For Decision-makers
This page gathers the essential data and recommendations for those working in institutions, government and parliament. The aim is to provide the tools for informed decisions on the digital sovereignty of the Public Administration.
PA bodies monitored
From the Index of Public Administrations
PA on non-EU providers
Providers subject to non-EU jurisdiction
PA on Italian providers
Providers based in Italy
PA on EU providers
Non-Italian EU providers
Data last updated: 2026-06-14 — coverage 97%. Source: MxMap.it.
Sovereignty by category of body
Share of bodies on providers subject to non-EU jurisdiction (e.g. CLOUD Act), by category. Ordered from the most dependent. Source: MxMap.it.
"Non-EU" indicates bodies whose email is managed by providers subject to non-European regulations. Figure aggregated by IPA category — source MxMap.it on IndicePA.
Most widespread providers in the PA
By number of bodies served, with their jurisdiction. Source: MxMap.it.
Italian EU Non-EU Unknown
The problem in brief
Question from the committee's rapporteur, Senator Dany Wattebled:
“Can you guarantee before this committee, under oath, that the data of French citizens entrusted to Microsoft will never be transmitted, following an injunction from the American government, without the explicit agreement of the French authorities?”“No, I cannot guarantee it, but, once again, this has never yet happened.”The hearing took place under oath, with the committee chair expressly warning of the criminal penalties for false testimony. The question concerned French citizens' data, but the mechanism is identical for Italy: what determines jurisdiction is the supplier's nationality, not the customer's. The difference is that in Italy no one has ever put the question to Microsoft in a parliamentary setting.
Anton Carniaux, Director of Public and Legal Affairs, Microsoft France — hearing before the French Senate committee of inquiry into public procurement, 10 June 2025 (findings taken up in Senate report no. 830 of 8 July 2025). Senate record · heise (EN)
A way out exists. France excludes the CLOUD Act structurally through its SecNumCloud 3.2 certification, and Microsoft itself already operates “national clouds” run by local companies where a government has required it. See Certifications and Sovereignty.
When an Italian PA uses an email service managed by a provider subject to non-EU jurisdiction (for example US), institutional communications — including those containing citizens' personal data — can be accessible to foreign authorities under laws such as the CLOUD Act (USA, 2018), even without the consent or notification of the Italian body.
The Court of Justice of the EU has twice invalidated the data transfer agreements to the USA (Schrems I, 2015 and Schrems II, 2020) for insufficient protection. The new EU-US Data Privacy Framework (2023) is already the subject of challenges. PAs that entrust data to US providers operate in an unstable legal context.
The concentration of the PA's digital services on a few large non-European providers creates a strategic dependence that exposes the country to risks in the event of geopolitical tensions, sanctions, service interruptions or unilateral changes to contractual terms.
Italy signed the European Declaration on digital sovereignty (2025) and has adopted a Cloud Strategy, but real migration remains limited: the National Strategic Hub itself relies on US hyperscalers for ordinary and critical data, legally protecting only those classified as "strategic". Moreover, it is the nationality of the supplier — not the location of the data — that determines jurisdiction. The gap between what is declared and what is built is exactly what the Observatory measures.
The national cloud programme and sovereignty
The Polo Strategico Nazionale delivers real consolidation and real security engineering. It does not deliver digital sovereignty, and it is presented as if it did.
- In its own user manual, the label “data sovereignty” is attached to a periodic off-site backup.
- Across 161 pages of contractual documents, neither the terms nor the substantive safeguard clauses appear: CLOUD Act, extraterritorial, nationality, corporate control, Article 48 GDPR, third-country order — all zero.
- The two technical measures relied upon — own key management and confidential computing — are declared insufficient for this purpose by the French agency that wrote the European sovereignty standard.
- No offering used by the programme holds a sovereignty qualification, and none is under assessment. In France, one is qualified and another is being assessed.
- The instrument that would reach the provider is the procurement requirement — not golden power, which by law reaches only Italian entities. That requirement was never written.
Consolidating thousands of scattered server rooms into supervised data centres is a genuine gain in physical security, continuity and management — whatever software runs on top. Encryption, segmentation and access control reduce real risks. Any criticism that ignores this is not worth making. The objection is narrower: these measures answer a security question, and sovereignty is a jurisdictional one.
