Skip to content

GDPR-Compliant Cloud Migration: Breaking Free from Hyperscaler Dependency

Is your infrastructure running on AWS, Azure, or Google Cloud? If so, U.S. authorities theoretically have access to your data—even if the server is located in Frankfurt. At the same time, the EU is taking digital sovereignty seriously: New rules make it easier to switch providers, and European cloud alternatives are being actively promoted.

We’ll help you break free from this dependency—from the initial analysis of your existing infrastructure on AWS, Azure, Google Cloud, or other cloud providers to secure operations on Scaleway, one of the four providers selected by the European Commission for sovereign cloud services.

Background

Why are more and more companies rethinking their cloud strategy?

Four trends are prompting European companies to reevaluate their cloud infrastructure:
  1. Foreign Jurisdiction
    U.S. authorities can access data on AWS, Azure, and Google Cloud—even if the servers are located in the EU.

  2. New EU regulations
    The EU Data Act and the Tech Sovereignty Package are tightening requirements for data sovereignty and cloud portability.

  3. Technical Dependency
    Proprietary services such as AWS Lambda or Google BigQuery make infrastructure difficult to migrate.

  4. Non-Transparent Costs
    Egress fees, reserved instance commitments, and hidden surcharges make budget planning difficult.

None of these developments is new. But together, they create a sense of urgency that can no longer be ignored—and an opportunity to consciously shape our own digital infrastructure.

Scaleway-logo_200x100

SCALEWAY PARTNERS
Your Own Infrastructure on Scaleway
25+
Years of e-commerce experience
8+
Average Customer Retention Period
SINCE 1989

Founded in Göttingen

EU
Sovereign Cloud (Scaleway)
Pimcore Platinum Partner

PIM/MDM Expertise

Why is a cloud based in the U.S. a problem for European companies?

The U.S. CLOUD Act of 2018 gives U.S. authorities the right to request data from U.S. companies—regardless of where that data is physically located.

This affects not only companies with a U.S. parent company, but all customers of AWS, Azure, and Google Cloud: Because these providers are subject to U.S. law, U.S. authorities can access data stored there on behalf of European customers.

A server in Frankfurt or Amsterdam does not change this. The GDPR prohibits precisely such transfers without an international legal basis (Art. 48).

This is not a theoretical risk. In 2025, Microsoft’s French subsidiary confirmed before the French Senate that it cannot guarantee data sovereignty vis-à-vis U.S. authorities—even for data stored in France.

Those who move their infrastructure to a provider not subject to U.S. jurisdiction resolve this conflict at its root.

What exactly do “data sovereignty” and “data autonomy” mean?

Data residency means that data remains within the EU. Data sovereignty means that no access by third countries is legally enforceable. True data sovereignty requires both—and a provider that operates entirely under EU law.

GDPR compliance requires verifiable control over data storage and processing.

For U.S. providers, demonstrating this compliance is structurally more difficult—not because of a lack of technology, but because of the corporate structure. Even “EU regions” and “sovereign cloud” offerings from AWS, Azure, or Google Cloud do not change this as long as the operating company remains a U.S. subsidiary.

How Does Vendor Lock-in Occur with AWS, Azure, and Google Cloud?

Do you use any of these services?

AWS Lambda · DynamoDB · S3 with CloudFront · Google BigQuery · Azure Functions · AWS SQS · Google Cloud Build · Azure DevOps

If so, you’re more locked in than you might think.

Proprietary services make infrastructure difficult to migrate. Those who have deeply integrated them lose three things: bargaining power with the provider, flexibility in making new architectural decisions, and the ability to respond quickly to regulatory changes.

Starting in September 2025, the EU Data Act gives you the right to switch providers more easily. But that right alone does not resolve technical dependencies—that requires a migration strategy.

The good news: If you transition your architecture to open standards, you’ll regain freedom of choice—not just from your current provider, but permanently.

Why are cloud costs with hyperscalers so difficult to plan for?

Cloud spending often grows without a clear breakdown. Egress fees, reserved instance commitments, and opaque pricing models for compute and storage—many companies lack a clear picture of where their budget is going. Cloud cost optimization starts with gaining a clear understanding of the cost structure in the first place.

