Compliance Compass: EU Regulations for Software, SaaS, and Cloud Hosting
Overview of the EU regulatory landscape for software and cloud hosting
Blog
Cloud-Native Insights & Expertise
Discover our latest articles about cloud-native technologies, Kubernetes, DevOps, and modern software development. From practical tutorials to in-depth analyses.
Latest Blog Posts
Stay up to date with our latest articles about cloud-native technologies, Kubernetes, and DevOps.
1210 posts
Overview of the EU regulatory landscape for software and cloud hosting
Cloudflare is far more than just a CDN provider. In addition to performance optimization and security features, the platform offers numerous tools that can be creatively used to address individual requirements in modern infrastructure setups—without necessarily relying on the paid Enterprise features.
With the **Digital Networks Act (DNA)**, the EU is preparing one of the most profound reforms of its telecommunications sector. The aim is to overcome regulatory fragmentation, accelerate investments in future-proof network infrastructures, and strengthen Europe's digital competitiveness on a global scale.
On September 24, 2025, SAP and OpenAI announced a new partnership: *OpenAI for Germany*. The goal is to bring artificial intelligence "made for Germany" to the public sector – responsibly, legally compliant, and sovereign. The project is supported by SAP and operated through their subsidiary Delos Cloud – based on Microsoft Azure technology.
The Reuters report is making waves: Nvidia plans to invest up to $100 billion in OpenAI. A move that impresses not only by its sheer scale but also by the structure of the deal. Nvidia aims not only to provide capital but also to supply the necessary hardware—thus securing the foundation for OpenAI's future data centers.
Hyperscalers have shaped the digital world like few other models. With the promise of unlimited scaling, global availability, and seemingly endless innovation, they have dominated an entire generation of IT strategies. However, upon closer inspection, little remains of this narrative: The business model of hyperscalers is still almost exclusively based on the sale of hardware—compute, storage, network traffic. Nicely packaged, globally distributed, encapsulated in APIs, but at its core, it's still the same logic: You rent machines.
When discussing digital sovereignty and modern IT infrastructures today, Kubernetes is unavoidable. In just a few years, this open-source project has evolved from a container orchestrator to a de facto standard, comparable in significance to the Linux kernel. To understand why, one must examine its architecture and take the parallels seriously.
Cloud-native software development is more than just a set of methods. It describes a paradigm that designs applications to function reliably in highly dynamic infrastructures—environments where servers, databases, and networks no longer exist statically but can be provisioned and removed via API.
On September 18, *golem.de* reported a security vulnerability in **Microsoft Entra ID**, discovered by security researcher Dirk-Jan Mollema, who described it as "probably the most significant Entra ID security vulnerability" of his career. Registered as **CVE-2025-55241** and rated as critical with a **CVSS score of 9.0**, the case exemplifies how vulnerable central identity and access platforms can be.
The news is making waves: Several npm packages from CrowdStrike – a company known for security and protection – have been compromised. What might seem like a footnote is actually a massive wake-up call for the entire software industry. This is a continuation of the **"Shai-Halud" campaign**, which had already been noted during the **Tinycolor attack**.
In recent years, *Cloud First* has been considered an almost unshakeable maxim. Companies of all sizes were encouraged to move their infrastructure to the public cloud as quickly as possible to ensure scalability, innovation, and competitiveness. For many, this sounded like a simple formula: the more cloud, the better. However, it has become apparent that this approach does not always deliver the promised solution—in fact, it raises new questions that are increasingly being critically discussed.
The European Union is on the verge of enacting one of the most profound intrusions into digital privacy since the inception of the internet. The draft law for the so-called "Chat Control," officially the "Regulation to Prevent and Combat Child Sexual Abuse," initially appears to be a necessary protective measure. However, in reality, it is a proposal that not only undermines encrypted communication but also questions the fundamental rights of hundreds of millions of EU citizens.
Since September 8th, concrete evidence has emerged that a number of extremely widespread NPM packages — including *debug*, *chalk*, *ansi-styles*, *supports-color*, and other core components of the Node.js ecosystem — have been compromised. According to public accounts, the maintainer was tricked via phishing into a fake NPM support domain, leading to the release of new, tampered versions that, in total, are downloaded billions of times weekly across the entire set, potentially infiltrating virtually every modern frontend, backend, and CI/CD pipeline.
