↓ Skip to main content
Cloud / Google Cloud / Products / Sovereign Controls by Partners - Partner-Operated Sovereignty Controls

Sovereign Controls by Partners - Partner-Operated Sovereignty Controls

Sovereign Controls by Partners provides partner-operated sovereignty controls for Google Cloud, with GA data boundaries including Germany (T-Systems).

Security
Pricing Model No separate pricing model published on the overview page; check conditions with Google Cloud or the respective partner
Availability GA data boundaries per documentation: France Data Boundary by S3NS, Germany Data Boundary by T-Systems, Italy Data Boundary by Polo Strategico Nazionale (PSN), Kingdom of Saudi Arabia Data Boundary Advanced by CNTXT, Kingdom of Saudi Arabia Data Boundary Foundation by CNTXT
Data Sovereignty Partner-operated data boundaries with data residency, encryption and key management; for the Germany Data Boundary by T-Systems, resource creation is documented as restricted to the europe-west3 region
Reliability SLA per provider (see official SLA page) SLA

Sovereign Controls by Partners extends Google Cloud’s sovereignty offering with partner-operated data boundaries. For the DACH region, the Germany Data Boundary by T-Systems is the relevant option: it mandates the europe-west3 region and customer-managed encryption keys for a defined set of Google Cloud services.

What is Sovereign Controls by Partners?

Per the official overview page, Sovereign Controls by Partners provides sovereignty controls for Google Cloud workloads that are operated by partners. It helps enforce data residency and provides security configurations covering critical aspects of the cloud infrastructure, such as encryption and key management.

The documentation lists five generally available (GA) data boundaries: France Data Boundary by S3NS, Germany Data Boundary by T-Systems, Italy Data Boundary by Polo Strategico Nazionale (PSN), Kingdom of Saudi Arabia Data Boundary Advanced by CNTXT, and Kingdom of Saudi Arabia Data Boundary Foundation by CNTXT.

In the Sovereign Cloud from Google security catalog, Sovereign Controls by Partners is listed as a complementary, partner-operated sovereignty control alongside Google Cloud Data Boundary and Google Cloud Dedicated.

Germany Data Boundary by T-Systems in detail

For folders in the Germany Data Boundary by T-Systems, documentation describes an organization policy constraint (gcp.resourceLocations) that allows new resources to be created only in the europe-west3 region. In addition, for a defined list of API services, including Compute Engine, Google Kubernetes Engine, BigQuery, Cloud SQL, Spanner, Cloud Storage and Pub/Sub, encryption with customer-managed encryption keys (CMEK) is mandatory, enforced through the gcp.restrictNonCmekServices organization policy constraint. The full product table lists 57 supported services with their API endpoints and any restrictions (as of September 20, 2026), including Compute Engine, GKE, Cloud SQL, AlloyDB for PostgreSQL, BigQuery, Cloud Storage, Cloud KMS, Cloud HSM, Cloud EKM, Secret Manager, IAM, Cloud Build, Artifact Registry, Cloud Run and Speech-to-Text. Services not listed in this table are considered unsupported by the documentation and are not recommended for Sovereign Controls customers without further due diligence.

Division of responsibility

Google documents a dedicated shared responsibility model for Sovereign Controls by Partners. Customers are responsible for, among other things, placing regulated or sensitive data in the appropriate Sovereign Controls folders, configuring IAM correctly, and organizing their org hierarchy so it doesn’t expose personal data. Google is responsible for, among other things, default encryption and infrastructure controls, enforcing the IAM policies customers set, and configuring and enforcing the chosen Sovereign Controls settings, including which Google employees can access customer data in the course of their business activities.

Google does not publish a dedicated pricing model on the overview page; check conditions with Google Cloud or the respective partner.

Core Features

  • Partner-operated data boundaries: Five GA data boundaries, operated by S3NS, T-Systems, PSN and CNTXT.
  • Region restriction via organization policy: For the Germany Data Boundary by T-Systems, resource creation is limited to europe-west3.
  • Mandatory CMEK: Encryption with customer-managed keys is required for a defined set of services.
  • Product-specific approval: A product table per data boundary defines which Google Cloud services are supported.
  • Dedicated shared responsibility model: Clear division of responsibility between Google, the partner and the customer.

Typical Use Cases

Regulated workloads with German data residency

A company with residency requirements for Germany uses the Germany Data Boundary by T-Systems to ensure resources are created only in europe-west3.

Evidencing customer-managed keys

For audits, evidence is provided that in-scope services such as BigQuery, Cloud SQL or Cloud Storage are encrypted exclusively with customer-managed keys.

Selecting approved services before project start

Before architecture planning, the product table is checked to determine which Google Cloud services are supported within the chosen data boundary.

Clarifying responsibilities in compliance projects

Security and compliance teams use the documented shared responsibility model to document customer and provider obligations for an audit.

Benefits

  • Local partner operation: Operated by established, nationally anchored partners such as T-Systems or S3NS.
  • Technically enforced region binding: Organization policies rather than mere declarations of intent.
  • Clear key control: Mandatory CMEK for in-scope services.
  • Transparent product coverage: Documented list of supported services per data boundary.
  • Complements existing sovereignty options: Positioned alongside Data Boundary and Dedicated within Sovereign Cloud from Google.

