A row of grey archive folders, one single teal folder pulled out

Cloud storage in public authorities: why projects fail and what helps

Written By Alexander Burba
October 7, 2026

Most cloud projects in public authorities do not fail on technology but on the way there: requirements that only emerge during procurement, a data protection review at the end instead of the start, and day-to-day work that has long run on email attachments. This guide describes the five typical points of failure, the legal framework from the GDPR to the BSI minimum standard, and a six-step introduction path.

The need is high and the starting point low. In a survey of 57 German authorities and public IT service providers, 80 percent give cloud transformation high priority, yet 70 percent run at most a fifth of their applications in the cloud. 77 percent name data protection and European legal standards as the biggest hurdle (Lünendonk study "Cloud transformation in the public sector", 30 April 2025, produced with consulting and IT service partners).

Five points where cloud projects in public authorities fail

The project is often treated as an IT purchase, although it changes how people work. Failed projects almost always stall at one of these five points.

  1. Requirements only emerge during procurement. Tender without a requirements profile and you get offers that cannot be compared, and in the end you decide on price.
  2. Data protection reviews at the end. If the data protection officers only see the finished shortlist, every no stops the project. At the start it would have been a selection criterion.
  3. Co-determination comes too late. Cloud storage with audit logging can make staff behaviour and performance visible. For such technical systems the staff council (Personalrat) has a right of co-determination, in the federal administration under Section 80 (1) No. 21 of the Federal Staff Representation Act (BPersVG), in states and municipalities under state law. If it is only involved before rollout, the negotiation starts again.
  4. The current state is underestimated. As long as there is no secure route, confidential documents leave the building as email attachments. That route does not disappear with a new tool, only with a rule that replaces it. Which duties this breaches is covered in our article Confidential files by email: who is liable, and for what.
  5. The pilot runs without real cases. A test with sample files proves nothing. Only real cases show whether permissions, workflows and logs hold up in daily work.

Strategy, sovereignty and NIS2 raise the pressure on every administration

The conditions have shifted noticeably in the last two years. Three developments affect every cloud project in German public administration.

  • A shared target architecture. With the German Administrative Cloud Strategy (Deutsche Verwaltungscloud-Strategie), the IT Planning Council of federal and state governments has set a common architecture since 2021. It adopted the current version 3.0 on 26 March 2025, together with a maturity model (Decision 2025/15). On 18 March 2026 the key points for the Deutschland-Stack followed, whose standards are binding for federal, state and municipal administration.
  • Sovereignty is being implemented. On 2 October 2025, the state of Schleswig-Holstein completed the move of its administration's email, more than 40,000 mailboxes, to open-source software (State government of Schleswig-Holstein, 6 October 2025). In the Lünendonk survey, 83 percent of participants are looking at sovereign cloud.
  • NIS2 applies to the federal level too. Germany's NIS2 implementation act has been in force since 6 December 2025. Federal administration bodies are treated like particularly important entities (Section 29 BSIG, the BSI Act), management is responsible for information security (Section 43 BSIG) and must comply with IT-Grundschutz and the BSI minimum standards (Section 44 BSIG).

Collaboration multiplies access, while the obligations stay the same

Working together in cloud storage means more access, more recipients and more changes. Four points decide whether it stays compliant with data protection law.

  • Data processing agreement. Under Art. 28 of the GDPR, the authority needs a data processing agreement with the provider, including a traceable list of sub-processors. If the provider belongs to a group outside the EU, foreign law can demand access to data regardless of where the servers are. That question belongs in the risk assessment before the choice is made.
  • Technical and organisational measures. Art. 32 GDPR requires safeguards that are appropriate to the risk and documented. For administrative data that means encryption, access control and a log that makes access traceable.
  • Permissions per person instead of all or nothing. Sharing with "everyone in the folder" is not access control. Storage only becomes compliant when permissions can be set per person, per case and with an expiry date.
  • Records management. If federal authorities keep electronic files, they must secure the principles of proper records management through technical and organisational measures according to the state of the art (Section 6a of the E-Government Act, EGovG). Who changed, shared or deleted what, and when? Without an audit-proof log, even the most convenient storage is unsuitable for an administration. The email attachment meets none of these four points: once sent, there is neither control nor a log.

Sanctions work differently for authorities. Data protection supervisors impose no fines on federal authorities and other federal public bodies (Section 43 (3) of the Federal Data Protection Act, BDSG). The states regulate this in their own data protection acts and mostly allow fines only against public bodies that compete as businesses, for example Bavaria in Art. 22 BayDSG, North Rhine-Westphalia in Section 32 DSG NRW and Baden-Württemberg in Section 28 LDSG. The obligations still apply: supervisors can issue orders and ban processing (Art. 58 GDPR), and data subjects can claim damages (Art. 82 GDPR).

The BSI minimum standard requires C5 criteria and continuous evidence

For federal authorities, the BSI minimum standard for the use of external cloud services (version 2.1, legal basis now Section 44 BSIG) is binding; states and municipalities often use it as guidance. BSI is Germany's Federal Office for Information Security. Three requirements shape the selection:

  • C5 basic criteria as a requirement. In its security policy for cloud services, the authority must set at least the basic criteria of the BSI C5 catalogue as requirements.
  • Regular evidence. The provider must prove compliance regularly and without gaps over the whole period of use. The standard names a current C5 type 2 report as the way to provide it.
  • Right to audit. If a provider cannot present a C5 report, the authority must secure the right to commission a C5 audit by a third party itself.

The catalogue itself keeps evolving. Since the end of March 2026 the new version C5:2026 has been available, with criteria on post-quantum cryptography, supply chains and technical sovereignty, among others. On 27 April 2026 the BSI also published the C3A criteria on the sovereignty of cloud services. They are not binding and build on the C5 criteria.

