Who Really Controls Your Company's Data?
Data sovereignty is not just about where servers are located. It is about which laws can reach your data and whether anyone can technically read it while it is being processed.

On June 18, 2025, during a hearing before the French Senate, a Microsoft France executive was asked a straightforward question under oath: Can you guarantee that European data will never be requested by US authorities?
The answer was clear: No. That guarantee cannot be given.
The discussion concerned a product marketed in France as "sovereign." The data was stored in France, operated by a French partner, and governed by French regulations. Yet none of that changed the answer.
Data sovereignty is not about where a server is located. It is about which country's laws determine who can request access to your data. There is another question that many organizations never ask: Can anyone technically read your data while it is being processed?
Why Doesn't Data Location Guarantee Anything?
The US CLOUD Act allows US authorities to request data from any US company that controls or has access to it, regardless of where the servers are physically located. Frankfurt, Paris, or an "EU region" offer no guarantees if the service provider's parent company is headquartered in the United States.
Jurisdiction follows the service provider - not the server's location. That's why signing a cloud contract that promises "your data stays in the EU" only answers half of the question.
The other half remains: Who can legally require that data to be disclosed?
What Happens When Two Legal Systems Conflict?
The European Union has gradually strengthened its response. Chapter VII of the EU Data Act, applicable since September 2025, requires cloud providers to challenge unlawful requests from third countries for data stored within the European Union. But that alone doesn't solve the problem.
In June 2026, the European Commission proposed another step: a framework introducing four levels of data sovereignty for public sector procurement. The Commission acknowledged that the highest level would be extremely difficult for US providers to achieve because conflicts between legal jurisdictions cannot be resolved through contract language alone.
Even if the legal questions are addressed, one challenge still remains: the technical one.
What Does Confidential Computing Solve That Encryption Alone Cannot?
Data exists in three different states:
- at rest,
- in transit,
- and in use.
Encryption protects the first two extremely well. The third is more complicated.
For a server to process information, data typically has to be decrypted in memory for a brief moment. During that window, a privileged administrator, a compromised hypervisor, or another highly privileged component could theoretically access it.
Confidential computing was designed to solve exactly this problem. It allows data to be processed inside hardware-protected environments that remain inaccessible even to server administrators. Technologies such as Intel SGX, Intel TDX, AMD SEV-SNP, and ARM TrustZone are examples of this approach. Gartner identifies confidential computing as one of the technologies most likely to reshape enterprise infrastructure over the next several years, predicting that by 2029, more than 75% of data processing in untrusted environments will be protected in this way.
Combined with encryption keys that remain under the customer's control rather than the cloud provider's, the result is a fundamentally different security model. Even if a provider receives a lawful request to hand over customer data, it may simply have nothing readable to provide.
So... Do Your Company's Data Really Belong to You?
Your company's data do not belong to you simply because you created them or pay to store them. They truly belong to you only if you control who can legally request them - and who can technically read them.
Most organizations have answered only one question: Where are our data stored?
Far fewer have asked who has legal authority over those data - or whether they can be read while they are being processed. The next time you evaluate a cloud provider or a data processing platform, don't just ask: "Where are our data stored?"
Instead, ask: "Who can legally request our data - and who can actually read them?"
Related posts
Every System Looked Correct. Together They Described a Different Reality.
Every system looked correct on its own. The real warning appeared when ERP records, sales reports, and GPS data described the same business process differently.
Read moreData & StrategyThe Most Dangerous Business Decisions Are the Ones That Look Right
Most decisions that cost companies money seem completely reasonable at the time. They look logical. They are supported by data. The only problem is that they are based on only part of the available information.
Read moreReady to automate your sales process?
Let's map your workflow and identify where automation creates the fastest measurable impact.
Book a Call