Summary
- France and the Netherlands want targeted European-content criteria in public procurement and aid for digital infrastructure.
- Their joint position calls for stronger protection of sensitive cloud data against risks arising from extraterritorial legislation.
- The proposals connect cybersecurity, cloud procurement, strategic dependency, AI, semiconductors, quantum technology, and telecommunications policy.
France and the Netherlands are pressing the European Union to put digital sovereignty more directly into cloud regulation and public procurement, including measures intended to protect sensitive European data from risks created by non-European extraterritorial laws.
A joint Franco-Dutch technology declaration published on 2 September backs targeted European-content criteria in public procurement and public aid for the digital sector and infrastructure. It also calls for what the two governments describe as an ambitious and protective European framework for cloud sovereignty.
The declaration, published by the Government of the Netherlands and the French presidency, places those proposals within the EU’s developing Tech Sovereignty Package and the planned revision of the Cybersecurity Act.
France and the Netherlands argue that Europe’s dependency on external technology suppliers has become an economic and security issue, linking technological capability to political influence, military capacity, industrial competitiveness, and operational resilience.
The proposed approach goes beyond conventional requirements concerning where data is physically stored. The declaration specifically raises the risk of extraterritorial legislation, putting legal jurisdiction and external access alongside technical security as factors in cloud procurement.
That is a difficult policy area because sovereignty is not a single technical property. A cloud service can operate European data centres while depending on a parent company, software stack, support model, key-management process, or legal jurisdiction outside Europe. Conversely, a European supplier is not automatically secure simply because of its ownership or headquarters.
Any procurement regime built around sovereignty will therefore have to define which dependencies it is trying to control. Those could include access to encryption keys, administrative support from outside the EU, control over software updates, ownership of critical intellectual property, data-transfer obligations, supply-chain concentration, and the legal powers available to foreign authorities.
Cyber Insider has previously examined the Commission’s wider technology-sovereignty programme and its focus on European dependency. The Franco-Dutch position adds political pressure from two major member states for procurement rules to become one of the mechanisms used to change that dependency.
The declaration also extends well beyond cloud services. France and the Netherlands want European capacity strengthened across artificial intelligence, semiconductors, quantum technologies, photonics, telecommunications, defence, space, energy, and connected vehicles.
Quantum technology is treated in industrial as well as security terms. The governments want public procurement to support a European quantum value chain that is less exposed to non-European extraterritorial law, illustrating how resilience policy is being connected directly to industrial strategy.
The cloud proposals could prove among the most commercially consequential elements if they influence the Commission’s legislation. Public-sector and regulated-sector cloud purchasing represents a substantial market, and content or sovereignty requirements can affect hyperscale providers, European cloud operators, managed-service suppliers, and customers designing multi-cloud strategies.
They could also complicate procurement if different member states interpret sovereignty differently. A useful European framework would have to provide criteria precise enough to be evaluated contractually and technically, rather than relying on broad labels such as sovereign, trusted, or European.
The declaration is a joint political position rather than enacted EU law. The Commission and other member states will determine what ultimately appears in the Tech Sovereignty Package and the Cybersecurity Act revision.
What France and the Netherlands are making explicit is the direction of the debate: cyber resilience is increasingly being considered alongside who controls infrastructure, which legal regimes can reach sensitive data, and how European public spending shapes long-term technology dependency.




