Data Residency vs Data Sovereignty
Who Really Controls European Data?
- 5 minute read
For years, one of the first questions European organisations asked their cloud providers was simple: where is our data stored? Amsterdam, Frankfurt, Paris or Dublin often provided enough reassurance because the data remained inside the EU.
Europe is now moving towards a harder question: who actually controls that data? The answer reaches far beyond geography.
Data residency and data sovereignty are different questions
Data residency tells you where your data is physically stored or processed. Data sovereignty goes further. It asks which laws apply, who operates the infrastructure, who controls access, who holds the encryption keys, which companies provide the underlying technology, and which governments may have legal authority over those companies.
A server can physically sit inside the European Union while parts of the legal, technical and corporate environment around it remain connected to another jurisdiction. This distinction has become increasingly important as European organisations rely heavily on global cloud providers.
In 2026, the European Commission began formalising this wider view through its Cloud Sovereignty Framework. The framework evaluates 48 criteria across eight sovereignty areas, including legal and jurisdictional sovereignty, data and AI sovereignty, operational sovereignty, technological sovereignty, supply-chain sovereignty and strategic sovereignty.
The shift is significant because Europe is increasingly treating sovereignty as a question of control rather than geography alone.
Why Europe is paying closer attention
There is an uncomfortable economic reality behind this discussion. According to the European Commission, three non-EU hyperscalers control more than 70% of the European cloud market, while the market share of European cloud providers has declined over the past decade.
Foreign technology can provide enormous capability, scale and resilience. The sovereignty concern appears when critical European data and infrastructure depend heavily on legal, technical or operational environments controlled elsewhere.
The Commission’s proposed 2026 Cloud and AI Development Act addresses this issue directly. It warns that major cloud providers may fall under third-country jurisdictions with extraterritorial laws, including laws capable of reaching data stored outside those countries.
This is where data residency reaches its limit. A European datacentre answers the question of location. Ownership, corporate control, legal reach and technological dependence determine the wider sovereignty picture.
AWS shows how complex sovereignty has become
AWS provides one of the clearest examples of how the cloud industry is responding to European sovereignty concerns. In January 2026, AWS launched its European Sovereign Cloud.
The offering goes considerably further than placing another AWS region inside Europe. AWS says the environment is physically and logically separate from its other AWS regions, operates through dedicated legal entities incorporated in Germany, and is being transitioned towards operation exclusively by EU citizens located within the EU.
AWS has also introduced dedicated governance structures, encryption controls and sovereignty assurance mechanisms. These measures strengthen data residency and operational control. The remaining question sits at another level: AWS belongs to an American corporate group, which brings jurisdictional sovereignty into the discussion.
The CLOUD Act and legal reach
The US CLOUD Act allows American authorities, through defined legal procedures, to require certain service providers to produce data within their possession, custody or control. Server location alone does not determine the reach of the law.
AWS itself explains that the CLOUD Act can apply to qualifying service providers with operations in the United States, including organisations headquartered elsewhere.
This legal reach comes with important safeguards. Government access requires lawful authority, providers can challenge requests, and conflicting European law may create additional legal barriers. AWS also reports that since it began publishing this statistic in 2020, it has recorded zero disclosures of enterprise or government customer content stored outside the United States to the US government under the CLOUD Act.
That record matters, and so does the underlying legal structure. The sovereignty concern is therefore one of potential jurisdictional exposure. Physical location solves one part of the problem, while corporate structure and legal reach determine another.
Europe is building sovereignty into law
European legislation already contains mechanisms designed for these jurisdictional conflicts. Article 32 of the EU Data Act requires providers of data-processing services to take technical, organisational and legal measures against certain third-country governmental access to non-personal data stored within the Union where such access conflicts with EU or Member State law.
The direction of travel is clear. European policy increasingly asks organisations to examine where infrastructure is located, who owns it, who operates it, which technologies it depends on, which legal systems can reach the provider, and how much control the customer retains.
That makes sovereign cloud a much broader concept than European hosting.
Sovereignty has layers
An organisation evaluating a cloud provider should examine several questions together: where is the data stored and processed? Who operates and supports the infrastructure? Which legal entity provides the service? Which jurisdictions can compel that entity or its parent company? Who controls the encryption keys? Which technologies does the platform depend on? How easily can workloads move elsewhere? What happens if the provider, jurisdiction or supply chain becomes unavailable?
These questions expose the different layers of sovereignty. One cloud service may offer strong data residency and operational control while retaining jurisdictional exposure elsewhere. Another may provide European ownership while depending heavily on foreign hardware, software or supply chains. A third may deliver greater legal independence but offer fewer capabilities than a global hyperscaler.