Six measures, in order of feasibility
Each rests on an instrument that already exists. None requires abandoning the current providers.
- Publish which tier each administration uses. It costs nothing, and its absence prevents anyone — Parliament included — from measuring the exposure.
- Use the 12 January 2027 deadline, when European law already in force prohibits charging the cost of leaving a cloud.
- Map and publish the telemetry — which components transmit outside the perimeter, and what.
- Require approval, not visibility, over platform changes, with quarantine and validation before release.
- Write an establishment, ownership and administration requirement for the highest data classification. It need not be the French model — but it has to be written.
- Join the European purchasing arrangement, which a local authority may do even if its State does not — bearing in mind that the regulation is not yet in force.
Accepting a residual risk is a legitimate policy choice. Describing that risk as absent is a different thing — and it is the only thing our analysis argues against. The full documentation, with primary sources, hashes of every file examined and the method for reproducing every check, is in the dedicated analysis.
Reference regulatory framework
| Rule / Act | Relevance |
|---|---|
| GDPR (EU Reg. 2016/679) | Prohibits the transfer of personal data to third countries without adequate safeguards (Chapter V) |
| GDPR — arts. 48 and 115 | Prohibit acting on orders from authorities of third countries (e.g. CLOUD Act) not based on international agreements: a direct conflict with non-EU jurisdiction, with no clean way out for the provider |
| Schrems II (CGUE C-311/18, 2020) | Invalidated the EU-US Privacy Shield; requires case-by-case assessment of standard contractual clauses |
| CLOUD Act (USA, 2018) | Allows US authorities to request data from American providers even if stored in the EU |
| French Senate hearing (2025) | Microsoft (A. Carniaux) admits under questioning it cannot guarantee that European data will not be handed to the US government under the CLOUD Act — Senate record, heise |
| Italy's Cloud Strategy (2021) | Classifies PA data as strategic, critical and ordinary; provides for migration to qualified infrastructure |
| ACN Regulation (PA cloud) | Defines the requirements for the qualification of cloud services for the PA |
| CAD (D.Lgs. 82/2005) | Digital Administration Code — governs the use of technologies in the PA |
| NIS2 (EU Dir. 2022/2555) | Imposes cybersecurity requirements on essential and important entities, including PAs |
Policy recommendations
On the basis of the data collected, the Observatory makes the following recommendations:
Make it mandatory for every PA body to declare the digital services used (email, cloud, collaboration) and their jurisdiction. Integrate this information into IndicePA to make it public and monitorable.
Recipients: AgID, Department for Digital Transformation
Introduce digital sovereignty criteria (data jurisdiction, server localization, absence of obligations towards non-EU authorities) as requirements in Consip framework agreements for the PA's email and cloud services.
Recipients: Consip, MEF, AgID
Define a national plan with progressive deadlines for the migration of the PA's email services to providers compliant with sovereignty requirements. Provide dedicated funds — possibly from the PNRR or from cybersecurity funds — to support bodies in the transition.
Recipients: Presidency of the Council of Ministers, Parliament, ACN
Institutionalize the monitoring of the PA's digital sovereignty, making the data public and updated periodically. The Observatory already provides this function as a civic initiative; institutions can adopt it, integrate it or flank it with their own initiatives.
Recipients: AgID, ACN, Parliament
Propose, in European fora (Council of the EU, Commission), the adoption of a common framework for monitoring the digital sovereignty of PAs in all member states, starting from the Italian model as a case study.
Recipients: MAECI, Permanent Representation to the EU
What you can do
If you are a member of parliament
- Table a parliamentary question citing the Observatory's data
- Propose the inclusion of sovereignty requirements in legislation
- Request a committee hearing on the subject
If you are a PA manager
- Check your body's position in the Observatory's data
- Start an internal assessment on migration
- Request dedicated funds for the transition
If you are a regulator
- Use the data to update guidelines
- Launch GDPR compliance checks
- Include sovereignty requirements in framework agreements
Download the summary documents designed for institutional decision-makers:
Policy Brief
A 2-page summary with key figures and recommendations for political decision-makers.
Download PDFTechnical Brief
An in-depth technical and regulatory analysis for AgID, ACN, the Garante and research offices.
Download PDFTo receive new documents as soon as they are available, join the Telegram channel.