"I cannot guarantee it": under oath, Microsoft admits it cannot rule out that data entrusted to its cloud is handed to the US government (CLOUD Act). Hearing, French Senate committee — Jun 2025 ›
National Observatory
Digital Sovereignty

For Decision-makers

This page gathers the essential data and recommendations for those working in institutions, government and parliament. The aim is to provide the tools for informed decisions on the digital sovereignty of the Public Administration.

The figures of digital sovereignty

Data updated to the latest available report. Source: MxMap.it on IndicePA data.

22,987

PA bodies monitored

From the Index of Public Administrations

46%

PA on non-EU providers

Providers subject to non-EU jurisdiction

51%

PA on Italian providers

Providers based in Italy

0%

PA on EU providers

Non-Italian EU providers

Data last updated: 2026-06-14 — coverage 97%. Source: MxMap.it.

Sovereignty by category of body

Share of bodies on providers subject to non-EU jurisdiction (e.g. CLOUD Act), by category. Ordered from the most dependent. Source: MxMap.it.

Education · 8,403 bodies · Google Workspace 78%
Central government · 52 bodies · Microsoft 365 64%
Healthcare · 234 bodies · Microsoft 365 59%
Transport & Ports · 17 bodies · Microsoft 365 59%
Research · 68 bodies · Microsoft 365 56%
Regional agencies · 76 bodies · Microsoft 365 49%
Contracting authorities · 606 bodies · Microsoft 365 46%
Social security & assistance · 143 bodies · Microsoft 365 46%
Public service operators · 1,128 bodies · Microsoft 365 42%
Culture · 29 bodies · Italian provider 41%
Welfare & social policy · 468 bodies · Italian provider 28%
Environment & Territory · 272 bodies · Italian provider 28%
Local & regional authorities · 8,006 bodies · Italian provider 25%
Consortia & unions of local bodies · 1,464 bodies · Italian provider 24%
Professional bodies & Chambers · 2,021 bodies · Italian provider 22%

"Non-EU" indicates bodies whose email is managed by providers subject to non-European regulations. Figure aggregated by IPA category — source MxMap.it on IndicePA.

Most widespread providers in the PA

By number of bodies served, with their jurisdiction. Source: MxMap.it.

Italian EU Non-EU Unknown

Italian provider · 7,722 bodies 33.6%
Google Workspace · 6,374 bodies 27.7%
Microsoft 365 · 4,203 bodies 18.3%
Self-hosted infrastructure · 3,096 bodies 13.5%
Italian cloud · 954 bodies 4.2%
Unknown · 629 bodies 2.7%
AWS · 7 bodies 0.0%
Zoho · 2 bodies 0.0%

The problem in brief

Microsoft's own admission

Question from the committee's rapporteur, Senator Dany Wattebled:

“Can you guarantee before this committee, under oath, that the data of French citizens entrusted to Microsoft will never be transmitted, following an injunction from the American government, without the explicit agreement of the French authorities?”
No, I cannot guarantee it, but, once again, this has never yet happened.”

The hearing took place under oath, with the committee chair expressly warning of the criminal penalties for false testimony. The question concerned French citizens' data, but the mechanism is identical for Italy: what determines jurisdiction is the supplier's nationality, not the customer's. The difference is that in Italy no one has ever put the question to Microsoft in a parliamentary setting.

Anton Carniaux, Director of Public and Legal Affairs, Microsoft France — hearing before the French Senate committee of inquiry into public procurement, 10 June 2025 (findings taken up in Senate report no. 830 of 8 July 2025). Senate record · heise (EN)

A way out exists. France excludes the CLOUD Act structurally through its SecNumCloud 3.2 certification, and Microsoft itself already operates “national clouds” run by local companies where a government has required it. See Certifications and Sovereignty.

Jurisdictional risk

When an Italian PA uses an email service managed by a provider subject to non-EU jurisdiction (for example US), institutional communications — including those containing citizens' personal data — can be accessible to foreign authorities under laws such as the CLOUD Act (USA, 2018), even without the consent or notification of the Italian body.

Regulatory incompatibility

The Court of Justice of the EU has twice invalidated the data transfer agreements to the USA (Schrems I, 2015 and Schrems II, 2020) for insufficient protection. The new EU-US Data Privacy Framework (2023) is already the subject of challenges. PAs that entrust data to US providers operate in an unstable legal context.

Strategic dependence

The concentration of the PA's digital services on a few large non-European providers creates a strategic dependence that exposes the country to risks in the event of geopolitical tensions, sanctions, service interruptions or unilateral changes to contractual terms.

Declaring is easier than building

Italy signed the European Declaration on digital sovereignty (2025) and has adopted a Cloud Strategy, but real migration remains limited: the National Strategic Hub itself relies on US hyperscalers for ordinary and critical data, legally protecting only those classified as "strategic". Moreover, it is the nationality of the supplier — not the location of the data — that determines jurisdiction. The gap between what is declared and what is built is exactly what the Observatory measures.

The national cloud programme and sovereignty

The finding, in five lines

The Polo Strategico Nazionale delivers real consolidation and real security engineering. It does not deliver digital sovereignty, and it is presented as if it did.

