Sovereign Controls by Partners extends Google Cloud’s sovereignty offering with partner-operated data boundaries. For the DACH region, the Germany Data Boundary by T-Systems is the relevant option: it mandates the europe-west3 region and customer-managed encryption keys for a defined set of Google Cloud services.
What is Sovereign Controls by Partners?
Per the official overview page, Sovereign Controls by Partners provides sovereignty controls for Google Cloud workloads that are operated by partners. It helps enforce data residency and provides security configurations covering critical aspects of the cloud infrastructure, such as encryption and key management.
The documentation lists five generally available (GA) data boundaries: France Data Boundary by S3NS, Germany Data Boundary by T-Systems, Italy Data Boundary by Polo Strategico Nazionale (PSN), Kingdom of Saudi Arabia Data Boundary Advanced by CNTXT, and Kingdom of Saudi Arabia Data Boundary Foundation by CNTXT.
In the Sovereign Cloud from Google security catalog, Sovereign Controls by Partners is listed as a complementary, partner-operated sovereignty control alongside Google Cloud Data Boundary and Google Cloud Dedicated.
Germany Data Boundary by T-Systems in detail
For folders in the Germany Data Boundary by T-Systems, documentation describes an organization policy constraint (gcp.resourceLocations) that allows new resources to be created only in the europe-west3 region. In addition, for a defined list of API services, including Compute Engine, Google Kubernetes Engine, BigQuery, Cloud SQL, Spanner, Cloud Storage and Pub/Sub, encryption with customer-managed encryption keys (CMEK) is mandatory, enforced through the gcp.restrictNonCmekServices organization policy constraint. The full product table lists 57 supported services with their API endpoints and any restrictions (as of September 20, 2026), including Compute Engine, GKE, Cloud SQL, AlloyDB for PostgreSQL, BigQuery, Cloud Storage, Cloud KMS, Cloud HSM, Cloud EKM, Secret Manager, IAM, Cloud Build, Artifact Registry, Cloud Run and Speech-to-Text. Services not listed in this table are considered unsupported by the documentation and are not recommended for Sovereign Controls customers without further due diligence.
Division of responsibility
Google documents a dedicated shared responsibility model for Sovereign Controls by Partners. Customers are responsible for, among other things, placing regulated or sensitive data in the appropriate Sovereign Controls folders, configuring IAM correctly, and organizing their org hierarchy so it doesn’t expose personal data. Google is responsible for, among other things, default encryption and infrastructure controls, enforcing the IAM policies customers set, and configuring and enforcing the chosen Sovereign Controls settings, including which Google employees can access customer data in the course of their business activities.
Google does not publish a dedicated pricing model on the overview page; check conditions with Google Cloud or the respective partner.
Core Features
- Partner-operated data boundaries: Five GA data boundaries, operated by S3NS, T-Systems, PSN and CNTXT.
- Region restriction via organization policy: For the Germany Data Boundary by T-Systems, resource creation is limited to europe-west3.
- Mandatory CMEK: Encryption with customer-managed keys is required for a defined set of services.
- Product-specific approval: A product table per data boundary defines which Google Cloud services are supported.
- Dedicated shared responsibility model: Clear division of responsibility between Google, the partner and the customer.
Typical Use Cases
Regulated workloads with German data residency
A company with residency requirements for Germany uses the Germany Data Boundary by T-Systems to ensure resources are created only in europe-west3.
Evidencing customer-managed keys
For audits, evidence is provided that in-scope services such as BigQuery, Cloud SQL or Cloud Storage are encrypted exclusively with customer-managed keys.
Selecting approved services before project start
Before architecture planning, the product table is checked to determine which Google Cloud services are supported within the chosen data boundary.
Clarifying responsibilities in compliance projects
Security and compliance teams use the documented shared responsibility model to document customer and provider obligations for an audit.
Benefits
- Local partner operation: Operated by established, nationally anchored partners such as T-Systems or S3NS.
- Technically enforced region binding: Organization policies rather than mere declarations of intent.
- Clear key control: Mandatory CMEK for in-scope services.
- Transparent product coverage: Documented list of supported services per data boundary.
- Complements existing sovereignty options: Positioned alongside Data Boundary and Dedicated within Sovereign Cloud from Google.
Integration with innFactory
As a certified Google Cloud partner, innFactory helps you assess Sovereign Controls by Partners for your requirements: checking which of your Google Cloud services are supported within the Germany Data Boundary by T-Systems, designing CMEK key management, and aligning organization policies for region and service restrictions. We describe the additional legal questions that apply to professionals bound by confidentiality obligations in our article on professional secrecy under section 203 of the German Criminal Code in the public cloud.
Contact us for a consultation on Sovereign Controls by Partners.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Sovereign Controls by Partners?
Per the official documentation, Sovereign Controls by Partners provides sovereignty controls for Google Cloud workloads that are operated by partners. It helps enforce data residency and provides security configurations covering critical aspects of the cloud infrastructure, such as encryption and key management.
Which partner data boundaries are generally available (GA) according to Google?
The documentation lists five GA data boundaries: France Data Boundary by S3NS, Germany Data Boundary by T-Systems, Italy Data Boundary by Polo Strategico Nazionale (PSN), Kingdom of Saudi Arabia Data Boundary Advanced by CNTXT, and Kingdom of Saudi Arabia Data Boundary Foundation by CNTXT.
What specifically applies to the Germany Data Boundary by T-Systems?
For folders in the Germany Data Boundary by T-Systems, documentation states that an organization policy constraint restricts resource creation to the europe-west3 region (gcp.resourceLocations). For a defined list of services, including Compute Engine, GKE, BigQuery, Cloud SQL, Spanner, Cloud Storage and Pub/Sub, encryption with customer-managed encryption keys (CMEK) is mandatory. The supported products and their API endpoints are listed in a dedicated product table; services not listed are considered unsupported.
How is responsibility divided between Google, the partner and the customer?
Google documents a dedicated shared responsibility model for Sovereign Controls by Partners. Customers are responsible for, among other things, placing regulated data in the appropriate Sovereign Controls folders, configuring IAM correctly, and organizing their org hierarchy so it doesn't expose personal data. Google is responsible for, among other things, default encryption, enforcing the IAM policies customers set, and configuring and enforcing the chosen Sovereign Controls settings.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
