Legal Uncertainty
A constant conflict between U.S. security solutions and the strict regulatory requirements of the GDPR—access by authorities in third countries must be ruled out, but standing still is not a solution.
For many, preparing critical infrastructure for highly complex attacks using the world’s best security technologies while simultaneously guaranteeing European sovereignty requirements without compromise is a paradox. This necessary balancing act—global innovation on one hand and national legal certainty on the other—often leads to a strategic dilemma, as conventional cloud solutions usually cannot meet all requirements at the same time.
A constant conflict between U.S. security solutions and the strict regulatory requirements of the GDPR—access by authorities in third countries must be ruled out, but standing still is not a solution.
The digital infrastructure and data flows of critical sectors must not be subject to the interests or access of third countries outside the EU.
Modern cyberattacks are becoming increasingly complex, faster, and more automated due to the use of artificial intelligence. The use of public AI tools provides an additional entry point for cybercriminals. Traditional security architectures no longer offer sufficient protection against this.

Unlike traditional VPNs, which are often slow and connect users to the entire corporate network, your employees only use specific applications, such as an internal HR tool. This speeds up work and minimizes the risk of lateral movement in the event of a compromise.
Zscaler on STACKIT meets the strictest national and international compliance and security standards. Its unique selling point is the seamless operation provided by STACKIT, which—through BSI C5 certification—demonstrates the highest level of cloud security, verified by the German Federal Office for Information Security (BSI). This combination of market-leading cloud security and European infrastructure offers you fully verified protection:
“Zscaler on STACKIT” is a joint service offering that combines Zscaler’s market-leading Zero Trust Exchange platform with STACKIT’s European sovereign cloud infrastructure. The solution is specifically tailored to the requirements of highly regulated industries and the public sector.
Sovereignty and Zero Trust united—for a secure, independent digital future for Europe.
The initial scope includes the core “Zscaler for Users” services:
Market-leading SASE/Zero Trust security, paired with 100% digital sovereignty, top performance through local data centers, and guaranteed GDPR compliance.
The key features are:
The joint offering provides the following features:
Operational sovereignty:
Objective:
The solution is particularly suitable for European companies, KRITIS operators, the public sector, and highly regulated industries that are subject to the strictest requirements for sovereignty, resilience, and the protection of classified data, and that do not want to compromise between data protection and cybersecurity.
The platform is operated on the STACKIT cloud infrastructure of the Schwarz Group, a German company with data centers in Germany and Austria. Operations are carried out by European staff under European jurisdiction. Access by authorities from third countries (e.g., via the U.S. CLOUD Act) is prevented by the architecture and operating model.
The service includes end-to-end managed operations: platform operation, patching, monitoring, 24/7 support, and incident response by European staff. Escalation procedures and SLAs are clearly defined in the contract.
Where is my data processed with “Zscaler on STACKIT”?
Exclusively in STACKIT’s highly secure data centers (e.g., in Germany and Austria), operated by the Schwarz Group.
Sovereignty is guaranteed on four levels:
Through inline DLP, TLS inspection, encryption in transit and at rest, and granular policy controls. Logs and metadata remain entirely within the EU. Optional Bring-Your-Own-Key (BYOK) and Hold-Your-Own-Key (HYOK) models are available.
Zero Trust at Zscaler means that the platform does not automatically trust any user or device. Instead of granting users blanket access to the entire corporate network, Zscaler verifies every single request in real time and connects users exclusively to the exact application they need. The rest of the network remains invisible and protected from potential attackers. This consistent approach eliminates the digital attack surface, proactively prevents threats, and secures sensitive data highly effectively.