Glossary · Cloud infrastructure CPaaS (Communications Platform as a Service)
Cloud-based platform providing developer APIs for SMS, voice calls, verification codes, email, video, and messaging (WhatsApp Business, RCS). CPaaS providers hold sensitive customer communication data — phone numbers, message content, verification codes — making vendor jurisdiction structurally important.
## What CPaaS covers
Communications Platform as a Service (CPaaS) is the API layer that sits between an application and telecommunications infrastructure. A developer calls a REST endpoint or SDK method; the CPaaS provider routes the resulting SMS, voice call, verification code, email, WhatsApp message, or RCS message through mobile operators, carriers, and messaging platforms.
The category has consolidated around a few large vendors — **Twilio** (US, Nasdaq), **Sinch** (Sweden, Nasdaq Stockholm), **Infobip** (Croatia), **Vonage** (US, owned by Ericsson SE), **Bird / formerly MessageBird** (Netherlands, US private-equity owned), and **Amazon Connect / AWS End User Messaging** (US) — with a broader ecosystem of specialised players.
## Why CPaaS is a sovereignty question
CPaaS providers hold what is arguably the most sensitive routine communications-data category:
- Phone numbers of every customer receiving verification codes, receipts, notifications
- Contents of messages (SMS/WhatsApp) that carry order confirmations, health-appointment reminders, KYC verification codes, banking one-time passwords
- Metadata: who received what, when, from which sender ID, with what delivery status
- For email: message bodies, tracking pixels, engagement telemetry
- For voice: call metadata, and increasingly transcripts when conversational-AI features are enabled
Under EU law, these are personal data under GDPR and — for messages themselves — additionally protected under the ePrivacy Regulation. Under US law, a US-incorporated CPaaS provider is subject to the CLOUD Act, FISA Section 702, and National Security Letters.
## The jurisdiction question in practice
A European company using Twilio for SMS OTPs and Twilio SendGrid for transactional email is routing a genuinely sensitive telemetry stream through Twilio Inc. — a Delaware corporation. US authorities can compel Twilio to disclose data it holds, including data belonging to European customers hosted in Twilio's EU regions.
Structurally, only a CPaaS provider with no US parent removes that exposure. In practical 2026 terms, the credible European options are:
- **Sinch** — Stockholm, Sweden. Nasdaq Stockholm-listed (SINCH). 4000+ employees. Includes Mailgun and Mailjet (email) inside the same corporate group. Structurally the closest direct Twilio replacement.
- **Infobip** — Vodnjan, Croatia. Private, EU-controlled. Comparable global operator coverage. Strong in enterprise messaging.
Both operate EU data-residency by default; both are structurally EU-jurisdiction at the parent level.
## What CPaaS excludes
CPaaS is distinct from:
- **Contact-centre-as-a-service (CCaaS)** — voice-centric agent-facing platforms (Genesys, Talkdesk). CPaaS provides the APIs; CCaaS provides the agent UX.
- **Meetings / video-conferencing** — Zoom, Google Meet, Teams. These are meeting-first products, not developer APIs.
- **Marketing email platforms** — Mailchimp, GetResponse, Brevo. These handle broadcast newsletters; CPaaS handles per-user transactional messages.
The line blurs when CPaaS providers acquire adjacent capabilities — Sinch acquired Mailgun and Mailjet, Twilio acquired SendGrid — but the developer-API-first framing remains the CPaaS category anchor.
## Regulatory pressure in 2026
Three regulatory trends make CPaaS sovereignty more material:
1. **PSD3 and the Payment Services Directive review** — SCA (Strong Customer Authentication) flows delivered via SMS OTP or silent network authentication place messaging providers directly in the payments-regulated flow.
2. **NIS2 essential entities** are now asking direct questions about the jurisdiction of critical customer-communications vendors.
3. **AI Act processing chains** — as voice, SMS, and email are increasingly processed by conversational-AI layers, the AI-Act obligations on high-risk processing propagate to the CPaaS layer.
For European organisations reviewing their vendor stack under any of these regimes, CPaaS is not a background utility — it is a category worth explicit sovereignty scrutiny.
Was this helpful?
Thanks for your feedback!