TL;DR “Data sovereignty” sounds like a government problem. It isn’t. If your cloud provider is US-owned, such as Microsoft, Google or Amazon, it can be legally compelled to hand over your data, regardless of where the server sits, including a server in Malta or anywhere else in the EU. Maltese SMEs need to understand this for client due diligence, contracts and risk management, not to panic or rip out their software. This guide sets out the basics.
Why this has suddenly become a talking point
In September 2026, the Swiss government announced a pilot to move 3,000 federal workstations from Microsoft 365 to openDesk, an open-source alternative, citing cost and digital sovereignty as the reasons. It’s the latest in a run of similar moves: Denmark’s Ministry of Digital Affairs migrating away from Microsoft 365, France banning non-European videoconferencing tools from government use, and the Netherlands demanding exit strategies from US cloud providers.
None of this is really about software preference. It’s about a legal question that most Maltese business owners have never had reason to think about: who can be compelled to hand over your data, and under what law?
The basic legal mechanism
The US CLOUD Act (2018) allows US authorities to compel a US-headquartered company to produce data it controls, wherever in the world that data physically sits. A provider’s data centre in the EU doesn’t block this, because the compulsion is aimed at the company, not the building. If Microsoft, Google or Amazon is legally US-owned, then in principle your data is reachable under US law even if it never leaves a data centre in Frankfurt or Dublin.
The EU has tried to bridge this gap. The EU-US Data Privacy Framework, in force since 2023, is meant to make transatlantic data transfers lawful under GDPR. It survived its first legal challenge at the EU General Court in September 2025, but the case is on appeal, and the same framework’s two predecessors, Safe Harbour and Privacy Shield, were both struck down by the courts. Businesses that treat the current framework as a permanent fix are relying on something that has a track record of not staying in place.
There’s no Maltese or EU court precedent testing exactly how a CLOUD Act order would play out against a Maltese company’s GDPR obligations in practice. It’s an unresolved conflict between two legal systems, not a settled question with a clean answer.
Why this isn’t just a government-scale issue
It’s tempting to read all of this as something for Brussels and multinational corporations to worry about. For most Maltese SMEs, the exposure is unlikely to mean an actual data request ever lands on your desk. But there are three ways it becomes a genuinely practical business issue, and Malta’s economy makes all three more likely than most:
- Client and tender requirements. Malta’s economy runs on sectors, financial services, iGaming, professional services, tourism, where clients and partners routinely ask where data is processed and who controls it, as standard due diligence. Not having a clear answer can cost you the contract.
- Contractual obligations. Confidentiality and data-residency clauses are common in professional services, financial services and hospitality contracts. If you can’t demonstrate you’ve thought about this, you may be in breach without realising it.
- Insurance and risk assessment. Cyber insurers are starting to ask more detailed questions about data governance, not just security posture.
What Maltese SMEs can actually do about it
You don’t need to migrate off Microsoft 365 tomorrow, and for most businesses that wouldn’t be proportionate. What’s worth doing instead:
- Know who legally owns your providers. Not just where the servers are, but who the parent company is.
- Ask providers about encryption key control. If you hold the encryption keys rather than the provider, the provider may be technically unable to hand over readable data even under a valid order.
- Check your contracts. Look for data-residency or data-sovereignty clauses you’ve already signed up to, and make sure your actual setup matches what you’ve promised clients.
- Have an answer ready. Even a brief, honest explanation of where data sits and who controls it is better than being caught out by the question.
Where Malta stands
Unlike Switzerland, France or the Netherlands, Malta has no standalone digital sovereignty strategy of its own, and there’s no reason it should. As an EU member state, Malta’s position runs through Brussels: the EU Data Act, which took effect in September 2025, requires cloud providers operating in the EU to put technical and organisational measures in place to resist unlawful non-EU government access, and to challenge access requests that conflict with EU law. GDPR enforcement locally sits with the Information and Data Protection Commissioner (IDPC).
This means Maltese SMEs are, in practice, covered by a framework that’s still being tested and refined at EU level, not one that’s settled. Nobody is going to mandate a solution for you at short notice, which makes it more important to understand the basics rather than less.
Frequently asked questions
Does storing my data in an EU data centre protect it from the US CLOUD Act? No. The CLOUD Act applies based on who legally owns and controls the provider, not where the server is physically located. An EU data centre owned by a US company doesn’t remove the exposure.
Is this actually illegal under GDPR? It’s a legal grey area rather than a clear breach. GDPR requires organisations to guard against unauthorised access, and the EU-US Data Privacy Framework is meant to bridge the gap, but that framework is under active legal challenge and has no guarantee of surviving in its current form.
Do I need to stop using Microsoft 365 or Google Workspace? Not necessarily. For most SMEs, switching providers isn’t proportionate to the actual risk. What matters more is understanding your exposure, checking your contracts, and being able to answer the question if a client or auditor asks.
What’s the single most useful thing I can do this month? Find out whether your cloud provider gives you control of your own encryption keys. If you hold the keys and the provider doesn’t, that’s the most concrete technical safeguard available without changing software.
Is this only relevant to businesses that work with clients outside Malta? No, though it’s most acute there. Malta-only businesses can still be affected through insurance requirements, sector-specific regulation, or simply good governance practice, but the pressure is currently strongest from cross-border contracts and tenders.

