6 verifiable criteria for choosing an ethical cloud

An ethical cloud guarantees effective protection of your data, a measured environmental footprint and legal control over where you are hosted. In practice, that means demanding data portability, documented encryption and genuine contractual transparency from your provider. Yundera meets all three requirements with infrastructure hosted in France and guaranteed data export at any time.
In short:
- Before choosing an ethical cloud provider, it is essential to verify data portability, client-side encryption and the legal jurisdiction of the server.
- Contractual transparency must include explicit clauses on not selling and not sharing data, backed by ISO certifications or independent audits.
- GDPR compliance requires checking the safeguards around transfers outside the EU, users' rights, and the provider's ability to meet those obligations.
- Migrating to an ethical cloud calls for an export test, a backup plan and a post-migration performance check to avoid downtime.
- Opting for a private server hosted in France, with guaranteed exportability and open source applications, is a concrete answer to the privacy and legal-control criteria.
Table of contents
- The four pillars of a genuinely ethical cloud
- A practical checklist for choosing your cloud provider
- What the GDPR actually requires of your cloud provider
- How to migrate to an ethical cloud without breaking your operations
- Why a managed private offering meets these criteria
- Artificial intelligence in the cloud raises new ethical questions
- Concrete examples of the ethical cloud in action
- What ethical cloud adoption changes for the digital economy
- Building the ethical cloud into a real CSR strategy
- A managed private server, hosted in France, built for your privacy
- Sources
The four pillars of a genuinely ethical cloud
The phrase "ethical cloud" gets thrown around a lot, but it covers a precise approach that Okoni describes as the combination of privacy, sustainability and clear governance. Four pillars underpin that approach, and each one can be verified concretely rather than taken on trust:
- Privacy: no data collection or resale, verifiable encryption, access limited to what is strictly necessary.
- Sustainability: the datacenter's energy mix, hardware efficiency, quantified emissions commitments.
- Social responsibility: contribution to open source, working conditions for the technical teams, digital inclusion policy.
- Sovereignty: the legal jurisdiction of the hosting and the absence of any dependency on foreign regulation.
The cloud greenwashing trap: a "green" logo on a marketing page is never a substitute for a published carbon report. The cloud carries a growing physical footprint that serious players work to reduce through documented infrastructure choices, not just a statement of intent. A provider that fails to combine all four pillars — privacy and social responsibility in particular — is only practising a partial marketing of ethics.
A practical checklist for choosing your cloud provider
Before you sign, run the provider through six verifiable criteria. Each one deserves a written answer, not a verbal one in a sales meeting — a good practice you will also find in this Datenschutz Hosting en Deutschland für DSB und Gameserver checklist for ensuring hosting compliance.
- Portability and export: ask which file formats can be exported and what the contractual turnaround is for returning your data if you terminate.
- Encryption and key management: check who holds the encryption keys and whether tools such as Cryptomator are compatible for client-side encryption.
- Location and jurisdiction: identify the country where the servers are actually hosted, not just the company's commercial headquarters.
- Contractual transparency: read the SLA and look for an explicit clause stating that data is neither sold nor shared with third parties.
- Certifications and audits: favour providers able to produce ISO certifications, or HDS-type hosting where the data warrants it, backed by an independent audit.
- Measurable energy evidence: ask for a number, not an intention. A renewable energy mix and a quantified greenhouse gas report are worth more than a general declaration.
Pro tip: Always ask for a test export before signing a long-term contract. A serious provider will let you extract a sample of your data in under 24 hours so you can check the format and the integrity of the file.
There is nothing abstract about this list: it maps to the points a professional buyer should slip into a request for proposals. A provider who hesitates on any one of these six items often reveals a much broader vagueness about its data policy.
What the GDPR actually requires of your cloud provider
The European data protection regulation puts the client company in the position of data controller, even when hosting is outsourced. That means legal responsibility stays with you, not just with the technical provider. The role of the data protection officer (DPO) becomes central as soon as the volume or sensitivity of the data demands it.
Three points deserve a systematic check:
- Transfers outside the European Union: these require appropriate safeguards (standard contractual clauses, an adequacy decision), not just a passing mention in the terms and conditions.
- Data subjects' rights: portability, access and erasure must be technically feasible at the provider, not merely listed on paper.
- Contractual consequences: a provider that cannot guarantee these rights leaves you directly exposed in the event of an inspection.
France's CNIL recommends a precise mapping of processing activities before any outsourcing, with technical and organisational measures proportionate to the risk. To go further on the specific French obligations, our guide to enterprise cloud and the GDPR details the concrete cases SMEs run into.
How to migrate to an ethical cloud without breaking your operations
Migration is not something you improvise, especially when customer data or critical business files are at stake. A four-step roadmap keeps the risk of downtime down.
- Map your processing activities and rank them by criticality: start with what can be migrated without an immediate impact on the business.
- Test the export and the re-import before committing definitively. Portability that works in theory but fails in practice costs weeks of delay.
- Plan backup and restore with a verification point after every migration stage, not only at the end of the process.
- Check real-world performance once you have switched over, comparing the promised SLA against actual usage over the first few weeks.
Pro tip: Never migrate 100% of your data in a single operation. Switch over a secondary service first, measure latency and reliability for two weeks, then extend the migration to the rest of the infrastructure.
Our GDPR cloud compliance checklist walks through each of these steps with the associated legal verification points. The most common mistake remains underestimating how long export testing takes — it is often treated as a formality when in fact it reveals a provider's real technical limits.
Why a managed private offering meets these criteria
Let's apply that checklist to a concrete solution. Yundera hosts its private servers in France and guarantees data export at any time, with no hidden clause limiting the format or the turnaround. The company neither collects nor resells any user data, which directly answers the contractual transparency criterion above.
- A fully managed private server, with no technical skills required for day-to-day administration.
- More than 100 preinstalled open source applications, covering storage, email, password management and website hosting.
- Secure access from anywhere via a custom domain.
An ethical cloud is not proved by a charter displayed on a website, but by a user's real ability to retrieve their data within a few hours, without negotiating with a sales department.
This approach suits SMEs and freelancers who want to keep control of their files without hiring a system administrator, as well as families centralising photos and documents without depending on a third-party service. For the export side specifically, our article on managed ethical web hosting explains how it works technically.
Artificial intelligence in the cloud raises new ethical questions
The arrival of generative AI and local AI models changes the picture for any cloud that claims to be ethical. The question is no longer just "where is my data stored": it becomes "who is training which model with my data, and with whose consent". A cloud provider hosting AI services must make clear whether the content customers upload is used to train third-party models — a common practice among several major players in the sector.
Three questions are worth asking before you switch on a cloud-hosted AI service:
Do your documents, images or conversations feed a model shared with other customers? Is the processing done locally, on infrastructure you control, or does it pass through external servers whose jurisdiction remains unclear? And above all, is there an option to disable this collection entirely without losing the use of the service?

