Data sovereignty: whose laws reach your data?
“Our data’s in the EU” isn’t the same as “our data is under EU law and nobody else’s.” As regulation tightens, foreign-access laws collide with privacy rules, and “sovereign AI” becomes a national priority, where your data lives — and who can compel access to it — has moved from an IT detail to a board-level question. This guide explains what data sovereignty really means, the laws driving it, your options, and the uncomfortable truth: sovereignty is ultimately physical.
sovereignty
Three Words People Use Interchangeably (and Shouldn’t)
Most confusion — and most compliance risk — comes from blurring three distinct things. Pinning them down is the first step, because they demand different solutions.
Data residency
The geographic location where data is physically stored or processed. “Our data is in a Frankfurt region” is a residency statement — about where, nothing more.
Data sovereignty
Whose laws and jurisdiction the data is subject to — and crucially, who can lawfully compel access to it. Data can reside in one country yet remain reachable under another country’s laws.
Data localisation
A legal requirement that specific data must stay within a country’s borders. Not a choice — a mandate, common for government, health, financial and personal data in many jurisdictions.
The trap is assuming residency delivers sovereignty. Store data in-country with a foreign-owned provider and it may still be reachable by that provider’s home government — residency satisfied, sovereignty not. That single gap is what most of this topic turns on.
The Laws Making This Urgent
Data sovereignty isn’t a trend — it’s the collision of privacy law, foreign-access law and a wave of localisation rules, sharpened by geopolitics and the race for sovereign AI. The headline instruments to know:
GDPR & UK GDPR
Europe’s baseline. Strict rules on processing personal data and on transferring it outside the UK/EEA — you must guarantee an equivalent level of protection wherever it goes.
Schrems II (2020)
The CJEU struck down the EU–US Privacy Shield and put Standard Contractual Clauses under heavy scrutiny — because US surveillance law could reach EU data. It made transfer mechanisms a live compliance risk.
US CLOUD Act
Lets US authorities compel US-headquartered providers to hand over data regardless of where in the world it is stored. The reason in-country residency with a US provider may not equal sovereignty.
Data localisation laws
A growing number of countries (and sectors) legally require certain data — government, health, financial, telecoms — to be stored and processed within national borders.
Sector & national rules
UK DPA 2018, NIS2 and critical-infrastructure rules, financial-services and government classification schemes — layered obligations that often go beyond GDPR for regulated data.
Sovereign AI & geopolitics
Governments increasingly want AI and its training data built and held under their own jurisdiction — making sovereign infrastructure a strategic, not just compliance, concern.
Not legal advice — obligations depend on your data, sector and jurisdiction, and the law is evolving (EU–US Data Privacy Framework, new localisation rules, and more). The point isn’t to memorise statutes; it’s to recognise that where and how you host data has legal consequences — and to design for them.
The Spectrum of Control
Sovereignty isn’t binary — it’s a spectrum, traded against agility and cost. As you move from public cloud toward owned infrastructure, residency tightens, foreign-law exposure falls, and control rises. Explore the trade-offs:
From public cloud to owned infrastructure — pick a model to see residency, foreign-law exposure, control and sovereignty.
There’s no universally “right” answer — only the right answer for a given dataset and its obligations. Most organisations end up with a mix: public cloud for low-sensitivity workloads, and colocation or owned infrastructure in-jurisdiction for the regulated, sovereign or AI data that can’t leave.
Sovereignty Is Ultimately Physical
Strip away the contracts and the marketing and sovereignty reduces to four physical facts: where the building is, whose law it sits under, who owns and operates it, and who can get to the hardware. You can’t fully out-source or out-contract those — they’re decided by infrastructure. Which means the strongest sovereignty position is the one with the most physical control.
Where it is
The jurisdiction the facility sits in sets the baseline law — the non-negotiable starting point for residency and localisation.
Whose law applies
Not just the building’s country, but the ownership chain — a foreign parent can pull data into its home jurisdiction’s reach, wherever the kit sits.
Who operates it
Local entity, local staff, local control of access and keys — the operational separation that turns “in-country” into genuinely sovereign.
Who can touch it
Physical access control, audited chain of custody, and — at end of life — sovereign, certified data destruction so nothing leaves uncontrolled.
This is why so many regulated and security-conscious organisations are moving sovereign workloads onto colocation or owned infrastructure in the jurisdiction that matters — it’s the cleanest way to make the legal answer and the physical answer the same.
How Optronix Helps
Sovereignty is an infrastructure decision — which is where we live. We help you turn the legal requirement into the right physical home for your data, and get you there, across the UK, Europe and the wider EMEA region.
Understand the requirement
We help you translate the regulatory and sovereignty obligations on each dataset into clear infrastructure requirements — residency, jurisdiction, ownership, access and isolation — so you’re solving the right problem, not over- or under-building.
Select the right data centre
Vendor-neutral, we help you find and evaluate the right facility in the right jurisdiction — colocation or owned — against sovereignty, plus the usual tiers, power, connectivity and commercials. See our buyer’s guide → · Explore facilities by jurisdiction on our Data Centre Map →
Migrate — safely
We plan and execute the migration of your estate into the compliant, sovereign location — move-group planning, sequencing and cutover — with minimal disruption and an auditable chain of custody throughout.
Build & operate in-jurisdiction
Need your own? We design, build and operate data halls in the country you need — locally delivered, with the physical and operational control that genuine sovereignty requires.
Need your data somewhere it legally has to be?
Tell us the data, the regulations and the regions in play, and we’ll help you define the requirement, choose the right sovereign home for it, and migrate there cleanly.
Sources & notes
- GDPR (Regulation (EU) 2016/679) and UK GDPR / Data Protection Act 2018; international transfer rules and Standard Contractual Clauses
- Schrems II — CJEU Case C-311/18 (2020), invalidating the EU–US Privacy Shield
- US CLOUD Act (2018) on extraterritorial access to data held by US-based providers; data localisation requirements vary widely by country and sector
Educational guidance, not legal advice. Data protection and sovereignty obligations depend on your data, sector and jurisdiction and are evolving (including the EU–US Data Privacy Framework and new national rules). Confirm current requirements with qualified legal counsel before making compliance decisions.