Reviewed against EUR-Lex, the EDPB and NISTLast reviewed 4 min read
Kort sagt
- Ask for facts that exist as documents. Adjectives cannot be filed or re-checked.
- Ownership first: the contracting entity and its ultimate parent, both in writing.
- Support locations are the access path most residency statements omit.
- The subprocessor list matters less than whether it is change-controlled.
- Ask about inference location and prompt retention as two separate questions.
- Finish on reversibility: what an export looks like, and how long a migration takes.
Ownership: who you are actually contracting with
These three place a vendor in a category before any product discussion, and they are the ones most likely to be answered vaguely if asked verbally.
Who is the contracting entity, and who is its ultimate parent? Has the ownership changed in the last three years, and are you notified if it changes during the term? Which entity holds the encryption keys, and can any other entity in the group direct that entity to produce them?
The third is the one that separates a considered answer from a rehearsed one. A vendor who has thought about sovereignty will have an answer about key custody; one who has thought about marketing will return to the hosting region.
| Question | A good answer | A concerning answer |
|---|---|---|
| Contracting entity and ultimate parent? | Both named, in writing | We are a European company |
| Notified if ownership changes? | A contractual notice term | It has not come up |
| Who holds the keys, and who can direct them? | A named entity and a clear no | The data is encrypted at rest |
Källa: GDPR Chapter V, EUR-Lex
Data paths: where it goes and who can read it
Three more, and these are where residency statements are usually complete on storage and silent on everything else.
Which regions handle storage, processing and backup, and does failover ever land outside them? Which countries do support and administration staff operate from, and what can they read in a production incident? What product telemetry leaves the region, and is it content or metadata?
The support question is the one with the largest gap between the written answer and the operational reality. Ask specifically whether an engineer outside the EU can access production data during an escalation, since the answer is often yes with an approval step that nobody counts as a transfer.
The FTC has accumulated vast rulemaking, enforcement and adjudicatory powers, and it unquestionably exercises executive power, and must therefore be controlled by the Chief Executive, in whom such power is vested.
| Thought through | Not yet | |
|---|---|---|
| Failover region named | ✓ | ✕ |
| Support countries listed | ✓ | ✕ |
| Production access during escalation described | ✓ | ✕ |
| Telemetry split into content and metadata | ✓ | ✕ |
| Answers refer to the region selector | ✕ | ✓ |
Not yet is not the same as bad. A vendor who says they will find out and comes back with a document is more useful than one with a fluent answer to a question they misread.
Källa: NIS2 Article 21
The model layer: two questions, not one
Where does inference execute, under whose contract, and are you told if the provider changes? Are prompts and outputs retained, by whom and for how long?
They are separate because a vendor can have a good answer to the first and never have asked the second. Inference in an EU region with thirty-day prompt retention at the provider is a different exposure from the same region with zero retention, and the difference is contractual rather than technical.
If bring-your-own-model is offered, the questions move to your own procurement, which is usually an improvement for sovereignty and additional work for you. Worth knowing which of the two you are choosing.
Why the model layer carries content
- 60 %
- of European cases began with social engineering, whose alerts carry message content
- 21.3 %
- began with vulnerability exploitation, whose alerts carry host detail
- 68.6 %
- of recorded intrusions led to a data breach, which is what the context describes
- 53.7 %
- of recorded EU incidents involved essential entities under NIS2
Källa: ENISA Threat Landscape 2025
Källa: ENISA Threat Landscape 2025
Källa: ENISA Threat Landscape 2025
Källa: ENISA Threat Landscape 2025
Reversibility: the two that matter at renewal
What does an export of our data look like, in what format, and how long does it take? What happens to our data if we leave, and how is deletion evidenced?
These are the sovereignty questions that survive contact with reality, because they determine whether any of the earlier answers can be acted on. An arrangement you cannot leave is one where the ownership answer stops mattering the moment it changes for the worse.
For financial entities this is not optional. DORA Article 28 requires exit plans for arrangements supporting critical or important functions, and the same discipline is worth borrowing whether or not you are in scope.
| Question | A good answer | A concerning answer |
|---|---|---|
| What does an export look like? | A named format and a tested duration | Data can be exported |
| How long does a full export take? | Measured on a comparable estate | It depends on volume |
| What happens to data if we leave? | A retention period and a deletion process | It is deleted |
| How is deletion evidenced? | A certificate or an audit record | You have our assurance |
Källa: DORA Article 28, EUR-Lex
How to use the answers
File them with a date. Ownership, subprocessors and inference arrangements all change, and an answer from eighteen months ago describes a company that may not exist in the same form.
Score them against each other rather than against an imagined ideal vendor. The one who says plainly that inference runs outside the EU and explains the retention terms is more useful than the one who says sovereign and declines the detail.
Then ask the question that is not on the list: what would make you tell us we are not a good fit? A vendor with a real answer names a data classification, a sector or a scale where their arrangement is the wrong one. A vendor without one has described a product that suits everybody, which no product does.
Questions
Common questions
- What should we ask a vendor about sovereignty?
- Facts with documented answers: the contracting entity and ultimate parent, storage and backup regions, support locations, the subprocessor list with change notification, inference location and prompt retention, and what an export looks like.
- Which question sorts vendors fastest?
- Who holds the encryption keys, and can any other entity in the group direct that entity to produce them. A vendor who has thought about sovereignty answers it; one who has not returns to the hosting region.
- Why ask about support staff locations?
- Because a support engineer with production access is an access path regardless of where the disk sits, and residency statements rarely cover it.
- Why are inference and retention separate questions?
- A vendor can have a good answer about where inference runs and never have asked whether the provider keeps prompts. The exposure differs and the difference is contractual.
- What should we do with the answers?
- File them with a date and re-ask at renewal. Ownership, subprocessors and inference arrangements change, and nobody sends a notification.
Primärkällor
Källor
Varje regulatoriskt påstående på den här sidan går att spåra till en av källorna nedan. Ingen av dem är en konsultblogg.
- GDPR Chapter V, EUR-Lex— The transfer regime the answers are measured against
- EDPB letter on Trump v. Slaughter— Why ownership questions are live
- NIS2 Article 21, EUR-Lex— Supply chain security as its own requirement
- DORA Article 28, EUR-Lex— Exit plans and contractual terms
- NIST AI Risk Management Framework— The govern and map functions behind the model questions
Further reading
