What Schwarz Digits actually added
On September 18, Schwarz Digits, the technology and IT arm of Schwarz Group, the German conglomerate behind Lidl and Kaufland, announced it had integrated Celonis and Snowflake into its STACKIT sovereign data and AI ecosystem. Techzine reports that Snowflake's AI Data Cloud now runs on STACKIT with data stored in Apache Iceberg format and encryption keys retained within EU infrastructure, meaning Schwarz controls the keys even though it is running a third party's platform on top of its own cloud. That is a structurally different arrangement than simply buying Snowflake as a SaaS product, since STACKIT sits underneath as the sovereign hosting and key-management layer rather than the other way around.
The addition builds on prior integrations with SAP through RISE with SAP, plus security vendors Zscaler and CrowdStrike, and joins Celonis for process intelligence. Martin Frederik, Snowflake's Benelux country manager, described the underlying motivation directly: "Data sovereignty ultimately revolves around freedom of choice." A Dutch sovereign cloud deployment is expected to follow in mid-2027, extending the model beyond Germany into a second major EU market and signaling this is a multi-year platform strategy rather than a single national compliance project.
Why a grocery company is building cloud infrastructure at all
It is easy to read this as a story about Snowflake or Celonis expanding their European footprint, but the more interesting actor is Schwarz Group itself. This is a grocery and retail conglomerate that decided, years ago, to build and operate its own sovereign cloud platform rather than simply buying whatever sovereignty product AWS, Microsoft, or Google offered. STACKIT is now mature enough that other major software vendors want to run on top of it.
That is a meaningfully different posture than most retailers take toward infrastructure. Schwarz treated data sovereignty as a strategic capability worth owning rather than a compliance checkbox to purchase from a hyperscaler, and it is now monetizing that decision by hosting other vendors' platforms. For a CIO at a retail or CPG company operating across US and EU jurisdictions, this is a live example of vertical integration into infrastructure paying off at a scale most peers assumed was only available to hyperscalers themselves.
The compulsion risk that is driving this, explicitly
The stated rationale is grounded in a specific, concrete concern rather than abstract data protection philosophy: US legislation that can compel American cloud and software providers to hand over customer data regardless of where that data is physically stored. That risk applies to any EU company running workloads on a US hyperscaler, even one with a European data center, because the legal exposure follows the company's headquarters, not the server's location. A German grocery conglomerate is unusually exposed to this concern given how much supplier, pricing, and customer data it processes daily across its Lidl and Kaufland banners.
STACKIT's answer is retaining encryption key control within EU infrastructure even when the software layer, Snowflake in this case, is American. That architecture, keys held locally, software hosted on sovereign infrastructure, is becoming the reference pattern for regulated European buyers who need US vendors' functionality without the compulsion exposure. Retail and CPG companies with EU operations should expect this key-custody model to become a procurement requirement, not just a nice-to-have, within the next two years.
The certification stack that makes this credible, not just marketing
Sovereignty claims are cheap to make and hard to verify, which is why the certification list matters more than the press release language surrounding it. Both Snowflake and STACKIT hold C5 certification from Germany's BSI federal security agency, plus ISO 27001 for information security, ISO 42001 specifically for AI management systems, and PCI-DSS for payment data. That combination gives a procurement or security team a concrete audit trail rather than a vendor's self-description of how seriously it takes sovereignty, and it gives a CIO a specific checklist to hand to their own compliance team when a European regulator or customer asks for proof.
ISO 42001 is the detail worth noting specifically, since it is one of the first AI-specific management system certifications to see real adoption, and its presence here signals that AI governance auditing is becoming table stakes for any vendor selling into regulated European retail and CPG buyers, not just a differentiator for the most cautious enterprises. Expect procurement teams at large retailers to start listing ISO 42001 as a required, rather than preferred, certification in AI vendor RFPs over the next few procurement cycles, mirroring how ISO 27001 became a baseline requirement for cloud vendors a decade earlier.
What this means for your own multi-cloud AI strategy
The Schwarz model argues for a specific answer to a question every large retailer is currently facing: whether to consolidate AI and data workloads onto a single hyperscaler's sovereign offering, or build a neutral sovereign layer and invite multiple best-of-breed vendors onto it. STACKIT chose the latter, and the fact that Snowflake, Celonis, and SAP have all now integrated suggests the model is working well enough to attract serious platform partners rather than just niche European vendors.
For US-headquartered retailers with EU exposure, the practical takeaway is to start separating the sovereignty question from the vendor selection question. You do not need to abandon Snowflake, SAP, or any other preferred platform to satisfy EU data residency and compulsion concerns, provided you can architect key custody and data locality independently of which software vendor sits on top. That separation is exactly what STACKIT has now proven out at scale.



