Updated juli 22, 2026
Summary: CADA Article 29 (COM(2026) 502 final) mandates a structured sovereignty risk assessment before procuring or renewing cloud contracts, binding the result to one of four SEAL assurance levels. DPOs must consolidate this with a GDPR Article 46 Transfer Impact Assessment to produce a single, audit-ready procurement dossier.

The CADA Article 29 sovereignty risk assessment methodology is the structured, legally binding process by which public bodies and regulated entities must evaluate, score and document the jurisdiction risk of a cloud service before signing or renewing a contract. Proposed under COM(2026) 502 final, the Cloud and AI Data Act (CADA), Article 29 moves sovereignty due diligence from a best-practice recommendation into a mandatory pre-procurement obligation with enforceable evidence standards.

What CADA Article 29 Actually Requires

Article 29 demands a written sovereignty risk assessment that addresses three distinct risk dimensions before any contract signature or material renewal: jurisdiction exposure of the provider, operational control over data and keys, and workload sensitivity classification. The evidence standard is not a self-declaration. Procurement teams must supply externally verifiable documentation, such as corporate registry extracts confirming the provider’s ultimate beneficial ownership, an audited cryptographic key management statement, and a mapping of all sub-processors to their country of incorporation.

The assessment must also identify every legal instrument in the provider’s home jurisdiction that could compel disclosure of data without the data subject’s member state being notified in advance. This explicitly includes the US CLOUD Act (18 U.S.C. § 2713), FISA Section 702 (50 U.S.C. § 1881a), and equivalent instruments in other third-country legal systems. The documentation must explain why each identified instrument either does or does not create a realistic access pathway to the data in question.

Note: A sovereignty risk assessment completed solely on the basis of a provider’s self-published compliance whitepaper does not meet the CADA Article 29 evidence standard. Supervisors will look for independent, dated, and workload-specific documentation.

The Interaction Between Article 29 and CADA SEAL Assurance Levels 1 to 4

The risk assessment does not exist in isolation. Its direct output is a binding minimum SEAL assurance level for the workload under review. CADA defines four SEAL assurance levels (SEAL 1 through SEAL 4), each representing a progressively stronger set of technical, legal and operational guarantees that the cloud provider must hold before being eligible to process data at that sensitivity tier.

SEAL Level Typical workload category Minimum provider requirements Key sovereignty gate
SEAL 1 Public-facing, non-sensitive administrative data Basic ENISA EUCS Substantial or equivalent Provider transparency obligation only
SEAL 2 Internal operational data, limited personal data ENISA EUCS Substantial, EU/EEA processing Sub-processor disclosure; no third-country transfer without TIA
SEAL 3 Sensitive personal data, regulated sector records ENISA EUCS High; EU-controlled key management No compellable access by non-EU jurisdiction
SEAL 4 Classified, critical-infrastructure or state-secret data EUCS High plus national security clearance equivalent Air-gapped or on-premises deployment; full operational autonomy

The Article 29 assessment process determines which SEAL level applies to the workload. Once that determination is documented and signed off by the responsible officer, procuring a provider that does not hold the corresponding SEAL certification is a non-conformity, not a risk-accepted deviation.

See how Qsentinel solves this in practice.Start a 10-user pilot →

Scoring Third-Country Jurisdiction Factors

The most contested part of any Article 29 assessment is the jurisdiction scoring grid, where assessors must assign a risk tier to each legal-access vector. The EU Cloud Sovereignty Framework’s 48-criteria scoring grid provides the operationalised checklist that procurement teams without in-house legal counsel can follow. The 48 criteria are grouped into four domains: legal jurisdiction, ownership and control, technical access pathways, and contractual remedy adequacy.

For US-headquartered hyperscalers, the CLOUD Act and FISA 702 vectors routinely score high risk, because a US parent company with operational control over EU infrastructure can be served with a US court order that has no reciprocal notification obligation to the EU member state. Foreign ownership control is scored separately: a provider in which a non-EU state-owned entity holds more than a defined threshold interest (the draft text references 25%) is automatically escalated to the next-higher risk tier regardless of the datacenter location.

A Swiss-hosted alternative, where the provider is incorporated under Swiss law, has no US parent, employs no US persons in roles with privileged data access, and stores encryption keys on hardware located exclusively in Switzerland, scores the lowest available risk tier on all three CLOUD Act, FISA 702 and foreign-ownership criteria. Switzerland’s revised Federal Act on Data Protection (revFADP), which entered into force on 1 September 2023, provides a legal framework that the European Commission has recognised as offering adequate protection, further supporting a low-risk scoring outcome. That combination, when documented with corporate registry evidence and a third-party key-management audit, substantially reduces the aggregate jurisdiction risk score and may lower the required SEAL level by one tier for non-EU-classified workloads.

