🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

LeaseWeb

Netherlands · IaaS · https://www.leaseweb.com

Sovereignty score57.7%
Global (unweighted)55.7%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty82.3SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty54.4SEAL-1
SOV-3 Data & AI Sovereignty55.0SEAL-1
SOV-4 Operational Sovereignty54.4SEAL-3
SOV-5 Supply Chain Sovereignty43.1SEAL-1
SOV-6 Technology Sovereignty50.0SEAL-2
SOV-7 Security & Compliance Sovereignty50.2SEAL-1
SOV-8 Environmental Sustainability56.3SEAL-2

SOV-1 · Strategic Sovereignty 82.3% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (LeaseWeb Global B.V. Amsterdam, owned by Dutch group OCOM/Dutch founders, no non-EU controlling parent) -> entirely within EU, opt4. (src: https://www.leaseweb.com/en/about-us)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highPrivately held by its Dutch founders via OCOM with no external/PE investors; takeover by a non-EU sovereign entity very unlikely (all-SEAL-4 factor, kept).
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumEU-controlled provider active in Gaia-X/IPCEI-CIS governance bodies; roadmap set internally by EU owner with EU-actor participation -> opt3.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highSelf-funded, owned entirely by Dutch founders through OCOM, no disclosed non-EU capital -> entirely EU-based funding (all-SEAL-4 factor, kept).
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4mediumHeadquartered and historically rooted in NL with major EU operations though substantial US/APAC revenue; majority of value in the EU (all-SEAL-4 factor, kept).
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4highMember of Gaia-X AISBL and CISPE and the only Dutch provider in IPCEI-CIS sovereign-cloud programme; strong participation (all-SEAL-4 factor, kept).
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumRuns a European Cloud Campus / Sovereignty-by-Design programme with measured IPCEI-CIS deliverables and dedicated governance (all-SEAL-4 factor, kept).
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2mediumown_stack but with real non-EU operational dependency (NVIDIA/server silicon, US subsidiary); owns network/EU DCs and could source alternatives or internalise, not full autonomy -> opt4 (seal 2).

SOV-2 · Legal & Jurisdictional Sovereignty 54.4% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highCore entity under Dutch/EU law but group runs US (Leaseweb USA Inc.)/UK/Singapore/Hong Kong/Sydney subsidiaries and data centres; mixed EU/non-EU jurisdiction -> opt2 (CEIL, seal 1). Genuine non-EU footprint differentiator vs the pure-EU cluster peers. (src: https://www.datacentermap.com/c/leaseweb/)
SOV-2.2Extraterritorial laws exposure3. EU subsidiary with contractual protections84/167SEAL-1highNo immunity: EU HQ with GDPR/data-residency options but the US subsidiary (Leaseweb USA Inc.) is compellable via the parent under the CLOUD Act and no SecNumCloud/EUCS-High certification; EU entity with contractual protections only -> opt3 (seal 1). (src: https://www.datacentermap.com/c/leaseweb/)
SOV-2.3Data access pathways for non-EU authorities4. Requests disputed, sometimes accepted with notification125/167SEAL-1highDisputes/scrutinises requests and publishes transparency reports, but the US subsidiary can be compelled under the CLOUD Act (no immunity) -> requests disputed/sometimes accepted, opt4 (CEIL/NO3, seal 1). (src: https://www.leaseweb.com/security-certifications)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowMajority of revenue and operations in the EU but no specific export-control shielding of the offer toward EU Member States documented -> opt3 (seal 2).
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4lowPlatform software/tooling developed in the EU but hardware/chip IP (NVIDIA, server silicon) and some third-party software originate outside the EU; mixed (all-SEAL-4 factor, kept).
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3lowLeaseWeb's own software IP held by EU entities while underlying hardware/chip IP is held by non-EU vendors; mixed law with EU component -> opt3.

SOV-3 · Data & AI Sovereignty 55.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2lowIaaS customers can deploy their own encryption but managed offerings typically involve provider-held/override keys; shared control -> opt3.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowLogging/monitoring exist and transparency reports published, but no real-time independently-auditable customer oversight of all flows; vendor-controlled logs -> opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowISO 27001/PCI data-handling implies internal deletion per policy, but no independently verified proof-of-erasure documented -> opt3 (seal 1).
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1highNo eu_exclusive: EU sovereign cloud keeps data in EU by default but the global platform offers US/APAC regions (Washington DC, San Francisco, Singapore, Hong Kong, Sydney, etc.) in the same product; EU-default with controlled exceptions -> opt4 (CEIL/NO3, seal 1). (src: https://www.datacentermap.com/c/leaseweb/)
SOV-3.5AI services sovereignty3. Mixed: auditable/open-source AI, foreign chips100/200SEAL-2mediumAI/HPC runs on imported NVIDIA GPUs with customer-chosen/open models on EU-hostable infra; mixed/auditable AI on foreign chips -> opt3 (seal 2).

