Europe's Fintechs Talk About Sovereignty. Most of Them Still Run on American Clouds.

Europe's Fintechs Talk About Sovereignty. Most of Them Still Run on American Clouds.

DORA, the Data Act, a proposed Cloud and AI Development Act, Wero and the digital euro all point in the same direction: Europe wants control over its financial infrastructure. The hard part is that most of its banks and fintechs depend on three US hyperscalers.

"Data sovereignty" has become one of the most used phrases in European fintech this year. It shows up in bank strategy decks, in regulators' speeches and in almost every LinkedIn post about Wero or the digital euro. Behind the buzzword sits an uncomfortable fact: a large share of Europe's financial data is stored and processed on infrastructure owned by US companies, and several new EU rules are now asking whether that is acceptable.

The dependency, in black and white

Since January 2025, the Digital Operational Resilience Act (DORA) has required banks, insurers and payment firms to manage the risk of their ICT providers. In November 2025, the European Supervisory Authorities published their first list of 19 critical ICT third-party providers, including AWS, Google and Microsoft. Those providers now face direct EU oversight, and financial firms using them need documented and tested exit strategies.

DORA is about resilience, not nationality. But the list made the concentration visible. When a handful of providers carry the core systems of thousands of financial firms, an outage, a sanctions dispute or a foreign court order is no longer a theoretical risk.

GDPR meets the CLOUD Act

The legal tension is well known. The US CLOUD Act of 2018 allows US authorities to require US-based providers to hand over data they control, even if it is stored in a European data centre. GDPR restricts exactly such transfers. EU data centres run by US companies reduce latency and satisfy many data residency rules, but they do not fully resolve the question of who can ultimately be compelled to provide access.

According to Morningstar DBRS commentary from March 2026, European banks are responding with hybrid and multi-cloud setups and are taking a closer look at European providers such as OVHcloud, IONOS and Scaleway. Few are leaving the hyperscalers entirely. Most are trying to make sure they could.

Brussels turns sovereignty into rules

  • EU Data Act: Applicable since September 2025, it forces cloud providers to make switching easier. Switching charges must disappear completely from 12 January 2027, which makes a credible exit plan cheaper to execute.
  • Cloud and AI Development Act (CADA): Proposed on 3 June 2026, it defines four sovereignty assurance levels, from EU-based data processing up to full EU control of the software supply chain. The Commission could require companies in NIS2 sectors, including banking, to assess their cloud dependencies against these levels. Adoption is targeted for late 2027.
  • FiDA: The revised Financial Data Access proposal from April 2026 decides who may access customer financial data beyond payment accounts, and on which terms. It is data sovereignty at the level of the individual customer.

Payments: the sovereignty debate customers can see

For most people, sovereignty becomes tangible at the checkout. Wero, the account-to-account wallet of the European Payments Initiative, reports around 43 million registered users. It went live for e-commerce in Germany in November 2025 and in France and Belgium in January 2026, with in-store payments planned for late 2026. Through its alliance with EuroPA, which links schemes such as Bizum and MB Way, the potential reach grows to around 130 million people.

The digital euro is moving too. After the European Parliament cleared its position in July 2026, negotiations with member states began on 13 July. A launch is currently targeted for 2029.

The sovereign infrastructure Europe already has

The debate often overlooks that Europe already runs financial infrastructure that nobody outside the continent controls. SEPA is one example. EBICS, the corporate banking protocol used in Germany, France, Switzerland and Austria, is another: companies hold their own keys and connect directly to their bank, with no platform in between. We looked at how it compares with open banking APIs in EBICS vs. PSD2.

What fintechs should do now

  • Map your dependencies. Know which of your critical services run on which provider, in which jurisdiction, and under which parent company.
  • Make exit plans real. DORA already demands them, and the Data Act is making them cheaper. Test one.
  • Treat sovereignty as a sales argument. Banks will increasingly ask their vendors the same questions supervisors ask them. A clear answer can win deals.
  • Stay pragmatic. Full independence from US technology is not realistic for most firms in the short term. Controllability and portability are.
Europe's sovereignty push is no longer just rhetoric. It is turning into supervision, procurement criteria and payment schemes with millions of users. For fintechs, the question is shifting from "where is our data?" to "could we move it tomorrow if we had to?"

This article was researched and written with AI assistance for FinTech Weekly. All facts are linked to their sources in the text.

Related Articles