The GDPR, BSI C5 and IT-Grundschutz set the framework

Framework Source What it means for the introduction
Data processing, technical and organisational measures GDPR Art. 28, 32 Agreement before the start, documented measures
Cloud security criteria BSI C5 criteria catalogue A verifiable benchmark for a cloud provider's security
Cloud use in the federal administration BSI minimum standard for external cloud services, Section 44 BSIG C5 basic criteria as a requirement, evidence without gaps
Information security BSIG Sections 29, 43, 44 (NIS2 implementation) Management responsibility, IT-Grundschutz, minimum standards
Co-determination Section 80 (1) No. 21 BPersVG, state staff representation acts Involve the staff council before the selection
Electronic records Section 6a EGovG Audit-proof log in cloud storage too
Digital public services Online Access Act (OZG), amendment in force since 24 July 2024 Digital services need secure document routes behind them
Procurement EVB-IT Cloud (IT Planning Council, Decision 2022/01) Standard contract with criteria catalogue; the requirements profile belongs in the service specification

How SecureCloud meets these requirements is shown on Cloud for government and the public sector and Certificates and attestations.

Six steps from the current state to regular operation

  1. Map the exchange routes. For two weeks, record which documents leave the building, to whom and by which route. A simple tally per department is enough. The result is almost always sobering and at the same time the best justification for the project.
  2. Requirements profile before procurement. The table above becomes the knock-out criteria: where the data is stored, data processing agreement with a list of sub-processors, C5 attestation with a current audit period, permissions per person, audit-proof log, deletion periods. The authority decides what is mandatory now, not the provider later.
  3. Data protection, information security and staff council from step one. All three receive the requirements profile for sign-off before a provider list exists. A data protection impact assessment, if needed, starts here, not after the award. That costs two weeks at the start and saves months at the end.
  4. Procurement with a test phase. EVB-IT Cloud, with its standard contract and criteria catalogue, sets the framework. The service specification should include a test phase with real users from the department and the obligation to keep evidence such as the C5 attestation current for the whole term.
  5. Pilot with real cases. One department, one quarter, real and suitable cases, and a success measure defined in advance: how many documents went through the secure route instead of as attachments, and how many external recipients used it without help?
  6. Regular operation with a replacement rule. Training, clear ownership and the one rule that carries everything: confidential documents only leave the building as a controlled share, for example through secure data exchange, no longer as attachments. After 90 days, measure rather than assume.

Administrations recognise a suitable provider by verifiable evidence

Assurances are not enough. What can be verified: a named storage location, a data processing agreement with a list of sub-processors, a BSI C5 attestation with a current audit period, an ISO/IEC 27001 certification, permissions per person and case, an audit-proof log, and the option to check all of this yourself before deciding. It also helps to ask who owns the provider and which law its parent company is subject to.

SecureCloud processes all data exclusively in German data centres, is ISO/IEC 27001 certified (TÜV Rheinland), BSI C5 attested and GDPR compliant. Secure cloud storage, encrypted shares and Office editing in the browser run on the same permission model: file and folder permissions and shares with an expiry date in every plan, the audit log with export from the Advanced plan. Which evidence SecureCloud provides for NIS2, DORA and KRITIS requirements is shown in the compliance overview. For a structured switch, there is the white paper Sovereign in 30 days.

If you want to check SecureCloud against your requirements profile, the best way is to test it yourself: try SecureCloud.

This article gives a general overview and does not replace legal advice in individual cases. As of October 2026.

Frequently asked questions

Why do many public authorities fail to introduce secure cloud storage?

Usually on the way, not the technology: requirements emerge only in procurement, data protection reviews at the end, the staff council comes in too late, and daily work keeps running on email attachments.

How do administrations best introduce secure cloud storage?

In six steps: map the current state, requirements profile before procurement, involve data protection and the staff council early, procurement with a test phase, pilot with real cases, regular operation with a replacement rule.

Is a BSI C5 attestation mandatory for public authorities in Germany?

Federal authorities must set the C5 basic criteria as a requirement under the BSI minimum standard and obtain evidence without gaps, typically a C5 type 2 report. SecureCloud is BSI C5 attested.

Can data protection authorities fine public authorities in Germany?

Not federal public bodies (Section 43 (3) BDSG). The states mostly allow fines only against bodies that compete as businesses. Bans on processing and damages remain possible.

Does the staff council have to be involved when introducing cloud storage?

Yes, if the system can monitor staff behaviour or performance, for example through logs. In the federal administration this follows from Section 80 (1) No. 21 BPersVG, in the states from state law.

Does SecureCloud meet the requirements of public authorities?

Data is stored exclusively in German data centres; SecureCloud is ISO/IEC 27001 certified (TÜV Rheinland), BSI C5 attested and GDPR compliant. DPA and permissions always, audit log from Advanced.

Interessiert Sie die souveräne Cloud?

Unsere Experten erklären Ihnen gerne mehr.

Picture of Alexander Burba

Alexander Burba

Alexander Burba is Marketing Manager at SecureCloud and is responsible for brand awareness and positioning online. He follows the German market for secure cloud infrastructure and the regulatory shifts reshaping it, from NIS2 and DORA to the sovereignty requirements now placed on the public sector. In his articles he translates those shifts into the requirements that actually apply in regulated industries, and into the decision that comes next.

Related Articles

Cloud Security

it-sa 2026: Worth the visit, and what SecureCloud is showing

27 to 29 October in Nuremberg: why it-sa 2026 is worth attending, which topics matter and what SecureCloud is showing in Hall 7A, with...

Cloud Security

Confidential files by email: who is liable, and for what

Law firms, hospitals, banks and public authorities: which rules apply when confidential files travel by email, what the sanctions are,...