SOV-4 · Operational Sovereignty 54.4% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandards-based IaaS with documented APIs, open-definition compute API, Terraform provider and formal migration support -> opt4 (seal 4).
SOV-4.2Ability to operate without foreign dependencies3. Ops balanced EU/non-EU teams84/167SEAL-3mediumOps/NOC centred in Amsterdam but group runs offices/operations across EU, Asia and North America; teams balanced EU/non-EU -> opt3 (seal 3).
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3mediumEngineering/NOC skills concentrated in EU (Amsterdam) with escalation to global teams; majority EU with escalation abroad -> opt3 (seal 3).
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3medium24/7 support from a global org (EU/Asia/NA) with NOC escalation on Amsterdam time; treated as majority-EU with non-EU escalations -> opt3 (seal 3).
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation/knowledge bases EU-managed but global org has non-EU exposure; EU primary with non-EU fallback -> opt3 (seal 4).
SOV-4.6Subcontractor & supplier jurisdiction3. Continue temporarily per contractual agreement84/167SEAL-3lowOwns its own network/datacenters and has contractual supplier arrangements; could continue temporarily and source alternatives -> opt3 (seal 3).

SOV-5 · Supply Chain Sovereignty 43.1% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowServer/GPU hardware sourced from non-EU OEMs with only partial public disclosure of component provenance -> opt2 (seal 1).
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowCompute hardware manufactured abroad (Asia/US OEMs) with limited disclosure; foreign origin, partial transparency -> opt2 (seal 1).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code in servers and accelerators comes from foreign OEMs with only partial disclosure (all-SEAL-4 factor, kept).
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumNo foreign_core: core cloud-platform software (compute API, networking overlay, tooling) is developed and maintained by EU teams on open-source; core/essential parts EU-maintained -> opt3 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware controlled and built by LeaseWeb's EU engineering org; EU control and execution without documented formal EU policy gates -> opt4 (seal 3).
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowA few critical dependencies are non-EU (NVIDIA GPUs, server silicon) but documented; not solely reliant on non-EU vendors -> opt3 (seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers auditable under its ISO 27001/PCI regime, but full end-to-end supply-chain auditability not evidenced -> opt3 (seal 2).

SOV-6 · Technology Sovereignty 50.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based APIs, open-definition compute API and Terraform provider enabling broad compatibility and portability -> opt4 (seal 3).
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumUses open standards (S3-compatible storage, OpenStack-style/Terraform tooling) across core services but not a documented all-services policy -> opt3 (seal 2).
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumBuilds on open source and contributes many projects, but commercial-platform governance is centralised within LeaseWeb (no foreign_core) -> open source, centralised governance, opt3 (seal 3).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowPublic documentation, blogs and open APIs give some public insight into architecture beyond audit-only access -> opt3 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowHPC/AI compute EU-hosted but built on imported NVIDIA accelerators and a foreign hardware stack; EU-hosted, foreign stack -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 50.2% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2mediumHolds ISO 27001:2022 (EY CertifyPoint) + SOC 1 Type II + PCI DSS + NEN 7510 but no C5/ENS-High and no Common Criteria EAL; ISO+SOC maps to EAL2 -> opt3 (seal 2). (src: https://www.leaseweb.com/security-certifications)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumGDPR-committed (CISPE Code of Conduct), ISO 27001:2022, PCI DSS, SOC 1 Type II and DSA reporting; partial-to-strong compliance without a single full independently-audited attestation (all-SEAL-4 factor, kept).
SOV-7.3EU-based SOC & incident handling3. Primary SOC in EU, escalations non-EU72/143SEAL-1lowSecurity monitoring/NOC centred in EU (Amsterdam) with escalation to global teams; primary SOC in EU with non-EU escalation -> opt3 (seal 1).
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get a monitoring portal and reports, but full direct customer access to immutable EU-stored security logs is not demonstrated -> opt3 (seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumDiscloses incidents in line with GDPR/NIS2 expectations and publishes transparency reports; GDPR/NIS2-aligned disclosure -> opt3 (seal 2).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowAs infrastructure owner has moderate maintenance autonomy with notice/testing windows, dependent on OEM firmware/patch cycles -> opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: independent audits occur via certification bodies (EY CertifyPoint) only, no full audit by any entity -> opt2 (CEIL/NO3, seal 1). (src: https://www.leaseweb.com/security-certifications)

SOV-8 · Environmental Sustainability 56.3% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowSelects low-PUE facilities, Climate Neutral Data Centre Pact certified (NL+DE) and ISO 14001:2015 with adiabatic-cooling efficiency roadmap, but no verified PUE below 1.3; PUE<1.5 with roadmap -> opt3 (seal 4). (src: https://www.leaseweb.com/en/about-us/our-story/corporate-social-responsibility)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowDocumented hardware recycling and circular-practice programme with a green team and 90% recycled-materials goal -> documented program, opt3 (seal 3).
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowPublishes sustainability commitments and reports annually, but not a detailed EU-methodology or independently-audited environmental report -> annual report, opt3 (seal 2).
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4mediumNL datacenters on 100% renewable energy and Montreal on hydro; EU footprint on EU green energy though global mix includes non-EU (all-SEAL-4 factor, kept). (src: https://www.leaseweb.com/en/about-us/our-story/corporate-social-responsibility)