Sovereignty
It is not about where your data lives. It is about who can reach it.
A European data centre is a start, not a guarantee. What decides it is who owns the parties in your chain, and under which law that owner can be compelled to cooperate.
Location is not enough
Laws travel with the owner.
The US CLOUD Act (2018) allows US authorities to demand data from companies subject to US law, even when that data is stored in Europe. Other countries have similar laws. Where the server stands then makes little difference.
That affects more than your cloud provider. It affects every link with access to your environment: the vendor of the management platform, the backup software, the remote support tool, the password vault. And therefore your MSP too, which uses all those tools with admin rights to everything you own.
That is why we look beyond location, at the ownership and jurisdiction of every party in the chain, right down to our own suppliers.
Making it measurable
From gut feeling to a level.
With the Cloud Sovereignty Framework, the European Commission introduced a yardstick that expresses sovereignty in levels, from SEAL-0 to SEAL-4. Storing data in the EU is a minimum in that framework, not the end point. We use those levels to make your current position and your goal concrete.
From the inside out
Build from the core outwards.
Start with what you protect. The order decides whether you remove risk or merely move it.
Data
The core. Which data is critical, where does it live and who can claim it?
Infrastructure
Hosting, network and storage. Location matters, but ownership matters more.
Management
The layer that is often forgotten: who has admin rights, and with which tools?
Workplace & software
Where people work. Updates, integrations and licences decide who is watching.
Step by step
Pragmatic, not dogmatic.
Replacing everything at once usually creates more risk, not less. Some tools are deeply woven into how people work; ripping them out overnight breaks more than it fixes.
We start where the dependency hurts most, choose European alternatives that are genuinely mature, and bring your people along. Sometimes a hybrid interim phase is the wisest route.
Control you can sustain beats a transition you cannot.
Self-assessment
Five questions for your current IT partner.
Can your provider answer them without hesitation? Then you are in good shape. If not, that is exactly the conversation we would like to have.
- Who ultimately owns your IT partner, and the vendors of its management tools?
- Under which law can any of those parties be compelled to hand over data or access?
- Where are your backups, and who holds the keys?
- Can a foreign vendor block your accounts or licences remotely?
- How quickly could you switch if you had to?
Dependent without knowing it?
Let's count the keys.
A first conversation is an inventory: which vendors, tools and jurisdictions sit between you and your data? You get an honest picture, even if the conclusion is that you are in better shape than you thought.