A public buyer asks for "sovereign cloud." The Scaleway sales rep shows French datacenters on a map. The architect asks who owns the capital, which court applies in dispute, and whether backups leave for Amsterdam. Three questions, three different answers — and that is normal.
Scaleway scores strongly on sovereignty in our directory, with documented FR/NL/PL zones and a "sovereign French cloud" pitch. Confusing location, ownership, and jurisdiction is the costliest mistake on sensitive projects.
Three sovereignty axes — three questions
| Axis | Question | What Scaleway offers (to verify) |
|---|---|---|
| Location | Where are data stored and processed? | Paris, Amsterdam, Warsaw regions; France/EU data jurisdiction per profile |
| Ownership | Who controls the company and strategic decisions? | iliad group; match capital and governance to your spec |
| Jurisdiction | Which law, authorities, lawful access? | French entity, EU law; separate physical residence from state access conditions |
A project may require all three aligned — or only EU location. Clarify before paying an unnecessary "sovereign" premium or underestimating SecNumCloud needs.
Location: beyond the map pin
Our profile lists FR, NL, PL datacenters and France / EU jurisdiction. In practice:
- Pick region at deploy time — Paris for France constraint, Amsterdam or Warsaw if latency or product requires it, documenting any gap.
- Trace replicas: object storage, snapshots, S3 lifecycle rules, managed databases.
- Isolate support and logs: who can access from which country?
Scaleway documents better than many providers — use that to demand diagrams and DPA, not only the Paris slogan.
Ownership: when capital becomes a criterion
Public sector and critical operators sometimes require:
- Majority European or French capital
- No control by a Cloud Act–subject entity
- Transparency on subsidiaries and any US sub-processors
Scaleway / iliad is an established European player — credible for most "sovereign" projects in the GDPR+ sense. For SecNumCloud or defence scope, capital analysis goes further: read the spec, not the brochure.
Capital sovereignty lives in corporate registers and contract annexes — not a France badge.
Jurisdiction: residence ≠ access conditions
Even with data in Paris, questions remain:
- Which entity signs the contract?
- Which sub-processors handle L3 support, anti-DDoS, hardware?
- How Scaleway responds to French or EU authority requests?
This ties to the Netherlands / Cloud Act debate for other providers: see Netherlands: residence and authority access. The lesson transfers — separate where bits live and who may legally access them.
The crux: sovereign on the slide, hybrid in architecture
That is what "100% sovereign" tenders forget: sovereignty is the state of your architecture, not the sales slide.
Decide and move forward without blind spots
- Define the exact framework: EU GDPR, French sovereignty, SecNumCloud, other.
- Cross-check location, capital, and jurisdiction with Scaleway's DPA.
- Map prod, backups, logs, support.
- Review the Scaleway profile and compare tool.
- Read SecNumCloud: reversibility if the project is state or critical.
Browse the directory to benchmark other European clouds on the same sovereignty criteria.
Frequently asked questions
Is Scaleway a sovereign French cloud?
Scaleway positions as European cloud with FR/NL/PL DCs and French entity. Marketing "sovereign" ≠ SecNumCloud or public spec without verification.
Does Scaleway ownership matter?
Yes for sensitive projects: capital control affects location and sub-processing. Scaleway belongs to iliad — match to your framework.
Is hosting in Paris legally enough?
Paris sets primary location, not the full chain. Jurisdiction = contract, entity, sub-processors, and access law.
Does Scaleway replace SecNumCloud?
No. SecNumCloud is a distinct ANSSI qualification with its own requirements and evidence.
When you ask for "sovereign cloud," use three words: where, who owns, who can access — if the answer blends them, it is not an answer yet.
