Magistrae
Sign inTry
All articles

Sovereign LMS: what it means, and how to verify it

An LMS hosted in the EU is not necessarily sovereign. The verifiable criteria, what EU law actually says about transfers, and the questions to ask a vendor.

·

A sovereign LMS depends on no foreign company and no foreign law. Server location alone does not achieve this: what determines the applicable law is the nationality of the operator and of its capital. Five criteria make this verifiable, and none of them rests on the vendor's word.

This page covers what to establish before entrusting a platform with your employees' training records. It is written for the European market; a separate French edition covers requirements specific to France, including Qualiopi and the national SecNumCloud qualification.

The confusion to clear first

Ask a vendor where your data is hosted. You will hear "in the EU". That is often true, it is verifiable, and it does not answer the question.

The CLOUD Act, enacted on 23 March 2018 as division V of Public Law 115-141, allows US federal authorities to compel a company subject to United States law to produce data it holds or controls, regardless of where that data is stored. The test the statute applies is not geographic, it is jurisdictional. A European subsidiary of a US group remains in scope through its parent company.

Put plainly: a Frankfurt or Paris data centre creates a boundary in fact, never a boundary in law.

European regulators put it in the same terms. In a publication of 19 July 2024 on the draft European cloud certification scheme, France's data protection authority, the CNIL, writes that data stored by a company subject to non-European law, "as is the case with hosting providers whose parent companies are located in the United States", may be exposed to a risk of having to disclose that data to the public authorities of that country.

The criteria

A sovereign LMS can be checked on five points. None of them rests on the vendor's word.

Criterion What can be checked
Hosting the named provider and the location of servers, backups included
Operating company legal form and registration, within the Union
Capital ownership, including investment funds
Development where the engineering teams actually work
Data a contractual commitment that data does not leave the Union

Capital ownership is the criterion most often skipped, and the most decisive after hosting. A company incorporated in the EU but majority-owned by a non-European fund raises exactly the same question as a US subsidiary.

Backups are the second omission. Infrastructure hosted in the EU but backed up elsewhere is not EU infrastructure.

What EU law says

The GDPR governs transfers outside the Union in Chapter V, Articles 44 to 50. A transfer is lawful if it rests on an adequacy decision, on appropriate safeguards, or on one of the derogations the text provides.

Article 48 is the pivot of the whole subject. It provides that a decision of a court or administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may be recognised or enforceable only if it is based on an international agreement.

In July 2019, the European Data Protection Board and the European Data Protection Supervisor delivered a joint legal assessment of the CLOUD Act to the European Parliament's LIBE Committee, which covers civil liberties, justice and home affairs. They adopt a restrictive reading of Article 48: absent an international agreement, a transfer based on the CLOUD Act alone would be lawful only if a separate legal basis could be found under Articles 6 and 49. The European authorities therefore identify a conflict of norms, not a point of attention.

On transfers to the United States, precision matters, because this is where most vendor claims fail:

Framework Adopted Outcome
Safe Harbor 2000 struck down by the CJEU on 6 October 2015, case C-362/14
Privacy Shield 2016 struck down by the CJEU on 16 July 2020, case C-311/18
EU-US Data Privacy Framework 10 July 2023 in force, appeal pending

The current framework is in force. The General Court dismissed the action for annulment brought against it on 3 September 2025. Transfers to the United States are not unlawful today, and anyone who tells you otherwise is oversimplifying.

An appeal was lodged before the Court of Justice on 31 October 2025 and is pending. More to the point, this is the third framework in ten years and the Court has annulled the first two. An organisation whose data never leaves the Union, held by an operator subject only to EU law, depends on none of these decisions.

The open source question

The objection arrives quickly: refusing US technology while running a kernel, a language and libraries largely written in the United States would be inconsistent.

It does not hold, because origin is the wrong test. Open source software is auditable, runs on your own infrastructure, and can be forked if the project changes direction. None of these three properties depends on where the code was written. A hosted service offers none of them: it is opaque, it runs on the vendor's infrastructure, under the vendor's law, and it cannot be forked.

What we refuse are services subject to foreign law. Not software whose code we can read.

Sovereignty also means being able to leave

A platform you cannot exit is not sovereign, it is merely well located. Reversibility rests on four checks: export available from the administration interface without vendor involvement, the exact scope of that export, no automatic renewal, and a known exit cost.

Questions to ask a vendor

  1. Is your company, or any parent company, subject to the law of a state outside the European Union?
  2. Who owns your capital?
  3. Where are backups hosted?
  4. Which sub-processors have access to our learners' data?
  5. Can we export all content and tracking history without going through you?
  6. What will appear on our final invoice if we leave?

An honest answer is short. An answer that expands on certifications and encryption while avoiding the question is also an answer.

Where Magistrae stands

Hosted in Paris with Scaleway, backups included. French company, French capital, taxes paid in France, development carried out in France. Customer data does not leave the territory. Export available from the platform, no lock-in period, no automatic renewal.

What we do not claim: our source code is not open today, customer self-hosting is not yet available, and we hold no cloud sovereignty qualification. We also retain dependencies that are not sovereign, GitHub and US-based AI tooling used internally, none of which processes customer data. We publish that list.

Frequently asked questions

Is hosting in the EU enough for GDPR compliance? No. Compliance covers the whole processing operation: purposes, minimisation, retention, data subject rights, security. Location concerns only the transfer chapter.

What is the difference between "hosted in the EU" and "sovereign"? The first describes a place, the second an applicable law. An EU provider owned by a non-EU group remains exposed to its parent's jurisdiction.

Do standard contractual clauses solve the problem? They remain valid after Schrems II, but the exporter must verify, case by case, that the destination country's law does not prevent compliance with them, and suspend the transfer otherwise.

Does encryption solve it? It depends who holds the keys. If the provider can decrypt data to operate the service, it can be compelled to do so.

Can we get our data back if we move to another platform? That is verified before signing, not on the way out.


Sources