Government Cloud Dependency And Sovereign Infrastructure Risks .
Government Cloud Dependency And Sovereign Infrastructure Risks
Introduction
Government cloud dependency arises when public authorities rely heavily on a small number of private cloud providers for computing, storage, databases, cybersecurity, identity systems, artificial intelligence, digital public services, and critical government applications. Sovereign infrastructure risk arises when the State's ability to control those systems is affected by foreign ownership, foreign jurisdiction, cross-border data transfers, proprietary technology, geopolitical restrictions, or dependence on infrastructure that the government does not itself control.
The issue is broader than ordinary IT procurement. Once essential public functions are concentrated in cloud infrastructure, questions arise concerning national security, administrative continuity, data sovereignty, competition law, public procurement, privacy, jurisdiction, interoperability, resilience and strategic autonomy.
A government may therefore face a paradox: cloud infrastructure can increase efficiency and resilience against some failures while simultaneously creating a new structural dependency on a limited number of infrastructure providers.
1. Meaning of Government Cloud Dependency
Government cloud dependency occurs where public bodies become reliant upon external cloud providers for functions such as:
- government databases;
- tax and customs systems;
- healthcare platforms;
- identity infrastructure;
- welfare-payment systems;
- defence and security applications;
- judicial and administrative systems;
- public-sector AI;
- digital procurement;
- communications;
- disaster-management systems;
- critical infrastructure monitoring; and
- government employee and citizen data.
Dependency may exist at several layers:
A. Infrastructure dependency
Dependence upon:
- data centres;
- servers;
- storage;
- networking;
- GPUs;
- telecommunications;
- backup infrastructure.
B. Platform dependency
Government applications may become dependent upon proprietary:
- databases;
- APIs;
- identity systems;
- orchestration tools;
- machine-learning platforms;
- serverless services.
C. Data dependency
Government data may be difficult or expensive to migrate because of:
- proprietary formats;
- enormous data volumes;
- technical incompatibility;
- encryption arrangements;
- metadata dependencies.
D. Contractual dependency
Long-term procurement contracts can create:
- switching costs;
- minimum-spend commitments;
- automatic renewal;
- termination charges;
- migration restrictions;
- vendor-specific licensing.
E. Legal dependency
A cloud provider incorporated in another jurisdiction may be subject to laws of that jurisdiction even where the physical servers are located domestically.
This is particularly important for government information.
2. What Is Sovereign Infrastructure?
Sovereign infrastructure refers broadly to infrastructure over which a State retains meaningful legal, operational and strategic control.
It can involve:
- domestic physical infrastructure;
- domestic ownership or control;
- domestic data storage;
- domestic personnel and operational control;
- domestic encryption-key management;
- continuity guarantees;
- independent cybersecurity capabilities;
- interoperability and portability;
- domestic legal jurisdiction; and
- the ability to continue essential governmental functions without a particular foreign provider.
Sovereignty therefore cannot be reduced to "the server is physically located inside the country."
A data centre can be physically domestic while the infrastructure remains subject to foreign corporate ownership, foreign law, foreign administrators or foreign technology dependencies.
3. Major Government Cloud Dependency Risks
A. Foreign jurisdiction risk
A foreign cloud provider may be required by the law of its home jurisdiction to disclose information to governmental authorities.
Consequently:
Physical location of data ≠ complete legal sovereignty over data.
This distinction became particularly important in litigation concerning US access to data held by multinational technology companies.
4. Data Sovereignty and Cross-Border Access
Government data may contain:
- national-security information;
- tax information;
- health records;
- biometric information;
- identity information;
- judicial records;
- immigration records;
- defence information.
If such information is transferred or technically accessible from another jurisdiction, conflicts may arise between:
State A's privacy/security law
and
State B's surveillance/disclosure law.
This produces a jurisdictional conflict that ordinary data-localisation requirements may not completely solve.
5. Case Law
1. United States v. Microsoft Corp. — 2018
This case concerned a US government warrant seeking emails stored on a server located in Ireland.
Microsoft argued that the US government could not use the relevant warrant to compel production of data stored abroad.
The litigation demonstrated an important principle for cloud sovereignty:
Data location and corporate control can exist in different jurisdictions.
The case ultimately became moot after the US Congress enacted the CLOUD Act, but its significance remains substantial.
Relevance to government cloud dependency
It illustrates the risk that:
- data may physically reside in one State;
- the cloud provider may be incorporated in another;
- the provider may operate infrastructure globally; and
- the provider may be subject to disclosure obligations under its home jurisdiction.
