Inetum and Stibbe assess cloud sovereignty rCloud

Inetum, a European leader in digital services, has commissioned an independent legal assessment on cloud sovereignty by Stibbe, a leading Benelux law firm. With this collaboration, both organizations aim to bring more clarity to a cloud landscape where topics such as sovereignty, compliance, and digital control are becoming more important, but also more difficult for organizations to navigate.

Release date : 18/06/2026 

 

Cloud technologies give organizations more flexibility and scalability. At the same time, organizations are paying closer attention to how and where sensitive data is stored and managed. In practice, most major cloud providers are American or Chinese. According to the Centre for European Policy Studies, around 70% of European data currently resides in U.S.-based cloud environments.

Even when data is stored in Europe, organizations still need to consider factors such as foreign legislation, data access requests and orders, operational and technical dependencies, and compliance requirements. As a result, cloud sovereignty has become an important topic for businesses, public institutions, and regulated sectors across Europe. This strategic focus is reflected in the latest Beltug Priorities Compass top 20 ranking, where the shift toward European cloud alternatives ranked straight into the top 10 priorities for Belgian CIOs, while digital sovereignty and geopolitical risk management debuted at number 15.

At the same time, there is still no clear legal definition of what a “sovereign cloud” actually means. This makes it difficult for organizations to assess what level of sovereignty, control, and protection a cloud environment really offers. Inetum therefore commissioned Stibbe to assess its rCloud platform, and to help it determine its strengths and unique selling points in terms of sovereignty. By combining a concrete use case with a broader methodology, this collaboration helps bring more clarity to the debate from both a legal and operational perspective.

Bringing legal clarity to the cloud sovereignty debate

The assessment framework combines legal, operational, and technical criteria to help organizations better understand and evaluate cloud sovereignty. Rather than treating sovereignty as a purely technical topic, the framework looks at how cloud environments are structured, governed, managed, and protected in practice.

The process takes into account European and Belgian law such as data protection laws (including the GDPR), the case law on international transfers, cybersecurity laws, and the Data Act, alongside foreign legislation with extraterritorial effects including the U.S. CLOUD Act, FISA, etc. It also considers elements such as data location, governance structures, operational control, access by subcontractors, security measures, and potential exposure to foreign legislation or external access requests. The goal is to help organizations gain a clearer view of the legal and operational implications behind different cloud setups and sovereignty claims.

“Cloud sovereignty is not a fixed or purely technical concept. It is a legal, operational, and strategic question that requires nuance and context,” says Erik Valgaeren, partner at Stibbe.  “Organizations today face growing challenges around international data access, compliance obligations, and operational dependencies. Our role in this collaboration is to help clarify what sovereignty means within the current legal framework, and to give organizations a clearer understanding of the risks and responsibilities linked to their cloud services. Our assistance helps Inetum to communicate clearly and confidently about what cloud sovereignty actually means in practice.”

“Organizations increasingly need clarity on how their cloud environments are structured and governed, especially in highly regulated contexts,” says Thomas Breuer, General Manager at Inetum Belgium. “At the same time, cloud sovereignty is not an all-or-nothing story. Different organizations have different risk profiles, operational needs, and compliance requirements. With this independent assessment from Stibbe and with rCloud, we aim to offer a sovereign cloud approach aligned with European expectations and to provide customers with a more transparent and realistic view on what sovereignty means in practice.”