Skip to content

EU sovereignty

Data sovereignty for security operations: what is actually checkable

Most writing on data sovereignty is about where servers sit, which is the least interesting part of the question and the easiest to answer with a map on a slide. The harder question, and the one that decides whether an arrangement survives a supervisory conversation, is which legal system can compel access to the data and under what process. A dataset held in Frankfurt by a provider subject to a foreign disclosure order is physically in the EU and legally reachable from outside it. That distinction is the whole subject. It matters more for security tooling than for most other software, because a detection platform sees everything: authentication events, internal traffic, the contents of alerts, and increasingly the reasoning of a model that was handed all of it. This hub separates the sovereignty claims that can be verified from the ones that cannot, and it cites the legal instruments rather than vendor marketing, because the SERP for this term currently contains almost none of them.

Not the same as
Residency
Turns on
Jurisdiction
Sharper for
Security tools
Checkable
Five things
Written byRobin ÖsterdalFounder & CEOReviewed byMalthe Bang NorengaardCo-founder & CTO

Reviewed against EUR-Lex, the EDPB and ENISALast reviewed 5 min read

Kort sagt

  • Sovereignty is a jurisdiction question. Residency is a geography question. They are not the same claim.
  • A dataset in Frankfurt held by a provider subject to a foreign disclosure order is reachable from outside the EU.
  • Security tooling raises the stakes: the platform sees authentication, internal traffic and alert contents.
  • Model-driven tooling adds a second hop, because inference may run where the rest of the stack does not.
  • Five things are checkable: region, ownership, subprocessors, inference location, and the transfer mechanism.
  • Under NIS2 and DORA the vendor's own dependencies sit inside your assessment whether or not you looked.
Claims a vendor can prove against claims they cannot
Provableask for the documentNot provabletreat as positioning
Which region the workload runs in
Who ultimately owns the operating entity
The current subprocessor list
Where model inference executes
Which transfer mechanism is relied on
That no foreign authority could ever compel access
Being described as sovereign

The right column is not necessarily dishonest. It is unprovable: no commercial party can bind a foreign legislature, and a vendor claiming otherwise has made a promise they cannot keep.

Källa: GDPR Chapter V, EUR-Lex

The distinction that does the work

Residency answers where bytes are stored. It is verifiable, it appears in contracts, and it is what most sovereignty pages actually describe.

Sovereignty answers which legal system governs compelled access. That turns on three things that have nothing to do with geography: which entity operates the service, who ultimately controls that entity, and which legal orders bind it. A European subsidiary of a foreign parent is a European company with a foreign chain of control, and both halves of that sentence matter.

For most software the gap between the two is theoretical. For a detection platform it is not, because the data in question is the record of who accessed what across your entire estate, which is precisely the material a compelled-disclosure regime would be interested in.

The FTC has accumulated vast rulemaking, enforcement and adjudicatory powers, and it unquestionably exercises executive power, and must therefore be controlled by the Chief Executive, in whom such power is vested.

Why security tooling is the sharp case

A detection platform is granted the broadest read access in the organisation by design. It ingests authentication events, endpoint telemetry, network flows and the contents of alerts, and it retains them long enough to investigate. That makes it a single place where the shape of the whole business is legible.

Model-driven tooling extends the exposure in a way architecture diagrams often miss. Alert context is sent to an inference endpoint, and that endpoint is a separate contractual arrangement with a separate location. A pipeline hosted in Europe that calls a model elsewhere has moved the data without moving the diagram.

This is also where the answer is unusually easy to give if a vendor has thought about it. The hosting region, the model provider and the inference location are three facts, and a vendor who cannot state all three in a sentence has not decided them.

Where security data actually travels
HopWhat crossesThe question to ask
Agent to collectorEndpoint telemetryWhich region terminates the connection?
Collector to storageRetained eventsWhere is the retention, and for how long?
Storage to analysisCorrelated contextDoes analysis run in the same jurisdiction?
Analysis to modelAlert context, often verbatimWhere does inference execute, under whose contract?
Model to verdict storeReasoning and conclusionsIs the reasoning retained, and where?
Verdict to supportWhatever an engineer seesWhich staff, in which country, can read it?

Källa: GDPR Chapter V, EUR-Lex

Where the regulations put this

Sovereignty is not itself a legal requirement in the EU. There is no article that says security tooling must be EU-operated, and a vendor implying otherwise is overstating.

