🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Tencent Cloud

China · IaaS/PaaS · https://www.tencentcloud.com

Sovereignty score28.1%
Global (unweighted)30.1%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty15.6SEAL-0
SOV-2 Legal & Jurisdictional Sovereignty12.6SEAL-1
SOV-3 Data & AI Sovereignty45.0SEAL-0
SOV-4 Operational Sovereignty25.1SEAL-1
SOV-5 Supply Chain Sovereignty18.0SEAL-0
SOV-6 Technology Sovereignty35.0SEAL-2
SOV-7 Security & Compliance Sovereignty39.6SEAL-1
SOV-8 Environmental Sustainability50.0SEAL-2

SOV-1 · Strategic Sovereignty 15.6% · SEAL-0 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highforeign_parent (CN): Tencent Cloud is the cloud arm of Tencent Holdings Ltd, HQ Shenzhen; entity control entirely outside the EU -> SOV-1.1 opt1. (src: https://en.wikipedia.org/wiki/Tencent_Cloud)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumKept per instruction (all-SEAL-4 factor): already controlled from China, transfer to a different non-EU sovereign very unlikely -> opt5.
SOV-1.3Control over roadmap1. No influence possible0/125SEAL-2mediumRoadmap set entirely by Tencent in China; no governance body giving EU actors meaningful influence -> SOV-1.3 opt1 (no immunity/eu_entity).
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highKept (all-SEAL-4 factor): funding overwhelmingly non-EU (Chinese parent, HK-listed) -> opt1.
SOV-1.5EU economic contribution1. Minimal0/125SEAL-4mediumKept (all-SEAL-4 factor): economic activity, R&D, employment, tax base overwhelmingly in China -> opt1.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4highKept (all-SEAL-4 factor): no participation in Gaia-X / IPCEI-CIS or other EU strategic programs -> opt1.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4highKept (all-SEAL-4 factor): no evidence of alignment with EU industrial strategy; aligns with Chinese national policy -> opt1.
SOV-1.8Resilience to cut-off2. Service would stop, with delay for customer reaction31/125SEAL-0lowNo own_stack: on geopolitical cut-off (sanctions/export controls) the service would stop with delay; no autonomy from Chinese parent -> SOV-1.8 opt2 (seal 0 gate).

SOV-2 · Legal & Jurisdictional Sovereignty 12.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highEU contract runs through the Frankfurt region under EU law, but the controlling group is governed by PRC law -> mixed EU/non-EU -> normalised to cluster answer SOV-2.1 opt2 (was opt1), consistent with Alibaba/Huawei who likewise operate EU regions. (src: https://www.datacenterdynamics.com/en/news/tencent-cloud-launches-availability-zone-in-franfurt-germany/)
SOV-2.2Extraterritorial laws exposure1. Fully exposed to non-EU laws0/167SEAL-1highNo immunity: fully exposed to extraterritorial PRC laws (National Intelligence, Data Security, Cybersecurity) -> SOV-2.2 opt1. (src: https://www.tencentcloud.com/services/compliance)
SOV-2.3Data access pathways for non-EU authorities1. Can compel access without customer notification0/167SEAL-1highforeign_parent (PRC National Intelligence Law): Chinese firms can be compelled to provide data covertly with no right to refuse -> SOV-2.3 opt1 (SEAL-1 cap). (src: https://www.tencentcloud.com/services/compliance)
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1mediumNo eu_exclusive shield: Chinese export-control/data-export regimes plus Western sanctions affect EU citizens/orgs; revenues not majority-EU -> SOV-2.4 opt2.
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highKept (all-SEAL-4 factor): core IP (platform, Hunyuan models, infra designs) originates entirely outside the EU -> opt1.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highIP held by Tencent under non-EU (Chinese) law in a single country -> SOV-2.6 opt1.

SOV-3 · Data & AI Sovereignty 45.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2mediumKMS/customer-managed keys exist but provider retains override and can technically read; no provider-cannot-read guarantee against PRC compulsion -> SOV-3.1 opt3 (shared).
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2mediumCloudAudit/activity logs exist but vendor-controlled, not real-time independent auditability -> SOV-3.2 opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion per internal policy/certs (ISO 27018) with confirmation; no independently verified proof of irreversible erasure -> SOV-3.3 opt3.
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0mediumNo eu_exclusive offer: global control plane, support and parent in China; Frankfurt region is partly-EU with significant third-country reliance -> SOV-3.4 opt2 (seal 0 gate). (src: https://www.datacenterdynamics.com/en/news/tencent-cloud-launches-availability-zone-in-franfurt-germany/)
SOV-3.5AI services sovereignty3. Mixed: auditable/open-source AI, foreign chips100/200SEAL-2mediumHunyuan partly open/auditable but runs on foreign (Nvidia) accelerators and model origin is non-EU -> SOV-3.5 opt3 (mixed).

SOV-4 · Operational Sovereignty 25.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandard documented data-export methods/APIs exist; not deployed on EU sovereign infrastructure -> SOV-4.1 opt3.
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1highNo eu_ops: critical operations, platform engineering and control plane delivered by non-EU (Chinese) teams -> SOV-4.2 opt1.
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1mediumNo eu_ops: engineering/skills concentrated in China with thin EU commercial team; majority of relevant staff outside EU -> SOV-4.3 opt2.
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2mediumSupport global with escalation to China; majority of support engineering outside EU -> SOV-4.4 opt2.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation global/English, no enforced EU-only knowledge repositories; EU residency optional -> SOV-4.5 opt2.
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2lowNo own_stack: Frankfurt facilities leased from third parties and core deps non-EU; on supplier withdrawal service stops with delay -> SOV-4.6 opt2.

