Reviewed against EUR-Lex and the EDPBLast reviewed 4 min read
Kort sagt
- The term has no settled legal definition, which is why it survives procurement unchallenged.
- Four different arrangements are all marketed as EU sovereign.
- They differ in who operates the service and who ultimately controls that operator.
- A region selector changes geography and leaves the control chain untouched.
- A European subsidiary changes the contracting entity and not the ownership.
- One question sorts them: who is the contracting entity, and who is its ultimate parent?
| Regionon a foreign platform | Operated by partnerEuropean operator | European subsidiaryforeign parent | European companyno foreign parent | |
|---|---|---|---|---|
| Data stored in the EU | ✓ | ✓ | ✓ | ✓ |
| Contracting entity is European | ✕ | ✓ | ✓ | ✓ |
| Operator is European | ✕ | ✓ | ~ | ✓ |
| No foreign ultimate parent | ✕ | ~ | ✕ | ✓ |
| Support staff only in the EU | ✕ | ~ | ~ | ~ |
| Technology is independently controlled | ✕ | ✕ | ✕ | ✓ |
The last row matters at renewal rather than at signature. An operator who licenses the technology from a foreign parent depends on that licence continuing.
Källa: GDPR Chapter V, EUR-Lex
The four arrangements
A region on a foreign platform is the most common and the weakest form. Data is stored and processed in an EU region of a platform operated by a foreign company. Geography changes; the control chain does not.
A foreign platform operated by a European partner goes further. A European company runs the service under licence, holds the customer contract and employs the operators. Whether the arrangement withstands pressure depends on how genuinely separated the operations are, which is a factual question rather than a marketing one.
A European subsidiary of a foreign parent gives you a European contracting entity and European staff, with a foreign ownership chain above it. This is where most enterprise offerings sit, and it is a real improvement over a region selector without being the same thing as independence.
A European company with no foreign parent is the only arrangement where the ownership question has a clean answer. It is also the smallest category, and it frequently comes with tradeoffs in scale, feature breadth or price that are worth being honest about.
What each one changes about compelled access
The relevant question is which entity holds the data and the keys, and which legal orders bind that entity. Geography is a weak proxy for it.
A region selector leaves the answer unchanged, because the entity is the same one it was before. An operating partner changes the answer if the partner genuinely holds the keys and the parent genuinely cannot direct them, and leaves it unchanged if either is not true. A subsidiary changes the contracting party while leaving the corporate chain intact, which matters because a parent can direct a subsidiary through ordinary corporate governance.
None of the four removes the possibility of legal process entirely. What they do is change how many parties an order would have to reach and how visible that would be, and for most buyers that shift is the realistic goal rather than absolute immunity.
The context the question sits in
- 38.2 %
- of EU incidents hit public administration, where the question is asked first
- 53.7 %
- of recorded incidents involved essential entities under NIS2
Källa: ENISA Threat Landscape 2025
Källa: ENISA Threat Landscape 2025
The one question that sorts them
Who is the contracting entity, and who is its ultimate parent? Both halves, in writing.
The answer places a vendor in one of the four categories in a sentence, and it is a fact rather than a description, so it cannot be answered with adjectives. It is also stable enough to be worth re-asking at renewal, since ownership changes and nobody sends a notification.
If you want a second question, ask which countries support and administration staff operate from. Between the two you have the ownership chain and the human access path, which is most of the actual exposure.
The FTC has accumulated vast rulemaking, enforcement and adjudicatory powers, and it unquestionably exercises executive power, and must therefore be controlled by the Chief Executive, in whom such power is vested.
When the weaker forms are the right answer
Independence is not free, and pretending it is would be the same overclaiming this page argues against. A smaller European vendor may have fewer certifications, a narrower feature set, a shorter track record and a real concentration risk of its own.
For a workload with no personal data and no regulatory exposure, a region selector on a large platform is a perfectly good answer and the sovereignty conversation is a distraction.
The calculation changes where the data is the record of everything that happens across the estate, where a supervisory authority may ask about the arrangement, and where the cost of migrating later is high. Security tooling sits in all three, which is why the question is worth the time here and not everywhere.
Questions
Common questions
- What does EU sovereign mean?
- There is no settled legal definition. Four arrangements share the label, differing in who operates the service and who ultimately controls that operator.
- Is an EU region enough?
- It changes geography and leaves the control chain untouched. The entity holding the data and the keys is the same one it was before.
- Is a European subsidiary sovereign?
- It gives you a European contracting entity and European staff with a foreign ownership chain above. A real improvement over a region selector, and not the same as independence.
- Which question sorts vendors fastest?
- Who is the contracting entity, and who is its ultimate parent. Both in writing. The answer places a vendor in one of the four categories in a sentence.
- Is independence always the right choice?
- No. It can come with fewer certifications, narrower features and its own concentration risk. It matters most where the data is broad, the regulator may ask, and migration would be expensive.
Primärkällor
Källor
Varje regulatoriskt påstående på den här sidan går att spåra till en av källorna nedan. Ingen av dem är en konsultblogg.
- GDPR Chapter V, EUR-Lex— The transfer regime the distinctions sit inside
- EDPB letter on Trump v. Slaughter— Why the ownership chain is a live question
- NIS2 Article 21, EUR-Lex— Supply chain security as its own requirement
- DORA Article 28, EUR-Lex— Contractual terms including place of provision
- ENISA Threat Landscape 2025— Which sectors face the question first
Further reading
