NEWNew: French Tech B2B SaaS Positioning Report 2026  Read the report β†’

Digital Sovereignty: Legal Access, Before Even the Hacking

5 min read

This article was automatically translated from the original version.

Since this summer, the news has been regularly punctuated by new data leak announcements, both public and private: more than 670,000 DGFiP (French tax authority) users affected in August, 2.1 million SFR accounts exposed the same month, Bloctel and (far too) many others also hit throughout August (source). There’s real work to do on cybersecurity.

Every cybersecurity training teaches two key principles:

  • the question isn’t whether you’ll get hacked, but when
  • the main security flaw is human, especially through what’s known as “social engineering”

And factually, there’s an even deeper gap, of a different nature: the moment a foreign government can, through the simple application of a law, gain access to all of your data without guaranteeing either its security or its confidentiality once obtained, no technical barrier changes anything. Here, the human flaw isn’t clicking a phishing email, it’s the choice, made once and never revisited, of a vendor, without ever asking who can legally access your data.

That’s where SecNumCloud 3.2 starts to change things. A framework in the works since 2022, it strengthens the public-sector requirement through the August 12, 2026 order.

Before listing its key changes compared to version 3.1, a bit of history.

Just Because It Hasn’t Happened Yet Doesn’t Mean It Won’t

Microsoft is bound by the Cloud Act, and there’s nothing you can do about it. During the hearing of Anton Carniaux (Director of Public and Legal Affairs at Microsoft France), on June 10, 2025, he was asked whether he could guarantee that no French data would ever be handed over to US authorities without French authorities’ agreement. His answer: “No, I cannot guarantee that, but again, it has never happened yet.”

As I wrote above, the question isn’t “if,” it’s “when.”

SecNumCloud 3.2: A Game Changer?

SecNumCloud has been at version 3.2 since March 8, 2022. The April 14, 2026 decree makes a qualification at this level mandatory for state services, its operators, and six named public-interest groups. The August 12 order approves SecNumCloud 3.2 as the reference framework that fulfills this obligation.

The key changes, specifically designed to guard against foreign interference:

  • the vendor’s registered office, management, and capital must be very predominantly European.
  • non-EU entities cannot individually hold more than 24% of the capital, nor more than 39% combined, and have no veto right or board majority.
  • a subcontractor based outside the EU must be technically unable to access the data.
  • the vendor’s ties to a foreign government can be taken into account when assessing its compliance.
  • remote access from outside the EU, as part of technical support, must go through a secure gateway, supervised in real time.
  • remote maintenance of the infrastructure by an unverified person must go through that same secure gateway.
  • the vendor must monitor and be able to filter everything that leaves its infrastructure (billing, logs, etc.) to prevent a data leak through that channel.

What About the Private Sector?

Across the various SaaS and PaaS products I’ve worked on since 2015, I’ve seen growing attention to sovereignty issues, with questions about where data is hosted and how it’s shared with third parties coming up more and more often.

But in practice, it was mostly about “having a general idea of what happens to the data,” rather than setting strict limits.

Let’s be honest: today, a French B2B SaaS startup would struggle enormously to write its code, host its solution, and fully equip itself with sovereign tools to bring a product to market. Some solutions simply don’t exist yet, others aren’t good enough. Among more established companies, we do have genuine gems to be proud of.

And even then, those same companies may rely on third-party tools for customer relationship management. Your users’ data is secured, but yours, as their customer, may not be. For every tool you use, take a moment to check its privacy, cookie, and GDPR policies. Chances are you’ll find American third parties, or third parties who themselves rely on American subcontractors. Here, GDPR hasn’t guaranteed your data won’t leak. What it has mostly done is force a degree of traceability, one that will always be limited by a SaaS company’s willingness to actually keep those pages up to date.

What to Do About It

No need to migrate your entire stack to SecNumCloud overnight. That would be overkill for most SMEs and mid-market companies, and it’s not the point of this article anyway.

Two simpler things to do this week:

  • from the perspective of your company’s own data: map out where your genuinely sensitive data actually lives: HR, contracts, R&D, customer data, anything whose leak or unauthorized access would really cost you.
  • from the perspective of your data as a buyer: explicitly ask your cloud vendors where your data sits and who can legally access it without notifying you, and if the answer isn’t enough, go check their privacy and subcontracting policies yourself, that’s often where the American third parties you hadn’t spotted are hiding.

SecNumCloud doesn’t stop anything on its own. But looking into it more closely forces you to ask the right questions, the ones that keep your data from ending up out there despite massive cybersecurity efforts. A bit like that gate standing in the middle of a path, with a clear, well-worn detour running right next to it: it stops no one, because nothing frames it.


Cover image: “Gates without wall” by Sergei Gutnikov, CC BY-SA 3.0

Share :