independent and someone else can switch off the lights?)</li>
</ul>
<p>The framework goes into more detail about some of the specific examples and criteria they look for and assess in each of those factors. At this stage I just wanted to give you some relevant context to frame the Hyperscaler response, where it works and where it doesn&rsquo;t.</p>
<h2 id="hyperscaler-response">Hyperscaler response</h2>
<p>I&rsquo;ve stated outright that I personally operate in the AWS arena - other hyperscalers are taking this seriously too - but I&rsquo;ll talk about how AWS are now facing up to the sovereignty challenge in the EU.</p>
<h3 id="enter-eu-aws-sovereign-cloud">Enter EU AWS Sovereign Cloud.</h3>
<p>AWS first announced plans for their EU Sovereign Cloud business in October 2023. In January 2026, following €8 billion investment, AWS formally announced general availability of its EU Sovereign Cloud located in Germany.</p>
<blockquote>
<p>&ldquo;<em>The AWS European Sovereign Cloud is a new, independent cloud for Europe entirely located within the European Union (EU), designed to help customers meet their evolving sovereignty requirements.</em>&rdquo;</p>
</blockquote>
<p>AWS conceived and built the EU Sovereign Cloud to be &ldquo;Sovereign-by-design&rdquo;. AWS have worked with various EU organizations to gather the needs of clients who are interested in Sovereign Cloud. In that sense it&rsquo;s a genuine attempt at a purpose built Sovereign Cloud. You can see the thought that&rsquo;s gone into that when you look at service availability. For example, at the time I write this there are only two Foundational Models available in <code>eusc-de-east-1</code> under Amazon Bedrock - &lsquo;Nova Lite&rsquo; and &lsquo;Nova Pro&rsquo;.<br>
Is that just taking time to roll out services and features, or is it regulation making vendors think carefully and seriously about risk, compliance, &amp; governance?</p>
<p>If you&rsquo;re already familiar with AWS, then EU Sovereign Cloud won&rsquo;t initially look any different. In many respects it looks and behaves like any other AWS Region.
As with AWS Regions, there&rsquo;s variation in number of Availability Zones (<code>eusc-de-east-1</code> has two), variation in service/feature availability, and pricing differences.</p>
<p>The sole purpose of AWS&rsquo;s investment in the EU Sovereign Cloud is to offer, as close as is achievable, a truly sovereign platform for the EU. In their words, from the</p>
<p>Does it manage that? Let&rsquo;s look first at how AWS&rsquo; EU Sovereign cloud measures up to the framework:</p>
<p><strong>Strategic Sovereignty</strong></p>
<p>AWS EU Sovereign Cloud is owned by &ldquo;AWS European Sovereign Cloud GmbH&rdquo;, a German registered company - who are themselves 100% owned the US based Amazon.
Although, the AWS EU board is entirely based in the EU though and comprised of EU Citizens. This means they&rsquo;ll be able to get involved in EU initiatives, and they&rsquo;ll be able to sustain the service in the EU even if the US government did something unthinkable like instructing Amazon to stop offering services in the EU. AWS have made some pretty firm and public commitments here, saying:</p>
<blockquote>
<p><a href="https://aws.eu/faq/#governance-and-leadership--1hs32zh"> &ldquo;<em>AWS established an independent advisory board for the AWS European Sovereign Cloud, legally obligated to act in the best interest of the AWS European Sovereign Cloud. Reinforcing the sovereign control of the AWS European Sovereign Cloud, the advisory board will consists of five members, all EU citizens residing in the EU, including at least two independent board members who are not affiliated with Amazon. The advisory board will act as a source of expertise and provide accountability on sovereignty-related aspects of the AWS European Sovereign Cloud operations, including strong security and access controls and the ability to operate independently in the event of disruption.</em>&rdquo;</a></p>
