Germany cross-border data flows

Germany's Google Cloud Deal Shows Sovereignty Can Be Bought Through Contracts, Not Bans

By end of 2026, Thales alone will hold the encryption keys to Google's German cloud — a contractual fix that beats forced data localization.

Germany's Sovereign Cloud Handover People of Internet Research · Germany €5.5B Google Germany infrastructure spend Committed investment through 2029. End of 2026 Full key handover target Thales gains sole control of keys … Apr 2026 BSI sovereignty framework launched New voluntary C3A criteria catalog… 2,300 employees Thales Germany workforce Across nine sites; will staff the … peopleofinternet.com
Germany's Sovereign Cloud Handover People of Internet Research · Germany €5.5B Google Germany infrastructure s… End of 2026 Full key handover target Apr 2026 BSI sovereignty framework launch… 2,300 employees Thales Germany workforce peopleofinternet.com

Key Takeaways

The handover

Google Cloud and Thales announced their partnership on May 20, 2026, to launch a sovereign cloud region in Germany, mirroring the PREMI3NS offering Thales subsidiary S3NS already runs in France (Google Cloud Press Corner). The service entered preview immediately; general availability is targeted for the end of 2026. That same deadline is the one that matters most: by then, Thales — not Google — will hold the cryptographic keys, the root of trust, the IP addressing, and the identity infrastructure for the entire platform. The operating entity will be a new German company, legally and operationally separate from Google, owned by Thales and staffed by local personnel (heise online). Google supplies the underlying technology stack; it does not get to touch the keys that unlock customer data.

The timing lines up with a new German government instrument. On April 27, 2026, Germany's Federal Office for Information Security (BSI) published its C3A criteria catalog — "Criteria enabling Cloud Computing Autonomy" — the first structured framework for measuring how independent a cloud customer actually is from its provider (BSI). C3A doesn't replace BSI's existing C5 security catalog; it assumes a provider already meets C5 and then asks a separate question — can a customer actually exit, audit, or control this service, or are they dependent on the vendor's goodwill? (BSI C3A catalog). Crucially, BSI is explicit that C3A carries no regulatory force — it's a procurement yardstick, not a mandate.

The fear this answers is real

It's worth taking seriously why German public bodies, hospitals, and financial infrastructure firms — Thales names AOK Niedersachsen, University Hospital Schleswig-Holstein, and Deutsche Börse among early customers (TheFastMode) — have spent two years asking whether the American cloud majors' European promises hold up. In June 2025, Microsoft France's director of public and legal affairs, Anton Carniaux, was asked under oath at a French Senate hearing whether he could guarantee French citizens' data would never reach US authorities without French government consent. He said no: the US CLOUD Act obliges American firms to comply with valid US legal process regardless of where the servers physically sit (The Register). That admission did real damage to the credibility of "sovereign" cloud products that were, underneath the marketing, still legally American entities holding their own keys. A regulator or hospital administrator who reads the CLOUD Act's extraterritorial reach and concludes that geography alone doesn't solve the problem is not being paranoid — that is a correct legal reading.

Why this is the right kind of fix

What makes the Google-Thales structure notable is that it addresses the actual legal mechanism rather than the optics. The CLOUD Act reaches data controlled by a US company; it does not reach data where a US company has no technical means of production, because it holds neither the keys nor the infrastructure. By transferring the root of trust to a French-headquartered, EU-owned defense and security contractor operating a separate German legal entity, the deal removes Google from the compliance chain entirely for this platform — not through a ban, a mandated divestment, or a data-localization law, but through a commercial contract responding to a market signal that BSI itself created with C3A.

That is the model European digital-sovereignty policy should keep pointing toward. The alternative — proposals floated in Brussels and Berlin to require EU-only ownership of cloud infrastructure, or to bar US hyperscalers from public-sector contracts outright — would strip European customers of Google's actual engineering advantages in AI infrastructure, custom silicon, and global scale, for a sovereignty guarantee this contractual structure already delivers. Germany's own €5.5 billion in projected Google infrastructure investment through 2029 depends on exactly this kind of arrangement remaining viable rather than being pre-empted by blanket localization mandates (heise online).

What to watch before calling this solved

Two caveats keep this from being a finished story. First, C3A is voluntary and unenforced — BSI can certify that Thales's structure meets the criteria, but nothing compels any other provider to follow, and nothing stops a future contract renegotiation from quietly re-centralizing control. Second, the real test isn't the architecture diagram, it's an actual US legal demand hitting Google while the German entity's keys sit with Thales. Until that happens once and the wall holds, this is a well-designed structure, not yet a proven one. Regulators should keep watching whether Thales's operational independence survives contact with a genuine cross-border request — and resist the urge to declare victory, or to over-legislate, before that test arrives.

Sources & Citations

  1. BSI: C3A sovereignty criteria published
  2. BSI: C3A criteria catalog
  3. Google Cloud Press Corner
  4. heise online
  5. The Register
  6. TheFastMode