The EU’s Proposed CADA: Why Cloud Sovereignty Matters for Business Strategy, IAPP | McDermott

COVERAGE

The EU’s proposed CADA: why cloud sovereignty matters for business strategy, IAPP

Aug 20, 2026

Read time: 2 min

Partner Natallia Karniyevich co-authored an International Association of Privacy Professionals (IAPP) analysis examining the European Commission’s proposed Cloud and AI Development Act (CADA) and its potential implications for cloud providers and users.

The authors explain how CADA would introduce four assurance levels for cloud services, with requirements addressing data localization, third-country access, cybersecurity certification, and EU control. While initially focused on the public sector, the proposal could also affect private companies in highly critical sectors regulated under NIS2. The article outlines steps providers and users can take now, including mapping where data is stored, who controls cloud providers, which jurisdictions can access data, and which assurance levels may apply.

Read the full IAPP article >>
Subscription may be required

In this article

Dr. Natallia Karniyevich

Partner

Düsseldorf

You may also like