What is data residency and why is it not sovereignty?
The physical location where data is stored and processed. It says where data resides, not who can be compelled to hand it over: it is not sovereignty.
Data residency is the physical location where your data is stored and processed: the cloud region, the data center, the country. It is a geographic attribute, not a legal one, and this is where the most expensive confusion in the sovereignty debate begins: residency says where data resides, sovereignty is about who can be compelled to hand it over. A data center in Milan does not change the jurisdiction of a non-EU provider, in the same way a contract signed in Italy does not change the nationality of the company signing it. The practical paradox is that many companies pick the right cloud region and then ignore where backups, application logs and support tickets end up, since those often travel different technical paths than the primary record and end up outside the perimeter they thought they had protected. Understanding this distinction before signing a cloud contract avoids discovering, during an audit or a foreign authority request, that the promised protection only covered half the problem.
When residency clauses genuinely help
Residency is not marketing per se: it has legitimate, verifiable uses. It reduces latency for nearby users. It simplifies your GDPR position on transfers outside the EU: if data never leaves the Union, a whole layer of complexity disappears. It satisfies sector or contractual requirements that explicitly demand data in a given country, and it makes audits and inspections easier. Watch the details the sales pitch leaves out, though: backups, logs, telemetry and support flows often travel different paths than the primary data. Residency that covers the database but not the support ticket containing an extract of your data is half a guarantee: always ask for the complete flow map, not the location of the primary record.
When it becomes marketing
It becomes marketing when it is sold as protection from foreign jurisdiction. The CLOUD Act follows the provider, not the data's location: if your goal is that no non-EU authority can order its disclosure, residency alone does not deliver that. For that you need keys managed outside the cloud, providers under European jurisdiction or hybrid architectures. The question to ask is not "where is the data?" but three questions together: where it is, who holds the keys, which legal entity can receive a disclosure order. If the answer to the first is excellent and the other two stay vague, you are buying geography, not control. And before negotiating any clause you need to know what data you have and where it flows: mapping those flows is a data governance exercise.
Frequently asked questions
Related terms
- CLOUD Act · US law compelling American providers to hand over data under US legal orders, even when it is stored in Europe.
- Digital sovereignty · An organization's effective control over its data, infrastructure and technology: who can access it, who can compel disclosure, who it depends on.
- Sovereign cloud · Cloud offerings built to guarantee control over data and operations: residency, staffing, isolation. The critical point remains jurisdiction.
- Data governance · The rules, roles and processes that make company data reliable, secure and usable: who can do what, on which data, at what quality.
- Data Governance Act · EU Regulation 2022/868 on data intermediaries and public data reuse, applicable since 24 September 2023.
A term that hits close to home? Let's talk.
CONTACT ME