NIS2
What is data sovereignty, and why does it matter for your data?
Storing data in an EU region is a start. Sovereignty is about which laws reach it, who controls access and whether you can recover without depending on one foreign supplier.

The short answer
Data sovereignty means your data is subject to the laws of the jurisdiction you choose, and that you keep control over it. For EU organisations it combines three things: data stored in the EU, a provider that falls under EU law rather than foreign law, and the ability to access, restore or move your data without depending on one supplier.
Key takeaways
- Data residency is where data is stored; data sovereignty also covers which laws can compel access to it and who controls it.
- The US CLOUD Act (18 U.S.C. § 2713) requires US providers to disclose data in their control regardless of whether it is stored inside or outside the United States.
- GDPR Article 48 says a third-country court order to transfer personal data is only recognised if based on an international agreement such as a mutual legal assistance treaty.
- The EU–US Data Privacy Framework was upheld by the EU General Court on 3 September 2025, but an appeal to the Court of Justice is pending.
- Keeping your backup with an EU provider in EU data centres is one of the quickest ways to add sovereignty to an existing cloud setup.
What does data sovereignty mean?
Data sovereignty is the principle that data falls under the laws and control of a chosen jurisdiction, in practice the EU for European organisations. It goes further than knowing which country your data centre is in.
Imagine your board asks three questions: where is our customer data, which governments could demand it, and could we still operate if our main cloud provider became unavailable or untrustworthy? Data sovereignty is the set of answers. It also sits squarely inside NIS2 risk management, which we cover on our NIS2 compliance page.
| Term | What it answers | Example |
|---|---|---|
| Data residency | Where is the data physically stored? | "Our mailboxes are hosted in an EU region." |
| Data localisation | Does a law require the data to stay in a country? | A national rule that certain records stay in-country |
| Data sovereignty | Which laws apply, who controls access, and can we leave? | "Our backup is held by an EU company, under EU law, and we've tested restoring it." |
In short: residency is about geography, sovereignty is about jurisdiction and control.
Why does the US CLOUD Act matter for data stored in the EU?
Because it follows the provider, not the data centre. The CLOUD Act lets US authorities require US providers to hand over data they control, even if it's stored in the EU.
The key provision, 18 U.S.C. § 2713, added in March 2018, requires a provider to disclose data "within such provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States." The US Department of Justice's CLOUD Act resources also list executive agreements with the UK and Australia, and EU–US negotiations that resumed in March 2023.
US providers have responded with EU-based offerings. Microsoft's EU Data Boundary, for example, commits to storing and processing Microsoft 365 and Azure customer data in the EU and EFTA, with limited documented exceptions. That improves residency. It doesn't change who owns the provider. When a French Senate inquiry asked Microsoft France's Anton Carniaux in June 2025 whether he could guarantee French data would not be passed to US authorities without French approval, he answered "No, I cannot guarantee that," adding that it had never happened, according to The Register.
EU law pushes back. Article 48 GDPR says a third-country court judgment or authority decision requiring a transfer of personal data "may only be recognised or enforceable in any manner if based on an international agreement, such as a mutual legal assistance treaty." A provider can end up caught between the two.
Is the EU–US Data Privacy Framework enough?
It's a valid legal basis for transferring personal data to certified US companies today, but it's under appeal and it doesn't remove US law enforcement access under the CLOUD Act.
The European Commission adopted its adequacy decision for the EU–US Data Privacy Framework in July 2023. On 3 September 2025 the EU General Court dismissed a challenge by French MP Philippe Latombe, IAPP reported, noting it's the third EU–US transfer framework reviewed by EU courts in a decade, after Safe Harbor (struck down in 2015) and Privacy Shield (2020). Latombe appealed to the Court of Justice on 31 October 2025, and the case is pending, according to WilmerHale.
For risk planning, that history matters more than any single ruling. If your recovery depends entirely on a transfer mechanism that has been overturned twice before, you carry legal as well as technical risk.
How does the European Commission define cloud sovereignty?
Through its Cloud Sovereignty Framework, a procurement scoring model published in October 2025. It's written for the Commission's own cloud tenders, but it's a useful checklist for anyone.
The Cloud Sovereignty Framework (version 1.2.1) assesses providers on eight objectives:
- Strategic sovereignty
- Legal and jurisdictional sovereignty
- Data and AI sovereignty
- Operational sovereignty
- Supply chain sovereignty
- Technology sovereignty
- Security and compliance sovereignty
- Environmental sustainability
Each is scored on a SEAL scale from SEAL-0, "no sovereignty", where services are under exclusive control of non-EU parties, up to SEAL-4, "full digital sovereignty", with technology and operations "under complete EU control, subject only to EU law". The takeaway for an SME or MSP: ask suppliers about ownership, jurisdiction and operational control, not only about data centre location.
What does data sovereignty mean for backup and NIS2?
