In today’s digital economy, data has become an indispensable strategic asset—the primary fuel powering artificial intelligence, shaping industrial value chains, and guiding executive decision-making. Yet, this central role creates a fundamental paradox: organisations must circulate data to drive value, while navigating a threat landscape where economic espionage and covert intelligence gathering pose systemic risks. As reliance on foreign-hosted cloud infrastructures grows, European organisations’ most critical assets face heightened exposure to both state-sponsored and criminal exploitation.
To address this strategic dilemma, Cigref launched a collective intelligence initiative in 2023, mobilizing senior executives and industry experts. Moving beyond simple technical analysis, this initiative delivers high-level strategic reflection and a unified framework for major public and private organisations.
Ce rapport est disponible en français (French version)
The Impasse of Current Approaches: The Legal and Technical ‘Blind Spot’
A core finding of this work is the existence of a legal “blind spot” surrounding non-personal data. While European regulation has extensively focused on personal data and privacy protection, industrial and strategic corporate data remain trapped in a regulatory grey area—to the direct detriment of European competitiveness.
The report demonstrates why traditional safeguards are no longer sufficient in a globalised environment:
- The inadequacy of legal mechanisms: Contractual clauses, trade secrets, and intellectual property rights—while necessary—offer little defense against non-European laws with extraterritorial reach (such as Section 702 of the US FISA). These mandatory criminal and intelligence laws are forcefully imposed on cloud providers, systematically overriding private law agreements.
- The structural vulnerability of “data in use”: From a technical perspective, standard encryption effectively secures data at rest and in transit. However, processing data requires decrypting it into plaintext within random access memory (RAM). This creates a critical window of vulnerability whenever a cloud operator is subject to foreign jurisdiction.
- The current limits of emerging technologies: Fully Homomorphic Encryption (FHE) is not yet commercially mature at scale, while Confidential Computing merely shifts trust toward chip manufacturers and proprietary hardware architectures that cannot be independently audited.
Legal Supremacy and the Drive for a European Regulatory Framework
These findings lead to an uncomfortable yet inescapable conclusion: there is no purely technical shield. Ultimate data security relies not on the complexity of cryptographic defenses, but on the legal jurisdiction governing the infrastructure operator. True immunity from extraterritorial reach can only be achieved through a legal guarantee—specifically, by selecting cloud providers operating exclusively under European law.
While France paved the way with its SecNumCloud qualification and « Cloud-at-the-Centre » doctrine, the purely domestic scope of these measures creates regulatory fragmentation for multinational organizations.
The challenge now is to scale this protective model across the continent. With the European Data Act fully applicable since September 2025, alongside current 2026 legislative momentum—including negotiations on the revised Cybersecurity Act (CSA 2) and the Cloud and AI Development Act (CADA)—Europe faces a historic window of opportunity to consolidate the security of its strategic data assets.
Cigref’s Vision: Reconciling Security and Economic Performance
In light of these geopolitical challenges, Cigref is not advocating for burdensome constraints, but for an approach built on incentives, stakeholder accountability, and business realities. Our proposals center on four core pillars:
- A flexible definition of sensitive data: Giving organisations the autonomy to define their sensitive data scope based on their own detailed business risk assessments.
- A matrix-based certification framework: Seamlessly aligning the technical protection tiers of CSA 2 with the legal safeguards against extraterritoriality provided by the CADA within the future EUCS scheme.
- Economic demand-side support: Redirecting public funding and leveraging tax incentives (such as tax credits and accelerated depreciation) to help enterprises offset the cost premium of trusted cloud offerings—estimated at 15% to 20% compared to hyperscalers.
- Pragmatic transition pathways: Implementing phased timelines of 3 to 5 years (and up to 10 years for the most critical assets), aligned with contract renewal cycles, so as not to compromise the technological capabilities of European organisations.
Through this briefing note, Cigref positions itself as a constructive advocate for balanced regulation—transforming data security from a simple factor of trust into a cornerstone of Europe’s economic strength.