EU data sovereignty is the practical ability to control personal data, understand which laws and actors can affect it, and make lawful transfer and access decisions. Keeping data in an EU region can reduce exposure, but residency alone does not establish GDPR compliance or prevent remote access from a third country.
Separate four concepts
| Concept | Question |
|---|---|
| Location | Where are active data, logs, backups and support copies stored? |
| Access | From which countries and legal entities can people or systems access them? |
| Control | Who determines purposes, permissions, encryption keys, deletion and onward sharing? |
| Transfer mechanism | If Chapter V applies, what legal route and safeguards support the transfer? |
Confusing these concepts causes weak cloud reviews. An EU data centre may still involve a non-EEA support team or sub-processor. Conversely, a transfer outside the EEA is not automatically prohibited if an applicable Chapter V mechanism and the rest of the GDPR requirements are satisfied.
GDPR transfer routes
When personal data is transferred to a third country or international organisation, work through the hierarchy:
- Adequacy decision (Article 45): verify that the current decision covers the destination, recipient and transfer.
- Appropriate safeguards (Article 46): examples include the European Commission’s standard contractual clauses (SCCs) and approved binding corporate rules. Assess whether the safeguard can work effectively in the circumstances and add supplementary measures where needed.
- Derogation (Article 49): use only where its specific conditions are met. Derogations are not a routine substitute for a durable transfer mechanism.
The status and scope of adequacy decisions can change. Record the decision relied on, date checked, covered entity or sector, and a monitoring owner rather than writing “adequate country” permanently into a contract register.
Cloud sovereignty review
For each service, establish:
- contracting entity and controller/processor roles;
- primary, disaster-recovery, telemetry and backup locations;
- support and administrative access countries;
- subprocessors and change-notification terms;
- transfer mechanism for each relevant flow;
- encryption in transit and at rest, and who controls keys;
- identity, privileged-access and logging controls;
- deletion behaviour, including backup expiry and account closure;
- government-request policy and transparency information; and
- exit options, formats, verification and residual copies.
Vendor labels such as “sovereign cloud” are not legal conclusions. Translate them into contract commitments and technical evidence.
A proportionate control strategy
Classify processing by sensitivity, scale, essentiality and potential impact on individuals. Then choose controls that match the scenario:
- limit data and purposes before selecting infrastructure;
- prefer regional processing where it materially reduces transfers and operational risk;
- segregate tenants, environments and administrator duties;
- use strong encryption and consider customer-controlled keys where useful;
- restrict and monitor remote access;
- minimise provider-readable identifiers through pseudonymisation where feasible;
- test deletion and portability; and
- revisit the assessment when laws, recipients, subprocessors or architecture change.
Localisation can be a policy, contractual or sector-specific requirement beyond the GDPR. Check applicable EU and national rules for regulated data; do not infer a general GDPR duty to keep all personal data inside the EU.
Our data protection service can map transfers and controls across cloud and vendor chains. An independent GDPR audit can test whether the documented location, access and safeguard model matches evidence.
Sources and review
- Regulation (EU) 2016/679, Chapter V on international transfers
- European Commission: international dimension of data protection
- EDPB Recommendations 01/2020 on supplementary measures
Reviewed on 8 August 2026. The guide avoids presenting EU hosting, SCCs or adequacy as automatic or permanent compliance conclusions.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.