Principle
Domestic data hosting does not necessarily eliminate extraterritorial legal exposure.
6. Schrems II — Data Protection Commissioner v Facebook Ireland and Maximillian Schrems, C-311/18
The Court of Justice of the European Union invalidated the EU-US Privacy Shield and upheld the validity of standard contractual clauses subject to safeguards.
A major concern was the possibility that US authorities could obtain access to data transferred to US-linked companies under US surveillance legislation.
Importance for sovereign government infrastructure
Schrems II demonstrates that cloud sovereignty involves more than contractual promises.
Authorities must consider:
- foreign surveillance laws;
- government-access powers;
- effective remedies;
- proportionality;
- encryption;
- supplementary safeguards.
Principle
A cloud arrangement can become legally problematic where the receiving jurisdiction does not provide protections essentially equivalent to those required under the originating legal order.
7. Schrems I — Maximillian Schrems v Data Protection Commissioner, C-362/14
In Schrems I, the CJEU invalidated the EU-US Safe Harbor framework because of concerns surrounding US governmental access to transferred personal data and inadequate judicial protection.
Significance
The case established an important foundation for modern data-sovereignty analysis.
Government cloud contracts involving foreign providers cannot simply assume that:
"the provider promises confidentiality, therefore the data is sovereign."
The relevant question is whether the legal environment surrounding the provider permits effective protection.
8. Digital Rights Ireland Ltd v Minister for Communications, Joined Cases C-293/12 and C-594/12
The CJEU invalidated the EU Data Retention Directive because of serious interference with fundamental rights to privacy and data protection.
Although the case did not concern government cloud procurement specifically, it is highly relevant to cloud-based public infrastructure.
Importance
Cloud systems can make the State's capacity to:
- collect;
- retain;
- analyse;
- search; and
- correlate
large volumes of information substantially greater.
The case therefore supports the principle that technological capability does not remove proportionality and fundamental-rights constraints.
Sovereignty implication
State control over infrastructure must remain subject to legal limits on State power.
9. Tele2 Sverige AB v Post- och telestyrelsen and Watson, Joined Cases C-203/15 and C-698/15
The CJEU addressed general and indiscriminate retention of communications data and imposed significant restrictions based on EU fundamental rights.
Relevance to cloud infrastructure
Government cloud systems increasingly integrate:
- communications metadata;
- identity information;
- location data;
- authentication logs;
- behavioural information.
Centralisation can therefore increase the consequences of unlawful or disproportionate access.
Principle
Infrastructure centralisation does not automatically justify unrestricted governmental access.
10. Google Spain SL, Google Inc. v Agencia Española de Protección de Datos, C-131/12
The CJEU recognised important rights concerning the removal of certain search-engine results relating to individuals.
Although this was not a government-cloud case, it illustrates a broader issue:
digital infrastructure operators can become powerful intermediaries controlling access to information.
Relevance
Where governments depend on cloud platforms, the provider may control important technical functions relating to:
- indexing;
- storage;
- access;
- identity;
- authentication;
- data retrieval.
This raises questions about whether critical governmental functions should be dependent upon private infrastructure intermediaries.
11. La Quadrature du Net and Others, Joined Cases C-511/18, C-512/18 and C-520/18
The CJEU considered national laws concerning retention and access to electronic communications data in the context of national security and serious crime.
The judgments are important because they recognise the interaction between:
- national security;
- communications infrastructure;
- data retention;
- privacy;
- proportionality.
Government-cloud significance
States may have legitimate security interests in controlling critical infrastructure, but those interests operate within a legal framework governing surveillance and data processing.
Thus:
sovereign infrastructure ≠ unrestricted governmental power.
12. Schrems II and the Concept of "Equivalent Protection"
One of the most important lessons from the Schrems litigation is that sovereignty should be assessed across several dimensions.
| Dimension | Question |
|---|---|
| Physical | Where are the servers? |
| Corporate | Who owns the provider? |
| Legal | Which jurisdiction governs the provider? |
| Operational | Who administers the systems? |
| Technical | Who controls encryption and keys? |
| Contractual | What happens when the contract ends? |
| Security | Can the State independently respond to incidents? |
| Migration | Can data and applications be moved elsewhere? |
A government that examines only physical location may therefore underestimate its dependency.
13. Lock-In Risk
One of the greatest economic risks is cloud vendor lock-in.
Suppose a government initially purchases inexpensive infrastructure.
Over time it adopts the provider's:
- proprietary database;
- AI services;
- identity system;
- serverless architecture;
- monitoring tools;
- storage APIs.