  • In its own user manual, the label “data sovereignty” is attached to a periodic off-site backup.
  • Across 161 pages of contractual documents, neither the terms nor the substantive safeguard clauses appear: CLOUD Act, extraterritorial, nationality, corporate control, Article 48 GDPR, third-country order — all zero.
  • The two technical measures relied upon — own key management and confidential computing — are declared insufficient for this purpose by the French agency that wrote the European sovereignty standard.
  • No offering used by the programme holds a sovereignty qualification, and none is under assessment. In France, one is qualified and another is being assessed.
  • The instrument that would reach the provider is the procurement requirement — not golden power, which by law reaches only Italian entities. That requirement was never written.
What must be said first

Consolidating thousands of scattered server rooms into supervised data centres is a genuine gain in physical security, continuity and management — whatever software runs on top. Encryption, segmentation and access control reduce real risks. Any criticism that ignores this is not worth making. The objection is narrower: these measures answer a security question, and sovereignty is a jurisdictional one.

Six measures, in order of feasibility

Each rests on an instrument that already exists. None requires abandoning the current providers.

  1. Publish which tier each administration uses. It costs nothing, and its absence prevents anyone — Parliament included — from measuring the exposure.
  2. Use the 12 January 2027 deadline, when European law already in force prohibits charging the cost of leaving a cloud.
  3. Map and publish the telemetry — which components transmit outside the perimeter, and what.
  4. Require approval, not visibility, over platform changes, with quarantine and validation before release.
  5. Write an establishment, ownership and administration requirement for the highest data classification. It need not be the French model — but it has to be written.
  6. Join the European purchasing arrangement, which a local authority may do even if its State does not — bearing in mind that the regulation is not yet in force.

Accepting a residual risk is a legitimate policy choice. Describing that risk as absent is a different thing — and it is the only thing our analysis argues against. The full documentation, with primary sources, hashes of every file examined and the method for reproducing every check, is in the dedicated analysis.

Read the full analysis PDF

Reference regulatory framework

Rule / ActRelevance
GDPR (EU Reg. 2016/679)Prohibits the transfer of personal data to third countries without adequate safeguards (Chapter V)
GDPR — arts. 48 and 115Prohibit acting on orders from authorities of third countries (e.g. CLOUD Act) not based on international agreements: a direct conflict with non-EU jurisdiction, with no clean way out for the provider
Schrems II (CGUE C-311/18, 2020)Invalidated the EU-US Privacy Shield; requires case-by-case assessment of standard contractual clauses
CLOUD Act (USA, 2018)Allows US authorities to request data from American providers even if stored in the EU
French Senate hearing (2025)Microsoft (A. Carniaux) admits under questioning it cannot guarantee that European data will not be handed to the US government under the CLOUD Act — Senate record, heise
Italy's Cloud Strategy (2021)Classifies PA data as strategic, critical and ordinary; provides for migration to qualified infrastructure
ACN Regulation (PA cloud)Defines the requirements for the qualification of cloud services for the PA
CAD (D.Lgs. 82/2005)Digital Administration Code — governs the use of technologies in the PA
NIS2 (EU Dir. 2022/2555)Imposes cybersecurity requirements on essential and important entities, including PAs

Policy recommendations

On the basis of the data collected, the Observatory makes the following recommendations:

Make it mandatory for every PA body to declare the digital services used (email, cloud, collaboration) and their jurisdiction. Integrate this information into IndicePA to make it public and monitorable.

Recipients: AgID, Department for Digital Transformation

Introduce digital sovereignty criteria (data jurisdiction, server localization, absence of obligations towards non-EU authorities) as requirements in Consip framework agreements for the PA's email and cloud services.

Recipients: Consip, MEF, AgID

Define a national plan with progressive deadlines for the migration of the PA's email services to providers compliant with sovereignty requirements. Provide dedicated funds — possibly from the PNRR or from cybersecurity funds — to support bodies in the transition.

Recipients: Presidency of the Council of Ministers, Parliament, ACN

Institutionalize the monitoring of the PA's digital sovereignty, making the data public and updated periodically. The Observatory already provides this function as a civic initiative; institutions can adopt it, integrate it or flank it with their own initiatives.

Recipients: AgID, ACN, Parliament

Propose, in European fora (Council of the EU, Commission), the adoption of a common framework for monitoring the digital sovereignty of PAs in all member states, starting from the Italian model as a case study.

Recipients: MAECI, Permanent Representation to the EU

What you can do

If you are a member of parliament

  • Table a parliamentary question citing the Observatory's data
  • Propose the inclusion of sovereignty requirements in legislation
  • Request a committee hearing on the subject

If you are a PA manager

  • Check your body's position in the Observatory's data
  • Start an internal assessment on migration
  • Request dedicated funds for the transition

If you are a regulator

  • Use the data to update guidelines
  • Launch GDPR compliance checks
  • Include sovereignty requirements in framework agreements
Downloadable documents

Download the summary documents designed for institutional decision-makers:

Policy Brief

A 2-page summary with key figures and recommendations for political decision-makers.

Download PDF

Technical Brief

An in-depth technical and regulatory analysis for AgID, ACN, the Garante and research offices.

Download PDF

To receive new documents as soon as they are available, join the Telegram channel.

Telegram