Updated juli 5, 2026
Summary: The EU Data Union Strategy commits the European Commission to concrete measures protecting sensitive non-personal data from foreign jurisdiction by Q3 2026, fundamentally reshaping how procurement teams, CISOs and sovereign infrastructure operators must evaluate cloud supply chains.

The EU Data Union Strategy, published by the European Commission in November 2025, is the most structurally significant data policy initiative since the General Data Protection Regulation. Unlike GDPR, which governs personal data, the Data Union Strategy explicitly targets sensitive non-personal data: industrial datasets, governmental records, critical infrastructure telemetry and publicly funded research outputs that sit outside GDPR’s scope but carry profound strategic and economic value.

For compliance officers, CISOs and data protection officers in the public sector, finance, healthcare and legal industries, this strategy is not background reading. It introduces enforceable commitments, procurement guidelines and contractual requirements that will reshape vendor selection and cloud architecture decisions well before the 2026 implementation deadlines arrive.

What the Commission committed to by Q3 2026

The Data Union Strategy sets a concrete legislative calendar: the Commission will adopt measures specifically protecting sensitive non-personal data from unjustified foreign access by Q3 2026. The categories explicitly in scope include industrial operational data, governmental administrative datasets, data processed under sector-specific regimes such as NIS-2 Directive 2022/2555 and the Digital Operational Resilience Act (DORA), and clinical and health data governed by the European Health Data Space (EHDS).

The mechanism is a multi-layer “sovereignty toolbox” addressing three distinct failure modes: unjustified data localisation requirements imposed by third countries on EU operators, discriminatory exclusion of EU entities from data ecosystems, and passive data leakage through cloud providers subject to extraterritorial law. The toolbox does not prohibit cross-border data flows. It creates a structured basis for challenging arrangements where EU organisations have no effective legal remedy when a non-EU government compels disclosure.

Key commitment: The Commission’s Q3 2026 measures will for the first time give sensitive non-personal data parity of protection with personal data under GDPR, closing a legal gap that currently leaves industrial and governmental datasets without any horizontal EU-level sovereignty safeguard.

Interaction with GDPR and the Swiss FADP

The Data Union Strategy does not modify GDPR. It operates in parallel, covering the data categories that GDPR explicitly excludes. For sovereign infrastructure operators, the practical implication is that a dual compliance framework now applies: GDPR for personal data, and the emerging Data Union Strategy instruments for non-personal data held alongside it.

Switzerland’s revised Federal Act on Data Protection (revFADP), in force since September 2023, already provides adequacy-equivalent protections recognised by the EU. More importantly for the sovereignty calculus, Swiss-domiciled providers with no US parent entity are outside the jurisdiction of the US CLOUD Act, FISA 702 and the Patriot Act. A US-headquartered hyperscaler operating a Frankfurt data centre remains subject to those statutes regardless of where the physical infrastructure sits. The Data Union Strategy’s toolbox will codify this distinction and provide procurement teams with a formal basis for weighting jurisdictional exposure in tender evaluations.

“Data is the lifeblood of the digital economy. We need a genuine Data Union where data flows freely within Europe, but where Europe also has the tools to prevent strategic data from leaving without proper safeguards.” (European Commission, Data Union Strategy Communication, November 2025)

Approximately 75% of European enterprise cloud spending flows to US-headquartered hyperscalers, according to the European Commission’s Digital Decade Report (2023). This concentration creates systemic jurisdictional exposure that no contractual clause can fully neutralise when a provider is subject to a secret court order under FISA 702.

Q2 2026 fair-treatment guidelines for procurement teams

The Commission will issue guidelines by Q2 2026 for assessing the fair treatment of EU data processed outside the Union. These guidelines are designed to give procurement teams a structured methodology rather than a checklist. For decision-makers evaluating non-EU cloud providers that process industrial or governmental datasets, three assessment dimensions are already signalled in the strategy text.

Assessment dimension What to verify in practice Relevant instrument
Jurisdictional exposure Identify all entities in the provider’s corporate group that are incorporated or operate in a state with extraterritorial data access powers CLOUD Act, FISA 702, EU e-Evidence Regulation
Reciprocal access rights Verify that the EU customer retains meaningful audit rights and legal remedies equivalent to those available in EU jurisdictions Data Union Strategy fairness criteria, Data Act Article 25
Technical sovereignty Confirm end-to-end encryption with customer-held keys and portability mechanisms that function without provider cooperation EU Data Act Article 25, SWIPO code of conduct

Procurement officers should not wait for the formal Q2 2026 guidelines. The three dimensions above are already implicit in the Data Governance Act (Regulation (EU) 2022/868) and the EU Data Act applicable from September 2025. Building these criteria into standard tender documents now positions organisations to meet the 2026 requirements without a disruptive retrospective review.

