Industrial Data Hosted in France: Why It's Essential for NIS2 and the GDPR

· 12 min read
12 min read
Eziwan Team
IoT Infrastructure

The issue of the location of industrial data evolved from a technical debate into a major regulatory challenge in 2025–2026. With the gradual implementation of NIS2, new GDPR sanctions on transfers outside the EU, and growing awareness of the risks associated with the U.S. CLOUD Act, French industrial companies must know where their OT/IoT monitoring data is hosted.

This article explores why hosting in France has become a non-negotiable selection criterion for many manufacturers, and what that means in practical terms for your choice of IIoT solution.

What is "industrial data," and why does its location matter?

The industrial data generated by your IoT gateways, PLCs, sensors, and SCADA systems covers a wide range:

  • Process data: temperatures, pressures, flow rates, levels—the physical measurements of your production
  • Operational data: alarm statuses, machine events, maintenance logs
  • Network topology data: IP addresses, installation diagrams, equipment firmware versions
  • Access data: who logged in to which device, when, and from where

Taken together, these data points form a detailed map of your industrial infrastructure: its production capacity, vulnerabilities, and failure modes. If they fall into the wrong hands—competitors, hostile state actors, cybercriminals—the consequences could be severe.

So the question is not "Is my data sensitive?" but "Who has access to it, and under which jurisdiction?"


The Problem with the U.S. CLOUD Act

Since 2018, the Clarifying Lawful Overseas Use of Data Act (CLOUD Act) has required U.S. companies to provide U.S. federal authorities with the data they host—even if that data is physically stored in Europe.

In practical terms, this means that if you use AWS, Microsoft Azure, or Google Cloud, your business data can be accessed by the FBI or the NSA, even if your servers are located in Paris or Frankfurt, without you necessarily being notified, and without any effective legal recourse under European law.

When it comes to industrial data, this risk is particularly concerning:

  • Industrial espionage: Your production parameters, production rates, and formulations could be exploited by U.S. competitors
  • Critical infrastructure: For OIVs (Operators of Vital Importance), the disclosure of monitoring data could pose a national security risk
  • Economic intelligence: a plant’s actual production capacity, its suppliers, and its logistics flows—all of these may be of interest to state actors

Both the European Commission and ANSSI have recommended avoiding service providers subject to the CLOUD Act when handling sensitive data. NIS2 reinforces this recommendation by making it a de facto requirement for critical entities.


What NIS2 Says About Data Localization

NIS2 does not explicitly require that all data be hosted in France or the EU. However, several of its requirements indirectly lead to this:

1. Digital Supply Chain Management

Article 21 of NIS2 requires supply chain risk management, including cloud service providers. This involves a formal assessment of each cloud provider: Where is it domiciled? Under which jurisdiction can its data be seized? What security certifications do they hold?

For critical entities (CE)—which include many companies in the energy, water, transportation, healthcare, and digital infrastructure sectors—this assessment must be documented and defensible in the event of an ANSSI audit.

2. Incident Reporting and Availability of Evidence Data

NIS2 imposes very short notification deadlines: 24 hours for the initial alert, 72 hours for the incident report. To meet these deadlines, you must have immediate access to audit logs, connection logs, and monitoring data. If this data is hosted by a U.S. service provider subject to legal procedures, you may not be able to access it in a timely manner.

3. Business Continuity and Resilience

NIS2 requires a business continuity plan that includes the resilience of information systems. A cloud service provider whose operations could be compromised by a U.S. court order (such as an injunction or asset freeze) poses an unacceptable continuity risk for critical entities.

4. Penalties

For critical entities, NIS2 penalties can reach 10 million euros or 2% of global revenue. Senior executives are also held personally liable. In this context, choosing “cheap but risky” hosting is no longer economically rational.


