Reviewed against EUR-Lex, the EDPB and ENISALast reviewed 5 min read
Kort sagt
- Sovereignty is a jurisdiction question. Residency is a geography question. They are not the same claim.
- A dataset in Frankfurt held by a provider subject to a foreign disclosure order is reachable from outside the EU.
- Security tooling raises the stakes: the platform sees authentication, internal traffic and alert contents.
- Model-driven tooling adds a second hop, because inference may run where the rest of the stack does not.
- Five things are checkable: region, ownership, subprocessors, inference location, and the transfer mechanism.
- Under NIS2 and DORA the vendor's own dependencies sit inside your assessment whether or not you looked.
| Provableask for the document | Not provabletreat as positioning | |
|---|---|---|
| Which region the workload runs in | ✓ | ✕ |
| Who ultimately owns the operating entity | ✓ | ✕ |
| The current subprocessor list | ✓ | ✕ |
| Where model inference executes | ✓ | ✕ |
| Which transfer mechanism is relied on | ✓ | ✕ |
| That no foreign authority could ever compel access | ✕ | ✓ |
| Being described as sovereign | ✕ | ✓ |
The right column is not necessarily dishonest. It is unprovable: no commercial party can bind a foreign legislature, and a vendor claiming otherwise has made a promise they cannot keep.
Källa: GDPR Chapter V, EUR-Lex
The distinction that does the work
Residency answers where bytes are stored. It is verifiable, it appears in contracts, and it is what most sovereignty pages actually describe.
Sovereignty answers which legal system governs compelled access. That turns on three things that have nothing to do with geography: which entity operates the service, who ultimately controls that entity, and which legal orders bind it. A European subsidiary of a foreign parent is a European company with a foreign chain of control, and both halves of that sentence matter.
For most software the gap between the two is theoretical. For a detection platform it is not, because the data in question is the record of who accessed what across your entire estate, which is precisely the material a compelled-disclosure regime would be interested in.
The FTC has accumulated vast rulemaking, enforcement and adjudicatory powers, and it unquestionably exercises executive power, and must therefore be controlled by the Chief Executive, in whom such power is vested.
Why security tooling is the sharp case
A detection platform is granted the broadest read access in the organisation by design. It ingests authentication events, endpoint telemetry, network flows and the contents of alerts, and it retains them long enough to investigate. That makes it a single place where the shape of the whole business is legible.
Model-driven tooling extends the exposure in a way architecture diagrams often miss. Alert context is sent to an inference endpoint, and that endpoint is a separate contractual arrangement with a separate location. A pipeline hosted in Europe that calls a model elsewhere has moved the data without moving the diagram.
This is also where the answer is unusually easy to give if a vendor has thought about it. The hosting region, the model provider and the inference location are three facts, and a vendor who cannot state all three in a sentence has not decided them.
| Hop | What crosses | The question to ask |
|---|---|---|
| Agent to collector | Endpoint telemetry | Which region terminates the connection? |
| Collector to storage | Retained events | Where is the retention, and for how long? |
| Storage to analysis | Correlated context | Does analysis run in the same jurisdiction? |
| Analysis to model | Alert context, often verbatim | Where does inference execute, under whose contract? |
| Model to verdict store | Reasoning and conclusions | Is the reasoning retained, and where? |
| Verdict to support | Whatever an engineer sees | Which staff, in which country, can read it? |
Källa: GDPR Chapter V, EUR-Lex
Where the regulations put this
Sovereignty is not itself a legal requirement in the EU. There is no article that says security tooling must be EU-operated, and a vendor implying otherwise is overstating.
What exists instead are three adjacent requirements that make the question unavoidable. GDPR Chapter V governs transfers of personal data to third countries and requires a lawful mechanism for each one. NIS2 Article 21 makes supply chain security a risk management requirement in its own right, so your detection vendor's dependencies are inside your assessment. And for financial entities, DORA Article 28 requires contractual terms including where the service is provided from.
Read together, the effect is that you do not have to argue that sovereignty matters. You have to be able to describe your arrangement, and describing it is what surfaces the problem when there is one.
