Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglishESEspañolFRFrançaisTRTürkçe
Two colleagues in front of a large wall screen showing cloud diagrams in a darkened room

Sovereign cloud: the question behind "where is our data"

Sovereign cloud stopped being only about where a data centre stands. It is about who can reach the data, under whose law that happens, and whether you can keep running if the relationship with a provider changes. This page separates those layers.

The layers

Four layers of sovereignty

They get lumped together, and a provider delivering the first layer then gets taken for all four.

  • Where the data sitsThe easiest layer and usually a choice at setup: a region inside the EU. This is what most providers mean when they say "sovereign", and it is the layer that says least — where a disk stands does not decide who can reach it.
  • Who can technically reach itAdministrators, support, subcontractors. This is about encryption with keys you control, about prior approval for provider access, and about whether support looks in from a country outside the EU.
  • Whose law the provider falls underA European data centre run by a party subject to non-European law can still fall under a demand from that country. Whether that is a problem depends on your data and your sector; that judgement should come from a lawyer and not from us.
  • Whether you can leaveThe layer that weighs heaviest in procurement and gets tested least: can you get your data out, in a usable form, within a reasonable time, and does it run elsewhere. Until that has been tried once, it is an assumption.
The questions

What to ask a provider

Four questions a brochure cannot answer. They work on the provider you already have as well.

Who can reach it without my knowledge?

Ask for the procedure rather than the promise: how does a provider engineer obtain access, who approves it, and where is the log that I can read myself.

Whose keys are they?

Encryption with keys the provider holds protects against a stolen disk and not against the provider. If you hold them yourself, ask straight away who revokes one when things go wrong and what happens then.

Where does the support process run?

Access is not only production. Support, monitoring and fixing an outage are the moments when someone genuinely looks in. Ask where those people sit.

What does leaving look like?

In what form does the data come out, how long does it take, and what stays behind. Put it in the contract, and try it once with a test set — the only way to know whether the answer holds.

Our part

What we do in this, and what we do not

We build and we record. We do not decide whether something is legally acceptable.

  • Building to the choice that was madeRegion, encryption, key management, network separation and access control, and where it fits an environment running on your own equipment or at a European provider. The choice is yours; we make sure reality follows it.
  • Recording that it stands that wayWhich region, which keys, who has access and when that changed. That is what an auditor, a large customer or a regulator wants to see, and it is the part you cannot reconstruct afterwards.
  • Thinking about the exitWe build with the way out included: exports that work, formats readable elsewhere, and trying it once instead of trusting it. Including when we are the party you would be leaving.
  • What we do not doSay whether a service meets a law or your sector’s policy. That is a legal qualification. We supply the facts that judgement rests on, and we say so when the technology cannot make a promise true.

This is not legal advice. What stands here is the translation into technology and record-keeping; whether a processing activity is permitted should come from your lawyer or the regulator. See also digital sovereignty for the wider trade-off.

Frequently asked

Questions we get about this

The ones that come up most, answered briefly.

Is data in a European data centre automatically sovereign?

No. Where a disk stands says nothing about who can reach it. A provider subject to non-European law can still fall under a demand from that country despite a European data centre, and administrators and support outside the EU may have technical access.

Which question says most about a provider?

What leaving looks like. In what form the data comes out, how long that takes and what stays behind. Put the answer in the contract and try it once with a test set; it is the cheapest insurance in the whole programme.

Do you decide whether a cloud service is legally permitted?

No, that is a legal qualification and an IT supplier does not make it. We build to the choice that was made, record what stands, and say so when the technology cannot make a promise true.

Find out where your data actually sits

We walk the environment through the four layers above and put on paper what applies today. That often turns up differences between what was agreed and what was built.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. Privacy policy.