Skip to content
HexaTransfer
Back to blog
GDPR & Compliance

French Digital Sovereignty and Secure File Hosting

Explore French digital sovereignty requirements for file hosting, including SecNumCloud certification, local data storage, and compliance with French law.

French digital sovereignty requirements for file hosting center on three things: where the data physically lives, who can legally access it, and whether the provider can be compelled by foreign law to hand it over. In 2026, public sector and regulated buyers increasingly demand SecNumCloud qualification from ANSSI, storage on French or EU soil under French-law providers, and immunity from extraterritorial laws like the US CLOUD Act. The doctrine "Cloud au centre" formalized by the Prime Minister's circular of May 2021 and strengthened since makes this a procurement requirement, not just a preference.

Why Sovereignty Matters for File Transfer

A French hospital sending patient imaging through a US-headquartered file transfer service creates three problems. First, the US CLOUD Act (2018) lets US law enforcement compel the provider to produce customer data regardless of where it's stored. Second, Section 702 of FISA covers non-US persons' communications in ways that have repeatedly triggered Schrems rulings from the CJEU. Third, Article 3 of the French Military Programming Law and the recent Cybersecurity Law expect sensitive sectors to use providers immune from such compulsion. File transfer data isn't usually "secret defense," but patient records, legal strategy, and R&D documents often fall under sector-specific protections that line up with sovereignty requirements.

SecNumCloud: What Qualification Means

SecNumCloud is ANSSI's cloud qualification. It tests both technical security and legal independence. The 2022 v3.2 referential, updated to v3.2bis with clarifications in 2023-2024, added explicit immunity criteria: the provider's capital, its contracts, and its decision-making must be structured so non-European law cannot compel data disclosure. In practice, majority European ownership, European-law contracting entities, and European operational control. Qualified providers as of 2026 include OVHcloud (Hosted Private Cloud), Outscale, Worldline, Bleu (the Microsoft-Orange-Capgemini joint venture for sovereign Azure), and S3NS (Thales-Google Cloud). The list is short because the bar is high.

Hosting French Health Data: HDS Certification

Separate from SecNumCloud, health data hosting in France requires HDS certification (Hébergeur de Données de Santé) under Article L1111-8 of the Public Health Code. HDS has two scopes, infrastructure hosting and outsourced hosting, and is audited against a reference framework aligned with ISO 27001 and sector-specific controls. Any file transfer service used by French hospitals, clinics, or medical labs handling PHI must be HDS-certified or sit behind an HDS-certified platform. The list of certified hosts is public on the ESanté website. Non-HDS hosting of French health data is a contractual and regulatory violation even if the data is encrypted.

French Law on Data Retention and Law Enforcement Access

French law enforcement can access hosted files under the Code of Criminal Procedure's digital investigation articles, requiring a judicial order in most cases and a légitime procedural basis. For intelligence services, Loi du 24 juillet 2015 on renseignement allows specific interception with prior authorization. Neither regime resembles the US National Security Letter or FISA 702 secret process. French sovereignty-focused hosting means your data still can be accessed by French authorities under French law with French judicial review, which many French regulated buyers prefer to foreign disclosure regimes they don't control.

EU-Centered Alternatives and Gaia-X

Beyond purely French providers, the broader European cloud ecosystem offers sovereignty through the Gaia-X framework, which defines federated data and service criteria, including provider localization and contractual terms. Gaia-X labels at different levels indicate compliance depth. Providers like OVHcloud, Scaleway, IONOS, Hetzner, and T-Systems participate. For file transfer, the practical question is whether the vendor's infrastructure, from storage backend to CDN to observability, sits under European-law providers or whether bits of the stack leak into the US sphere. A transfer service on AWS Paris with US-parent company management does not meet SecNumCloud sovereignty criteria.

Extraterritoriality and the CLOUD Act in Practice

The US CLOUD Act authorizes the US government to request stored data from US-based service providers irrespective of where the data resides. In 2023 and 2024, several high-profile French procurement decisions explicitly excluded US-parented clouds even when those clouds offered EU-only regions. The legal reasoning: encryption at rest doesn't block disclosure if the provider controls the keys. A sovereignty-grade file transfer service holds keys exclusively under European entities, or better, uses end-to-end encryption so the provider has no plaintext to disclose even under compulsion.

Procurement Language That Enforces Sovereignty

French public buyers increasingly write sovereignty into RFPs with specific clauses. Typical wording: the provider must be qualified SecNumCloud, data must remain within the French or EU territory, the operator and its sub-processors must be governed by EU law, and no access by non-EU authorities under foreign law may occur. Enforceable penalties attach to breaches. Private companies in regulated sectors (banking, insurance, defense) are adopting similar templates. Even outside regulated sectors, the 2023 French Intelligence Act and 2024 industrial strategy announcements have made sovereignty a board-level topic.

Implications for File Transfer Choices

For French entities handling sensitive data, the decision tree in 2026 is: Is the data subject to sector-specific rules (health, defense, public administration)? Pick SecNumCloud-qualified or HDS-certified. Is the data sensitive but unregulated? Pick an EU-law, EU-hosted provider with strong contractual commitments. Is the data low-sensitivity? Standard GDPR-compliant EU-hosted tools work. In all cases, encryption posture matters: client-side, end-to-end encryption neutralizes many disclosure risks because the provider literally cannot read the file. Tools that rely on provider-side encryption offer less sovereignty even if they run on French infrastructure.

HexaTransfer encrypts files in the browser with AES-256-GCM before upload, so the ciphertext sitting on EU infrastructure isn't readable by the service or any party lacking the link fragment. Try it at hexatransfer.com — free, no account, 10 GB max.

French digital sovereignty isn't isolationism. It's a set of concrete legal and technical controls that make data disclosure governable under French or European law. For file hosting, the right stack combines a qualified provider for regulated workloads, client-side encryption for everything else, and contracts that name French or EU jurisdiction. Anything short of that leaves a gap that a determined foreign authority can walk through.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file