🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Open Telekom Cloud

Germany · IaaS/PaaS · https://www.open-telekom-cloud.com

Sovereignty score68.7%
Global (unweighted)68.2%
Overall SEAL
SEAL-2 Data Sovereignty
SOV-1 Strategic Sovereignty82.3SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty79.2SEAL-2
SOV-3 Data & AI Sovereignty85.0SEAL-3
SOV-4 Operational Sovereignty58.5SEAL-3
SOV-5 Supply Chain Sovereignty43.2SEAL-2
SOV-6 Technology Sovereignty50.0SEAL-2
SOV-7 Security & Compliance Sovereignty78.5SEAL-3
SOV-8 Environmental Sustainability68.9SEAL-3

SOV-1 · Strategic Sovereignty 82.3% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4highOperated by T-Systems, a wholly-owned subsidiary of Deutsche Telekom AG, a German (EU) incorporated company; the legal entity controlling the service is entirely within the EU. (src: https://www.open-telekom-cloud.com/en/products-services/core-services/certifications)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highDeutsche Telekom is a German blue-chip with the German federal government (via direct holding + KfW) as its largest shareholder at ~28%; takeover/transfer to a non-EU sovereign entity is very unlikely.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumBuilt on OpenStack/Kubernetes with EU governance, and Deutsche Telekom drives the roadmap including a planned 'Germany Stack'; EU actors participate in governance but the core OpenStack distribution is supplied by Huawei, limiting full control.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highDeutsche Telekom is EU-listed and EU-funded with the German state as anchor shareholder; financing is entirely EU-based.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highOperations, data centres (Biere/Magdeburg, Amsterdam), staff and revenue from the service are concentrated in the EU; economic contribution is fully in the EU.
SOV-1.6Participation in EU strategic programs3. Active participant in strategic projects63/125SEAL-4mediumOpen Telekom Cloud is Gaia-X compliant and Deutsche Telekom is a member of Gaia-X and engaged in German sovereign-cloud initiatives; an active participant in EU strategic projects without strategic projects depending on it.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumMarkets itself as 'from Europe for Europe' with measurable alignment (Gaia-X, sovereign public-administration cloud, Germany Stack ambition) and dedicated governance, but full bold means are still emerging.
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2mediumNo own_stack: the core OS is the Huawei FusionSphere/OpenStack distribution, a real non-EU operational dependency. As a German operator with EU data centres T-Systems could source alternatives or internalise key functions if cut off -> opt4 (seal 2), short of full autonomy.

SOV-2 · Legal & Jurisdictional Sovereignty 79.2% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highT-Systems is a German provider with data exclusively in Germany and the Netherlands, subject exclusively to EU/German law; no non-EU parent jurisdiction applies. (src: https://www.open-telekom-cloud.com/en/products-services/core-services/certifications)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2highimmunity is structural-not-certified: German-incorporated, no US parent, legal structures shielding from foreign law (e.g. CLOUD Act), but no SecNumCloud 3.2 / EUCS-High and a residual Huawei nexus in the core -> opt4 'Legal structures shielding' (seal 2), not verified statutory immunity. Genuine differentiator vs. the pure-DE anchors.
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: German entity, no US/CN authority can compel access (Huawei has no production or customer-data access) -> opt5 'Requests always rejected' (seal 4).
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4lowConsistency with its operator T-Systems and the German cohort: a German EU operator with EU-based revenue/operations and no export-control restrictions toward EU member states or international orgs -> offer shielded toward EU MSs, opt5.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4mediumCore platform IP is the Huawei OpenStack Distribution (non-EU/Chinese origin) layered on open-source OpenStack, with significant EU-developed operational tooling and integration; mixed within/outside the EU.
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3lowUnderlying Huawei-licensed software IP is held under non-EU (Chinese) law while operational and integration IP sits with Deutsche Telekom under EU law; mixed law with some EU.

SOV-3 · Data & AI Sovereignty 85.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys5. Customer exclusive control - provider cannot read data200/200SEAL-4highOffers BYOK and HYOK (Hold Your Own Key) so customers can hold keys exclusively, rendering data unreadable to the provider; zero-access architecture is promoted.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowProvides customer-controlled access logging and monitoring (Cloud Trace/audit services) with C5/SOC attestations, giving full customer visibility though not described as fully real-time independently auditable.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowDeletion is technically verified with access/audit logs under BSI C5 Type 2 / ISO 27001 controls (Cloud Trace logs in EU DCs) -> opt4 (seal 3), consistent with peer C5/ISO-based offers; not independently cryptographically proven (opt5).
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4highData is stored exclusively in EU data centres (Germany and the Netherlands, both regions certified) with no third-country fallback per provider statements and C5 scope. (src: https://www.open-telekom-cloud.com/en/products-services/core-services/certifications)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowConsistency with T-Systems and the cohort: AI/ML services run on the EU-operated OpenStack platform using auditable/open-source frameworks; EU-led AI on foreign (non-EU) GPU accelerators -> opt4.

