Data sovereignty: why the location of your data decides
Data sovereignty means actual control over data: where it sits, who can technically access it, and which law governs the organisation processing it. The server location answers only the first of those three questions.
That shortcut is what leads to wrong decisions in practice. A data centre in Frankfurt or Zurich says nothing about whether the operator is subject to a foreign disclosure obligation, or whether its staff can access data in the clear.
This article separates the three layers, places the US CLOUD Act and the legal bases for transfers, and names the questions that let you actually assess an offering.
Three layers that often get conflated
"Hosted in the EU" is a statement about exactly one layer. Assessing sovereignty means answering all three separately – and no layer resolves the others.
| Layer | The question | What it does not answer |
|---|---|---|
| Data residency | In which country does the data sit at rest and during processing? | Whether the operator can or must access it |
| Operator sovereignty | Which law governs the company running the infrastructure, and which governs its parent? | Which sub-processors are involved |
| Operational sovereignty | Who can technically access data in the clear, in which cases, and is that logged? | Whether the transfer is legally permissible |
The US CLOUD Act and the limits of server location
The Clarifying Lawful Overseas Use of Data Act of 2018 obliges providers subject to US law to hand data to US authorities on order – regardless of which country the servers are in. What counts is control over the data, not its physical location.
That also captures European subsidiaries of US groups, to the extent the parent can exercise control. A data centre in the EU changes nothing about that constellation; it only shifts the data residency layer.
In practice: asking about server location is necessary but not sufficient. The second question – which law governs the operator – determines whether a foreign disclosure obligation can bite at all.
What Schrems II changed
In its judgment of 16 July 2020 the Court of Justice of the European Union invalidated the EU-US Privacy Shield. Standard contractual clauses remained valid, but the Court required a case-by-case assessment of whether an equivalent level of protection is actually achieved in the recipient country.
That turned the transfer impact assessment into standard practice: a documented evaluation of the legal position in the destination country and of the supplementary measures meant to restore protection. The assessment sits with the exporting company, not the provider.
Since the adequacy decision of 10 July 2023 the EU-US Data Privacy Framework provides a workable basis again – but only for companies certified under it. Switzerland has its own parallel recognition, the Swiss-U.S. Data Privacy Framework, in force since 15 September 2024.
The legal bases for transfers
The EU and Switzerland regulate disclosure abroad separately, with comparable structure and different authorities. Serving both spaces means needing both bases.
| EU (GDPR) | Switzerland (revFADP) | |
|---|---|---|
| Core provision | Chapter V, Art. 44 et seq. | Art. 16 et seq. FADP |
| Country list | Adequacy decisions of the European Commission | Annex 1 to the Data Protection Ordinance, set by the Federal Council |
| Alternative safeguard | Standard contractual clauses, binding corporate rules | Standard contractual clauses, approved or recognised by the FDPIC |
| United States | EU-US Data Privacy Framework, since 10 July 2023 | Swiss-U.S. Data Privacy Framework, since 15 September 2024 |
| Additional assessment | Transfer impact assessment following Schrems II | Duty of care where no adequacy decision exists |
EU or Switzerland: what the choice turns on
Both offer a high level of protection, and the EU recognises Switzerland as adequate. The difference lies less in the level of protection than in the frame of reference of your own clientele.
For companies serving mainly German or Austrian clients, the EU is the obvious location: the GDPR is the framework clients, works councils and regulators think in. For Swiss institutions, law firms and public bodies, Switzerland is often the requirement – partly from supervisory law, partly from procurement rules.
The choice of region is therefore a product characteristic, not a worldview. What matters is that it is contractually fixed and not unilaterally changeable – and that the other two sovereignty layers are answered alongside it.
Questions that reveal the difference
These six questions separate defensible offerings from location promises. They should be answered in writing and reappear in the contract.
- In which country does the data sit at rest, and in which does inference happen? The two can diverge.
- Which law governs the operator, and who is its parent company?
- Which sub-processors are involved, in which countries, and how are changes communicated?
- Which individuals can access data in the clear, in which cases, and is every access logged?
- Is training on our data contractually excluded – including for sub-processors and including in aggregated form?
- How long are inputs retained, and can the retention period be fixed contractually?
What to document
Sovereignty you cannot evidence does not help under audit. These five records should be filed and findable.
- The data processing agreement including the list of sub-processors and the agreed processing region.
- The legal basis for the transfer: adequacy decision, certification or standard contractual clauses.
- Where no adequacy decision exists, the documented additional assessment and the supplementary measures.
- The entry in the record of processing activities with categories of recipients and any third-country element.
- The technical commitments: encryption, access rules, logging, retention periods.
Frequently asked questions
Is a data centre in the EU enough?
It answers the data residency question, not the operator sovereignty question. If the operator is subject to US law, the CLOUD Act can bite regardless of server location. Both questions have to be asked and answered separately.
What is the difference between data residency and data sovereignty?
Data residency is a geographical statement: in which country does the data sit? Data sovereignty is a control statement: who can access it legally and technically? Residency is a precondition of sovereignty but not the same thing.
Are transfers to the US unproblematic again under the Data Privacy Framework?
They rest on a basis again, but only for companies actually certified under it – which has to be checked before each transfer. Switzerland has its own recognition, in force since 15 September 2024. Earlier decisions were struck down by the courts, which is why a documented assessment remains sensible.
Does encryption help against a disclosure obligation?
Only where the provider does not control the keys. Encryption whose keys sit with the operator protects against third parties, not against an order directed at the operator. What matters is key custody, not encryption as such.
What is a transfer impact assessment?
A documented evaluation of whether, despite standard contractual clauses, an equivalent level of protection is achieved in the recipient country, and which supplementary measures secure it. The Court of Justice required it in the Schrems II judgment of 16 July 2020; responsibility sits with the exporting company.
EU or Switzerland – which is better?
Both offer a high level of protection, and the EU recognises Switzerland as adequate. The choice follows your clientele and any supervisory or procurement requirements. More important than the region is that it is contractually fixed and not unilaterally changeable.
Sources
- Regulation (EU) 2016/679 (GDPR) · EUR-Lex
- European Data Protection Board · EDPB
- Swiss Federal Act on Data Protection (FADP, SR 235.1) · Fedlex – Swiss Federal Chancellery
Related reading
Bring AI into your company securely.
Try Custodos with your team – and see how quickly secure AI becomes productive.
- Try it with the whole team
- Set up in minutes
- Productive from day one
