Data centres have become foundational infrastructure for the global economy. The sector is attracting investment at a scale and pace without modern precedent. Accelerating digitalisation, the computational demands of AI, and the strategic priority that governments now attach to sovereign compute capacity have together transformed data centres into pillars of national industrial strategy. Yet the regulatory and infrastructure frameworks that govern their development have not kept pace with that demand.

A defining feature of the sector is a collision between the political and economic imperative to build at speed on the one hand, and the physical and regulatory constraints on the other. Congested electricity grids, lengthening grid connection queues, inflexible planning regimes, tightening environmental obligations, and an increasingly assertive foreign investment-screening apparatus are factors that ultimately determine whether, where, when, and on what terms a project can in fact proceed.

Prepared by the European Best Friends network, this publication maps those constraints and opportunities that accompany them across seven jurisdictions – France, Germany, Italy, the Netherlands, Portugal, Spain, and the United Kingdom – together with the EU-level framework on which six Member State regimes build. It applies a common comparative framework organised around five principal themes that recur across the jurisdictions surveyed: (i) securing grid access; (ii) procuring power; (iii) national strategy, investment, and planning incentives; (iv) environmental regulation and sustainability; and (v) real estate and site structuring.

Power access has emerged as the single greatest constraint on data centre development in every jurisdiction surveyed. Connection queues are extensive, with grid connection timelines extending over several years. Structural reform is accompanying that scarcity of power access. The traditional “first-come, first-served” model of allocating connection capacity is giving way, jurisdiction by jurisdiction, to merit- and maturity-based systems that prioritise project readiness, financial commitment, and policy alignment at an earlier stage than the regimes they replace.

The divergence in national approach is perhaps most acute in relation to foreign investment screening. Each jurisdiction has a bespoke regime: Germany’s mandatory notification requirement, triggered at a 10% of voting rights level for non-EU acquirers of facilities meeting its 3.5 MW critical-facility threshold; the Netherlands’ 50 MW threshold under its telecommunications regime; the UK’s designation of “data infrastructure” as a mandatory notification sector under the National Security and Investment Act 2021 (“NSI Act”); and France’s composite test of facility size, multi-site operation and client sensitivity.

Data localisation follows a related logic. No European jurisdiction imposes a general localisation mandate for private sector data. However, each European jurisdiction overlays that permissive baseline with sector-specific constraints – for health data, defence and classified information, financial services outsourcing, and government workloads – that operate as implicit localisation requirements whose practical effects depend on the operator’s anticipated customer base.

Energy efficiency and sustainability regimes are matters on which national regimes are moving both fastest and farthest apart. Yet, the direction of travel is from disclosure towards prescription. For example, Germany already mandates a Power Usage Effectiveness (“PUE”) ratio of 1.2 or below for data centres commissioned after 30 June 2026, together with an escalating energy-reuse factor. Spain’s draft regime would tie compliance with efficiency and sustainability reporting directly to the grant and retention of grid access permits. France imposes detailed efficiency disclosure while declining, for now, to set a mandatory PUE floor. 

Waste heat recovery is emerging as a parallel obligation across several jurisdictions, and the credibility standard for renewable energy claims is expanding towards hourly temporal matching; the statutory certificate regimes on which such claims still rest – Guarantees of Origin (“GOs”) and, in the United Kingdom, Renewable Energy Guarantees of Origin (“REGOs”) – continue to operate on an annual accounting basis and impose no temporal-correlation requirement, so that hourly matching, like additionality, remains in most jurisdictions a contractual rather than a regulatory requirement. Greenwashing exposure remains latent – as no enforcement action has yet been taken against a data centre operator in any surveyed jurisdiction.

Beyond the contested credibility of environmental claims lies a more structural divergence. The United Kingdom imposes no mandatory, data centre-specific efficiency-reporting obligation equivalent to that under the recast EU Energy Efficiency Directive, and it has adopted a single- rather than a double-materiality basis for sustainability disclosure. This asymmetry confronts operators active in both markets with a choice between voluntary alignment with EU standards and the maintenance of separate compliance frameworks.