The requirements that make this unavoidable
- 53.7 %
- of recorded EU incidents involved essential entities under NIS2
- 38.2 %
- hit public administration, where sovereignty questions are asked first
- 60 %
- of European cases began with social engineering, which the platform is meant to catch
- 21.3 %
- began with vulnerability exploitation across the estate the platform watches
- 68.6 %
- of recorded intrusions led to a data breach, which is what the telemetry records
Källa: ENISA Threat Landscape 2025
Källa: ENISA Threat Landscape 2025
Källa: ENISA Threat Landscape 2025
Källa: ENISA Threat Landscape 2025
Källa: ENISA Threat Landscape 2025
Why the SERP for this term is unusually thin
It is worth saying plainly, because it explains why so much writing on this subject is unsatisfying. The pages that currently rank for data sovereignty come from infrastructure vendors, and between them they cite almost no legal instruments at all.
That is not laziness. An infrastructure vendor writing about sovereignty has a commercial reason to keep the discussion at the level of regions and certifications, because that is the part they can sell. Citing GDPR Chapter V invites the question of which transfer mechanism they rely on, and citing a pending appeal invites the question of what happens if it succeeds.
The practical consequence for a reader is that the available material describes the solvable half of the problem in detail and the unsolvable half not at all. This hub tries to do the opposite, which is why every page here carries its sources.
Run the analyst on Anthropic, or an EU-hosted model that meets your residency rules.
What has changed recently, and what has not
The legal basis for transfers to the United States remains in force. The EU-US Data Privacy Framework adequacy decision has not been suspended or annulled, and transfers made under it are lawful today. A challenge brought by Philippe Latombe was dismissed by the General Court on 3 September 2025, and an appeal is pending before the Court of Justice as Case C-703/25 P with no hearing date set.
What did change is the argument underneath it. On 29 June 2026 the US Supreme Court decided Trump v. Slaughter, overruling Humphrey's Executor, which had held that Congress could protect Federal Trade Commission commissioners from removal except for cause such as inefficiency, neglect of duty or malfeasance in office. The Court held that the FTC exercises executive power and must therefore be controlled by the Chief Executive.
The European Data Protection Board wrote to the Commission about that judgment. The relevance is that the FTC's independence was part of what the Commission relied on when it assessed adequacy, so a change to that independence is a change to a load-bearing element of the assessment, whatever the eventual outcome.
For a buyer the practical reading is narrow and useful: the mechanism is valid, and the mechanism is contested. An arrangement that does not depend on it is not more lawful today, but it is less exposed to a change in the assessment.
Questions
Common questions
- What is data sovereignty?
- Which legal system can compel access to data and under what process. It is a question about jurisdiction, corporate control and contract, not about which region a workload runs in.
- Is data residency the same thing?
- No. Residency is where the bytes are stored, which is verifiable and usually contractual. Sovereignty is which legal orders bind the entity operating the service.
- Does EU law require EU-operated security tooling?
- No. What exists are adjacent requirements: GDPR Chapter V on transfers, NIS2 Article 21 on supply chain security, and for financial entities DORA Article 28 on contractual terms.
- Is the EU-US Data Privacy Framework still valid?
- Yes. It has not been suspended or annulled, and transfers under it are lawful. An appeal is pending at the Court of Justice as Case C-703/25 P, and the EDPB has written to the Commission following Trump v. Slaughter.
- What should we actually ask a vendor?
- Five things with documented answers: hosting region, ultimate corporate ownership, current subprocessor list, where model inference executes, and which transfer mechanism is relied on.
Primärkällor
Källor
Varje regulatoriskt påstående på den här sidan går att spåra till en av källorna nedan. Ingen av dem är en konsultblogg.
- GDPR Chapter V, EUR-Lex— Transfers of personal data to third countries
- EU-US Data Privacy Framework adequacy decision, EUR-Lex— The mechanism currently in force
- EDPB letter on Trump v. Slaughter— The regulator's own reading of the judgment
- NIS2 Article 21, EUR-Lex— Supply chain security as its own requirement
- DORA Article 28, EUR-Lex— Contractual terms including place of provision
- ENISA Threat Landscape 2025— The incident population the tooling exists for
Further reading