Scaleway uses transparent, product-level pricing models and includes egress fees for many services. This isn’t a discount promotion—it’s a different philosophy.

Here's an example: Blackbit reduced the total cost of ownership of its own infrastructure by approximately 50% after migrating selected workloads from U.S. hyperscalers to European infrastructure.

Which EU laws apply to your cloud infrastructure?

The EU is no longer just talking about digital sovereignty—it’s putting it into practice. Three developments are directly relevant to your cloud strategy.

  • EU Data Act ( effective as of September 2025)
    The right to switch providers becomes enforceable, and switching fees are eliminated.

  • Tech Sovereignty Package ( adopted on June 3, 2026)
    The Cloud and AI Development Act introduces an EU-wide framework for assessing cloud sovereignty.
  • Cloud III Procurement Program (April 2026)
    The European Commission has selected four sovereign cloud providers—including Scaleway.

How Does the EU Data Act Affect Cloud Contracts?

The EU Data Act has been in effect since September 12, 2025. Cloud providers must actively facilitate switching to another provider: a maximum notice period of two months, completion of the switch within 30 days, and a gradual phase-out of switching fees. At the same time, the Data Act requires providers to take measures against unlawful data access from third countries.

For businesses, this means that the regulatory tailwind for switching providers has never been stronger.

What does the EU Tech Sovereignty Package cover?

On June 3, 2026, the European Commission adopted the Tech Sovereignty Package—a set of measures designed to strengthen Europe’s digital sovereignty. The package comprises four key areas: the Chips Act 2.0 for semiconductor technologies, the Cloud and AI Development Act (CADA) with an EU-wide framework for assessing cloud and AI sovereignty, an open-source strategy for European public administrations, and a roadmap for the digitalization of the energy sector.

Particularly relevant for cloud infrastructure: The Cloud and AI Development Act establishes a unified EU framework for assessing cloud sovereignty—a direct benchmark for companies that process sensitive data. Several EU member states are already taking parallel action: France is developing its own video conferencing solution to replace Microsoft Teams in government agencies, and Denmark is reducing the use of Microsoft software in parts of its public administration.

Why did the European Commission choose Scaleway?

In April 2026, the European Commission selected four cloud providers for the Cloud III procurement program—a €180-million framework agreement for sovereign cloud services spanning up to six years. Scaleway is one of these four providers.

Scaleway is 100% European-owned (Iliad Group), operates data centers exclusively within the EU, and employs all of its staff—including research and development personnel—in Europe. According to Scaleway, for every euro invested, approximately 68 cents are reinvested in the European economy—compared to about 20 cents for international hyperscalers.

What this means for you: These developments primarily affect the public sector. But they set the standard that private companies in regulated industries will also follow. Those who act now can actively shape their own infrastructure—rather than having to react later under time pressure.

Cloud Migration Consulting

What steps are involved in a cloud migration with Blackbit?

We guide you through three steps—from analysis to migration to ongoing operations. Each step has a clear outcome. No step requires you to proceed to the next one.
Free Cloud Independence Audit

Analysis of your existing infrastructure on AWS, Azure, Google Cloud, or other providers: architecture, dependencies, costs, compliance.

Result: Cloud Independence Report with a go/no-go recommendation

 
Cloud Migration
Implementation—full, hybrid, or phased.
Result: Infrastructure on Scaleway
 
Managed Sovereign Platform

Day-to-day operations, monitoring, security, compliance.

Result: Predictable costs under the retainer model

 
Free Cloud Independence Audit

What does the free cloud audit include?

The Free Cloud Independence Audit is an initial assessment of your cloud environment—not a comprehensive technical or legal audit, but a well-informed overview: Where do you stand, what risks exist, and is migration even worth it?
1
What are we going to watch?
Current cloud provider and core services, high-level infrastructure architecture, vendor lock-in and migration risks, key cost factors, data residency and jurisdictional risks, DevOps maturity level.
2
What will you get as a result?
A concise Cloud Independence Report that includes: key risks, major gaps, a recommended target scenario, and suggested next steps.
3
Optional Provider Comparison
Scaleway as the recommended top choice, with a comparison of other EU providers that are relevant to your situation.
4
For Context

Blackbit has reduced its infrastructure costs by approximately 50% after migrating selected workloads from U.S. hyperscalers to European infrastructure. Actual savings depend on architecture, usage patterns, and scale.

