Keeping data in a European data centre is often equated with digital sovereignty. But where data is stored is only part of the picture. What matters just as much is who can legally or technically access that data – and who ultimately controls the infrastructure behind it.

This is where the European Union’s proposed Cloud and AI Development Act (CADA) comes in. The new framework is designed to take a much broader view of digital sovereignty and will have a direct impact on how organisations evaluate cloud and software providers in the future.

What is CADA – and what will change?

CADA is a proposed EU framework for assessing the digital sovereignty of cloud and AI services, currently expected to be introduced in 2027.

Rather than focusing on data residency alone, the proposed model also considers protection from third-country access, European ownership and control, and sovereignty over infrastructure and supply chains.

In other words, digital sovereignty is no longer simply about where your data is stored. It is about who ultimately controls it.

The four CADA levels at a glance

The current model defines four levels of digital sovereignty:

Level 1

EU data residency

Data is processed within the European Union.

Level 2

Protection from third-country access

In addition to EU-based processing, data must be protected from access by third countries, including potential access under legislation such as the US CLOUD Act.

Level 3

European ownership and control

The provider itself must also be under European ownership and control.

Level 4

Full European sovereignty

Infrastructure and supply chains are fully under European control, without third-country influence.

The takeaway is simple: EU data residency is not the end goal of digital sovereignty. It is Level 1.

Who will CADA affect?

CADA will be particularly relevant to public-sector organisations and companies operating in critical sectors. Under the current framework, this includes organisations covered by NIS2, with the applicable sovereignty level depending on the organisation’s individual risk and impact assessment.

This includes banks and financial market infrastructures, healthcare organisations and public administrations, as well as sectors such as energy, transport and digital infrastructure.

These industries handle highly sensitive financial, patient, employee and contractual data every day. As a result, digital sovereignty will become an increasingly important factor when choosing technology providers that process or otherwise come into contact with this information.

What does CADA mean for eSigning?

For eSigning providers, EU hosting alone will no longer be sufficient from CADA Level 2 onwards.

Where documents are processed still matters, but so does the provider’s ability to access their contents, its exposure to third-country legislation, its ownership structure and the infrastructure it relies on.

This is particularly relevant for electronic signatures because the documents involved are often highly confidential – from banking and customer records to employment contracts and medical reports.

An eSigning provider can host its systems entirely within Europe and still be subject to legal or technical dependencies outside Europe. US-based eSignature providers such as DocuSign and Adobe Acrobat Sign, for example, are subject to the US CLOUD Act and therefore do not meet the Level 2 requirement of protection from third-country access.

Data residency is where digital sovereignty starts. It is not where it ends.

Privacy-First eSigning built for digital sovereignty

Certifaction takes a Privacy-First approach to eSigning. With Zero Document Knowledge, Certifaction cannot access the readable contents of customer documents. Documents are processed locally on the user’s device – whether a computer, smartphone or other endpoint – and end-to-end encrypted before they reach our systems.

Confidentiality therefore does not depend solely on policies, contractual commitments or organisational safeguards. It is built into the technical architecture.

Based on our current internal assessment of the CADA criteria published to date, Certifaction meets the requirements of all four sovereignty levels.*

Digital sovereignty goes beyond where your data lives

EU data residency is an important part of digital sovereignty. But true sovereignty requires more: control over who can access confidential information, who owns and controls the provider, and who controls the underlying infrastructure and supply chain.

With Privacy-First eSigning, confidential documents remain under your control throughout the entire signing process.

Is your eSigning solution ready for the upcoming requirements? If not, talk to us.

*CADA is still a proposed regulatory framework and its final criteria and requirements may change. This classification is based on Certifaction’s internal assessment of the CADA criteria currently available.

Sources

  • European Commission: Information on the proposed Cloud and AI Development Act (CADA), current planning status 2026.
  • European Union: Directive (EU) 2022/2555 (NIS2 Directive), Annexes I and II.
  • SECJUR: https://www.secjur.com/en/blogs/nis2