STACKIT
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign This listing EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
German sovereign cloud built by Schwarz Digits (Lidl/Kaufland parent), 4 EU DCs, EU Cloud III €180M winner with SEAL-3 highest rating.
STACKIT is an EU-owned service hosted in Germany, with no identified CLOUD Act exposure. It is listed under Cloud & hosting.
Assessment notes
STACKIT (Bad Friedrichshall, German Schwarz Digits, the IT arm of privately-held Schwarz Group, parent of Lidl and Kaufland) is built explicitly as a sovereign-cloud alternative to AWS/Azure/GCP: ISO 27001 + 27017 + 27018, BSI C5 Type 2 across 18 named platform services, TISAX Level 3 and DORA-ready, four EU data centres (Neckarsulm DC01, Ellhofen DC08, Ostermiething Austria DC10, fifth Lübbenau under construction), winner of the European Commission's €180M Cloud III tender (April 2026, SEAL-3 highest sovereignty rating) and the Dutch Ministry of Justice & Security SLM Rijk framework; EU-owned and EU-hosted with no CLOUD Act exposure.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Yes
-
Public DPA: Yes
-
Sub-processors disclosed: No
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About STACKIT
STACKIT is the sovereign cloud built by Schwarz Digits, the IT and digital division of the privately-held Schwarz Group, parent of the European discount-retail giants Lidl and Kaufland. Headquartered in Bad Friedrichshall, Germany (Am Campus 1, 74177), STACKIT runs four European data centres at Neckarsulm (DC01, Schwarz Group HQ campus), Ellhofen (DC08, Heilbronn region), Ostermiething (DC10, Salzburg, Austria), and a fifth facility under construction in Lübbenau, Germany. The Schwarz Group has invested approximately €11B in STACKIT, making it one of the most heavily-capitalised European cloud-sovereignty bets and a structurally different proposition from VC-funded EU cloud upstarts: the parent retailer is a private German Stiftung-controlled group with €146B annual turnover, with no PE or US-VC exposure on the cap table at any layer.
Sovereignty positioning is the entire product thesis. STACKIT markets itself as "100% European DNA" with the trio "Skalierbar. Sicher. Souverän" (scalable, secure, sovereign). The compliance footprint covers ISO 27001, ISO 27017 and ISO 27018, BSI C5 Type 2 across 18 named platform services, DORA-ready ICT-third-party status for regulated financial services, GDPR, and the Schwarz Group's own ES³ (European Sovereign Stack Standard) internal sovereignty measurement framework. The procurement validation came in two moves during 2026: (1) selection as one of four winners of the European Commission's €180M Cloud III sovereign-cloud framework (April 2026), with the highest SEAL-3 rating signifying engineering against supply-chain disruptions originating outside the EU; and (2) selection by the Dutch Ministry of Justice and Security under the SLM Rijk framework as a sovereign cloud alternative.
The product surface spans 11+ categories: infrastructure (compute, block/object storage, networking), managed databases, managed Kubernetes, AI workloads, and colocation. Pricing is via a configurable STACKIT Calculator; specific entry-tier figures were not captured at audit but the product is positioned mid-market to enterprise rather than indie/SMB. Best fit: EU public-sector procurement (post-Cloud III tender), DORA-regulated financial services, large EU corporates needing a non-VC-funded sovereign cloud, and any organisation aligning with Gaia-X or the EU Tech Sovereignty Package. Together with Hetzner, OVHcloud, and Scaleway, STACKIT forms the four-pillar EU hyperscaler-alternative stack on this directory.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of STACKIT
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Finland · $5/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Italy · €1.99/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: No Open source: No -
-
SwedenEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
$5/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: No
Open source: No
|
€1.99/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |