Data sovereignty in the cloud: Where your data sits is only half the story


Who controls the digital infrastructure that businesses depend on has become a live policy question. Governments in the UK and Europe are debating how far they can rely on overseas technology providers, a debate known as digital sovereignty. The EU has proposed new measures to reduce reliance on non-EU suppliers for cloud and AI, while the UK Government says it wants to balance access to global technology with resilience.

International data flows are part of day-to-day operations for most businesses, so international collaboration remains vital. Our view is that for most SMEs, the right first response is to understand exposure, not to rebuild, and that starts with a data sovereignty question: do you know where your data is, and which jurisdictions’ laws can reach it?

Data sovereignty is no longer a topic for lawyers and compliance teams but directly affects decisions about cloud providers, client and supplier contracts, and how companies work internationally.

 

Table of contents
  1. Data sovereignty vs data residency vs data localisation: what's the difference?

  2. Why data sovereignty is important for all businesses

  3. Why data sovereignty is an important issue in cloud computing

  4. How cloud providers are responding

  5. Four questions organisations should ask about their cloud data

  6. How should SMEs respond to the digital sovereignty question?
  7. Data sovereignty and cloud computing: common misconceptions

 

Data sovereignty vs data residency vs data localisation: what's the difference?

What is data sovereignty?

Data sovereignty is the concept that data is subject to the laws and regulations of one or more jurisdictions, depending on where data is collected, stored, processed, and accessed.

What is data residency?

Data residency is the geographic location where data is stored. It can partly be a business decision based on company priorities and local data sovereignty legislation.

What is data localisation?

Data localisation is a statutory requirement. Some governments require certain types of data to be held within their jurisdiction. The rules may cover just certain types of data.

What's the difference between data sovereignty, data residency and data localisation?

These three concepts are related and overlap. Businesses must establish how these concepts apply to their datasets to ensure compliance with the relevant regulatory authority.

Data sovereignty vs data residency vs data localisation Texaport

Why data sovereignty is important for all businesses

Closely tied to data protection legislation, data sovereignty is a compliance issue. However, it can also affect contractual obligations, how market-sensitive information is protected, and business continuity.

These elements become more complex for businesses operating internationally when data is regularly transferred across borders between offices or shared with local partners and contractors.

Entering new markets can mean operating within unfamiliar data protection frameworks. Companies involved in overseas mergers and acquisitions may inherit existing client contracts or several new cloud providers.

1. Regulatory compliance

What businesses need to know: Where is our data held and processed?

The GDPR applies to how personal data is collected, stored, and processed. The EU states that laws governing international transfers ensure that GDPR ‘protection travels with the data’.
Cross-border data flows are increasingly regulated, and companies that breach transfer rules can face stiff penalties.

In 2024, Uber was fined €290m after the Dutch Supervisory Authority found the company had transferred EU drivers’ personal information to Uber’s US headquarters without using the necessary transfer tools. As a result, the authority found the personal data was insufficiently protected.

2. Safeguarding market-sensitive data

What businesses need to know: Is our data subject to overseas legal frameworks?

Jurisdictions may have conflicting regulations for the same data, for example, data privacy protections versus national security concerns.

Following the US CLOUD Act, in certain legal circumstances, US authorities may request data held by a cloud provider that is under US jurisdiction, even if that data is held outside the US.

Some legal frameworks require particular types of data to be held within their jurisdiction for privacy or national security reasons.

3. Contractual obligations

What businesses need to know: Where must customer data be stored and processed to meet contractual requirements?

Customers and business partners could be subject to different regulatory regimes and may pass these requirements on to suppliers in contracts.

Contracts may stipulate where data should be held to ensure regulatory compliance or to protect intellectual property.

4. Business resilience

What businesses need to know: Could data sovereignty impact our business continuity

Regulations change, geopolitical events unfold unexpectedly, and regional disruption can affect access to cloud services.

The UK Government has itself acknowledged that concentration in a small number of cloud suppliers can create resilience risks for public services, and the same question applies to any business that depends heavily on one provider.

Data sovereignty is not only about avoiding heavy fines but also maintaining control and building resilience.

By tracking where data is held and processed, companies are better placed to mitigate risk and develop contingency plans.

 

Why data sovereignty is an important issue in cloud computing

Cloud data can be held across multiple jurisdictions

Knowing where information is located is essential to maintaining control and data protection. However, this is not always straightforward in cloud environments. Customers may choose cloud providers based on location, but copies of their data could still be held elsewhere.
SaaS applications may be hosted in one region, replicated in a second, backed up in a third, and accessed by a customer service provider in a fourth.

Cloud computing makes data sharing seem frictionless, and it’s easy to forget that data transfer rules apply to processing as well as storage.

Cloud data may also be processed across different jurisdictions

Data protection regulations such as GDPR apply to data processing. According to the ICO’s definition, data processing includes holding someone’s personal information and also sharing it or passing it to other people or organisations.

As data protection rules may still apply when data is transferred, companies must be able to track where data is stored and processed.

Data can still be transferred abroad if certain conditions are met, assuming there are no localisation laws.

For data subject to its jurisdiction, the UK ICO suggests asking three questions. If the answer is ‘yes’ to all three, then UK GDPR transfer rules apply:

  • Step 1: Does the UK GDPR apply to our processing of the personal information we’re transferring

  • Step 2: Are we initiating the transfer of personal information to an organisation located outside the UK?

  • Step 3: Is the organisation receiving the personal information a separate legal entity to us?

Cloud computing makes answering these questions more complex.

 

How cloud providers are responding

Major providers have responded to demand for greater control over data with sovereign cloud options in Europe.

AWS launched its European Sovereign Cloud in January 2026, Microsoft has completed its EU Data Boundary (with limited exceptions) and works with partners on national clouds in France and Germany, and Google offers partner-operated sovereign options.

These models differ in who operates the infrastructure and who controls access and encryption keys, and how far they change exposure to non-EU laws is still debated.

 

Four questions organisations should ask about their cloud data

Companies must be able to identify where their data is and should gather the following information:

1. Where is our data held and processed?

Organisations must be able to track data stored with cloud providers, including where it is replicated and where backups are held. Credentials, configuration data, derived metadata and logs are often overlooked.

Companies must also know where data is processed and managed, for example, whether it is accessed by remote contractors or digital supply chain partners.

2. Who can access our data, and where are they located?

This applies to employees located in different regions and third-party suppliers. Cloud and application providers may be able to access logs or personal information while monitoring services, providing technical support, or during routine maintenance.

Businesses must also be aware of any legal requirement to share certain data with authorities when mandated.

3. Which legal jurisdictions and frameworks apply?

Companies must clearly map data flows to assess which regulations apply. Data may be subject to more than one jurisdiction.

For example, a UK financial organisation operating in France and subject to EU financial regulations may have to navigate UK GDPR, EU GDPR and the EU’s Digital Operational Resilience Act (DORA). If it is using a US cloud provider, it could also be affected by the US CLOUD Act.

4. What controls and responsibilities do we retain?

Organisations and cloud providers often share responsibility for the data held in the cloud. However, companies remain accountable for personal data. This must be adequately protected using technical measures such as data encryption and robust access controls.
Contracts with cloud providers should establish where data is stored, including replicated data and backups.

Organisations must also establish whether they can transfer workloads, with or without a managed cloud services partner, if business needs change or if the cloud provider faces disruption.

 

How should SMEs respond to the digital sovereignty questions?

For most SMEs, the first response is to understand exposure, not to move data.

A practical starting point is a simple map of how data flows within your company and to external providers:

  1. Datasets: identify each dataset, how the data is collected, and whether it is personal, special category, regulated, proprietary or commercially sensitive.

  2. Flows: trace how each dataset moves between systems, SaaS applications and offices in different regions, and to external organisations such as cloud providers and third-party customer service providers.

  3. Borders: pinpoint where data leaves and enters a legal jurisdiction, then, for each flow, ask the first three of the four questions above: where the data is held and processed, who can access it, and which jurisdictions apply.