The cost of leaving may eventually exceed the original procurement cost.
This produces a phenomenon sometimes described as:
architectural lock-in.
The government is no longer merely purchasing cloud computing. It is becoming dependent upon the provider's technological ecosystem.
14. Competition-Law Dimension
Government cloud dependency can create competition concerns where a small number of providers control critical inputs.
Relevant theories include:
A. Essential-facility concerns
A cloud service may become sufficiently important that denial of access or discriminatory conditions could raise issues under abuse-of-dominance principles.
B. Foreclosure
A dominant provider might use its position in infrastructure cloud services to strengthen positions in:
- AI;
- cybersecurity;
- productivity software;
- databases;
- identity;
- government applications.
C. Bundling
A cloud provider may bundle:
- compute;
- storage;
- AI;
- security;
- identity;
- databases.
Bundling can make migration increasingly difficult.
D. Self-preferencing
A provider operating both infrastructure and application services may potentially favour its own downstream products.
E. Data advantages
A dominant provider may gain informational advantages from operating multiple layers of government digital infrastructure, subject to applicable confidentiality and data-protection restrictions.
15. Public Procurement Risk
Government procurement law introduces additional concerns.
A procurement authority should consider:
- interoperability;
- open standards;
- portability;
- exit rights;
- subcontracting;
- data-location requirements;
- audit rights;
- security certification;
- business continuity;
- disaster recovery;
- source-code access where justified;
- encryption-key control;
- termination assistance.
A procurement that focuses exclusively on the lowest initial price can create substantial long-term switching costs.
16. Sovereign Cloud vs Sovereign-Controlled Cloud
These concepts should be distinguished.
Sovereign cloud
May mean that infrastructure is located within national territory.
Sovereign-controlled cloud
More comprehensively involves:
- domestic legal control;
- operational control;
- independent security capability;
- encryption-key control;
- trusted personnel;
- portability;
- continuity;
- resilience against foreign intervention.
The second concept provides a more complete framework for analysing strategic dependency.
17. Concentration Risk
Government cloud markets can experience infrastructure concentration.
If a large proportion of government systems depend upon a few hyperscale providers, a single:
- outage;
- cyberattack;
- software failure;
- contractual dispute;
- sanctions regime;
- geopolitical conflict;
- pricing change; or
- provider insolvency
could affect multiple public services simultaneously.
This creates a systemic infrastructure risk.
The risk is particularly significant where the same provider supplies infrastructure to:
- central government;
- local government;
- hospitals;
- financial regulators;
- emergency services;
- defence contractors.
18. The "Single Cloud" Problem
A government may seek efficiency by placing most systems with one provider.
This can produce economies of scale but also creates:
single-provider dependency.
A more resilient architecture may instead involve:
- multi-cloud;
- hybrid cloud;
- government-owned infrastructure;
- private cloud;
- on-premises critical systems;
- interoperable backup systems.
The appropriate architecture depends on the sensitivity and criticality of the particular function.
19. Data Localisation Is Not Sufficient
Data localisation can reduce some risks but cannot eliminate all dependency.
For example:
Government data → domestic data centre → foreign-owned cloud company → foreign software stack → foreign administrators → foreign legal obligations
The data may be physically domestic while strategic dependency remains external.
Consequently, sovereignty analysis should examine the whole technology stack.
20. AI Intensifies the Problem
Government cloud dependency becomes more significant with AI.
Modern government AI systems may depend on:
- GPUs;
- foundation models;
- inference APIs;
- cloud storage;
- training infrastructure;
- model registries;
- cybersecurity services;
- proprietary orchestration systems.
If a government becomes dependent upon one provider for both compute and AI models, switching costs can become exceptionally high.
This creates a potential:
compute → cloud → model → application dependency chain.
21. Critical Infrastructure and National Security
Government cloud systems may support:
- electricity grids;
- transport;
- telecommunications;
- defence logistics;
- emergency response;
- financial infrastructure;
- water systems.
Cloud failure can therefore become a national infrastructure event, rather than an ordinary IT outage.
A sovereignty framework should consequently distinguish between:
Low-criticality systems
Routine administrative applications.
Medium-criticality systems
Tax, licensing and public-service platforms.
High-criticality systems
Defence, emergency response, national identity and critical infrastructure.
Different levels of domestic control and redundancy may be appropriate for each category.
22. Exit and Portability Rights
A government cloud contract should address:
Data portability
Can all government data be exported?
Application portability
Can applications operate on another provider?
API portability
Are proprietary APIs being used?
