🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Huawei Cloud

China · IaaS/PaaS · https://www.huaweicloud.com

Sovereignty score33.9%
Global (unweighted)34.3%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty30.2SEAL-0
SOV-2 Legal & Jurisdictional Sovereignty16.8SEAL-1
SOV-3 Data & AI Sovereignty40.0SEAL-0
SOV-4 Operational Sovereignty29.3SEAL-1
SOV-5 Supply Chain Sovereignty18.0SEAL-0
SOV-6 Technology Sovereignty40.0SEAL-2
SOV-7 Security & Compliance Sovereignty50.1SEAL-1
SOV-8 Environmental Sustainability50.0SEAL-2

SOV-1 · Strategic Sovereignty 30.2% · SEAL-0 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control2. Mostly outside the EU42/125SEAL-1highforeign_parent (Chinese): EU offering runs via Irish subsidiary Sparkoo Technologies Ireland, but controlling parent Huawei Investment & Holding is Chinese; control sits mostly outside the EU -> opt2 (seal 1). (src: https://scope-europe.eu/en/detail/sparkoo-technologies-ireland-co-limited-with-its-cloud-brand-name-huawei-cloud-declares-adherence-to-the-eu-cloud-code-of-conduct)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumAlready a Chinese-controlled group; no realistic risk of further takeover by another non-EU sovereign entity, so a transfer is very unlikely -> opt5 (all-seal-4 factor, choice kept).
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumforeign_parent: roadmap is set centrally by Huawei in China; EU customers have only voice-of-customer public channels, no EU governance body -> opt2 (seal 2).
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highFunding originates almost entirely from the Chinese parent group; no meaningful EU capital base -> opt1 (all-seal-4 factor, choice kept).
SOV-1.5EU economic contribution2. Some31/125SEAL-4mediumSome EU economic contribution via Irish entity, data centres and local jobs, but the bulk of R&D, manufacturing and value capture is in China -> opt2 (all-seal-4 factor, choice kept).
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4mediumGaia-X member but contentious; not a recognised participant in EU strategic programs like IPCEI-CIS, only limited participation -> opt2 (all-seal-4 factor, choice kept).
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo evidence of alignment with EU industrial strategy; positions itself as an alternative to Western/EU tech and EU policy treats it as a sovereignty risk -> opt1 (all-seal-4 factor, choice kept).
SOV-1.8Resilience to cut-off2. Service would stop, with delay for customer reaction31/125SEAL-0lowNo own_stack: not EU-autonomous; on a sanctions/export cut-off the service would stop with some delay for customer reaction (single non-EU vendor/parent dependency) -> opt2 (seal 0).

SOV-2 · Legal & Jurisdictional Sovereignty 16.8% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highEU ops under Irish entity (Sparkoo Technologies Ireland) but ultimate parent and IP governed by PRC law; jurisdiction is mixed EU/non-EU -> opt2 (seal 1). (src: https://eucoc.cloud/en/detail/press-release-huawei-cloud-becomes-a-member-of-the-eu-cloud-code-of-conduct)
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highNo immunity: EU subsidiary with contractual privacy commitments (EU Cloud CoC adherence) but remains exposed to PRC National Intelligence/Data Security/Cybersecurity laws via the parent -> opt2 (seal 1). Genuine differentiator vs peers: dedicated Irish operating entity. (src: https://www.huaweicloud.com/eu/securecenter/compliance/compliance-center/eu_cloud_coc.html)
SOV-2.3Data access pathways for non-EU authorities1. Can compel access without customer notification0/167SEAL-1highforeign_parent (PRC law): National Intelligence Law Art. 7 compels Chinese organisations and overseas subsidiaries to assist intelligence work, allowing compelled access without notification -> opt1 (seal 1) [caps SEAL at 1]. (src: https://www.huaweicloud.com/eu/securecenter/compliance/compliance-center/eu_cloud_coc.html)
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1mediumSubject to extensive Western export controls affecting chip/tech supply, creating restriction risk toward EU customers and international orgs -> opt2 (seal 1).
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highCore IP (Kunpeng/Ascend chips, Pangu models, cloud software) is designed and held in China, entirely outside the EU -> opt1 (all-seal-4 factor, choice kept).
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highIP held under PRC law by Chinese entities, a single non-EU country -> opt1 (seal 3).

SOV-3 · Data & AI Sovereignty 40.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2mediumKMS/customer-managed keys offered, but as provider it retains override capability and is compellable under PRC law; keys are shared, not customer-exclusive -> opt3 (seal 2).
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2mediumCloud Trace/audit logging exists but is vendor-operated, not real-time independently auditable by the customer -> opt3 (seal 2).
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion performed per internal policy with confirmation but without independently verifiable proof of irreversible erasure -> opt3 (seal 1).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0mediumNo eu_exclusive guarantee: although it has genuine EU regions (Dublin/Amsterdam/Paris) the offer is global-default with non-EU regions, global support and PRC parent access -> significant third-country reliance -> opt2 (seal 0 gate). (src: https://www.huaweicloud.com/eu/securecenter/data_protection/region_query.html)
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2highPangu models and Ascend AI accelerators are Chinese-origin; AI services are largely licensed/black-box with a hard non-EU chip dependency -> opt2 (seal 2).

