Executive Summary
Three terms get sold as one promise, and buyers pay for the difference. Residency describes location. Sovereignty describes control, the keys, and which laws can reach the data. Vendors sell the confusion, and a region inside the right country is easy to market as a sovereign platform.
A provider can meet residency and still fail the rest. Backups, logs, and metadata count as data, and a snapshot can land in a second region while the primary stays put. Sub-processors add jurisdictions one contract at a time. The US CLOUD Act lets American authorities compel US providers wherever the data lives. Schrems II struck down Privacy Shield over that gap in 2020. Key custody decides most arguments. Customer-held keys and an unsealed hardware module change the answer. France’s SecNumCloud scheme screens out exposure to non-EU law, and NIS2 raises the duties again. Run the exit test before signing. If you cannot move the data and take the keys without the provider’s help, you hold a long lease, not control.
Three terms get used as if they mean the same thing. They do not. Data residency, data sovereignty, and sovereign cloud describe different promises, and only one of them touches who can actually reach your data.
Vendors benefit from the confusion. A region inside the right country can be sold as a sovereign offering. Buyers rarely ask the harder questions until a regulator or a board member does.
Data Residency Only Promises Where the Bytes Sit
Residency is a location claim. Your data is stored and processed inside a named jurisdiction. Under the GDPR, moving personal data outside the EU triggers extra legal duties. Keeping it in a Frankfurt region avoids some of that work.
Residency leaves a great deal uncovered. It says nothing about who can access the data. It says nothing about the provider’s staff, its sub-processors, or the support engineer answering tickets from another country. It says nothing about which government can compel the provider to hand data over.
Backups, logs, and metadata count as data too. A provider can keep the primary database in one country and ship snapshots to a second region it operates elsewhere. The residency claim still holds, and the exposure grows.
Sub-processors are the other blind spot. A provider may pass data to a monitoring vendor, a payment processor, or a support contractor. Each one adds a jurisdiction to the chain, and the customer often learns about it in a terms-of-service update.
A provider can meet residency and still fail sovereignty. That is the whole point of the distinction. The bytes sit inside the country. The control does not. Careful teams still get this wrong. They verify the region, sign the contract, and file the paperwork. Nobody checks where the administrator credentials live.
Data Sovereignty Asks Who Holds the Keys and Who Can Compel Access
Sovereignty is about control and jurisdiction. It asks who can access the data, under which laws, and who holds the encryption keys. Residency answers where. Sovereignty answers who.
Provider nationality matters here. The US CLOUD Act lets American authorities compel US-based providers to produce data those providers control, wherever that data is stored. The Court of Justice of the European Union struck down the Privacy Shield over exactly this gap in its Schrems II ruling in 2020.
Key custody decides most of the argument. If the provider holds the keys, a lawful order can reach the data. Customer-managed keys held outside the provider’s reach change that answer. So does a hardware security module the provider cannot unseal.
Operational dependency is the part residency never touches. Someone patches the hypervisor, runs the control plane, and holds the break-glass account. If that someone answers to a foreign parent, the sovereignty claim leans on a promise rather than a control.
Read the contracts with those questions open. Ask where the keys live, who can rotate them, and what happens when a foreign court demands data. The answers separate real sovereignty from a marketing slide.
Sovereign Cloud Adds Operational Control, and You Should Test the Exit
A sovereign cloud bundles residency and sovereignty with operational independence. In-country staff, local support, no foreign dependencies, and audited controls. France’s SecNumCloud scheme is among the strictest, and it screens out exposure to non-EU law. The GAIA-X initiative pushes in a similar direction across Europe.
Staffing is a signal worth checking. Ask where the support engineers sit, which laws they answer to, and who can be ordered to hand over a decryption key. A local data center with a foreign operations team is residency with extra steps.
National rules tighten the picture. The EU’s NIS2 directive raises cybersecurity duties for critical sectors, and several member states layer their own certification schemes on top. Buyers should expect audits, not assurances.
Treat sovereignty as a spectrum, not a checkbox. Nearly every large provider now markets a sovereign option, and the details vary wildly. The European Data Protection Board keeps publishing guidance on international transfers, which tells you the legal ground keeps moving.
The exit test settles it. Can you move your data out without the provider’s help? Can you take the keys with you? Is the format open enough to run the workload somewhere else? If leaving is hard, you do not control the data. You hold a long lease on someone else’s platform.
Ask those questions before signing, not after. Residency is easy to prove and easy to sell. Sovereignty is the part that matters, and it is the part vendors describe in the vaguest terms.
The sovereignty picture behind this, from procurement gates to the CLOUD Act gap, is pulled together in the 2026 State of Enterprise Infrastructure report.
Related reading. where data sovereignty actually reshapes cloud workloads, and what a sovereign cloud does and does not cover, and why digital sovereignty is a procurement problem.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.

[…] Related reading. the data sovereignty layer underneath, and sovereign cloud is not data residency. […]
[…] reading. AI data centre power commitments, a running record. Sovereign cloud is not data residency. The 2026 State of Enterprise […]
[…] reading. Sovereign cloud is not data residency, and the gap costs money covers why the two get confused. Digital sovereignty is a procurement problem, not a data center […]