SOVEREIGNTY LAW ATLAS — FR
France
The verdict.
FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04France is the only demo jurisdiction where cloud sovereignty is a formal state qualification — public-sector and OSE workloads effectively require SecNumCloud-qualified providers.
ATLAS RECOMMENDATION — MAXIMUM CLEAN-ORIGIN · SecNumCloud doctrine — clean origin, immunity from extraterritorial reach. Seeded into the configurator; adjust anything.
The dossier.
SOURCES FOOTNOTED · EVIDENCE STATE LABELLEDDomains
D1 — Data residency & localization
GDPR Chapter V governs transfers.1 The Loi Informatique et Libertés (78-17, repeatedly amended) is the national layer, and health data carries its own regime: HDS certification for hosting health data, reflecting a broader French instinct to keep sensitive categories under qualified hosting.
D2 — AI-specific regulation
The EU AI Act applies directly, phased to August 2026 for most obligations.2 The CNIL has published structured AI guidance (GDPR applied to AI systems) and positions itself as an active national voice on the Act's application.
D3 — Cloud & procurement sovereignty
SecNumCloud, run by ANSSI, qualifies cloud services against security *and* sovereignty requirements — including immunity from extraterritorial reach, which in practice excludes US-controlled providers unless structurally separated.3 The "cloud de confiance" doctrine extends the posture beyond government to operators of essential services. France has also pressed for sovereignty criteria in the EU-wide EUCS scheme — contested, unresolved at capture. (REPORTED)
D4 — Export & access
France is the EU's most explicit jurisdiction on extraterritorial access: the SecNumCloud referential treats non-EU access statutes (read: CLOUD Act) as a qualification failure unless the provider is structurally insulated. This is policy, not a ban — but it shapes what can be sold to the French state.
Extraterritorial exposure
CLOUD Act reach applies to US-controlled providers; France's mitigation is the most formalized in the demo set — sovereignty is assessed at the provider-control layer, not the data-location layer, which is exactly the distinction the rest of the market is converging on. US reference record deferred to Phase 2.
Disclaimer
This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied.
- Regulation (EU) 2016/679 (GDPR), Ch. V — EUR-Lex CELEX 32016R0679 — fetch blocked by EUR-Lex bot-gating (202), cited to official source. (REPORTED) ↑
- Regulation (EU) 2024/1689 (AI Act) — EUR-Lex CELEX 32024R1689 — fetch blocked by EUR-Lex bot-gating (202), cited to official source. (REPORTED) ↑
- SecNumCloud referential (v3.2) — ANSSI — cyber.gouv.fr, not vaulted (capture pending). (REPORTED) ↑
The instruments.
3 ON RECORD · 1 GAPSRegulation (EU) 2016/679 (GDPR), Chapter V — transfers to third countries
REPORTEDSecNumCloud referential (v3.2), ANSSI — cloud service qualification
REPORTEDRegulation (EU) 2024/1689 (AI Act)
REPORTEDUS CLOUD Act / FISA 702 reference record deferred to Phase 2 (PRD §3.2)
This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.