SOV-5 · Supply Chain Sovereignty 18.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowLimited public disclosure of physical component provenance for EU-served infra; partial disclosure -> SOV-5.1 opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1mediumHardware (self-developed servers plus Nvidia GPUs) foreign-origin with partial disclosure; not built/audited by EU teams -> SOV-5.2 opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowKept (all-SEAL-4 factor): embedded firmware provenance largely undisclosed; partial disclosure -> opt2.
SOV-5.4Origin of software1. Fully foreign origin, black box0/143SEAL-0highCore platform software (Tencent Cloud control plane, managed services) is fully foreign-origin (Chinese), China-maintained and a black box to EU customers; open-sourcing some peripheral Hunyuan models/tools does not disclose the core -> normalised to cluster answer SOV-5.4 opt1 (seal 0 gate; was opt2), consistent with Alibaba/Huawei/Baidu black-box cores.
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1mediumSoftware build/release controlled and executed in China (non-EU control and execution) -> SOV-5.5 opt1.
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1mediumCritical services depend on non-EU vendors/facilities (Chinese parent, Nvidia, leased non-EU-controlled colo), little EU-facing documentation -> SOV-5.6 opt2.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers auditable via cert regimes, but supply chain not comprehensively auditable by EU customers -> SOV-5.7 opt2.

SOV-6 · Technology Sovereignty 35.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumMix of proprietary APIs and some standards-based interfaces (e.g. S3-compatible storage); partial openness -> SOV-6.1 opt3.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumPartial adoption of open standards across core services, not a comprehensive policy -> SOV-6.2 opt3.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumforeign_core: the IaaS/PaaS core platform is closed-source and vendor-controlled (some Hunyuan models open, but core governance centralised under Tencent in China) -> normalised to cluster answer SOV-6.3 opt2 (seal 2; was opt3), consistent with Alibaba/Huawei/Baidu foreign_core.
SOV-6.4Service architecture transparency2. Insight accessible during audits50/200SEAL-2lowArchitecture insight mainly under audit/NDA via cert evidence; limited public deep insight -> SOV-6.4 opt2.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowHPC/AI compute can be EU-hosted in the Frankfurt region but runs a foreign (Nvidia-based) stack with no EU processor IP -> EU-hosted, foreign stack -> normalised to cluster answer SOV-6.5 opt2 (seal 3; was opt1), consistent with Alibaba/Huawei who also EU-host foreign-stack accelerated compute.

SOV-7 · Security & Compliance Sovereignty 39.6% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2mediumNo BSI C5 / SecNumCloud / EUCS confirmed, but holds ISO 27001 + SOC 1/2/3 + CSA STAR; per gating_key ISO 27001 + SOC 2 maps to EAL2 -> SOV-7.1 opt3 (seal 2; was opt1). Lower than Alibaba/Huawei because no C5 confirmed (genuine cert difference). (src: https://www.tencentcloud.com/services/compliance)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)3. Moderate compliance72/143SEAL-4mediumKept (all-SEAL-4 factor): broad certs (ISO 27001/27017/27018/27701, SOC, CSA STAR, PCI DSS) and GDPR features, but no full audited NIS2/DORA -> opt3 (moderate).
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSecurity operations/IR hybrid with primary capability and escalation in China; not EU-only SOC lifecycle -> SOV-7.3 opt2.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get monitoring/logging portal (Cloud Monitor, CloudAudit) but not full direct control with guaranteed immutable EU log storage -> SOV-7.4 opt3.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowIncident disclosure broadly GDPR/contract-aligned for the EU region; moderate, not real-time CSIRT sharing -> SOV-7.5 opt3.
SOV-7.6Maintenance autonomy2. Limited autonomy (vendor schedules)36/143SEAL-1lowMaintenance follows vendor schedules; limited customer autonomy over managed-platform patching -> SOV-7.6 opt2.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: independent audit access limited to certification audits; customers/third parties cannot freely audit -> SOV-7.7 opt2.

SOV-8 · Environmental Sustainability 50.0% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowTencent's data centres reach PUE ~1.2-1.25 (Gen4) with a carbon-neutral-2030 roadmap; EU services run in efficient Frankfurt colo, no EU-verified figure -> PUE<1.5 + roadmap -> SOV-8.1 opt3 (seal 4; was opt2), consistent with Huawei's evidence-based treatment. (src: https://www.tencentcloud.com/global-infrastructure/sustainability)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowESG reporting describes hardware lifecycle/circular practices; documented program exists but not EU-certified -> SOV-8.2 opt3. (src: https://static.www.tencent.com/uploads/2025/04/08/00ef711d9596ce09344c0260b14cda7e.pdf)
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumPublishes annual ESG/sustainability report with environmental metrics; not EU-methodology specific or EU-audited -> SOV-8.3 opt3. (src: https://static.www.tencent.com/uploads/2025/04/08/00ef711d9596ce09344c0260b14cda7e.pdf)
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowKept (all-SEAL-4 factor): Frankfurt draws on German/EU grid mix while broader footprint mixes EU and non-EU supplies -> opt3. (src: https://www.tencent.com/en-us/esg/environment/policy.html)