Let's be honest: Our audit is an initial assessment.
If switching doesn’t make sense for you, we’ll tell you exactly that.

How does a GDPR-compliant cloud migration work?

A cloud migration is not simply a move in which everything is switched to a new provider on a specific date. It is a structured project involving architectural decisions, parallel operation, and a phased transition—based on the results of the Cloud Independence Audit.

When migrating to the cloud from one provider to another, does everything have to be moved at once?

No. Not every workload needs to be migrated. Some systems are best left on the existing infrastructure, while others benefit immediately from hosting within the EU. We’ll work with you to determine what belongs where—and design an architecture that seamlessly integrates on-premises systems and the EU cloud.

In many cases, the hybrid approach is the most pragmatic solution: Migrate compliance-relevant workloads and personal data to Scaleway. Other services—such as content delivery or certain SaaS integrations—remain in place as long as compliance is ensured. This allows you to reduce risk and effort without compromising data sovereignty.

What happens from a technical standpoint during cloud migration?

DevOps Pipeline Transformation

We migrate CI/CD workflows that are tied to AWS CodePipeline, Azure DevOps, or Google Cloud Build to open, vendor-neutral alternatives. The goal: a deployment pipeline that works on any infrastructure—and never ties you to a single vendor again.

Zero-Downtime Migration

Phased implementation with parallel operation. Your existing infrastructure continues to run while the new environment is set up and tested. No “big bang” deadline, no uncontrolled risk. Each migration step is validated before the next one begins.

Managed Sovereign Platform

Who will manage the infrastructure after the cloud migration?

After the migration, there are two options:

Option A – Blackbit takes over operations: We operate and monitor your EU-sovereign infrastructure under a retainer model. Your team doesn’t need to build its own cloud expertise.

Option B – Your team takes over: We train your team, gradually hand over operations and documentation, and provide support during the transition phase.

Both options can be combined—for example, if your team takes over day-to-day operations while Blackbit remains responsible for escalations, security updates, and compliance monitoring.

What does Blackbit handle during normal operations?

  • EU-based hosting on Scaleway: Data centers in Paris, Amsterdam, and Warsaw. Exclusively under EU jurisdiction.
  • Infrastructure Management: Operation and scaling of your platform with appropriate managed services—tailored to your architecture and requirements.
  • CI/CD pipelines: Automated deployments, rollback strategies, and release management.
  • Monitoring and Performance: Proactive monitoring, alerting, and performance tuning at the infrastructure and application levels.
  • Backup and Disaster Recovery: Automated backups, tested recovery processes, documented RPO/RTO targets.
  • Security and Compliance: Security updates, vulnerability scanning, ongoing GDPR compliance documentation.

Retainer Model for Predictable Costs

Predictable monthly costs instead of unexpected one-time bills. Prices for Managed Sovereign Infrastructure packages are determined on a case-by-case basis based on architecture, workload, and required service level.

A rough estimate based on our own experience: Blackbit reduced the total cost of ownership for its own infrastructure by approximately 50% after migrating selected workloads from U.S. hyperscalers to European infrastructure. Actual savings depend on the architecture, usage patterns, and the scope of the migration.

The free Cloud Independence Audit includes an initial cost assessment and identifies the key cost drivers as well as potential areas for optimization.
Case Study

Blackbit's Own Path to Cloud Independence

Blackbit reviewed its own infrastructure and migrated selected workloads from U.S. hyperscalers to European cloud infrastructure. This reduced the company’s dependence on U.S. providers and lowered the total cost of ownership for the infrastructure by approximately 50%.
Why Blackbit

Why Choose Blackbit for Cloud Migration Consulting and Implementation?

We are not just a cloud agency. We are a commerce engineering agency with in-house infrastructure expertise—and we already operate client infrastructure on Scaleway. This recommendation stems from our day-to-day operations, not from a partner agreement.

