On July 7, the Government of the Generalitat of Catalonia announced a call for bids for a sovereign public cloud that will be located entirely in Catalonia. According to the government, it will be the first infrastructure of its kind in Spain and the first European sovereign public cloud to meet the SEAL 3 standard, the second-highest level in the European framework for technological sovereignty and resilience.

 

The goal of this infrastructure is to strengthen control over data and reduce reliance on technology from outside the European Union. The Generalitat plans to host sensitive services and data related to public health, the Mossos d’Esquadra, and traffic management on this platform. The project is part of the Generalitat de Catalunya’s Technology Autonomy Strategy (ESTRATEC) and aims to increase the resilience of public services.

With a maximum budget of 481 million euros over eight years, the contract is expected to be awarded in the fourth quarter of 2026, and the service should become operational during the second half of 2027. The winning bidder will be able to offer the service to the Generalitat itself and to other public and private entities, but not to private individuals.

Now, what exactly is a sovereign public cloud, and what are its objectives? Before answering, it is worth clarifying a term that is prone to confusion: the term “public” cloud.

 

Table of Contents

Public cloud doesn't mean what it seems

The term “public” does not imply that the information is accessible to anyone or that the infrastructure necessarily belongs to a government agency. A public cloud is a model in which a provider offers computing resources, storage, and other technology services to different organizations, keeping their respective data and environments separate and secure.

A private cloud, on the other hand, uses infrastructure reserved for a single organization, although it may be managed internally or by an external provider. This model offers greater control over configuration, resources, and security policies. In contrast, the public cloud facilitates scalability and provides on-demand access to managed technology resources.

Sovereignty is not an alternative cloud model; it adds legal, operational, and technological safeguards to the chosen infrastructure—in the case of Catalonia, to a public cloud.

 

What does the term “sovereign” add?

The sovereign status involves requirements related to:

  • Applicable jurisdiction.
  • Data location and processing.
  • Access control and encryption keys.
  • Audit capabilities.
  • The chain of suppliers and subcontractors.
  • Hardware and software dependencies.
  • Service continuity.

 

A sovereign public cloud, therefore, combines the flexibility and scalability typical of cloud services with greater assurances regarding who controls the infrastructure and under which laws it is managed.

Its value lies in the decision-making authority that the organization retains. Specifically, it allows the organization to:

  • Determine where the most sensitive data is hosted.
  • Control who can access it.
  • Identify which technological components are involved.
  • Anticipate how services would be maintained in the event of an outage, a contractual change, or a regulatory conflict.

 

The physical location of data centers is a significant factor, although it is not sufficient on its own. Other important factors include the jurisdiction of the provider and its parent companies, the origin of the technology, the ability to migrate workloads, and the capacity to operate without significant interference from entities outside the European Union.

Technological sovereignty does not require forgoing all international solutions either. Its goal is to identify existing dependencies, reduce the most critical ones, and have alternatives for data and services that require greater guarantees of control, security, and continuity.

In the case of the Catalan cloud, the Generalitat already uses commercial public cloud services. The new development involves incorporating an environment that combines the capabilities of this model with greater legal, technological, and operational safeguards.

The procurement process is being managed by the Centre de Telecomunicacions i Tecnologies de la Informació (CTTI), the public entity that oversees the Generalitat’s IT and telecommunications services and coordinates its technology projects. The infrastructure will be located entirely in Catalonia and will be connected to the Generalitat’s other public communications infrastructures, such as the publicly owned fiber-optic network.

 

A hybrid cloud architecture

A hybrid architecture combines a private cloud with one or more public clouds, allowing applications and data to be distributed across them. Each workload is placed in the most appropriate environment based on its sensitivity, criticality, and requirements for security, capacity, performance, or innovation.

The European Commission itself defined a hybrid and multicloud strategy for its services, based on a combination of an internally managed private cloud and services provided by various public cloud operators.

In Catalonia, approximately 80% of the Generalitat’s services are currently hosted in a private cloud, while 20% use commercial public cloud services. The new model is expected to evolve, over the next two years, toward the following distribution:

  • 40% in the new sovereign public cloud.
  • 30% in commercial public cloud services.
  • 30% in private cloud.

 

The new sovereign cloud will not replace all the environments used by the Generalitat. It will provide an additional option for hosting data and services that require a combination of the capabilities of a public cloud with greater guarantees of sovereignty and resilience.

 

A benchmark for the company

Likewise, this same logic serves as a reference for businesses. A company can host its most sensitive systems in a private cloud, turn to commercial public cloud services when it needs scalability or advanced capabilities, and use sovereign infrastructure for information subject to specific legal or operational requirements. The Generalitat’s project thus offers a mirror in which organizations can reflect on their own technology strategy.

 

Sovereignty and resilience also depend on the network

Once data and applications are distributed across multiple environments, the network becomes the element that connects them and determines much of their security and continuity. In a hybrid architecture, the network must connect offices, data centers, users, applications, and different cloud environments securely and continuously. To achieve this, the following are particularly important:

  • Communication encryption.
  • Segmentation and separation of different types of traffic.
  • Redundancy of connections.
  • Centralized enforcement of security policies.
  • Visibility into access and data flows.
  • Detection of anomalous behavior.
  • The ability to isolate part of the infrastructure in the event of an incident.

 

The network alone does not determine the sovereignty of a cloud service, but it reinforces the security, availability, and resilience of access to that environment.