Once you have that map, consider business continuity: If access to a provider, or to a particular region, were disrupted, which services and data would you lose, and how long could the business operate without them?

Your IT team can do a first pass of this map. For more complex cases, such as after an acquisition or across several countries, an IT consultancy can help.

 

Data sovereignty and cloud computing: common misconceptions

“Our Microsoft 365 data is stored in the UK, so data sovereignty isn’t an issue”

Where data is stored is only one part of data sovereignty. For example, if remote staff located in other jurisdictions can access personal data, International Transfer rules may apply.

“Our data is stored in the UK, so it is only subject to UK jurisdiction”

If backups are held elsewhere or if the data is used in SaaS tools hosted overseas, more than one jurisdiction may be involved.

“Our cloud provider has a UK data centre, so our backups will also be in the UK”

Even if backups are held in the same UK data centre, data may be replicated elsewhere. We always recommend that organisations check with their cloud provider to establish where all copies of their data are held.

“Data residency and data sovereignty are the same”

Data residency is the location where data is stored or processed. Businesses can assess the best location based on regulatory demands and business requirements. Data sovereignty concerns the legal jurisdiction or jurisdictions that govern data.

“Only regulated industries need to worry about sovereignty.”

If data protection regulations apply to your data, we recommend checking whether International Transfer rules also apply. Customer contracts may stipulate where data must be held or processed.

Regulated industries may face additional data transfer rules.

“Our provider offers a sovereign cloud option, so we are covered”

Sovereign cloud options differ in who operates the infrastructure and who controls access and encryption keys. Check what the option changes for your own data, and whether it covers your region, your services and your backups.

 

Conclusion

Cloud computing offers a cost-effective way for organisations to scale and access new tools and applications. As businesses grow and increase their use of cloud services, data sovereignty becomes an important consideration, especially as they expand into overseas markets.

Storing data locally does not resolve data sovereignty complexities. Organisations must also know where data is processed, who can access it, and from which geographic location, together with the jurisdictions that may have legal oversight.

By mapping how data moves within your organisation and to third parties, you can establish which jurisdictions may apply and take steps to ensure compliance and maintain control.

Digital sovereignty will remain a live policy debate. For businesses, the practical task stays the same: know where your data is, who can access it and which laws apply.

 

Data sovereignty for businesses: frequently asked questions

What does data sovereignty mean?

Data sovereignty is the concept that data is subject to the laws and regulations of one or more jurisdictions, depending on where data is collected, stored, processed, and accessed.
What is the difference between data sovereignty and data residency?

Data residency is the location where data is stored or processed. Data sovereignty concerns the legal jurisdiction or jurisdictions that govern data.

Is data sovereignty the same as data localisation?

Data localisation is when a government requires certain types of data to be held within its jurisdiction. The rules stipulate where data must be held.

Data sovereignty concerns the legal jurisdiction or jurisdictions that have authority over the data.

What is the difference between digital sovereignty and data sovereignty?

Digital sovereignty concerns how far a country or region controls its digital infrastructure and technologies. Data sovereignty concerns which jurisdictions’ laws apply to a particular organisation’s data. Digital sovereignty is a policy question for governments, while data sovereignty is a practical question for businesses.

Does storing data in a country mean only that country’s laws apply?

Not necessarily. Storage location may make data subject to the laws of that country. However, other legal frameworks may apply, depending on where the data was collected, where it is processed, and where organisations handling the data are located.

Does data sovereignty only apply to data storage?

No. Data protection regulations such as GDPR apply to data processing as well as storage. Processing includes holding someone’s personal information, sharing it, or passing it to other people or organisations.

Companies must be able to track where data is stored and processed, together with the organisations involved.

How does cloud computing affect data sovereignty?

Cloud providers may store data in several data centres across different legal jurisdictions, with backups and replicas held in separate locations.

Cloud services make collaboration and data sharing easier. However, when data is accessed or processed by partners in different jurisdictions, it can be more difficult to ascertain which legal frameworks apply.

Power your progress

Join forces with us to build a stronger IT infrastructure, protect your data, and focus on your future.