What exists instead are three adjacent requirements that make the question unavoidable. GDPR Chapter V governs transfers of personal data to third countries and requires a lawful mechanism for each one. NIS2 Article 21 makes supply chain security a risk management requirement in its own right, so your detection vendor's dependencies are inside your assessment. And for financial entities, DORA Article 28 requires contractual terms including where the service is provided from.

Read together, the effect is that you do not have to argue that sovereignty matters. You have to be able to describe your arrangement, and describing it is what surfaces the problem when there is one.

The requirements that make this unavoidable

53.7 %
of recorded EU incidents involved essential entities under NIS2

Källa: ENISA Threat Landscape 2025

38.2 %
hit public administration, where sovereignty questions are asked first

Källa: ENISA Threat Landscape 2025

2 %
of worldwide turnover as the NIS2 sanction ceiling for essential entities

Källa: NIS2 Article 21

60 %
of European cases began with social engineering, which the platform is meant to catch

Källa: ENISA Threat Landscape 2025

21.3 %
began with vulnerability exploitation across the estate the platform watches

Källa: ENISA Threat Landscape 2025

68.6 %
of recorded intrusions led to a data breach, which is what the telemetry records

Källa: ENISA Threat Landscape 2025

Why the SERP for this term is unusually thin

It is worth saying plainly, because it explains why so much writing on this subject is unsatisfying. The pages that currently rank for data sovereignty come from infrastructure vendors, and between them they cite almost no legal instruments at all.

That is not laziness. An infrastructure vendor writing about sovereignty has a commercial reason to keep the discussion at the level of regions and certifications, because that is the part they can sell. Citing GDPR Chapter V invites the question of which transfer mechanism they rely on, and citing a pending appeal invites the question of what happens if it succeeds.

The practical consequence for a reader is that the available material describes the solvable half of the problem in detail and the unsolvable half not at all. This hub tries to do the opposite, which is why every page here carries its sources.

Run the analyst on Anthropic, or an EU-hosted model that meets your residency rules.

What has changed recently, and what has not

The legal basis for transfers to the United States remains in force. The EU-US Data Privacy Framework adequacy decision has not been suspended or annulled, and transfers made under it are lawful today. A challenge brought by Philippe Latombe was dismissed by the General Court on 3 September 2025, and an appeal is pending before the Court of Justice as Case C-703/25 P with no hearing date set.

What did change is the argument underneath it. On 29 June 2026 the US Supreme Court decided Trump v. Slaughter, overruling Humphrey's Executor, which had held that Congress could protect Federal Trade Commission commissioners from removal except for cause such as inefficiency, neglect of duty or malfeasance in office. The Court held that the FTC exercises executive power and must therefore be controlled by the Chief Executive.

The European Data Protection Board wrote to the Commission about that judgment. The relevance is that the FTC's independence was part of what the Commission relied on when it assessed adequacy, so a change to that independence is a change to a load-bearing element of the assessment, whatever the eventual outcome.

For a buyer the practical reading is narrow and useful: the mechanism is valid, and the mechanism is contested. An arrangement that does not depend on it is not more lawful today, but it is less exposed to a change in the assessment.

Questions

Common questions

What is data sovereignty?
Which legal system can compel access to data and under what process. It is a question about jurisdiction, corporate control and contract, not about which region a workload runs in.
Is data residency the same thing?
No. Residency is where the bytes are stored, which is verifiable and usually contractual. Sovereignty is which legal orders bind the entity operating the service.
Does EU law require EU-operated security tooling?
No. What exists are adjacent requirements: GDPR Chapter V on transfers, NIS2 Article 21 on supply chain security, and for financial entities DORA Article 28 on contractual terms.
Is the EU-US Data Privacy Framework still valid?
Yes. It has not been suspended or annulled, and transfers under it are lawful. An appeal is pending at the Court of Justice as Case C-703/25 P, and the EDPB has written to the Commission following Trump v. Slaughter.
What should we actually ask a vendor?
Five things with documented answers: hosting region, ultimate corporate ownership, current subprocessor list, where model inference executes, and which transfer mechanism is relied on.

Primärkällor

Källor

Varje regulatoriskt påstående på den här sidan går att spåra till en av källorna nedan. Ingen av dem är en konsultblogg.

Further reading

Working out what to ask about sovereignty?

We will go through your requirement and the questions worth asking, including the ones where our own answer is inconvenient. Half an hour, no preparation needed.