A structural tension runs through every planning and environmental regime surveyed in this report. While jurisdictions are seeking procedurally to accelerate strategically important projects, they are simultaneously tightening the substantive obligations those projects must satisfy. National AI and digital infrastructure strategies have recast data centres as instruments of industrial and sovereign compute policy. Several jurisdictions have responded by introducing fast-track consenting routes for data centres: including the UK’s Nationally Significant Infrastructure Project (“NSIP”) regime from January 2026; France’s extension of its project-of-major-national-interest (“PINM”) regime; Spain’s new category of Strategic Investment Projects; Portugal’s project-of-national-interest regime; and Italy’s unified, simplified authorisation, supplemented by a strategic national interest designation for projects of €1 billion or more. 

The procedural acceleration coincides with tightening environmental obligations, and environmental impact assessment (“EIA”) requirements triggered in every jurisdiction by the ancillary infrastructure on which data centres depend, typically standby generation. The screening triggers diverge sharply in their level of calibration and, in each case, they are set by reference to the capacity of that standby generation rather than to the data centre’s own demand. Italy’s threshold of 50 MW of standby capacity (with a full assessment above 150 MW), for example, sits well below the German (200 MW) and Dutch (300 MW) equivalents, exposing certain projects to more scrutiny than elsewhere. This risks regulatory arbitrage undermining the functioning of the internal market and its level playing field.

Read together, the chapters trace a regulatory environment converging in overall trajectory, while diverging in national form. As power scarcity deepens, the contest for grid capacity will increasingly be resolved by administrative judgments of readiness and strategic value, rather than by the order of application. Regulation across all the surveyed jurisdictions is increasingly dependent on capacity thresholds. A consequence is that a single facility may be subject to different rules – particularly regarding efficiency reporting, critical infrastructure designation, foreign investment screening, and planning – at different capacity values (measured variously by installed IT load, total site load, and floorspace).

Beneath the national variation lies a shared regulatory foundation, and the six EU Member State regimes build upon a common foundation of EU law governing grid access, cybersecurity and physical resilience, energy efficiency, renewable certification, and corporate sustainability reporting. The national regimes diverge principally in the speed and ambition of national execution rather than in the underlying design. However, the UK’s position increasingly diverges more significantly.

Efficiency disclosure may well follow a conveyor belt trajectory towards mandatory performance standards. Security designation and foreign investment scrutiny of data centres will widen. Actions at the EU level, meanwhile, are likely to press EU Member State regimes toward a more prescriptive and harmonised position. By way of example, the EU Tech Sovereignty package gives that trajectory concrete form, and adds a further axis to it: alongside efficiency and security, the sovereignty of compute itself – who owns it, where it sits, and which workloads it may carry – is becoming a regulated characteristic of the asset. 

For sponsors, investors, and corporates, the practical consequence is that the constraints which determine a project’s viability – grid, security, planning, and environment – should be addressed cohesively. Those who engage network operators at the earliest stage of site selection, who pre-empt changes to efficiency standards, who structure ownership, financing, and data flows with foreign investment and localisation exposure in view from the outset, will find the advantage runs with them.

What Makes a Data Centre? 

A data centre is, at its most elementary, a physical facility that houses the computing systems on which digital services depend – servers, data storage arrays and network equipment – together with the power, cooling, and supporting building systems that keep them operating securely and without interruption. Its distinguishing features from ordinary commercial buildings are the intensity and criticality of those supporting systems: the redundant power supply, the standby generation, the dedicated cooling, and the connectivity infrastructure that sustain continuous operation are integral to the asset, rather than ancillary to it.

A data centre is therefore best understood as an engineered environment whose entire purpose is the uninterrupted, secure processing and storage of data. This requirement for continuity shapes both a data centre’s physical design and the regulatory regimes to which it is subject.

Comparing AI and traditional data centres

Defining infrastructure: power, storage, water and cooling

The defining characteristic of a data centre is its dependence on a continuous and resilient supply of electricity. Its electrical topology is built in three layers, each addressing a different mode of failure. The first is a grid connection, either to the public transmission or distribution network, or a private wire or onsite arrangement. The (optional) second layer is an uninterruptible power supply (“UPS”), which bridges the interval before standby generation comes online and, in normal operation, conditions the incoming power to protect sensitive equipment. The third is standby generation. These layers are often designed to ensure redundancy. For details, see figure 1. 