As a Pimcore Platinum Partner, we understand the infrastructure, performance, and compliance requirements of complex commerce platforms. For us, cloud migration consulting isn’t a standalone service—it’s part of a comprehensive understanding of digital commerce architecture.

And if a migration doesn’t make sense for your situation, we’ll tell you so. We’re not driven by commission incentives to make a recommendation that doesn’t fit your business.

Next Step

How can you determine how dependent your company is on U.S. hyperscalers?

With the free Cloud Independence Audit. We analyze your cloud architecture, assess dependencies, costs, and compliance risks—and provide you with an honest assessment of whether migrating to EU-sovereign infrastructure makes sense for your company. No sales pitch, no presentation—just your questions and our assessment.


FAQ

Frequently Asked Questions About Cloud Migration and EU-Controlled Infrastructure

What exactly is analyzed in the Free Cloud Independence Audit? The audit is an initial assessment, not a comprehensive technical or legal audit. We review your current cloud provider and core services, evaluate the infrastructure architecture at a high level, identify vendor lock-in and migration risks, examine key cost factors, assess data residency and jurisdictional risks, and evaluate your DevOps maturity level. The result is a concise Cloud Independence Report highlighting key risks, major gaps, a recommended target scenario, and suggested next steps. Optionally, we can also provide a vendor comparison. The audit is free of charge and non-binding.
Is a complete cloud migration from AWS to Scaleway realistic? That depends on your architecture. Companies that rely heavily on proprietary AWS services (Lambda, DynamoDB) face a greater migration effort than those that are already containerized and use open standards. In many cases, a hybrid approach makes more sense: migrate compliance-related workloads to EU infrastructure, while leaving others—for now—where they are. The audit will determine which migration approach is best suited to your situation.
How much does a GDPR-compliant cloud migration cost? The costs depend on the scope: how many workloads are being migrated, the extent of the dependency on proprietary services, and whether a full or hybrid migration is taking place. Following the Cloud Independence Audit, we provide a transparent breakdown of costs—including effort, timeline, and ongoing expenses. We do not quote flat rates because every infrastructure is different.
Why did the European Commission choose Scaleway? Scaleway is one of the four cloud providers selected by the European Commission in April 2026 for the Cloud III procurement program—a €180-million framework contract for sovereign cloud services. Scaleway is 100% European-owned (Iliad Group), operates data centers exclusively within the EU, and employs all of its staff in Europe. OVHcloud, Hetzner, and IONOS are also European alternatives—in the Cloud Independence Report, we compare the relevant options for your specific situation and evaluate which provider is best suited to your needs.
Would a hybrid solution—partly AWS, partly an EU cloud—work? Yes, and in many cases, that’s the most pragmatic solution. Workloads subject to compliance requirements, personal data, and business-critical systems are migrated to Scaleway. Other services—such as content delivery or certain SaaS integrations—remain on the existing infrastructure as long as compliance is ensured. We design hybrid architectures that seamlessly integrate both worlds.
How long does a cloud migration take? That depends heavily on the project. A straightforward cloud migration of containerized workloads can be completed in a few weeks. Complex infrastructures with deep AWS integration, database migrations, and legacy systems require several months of parallel operation. We work in phases—each step is validated before the next one begins. The Cloud Independence Audit provides you with a realistic time estimate.
How has the EU Data Act changed existing cloud contracts? The cloud switching rules of the EU Data Act (Regulation (EU) 2023/2854, Chapter VI) have been in effect since September 12, 2025. Cloud providers must actively facilitate switching to another provider: a maximum notice period of two months, completion of the switch within 30 days, and a phased reduction of switching fees. Chapter VII additionally requires providers to take measures against unlawful data access from third countries—this directly addresses the conflict between the U.S. CLOUD Act and the GDPR. Whether the switching rules also apply to contracts concluded before September 2025 has not yet been conclusively clarified in law.
Who will manage the infrastructure after the cloud migration? That’s up to you. There are two options: Blackbit handles day-to-day operations under a retainer model—EU-based hosting, infrastructure management, CI/CD, monitoring, security, and compliance documentation. Or Blackbit will mentor your team and gradually hand over operations, providing documentation, knowledge transfer, and support during the transition phase. Both models can be combined.