Compliance and data sovereignty for the public sector.
Institutional email hosted in Europe, demonstrable GDPR compliance and communications with legal validity, with EU invoicing and a team based in Europe.
- European hosting
- GDPR compliance
- EU invoicing


Requirements met
What a public body needs to guarantee.
Four common tender specification requirements, met from the outset.
European hosting
Citizen and employee data on servers located in Europe, under exclusively European jurisdiction.
GDPR compliance
Full traceability and compliance documentation to respond to audits and data subject requests.
EU invoicing
Portuguese entity, Portuguese VAT number, invoicing in euros. No non-European intermediaries in the procurement process.
Registered Email
Official notifications and communications with legal validity equivalent to registered mail with acknowledgement of receipt.
Digital sovereignty
Citizens' data should not depend on transatlantic agreements.
EU-US data transfer frameworks have already collapsed twice and face a new challenge. For a public body, the simplest answer is structural: data in Europe, exclusively European jurisdiction, no transfers.
The European context
Our peers are already reducing their dependence. Portugal is only starting now.
France, Italy, Germany and the Netherlands have taken concrete steps in recent years. In Portugal, the national plan has been approved, but implementation is years away. Organisations do not have to wait for it to protect their email.
France
Since 2021, the "Cloud au centre" doctrine has reserved state systems holding sensitive data for qualified clouds (SecNumCloud) that are immune to non-European laws. This halted the migration of ministries to American cloud suites, including email.
Italy
Italy's Cloud Strategy (Strategia Cloud Italia) classifies public data (ordinary, critical, strategic) and created the Polo Strategico Nazionale: critical and strategic data live on qualified infrastructure under national control, with hundreds of administrations already on board.
Germany
In 2025, the state of Schleswig-Holstein migrated the email of its entire administration (more than 40,000 mailboxes) from Exchange/Outlook to open solutions, and the federal government is developing openDesk, a sovereign workplace for public administration.
The Netherlands
In 2025, Parliament passed a series of motions to halt unnecessary migrations of government IT to American cloud providers, require exit strategies and launch a sovereign state cloud.
What about Portugal?
The plan exists. Implementation will take years. Email does not need to wait.
Portugal has approved the National Sovereign Cloud Plan, with data classification planned by 2027 and infrastructure by 2030. It is official recognition that current dependence is a risk. But no organisation needs to wait until the end of the decade to protect its most critical communication: institutional email can move now to Portuguese infrastructure, subject exclusively to Portuguese and European law, with assisted migration and no service interruption.
Institutional trust
Public bodies that already trust Sooma.
The Municipality of Murtosa entrusts its email to Sooma. In domain management, the list includes the Municipalities of Almada and Coimbra and the Instituto de Informática, I.P. And the Portuguese Bar Association (Ordem dos Advogados), a public-interest institution with thousands of users, manages its mailboxes on our infrastructure.
Paperless
Administrative notifications with legal validity, without paper.
Meeting notices, notifications and official communications with proof of sending and receipt equivalent to registered mail (eIDAS + Decree-Law 12/2021). Instant, and at a fraction of the cost of paper.
Frequently asked questions
Before signing up
What public bodies ask first.
Can our organisation's emails be accessed by authorities in other countries?
If they are hosted with providers subject to the laws of third countries, yes: legislation such as FISA Section 702 and the CLOUD Act allows US authorities to demand data from American providers, even when the servers are in Europe and without the knowledge of the organisation concerned. At Sooma, data is subject exclusively to Portuguese and European law: any access is only possible under Portuguese law, with judicial oversight.
And matters subject to confidentiality: disciplinary proceedings, health data, non-public information?
This is where the risk weighs most. When communications live outside European jurisdiction, the duty of confidentiality no longer depends solely on the organisation: it comes to depend on decisions by foreign authorities, taken without its knowledge. With data in Europe, administrative secrecy and the confidentiality of proceedings are protected by the Portuguese and European legal framework, with no extraterritorial exceptions.
Where is residents' and service users' data kept?
On servers in Europe, subject exclusively to the GDPR and to Portuguese and European law, with no transfers to third countries.
Is there an availability SLA?
Yes, 99.9% availability guaranteed by contract.
Does migrating from the current system interrupt the service?
No. Data is copied without deleting the source, and the current service keeps running until the switch has been validated, with the team supporting you from planning to go-live.
Talk to us before your next procurement procedure.
Proposal, documentation and proof of concept, straight from our team in Europe.