Your backup is your fallback when the primary platform fails, is compromised or becomes legally complicated. Keeping it with an independent EU provider gives you a second supplier and a second jurisdiction for recovery.
Both laws point the same way. NIS2 Article 21(2)(c) requires "business continuity, such as backup management and disaster recovery, and crisis management", and Article 21(2)(d) requires supply chain security, including the risks of your direct suppliers. Under the GDPR, a backup provider is a processor, so Article 28 requires a contract with it, and Article 32(1)(c) requires "the ability to restore the availability and access to personal data in a timely manner."
A GDPR-compliant backup, in practical terms, has:
- A Data Processing Agreement under Article 28 GDPR.
- Storage in the EU, with a provider that doesn't rely on third-country transfers for the backup data.
- Encryption in transit and access controls with MFA.
- Tested restores, so "timely" is a number you can show.
This is how we built our backup service. Data is stored only in our own Tier III data centres in the Netherlands and Germany, under EU law and independent of US hyperscalers. Every contract includes a GDPR Data Processing Agreement, and we're ISO 27001 and NEN 7510 audited. If your production data lives in Azure, see Azure backup, and for the difference between the two kinds of copy, read cloud storage vs cloud backup.
How do you improve data sovereignty without leaving your cloud?
Start with your recovery copy and your supplier list. You don't need to migrate away from Microsoft 365, Google Workspace or a public cloud to make real progress.
- Map data and suppliers. List where critical data lives and who owns each provider, including parent companies outside the EU.
- Classify. Decide which data is sensitive enough that foreign access or supplier lock-in is unacceptable.
- Check contracts. Confirm Data Processing Agreements, sub-processors and the transfer mechanism each one relies on.
- Add a sovereign recovery copy. Back up critical workloads to an EU provider, with immutable storage and separate credentials.
- Plan your exit. Know how you'd restore data outside the primary platform, and test it once a year.
- Report to management. Under NIS2 Article 20, management bodies approve and oversee cybersecurity measures, so put sovereignty risk on the agenda.
Not sure whether NIS2 applies to you? Check who falls within NIS2 scope. For supplier assessments, see NIS2 supply chain security.
What to do next
Data sovereignty isn't a label on a data centre. It's knowing which laws reach your data, keeping control of access, and being able to recover without depending on a single foreign supplier. For most organisations the fastest win is an independent, EU-based backup of the systems they can't run without.
Read how sovereignty fits your wider obligations on our NIS2 compliance page, or request a free assessment of where your data and backups sit today.
This article is information, not legal advice.
Frequently asked questions
What is the difference between data residency and data sovereignty?
Data residency is the physical location where data is stored, such as an EU region. Data sovereignty goes further: it asks which country's laws apply to the data and the provider, who controls access, and whether you can move or recover the data independently. Data can be resident in the EU without being sovereign if the provider answers to foreign law.
Does data sovereignty mean we must leave Microsoft 365?
No. Most organisations keep using Microsoft 365 and reduce their dependency instead. Common steps are enabling EU data residency options, hardening identities and keeping an independent backup with an EU provider under separate credentials. That way you can recover your data even if your tenant is compromised or access becomes legally complicated.
Is storing data in the EU enough for GDPR compliance?
Not on its own. The GDPR also covers processing contracts (Article 28), security measures including timely restore (Article 32) and transfers outside the EU (Chapter V). If a provider can be compelled by foreign law to disclose data, transfer and access questions remain even when servers are in the EU. Document how each provider handles this.
What is a GDPR-compliant backup?
There's no official certification, but a backup that supports GDPR compliance has a Data Processing Agreement with the provider, stores data in the EU without relying on third-country transfers, encrypts data and protects admin access with MFA, and is tested so you can restore personal data in a timely manner, as Article 32(1)(c) requires.
Does the US CLOUD Act apply to European companies?
The CLOUD Act applies to providers subject to US jurisdiction and covers data in their possession, custody or control, wherever it's stored. That can include data held by EU subsidiaries of US providers. A European company with no US presence is generally outside its direct reach. The legal detail varies, so take advice for your situation.
Sources
- 18 U.S. Code § 2713 - Required preservation and disclosure of communications and recordsLegal Information Institute, Cornell Law School, 2018
- CLOUD Act ResourcesU.S. Department of Justice, Criminal Division, 2023
- What is the EU Data Boundary?Microsoft Learn, 2025
- Microsoft admits it 'cannot guarantee' data sovereigntyThe Register, 2025
- Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, 2016
- European General Court dismisses Latombe challenge, upholds EU-US Data Privacy FrameworkIAPP, 2025
- European Court of Justice to review challenge to EU-U.S. Data Privacy FrameworkWilmerHale, 2025
- Cloud Sovereignty Framework, version 1.2.1European Commission, DG DIGIT, 2025
- Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, 2022