</blockquote>
<p>Therefore, compared to AWS Public Cloud, AWS EU Sovereign Cloud offers a significant improvement in this regard, but it wouldn&rsquo;t score as highlight as truly owned EU organization with no ties or ownership outside of the EU.</p>
<p><strong>Legal &amp; Jurisdictional Sovereignty</strong><br>
AWS have done a good job of keeping the &ldquo;AWS European Sovereign Cloud GmbH&rdquo; entity at arm&rsquo;s length. Physically and logically isolated from wider AWS. All staff are EU residents, and the board are entirely EU citizens. AWS state in their Sovereign Cloud overview that:</p>
<blockquote>
<p>As part of the technical design, access to the AWS European Sovereign Cloud physical infrastructure and
logical system is managed by Qualified AWS European Sovereign Cloud Staff and can only be granted to
Qualified AWS European Sovereign Cloud Staff located in the EU. AWS European Sovereign Cloud restricted data will not be accessible, including to AWS employees, from outside the EU.</p>
</blockquote>
<p>So only AWS staff employed in the EU have any sort of access.<br>
Is that enough to say there isn&rsquo;t a loophole that means the FBI can&rsquo;t petition AWS in the US to get at data? It appears that would require compelling EU employees to brake local law, which doesn&rsquo;t seem likely.<br>
Truthfully - I think we&rsquo;ll need to see this tested in the courts to know whether this is as robust as we hope or not, but we might be waiting a while&hellip;</p>
<blockquote>
<p><a href="https://aws.amazon.com/compliance/cloud-act/"><em>The CLOUD Act has resulted in zero disclosures of AWS enterprise or government customer content stored outside the U.S. to the U.S. government, since we started reporting the statistic in 2020.</em></a></p>
</blockquote>
<p><strong>Data &amp; AI</strong><br>
AWS EU Sovereign Cloud offer a lot to assure clients in this respect, whether on AWS EU Sovereign Cloud or AWS Public Cloud. There are strong controls in places to allow clients to secure access and auditing to their data to a high degree.
Factor in things like <a href="https://aws.amazon.com/ec2/nitro/">AWS Nitro</a> which provides strong isolation between tenants. In fact, Nitro Isolation prevents anyone other than the client accessing instances - even AWS Staff have no access to customer Instances. Nitro offloads networking, storage, and management functions to dedicated hardware, it significantly reduced the attack surface of the Hypervisor, and all admin access is prohibited.<br>
AWS EU Sovereign Cloud is independently audited and verified to various compliance standards - including attestations for Nitro.</p>
<p><strong>Operational Sovereignty</strong><br>
AWS EU Cloud staff is entirely comprised of EU residents, and AWS have committed that this will be EU citizens located in the EU shortly.
No non-EU residents will have access to the EU Sovereign Infrastructure.</p>
<p>Who clients choose to support the solutions they deploy on EU Sovereign Cloud is entirely in their control - but AWS have closed the door on this one.</p>
<p><strong>Supply Chain Sovereignty</strong><br>
Okay. This is a difficult one to check and satisfy. The EU framework refers to a few aspects of supply chain including where key components are manufactured. But it doesn&rsquo;t clarify what it means by <em>key</em>.<br>
Think of all the devices involved in a typical solution (regardless of where it is) - cpu, PSU, motherboards, network cards, storage devices, adapters, cables, switches, firewalls, gpus, etc - and how many chips and electronics in each of those?</p>
<p>I couldn&rsquo;t find much clarity in AWS published material on this point.
