Why Tech Experts Must Take the Lead on European Cloud Rules

Why Tech Experts Must Take the Lead on European Cloud Rules

2026-08-26 digital

Amsterdam, Wednesday 26 August 2026
A Leaseweb executive warns that non-technical policymakers dominate EU cloud rules, urging that practical implementation be handed over to IT experts to avoid critical operational bottlenecks.

A Call for Practical IT Leadership

Jan Willem des Tombe, the global strategic relations director at Dutch hosting and cloud provider Leaseweb, has raised alarms over the recent direction of Dutch and European cloud policies [1]. Over the past few months leading up to August 2026, the revision of cloud frameworks in the Netherlands and the European Union has been heavily dominated by non-technical actors, including policymakers, lawyers, consultants, and civil servants [1]. Des Tombe argues that the era of theoretical discussion is now over, and as the implementation phase of sovereign cloud policy begins, the responsibility must shift to IT professionals who possess practical technical expertise [1]. Leaving the execution to legal teams or advisory firms risks creating unworkable systems that fail to align with the actual architecture of the internet [1].

The Fragmentation and Pitfalls of Cloud Policy

A significant hurdle in implementing a cohesive European cloud framework is the sheer fragmentation across the EU, which spans numerous countries, distinct legal environments, and varying cultures [1]. To overcome this, Des Tombe emphasises that interoperability must be a core focus, allowing different systems to work together seamlessly [1]. He cautions that IT systems are highly complex, consisting of multiple components across various layers, which makes it almost inevitable that a non-European link will exist somewhere in the supply chain [1]. This technical reality means that achieving absolute digital sovereignty requires deep architectural planning—focusing on ownership, legal structures, governance, procurement, and contractual terms—rather than simply relying on retrospective legal rules [1].

Bridging Architectural Requirements and Corporate Realities

Historically, the shift in corporate IT began around 2010 with the “consumerisation of IT,” where business departments rapidly adopted public cloud services [1]. This transition often occurred without rigorous evaluation of vendor lock-in, governance, or underlying technical architectures, effectively sidelining traditional IT departments [1]. To address these structural dependencies, Leaseweb advocates for a hybrid cloud model [1]. This pragmatic approach combines private clouds, on-premises infrastructure, dedicated servers, and public clouds, allowing organisations to distribute workloads based on data sensitivity [1]. For instance, critical industrial process data can be secured within private clouds, while non-sensitive workloads are allocated to public clouds, balancing security with scalability [1].

Sovereignty in Action: The European Landscape

The push for digital sovereignty is reshaping the European cloud market, which features prominent public providers such as OVHcloud, Scaleway, Proximus, T-Systems, and Hetzner [1]. In parallel, private cloud initiatives are gaining traction, such as Schwarz Digits’ StackIT platform partnering with KPN, alongside the Open Cloud Alliance (OCA), which involves Dutch players like Centric, Info Support, Intermax, KPN, Nebul, Previder, and Uniserver [1]. To actively build this sovereign future, Leaseweb is participating in the EU’s Important Project of Common European Interest on Next Generation Cloud Infrastructure and Services (IPCEI-CIS) through the European Cloud Campus project [1]. This initiative aims to develop a multi-provider cloud-to-edge continuum, utilising scalable compute platforms, open APIs, and modern container architectures [1].

The Sovereignty Debate and the DigiD Precedent

The critical nature of digital sovereignty and the risks of foreign dependency are further highlighted by the upcoming Cybersec Netherlands 2026 event, scheduled for 9 and 10 September 2026 at Jaarbeurs Utrecht [6]. Whistleblower Pieter van Oordt is set to deliver a keynote detailing the controversial proposed acquisition of Dutch IT company Solvinity—the operator of the Picard platform powering DigiD, MijnOverheid, and Digipoort—by US-based Kyndryl [6]. DigiD alone processes 700 million authentications annually, while MijnOverheid handles 100 million letters and supports 10 million digital mailboxes [6]. This case underscores that digital sovereignty is fundamentally a governance issue [6]. It requires a risk-driven approach to manage vendor dependencies, incorporating change-of-control clauses, exit strategies, and strict contractual protections [6].

Substantial Capital Infusions for Digital Infrastructure

To support this massive migration towards secure, scalable, and sovereign digital solutions, European infrastructure providers are securing substantial funding. For example, Eurofiber, a major European provider of open digital infrastructure and data centres, completed a €2.2 billion sustainability-linked refinancing round in August 2026 [3]. This long-term financing replaces an existing €1.5 billion credit facility, representing an increase of 46.667 per cent [3]. The capital, backed by major financial advisors BNP Paribas and Rothschild & Co, is tied to environmental, social, and governance (ESG) targets, including carbon reduction, circularity, and gender diversity [3]. These funds will directly fuel the expansion of Eurofiber’s fibre-optic networks and secure cloud infrastructure services across Europe [3].

The Technical Foundation: Latency, Bandwidth, and QoS

The transition from local server-based corporate IT to cloud-based environments places immense pressure on physical internet connections [4]. As data traffic rises exponentially due to cloud applications, video conferencing, and remote storage, businesses must transition to high-performance business fibre-optic connections [4]. Unlike older copper connections, fibre-optic networks offer symmetrical upload and download speeds, low latency, and immunity to electromagnetic interference and weather conditions [4]. Low latency is particularly vital for real-time, cloud-based ERP systems and data analytics [4]. Furthermore, network administrators must deploy Quality of Service (QoS) techniques to prioritise critical traffic like VoIP and video calls over non-time-sensitive tasks like backups, preventing productivity losses as hundreds of concurrent users access the cloud [4].

Sources & Ecosystem Partners

  1. www.computable.nl
  2. www.computable.nl
  3. www.computable.nl
  4. www.computable.nl

Digital Sovereignty Cloud Regulation