Local AI, run directly on a private server rather than through an external API, goes some way to answering these concerns. It limits the circulation of sensitive data to third parties and gives the user back control over what the model actually sees. This architectural choice is becoming a selection criterion in its own right for companies handling customer data, HR files or financial information through AI tools built into their cloud.
Concrete examples of the ethical cloud in action
Ethical cloud best practice is not a matter of theory. A medical-sector SME, for instance, that hosts its patient records on a server located in France rather than on an international platform is directly meeting sector-specific regulatory obligations while reducing its legal exposure to transfers outside the EU.
An architecture practice that centralises its plans and large files on a private server with secure remote access illustrates another common use case: portability becomes a selling point with its own clients, who increasingly demand guarantees about where their data is located.
Nonprofits and local authorities are a revealing third use case. Facing tight budgets and a requirement for public transparency, they turn to sovereign hosting solutions that document their stance on infrastructure control and transparent billing, rather than offers seen as less legible contractually.
In every one of these cases, the common thread is not the size of the organisation but the sensitive nature of the data being handled. The more a piece of data involves a third party's confidentiality — a patient, an end customer or a citizen — the more demonstrating an ethical cloud becomes a measurable argument for trust rather than a mere marketing line.

What ethical cloud adoption changes for the digital economy
Choosing an ethical cloud has effects that reach beyond the client company alone. Economically, it supports a fabric of European and French hosting providers investing in low-footprint datacenters, rather than concentrating still more value in a handful of global players. That diversification also reduces a systemic risk: dependence on a single provider weakens the digital resilience of an entire sector in the event of a major outage or a change in pricing policy.
Socially and culturally, the gradual adoption of the ethical cloud is shifting what end users expect. An employee or a citizen used to seeing their local authority state clearly where their data is stored naturally becomes more demanding of the other digital services they use, including in their private life. That knock-on effect is already visible in the way some public tenders now include digital sovereignty criteria, where previously only price counted.
This shift remains uneven across sectors. Organisations under heavy regulatory pressure — healthcare, finance, the public sector — are moving faster than small commercial outfits, where the perceived cost of change still holds the decision back. Reducing your overall digital footprint, as our guide to reducing your digital footprint explains, takes an adjustment effort that not every organisation has begun at the same pace.
Building the ethical cloud into a real CSR strategy
Many companies treat the choice of cloud as a purely technical decision, separate from their CSR strategy. That is a mistake that costs dearly in consistency. A cloud provider's energy mix weighs directly on an organisation's greenhouse gas footprint — often more than all its business travel combined.
Tracking cloud-related carbon emissions as a CSR indicator in its own right, with precise figures rather than vague estimates, changes the nature of the conversation with providers. It forces you to ask concrete questions instead of settling for a statement of commitment. Regulatory compliance deserves the same treatment: it becomes a measurable indicator of trust, not just a box to tick during an annual audit. Training teams in this shared responsibility, particularly around access and password management, rounds out the approach without ever replacing it.
— Yundera
A managed private server, hosted in France, built for your privacy
Yundera offers a concrete alternative to conventional cloud offerings: a private server hosted in France, with guaranteed data export at any time.

The offering includes a wide range of preinstalled open source applications, accessible through your own domain with no technical skills required. It suits privacy-conscious individuals just as well as families centralising their photos, or startups and small businesses looking to cut their IT costs while keeping legal control of their data. To work out whether this approach fits your use case, the page for privacy-conscious users sets out the technical guarantees and the trial terms.
Sources
- Platformsh / Bpifrance — Le cloud éthique à la française
- Regulation (EU) 2016/679 — GDPR (official text)
- GoodTech — Infomaniak se veut le champion du cloud éthique
6 Verifiable Criteria for Choosing an Ethical Cloud