Sovereignty therefore becomes a risk-management decision based on degrees of control, dependence and legal exposure.
The question has changed
European organisations have spent years asking whether their data is in Europe. That remains an important question, but the discussion has moved further.
The European Commission’s sovereignty framework now treats legal jurisdiction, operational independence, supply chains, technological dependence and cryptographic control as separate parts of the same problem. The more useful question for the next decade of European cloud computing is therefore: who ultimately has legal and technical power over our data?
A European server tells you where the data lives. Sovereignty tells you who has power over it.
For years, European organisations mostly asked one cloud question: where is our data stored? If the answer was Amsterdam, Frankfurt, Paris or Dublin, that often felt reassuring because the data stayed inside the EU.
Today, Europe is asking a broader question: who actually controls that data?
That question goes far beyond the location of the server.
Data residency and data sovereignty
Data residency tells you where your data is stored or processed.
Data sovereignty asks who has power over it.
That includes the laws that apply, the company operating the service, the people who can access the systems, the organisation controlling the encryption keys, and the governments that may have legal authority over the provider.
A server can sit inside the EU while parts of the company structure, technology or legal control still connect to another country.
This is why the European Commission introduced its Cloud Sovereignty Framework in 2026. The framework looks at 48 different criteria across areas such as legal control, operations, technology, supply chains, data and AI.
The main idea is clear: sovereignty is about control, not only location.
Why Europe is paying more attention
Europe depends heavily on large cloud providers from outside the EU. According to the European Commission, three non-EU hyperscalers control more than 70% of the European cloud market.
These providers offer strong technology, global scale and advanced services. The concern appears when important European systems depend on companies that operate under foreign laws and foreign corporate control.
The Commission’s proposed 2026 Cloud and AI Development Act highlights this directly. Some foreign laws can reach data stored outside the country where those laws were created.
So an EU datacentre answers one question: where is the data?
Sovereignty adds several more: who owns the service, which laws apply, who operates it, and who can legally compel the provider?
AWS is a useful example
AWS launched its European Sovereign Cloud in January 2026.
This service goes much further than placing servers inside Europe. AWS says the environment is physically and logically separate from its other regions, uses dedicated legal entities in Germany, and is moving towards operations carried out by EU citizens located inside the EU.
These are meaningful sovereignty measures. They strengthen European data residency and operational control.
AWS still belongs to an American corporate group. That brings another layer into the discussion: jurisdictional sovereignty.
The CLOUD Act
The US CLOUD Act allows American authorities, through legal procedures, to require some service providers to produce data that falls within their possession, custody or control.
The physical location of the server is only one part of that legal question.
AWS itself explains that the CLOUD Act can apply to service providers with operations in the United States, including companies headquartered elsewhere.
There are also important safeguards. Authorities need legal authority, providers can challenge requests, and European law can create additional barriers.
AWS reports that since 2020 it has recorded zero disclosures of enterprise or government customer content stored outside the US to the US government under the CLOUD Act.
That record matters. At the same time, the legal structure still matters because sovereignty also includes possible foreign legal reach.
Europe is responding
The EU already has protections designed for these situations.
Article 32 of the EU Data Act requires cloud and data-processing providers to take technical, organisational and legal measures against certain foreign-government access requests when those requests conflict with EU or Member State law.
This shows how the European approach is changing.
The discussion now includes server location, company ownership, operational control, legal jurisdiction, encryption control and technology dependence.
That is much broader than simply asking whether the datacentre is in Europe.
Sovereignty has several layers
When an organisation chooses a cloud provider, it should look at several things together.
Where is the data stored? Who operates the infrastructure? Which company provides the service? Which laws apply to that company? Who controls the encryption keys? Which governments can legally compel the provider? How dependent is the service on foreign technology or suppliers? How easily can the organisation move its data elsewhere?
Different providers will have different strengths.
One provider may offer strong European operations while still carrying foreign legal exposure. Another may offer greater European ownership but fewer services. A third may provide strong legal independence while depending heavily on foreign hardware or software.
This is why data sovereignty is a risk-management decision. It depends on the level of control, dependence and legal exposure an organisation is willing to accept.
The question has changed
European organisations have spent years asking: is our data stored in Europe?
Today, the more useful question is: who has legal and technical power over that data?
A European server tells you where the data lives.
Sovereignty tells you who controls the environment around it.
Need expert help protecting your environment?
Get Started