AWS does publish <a href="https://sustainability.aboutamazon.com/amazon-supply-chain-standards-english.pdf">Supply Chain Standards</a> which includes relevant information - but it&rsquo;s quiet on <em>where</em> components come from.</p>
<p>My personal belief is that this is a complicated topic even for behemoth organizations like AWS - and the reality is the growing demand for full digital sovereignty shines on a light on an interconnected, complex, global supply chain - which means this is currently an extremely difficult lens to be viewed as Sovereign.</p>
<p>Organizations will have to make individual decisions about how far they progress in this direction, or except their partners and suppliers to.</p>
<p><strong>Technology Sovereignty</strong><br>
Transparency, auditability, and avoiding proprietary lock in is the objective here. i.e. Are you using software that can be transparently audited? Can you influence the direction of the code. Could someone else prevent you using that code?</p>
<p>Many AWS services are based on Open Source software, or software that has functional Open Source equivalents, and lock-in is something to be managed anyway when deploying to a cloud - but there are ways to manage that so you&rsquo;re not entirely dependent on a cloud platform - especially for containerised workloads.</p>
<p>But AWS in the USA are still responsible for the upstream code. So even though the EU is independent in some ways, it&rsquo;s still seen to be reliant on the US entity for that upstream code.</p>
<p>Again, Organizations will have to decide on the right balance of convenience and compliance in terms of transparency, and whether the improved independence of the AWS EU Sovereign cloud is sufficient.</p>
<p><strong>Security &amp; Compliance Sovereignty</strong><br>
AWS have traditionally done well in this space. The AWS EU cloud is no exception. It has the same security and permissions models as the AWS Public Cloud. e.g. IAM, Organizations, SCPs, etc - but is regionally scoped, implemented, and operated.</p>
<p>Services like Amazon GuardDuty &amp; Security Hub are partially available - some features are on tap today; others planned for the EU Cloud. Check <a href="https://builder.aws.com/build/capabilities/explore?f=eJyrVipOzUlNLklNCUpNz8zPK1ayUoqOUUotLU7WTUnVTU0sLtE1jFGKVdKBK3QsS8zMSUzKzMksqQSqdsyrVEARqgUA4l8dog&amp;tab=service-feature">Builder Centre</a> for service/feature availability in <code>eusc-de-east-1</code>.</p>
<p>Amazon Nitro enables <a href="https://docs.aws.amazon.com/whitepapers/latest/security-design-of-aws-nitro-system/no-aws-operator-access.html">no operator access</a> - coupled with no access to anyone outside the EU - this is a strong position for AWS EU Sovereign Cloud.</p>
<p><strong>Environmental Sustainability</strong><br>
AWS do well here also. AWS have a <a href="https://www.aboutamazon.com/news/aws/aws-data-center-ai-circularity">strong message</a> on circular economy, energy efficient data centre, and <a href="https://aws.amazon.com/sustainability/">sustainability</a>. They&rsquo;re on track to meet targets to be water positive by 2030 and net-zero carbon by 2040.</p>
<p>This is an area that&rsquo;s weighted lowly in the EU framework though - at only 5%.</p>
<h2 id="aws-eu-sovereign-cloud-vs-aws-public-cloud">AWS EU Sovereign Cloud vs AWS Public Cloud</h2>
<p>How do the two platform compare then?<br>
As already pointed out, where a service exists on EU Sovereign Cloud, it&rsquo;s</p>
<h3 id="feature--usage-comparison">Feature / usage comparison</h3>
<p>At a high level <em>some</em> of the differences appear quite quickly:</p>
<table>
  <thead>
      <tr>
          <th></th>
          <th>AWS Public Cloud</th>
          <th>AWS EU Sovereign Cloud</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>What it&rsquo;s optimised for</td>
          <td>Speed, Scale, Global Reach</td>
          <td>Legal &amp; operational Sovereignty (EU)</td>
      </tr>
      <tr>
          <td>Strong Points</td>
          <td>Rapid innovation, Full AWS Service catalogue, Huge elastic scale, Low cost to entry</td>
          <td>EU Only operations, Reduced foreign legal exposure, AWS Native experience</td>
      </tr>
      <tr>
          <td>Limitations</td>
          <td>Jurisdictional ambiguity, cost predictability requires focus, easy to over engineer</td>
          <td>Smaller &amp; slower moving service set, narrow Geographic scope, High cost than AWS Public Regions</td>
      </tr>
      <tr>
          <td>Use cases</td>