The European Health Data Space and sovereign medical hosting

The European Health Data Space (EHDS), adopted in 2024, is explicitly incorporated into the Data Union Strategy as a sectoral pillar. The EHDS creates a secondary use framework for clinical and health data, enabling research and policy analysis while imposing strict data access conditions through national health data access bodies.

For sovereign hosting operators, the EHDS imposes a practical constraint: health data processed under secondary use rules must remain within an access environment that meets EHDS technical security requirements. Processing that data on infrastructure subject to foreign jurisdiction contradicts the EHDS access control model at a structural level. The IBM Cost of a Data Breach Report (2024) puts the average total cost of a breach at USD 4.88 million globally, with healthcare consistently reporting the highest sector-specific costs. For clinical datasets, the reputational and regulatory consequences of a jurisdictional disclosure are often more costly than a technical breach.

For healthcare IT decision-makers: Hosting EHDS-governed secondary use datasets on infrastructure where the provider is subject to FISA 702 creates an irreconcilable conflict between EHDS access control obligations and US law. This is not a theoretical risk; it is a structural incompatibility that no data processing agreement resolves.

Contractual safeguards aligned with the Data Act and Data Union Strategy

The EU Data Act, applicable from September 2025, establishes model contractual terms for business-to-business data sharing and, in Article 25, prohibits contract clauses that prevent cloud switching or create lock-in. The Data Union Strategy builds on this foundation by extending fairness requirements to data-sharing agreements involving sensitive non-personal data.

Sovereign infrastructure operators should include four categories of contractual provision to achieve alignment:

Jurisdictional warranty: The provider warrants that neither it nor any entity in its corporate group is subject to extraterritorial data access law that could compel disclosure of the customer’s data without the customer’s knowledge or consent.

Notification obligation: The provider commits to notify the customer immediately upon receipt of any governmental access request and to exhaust all available legal challenges before complying, mirroring the standard adopted in Microsoft’s contractual commitments to EU public sector customers but without the CLOUD Act carve-out.

Technical exit rights: Consistent with EU Data Act Article 25, contracts must include a documented, tested data portability process that functions independently of provider cooperation, with a maximum switching period and capped egress fees.

Audit and sub-processor transparency: Full disclosure of all sub-processors, their jurisdictions and the legal basis under which each processes the data, updated within 30 days of any change. This aligns with GDPR Article 28 for personal data and extends the same standard to non-personal data under the Data Union Strategy framework.

Mapping Data Union Strategy controls against NIS-2 supply-chain obligations

NIS-2 Directive 2022/2555 Article 21 requires operators of essential services to implement supply-chain security measures, including an assessment of the security practices of direct suppliers and service providers. ENISA’s implementation guidance is explicit: “NIS-2 is not a checkbox exercise. For operators of essential services, supply-chain risk means knowing exactly where your data lives and under which jurisdiction your provider can be compelled to disclose it.”

The risk for CISOs is not non-compliance with either framework in isolation. It is maintaining two parallel control registers, one for NIS-2 supply-chain risk and one for Data Union Strategy sovereignty requirements, that assess the same vendor relationships from different angles and generate redundant audit evidence. The Data Union Strategy’s Q2 2026 fair-treatment guidelines are explicitly designed to be machine-readable into standard risk frameworks. CISOs should treat them as an input to the NIS-2 supply-chain risk register, not as a separate compliance stream.

The practical unification point is the vendor due-diligence questionnaire. A single questionnaire that covers jurisdictional exposure (Data Union Strategy), security certification and incident notification (NIS-2 Article 21), cloud switching rights (EU Data Act Article 25) and sub-processor transparency (GDPR Article 28 and Data Union Strategy) eliminates duplication and produces a single audit trail usable across all four frameworks. The European Commission’s Impact Assessment accompanying the Data Act (SWD(2022) 34) projects that the volume of machine-generated industrial data in scope of these frameworks will grow substantially toward 2030, making this consolidated approach operationally necessary rather than merely efficient.