The GDPR and Industrial Data

The GDPR applies to personal data—which may include business data if it can be used to identify a natural person. Typical examples include:

  • Remote access data: who logged in to which PLC (user ID)
  • Production logs: productivity data by operator/machine (if linked to an individual)
  • Maintenance data: who performed which maintenance task (named technician)
  • Alarms with assignment: which person acknowledged which alarm

For this data, the GDPR prohibits any transfer outside the European Economic Area without an adequate protection mechanism (Standard Contractual Clauses, Binding Corporate Rules, etc.). Since the Privacy Shield was invalidated in 2020 (Schrems II ruling), transfers to the United States have been particularly vulnerable from a legal standpoint.

Hosting in France eliminates any ambiguity: the data remains within the EEA, under GDPR jurisdiction, without the need to justify any data transfer mechanisms.


Certifications That Matter to French Industry

Not all French hosting providers are created equal. For a mission-critical industrial IoT infrastructure, look for these certifications:

ISO 27001

The gold standard for information security certification. Essential. Requires a documented Information Security Management System (ISMS) that is audited annually.

HDS (Health Data Host)

Mandatory for health data (pharmaceuticals, hospitals, medical devices). ANSSI/MiPih standards.

SecNumCloud

The ANSSI certification for trusted cloud services. The highest security level available for the French cloud. Recommended for OIVs and NIS2-essential entities. Current providers: OVHcloud, Outscale (Dassault Systèmes), Oodrive.

ANSSI-Certified CSP (Cloud Service Provider)

List of service providers certified for sensitive information systems.

Warning: Some service providers advertise "hosting in France" even though they are subsidiaries of U.S. companies subject to the CLOUD Act. Insist on a written confirmation that the service provider is not subject to any extraterritorial law that would allow access to your data without notification.


Real-world examples: Which manufacturers are affected?

Operators of Vital Importance (OVI)

The 12 OIV sectors in France (energy, water, transportation, food, finance, healthcare, etc.) have had specific cybersecurity obligations since the 2013 Military Programming Act (LPM). For these sectors, hosting monitoring data in certified French data centers is not an option—it is a contractual requirement of ANSSI.

Essential and Important Entities Under NIS2

With NIS2, the scope expands significantly:

  • All companies with 250 or more employees in the covered sectors
  • Critical defense contractors
  • Local water and energy network operators (even medium-sized ones)
  • Pharmaceutical and medical device companies

Industrial SMEs that export to sensitive customers

An SME that is a subcontractor for Airbus, Dassault Aviation, or a pharmaceutical company may be contractually required to host its data in a manner that complies with the client’s requirements. Major industrial groups are increasingly including these clauses in their supplier requests for proposals.


How to Evaluate Your Current IoT Solution

Here are 5 questions to ask your current or future IIoT provider:

1. Where is my data physically hosted? Ask for a specific data center address, not just “in Europe.” “Europe” hosting could mean Ireland (Amazon), the Netherlands (Microsoft), or Finland (Google)—all of which are subject to the CLOUD Act.

2. Is the parent company subject to the CLOUD Act? If your service provider is a subsidiary of a U.S. company, it is subject to the CLOUD Act regardless of where its servers are located.

3. What security certifications do you have? ISO 27001 at a minimum. SecNumCloud if you are an OIV or a NIS2-designated critical entity.

4. Have you signed a GDPR Data Processing Agreement (DPA)? This is required whenever personal data is processed (which is often the case with access logs).

5. Can you provide me with a recent penetration test report? Reputable service providers publish summaries of their penetration tests or share them under an NDA.


Eziwan's Position

The Eziwan platform is hosted exclusively in France by ISO 27001-certified service providers. We are a French company (an SAS under French law) and are not subject to any extraterritorial laws that would allow access to your data without your consent and without a French court order.

Our concrete commitments:

  • Data hosted in France: ISO 27001-certified data center located in France
  • Company incorporated under French law: no disclosure obligations under foreign law
  • GDPR DPA: GDPR-compliant data processing agreement available upon request
  • NIS2 audit log: All access to data and equipment is logged and available for ANSSI audits
  • End-to-end encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)

For NIS2 critical entities and OIVs, we can provide a comprehensive package that includes the security policy, certifications, and contractual SLAs tailored to regulatory requirements.


