On March 5, 2026, cybersecurity leader CrowdStrike and Schwarz Digits, the IT and digital arm of the Schwarz Group (parent company of Lidl and Kaufland), announced a strategic partnership. This collaboration will bring CrowdStrike's AI-native Falcon platform to STACKIT, the sovereign cloud infrastructure developed and operated by Schwarz Digits. The joint offering is designed to meet the increasing demand from European organizations, particularly in the public sector and regulated industries, for powerful cybersecurity solutions that comply with strict data sovereignty regulations like GDPR and ensure sensitive data remains within Europe.
The partnership directly addresses the growing market for sovereign cloud solutions in Europe. Driven by regulations such as the General Data Protection Regulation (GDPR) and initiatives like GAIA-X, many European organizations are mandated to ensure their data is stored and processed within the European Union's legal and geographical boundaries, protected from access by foreign governments. By hosting the Falcon platform within STACKIT's German-based data centers, the offering provides customers with a security solution that is inherently compliant with these data residency and sovereignty requirements. This allows organizations to leverage CrowdStrike's advanced threat detection capabilities without compromising their data governance and compliance posture.
This offering is primarily targeted at:
For organizations adopting this solution, the key compliance benefit is the assurance of data sovereignty. The platform ensures that all security telemetry, analysis, and incident data collected by the CrowdStrike Falcon platform remains within STACKIT's EU-based cloud. This helps customers meet their obligations under GDPR and other national data protection laws. It simplifies compliance audits and provides legal certainty that data is not subject to foreign legal frameworks that may conflict with EU privacy standards.
This partnership has several significant market impacts:
European organizations evaluating their cloud and security strategy should consider the following:
Utilizing a sovereign cloud is a form of logical and legal segmentation, isolating data within a specific jurisdiction.
Mapped D3FEND Techniques:
Sovereign clouds provide assurance over the physical and logical location of data, which is a control that complements encryption.
Mapped D3FEND Techniques:
The partnership between CrowdStrike and Schwarz Digits to create a sovereign security platform is a strategic implementation of isolation at a macro level. For European organizations, this provides a form of jurisdictional isolation, ensuring that their sensitive security telemetry and data are processed and stored exclusively within the EU, on the STACKIT cloud. This directly addresses data sovereignty requirements under GDPR. By adopting this solution, companies are effectively isolating their security data from non-EU legal frameworks and potential foreign government access. This is a critical control for public sector, CNI, and other regulated entities that cannot have their data leave the EU. It's a proactive measure to harden their compliance posture and reduce legal and regulatory risk associated with cross-border data flows.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats