🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Alibaba Cloud

China · IaaS/PaaS · https://www.alibabacloud.com

Sovereignty score30.2%
Global (unweighted)32.4%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty15.6SEAL-0
SOV-2 Legal & Jurisdictional Sovereignty12.6SEAL-1
SOV-3 Data & AI Sovereignty45.0SEAL-0
SOV-4 Operational Sovereignty25.1SEAL-1
SOV-5 Supply Chain Sovereignty18.0SEAL-0
SOV-6 Technology Sovereignty40.0SEAL-2
SOV-7 Security & Compliance Sovereignty46.6SEAL-1
SOV-8 Environmental Sustainability56.3SEAL-2

SOV-1 · Strategic Sovereignty 15.6% · SEAL-0 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highforeign_parent (Alibaba Group Holding, Hangzhou CN / Cayman-incorporated) -> entity control entirely outside the EU -> SOV-1.1 opt1. (src: https://www.sec.gov/Archives/edgar/data/1577552/000104746915006981/a2225750zf-4.htm)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumAlready controlled by a non-EU (Chinese) parent and a core strategic asset; a transfer to a *non-EU* sovereign entity is very unlikely (no realistic path), so opt5 per existing all-seal-4 choice.
SOV-1.3Control over roadmap1. No influence possible0/125SEAL-2highRoadmap set centrally by Alibaba Group in China; no EU-actor governance bodies, only ordinary feedback -> SOV-1.3 opt1 (no influence possible).
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highFunding almost entirely non-EU (Alibaba Group capital, NYSE/HKEX listings, US/Asian institutional investors); no material EU funding base -> opt1 (all-seal-4 factor).
SOV-1.5EU economic contribution1. Minimal0/125SEAL-4mediumEU footprint a small fraction of an overwhelmingly China-centric business; EU economic contribution minimal -> opt1 (all-seal-4 factor).
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo clear participation in EU strategic programs (Gaia-X leadership, IPCEI-CIS); effectively excluded as a Chinese provider -> opt1 (all-seal-4 factor).
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo published action plan aligned with EU industrial strategies; industrial strategy aligns with Chinese national priorities -> opt1 (all-seal-4 factor).
SOV-1.8Resilience to cut-off2. Service would stop, with delay for customer reaction31/125SEAL-0lowNo own_stack: continuity depends entirely on the Chinese parent. On forced cut-off (sanctions/withdrawal) the service stops, with some delay for customer reaction -> SOV-1.8 opt2 (seal 0).

SOV-2 · Legal & Jurisdictional Sovereignty 12.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highEU contract runs through EU entity/regions (Frankfurt) under EU law, but the group is governed by Chinese law (PRC law dominant over the parent) -> mixed EU/non-EU -> SOV-2.1 opt2. (src: https://www.alibabacloud.com/en/trust-center/compliance)
SOV-2.2Extraterritorial laws exposure1. Fully exposed to non-EU laws0/167SEAL-1highNo immunity: fully exposed to extraterritorial PRC laws (National Intelligence Law Art.7, Cybersecurity Law, Data Security Law) compelling cooperation -> SOV-2.2 opt1. (src: https://www.sec.gov/Archives/edgar/data/1577552/000104746915006981/a2225750zf-4.htm)
SOV-2.3Data access pathways for non-EU authorities1. Can compel access without customer notification0/167SEAL-1highforeign_parent (PRC): authorities can compel the parent to provide data access without customer notification, no effective refusal -> SOV-2.3 opt1 (caps SEAL at 1). (src: https://www.alibabacloud.com/en/trust-center/compliance)
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowNo eu_exclusive shield: subject to Chinese export-control/data-export regimes plus Western sanctions risk affecting EU citizens/international orgs; revenue overwhelmingly China, not majority-EU -> normalised to cluster answer SOV-2.4 opt2 (Restrictions towards EU citizens/intl orgs), consistent with Tencent/Huawei (was opt3, undocumented).
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highIP (Apsara, ECS, OSS, Qwen, T-Head chip IP) developed and owned by Alibaba Group entities in China; origin entirely outside the EU -> opt1 (all-seal-4 factor).
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highCore IP held by Alibaba Group under Chinese (and Cayman) law - a single non-EU jurisdiction -> SOV-2.6 opt1.