Figure 1. Three layers of power resilience

The standby-generation fleet is the feature that most often brings a data centre within the scope of emissions control and environmental permitting, because it tends to comprise combustion activities. Furthermore, the scale and redundancy of the power supply determines the connection capacity a project must secure from the network operator, the constraint that dominates site-selection and grid analysis. Another distinct and growing function of energy storage systems is the deployment of larger battery units that interact with the grid.

Heating is a by-product of power usage. Almost all of the electricity drawn by IT equipment is ultimately converted into heat, which must be removed continuously if the equipment is to operate within its tolerances. As power densities have risen, air cooling has approached its physical limits, with liquid cooling increasingly displacing air cooling for the most demanding workloads and experimental use of immersion cooling also beginning. For details, see figure 2.

Many cooling systems consume water, whether through evaporative cooling towers or adiabatic systems that exploit evaporation to reject heat. A large facility may require both a substantial supply of, and a means to, discharge warmed or treated water. Both the abstraction and the discharge are subject to permitting rules. Water scarcity has become a major constraint on both cooling-technology choice and site selection alike: the specific licensing thresholds, and their bearing on where or how a facility can be built, are addressed in the section on site selection and in the jurisdiction chapters that follow. 

Typologies

The sector conventionally uses several overlapping typologies. For present purposes, the five most relevant are enterprise, colocation, hyperscale, AI inference, and AI training. Those typologies are distinguished partly by who owns or operates the physical infrastructure, partly by who owns and manages the computing equipment housed within it, and partly by the scale, architecture, and principal workload for which the facility is designed. In some regulatory regimes, the allocation of operational responsibility—and, in some cases, the resulting classification—carries direct regulatory consequences.

An enterprise data centre is dedicated to a single enterprise or corporate group and is typically operated under its control, although particular facilities-management functions may be outsourced. A colocation facility, by contrast, provides managed space, power, cooling, physical security, network access, and, often, interconnection services to one or more third-party customers, which typically install and manage their own computing equipment.

A hyperscale data centre is a very large, highly scalable facility designed to support cloud platforms or other large-scale digital services. It may be owned and operated by the hyperscale company itself, or provided on a leased basis. An AI inference data centre is designed principally to run trained models in production, processing new inputs to generate predictions, responses, or other outputs; its architecture typically prioritises high throughput, network connectivity, and, where the application requires it, low latency and proximity to users. An AI training data centre is designed principally to develop or refine models using large datasets and computationally intensive, highly parallel processing; it therefore typically requires high-density accelerator clusters, high-bandwidth interconnects, and substantial power and cooling capacity.

These categories are not mutually exclusive. Artificial intelligence training and inference workloads may be deployed in enterprise, colocation, or hyperscale facilities, while a hyperscale operator may use both facilities that it owns and capacity leased from colocation providers. The classification therefore identifies the facility’s predominant operational model, scale, or workload rather than imposing an exclusive technical boundary.

Capacity, efficiency and the regulatory significance of scale 

Two technical measures recur throughout the regulatory analysis that follows. The first is PUE: the ratio of a facility’s total energy consumption to the energy consumed by its IT equipment alone. A theoretically perfectly efficient facility, in which every unit of energy reached the IT load and none was lost to cooling, lighting, or power conversion, would achieve a PUE of 1.0. In practice, the global average has sat closer to 1.58, the gap representing the energy overhead of the supporting infrastructure. PUE has become the principal metric of data centre energy efficiency, and it is increasingly accompanied by related measures: water usage effectiveness (“WUE”), carbon usage effectiveness (“CUE”), and the energy reuse factor (“ERF”) that quantifies the proportion of waste heat recovered for use elsewhere.

The second is rack density: the electrical load drawn by a single rack or cabinet of equipment, expressed in kilowatts. Conventional enterprise deployments have historically operated at densities of 5 to 10 kW per rack. The computational demands of AI have transformed this picture, with the densest training and inference workloads now commonly drawing 50 to 150 kW per rack, and the most advanced configurations exceeding even that range. Rising density is the principal driver of the shift to liquid cooling, and it also mediates the relationship between a facility’s power capacity and its physical footprint: a given quantity of IT load may occupy a fraction of the floorspace at high density that it would at conventional density.

