Skip to main content

Worried About AWS and Data Sovereignty? You're Not Alone

3 min read By Tom C

Airbus is moving 70 critical applications(opens in new tab) off AWS and onto Scaleway, a French cloud provider, in a contract reportedly worth more than fifty million euros over up to ten years. The systems involved span ERP, manufacturing, CRM, and product-lifecycle software, essentially the core of what keeps the business running.

What makes this worth paying attention to isn’t the scale, it’s the reasoning. Airbus isn’t moving everything, and it isn’t building new sovereign infrastructure from scratch. It’s making a deliberate, risk-based call about which workloads need to sit outside US legal reach, and moving only those.

Why AWS is a sovereignty question at all

The concern isn’t really about server location. The US CLOUD Act gives American authorities the power to compel US-headquartered companies to hand over data they control, wherever in the world that data physically sits. An AWS region in London or Frankfurt doesn’t change who AWS is answerable to.

Airbus’s digital chief put it plainly: the move “keeps our critical data assets shielded from foreign extraterritorial laws.” For organisations under regulatory pressure - public sector, healthcare, financial services, defence supply chain - that’s become a real procurement blocker rather than a theoretical risk. Contracts increasingly ask directly: who can compel access to this data, and under which country’s law?

The risk-based approach is the right one

Airbus is still using Microsoft, Google, Salesforce, and other non-European platforms for lower-risk workloads. Its own framing is that it doesn’t intend to move away from all non-European solutions, only to balance the choice against how sensitive the data actually is.

That’s a much more useful model than “move everything to Europe” or “don’t worry about it.” Most organisations don’t need a wholesale exit from AWS. They need to know which of their applications actually carry sovereignty risk, and a clear plan for moving those specifically.

What this looks like for a smaller organisation

Airbus has the budget and internal digital team to run this as a multi-year programme. Most businesses don’t, and don’t need to. The underlying steps are the same regardless of scale:

  • Work out what’s actually sensitive. Which applications handle regulated, personal, or commercially critical data, and which genuinely don’t.
  • Pick a EU-based destination. Scaleway is the example in the headlines, but OVHcloud and other European providers fit the same brief - or our own UK infrastructure, depending on your jurisdiction.
  • Keep key control in-jurisdiction. Hosting location alone doesn’t solve the problem if encryption keys are still managed by a foreign-controlled entity.
  • Migrate without a rebuild. Most applications can move to a new provider without being rearchitected, if the migration is planned properly.

Where to start

If AWS exposure and CLOUD Act risk has been sitting on your risk register rather than your project plan, it’s worth an honest look at what would actually be involved in moving the applications that matter. We’ve written up how our approach works in our data sovereignty flyer, covering hosting options, key management, and the migration process end to end.

Airbus just showed that this doesn’t have to be all-or-nothing. Work out what’s actually at risk, move that, and leave the rest where it is.