SOV-3 · Data & AI Sovereignty 45.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2mediumKMS with BYOK/customer-managed keys plus Dedicated/Managed HSM exist, but as a PRC-compellable provider it operates the platform and retains override / can technically read data -> shared keys, provider has override -> normalised to cluster answer SOV-3.1 opt3 (was opt4; provider-cannot-read not credible under PRC law).
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2mediumActionTrail/CloudMonitor provide access/audit logs but vendor-operated and not real-time independently auditable by the customer -> SOV-3.2 opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion follows internal lifecycle policy (per ISO 27018) with no independent cryptographic proof of irreversible erasure -> SOV-3.3 opt3 (policy-only).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0mediumNot eu_exclusive: EU regions (Frankfurt) offer residency but it is a global-default product with a PRC-controlled management plane creating significant third-country exposure and no contractual no-fallback guarantee -> SOV-3.4 opt2 (seal 0 gate; was opt4 which gave seal 1 and broke the SEAL-0 target). (src: https://www.alibabacloud.com/en/press-room/alibaba-cloud-launches-third-datacentre-in-germany)
SOV-3.5AI services sovereignty3. Mixed: auditable/open-source AI, foreign chips100/200SEAL-2mediumAI partly open/auditable (open-source Qwen on Hugging Face/ModelScope) but runs on foreign/Chinese-designed accelerators (Hanguang) fabbed outside the EU -> mixed, not EU-led -> SOV-3.5 opt3.

SOV-4 · Operational Sovereignty 25.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandard documented export/API methods (S3-compatible OSS, standard formats) support portability despite higher-level managed-service lock-in -> SOV-4.1 opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1mediumNo eu_ops: critical operations, platform engineering and management plane delivered by non-EU (mainly Chinese) teams; cannot be operated without the parent -> SOV-4.2 opt1.
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1lowEngineering/operational skills concentrated in China; EU staff a minority on regional sales/support -> mixed, majority outside the EU -> SOV-4.3 opt2.
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2lowGlobal follow-the-sun support with significant China/Asia presence; some EU support exists but the majority sits outside the EU -> SOV-4.4 opt2.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation/knowledge bases are global with primary engineering/content originating in China; EU access is optional, not enforced -> SOV-4.5 opt2 (EU optional).
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2lowSubcontractors/suppliers largely non-EU (parent group, Chinese/Asian vendors); on disruption the service stops with some delay and no EU-side ability to internalise -> SOV-4.6 opt2.

SOV-5 · Supply Chain Sovereignty 18.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowHardware (T-Head Yitian/Panjiu servers plus third-party components) sourced/assembled outside the EU with only partial provenance disclosure -> SOV-5.1 opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1mediumServers/chips foreign-manufactured (China design, TSMC/foundry fabrication) with partial disclosure; no EU manufacturing or EU audit rights -> SOV-5.2 opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code in custom T-Head silicon and servers is proprietary, developed in China, with only partial disclosure -> opt2 (all-seal-4 factor).
SOV-5.4Origin of software1. Fully foreign origin, black box0/143SEAL-0highBeyond foreign_core: core platform software (Apsara, control plane, managed services) is fully foreign-origin, China-maintained and a black box to EU customers -> SOV-5.4 opt1 (seal 0 gate).
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1mediumBuild/release pipelines controlled and executed by Alibaba in China; no EU control or EU execution -> SOV-5.5 opt1.
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1mediumCritical dependencies mostly non-EU (Chinese parent for software, operations and chip supply) and largely undocumented for EU sovereignty -> SOV-5.6 opt2.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers auditable via certification reports, but the full supply chain (parent, chip foundries) is not independently auditable by EU customers -> SOV-5.7 opt2.