The last point carries direct regulatory salience, because European and national legislation increasingly define and regulate data centres by reference to capacity thresholds, rather than to typology, and those thresholds are measured against several different metrics. The recast EU Energy Efficiency Directive imposes reporting obligations on facilities with an IT power demand of 500 kW or more, and waste heat recovery obligations on those with a total rated energy input exceeding 1 MW. The EU NIS2 Directive and the EU Critical Entities Resilience Directive identify data centre providers as essential, important, or critical entities by reference to size. National tests add further thresholds of their own – Germany’s designation of facilities of at least 3.5 MW (and 10 racks) as critical, the UK’s forthcoming distinction between colocation facilities at or above 1 MW and enterprise facilities at or above 10 MW – each measured variously by installed IT load, total site load, or floorspace. 

Main Criteria for Site Selection

Site selection for a data centre is governed more by the availability of power, connectivity, and the regulatory headroom to build, rather than solely by conventional real-estate considerations. A viable site must satisfy a cluster of interdependent requirements: a grid connection of sufficient capacity and realistic delivery date; access to dense and diverse fibre routes; the water and climatic conditions to cool the facility efficiently; buildable land with a workable consenting route; and a tolerable profile of natural hazard and community-opposition risk. These constraints lie largely outside a developer’s control, and frequently set the entire project’s timetable. They are also cumulative rather than severable: a parcel with abundant power but no fibre, or buildable land with no realistic grid connection, will not support a facility, however attractive its other attributes.  

As foreshadowed in the previous sections, access to power has become the single greatest constraint, displacing the traditional primacy of proximity to the populations a facility serves. That displacement has been reinforced by the rise of latency-tolerant AI workloads, which loosen the historic need to site capacity close to end users, and allow developers to follow available power to more remote locations. Grid congestion and lengthening interconnection queues now extend connection lead times by several years in the most established markets. Developers are, accordingly, prioritising regions with robust transmission and distribution infrastructure, and are increasingly transacting in “powered land” sold on the strength of confirmed capacity: a practice that makes early engagement with the network operator a crucial step in site identification. 

Connectivity is equally decisive. Sites are valued for their proximity to dense and diverse fibre routes, internet exchange points, cloud on-ramps, and for the resilience of redundant paths. Latency sensitivity varies by workload. AI training is relatively latency-tolerant, and may be sited remotely, whereas colocation serving financial trading or content streaming requires network-rich locations adjacent to the users it serves. 

Operators continue to cluster where power, connectivity, and a skilled construction and operations workforce converge, weighing the advantages of established hubs against congestion and regulatory pressures. They are also increasingly expanding into secondary markets where capacity remains available. Community sentiment has itself also become a seminal factor: local opposition has halted significant projects, making early engagement with the host community integral to responsible site selection.

A site’s viability turns, ultimately, on the convergence of power, connectivity and a workable consenting route at a single location, and on the timetable within which each can be secured. Power capacity and grid-connection lead times are now primary constraints, followed closely by connectivity, water, and applicable planning routes. The absence of any one condition defeats a project that satisfies all the others. The practical discipline is to resolve these questions in parallel and at the earliest possible stage, before committing significant development capital, since each is capable on its own of affecting whether, and when, a project can proceed.

Land use and planning are also determinative. Buildable land is scarce in key connectivity hubs, and the applicable consenting route is often decisive, with jurisdictions diverging between general commercial planning and dedicated fast-track regimes for strategically significant projects. Whether a project requires an EIA is frequently determined on a case-by-case basis by reference to ancillary infrastructure, such as standby generation. The consequences of an inadequate assessment are significant. Developers assess natural-hazard exposure – flood plains, seismic activity and ground stability – to screen out sites whose physical characteristics would compromise resilience.

Cooling and water access shape both operational efficiency and regulatory exposure. Lower ambient temperatures reduce cooling loads and operating costs, whereas water availability is subject to ever-closer scrutiny in resource-constrained regions.