SOV-4 · Operational Sovereignty 58.5% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandards-based (OpenStack, Kubernetes, Terraform/OpenTofu) with documented export methods and formal migration support, easing portability away from lock-in.
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumInfrastructure operation, maintenance, hardware decommissioning and software installation are performed exclusively by T-Systems (EU) staff; Huawei has no production access and only provides 3rd-level video-conference advice, so ops are predominantly EU-based but a non-EU advisory dependency remains.
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3mediumEngineering and operations skills are majority EU-based at T-Systems, with occasional escalation to Huawei third-level experts abroad.
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3mediumFirst and second level support handled exclusively by T-Systems in the EU, with non-EU (Huawei) third-level escalation by video conference only.
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowPrimary documentation and knowledge sit with EU-based T-Systems, with the Huawei-supplied platform implying some non-EU fallback for deep platform knowledge.
SOV-4.6Subcontractor & supplier jurisdiction3. Continue temporarily per contractual agreement84/167SEAL-3lowCritical software supplier (Huawei) and some hardware are non-EU, but contractual partnership terms and EU-only operations would allow temporary continuation; alternatives sourcing is feasible but not immediate.

SOV-5 · Supply Chain Sovereignty 43.2% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3mediumHardware suppliers (incl. Huawei) are disclosed; component sourcing is transparent with exceptions under the sovereign offer / C5 scope -> opt3 (seal 3), consistent with peer providers using foreign components.
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3mediumMixed sourcing of foreign-origin hardware with EU audit rights under BSI C5/ISO controls -> opt3 (seal 3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code on foreign (Huawei and other) hardware is only partially disclosed.
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2highforeign_core: the core cloud OS is the Huawei OpenStack/FusionSphere distribution (licensed Chinese tech) with partial disclosure, not EU-maintained -> opt2 (seal 2). This is the SEAL-2 ceiling and the genuine differentiator vs. the own-stack German cohort. (src: https://www.huawei.com/en/news/2016/10/deutsche-telekom-cloud-openstack-interoperability-tests)
SOV-5.5Software build/release jurisdiction3. Non-EU control, EU execution72/143SEAL-3lowThe platform software is built/released under the Huawei (non-EU) partnership while deployment, integration and operation execution sit with EU-based T-Systems; non-EU control with EU execution.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumHuawei is a documented non-EU single point of dependency in a critical service (core OpenStack distribution and part of hardware), creating a critical non-EU dependency that is at least documented.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers are subject to audit under BSI C5/ISO 27001 controls, but full supply-chain auditability is not demonstrated.

SOV-6 · Technology Sovereignty 50.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3highStandards-based and broadly compatible via OpenStack and Kubernetes APIs, enabling interoperability and portability.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumOpen standards (OpenStack, Kubernetes, Terraform/OpenTofu) are adopted as policy across most core services.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumforeign_core: although built on upstream open-source OpenStack/Kubernetes, the production platform is the Huawei FusionSphere distribution under centralised non-EU vendor governance (source-available, not independently/EU-governed) -> opt2 (seal 2). SEAL-2 ceiling alongside SOV-5.4. (src: https://www.huawei.com/en/news/2016/10/deutsche-telekom-cloud-openstack-interoperability-tests)
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowProvides public documentation and OpenStack-based transparency, with deeper insight available during audits; some public architectural insight.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowHPC/GPU capacity is EU-hosted but runs on a foreign hardware/software stack (foreign accelerators and Huawei-derived platform).

SOV-7 · Security & Compliance Sovereignty 78.5% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumcerts: holds BSI C5 Type 2 (since 2018) + ENS High + SOC 1/2/3 + TISAX. Per the answer-key cert->EAL map, BSI C5 (and ENS-High) is a high-assurance EU/national cloud certification mapping to EAL3 (opt4 'EAL3', seal 3); no SecNumCloud/EUCS-High to reach opt5. (src: https://www.open-telekom-cloud.com/en/blog/benefits/open-telekom-cloud-certified-according-to-bsi-c5-2020-and-and-soc-1-soc-2-soc-3)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highHolds BSI C5 Type 2, ISO 27001/27017/27018/27701, SOC 1/2/3, TISAX and the EU Cloud Code of Conduct, demonstrating independently audited GDPR/NIS2-aligned compliance.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecurity operations and incident handling are run by EU-based T-Systems teams within German/EU data centres; full lifecycle by EU teams, ENISA-specific sharing not explicitly evidenced.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumCustomers get direct access to monitoring/audit logging (Cloud Trace) with logs stored in EU data centres.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumIncident disclosure follows GDPR/NIS2 obligations with monitored flows and SLAs as a German telecom operator; real-time CSIRT sharing not specifically documented.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowMaintenance and patching are performed by T-Systems with notice/testing windows, giving moderate autonomy; some dependence on the Huawei platform vendor for deep fixes remains.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4lowaudit_rights: the sovereign public-sector offer (ENS-High, C5, German federal procurement) binds full audit by the contracting authority and independent EU bodies -> opt5 (seal 4), consistent with peer sovereign offers. Tender-grade commitment, low confidence.

SOV-8 · Environmental Sustainability 68.9% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)4. PUE < 1.3188/250SEAL-4mediumConsistency with operator T-Systems (same Deutsche Telekom Biere/Amsterdam DCs): published PUE ~1.3 (Biere) with the Biere site holding the EU Code of Conduct energy-efficiency award -> opt4 'PUE < 1.3'. (src: https://www.open-telekom-cloud.com/en/benefits/sustainability)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowDeutsche Telekom runs documented hardware reuse and recycling/circular programs as part of its sustainability strategy.
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3mediumConsistency with operator T-Systems: Deutsche Telekom publishes detailed sustainability/environmental reporting under EU methodology covering data-centre energy and emissions -> opt4 (detailed EU methodology).
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4highOpen Telekom Cloud data centres are powered by 100% renewable energy, sourced within the EU. (src: https://www.open-telekom-cloud.com/en/benefits/sustainability)