FAQ

What categories of sensitive non-personal data are in scope of the Data Union Strategy’s Q3 2026 protection measures?

The strategy covers industrial datasets, governmental datasets, publicly funded research data, critical infrastructure operational data and data processed in sectors governed by DORA, NIS-2 and the EHDS. Personal data continues to fall under GDPR, but the new measures explicitly address the protection gap for high-value non-personal data that existing privacy law does not cover.

Does the EU Data Union Strategy replace GDPR obligations for data controllers in the public sector?

No. The Data Union Strategy adds a sovereignty layer on top of GDPR, not a substitute for it. Controllers must still comply with GDPR lawful basis, data minimisation and transfer rules. The strategy’s toolbox addresses non-personal data and structural market power issues that GDPR was not designed to resolve.

How does EU Data Act Article 25 affect contracts with US-based cloud providers already in place?

Article 25 of the EU Data Act, applicable from September 2025, prohibits cloud contracts that prevent switching to an alternative provider and requires providers to offer functional data portability. Existing contracts must be brought into compliance at renewal. Procurement officers should require providers to demonstrate SWIPO code of conduct adherence or equivalent technical exit mechanisms.

Why does Swiss hosting under the revised FADP reduce legal exposure compared with EU-based hosting under a US-controlled provider?

Switzerland’s revised FADP provides adequacy-equivalent protection recognised by the EU, but critically, Swiss-domiciled entities are not subject to the US CLOUD Act, FISA 702 or Patriot Act. A US-headquartered provider operating a data centre in Frankfurt remains subject to US extraterritorial orders. A Swiss provider with no US parent or US nexus removes that vector entirely.

When should a CISO treat the Data Union Strategy’s sovereignty requirements as a NIS-2 supply-chain control rather than a separate compliance stream?

Immediately. NIS-2 Article 21 requires operators of essential services to assess supply-chain security risks, including the jurisdiction of sub-processors. The Data Union Strategy’s fair-treatment guidelines, expected in Q2 2026, will provide a structured assessment methodology that directly maps onto the NIS-2 supply-chain risk register. CISOs should align both frameworks into a single vendor due-diligence process to avoid parallel audit trails.

Frequently asked questions

What categories of sensitive non-personal data are in scope of the Data Union Strategy's Q3 2026 protection measures?
The strategy covers industrial datasets, governmental datasets, publicly funded research data, critical infrastructure operational data and data processed in sectors governed by DORA, NIS-2 and the EHDS. Personal data continues to fall under GDPR, but the new measures explicitly address the protection gap for high-value non-personal data that existing privacy law does not cover.
Does the EU Data Union Strategy replace GDPR obligations for data controllers in the public sector?
No. The Data Union Strategy adds a sovereignty layer on top of GDPR, not a substitute for it. Controllers must still comply with GDPR lawful basis, data minimisation and transfer rules. The strategy's toolbox addresses non-personal data and structural market power issues that GDPR was not designed to resolve.
How does EU Data Act Article 25 affect contracts with US-based cloud providers already in place?
Article 25 of the EU Data Act, applicable from September 2025, prohibits cloud contracts that prevent switching to an alternative provider and requires providers to offer functional data portability. Existing contracts must be brought into compliance at renewal. Procurement officers should require providers to demonstrate SWIPO code of conduct adherence or equivalent technical exit mechanisms.
Why does Swiss hosting under the revised FADP reduce legal exposure compared with EU-based hosting under a US-controlled provider?
Switzerland's revised FADP provides adequacy-equivalent protection recognised by the EU, but critically, Swiss-domiciled entities are not subject to the US CLOUD Act, FISA 702 or Patriot Act. A US-headquartered provider operating a data centre in Frankfurt remains subject to US extraterritorial orders. A Swiss provider with no US parent or US nexus removes that vector entirely.
When should a CISO treat the Data Union Strategy's sovereignty requirements as a NIS-2 supply-chain control rather than a separate compliance stream?
Immediately. NIS-2 Article 21 requires operators of essential services to assess supply-chain security risks, including the jurisdiction of sub-processors. The Data Union Strategy's fair-treatment guidelines, expected in Q2 2026, will provide a structured assessment methodology that directly maps onto the NIS-2 supply-chain risk register. CISOs should align both frameworks into a single vendor due-diligence process to avoid parallel audit trails.