Metadata portability
Can logs, configurations and metadata be transferred?
Encryption portability
Can government-controlled keys be migrated?
Migration assistance
Must the provider cooperate during transition?
Deletion
Can the government verify deletion after migration?
Without these protections, contractual termination may not mean practical independence.
23. Government Cloud Dependency as a Competition Problem
The central competition-law question is not simply:
"Is cloud computing expensive?"
It is:
"Can government customers realistically discipline cloud providers through switching, multi-sourcing and procurement competition?"
If switching is technically or economically impossible, conventional assumptions about competitive procurement become weaker.
This creates a potential relationship between:
market concentration + switching costs + interoperability barriers + public-sector dependence.
24. Relevant Legal Principles From the Case Law
The six-plus cases collectively support several propositions:
| Legal principle | Relevant case |
|---|---|
| Data location and corporate jurisdiction may diverge | United States v Microsoft |
| Foreign surveillance laws can affect legality of data transfers | Schrems II |
| International data-transfer mechanisms require effective safeguards | Schrems I |
| State data practices remain subject to proportionality | Digital Rights Ireland |
| Mass communications-data retention faces fundamental-rights limits | Tele2/Watson |
| Search/information intermediaries can exercise significant control over digital information | Google Spain |
| National-security interests must coexist with fundamental-rights constraints | La Quadrature du Net |
25. Risk Taxonomy
Government cloud dependency can therefore be divided into eight major risks:
1. Jurisdictional risk
Foreign laws may affect government data.
2. Operational risk
The State may lack independent technical capability.
3. Concentration risk
Multiple government services may depend on the same provider.
4. Lock-in risk
Migration becomes prohibitively expensive.
5. Cybersecurity risk
A single compromise can affect numerous public functions.
6. Geopolitical risk
Sanctions or international disputes may affect service availability.
7. Competition risk
Dominant cloud providers may gain structural market power.
8. Sovereignty risk
The State may formally own the data but lack practical control over the infrastructure through which it operates.
26. Regulatory Responses
A comprehensive government-cloud policy can include:
- multi-cloud requirements for critical systems;
- mandatory interoperability standards;
- open APIs;
- portability obligations;
- government-controlled encryption keys;
- domestic administrative access controls;
- source-code escrow where appropriate;
- independent security audits;
- mandatory exit plans;
- tested disaster recovery;
- restrictions on subcontracting;
- transparency regarding foreign governmental access;
- procurement rules addressing switching costs;
- competition-law monitoring;
- domestic backup infrastructure;
- sovereign cloud requirements for especially sensitive systems.
27. A Sovereign Infrastructure Decision Framework
A government assessing a cloud contract can ask:
Step 1 — What data is involved?
Personal, confidential, strategic or classified?
↓
Step 2 — How critical is the service?
Can government operations continue without it?
↓
Step 3 — Who controls the infrastructure?
Domestic government, domestic private entity or foreign provider?
↓
Step 4 — Which laws apply?
Domestic law plus potentially foreign jurisdictional obligations?
↓
Step 5 — Can the government switch providers?
Assess technical and economic switching costs.
↓
Step 6 — Is there genuine interoperability?
↓
Step 7 — Is there an independent backup?
↓
Step 8 — Does the arrangement create excessive market concentration?
↓
Step 9 — Can the State maintain essential services during provider failure?
↓
Step 10 — Conduct periodic sovereignty and competition review.
28. Key Legal and Policy Insight
The fundamental mistake would be to treat cloud sovereignty as merely a question of server location.
A more complete formula is:
Sovereign control = physical control + legal control + operational control + technical control + data control + portability + continuity.
A government can therefore have domestically hosted data while remaining dependent upon foreign:
- software;
- hardware;
- cloud management;
- AI models;
- encryption technologies;
- technical personnel;
- corporate governance;
- legal jurisdiction.
Conclusion
Government cloud dependency represents a distinctive intersection of competition law, public procurement, data protection, national security, digital sovereignty and infrastructure regulation.
The principal legal lesson from cases such as United States v Microsoft, Schrems I, Schrems II, Digital Rights Ireland, Tele2/Watson, Google Spain and La Quadrature du Net is that control over digital infrastructure cannot be analysed solely through physical possession of servers. Legal jurisdiction, access rights, fundamental rights, corporate control and technical architecture can be equally important.
For competition policy, the deeper concern is structural dependency. Where governments become locked into a small number of cloud ecosystems, procurement competition at the beginning of a contract may not translate into effective competition throughout the infrastructure's lifetime.

comments