SOV-6 · Technology Sovereignty 40.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumMixed openness: many APIs are AWS/S3-compatible and standards-aligned, but core managed services use proprietary interfaces creating partial lock-in -> SOV-6.1 opt3.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowOpen standards adopted in parts of the core (S3 API, standard protocols, Kubernetes/ACK) but no comprehensive policy mandating open standards across all core services -> SOV-6.2 opt3 (partial).
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumforeign_core: core platform is closed-source and vendor-controlled; though Alibaba open-sources components (Qwen, RISC-V XuanTie), core/key-project governance is centralised under Alibaba in China -> SOV-6.3 opt2 (seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSome public architectural insight via docs/whitepapers/blogs, but customers cannot adapt or deeply inspect the proprietary platform internals -> SOV-6.4 opt3 (some public insight).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowHPC/accelerated computing in EU regions is EU-hosted but runs a foreign (Chinese/non-EU-designed) hardware+software stack; no EU processor IP or EU fab -> SOV-6.5 opt2 (EU-hosted, foreign stack).

SOV-7 · Security & Compliance Sovereignty 46.6% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumHolds German BSI C5 (Germany + Singapore) plus ISO 27001 and SOC 2 Type 2; per gating_key BSI C5 maps to EAL3 -> SOV-7.1 opt4 (seal 3; was opt1, which mis-scored a real high-assurance national cloud cert). (src: https://www.alibabacloud.com/en/trust-center/security-compliance-practice)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumHolds broad certs (ISO 27001/27017/27018/27701, SOC 1/2/3, PCI DSS, German C5, AIC4) with GDPR-aligned commitments -> partial compliance to most -> opt4 (all-seal-4 factor).
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSecurity operations global (follow-the-sun) with substantial China-based capability; SOC/incident handling hybrid EU/non-EU -> SOV-7.3 opt2.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get a monitoring/logging portal (CloudMonitor, ActionTrail) but not full direct control with guaranteed immutable EU-resident log storage -> basic monitoring portal -> normalised to cluster answer SOV-7.4 opt3 (seal 1), consistent with Tencent/Huawei (was opt2).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowIncident disclosure moderate and GDPR/NIS2-aligned for EU customers via contract, but without real-time CSIRT/ENISA integration -> SOV-7.5 opt3 (moderate).
SOV-7.6Maintenance autonomy2. Limited autonomy (vendor schedules)36/143SEAL-1lowMaintenance on vendor-controlled schedules with limited customer autonomy over the managed platform -> SOV-7.6 opt2 (limited autonomy).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: auditability limited to certification audits and contractual reports; no full independent EU audit of the platform -> SOV-7.7 opt2.

SOV-8 · Environmental Sustainability 56.3% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)4. PUE < 1.3188/250SEAL-4mediumAlibaba Cloud reports a fleet-average PUE of 1.200 for self-built data centres (FY ending Mar 2024); EU-region independent verification is not confirmed, so opt5 ('PUE<1.2, EU verified') is not met -> SOV-8.1 opt4 (PUE<1.3; was opt5). (src: https://www.alibabagroup.com/en-US/document-1752073403914780672)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowDocumented hardware reuse/recycling program within ESG reporting, but not EU-certified or specifically EU-aligned circular-economy compliant -> SOV-8.2 opt3 (documented program). (src: https://www.alibabagroup.com/en-US/document-1752073403914780672)
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumPublishes an annual ESG/carbon report with quantified PUE, clean-energy share and emissions, but on global/Chinese methodology rather than an EU-audited framework -> SOV-8.3 opt3 (annual report). (src: https://www.alibabagroup.com/en-US/document-1752073403914780672)
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowEnergy a mix of EU and non-EU sources (global clean-energy share ~56%, 100% target by 2030); EU regions draw on a mixed grid -> opt3 (all-seal-4 factor). (src: https://www.alibabagroup.com/en-US/document-1752073403914780672)