Conclusion: Industrial Digital Sovereignty Is No Longer Optional

By 2026, the question “Where is my industrial data stored?” had become just as important as “Is my equipment redundant?” or “Do I have a backup of my PLC configurations?”

The risks are real and well-documented:

  • Regulatory: NIS2 penalties of up to €10 million for critical entities
  • Legal: unlawful GDPR data transfers that could result in fines from the CNIL
  • Operational: data unavailability in the event of a dispute with a foreign service provider
  • Competitive: potential disclosure of production data to foreign entities

The good news is that high-performance, affordable sovereign hosting solutions are available in France. It’s no longer a matter of choosing between security and convenience—modern IIoT platforms hosted in France offer the same features as their U.S. counterparts, with the added assurance of digital sovereignty.

Checklist: Assessing the Sovereignty of Your Entire IoT Chain

The location of the data center is not enough: industrial data travels through an entire chain that must be evaluated link by link.

ComponentQuestion to AskPoint of Concern
SIM Card / CarrierWhere does mobile data pass through (APN)?A public APN routes data through the open Internet; a private APN keeps the data within the carrier’s network
Gateway / routerDoes the firmware and its telemetry data get sent to a third-party cloud?Some Asian manufacturers require the use of their own management cloud
TransportIs encryption end-to-end (VPN, TLS)?A tunnel terminating at an intermediary creates a point of interception
Cloud platformWho is the ultimate host, and which jurisdiction’s laws apply?A French interface on AWS remains subject to the CLOUD Act
BackupsWhere is the data replicated?Backups are sometimes stored in another jurisdiction
SupportFrom where do support teams access the data?Offshore support = de facto access from outside Europe

This end-to-end audit takes half a day and helps you avoid unpleasant surprises during a customer security questionnaire or a NIS2 audit.


FAQ — Industrial Data Hosting in France

Is all industrial IoT data subject to the GDPR?

The GDPR applies to personal data—typically location data linked to identifiable vehicles, access logs containing personal identifiers, or production data linked to identifiable operators. Purely process-related data (such as temperatures, pressures, and flow rates from an anonymized line) is not personal data. However, VPN access logs (including technicians’ identities) and geolocation data for mobile assets are indeed personal data subject to the GDPR.

Does the U.S. CLOUD Act apply to a cloud service provider based in Europe?

Yes, if that service provider is a subsidiary or a company subject to U.S. law (headquartered in the United States, listed on the NYSE or Nasdaq, or part of a U.S. corporate group). AWS Europe (Frankfurt), Azure Europe, and Google Cloud EU are all entities subject to the CLOUD Act through their U.S. parent companies. Only hosting providers governed exclusively by French or European law (OVHcloud, Scaleway, 3DS Outscale, Outscale) fall outside the scope of the CLOUD Act.

Does NIS2 explicitly require hosting in France or the EU?

NIS2 does not explicitly require a specific country of hosting, but mandates “appropriate technical and organizational measures,” including supply chain security and data protection. For OIVs (Operators of Vital Importance) governed by the LPM, the SGDSN often requires hosting on SecNumCloud-certified infrastructure—which effectively excludes non-European clouds for the most sensitive data.

What is the SecNumCloud certification, and who can obtain it?

SecNumCloud is ANSSI’s certification framework for “trusted” cloud service providers. Qualified providers must, among other things, guarantee immunity from non-European laws (no CLOUD Act), ensure that data is stored in France, and maintain audited security standards. As of the end of 2025, SecNumCloud-certified providers include OVHcloud, Outscale (3DS), and a few others.

Can a manufacturer require its end customer to host its data in France?

Yes, through contractual provisions (SLA, DPA—Data Processing Agreement). In industrial B2B contracts, particularly in regulated sectors (defense, energy, water), it is common to contractually require that data be hosted in France or the EU. Compliance with these clauses can be verified through annual audits.


Additional Resources