Integration with innFactory

As a certified Google Cloud partner, innFactory helps you assess Sovereign Controls by Partners for your requirements: checking which of your Google Cloud services are supported within the Germany Data Boundary by T-Systems, designing CMEK key management, and aligning organization policies for region and service restrictions. We describe the additional legal questions that apply to professionals bound by confidentiality obligations in our article on professional secrecy under section 203 of the German Criminal Code in the public cloud.

Contact us for a consultation on Sovereign Controls by Partners.

Typical Use Cases

Partner-operated data residency for regulated workloads
Meeting national sovereignty requirements with a local partner
Mandatory encryption with customer-managed encryption keys (CMEK)
Restricting resource creation to an approved region

Technical Specifications

Classification Complementary sovereignty offering in the Google Cloud security catalog, referenced from Sovereign Cloud from Google
Ga partners France Data Boundary by S3NS, Germany Data Boundary by T-Systems, Italy Data Boundary by Polo Strategico Nazionale (PSN), Kingdom of Saudi Arabia Data Boundary Advanced by CNTXT, Kingdom of Saudi Arabia Data Boundary Foundation by CNTXT
Germany encryption For a defined list of API services (including Compute Engine, GKE, BigQuery, Cloud SQL, Spanner, Cloud Storage, Pub/Sub), customer-managed encryption keys (CMEK) are mandatory
Germany product scope 57 supported Google Cloud products per the product table (as of September 20, 2026), including Compute Engine, Google Kubernetes Engine, Cloud SQL, AlloyDB for PostgreSQL, BigQuery, Cloud Storage, Spanner, Pub/Sub, Cloud KMS, Cloud HSM, Cloud EKM, Secret Manager, IAM, Cloud Build, Artifact Registry, Cloud Run and Speech-to-Text
Germany region gcp.resourceLocations for Germany Data Boundary by T-Systems folders is restricted to europe-west3
Operations Data boundaries are operated by the respective partners (per documentation: "operated by partners")
Shared responsibility Dedicated shared responsibility model: customers are responsible for classifying regulated data and configuring IAM, among other things; Google is responsible for default encryption, enforcing customer-set IAM policies, and the configured Sovereign Controls settings

Frequently Asked Questions

What is Sovereign Controls by Partners?

Per the official documentation, Sovereign Controls by Partners provides sovereignty controls for Google Cloud workloads that are operated by partners. It helps enforce data residency and provides security configurations covering critical aspects of the cloud infrastructure, such as encryption and key management.

Which partner data boundaries are generally available (GA) according to Google?

The documentation lists five GA data boundaries: France Data Boundary by S3NS, Germany Data Boundary by T-Systems, Italy Data Boundary by Polo Strategico Nazionale (PSN), Kingdom of Saudi Arabia Data Boundary Advanced by CNTXT, and Kingdom of Saudi Arabia Data Boundary Foundation by CNTXT.

What specifically applies to the Germany Data Boundary by T-Systems?

For folders in the Germany Data Boundary by T-Systems, documentation states that an organization policy constraint restricts resource creation to the europe-west3 region (gcp.resourceLocations). For a defined list of services, including Compute Engine, GKE, BigQuery, Cloud SQL, Spanner, Cloud Storage and Pub/Sub, encryption with customer-managed encryption keys (CMEK) is mandatory. The supported products and their API endpoints are listed in a dedicated product table; services not listed are considered unsupported.

How is responsibility divided between Google, the partner and the customer?

Google documents a dedicated shared responsibility model for Sovereign Controls by Partners. Customers are responsible for, among other things, placing regulated data in the appropriate Sovereign Controls folders, configuring IAM correctly, and organizing their org hierarchy so it doesn't expose personal data. Google is responsible for, among other things, default encryption, enforcing the IAM policies customers set, and configuring and enforcing the chosen Sovereign Controls settings.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.

Google Cloud Partner

innFactory is a certified Google Cloud Partner. We provide expert consulting, implementation, and managed services.

Google Cloud Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

STACKIT

STACKIT CSPM - Cloud Security Posture Management

STACKIT CSPM (Public Preview): assess cloud security posture with a compliance dashboard, BSI C5/ISO 27000 benchmarks, …

Pricing Pricing as published in the STACKIT …
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Key Management Service - Key Management

STACKIT KMS: centralized cryptographic key management from German data centers, BYOK, rotation, GDPR-compliant.

Pricing Consumption-based, billed per key …
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Secrets Manager - Secure Credential Management

STACKIT Secrets Manager: Secure management of API keys, passwords, certificates. Versioning, audit logs, GDPR compliant.

Pricing Hourly billing based on capacity tier …
SLA SLA as published by the provider
Compare →
AWS

AWS Continuum: AI-Driven Security Platform

AWS Continuum discovers, prioritises, validates, and remediates security risks across the software lifecycle, with …

Pricing No official pricing page published yet
SLA Per provider / see official documentation
Compare →
AWS

AWS European Sovereign Cloud: Sovereign AWS Partition in the EU

AWS European Sovereign Cloud: an independent AWS partition with its first Region in Brandenburg, generally available …

Pricing Billed per service used, see official …
SLA Per provider / see official documentation
Compare →
AWS

AWS Payment Cryptography - Managed Payment HSM

AWS Payment Cryptography provides payment cryptographic operations and key management as a managed service, without …

Pricing Per active key per month plus per API …
SLA As stated by the provider; see official documentation
Compare →

56 comparable products found across other clouds.

Ready to start with Sovereign Controls by Partners - Partner-Operated Sovereignty Controls?

Our certified Google Cloud experts help you with architecture, integration, and optimization.

Schedule Consultation