Procurement
How to write the sovereignty section of a data platform RFP
Airbus scored protection from extraterritorial law as a weighted criterion rather than a yes/no box. That one decision is worth copying, and it is easier than it looks.
Most sovereignty requirements in RFPs are unusable. They read like this:
The supplier shall guarantee that all data remains within the European Union and shall be fully GDPR compliant.
Every serious bidder will answer yes. The large US platforms will answer yes truthfully, because they all operate EU regions and all offer a DPA with standard contractual clauses. You have written a question that does not discriminate between the options you are trying to discriminate between, and you will discover that at evaluation, when it is too late to rewrite the criterion.
The interesting development of 2026 is that some large buyers stopped doing this.
What Airbus did differently
Airbus ran a tender to move mission-critical systems — ERP, MES, CRM, PLM — to a sovereign European cloud. Reported at over €50 million, up to ten years, and awarded to Scaleway.
The detail worth copying is not the outcome. It is that protection from non-European extraterritorial legislation was a scored criterion, weighted alongside technical capability — not a compliance gate the bidders passed or failed.
That change does three things at once:
- It admits degrees. “Are you outside the CLOUD Act?” is a binary that most bidders can talk their way around. “How structurally are you outside it, and show your working” produces a spread of answers you can rank.
- It stops sovereignty being free. As a pass/fail gate, sovereignty costs a bidder one paragraph. As twenty weighted points, it costs them architecture — and the bidders who actually have that architecture finally get credit for it.
- It survives legal review. A weighted criterion applied consistently to all bidders is ordinary procurement practice. A requirement that only one nationality of supplier can meet invites a challenge.
The EU now supplies the vocabulary for this too: the Commission’s Cloud Sovereignty Framework grades offerings on SEAL levels, and the €180 million sovereign cloud framework awarded in April 2026 used it. You can reference a published scale instead of inventing a private one.
A scoring rubric you can lift
Weight this against your other criteria however you like — Airbus’s point is that it should carry real weight, not that it should carry a specific number. Within the sovereignty block, we would distribute roughly like this:
Entity and control (35%)
- Which legal entity signs, where is it incorporated, and who owns it up the chain?
- Is any entity in the ownership chain subject to non-EU disclosure law?
- Score structural answers above contractual ones. “Our parent cannot be compelled because there is no non-EU parent” outranks “our parent has committed to challenge orders.”
Control plane and metadata (25%)
- Where does the control plane run — orchestration, metadata, query text, credentials, audit logs?
- Which of these leave the EU, ever, including for telemetry and support tooling?
- Ask per subsystem. Aggregate answers hide the exceptions, and in analytics the metadata is not a minor leak: table names, column names, and query text describe your business.
Operational access (20%)
- Which countries do support and SRE staff sit in?
- Full subprocessor list with countries, and the notification terms when it changes.
- Break-glass procedure: who can reach production data, under what approval, logged how?
Exit and portability (20%)
- Open formats, documented export, no egress penalty, and a tested restore.
- The access-control model too: roles, groups, and grants should export in a documented format you can diff, version, and re-import elsewhere — permissions are configuration, not lore. (Disclosure: Molinia ships this as a portable RBAC snapshot with merge-import and a dry-run preview; ask every bidder for their equivalent.)
- The EU Data Act’s switching provisions are your floor here, not your ceiling.
- Sovereignty you cannot leave is a different vendor lock-in wearing a flag.
Two scoring notes. First, weight evidence over assertion: a documented architecture diagram beats a sentence in a proposal, and a transparency report beats a promise. Second, require the answers as contract schedules rather than proposal prose, so they survive into the agreement.
What not to do
Do not write “must be a European company.” Depending on your organisation and the procurement regime, that may be challengeable, and it is bad evaluation anyway — it scores a passport rather than a property. Score the property. European incorporation will come out ahead on a well-designed rubric without you having to name it.
Do not conflate residency with jurisdiction. If your requirement can be met by selecting a region from a dropdown, it is a residency requirement. That is a legitimate thing to want; it is just not the thing this section is for.
Do not skip the boring resilience questions. DORA asks financial entities about concentration risk, and the same logic applies outside finance: a supplier who is sovereign, excellent, and the single point of failure for four critical systems is still a risk you have to write down.
Do not let sovereignty outrank correctness. A European vendor that loses your data is worse than a non-European one that does not. Airbus scored extraterritorial protection alongside technical capability. The order matters less than the “alongside.”
Why this is worth the effort now
The buyer-side momentum is real and it is documented. ABN AMRO, ING and Rabobank announced in February 2026 that they are working with other European banks on shared European cloud and data infrastructure, on a three-to-five-year horizon. The Dutch government moved cloud services to a European provider in April 2026. Dutch universities have stood up a digital-autonomy committee and are consolidating around SURF. Gartner has European sovereign IaaS growing roughly 83% year over year.
At the same time, Forrester’s read is that none of this will dislodge the US hyperscalers at an aggregate level — and that is probably right. Both things are true: the aggregate barely moves, and specific categories move a lot. Analytics is one of the categories that moves, because the warehouse is where the linkable data accumulates and where the transfer assessment is hardest to write.
Which means the useful question for most teams is not “should we go sovereign.” It is “where, specifically, is sovereignty worth paying for” — and an RFP section that scores rather than gates is how you find out.
Molinia is an EU-sovereign OLAP platform, so we are not a neutral party here. We have answered enough of these questionnaires to think the scored version is better for buyers even when it costs us points. If you are drafting one and want the questions pressure-tested by someone who has to answer them, get in touch.