SOV-4 · Operational Sovereignty 29.3% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandard documented data export and S3/OpenStack-compatible interfaces enable standard export methods, though no sovereign-infra deployment -> opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies2. Ops partially sourced within EU42/167SEAL-1mediumNo eu_ops: critical engineering and platform operations run from China with EU regions locally staffed; ops only partially sourced within the EU -> opt2 (seal 1).
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1mediumWorkforce and expertise predominantly in China with EU-local presence; majority of skills sit outside the EU -> opt2 (seal 1).
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2lowSupport is global with significant follow-the-sun/China-based escalation; majority of support capability is outside the EU -> opt2 (seal 2).
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowEU-language documentation and trust-centre material exist but EU-only knowledge custody not enforced; global repositories apply -> opt2 (seal 2).
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2lowNo own_stack: on loss of the foreign parent/chip supply chain the service would stop with delay; limited ability to internalise critical functions in the EU -> opt2 (seal 2).

SOV-5 · Supply Chain Sovereignty 18.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1mediumHardware (Kunpeng/Ascend, Huawei servers) is Chinese-origin with only partial public disclosure of component provenance -> opt2 (seal 1).
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1highServers and silicon designed and manufactured in China; foreign origin with at best partial disclosure, no EU build -> opt2 (seal 1).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4mediumFirmware/embedded code is Huawei-proprietary from China with only partial disclosure; no EU-certified firmware provenance -> opt2 (all-seal-4 factor, choice kept).
SOV-5.4Origin of software1. Fully foreign origin, black box0/143SEAL-0highWorse than foreign_core: cloud software is fully Chinese-origin black-box, designed and maintained in China, not EU-maintained and not a disclosed licensed core -> opt1 (seal 0 gate).
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1mediumSoftware build and release pipeline is controlled and executed in China; non-EU control and execution -> opt1 (seal 1).
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1mediumCritical dependencies (chips, core software, parent) are non-EU and largely undocumented from a sovereignty standpoint -> opt2 (seal 1).
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome certification-driven auditability exists, but the deep China-based supply chain is not broadly independently auditable -> opt2 (seal 1).

SOV-6 · Technology Sovereignty 40.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumMix of proprietary APIs with some OpenStack/S3-compatible and Kubernetes-based open interfaces; partial openness -> opt3 (seal 2).
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumPartial adoption of open standards (OpenStack, Kubernetes, S3 API) across core services rather than a comprehensive open-standards policy -> opt3 (seal 2).
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2lowforeign_core: platform largely vendor-controlled; Huawei contributes to some OSS but the cloud stack itself is mostly closed with limited review rights -> opt2 (seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowPublic architecture/security white papers and trust-centre documentation provide some public insight into the service architecture -> opt3 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumHPC/AI compute can be EU-hosted but runs on a fully foreign (Chinese Ascend) stack, no EU processor IP -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 50.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumHolds German BSI C5 plus ISO 27001 and SOC 2 Type II; per gating_key BSI C5 (high-assurance national cloud cert) maps to EAL3 -> SOV-7.1 opt4 (seal 3; was opt3). Applied identically to Alibaba which also holds C5. (src: https://www.huaweicloud.com/intl/en-us/securecenter/compliance/compliance-center.html)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumGDPR alignment, EU Cloud Code of Conduct adherence (Sparkoo Ireland) and broad certifications indicate partial compliance to most EU regulatory regimes -> opt4 (all-seal-4 factor, choice kept).
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSecurity operations and incident response are hybrid, with EU presence but China-based escalation and threat intelligence -> opt2 (seal 1).
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get a monitoring/logging portal (Cloud Eye/Cloud Trace) but not full immutable EU-resident tamper-proof control of all logs -> opt3 (seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure is GDPR/NIS2-aligned for the EU entity but without demonstrated real-time CSIRT integration -> opt3 (seal 2).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowCustomers have moderate maintenance autonomy with notice and testing windows for non-zero-day updates -> opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: auditability limited to certification-driven access and vendor-mediated audits; no full independent audit by any entity -> opt2 (seal 1).

SOV-8 · Environmental Sustainability 50.0% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4mediumFlagship Huawei data centres report PUE around 1.12-1.15 with an efficiency roadmap, but these are not EU-verified figures for the EU regions -> PUE<1.5 + roadmap -> opt3 (seal 4). (src: https://www.huawei.com/en/sustainability/the-latest/stories/green-data-centers-optimal-pue)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowDocumented hardware reuse and recycling programs, but not demonstrably EU-aligned circular-economy certification -> opt3 (seal 3).
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowAnnual sustainability/environmental reporting published at group level, but not using a detailed EU methodology or EU-audited -> opt3 (seal 2).
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowEnergy supply for EU data centres draws on a mix of EU grid and renewable PPAs alongside non-EU group operations; mixed EU/non-EU supply -> opt3 (all-seal-4 factor, choice kept). (src: https://www.huawei.com/en/sustainability/the-latest/stories/full-liquid-cooling-data-centers-energy-efficient)