          <td>Digital native apps, SaaS platforms, Data analytics &amp; AI/ML, Global customer solutions, Strong governance &amp; compliance requirements</td>
          <td>Public Sector &amp; Critical National Infrastructure, Strong Sovereignty Requirements, FIS, National Data platforms, High assurance workloads</td>
      </tr>
      <tr>
          <td>Bad fits</td>
          <td>Strong EU Sovereignty Requirements, Data platforms subject to strict national control</td>
          <td>Non Sovereign workloads with tight budgets, Rapid global expansion</td>
      </tr>
  </tbody>
</table>
<h3 id="sovereignty-effectiveness-assurance-level">Sovereignty Effectiveness Assurance Level</h3>
<p>The formula to calculate SEAL Scores is explained in the EU Sovereign Compliance Framework - refer to that for details.  To my mind scoring is subjective to a point You can review the framework, review the platform capabilities, and decide how close you feel there are or aren&rsquo;t and score accordingly.</p>
<p>I won&rsquo;t show my working here for various mandated commercial reasons - but I&rsquo;ll share the outcomes. My <strong>personal opinion</strong> after consideration resulted in me viewing the platforms to be:</p>
<ul>
<li>AWS Public Cloud - SEAL 2</li>
<li>AWS EU Sovereign Cloud - SEAL 3</li>
</ul>
<h2 id="final-thoughts">Final thoughts</h2>
<p>The <a href="https://aws.eu">AWS EU Sovereign Cloud</a> is a strong option for clients with strong Sovereignty requirements, but it isn&rsquo;t the right choice for everyone. It&rsquo;s not a one-size-fits-all solution.</p>
<p>Given AWS prices usually fluctuate by region, it&rsquo;s difficult to accurately compare the cost difference with EU cloud. I deploy in <code>eu-west-1</code> &amp; <code>eu-west-2</code> a lot, so I compared with my costs there and found the price was in the region of 15-20% more in <code>eusc-de-east-1</code>. That&rsquo;s enough to be noticed and given the improved Sovereignty posture over AWS Public cloud, that feels reasonable to me. It also feels <em>just high enough</em> that it&rsquo;ll help AWS clients decide if they want improved compliance, security, and data control (which they could likely do in their existing environments) or whether they <em><strong>really</strong></em> need a full sovereign platform.</p>
<p>The highest SEAL rating is &lsquo;4&rsquo;. I think as we see other platforms being assessed - 4 will be awarded rarely. The framework doesn&rsquo;t easily allow for that in a global economy with global supply chains.</p>
<p>Both AWS Cloud and Sov Cloud lose points in &lsquo;Strategic&rsquo;, &lsquo;Supply chain&rsquo;, and &lsquo;Technology&rsquo; sovereignty objectives.<br>
However, AWS EU Sov cloud does significantly improve the position on &lsquo;Legal &amp; Jurisdictional&rsquo;, &lsquo;Operational&rsquo;, &amp; &lsquo;Data &amp; AI&rsquo; sovereignty objectives.</p>
<p>The small caveat is that the scoring of these is somewhat subjective (hence I stressed above my <strong>personal opinion</strong>) and clients will decide themselves what they need.  It&rsquo;s our job to understand the differences, articulate those, and design &amp; build accordingly.</p>
<h2 id="additional-resources">Additional Resources</h2>
<ul>
<li><a href="https://commission.europa.eu/document/download/09579818-64a6-4dd5-9577-446ab6219113_en?filename=Cloud-Sovereignty-Framework.pdf">EU Cloud Sovereignty Framework</a></li>
<li><a href="https://aws.amazon.com/blogs/security/five-facts-about-how-the-cloud-act-actually-works/">Five facts about how the CLOUD Act actually works</a></li>
<li><a href="https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/whitepapers/compliance/Overview_of_the_AWS_European_Sovereign_Cloud.pdf">Overview of the AWS EU Sovereign Cloud</a></li>
</ul>
<hr>
<p><em>This post is part of my AWS technical blog series. Found this helpful? Connect with me on <a href="https://www.linkedin.com/in/john-mcmillan-aaa4274/">LinkedIn</a> or check back here for more AWS content and discussions.</em></p>
]]></content:encoded><category>AWS</category><category>Sovereign Cloud</category><category>Compliance</category><category>AWS</category><category>EU Sov Cloud</category><category>EU Sovereign Cloud</category><category>Sovereign</category><category>Compliance</category><category>AWS AWS EU Sovereign Cloud</category><category>AWS AWS Nitro</category><enclosure url="https://aws.mcmillearn.net/images/aws-eu-sov-banner.png" type="image/png"/></item></channel></rss>