Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The cloud is not weightless, and it is not just a place to store files. It is a chain of buildings, electricity, networks, chips, software, operators, contracts and laws. Knowing that your data is stored in a local data centre tells you where one part of that chain sits—not who can control or interrupt the service.

What does the geography of the cloud include?

“The cloud allowed us to stop thinking about servers,” writes Andrei Mochola, COO at Circularo, in an opinion article dated October 2, 2026. That convenience can make the cloud seem detached from place. In practice, every cloud service depends on physical infrastructure and on people, companies and legal systems that may be located in different countries.

Cloud geography also has a less visible dimension. In Cloud Geographies: Computing, Data, Sovereignty, Louise Amoore distinguishes the geography of cloud infrastructure from the way cloud systems make traces, patterns and possible futures calculable. The first asks where the equipment and data are. The second asks how information is processed and used to draw conclusions. Both matter when assessing who has power over a service and the information flowing through it.

Layer Question to ask Why it matters
Buildings, power and networks Where are the facilities, and what supplies their electricity and connectivity? A local data centre still depends on physical infrastructure and connections that can be disrupted or controlled.
Chips and hardware Who supplies and maintains the equipment? A service may rely on technology and supply chains from outside the country where its data is stored.
Operating systems, cloud platform and applications Who provides the software, updates it and sets its operating rules? Software control and dependencies can matter as much as the server’s address.
Identity, management and operations Who administers the service, and which people or systems can access it? Administrative access can create control or exposure even without a provider physically holding a server.
Data and encryption Where are data, metadata and telemetry stored, and who controls the keys? Data location alone does not establish who can access or manage information.
Contracts, companies and law Which company provides the service, which country’s laws apply to it, and what remedies or alternatives exist? A provider’s legal obligations and the customer’s contractual rights can cross borders.

These layers are connected. A country may host the building while companies elsewhere supply the hardware, software or management systems. The “cloud” therefore describes a service assembled across geography, not a single national location.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Where is my data?” is only the first question

A useful assessment separates the location of stored data from the location and control of the rest of the service. Ask where primary data, backups, metadata and telemetry are held; where they may be processed; and who can reach them through support or administration. Then ask who provides the hardware, platform and application, who operates them, and who controls encryption keys and identity systems.

Consider a hypothetical service whose servers are in Germany. The data centre may be local, while the hardware supplier, platform software, management tools and support operation have different origins. That arrangement does not, by itself, prove that a foreign company can access the data. It does mean that “the data is in Germany” cannot answer every question about dependency, control or legal exposure.

Question What the answer establishes What it does not establish by itself
Where is stored data? The stated location of the specified data at rest. Where processing occurs, who administers the service, or which laws apply to the provider.
Who owns or controls the infrastructure? Which companies or institutions have a role in the underlying facilities and technology. That the customer can operate, audit or replace those components independently.
Who operates it and controls the management layer? Who performs administration and has operational privileges. That data is physically stored in the operator’s country, or that the operator can read encrypted content.
Who provides the software? Which products and suppliers the service depends on. That the software can be replaced quickly or that an alternative will work with the same data and workflows.
Which country’s laws apply to the provider? Which legal obligations may affect the company. A complete answer about every jurisdiction, contract or circumstance relevant to a particular service.

As Mochola puts it, “The building is local. The dependency may not be.” The distinction is not proof of wrongdoing by a provider; it is a reason to examine the whole service rather than treating a data-centre address as a sovereignty guarantee.

How can a provider’s jurisdiction matter if data is stored elsewhere?

A provider can be subject to laws because of the company’s legal status and operations, not solely because a particular server is within the country’s borders. The U.S. CLOUD Act is an example often used to illustrate this issue: the legal exposure of a provider can matter even when data is stored abroad. The practical question is not simply “Is the data in the United States?” but which company holds or controls it, what legal obligations apply to that company, and how those obligations interact with the customer’s jurisdiction and contract.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That does not mean every foreign provider can freely disclose every customer’s data, or that storage location is irrelevant. Access, disclosure and safeguards depend on the applicable law and circumstances. For a consequential service, customers should establish the provider’s legal entity, the data and systems covered by the contract, access and disclosure procedures, and what notice or challenge mechanisms the agreement provides.

What is the EU proposing for sovereign cloud and AI services?

A 2026 European Commission staff working document says “digital sovereignty” lacks a clear, actionable definition for cloud and AI services. It proposes a harmonised framework with four assurance levels rather than treating sovereignty as a simple yes-or-no label. The proposed criteria span provider establishment, infrastructure and personnel, data location, cybersecurity, operational autonomy, and exposure to third-country laws.

At the described Level 1, criteria include a provider established in the Union; infrastructure, personnel and assets in the EU or EEA; EU customer data, including metadata and telemetry, kept in the EU unless otherwise required; state-of-the-art cybersecurity; and safeguards against third-country interference. The document says higher levels would involve stronger control, audit and verification by national authorities. It does not make those proposed levels an adopted certification merely by describing them.

The Commission assessment also describes a proposed public repository of audited sovereign cloud and AI services. It records consultation support for sovereignty criteria, EU-level procurement guidance, interoperability and public-sector cloud federation. These are policy proposals, not proof that any particular service has already been certified under a final scheme.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What do European respondents say they want?

The Commission’s 2026 consultation points to demand for autonomy and resilience, but the figures describe responses to that consultation—not a universal measure of every European buyer or resident:

  • 77% of responding public authorities supported a criterion covering sovereignty, autonomy, resilience and availability.
  • 80% of respondents emphasized reducing EU reliance on non-EU cloud and AI providers.
  • 85% of citizens reported low or very low trust in providers based outside the EU.
  • 76% considered that EU public services should not store citizen data with non-EU cloud providers.

These responses help explain the policy focus on dependence and assurance. They do not establish that every non-EU provider is insecure, or that a provider based in the EU automatically meets a customer’s sovereignty needs.

How can you tell whether a cloud service leaves you real options?

Sovereignty is not only a question of where a service starts; it is also a question of what you can do when a supplier, jurisdiction or supply chain becomes unavailable or unacceptable. Before signing, document the answers to these checks and make them contractual or testable where appropriate:

  • Another region: Can the service run from a second region, and what data or functionality would not be available there?
  • Another provider: Is there a technically viable alternative, and what would it take to transfer the workload?
  • Data export: Can you export data, metadata and relevant configurations in usable formats? What is excluded, and how long does export take?
  • Replacement technology: Can you replace key hardware or software dependencies without rebuilding the entire service?
  • Alternate operator: Could another qualified team take over administration, and what access, documentation and credentials would it need?
  • Supplier outage: Which essential functions can continue if the provider or a critical component is unavailable, and for how long?
  • Visibility and assurance: What can you audit about access, security controls, data location and dependencies? Which certifications or assessments apply to the service you are buying?
  • Switching cost and time: What are the expected technical, contractual and operational steps to leave, and how will you verify those estimates?

Evaluate the answers together. An export clause is of limited practical value if the data cannot be used elsewhere; a second region is not a complete fallback if it depends on the same management layer; and a local operator may not be an alternative if it cannot access the required documentation or credentials. The useful measure is whether a customer can change provider, technology or operator and keep critical work running.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does cloud sovereignty mean in practice?

It does not mean that every component must be domestic, nor does a domestic data-centre address settle the question. It means understanding the geography and control of the complete service, including its legal dependencies, and deciding which dependencies are acceptable for the workload. As Mochola concludes, “Sovereignty is ultimately a question of options.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.