Strategy Guide

Data sovereignty: whose laws reach your data?

“Our data’s in the EU” isn’t the same as “our data is under EU law and nobody else’s.” As regulation tightens, foreign-access laws collide with privacy rules, and “sovereign AI” becomes a national priority, where your data lives — and who can compel access to it — has moved from an IT detail to a board-level question. This guide explains what data sovereignty really means, the laws driving it, your options, and the uncomfortable truth: sovereignty is ultimately physical.

Educational overview, not legal advice. Regulatory references are summarised; confirm specifics with qualified counsel. See notes at the end.
residency ≠
sovereignty
Where data is stored is not the same as whose laws can reach it
CLOUD Act
US law can compel US-owned providers to disclose data held anywhere in the world
Schrems II
The 2020 ruling that upended EU–US data transfers and hardened GDPR enforcement
localisation
A growing list of countries legally require certain data to stay within their borders
physical
Ultimately, sovereignty comes down to which building your data sits in — and under whose law
01 | The Definitions

Three Words People Use Interchangeably (and Shouldn’t)

Most confusion — and most compliance risk — comes from blurring three distinct things. Pinning them down is the first step, because they demand different solutions.

1

Data residency

The geographic location where data is physically stored or processed. “Our data is in a Frankfurt region” is a residency statement — about where, nothing more.

2

Data sovereignty

Whose laws and jurisdiction the data is subject to — and crucially, who can lawfully compel access to it. Data can reside in one country yet remain reachable under another country’s laws.

3

Data localisation

A legal requirement that specific data must stay within a country’s borders. Not a choice — a mandate, common for government, health, financial and personal data in many jurisdictions.

The trap is assuming residency delivers sovereignty. Store data in-country with a foreign-owned provider and it may still be reachable by that provider’s home government — residency satisfied, sovereignty not. That single gap is what most of this topic turns on.

02 | The Drivers

The Laws Making This Urgent

Data sovereignty isn’t a trend — it’s the collision of privacy law, foreign-access law and a wave of localisation rules, sharpened by geopolitics and the race for sovereign AI. The headline instruments to know:

GDPR & UK GDPR

Europe’s baseline. Strict rules on processing personal data and on transferring it outside the UK/EEA — you must guarantee an equivalent level of protection wherever it goes.

Schrems II (2020)

The CJEU struck down the EU–US Privacy Shield and put Standard Contractual Clauses under heavy scrutiny — because US surveillance law could reach EU data. It made transfer mechanisms a live compliance risk.

US CLOUD Act

Lets US authorities compel US-headquartered providers to hand over data regardless of where in the world it is stored. The reason in-country residency with a US provider may not equal sovereignty.

Data localisation laws

A growing number of countries (and sectors) legally require certain data — government, health, financial, telecoms — to be stored and processed within national borders.

Sector & national rules

UK DPA 2018, NIS2 and critical-infrastructure rules, financial-services and government classification schemes — layered obligations that often go beyond GDPR for regulated data.

Sovereign AI & geopolitics

Governments increasingly want AI and its training data built and held under their own jurisdiction — making sovereign infrastructure a strategic, not just compliance, concern.

Not legal advice — obligations depend on your data, sector and jurisdiction, and the law is evolving (EU–US Data Privacy Framework, new localisation rules, and more). The point isn’t to memorise statutes; it’s to recognise that where and how you host data has legal consequences — and to design for them.

03 | The Options

The Spectrum of Control

Sovereignty isn’t binary — it’s a spectrum, traded against agility and cost. As you move from public cloud toward owned infrastructure, residency tightens, foreign-law exposure falls, and control rises. Explore the trade-offs:

Interactive · The sovereignty spectrum

From public cloud to owned infrastructure — pick a model to see residency, foreign-law exposure, control and sovereignty.

Data residency
Foreign-law exposure
Your control
Sovereignty

Best for
Watch for

There’s no universally “right” answer — only the right answer for a given dataset and its obligations. Most organisations end up with a mix: public cloud for low-sensitivity workloads, and colocation or owned infrastructure in-jurisdiction for the regulated, sovereign or AI data that can’t leave.

04 | The Truth

Sovereignty Is Ultimately Physical

Strip away the contracts and the marketing and sovereignty reduces to four physical facts: where the building is, whose law it sits under, who owns and operates it, and who can get to the hardware. You can’t fully out-source or out-contract those — they’re decided by infrastructure. Which means the strongest sovereignty position is the one with the most physical control.

Where it is

The jurisdiction the facility sits in sets the baseline law — the non-negotiable starting point for residency and localisation.

Whose law applies

Not just the building’s country, but the ownership chain — a foreign parent can pull data into its home jurisdiction’s reach, wherever the kit sits.

Who operates it

Local entity, local staff, local control of access and keys — the operational separation that turns “in-country” into genuinely sovereign.

Who can touch it

Physical access control, audited chain of custody, and — at end of life — sovereign, certified data destruction so nothing leaves uncontrolled.

This is why so many regulated and security-conscious organisations are moving sovereign workloads onto colocation or owned infrastructure in the jurisdiction that matters — it’s the cleanest way to make the legal answer and the physical answer the same.

05 | The Bridge

How Optronix Helps

Sovereignty is an infrastructure decision — which is where we live. We help you turn the legal requirement into the right physical home for your data, and get you there, across the UK, Europe and the wider EMEA region.

Understand the requirement

We help you translate the regulatory and sovereignty obligations on each dataset into clear infrastructure requirements — residency, jurisdiction, ownership, access and isolation — so you’re solving the right problem, not over- or under-building.

Select the right data centre

Vendor-neutral, we help you find and evaluate the right facility in the right jurisdiction — colocation or owned — against sovereignty, plus the usual tiers, power, connectivity and commercials. See our buyer’s guide →  ·  Explore facilities by jurisdiction on our Data Centre Map →

Migrate — safely

We plan and execute the migration of your estate into the compliant, sovereign location — move-group planning, sequencing and cutover — with minimal disruption and an auditable chain of custody throughout.

Build & operate in-jurisdiction

Need your own? We design, build and operate data halls in the country you need — locally delivered, with the physical and operational control that genuine sovereignty requires.

Need your data somewhere it legally has to be?

Tell us the data, the regulations and the regions in play, and we’ll help you define the requirement, choose the right sovereign home for it, and migrate there cleanly.

Talk to our team

Sources & notes

  • GDPR (Regulation (EU) 2016/679) and UK GDPR / Data Protection Act 2018; international transfer rules and Standard Contractual Clauses
  • Schrems II — CJEU Case C-311/18 (2020), invalidating the EU–US Privacy Shield
  • US CLOUD Act (2018) on extraterritorial access to data held by US-based providers; data localisation requirements vary widely by country and sector