GDPR
Reg. (EU) 2016/679. Sovereign is positioned around data minimisation, portability, erasure planning, and deployment boundaries that make processor review easier.
Project Sovereign is positioned around European regulatory review: data minimisation, continuity, auditability, exit strategy, AI governance, and clear deployment boundaries.
These are public positioning areas, not certifications. Deployment-specific evidence should be requested during review.
Reg. (EU) 2016/679. Sovereign is positioned around data minimisation, portability, erasure planning, and deployment boundaries that make processor review easier.
Dir. (EU) 2022/2555. Document workflows need risk analysis, incident handling, continuity, supply-chain review, and cryptography evidence mapped to Article 21 controls.
Reg. (EU) 2022/2554. Financial entities need ICT vendor review, exit strategy, audit rights, resilience evidence, and clear sub-processor boundaries.
Reg. (EU) 2024/1689. AI is described as optional, provider-controlled, auditable, and off by default rather than embedded as an unavoidable cloud feature.
Production deployments should confirm regions, sub-processors, backups, logs, and support access before handover.
The intended posture records actors, actions, timestamps, sessions, and document state without exposing document bodies in logs.
AI features are not described as default cloud behavior. Provider choice and data flow belong to the deploying institution.