Important: Datacenter location alone is not sufficient to score jurisdiction risk as low. The provider’s legal entity, its ownership chain, and the employment nationality of staff with privileged access must all be evaluated independently. A US company running a datacenter in Amsterdam remains subject to CLOUD Act compulsion.

Consolidating the Article 29 Assessment with a GDPR Transfer Impact Assessment

Many DPOs treat the GDPR Article 46 Transfer Impact Assessment (TIA) and the CADA Article 29 assessment as parallel but separate exercises. That approach creates duplicated effort and risks contradictory conclusions in the same procurement dossier. A defensible consolidated dossier maps both assessments onto a single evidence base, with clearly labelled sections indicating which finding satisfies which legal obligation.

The GDPR Article 46 TIA, as clarified by the European Data Protection Board in its Guidelines 05/2021, focuses on whether standard contractual clauses or binding corporate rules provide enforceable rights and effective remedies for data subjects when personal data is transferred to a third country. The CADA Article 29 assessment is broader: it covers non-personal sensitive data, operational continuity risk, and the assurance level threshold. A DPO building a single consolidated dossier should structure it in three layers: (1) the TIA personal-data analysis satisfying GDPR Article 46; (2) the jurisdiction scoring grid satisfying CADA Article 29 for all data categories; and (3) the SEAL determination and provider certification check. All three layers must be dated, version-controlled and signed by a named responsible officer.

According to IBM’s Cost of a Data Breach Report 2024, the average total cost of a data breach reached USD 4.88 million, the highest figure ever recorded in that report series. Regulators increasingly treat inadequate procurement due diligence as a contributing factor to breach severity, directly linking documentation quality to liability exposure.

ENISA EUCS and the 48-Criteria Scoring Grid in Practice

The ENISA European Cybersecurity Certification Scheme for Cloud Services (EUCS) is the technical instrument that operationalises sovereignty assurance for procurement teams. EUCS certification at the High level requires a provider to demonstrate that it can resist compelled access by any non-EU authority, that cryptographic controls are not accessible to staff outside the EU/EEA, and that operational continuity is guaranteed independently of any non-EU parent entity.

The EU Cloud Sovereignty Framework’s 48-criteria scoring grid translates these EUCS requirements into a procurement-usable checklist. Each criterion is scored on a three-tier scale (compliant, partially compliant, non-compliant), and the aggregate score determines whether the provider reaches the minimum threshold for the target SEAL level. Procurement teams can use the grid as a request-for-information template, asking bidders to provide documented evidence for each criterion rather than relying on marketing assertions.

ENISA has stated clearly that “operators of essential services and digital service providers must be able to demonstrate to supervisory authorities, at any time and without prior notice, that their risk management measures are proportionate to the actual threats they face.” This standard applies directly to the sovereignty risk assessment: it must be available on demand, not reconstructed after the fact.

Over 75% of European enterprises rely on hyperscalers headquartered in the United States, according to ENISA’s Cloud Cybersecurity Market Analysis 2023. That concentration means the majority of current cloud contracts in regulated sectors would require a new or updated Article 29 assessment under CADA before renewal.

Enforcement, Audit Mechanisms and NIS-2 Overlap

CADA designates national competent authorities as the primary enforcement body for Article 29 obligations. A failure to conduct or document an adequate sovereignty risk assessment is a standalone compliance violation, independent of whether a breach or data access incident has actually occurred. Supervisors may request the assessment dossier during routine audits, during contract renewal reviews, or following any incident that suggests a jurisdiction risk materialised.

For entities that also qualify as essential or important entities under NIS-2 Directive (EU) 2022/2555, the NIS-2 Article 32 supervisory powers apply in parallel. Article 32 authorises the competent authority to conduct on-site inspections without prior notice, issue binding remediation orders with defined timelines, and impose fines of up to EUR 10 million or 2% of global annual turnover for essential entities, whichever is higher, under NIS-2 Article 34. A missing or inadequate Article 29 assessment is a directly recordable non-conformity under NIS-2’s risk management obligation in Article 21, because sovereign cloud procurement is part of the supply chain risk management duty.

The European Data Protection Board has made its position on documentation standards unambiguous: “Cloud sovereignty is not a marketing term. It is a legal requirement that demands documented, verifiable evidence that data cannot be accessed by a foreign government without the consent of the data subject’s member state.” Supervisory authorities in France (ANSSI), Germany (BSI) and the Netherlands (NCSC-NL) have each issued national guidance reinforcing this position, and cross-border supervisory cooperation under NIS-2 Article 15 means that a gap identified in one member state can trigger coordinated review in another.