At the end of July 2025, Meta released its latest quarterly figures – alongside strong revenues (22% growth to $47.52 billion, profit increase of 36% to $18.34 billion), Mark Zuckerberg primarily delivered one message: "Superintelligence" is within reach. Meta aims to "create a personal superintelligence for all people in the world."
The security of software supply chains is one of the central topics in IT security today. Companies are under increasing pressure to ensure transparency, traceability, and reliability of the software they use. A key tool in this regard is the **Software Bill of Materials (SBOM)**, complemented by automated scanning for known vulnerabilities – **Common Vulnerabilities and Exposures (CVE)**.
Storage in Kubernetes is by no means trivial. Stateful workloads impose the highest demands on stability, performance, and availability—handling persistent data is thus one of the most complex tasks in the Cloud-Native environment. This article provides a comprehensive overview: from CSI, Cloud vs. On-Premise CSI, Longhorn, Ceph, and another solution, to Cloud-Controller-Manager, costs, scaling, redundancy, security, and the challenges of local storage landscapes.
The security of the software supply chain is one of the central topics in modern software development. With every new dependency, external artifact, and library used, the attack surface grows – and so does the responsibility of developers to secure this chain against manipulations and accidental errors. GitHub has now introduced a feature called **Immutable Releases**, which marks a significant step in this direction: once published, releases can no longer be altered.
Kubernetes has become the de facto standard for operating cloud-native applications. However, with its flexibility comes immense complexity. In highly regulated environments—such as finance, healthcare, or public administration—secure use of Kubernetes is only possible when **policies** strictly control the behavior of clusters, workloads, and users. Without such mechanisms, there is a risk of compliance violations, security gaps, and uncontrolled deviations from internal standards.
Internal Developer Platforms (IDPs) have been a hot topic in software development for several years. Companies face the challenge of managing complex cloud-native landscapes with microservices, APIs, Kubernetes clusters, and a multitude of tools. Developer teams lose time due to context switching, incomplete documentation, and fragmented toolchains. This is where [Spotify Backstage](https://backstage.io) comes in – an open-source platform for developer portals, released by [Spotify](https://engineering.atspotify.com) in 2020 and now part of the [Cloud Native Computing Foundation (CNCF)](https://www.cncf.io).
The debate about sovereignty in the cloud in Europe often revolves around the question: *Do we need our own hyperscalers to be independent?* Many see the solution in a "European cloud" that should replace AWS, Azure, or Google Cloud. But the reality is much more complex—and in many ways, more pragmatic. Most services offered by hyperscalers are based on well-known open-source projects. The difference lies in branding, integration, and pricing. Those truly seeking sovereignty don't necessarily need to build a new hyperscaler. The real alternative is closer: Kubernetes as a foundation and open tools instead of proprietary "cloud services."
The European debate on "sovereign AI" is often reduced to regulation, data protection, and societal acceptance. What is often overlooked: Sovereignty in Artificial Intelligence is not only determined by algorithms or models but crucially by the supply chain of the underlying hardware. Without chips, without GPUs, without the necessary infrastructure, any vision of European AI sovereignty is nothing more than an academic exercise. In this post, I aim to highlight the real bottlenecks blocking Europe on this path and simultaneously identify the remaining opportunities for action. This will not be a romantic plea for autarky, but a sober analysis of dependencies, market mechanisms, and industrial policy options.
Kubernetes continues to grow – with version 1.34, the next major release is here. The cycle includes 58 new features: 23 are stable, 22 are Beta, and 13 are newly Alpha. Numbers alone don't say much. What's interesting is how Kubernetes is developing technically – and where it's headed.
Operating databases in Kubernetes was long considered risky: Stateful workloads, persistent data, and container orchestration seemed incompatible. Today, the situation is different. Specialized operators, optimized storage solutions, and proven practices have made relational and document-based databases stable building blocks for cloud-native architectures.
Kubernetes has become the standard for running containerized applications in recent years. As its adoption grows, so does the need to monitor clusters and applications transparently, traceably, and efficiently. **Observability** – the ability to reconstruct the state of a system from external signals such as logs, metrics, and traces – is a central concept for this purpose.