Organisations that process data across multiple member states should appoint a single coordinating DPO or CISO to own the consolidated CADA/GDPR dossier, ensuring that jurisdiction scoring, SEAL determinations and TIA conclusions are consistent across all entities in the corporate or institutional group. Inconsistency between dossiers filed with different national authorities is itself a supervisory red flag.

Frequently Asked Questions

Is a CADA Article 29 sovereignty risk assessment required for every cloud renewal, or only for new contracts?

CADA Article 29 (COM(2026) 502 final) applies to both new procurements and material contract renewals. A renewal that extends the processing of classified or sensitive workloads without a fresh assessment will be treated as a compliance gap by supervisory authorities.

Can a GDPR Transfer Impact Assessment serve as a substitute for the CADA Article 29 risk assessment?

No. A GDPR Article 46 TIA focuses on whether SCCs or equivalent safeguards protect personal data in transit to a third country. The CADA Article 29 assessment covers a broader sovereignty perimeter, including non-personal sensitive data, operational continuity and assurance level thresholds. Both documents are required, but they can be consolidated into a single procurement dossier with clearly labelled sections.

What SEAL level applies to healthcare patient records processed in a national hospital information system?

Healthcare patient data is classified as high-sensitivity under CADA’s workload taxonomy, which generally maps to a minimum of SEAL 3. SEAL 3 requires that the provider holds an ENISA EUCS High certification or equivalent, that operational control remains inside the EU/EEA, and that cryptographic key management cannot be compelled by a non-EU jurisdiction.

How does Swiss hosting reduce the CLOUD Act and FISA 702 exposure scores in the Article 29 jurisdiction grid?

A provider incorporated under Swiss law with no US parent, no US-person employees in key roles, and infrastructure physically located in Switzerland falls outside the personal jurisdiction of US courts for CLOUD Act and FISA 702 purposes. In the Article 29 scoring grid, each of those three vectors scores the lowest risk tier, materially lowering the aggregate jurisdiction risk score compared with a US-headquartered hyperscaler.

Which supervisory authority can enforce a failure to conduct an adequate Article 29 assessment, and what are the consequences?

Under CADA, the designated national competent authority has primary enforcement competence. For entities that also qualify as essential or important entities under NIS-2, the NIS-2 Article 32 supervisory powers apply in parallel: on-site inspections, binding remediation orders, and fines of up to EUR 10 million or 2% of global turnover. A failure to document the assessment is itself a recordable non-conformity that can trigger a formal investigation.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Is a CADA Article 29 sovereignty risk assessment required for every cloud renewal, or only for new contracts?
CADA Article 29 (COM(2026) 502 final) applies to both new procurements and material contract renewals. A renewal that extends the processing of classified or sensitive workloads without a fresh assessment will be treated as a compliance gap by supervisory authorities.
Can a GDPR Transfer Impact Assessment serve as a substitute for the CADA Article 29 risk assessment?
No. A GDPR Article 46 TIA focuses on whether SCCs or equivalent safeguards protect personal data in transit to a third country. The CADA Article 29 assessment covers a broader sovereignty perimeter, including non-personal sensitive data, operational continuity and assurance level thresholds. Both documents are required, but they can be consolidated into a single procurement dossier with clearly labelled sections.
What SEAL level applies to healthcare patient records processed in a national hospital information system?
Healthcare patient data is classified as high-sensitivity under CADA's workload taxonomy, which generally maps to a minimum of SEAL 3. SEAL 3 requires that the provider holds an ENISA EUCS High certification or equivalent, that operational control remains inside the EU/EEA, and that cryptographic key management cannot be compelled by a non-EU jurisdiction.
How does Swiss hosting reduce the CLOUD Act and FISA 702 exposure scores in the Article 29 jurisdiction grid?
A provider incorporated under Swiss law with no US parent, no US-person employees in key roles, and infrastructure physically located in Switzerland falls outside the personal jurisdiction of US courts for CLOUD Act and FISA 702 purposes. In the Article 29 scoring grid, each of those three vectors scores the lowest risk tier, materially lowering the aggregate jurisdiction risk score compared with a US-headquartered hyperscaler.
Which supervisory authority can enforce a failure to conduct an adequate Article 29 assessment, and what are the consequences?
Under CADA, the designated national competent authority has primary enforcement competence. For entities that also qualify as essential or important entities under NIS-2, the NIS-2 Article 32 supervisory powers apply in parallel: on-site inspections, binding remediation orders, and fines of up to EUR 10 million or 2% of global turnover. A failure to document the assessment is itself a recordable non-conformity that can trigger a formal investigation.